Privacy Policy

Effective Date: May 20, 2026 | Last Updated: July 13, 2026

1. Introduction & Legal Framework

This Privacy Policy explains how Venlio AS ("we", "us", or "our") collects, uses, shares, and protects personal data through our B2B and B2C club management platforms, analytics dashboards, mobile interfaces, and facility automation ecosystems (collectively, the "Service").

We process personal data in strict compliance with the European General Data Protection Regulation (GDPR), the Norwegian Data Protection Act (Personopplysningsloven), the DAC7 directive for marketplace payment tracking, and the Norwegian Bookkeeping Act.

2. Our Legal Status: Data Controller vs. Data Processor

Depending on your relationship with Venlio and the specific features being utilized, our regulatory role under the GDPR changes dynamically. We act as either a Data Controller (determining the purpose and means of data processing) or a Data Processor (executing data operations solely on behalf of another entity):

Venlio as a Data Controller

We act as Data Controller for your global application authentication account, casual/friend-group court reservations, peer match-making level evaluations, user profile images, split-billing transaction paths, structural configurations of sports facilities, and platform-wide system telemetry used to optimize Venlio.

Venlio as a Data Processor

We act as a Data Processor in two scenarios: (1) When you join a Corporate Club (where your employer controls membership terms), and (2) When we compile custom venue-specific metrics (performance dashboards, player usage trends, and marketing campaign outcomes) exclusively on behalf of, and according to instructions from, the respective Venue Owner.

Entity Details: Venlio AS (Org. Nr: 937844166)

Official Address: Husaberget 6, 4032 Stavanger, Norway

Privacy Inquiries: privacy@venlio.app

3. Segmented Scope of Data Processing

To ensure transparent information handling, our data mapping is strictly separated by the persona and structural functionality you engage with:

A. Casual Players & Friend-Group Clubs (Venlio = Controller)

Applies to users using standard registration, public matches, activities, peer match-making, or managing self-organized internal club friend circles.

Data Categories Processing Purpose Legal Basis & Retention
Full Name, Email, Phone Number, Profile Avatar, and Skill Ranking parameters. Constructing user profiles, authorizing app security, managing social player rankings, and executing match matchmaking feeds. Contract Performance
Until profile deletion request, or purged 5 years after last active authentication.
Phone-Identifier Connections: Exact verified mobile phone number search index. Enabling friends who already hold your exact, verified mobile phone number to search, locate, and verify your profile for match invites, team setups, and split cost allocations, even when public directory visibility is turned off. Contract Performance
Required functional connection mechanism of our peer-to-peer sports matching platform; only exact numbers find accounts, "fuzzy" or partial listings strictly blocked.
Split Billing Variables: Friend connections, peer billing splits, and transaction IDs. Processing instant platform court cost distribution among player configurations via our Stripe gateway integrations. Contract Performance / Legal Duty
Retained for 5 years following the financial year close under Bokføringsloven § 13.

B. Corporate Clubs & Subsidized Schemes (Venlio = Processor)

Applies to employees/members utilizing slots sponsored, managed, or subsidized by their company or corporate club framework.

Data Categories Processing Purpose Legal Basis & Operational Scope
Corporate affiliation identifiers, corporate subsidy balances, and facility utilization patterns. To calculate workplace allowances, deliver booking logs to corporate administrators, and confirm invoicing values for employers. Processor Directives
Governed exclusively by your employer’s corporate privacy policy. Data is maintained or purged based on corporate instructions.
Corporate Administration Dependency: Because Venlio functions strictly as a Processor here, members wishing to alter corporate attributes or terminate company club access must submit their requests directly to their organization's internal club administrator.

C. Venue Owners & Managers — Administrative Accounts (Venlio = Controller)

Applies to operators and facility managers setting up commercial business properties and managing portal account infrastructure.

Data Categories Processing Purpose Legal Basis & Retention
Business Registry Name, Venue Coordinates, Admin Contact metrics, and Manager Login Credentials. Configuring and localizing physical sports facilities on our platform, enabling real-time player reservation views, and managing admin permissions. Contract Performance
Retained for the commercial lifespan of the registered sports facility account.
Stripe Connect Metadata, Company Tax IDs, and routing numbers. Executing secure B2B payouts. Sensitive KYC (Know Your Customer) data goes directly to Stripe for compliance auditing. Legal Obligation / Contract
Retained for 5 years post-turnover to fulfill the Norwegian Bookkeeping Act and DAC7 requirements.

D. Venue Owners — Analytics & Reporting Dashboards (Venlio = Processor)

Applies to operational reports, graphs, and campaign metrics handled by Venlio on behalf of a specific venue operator.

Data Categories Processing Purpose Legal Basis & Retention Scope
Venue Performance Metrics: Historic venue occupancy files, localized tracking of player patterns, and marketing campaign click-through conversions. To compile customized dashboard metrics, venue efficiency charts, utilization graphs, and promotional analysis exclusively within the venue's management interface. Processor Directives / DPA
Processed purely on the instructions of the Venue Owner under our B2B Data Processing Agreement. Stored for the duration of the commercial service agreement.

E. IoT Automation & Telemetry (Venlio = Controller)

Data Categories Processing Purpose Legal Basis & Retention
Reservation metadata linked directly with venue entry identifiers. Generating temporary physical lock access codes and automating court lighting relays during active booking slots. Contract Performance
Processed and maintained synchronously with core court booking metrics.
IP Addresses, device identifiers, browser types, and crash dump states. Maintaining platform uptime, debugging application builds, running firewalls, and preventing transaction fraud. Legitimate Interest
Telemetry traces are systematically deleted or anonymized within 90 days.

4. Is Data Provision Mandatory?

Providing essential personal attributes (such as your full name, verification phone/email, business identity, or transaction profiles) is an operational and statutory requirement. Without this information, it is technically impossible to instantiate your software account, issue electronic pin entry codes, execute split bills, or coordinate venue configurations.

Optional fields—such as uploading an avatar image or enabling non-essential system match alerts—are entirely voluntary.

5. Secure Information Sharing & Subprocessors

Venlio does not sell, trade, or rent personal data. We disclose targeted segments of data to the following third parties solely to fulfill our operations:

  • Partner Sports Venues: Receive participant booking rosters to physically cross-check court occupancy and verify entry safety.
  • Corporate Club Data Controllers: For subsidized corporate profiles, booking metrics are transferred back to your employer for invoicing and payment auditing.
  • Stripe Connect (Payment Gateway): Transaction states, automated multi-peer billing logs, and vendor verification elements are routed straight to Stripe to clear payments.
  • Regulatory & Law Enforcement Bodies: Disclosed only if required by binding directives under corporate tax transparency systems (DAC7) or statutory accounting audits.

International Data Transfers:

Although our core server stack operates entirely within European data environments, global sub-processors like Stripe may route transactions through international hubs. Wherever cross-border operations occur, safety is enforced via the European Commission's approved Standard Contractual Clauses (SCCs).

6. Cookies & Local Storage

We use necessary technical cookies and client-side browser storage (such as JWT authentication tokens) to safely persist your login state and facilitate secure transactional checkout pipelines powered by Stripe. We do NOT run third-party cross-site behavioral tracking networks or sales profiling trackers.

7. Children's Privacy

In compliance with our Terms of Service, registerable access to our platform requires users to be at least 18 years of age. We do not knowingly compile, query, or store personal information belonging to minors. If you believe we have inadvertently collected data of a minor under 18, please alert us at privacy@venlio.app so we can delete the records immediately.

8. Core Security Safeguards

We enforce technical and organizational safeguards to minimize the risks of unauthorized access, data alteration, or loss:

  • Encryption Protocols: All data is fully encrypted in transit using industry-standard TLS 1.3, and at rest using AES-256 encryption.
  • Access Management: Strictly guarded role-based access permissions (RBAC) to production cloud environments.
  • Monitoring & Recovery: Automated integrity checks, real-time firewalls, and nightly isolated backup cycles.

9. Amendments & Policy Updates

We reserve the right to modify this Privacy Policy to comply with regulatory changes or operational scaling. When amendments occur, we will update the "Last Updated" timestamp at the top of this documentation. In the event of material structural changes, a descriptive pop-up banner or email notification will be distributed to players before the changes take effect.

10. Your Legal GDPR Rights

Under the GDPR, you maintain comprehensive rights regarding our processing of your personal data when we act as a Data Controller:

Access & Rectification

Request a transparent digital readout of all personal files stored on our network and immediately correct inaccurate profiles.

Right to Erasure ("Forgotten")

Command the complete deletion of your profile. Note that financial ledgers bound by 5-year accounting law obligations cannot be removed prematurely.

Objection & Restriction

Halt target telemetry configurations or contest our processing actions when they rely on corporate legitimate interest frameworks.

Data Portability

Extract your structural account data profile into a portable, machine-readable digital file layout.

To invoke any of these rights, email us at privacy@venlio.app. Note: If the inquiry concerns information collected under a Corporate Club framework or a Venue Analytics dashboard where Venlio operates as a Data Processor, we will forward your request directly to the respective organization for authorization. You also maintain the absolute right to register structural complaints directly with the Norwegian Data Protection Authority (Datatilsynet).