Privacy Statement
You gotta do whatcha gotta do whatcha gotta do.
1. General information and principles of data processing
We are pleased that you visit our website.
The protection of your privacy and the protection of your personal data, the so-called personal data, when using our website is an important concern for us.
According to Art. 4 No. 1 GDPR, personal data is all information relating to an identified or identifiable natural person. This includes information such as your first and last name, your address, your telephone number, your e-mail address, but also your IP address.
Data which cannot be linked to your person, such as through anonymization, is not personal data. Processing (e.g., collection, storage, readout, retrieval, use, transmission, deletion or destruction) in accordance with Art. 4 No. 2 of the GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of the processing has been achieved and there is no longer any legally prescribed obligation to retain data.
Here you will find information on how we handle your personal data when you visit our website. In order to provide the functions and services of our website it is necessary for us to collect personal data about you.
We also explain the type and scope of the respective data processing, the purpose and the corresponding legal basis and the respective storage period.
This privacy policy applies only to this website. It does not apply to other websites to which we merely refer by hyperlink. We cannot assume any responsibility for the confidential handling of your personal data on these third-party websites, as we have no influence on whether these companies comply with the data protection regulations. You can find out more about how these companies handle your personal data directly on these websites.
Below you will find the contact details of the responsible office.
2. Responsible authority
Responsible for the processing of personal data on this website is (see legal notice / imprint):
Hanso Pte. Ltd.
1 Phillip Street
#09-00 Royal One Phillip
Singapore 048692
3. Use of the website / server log files
a) The nature and extent of the data processing
If you use this website without transmitting data to us in any other way (e.g., by registering or using the contact form), we collect technically necessary data via server log files, which are automatically transmitted to our server, including
- IP address
- Data and time of the request
- Name and URL of the retrieved file
- Website from which the access takes place (Referrer URL)
- Access status/HTTP-status code
- Browser type
- Language and version of the browser software
- Operating system
b) Purpose and legal basis
This processing is technically necessary to display our website. We also use the data to ensure the security and stability of our website.
The legal basis for this processing is Art. 6 (1) (f) GDPR. The processing of the aforementioned data is necessary for the provision of a website and thus serves to protect a legitimate interest of our company.
c) Storage period
As soon as the personal data is no longer required to display the website, it will be deleted. The collection of the data for the provision of the website and the storage of the data in log files is mandatory for the operation of the website. There is therefore no possibility for the user to object to this aspect. A further storage can take place in individual cases, if this is legally required.
4. Use of Cookies
a) The nature and extent of the data processing
We use cookies. Cookies are small files that are sent by us to the browser of your terminal device when you visit our website and stored there.
Some functions of our website cannot be offered without the use of technically necessary cookies. Other cookies, on the other hand, enable us to perform various analyses. For example, some cookies can recognize the browser you are using when you visit our website again and transmit various information to us. We use cookies to facilitate and improve the use of our website. For example, cookies enable us to make our website more user-friendly and effective for you, for example by tracking your use of our website and determining your preferred settings (e.g., country and language settings). If third parties process information via cookies, they collect the information directly via your browser. However, cookies do not cause any damage to your end device. They cannot execute programs and cannot contain viruses. Various types of cookies are used on our website, the type and function of which are explained below.
Temporary cookies/Session cookies
Our website uses so-called temporary cookies or session cookies, which are automatically deleted when you close your browser. Through this type of cookies, it is possible to record your session ID. This allows various requests from your browser to be assigned to a common session and makes it possible to recognize your terminal device during subsequent visits to the website.
Permanent cookies
So-called permanent cookies are used on our website. Permanent cookies are cookies that are stored in your browser over a longer period of time and can transmit information. The respective storage period varies depending on the cookie. You can delete permanent cookies independently via your browser settings.
Third party cookies
We use analytical cookies to monitor anonymous user behavior on our website.
We also use advertising cookies. These cookies allow us to track user behavior for advertising and targeted marketing purposes.
Social media cookies allow us to connect to your social networks and share content from our website within your networks.
Configuration of the browser settings
Most web browsers are preset to automatically accept cookies. However, you can configure your browser so that it only accepts certain cookies or none at all. We would like to point out, however, that you may then no longer be able to use all the functions of our website.
You can also use your browser settings to delete cookies already stored in your browser. Furthermore, it is possible to set your browser to notify you before cookies are stored. Since the various browsers may differ in their respective functions, we ask you to use the respective help menu of your browser for the corresponding configuration options.
Disabling the use of cookies may require a permanent cookie to be stored on your computer. If you delete this cookie afterwards, you will have to deactivate it again.
b) Legal basis
Because of the purposes described, the legal basis for the processing of personal data using cookies is Art. 6 (1) (f) GDPR. Only those cookies that are technically absolutely necessary to enable you to use the website can be based on this.
If you have given us your consent to the use of cookies based on a notice ("cookie banner") provided by us on the website, the legal basis is additionally Art. 6 (1) (a) GDPR. This is necessary for cookies that enable us to analyze your usage behavior and to place appropriate advertising.
c) Storage period
As soon as the data transmitted to us via cookies is no longer required for the purposes described above, this information is deleted. Further storage may be carried out in individual cases if this is required by law.
5. Data collection for the implementation of pre-contractual measures and for the fulfilment of the contract
a) The nature and extent of the data processing
We do not collect any personal data from the users of our website in the form of registration or in any other way. However, if a user of the website contacts us via the contact options to initiate a contract or for other reasons in order to find out more about our services, the data specified in the contact will be processed by us.
b) Purpose and legal basis
We collect and process this data exclusively for the purpose of executing the contract or fulfilling pre-contractual obligations.
c) Storage period
The data will be deleted as soon as they are no longer necessary for the purpose of their processing.
In addition, there may be statutory retention obligations, for example, commercial or tax retention obligations. Insofar as such obligations to retain data exist, we will block or delete your data at the end of these retention obligations.
6. Newsletter
a) The nature and extent of the data processing
When registering for the newsletter, the following data is collected:
- the page from which the page was requested (so-called referrer URL)
- the date and time of the call
- the description of the type of web browser used
- the IP address of the requesting computer, which is shortened in such a way that a personal reference can no longer be established
- the e-mail-address
- the date and time of registration and confirmation
b) Purpose and legal basis
The purpose of the data processing is to send you a newsletter to inform you about actions and offers of our company.
The legal basis for this is Art. 6 (1) (a) GDPR. The so-called double opt-in procedure is used. This means that after registering, you send a separate e-mail to the e-mail address you have provided us with. This will request confirmation that you wish to receive the newsletter. In this way, your registration can be verified, and any possible misuse of your personal data can be clarified. You can revoke your consent to receive the newsletter at any time. This can be done either via the link provided in all newsletter mails, as an e-mail to info@hanso.group or by sending another message to the contact data provided in the imprint.
c) Storage period
The data will be deleted as soon as they are no longer required for the purpose of processing or you have revoked your consent. In addition, there may be legal storage obligations, for example, commercial or tax storage obligations. Insofar as such obligations to retain data exist, we will block or delete your data at the end of these retention obligations.
7. Data transmission
We only pass on your personal data to third parties if:
- You have given the express consent to do so under Article 6 (1) (a) of the GDPR
- This is permitted by law and, pursuant to Art. 6 (1) (b) GDPR, is necessary for the performance of a contractual relationship with you or the implementation of pre-contractual measures.
- According to Art. 6 (1) (c) GDPR, there is a legal obligation for the disclosure.
- We are legally obliged to transfer data to state authorities, e.g. tax authorities, social security institutions, health insurance companies, supervisory authorities and law enforcement agencies.
- The transfer of data pursuant to Art. 6 (1) (f) GDPR is necessary to safeguard legitimate company interests and to assert, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data.
- In accordance with Art. 28 GDPR, we use external service providers, so-called contract processors, who are obliged to handle your data with care.
We may use such service providers in the following areas:
- IT, logistics, telecommunications, newsletter dispatch, invoicing
When transferring data to external parties in third countries, i.e., outside the EU/EEA, we ensure that these parties treat your personal data with the same care as they would within the EU/EEA. We only transfer personal data to third countries where the EU Commission has confirmed an adequate level of protection or where we ensure the careful handling of personal data through contractual agreements or other appropriate guarantees.
We only transfer your data to the USA if the requirements of the European Court of Justice ruling from 16.07.2020 - C-311/18 - are observed. If you have given us your consent, we will also transfer data to companies located in the USA.
8. Tracking, analysis and other tools
Google Analytics:
Analysis tool; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA;
With the help of Google Analytics, it is possible for the provider to track the behavior of users on the website and, based on this, to revise and adapt its own presentation of the offers. This is a legitimate interest within the meaning of Art. 6 (1) (f) GDPR.
Website: https://analytics.google.com/
Privacy policy: https://policies.google.com/privacy
Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Right of Appeal (Opt-Out): https://tools.google.com/dlpage/gaoptout?hl=de
For the setting for advertising, see: https://adssettings.google.com/authenticated
Facebook:
Social Network; Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA;
Website: https://www.facebook.com
Privacy policy: https://www.facebook.com/about/privacy
Privacy Shield: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC
Right of Appeal: https://www.facebook.com/settings?tab=ads
Instagram:
Social network; Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA;
Website: https://www.instagram.com
Privacy policy: http://instagram.com/about/legal/privacy
These listed three (social media) platforms serve the appropriate and user-friendly online presentation of the company. This is a legitimate interest within the meaning of Art. 6 (1) (f) GDPR.
WhatsApp:
Messenger-service; WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland;
Website: https://www.whatsapp.com
Privacy policy: https://www.whatsapp.com/privacy
WhatsApp is used by the company to enable a contact option for interested parties and to ensure an uncomplicated initiation of a contract. On the one hand, this is possible according to Art. 6 (1) (b) GDPR. In addition, the uncomplicated accessibility of the company serves a legitimate interest according to Art. 6 (1) (f) GDPR.
9. Rights of data subjects
Since we collect and process data from you, you have certain rights as a data subject of a data processing:
- The right to information from us. Should you exercise this right, we will inform you which of your personal data we have processed.
- Right to correction or deletion
- Right to limit processing
- Right to object to the processing
- Right to data transferability
- Right to withdraw your consent
- Right of appeal to a supervisory authority
- Right to object to the processing
- Art. 21 GDPR allows you to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) (e) or (f) GDPR.
-
Your right of revocation:
You can revoke your consent to process your personal data at any time with effect for the future.
You can declare the revocation by e-mail to info@hanso.group or by sending a message to the contact details listed at the beginning of this document.
10. The Kampong mobile app
Everything above concerns the website. This section covers the Kampong iOS app, which collects some things the website does not. The app collects nothing for advertising, and we do not track you across other companies' apps or websites.
a) Account and profile
The app uses the same account as the website: your name, e-mail address, the information you gave in your membership application, and anything you later add to your profile — biography, home base, social handles and a profile photo. Photos you choose are uploaded to our own storage. The app asks for access to your photo library only at the moment you pick one.
b) Location
If you allow it, the app shares your approximate location so other members can see who is nearby and so we can tell you about events near you. It is coarse, not precise. It may update in the background every few hours while the permission is granted, and only then. You can refuse this permission or withdraw it at any time in iOS Settings or in the app, and the rest of the app continues to work. Your travel timeline — the places you tell us you are going — is something you enter yourself, not something we measure.
c) Push notifications
If you allow notifications, Apple issues a device token which we store so we can send you messages about your events, bookings and the community. The token identifies the installation, not you personally, and we delete it when you sign out, delete the app's account, or turn notifications off. Notification content is sent through Apple's Push Notification service.
d) Payments
Payments for event tickets and stays are processed by Stripe Payments Europe, Ltd. and its affiliates. Payment happens in a Stripe-hosted checkout page — card details are never entered into, seen by, or stored by the Kampong app or our servers. We keep a record of what was paid, for what, and when, because we are required to. Stripe processes billing address and, where applicable, tax identification data in order to calculate tax. Stripe's own privacy policy applies to what it collects: stripe.com/privacy.
e) Sign-in
Authentication is handled by our own identity service at login.kampong.social. Access and refresh tokens are stored in the iOS Keychain on your device, restricted to that device and readable only while it is unlocked. They are not synced to iCloud, and they are cleared when you sign out or delete the app.
One account covers several services. The same identity signs you in to your Kampong mailbox, your chat account and your social account, so you do not keep separate passwords for them. What this means for your data is that those services are told who you are — your username, your display name and your e-mail address — when you first sign in to each of them. They are all operated by us, on our own infrastructure. It also means the reverse: suspending or deleting your Kampong identity closes those services too.
f) Communication services
Approved members may be given an e-mail mailbox, a chat account and a social account on services we operate ourselves. Concretely these are Stalwart for mail (which you read through our webmail at webmail.kampong.social), Matrix for chat (our own homeserver, reachable with any Matrix client such as Element), and Mastodon for social posts. The contents of your mailbox, your messages and your posts are held on our own infrastructure and are not read by us in the ordinary course of running the service.
Matrix and Mastodon are federated networks. That is the point of them, and it has a consequence worth stating plainly: if you send a message to somebody on another homeserver, or post publicly on Mastodon, that content leaves our infrastructure and reaches theirs. We cannot recall it and this policy does not govern what they then do with it. Messages between members on our own homeserver stay on it.
You may instead give us your own e-mail address, chat identifier or social handle. If you do, we confirm that you control it before sending anything to it, and from then on notifications go there. Anything you send to a service outside ours is governed by that provider's privacy policy, not this one.
g) Diagnostics
The app sends us no diagnostics at all. It contains no analytics or crash-reporting software, and no third-party SDK of any kind — the only servers it talks to are ours, our image storage, and Stripe's payment page when you choose to pay. If you have opted in to sharing analytics with Apple, Apple may share crash reports with us through App Store Connect; that is Apple's mechanism, governed by your device settings, and it is not something this app collects or transmits.
h) Deleting your account
You can delete your account from the Profile tab in the app, or from your account settings on the web. Deletion removes your profile, your content and the communication accounts created for you. Records we are legally required to retain — principally transaction records — are kept for the period the law requires and for no other purpose.
Website sections: 17.03.2021 · App section: 22.08.2026