Legal · Geniva

Privacy Policy

Last updated 28 September 2026

This is an archived version of our Privacy Policy. It no longer applies. Read the current version → · All versions

This Privacy Policy explains how Geniva accesses, collects, stores, uses and shares your personal information when you use our services (the "Services"), including when you download and use the Geniva mobile application, visit geniva.co.uk, or otherwise engage with us.

Geniva is a university social platform that brings together events, sports and group chat for student societies and their members. We are responsible for deciding how your personal information is processed. If you do not agree with this policy, please do not use the Services.

Who we are. The Services are operated by Joshua Hinder, trading as Geniva, a sole trader registered with the UK Information Commissioner's Office (registration number ICO00014031434), of 124 City Road, London EC1V 2NX, United Kingdom. Joshua Hinder is the data controller for the personal information described in this policy. If the controller ever changes (for example, if the business later incorporates), this policy will be updated to say so.

Questions? Contact us at [email protected].

Summary of key points

This summary highlights the main points. Use the table of contents to jump to any section in full.

What information do we collect? We collect the personal information you provide when you create an account and use the Services — such as your name, email address, username, society memberships and event activity. We do not collect your location.

Do we process sensitive information? We do not deliberately collect special category data. However, your membership of certain societies could reveal information such as religious belief or sexual orientation. We explain how we handle that below.

Do we collect information from third parties? No. We only collect information directly from you.

How do we process your information? To provide and run the Services, enable events and chat, keep the platform safe and secure, and comply with the law. We process information only when we have a valid legal basis.

Is any of it public? Yes. Societies, events and each society’s committee — including their names, usernames and photos — can be seen by anyone, with no account. Everything else needs you to be signed in.

Push notifications are off until you turn them on. When they are on, a chat notification carries the sender’s name and the first part of the message through Expo, Apple and Google to reach your phone.

Who do we share it with? Only the service providers needed to operate Geniva (such as our hosting and notification providers). We do not sell your personal information or share it for third-party marketing.

Where is your data held? Your account, posts and messages are stored in Frankfurt, Germany, and our servers run in the Netherlands. A few providers operate globally; we explain the safeguards for those transfers below.

What are your rights? Depending on where you live, you may have rights to access, correct, delete or restrict the use of your personal information. You can exercise these in the app or by contacting us.

Table of contents

01What information do we collect?

Personal information you provide to us

In short: We collect the personal information you give us when you register and use the Services.

We collect personal information that you voluntarily provide when you register, use the Services, take part in activities (such as joining a society, posting, or RSVPing to an event), or contact us. This may include:

  • names
  • email addresses
  • usernames
  • passwords (stored only in encrypted, hashed form by our authentication provider — we never see or store your password in plain text)
  • contact and notification preferences
  • society memberships and the events you create, join or attend
  • messages and content you post in society and event group chats

Sensitive (special category) information

We do not ask for, or deliberately collect, special category data — for example information about your health, racial or ethnic origin, religious beliefs, or sexual orientation.

However, because Geniva lets you join societies, your membership of a particular society could indirectly reveal special category information — for example, joining a faith society may suggest a religious belief, or joining an LGBTQ+ society may suggest sexual orientation.

Where this happens, we rely either on the "not-for-profit body" condition in Article 9(2)(d) of the UK GDPR (which covers societies processing data about their own members) or on your explicit consent. For each society's membership list, the society itself decides how that data is used and acts as the data controller, and Geniva acts as its data processor — meaning we only handle that membership data on the society's instructions.

Information collected automatically

In short: We collect a limited amount of technical information needed to run and secure the Services.

When you use the Services, our hosting and infrastructure providers automatically record limited technical information in server logs — principally your IP address, basic device and operating-system information, and diagnostic data such as error reports. We use this only to operate, secure and troubleshoot the Services. We do not collect or track your location, and we do not use this technical data to build advertising profiles.

If you use the mobile application, we may also process the device identifiers needed to deliver push notifications you have asked to receive.

02What other people can see

In short: Some of Geniva is public. You can browse it without an account, and so can anyone else.

You do not need an account to look at Geniva, and neither does anyone else — including search engines.

  • Public to anyone, with no account: society pages and their descriptions, logos and links; events, including their titles, descriptions, venues and times; our announcements; and, on each society page, the names, usernames, profile photos and roles of that society’s committee.
  • Visible to signed-in members: the feed, posts, photos, dumps, comments, attendee lists and group chats of the societies you belong to.
  • Visible only to you: your notifications, your settings, your email addresses and your verification status.

Profile photos and profile cover images are stored so that anyone holding the direct link to the image can open it, without signing in. Photos inside posts and dumps are not: those are served through links that expire after two hours.

If you join a society committee, your name, username and profile photo become part of a page that anyone on the internet can read. If you would rather they did not, step back from the committee role or change your display name and photo first.

03How do we process your information?

In short: We process your information to provide and improve the Services, communicate with you, keep the platform safe, and comply with the law.

We process your personal information for the following purposes:

  • To create and manage your account and keep you logged in.
  • To deliver the Services — including events, society and event group chats, and the features you choose to use.
  • To enable communication between users through group chats and related features.
  • To respond to your enquiries and provide support.
  • To send you administrative messages about your account, changes to our terms, and other service-related matters.
  • To keep the platform safe and lawful — including moderating content, preventing fraud and abuse, and meeting our obligations under the Online Safety Act 2023.
  • To protect vital interests where necessary to prevent harm to you or others.

04What legal bases do we rely on?

In short: We only process your personal information when we have a valid legal reason to do so under the UK GDPR.

The UK GDPR requires us to explain the legal bases we rely on. Depending on the activity, these are:

  • Performance of a contract. We process your information to provide the Services you sign up for and to fulfil our agreement with you — for example, creating your account and recording your RSVPs.
  • Legitimate interests. We process some information where it is in our legitimate interests and not overridden by your rights — for example, to keep the Services secure, prevent fraud and abuse, understand how the Services are used, and improve them.
  • Consent. We rely on your consent for specific activities, such as sending you push notifications or, where relevant, processing data revealed by your society memberships. You can withdraw consent at any time.
  • Legal obligations. We process information where necessary to comply with the law, including our duties under the Online Safety Act 2023 and to cooperate with law enforcement or regulators.
  • Vital interests. We process information where necessary to protect someone's life or safety.

05When and with whom do we share your information?

In short: We share information only with the service providers that help us operate Geniva, and in a few specific legal situations.

We use a small number of providers to run Geniva. They may access your personal information only to perform tasks for us, on our instructions, under contracts that require them to protect it. They may not use it for their own purposes, and none of them pays us for your data.

ProviderWhat it does for usWhat reaches itWhere
SupabaseDatabase, sign-in and file storageYour account, profile, posts, photos and messagesFrankfurt, Germany
RailwayRuns the Geniva APIEvery request you make, as it is handledNetherlands
CloudflareSecurity and content delivery in front of our sitesYour IP address and the requests you makeGlobal
ExpoDelivers push notificationsNotification text, including a message previewUnited States
Apple, GoogleDeliver notifications to your deviceThe same notification textGlobal
Amazon Web ServicesAutomated image safety checksEach image you upload, at the moment you upload itLondon, UK
SentryCrash and error reporting from the appCrash reports and the screens visited beforehandGermany
ResendSends our emailsYour email address and the message we send youUnited States
VercelHosts geniva.co.ukYour IP address when you visit the websiteGlobal
TermlyRuns the form you use to make a data requestYour name, email address and what you are asking for — only if you use that formUnited States

We may also disclose your information:

  • To comply with the law or respond to lawful requests from public authorities.
  • In connection with a business transfer — for example if Geniva is involved in a merger, acquisition or sale of assets, in which case your information would remain protected by a policy at least as protective as this one.

We do not sell your personal information, and we do not share it with third parties for their own marketing.

06Push notifications

In short: They are off until you turn them on, and they carry your message text to Expo, Apple and Google.

Push notifications are off until you switch them on. We never ask for permission when you first open the app, and we do not register your device until you choose to enable them in Settings.

When they are on, a notification about a new chat message contains the sender’s name, the name of the society or channel, and up to the first 140 characters of the message. To reach your phone it passes through Expo and then Apple or Google, so those companies handle that text.

Messages are encrypted while they are stored on our systems, but a notification is not — that is true of every push notification on every phone. If you would rather your messages did not appear on a lock screen, turn notifications off in Settings, or hide message previews in your phone’s own notification settings.

07Is your information transferred internationally?

In short: Everything that matters most is held in the UK or the EEA. Three providers operate globally, with safeguards.

Your account, profile, posts, photos and messages are stored in Frankfurt, Germany. The servers that handle your requests run in the Netherlands, and automated image safety checks run in London. Crash reports from the app are held in Germany. All of these are in the UK or the European Economic Area, and transfers from the UK to the EEA are permitted under the UK's data protection adequacy regulations without any further safeguard.

Four providers operate globally and may process some information outside the UK and EEA: Cloudflare, which protects and delivers our sites; Expo, together with Apple and Google, which deliver push notifications; Resend, which sends our email; and Termly, which runs our data-request form, and receives your details only if you use it. Where information is transferred outside the UK, the transfer is covered by safeguards recognised under the UK GDPR — the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum — as set out in each provider's data processing terms. Ask us and we will tell you which applies to which.

08How long do we keep your information?

In short: Most things go when you delete your account. A few are kept longer, and we say which and why.

Different information is kept for different lengths of time.

InformationHow long we keep it
Your account and profileUntil you delete your account, which takes effect immediately
Posts, comments and photosUntil you delete them, or until you delete your account
Photos posted in a dump windowDeleted when the window closes — between 1 and 168 hours after it opens, 24 by default — or at once if the committee closes it early
Messages you send in a group chat (society, committee and topic chats)Kept so the conversation stays readable for everyone else. If you delete your account, your name and photo are removed and your messages show as “Deleted user”
Direct (1-to-1) messages you sendUntil you delete your account, when they are deleted
A copy of a message someone reportedKept with the report as evidence. If the sender deletes their account, the copy is kept without their name or any identifier for 3 years after the report is closed, then deleted. Messages reported as child sexual abuse or exploitation are kept as described in the row about that material
NotificationsUntil you delete your account
Reports about content or people, and our record of what we did about themKept after the account involved is deleted, with names and identifiers removed, because we must be able to show how we handled a safety report
Privacy complaints you make to us, and our record of how we handled them3 years after we close the complaint, then deleted. We keep them for that time even if you delete your account, because we must be able to show the Information Commissioner's Office how we handled a complaint
Material reported as child sexual abuse or exploitation, the account details of the person who posted or sent it, and the username of the person who reported itKept for as long as needed to report it to the National Crime Agency and support any investigation, and not deleted or anonymised on request during that time. If the person who posted or sent it asks to delete their account, the account is closed and they are signed out, but these details are kept for that period unless we conclude the report was unfounded. If the person who reported it deletes their account, only their username is kept with the report
The email address of a banned accountKept after the account is deleted, so that the ban cannot be evaded by signing up again
Our internal record of moderator and administrator actionsKept as a record of how decisions were made. If you delete your account, your name is removed from these records
Server logs, crash reports and database backupsKept for a short operational period by our hosting providers, for security, troubleshooting and recovery

Where we cannot delete something immediately because it sits in a backup, we isolate it from further use until that backup is overwritten in the normal cycle.

09How do we keep your information safe?

In short: We use appropriate technical and organisational measures to protect your information.

We have put in place appropriate technical and organisational security measures designed to protect the personal information we process, including encryption in transit, access controls and authentication safeguards. However, no method of transmission or storage is completely secure, so we cannot guarantee absolute security. You should always access the Services within a secure environment.

10Do we collect information from minors?

In short: The Services are intended for users aged 18 and over.

We do not knowingly collect data from, or market to, anyone under 18 years of age. By using the Services, you confirm that you are at least 18. If we learn that we have collected personal information from someone under 18, we will deactivate the account and take reasonable steps to delete that information. If you believe we may hold information about someone under 18, please contact us at [email protected].

11What are your privacy rights?

In short: In the UK, EEA and Switzerland you have rights over your personal information, including access, correction and deletion.

Depending on where you live, you may have the right to:

  • request access to, and a copy of, your personal information;
  • request that we correct or delete your personal information;
  • restrict or object to how we process your information;
  • request portability of your information; and
  • withdraw consent where we rely on it (this does not affect processing that already took place).

You can exercise these rights in the app or by contacting us — see section 15. We will respond in line with applicable data protection law.

If you are unhappy with how we have used or looked after your information, you can complain to us — see section 16.

If you are in the UK and believe we are processing your information unlawfully, you have the right to complain to the Information Commissioner's Office (ICO). If you are in the EEA, you may complain to your local supervisory authority; if you are in Switzerland, to the Federal Data Protection and Information Commissioner.

Withdrawing your consent

Where we rely on your consent, you can withdraw it at any time by updating your preferences in the app or by contacting us. This will not affect the lawfulness of any processing carried out before you withdrew it.

Notifications

You can turn push notifications on or off at any time using the notification settings inside the Geniva app, or in your device's system settings.

Marketing communications

If we send you marketing emails, you can opt out at any time using the unsubscribe link in those emails or by contacting us. We may still send you service-related messages necessary to run your account.

12Controls for do-not-track features

Most browsers and some operating systems include a "Do-Not-Track" (DNT) setting. As no uniform standard for DNT signals has been agreed, we do not currently respond to them. If a standard is adopted that we are required to follow, we will update this policy.

13Do we make updates to this policy?

In short: Yes — we will update this policy as needed to stay compliant.

We may update this policy from time to time. The updated version will be shown by a revised "Last updated" date at the top. If we make material changes, we may notify you directly or by posting a prominent notice. We encourage you to review this policy regularly.

14How can you contact us?

If you have questions or comments about this policy, you can email us at [email protected] or write to us at:

Geniva
124 City Road
London EC1V 2NX
United Kingdom

15How can you review, update or delete your data?

You have two ways to review, update or delete the personal information we hold about you:

  • In the app (recommended). Log in and go to your account settings, where you can review and update your details, export a copy of your data, or request deletion of your account and information.
  • By contacting us. If you cannot access your account, email us at [email protected] and we will help you. You can also submit a data subject access request.

When you delete your account in the app, we delete your account, profile, uploaded photos, posts, comments, RSVPs, society memberships and your direct (1-to-1) messages straight away, and you are signed out. Messages you sent in group chats are kept so the conversation stays intact for other members, but they are anonymised: your name and profile are removed and they are shown as "Deleted user". If a message you sent was reported, the copy kept with the report is anonymised in the same way and deleted 3 years after the report is closed. Reports you submitted are kept for moderation with your identity removed. We may retain limited information where necessary to prevent fraud, resolve disputes, comply with legal obligations (including keeping material reported as child sexual abuse or exploitation, and the identities of the people who posted and reported it, available to the National Crime Agency, as described in section 8), or enforce our terms.

16How can you complain?

In short: You can complain to us using our online form or by email, and we'll acknowledge your complaint within 30 days.

If you're unhappy with how Geniva has used or looked after your personal data, you can complain to us directly using our complaints form at geniva.co.uk/privacy/complaints or by emailing [email protected]. We'll acknowledge your complaint within 30 days, look into it without undue delay, keep you updated, and let you know the outcome. You can also complain to the Information Commissioner's Office (ico.org.uk).

We keep your complaint, our messages to and from you about it, and our record of how we handled it for 3 years after we close the complaint, and then delete them. This applies even if you delete your Geniva account in the meantime.