Clara’s
Privacy notice
Last updated: 4 October 2026.
1. Who is responsible
Clara’s is a private, non-commercial members’ club for Düsseldorf, run by its founders, who are the controller for your data. Contact: hello@claras.club.
2. Your application
What: your full legal name, email, phone number, age bracket, where you live, how long you have lived here, how much English you speak, a link to one of your profiles (TikTok, Instagram, LinkedIn, anything), where you’re from (or that you’d rather not say), why you want to join, whether you’d be open to meeting a founder before your first evening, whether you’d help build Clara’s (optional), your answers about yourself, what you enjoy, which evenings you would come to, what you think makes a good group and a good evening, and, if you answer it after applying, what you find hardest about meeting people here. Only some of the founders see your legal name, phone number and profile link; at evenings, people only know your first name.
Why: to consider you for founding membership, plan the first evenings and decide who would get on together, and, using everyone’s answers together, to tell the list which evenings are most wanted (never anything that identifies you). Your answer about what you find hardest is never quoted on its own or shown to other members. Your phone number is so the host can reach you on the day of an evening. Your profile link is so the founders can see who is applying; we only look at what you’ve made public there and never copy anything from it. Where you’re from, why you want to join and whether you’d meet a founder first help the founders plan the club and say hello before someone’s first evening; whether you’d help build Clara’s only tells them who to ask, and is never a condition of joining.
Saved as you go. When you press “Continue” after the first page of the form, we save what you’ve given so far (name, email, phone, age bracket, where you live, how long you’ve lived here, English and profile link), so nothing is lost if you stop. Nothing is saved before you press it. Until you finish and submit, it is marked unfinished: only the founders see it, we never email you about it, and it is deleted after 30 days. Legal basis: taking the steps you asked for before membership (Art. 6(1)(b) GDPR).
Each application gets a short code for its share link. If you apply through a friend’s link, we note whose link it was, so we can see how people hear about Clara’s and seat friends sensibly at a first evening. We never tell either of you anything about the other’s application, and links never affect who is invited. Legal basis: our legitimate interest in setting good tables and knowing how people find us (Art. 6(1)(f) GDPR). The note is deleted with either application.
Our emails to the founding list include a private link where you can see and change your answers, or remove yourself. Removing yourself deletes your application straight away.
Legal basis: to consider your application and, if you join, to run your membership, at your request (Art. 6(1)(b) GDPR). Emailing you about Clara’s is based on your consent (Art. 6(1)(a) GDPR), which you give by ticking the one box on the form (it also covers agreeing to the code of conduct and this notice) and confirm by clicking the link in our confirmation email. You can withdraw it at any time, which does not affect anything done before.
You don’t have to apply. If you do, we need the answers the form marks as required to consider you. Your profile link is only used to check you are a real person and to recognise you at an evening; we never collect anything else from your profile. Please leave anything sensitive, such as health information, out of your free-text answers.
You need to be 18 or over to apply. If you choose “Thirty or over”, the form stops and nothing is sent or stored. Your answer about English never stops anyone applying.
3. Proof of consent and the confirmation email
When you apply we store the date and time, your IP address and which version of the consent wording you agreed to, and we send one email asking you to confirm your address. We record when you confirm. We send no other email until you have confirmed. Applying again with the same address changes nothing and sends at most one more confirmation email a day. Straight after applying you can also ask for it to be sent again, up to three times. Once you’ve confirmed, we write only when there is news about the founding list, at most twice a month, and record when we last wrote to you so we keep to that. Legal basis: Art. 6(1)(c) and (f) with Art. 7(1) GDPR (we must be able to show you agreed). Emails are sent through Resend, from its servers in Ireland (section 8).
4. If you become a member
If the founders invite you, we create a membership from your application and ask for your last name and mobile number, whether the host may message you on WhatsApp, and your agreement to the code of conduct. We store which evenings you take a seat at or wait for, and when you last signed in. For seated evenings the founders offer seats themselves: if they hold a seat for you, we store when the hold ends and whether you took it. Seat offers you turn down, or don’t answer, never count against you.
After each evening the founders note whether you came. Two missed evenings without notice can cost you your seat under the code of conduct; a founder always decides this, never software. The founders also mark each application yes, maybe or no and can add short notes, and they can pause a membership if the code of conduct is broken. While it is paused, you cannot sign in or take seats.
Why: so the host can find you and reach you on the day, so seats and waiting lists work, and so we can send you the address of evenings you have a seat at. Only the people who run Clara’s see your contact details; other members never do. If you allow WhatsApp, the host’s messages go through WhatsApp (Meta), under WhatsApp’s own terms.
The founders may write a short line about you, drawn from your application, to help the host introduce you on the night. Only the people who run Clara’s see it, and it isn’t on the downloadable guest list. If you come to an evening without a seat, we note that you were added on the night.
Tables. For seated evenings the founders place members at tables by hand, using their application answers and the evenings they have come to. Before an evening, you see which table you are at and a short note the founders may write about the table as a whole, never about one person. After an evening, the people who came and sat at your table (or, at an evening without tables, everyone who came) see your first name and the initial of your last name on that evening’s page, and you see theirs. If you host a table, the people at it see the name the founders give for the host (usually your first name) before the evening and in their reminder emails. Nobody at your table sees your answers or contact details. The founders may also note that two members should be kept apart, for example after a report; that is based on our legitimate interest in keeping evenings safe (Art. 6(1)(f) GDPR). If you ask what data we hold about you, we leave out who asked not to sit with you, to protect them (Art. 15(4) GDPR and § 29(1) BDSG).
After an evening we ask how it went, who you’d happily sit with again, and whether there is anyone you’d rather not sit with again. Only the founders see your answers, and they use them only to set future tables. Nobody is told who picked them, or who asked not to sit with them. Notes about something that made you uncomfortable are handled as reports (section 10). The email asking these questions is based on the consent you gave when you applied (emails about new evenings and how they went); you can still answer on the evening’s page if you have switched those emails off.
Legal basis: running your membership (Art. 6(1)(b) GDPR). Emails about new evenings are based on your consent, and you can switch them off in your profile or with the link in each one. Emails about seats you take yourself, and seat offers the founders send you personally for seated evenings (including one reminder before the hold ends and a note if it lapses), are part of the membership (Art. 6(1)(b) GDPR).
Signing in works with a one-time link we email you. Signing in sets one cookie, claras_session, which only says you are signed in; it is strictly necessary and needs no consent (§ 25(2) Nr. 2 TDDDG).
5. Which ad brought you here
If you arrive from one of our ads, the link carries a short campaign tag (for example utm_source=tiktok). We keep it in the page’s memory for your visit, without writing anything to your device, and store it with your application so we can see which ads work. Legal basis: our legitimate interest in knowing which ads are worth running (Art. 6(1)(f) GDPR).
6. Visit counts
We count a few steps: viewing the home page, arriving through a friend’s link, starting the application, reaching step two, submitting, answering the optional question, asking for the confirmation email again, confirming your email, and pressing a share button. Each count stores only the step, the campaign tag if there is one, and the time. We store no IP address or device information with it and set no cookie. Legal basis: our legitimate interest in knowing whether the site works (Art. 6(1)(f) GDPR).
7. TikTok Pixel (only if you click “Accept”)
If you accept in the cookie banner, we load the TikTok Pixel from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. It sets cookies and sends TikTok information about your visit (pages viewed, that you submitted an application, your IP address and browser details) so we can measure our ads and show them to similar people. TikTok also uses this data for its own purposes. The pixel does not send your name, email address, phone number or answers to TikTok: we never pass them to it, and automatic advanced matching is switched off.
For collecting and sending this data, we and TikTok are joint controllers (Art. 26 GDPR), under TikTok’s terms for business products, including its joint controller terms (ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms): TikTok handles requests about the data it holds, but you can contact either of us and we will pass yours on. TikTok alone is responsible for what it does afterwards (see TikTok’s privacy policy). We only receive aggregate ad reports and cannot see who you are. TikTok may process data outside the EU, including in countries without an EU adequacy decision, under the EU’s standard contractual clauses.
Legal basis: your consent (§ 25(1) TDDDG and Art. 6(1)(a) GDPR). If you click “Reject”, or do nothing, the pixel never loads. You can change your choice at any time on the cookie policy page, linked in the footer.
8. Hosting and where your data is kept
The website runs on Cloudflare Workers and the database on Cloudflare D1, both provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) under its data processing agreement (Art. 28 GDPR). The database is set to keep your data in the EU. Pages are delivered from Cloudflare’s data centres, normally the one nearest you; Cloudflare is certified under the EU-U.S. Data Privacy Framework for anything that leaves the EU. No other company receives your application. Cloudflare processes technical data (IP address, time, page) to deliver the site and protect it from attacks, and our own error logs are kept for at most 7 days. Legal basis: Art. 6(1)(f) GDPR. Fonts are served from our own site, not from Google.
Our emails are sent by Resend, Inc. (USA) from its servers in Ireland, under its data processing agreement, which includes the EU’s standard contractual clauses; Resend also takes part in the EU-U.S. Data Privacy Framework. Resend receives your email address and the email itself, and nothing else. We don’t track whether you open our emails or click their links. We keep a record of each email we send you (your address, which email, its subject and whether it was delivered) for 12 months, to show what we sent and to sort out delivery problems (Art. 6(1)(f) GDPR).
Cloudflare keeps a restore history of the database for 7 days, so anything we delete is also gone from it within 7 days.
9. Who sees your data
Only the people who run Clara’s read applications and see members’ contact details, and anyone who does is bound to keep them confidential. Your answers and contact details are never shown to other members and never sold; the people at your table see only what section 4 describes. For each evening the founders can download a guest list (names, phone numbers, profile links and whether WhatsApp is allowed) to have with them on the night, and delete it once the evening is over. Beyond Cloudflare (hosting), Resend (email), WhatsApp (only for members who allow it) and (with your consent) TikTok, nobody receives your data.
Venues we work with. If you run or work at a venue we book, we keep your name, work phone number and our booking notes to arrange evenings (Art. 6(1)(f) GDPR), and delete them 12 months after the evening they were for.
On the night, the founders may use a separate club phone number (on WhatsApp, if you message it there) so you can reach them if you’re late or can’t find the table. Messages to it are used only to help you on the night (Art. 6(1)(b) GDPR) and deleted within 30 days.
10. Emails and reports you send us
Emails you send us are used to reply and deal with the matter (Art. 6(1)(f) GDPR) and deleted 12 months after it is closed. Reports you send through the members’ area or by email are read only by the founders and used to deal with the matter and keep evenings safe (Art. 6(1)(f) GDPR). Where a report includes sensitive details about you, such as health or sexual matters, we rely on your explicit consent (Art. 9(2)(a) GDPR), which you give in the form or by confirming it when we reply to an emailed report. Sensitive details about anyone else in a report are used only as far as needed to deal with the matter and to establish, exercise or defend legal claims (Art. 9(2)(f) GDPR). If a report is about you, we will tell you what was raised unless that would put the person who reported it at risk. Reports are deleted 12 months after they are closed, unless we need them for a legal claim.
11. How long we keep it
Unfinished applications (you pressed “Continue” but never submitted): deleted after 30 days. Applications you never confirm: deleted after 30 days. Applications we turn down: deleted 6 months after the decision. Applications held for later tables: 12 months after we tell you, unless you join before then. Members who leave: deleted 30 days after leaving (your phone number straight away). These periods cover everything in your application, including your phone number, profile link, where you’re from, why you want to join, whether you’d meet a founder first and whether you’d help build Clara’s. Sign-in links: 7 days. Seats, waiting-list places, seat offers, tables, whether you came and your answers after an evening: 12 months after the evening. A note to keep two members apart at one evening: 12 months after that evening. A lasting one: until either member leaves. Our record of emails sent: 12 months. If an address bounces or reports our emails as spam, we stop writing to it and keep a scrambled code of it for 12 months so we don’t start again; the application or membership itself follows the periods above (Art. 6(1)(f) GDPR). If someone is removed for breaking the code of conduct, we keep a scrambled code of their email address for two years so they can’t simply apply again (Art. 6(1)(f) GDPR). Everything else: deleted within a month of your request, or 12 months after 30 September 2027 if no evening has taken place. If you unsubscribe, we stop emailing you; your application stays on the list unless you ask us to delete it. Your cookie choice: until you change it or clear your browser.
12. Your rights
You can ask for access to, correction of, deletion of, restriction of or a copy of your data, and withdraw consent at any time, by emailing hello@claras.club. Every email we send about Clara’s news has an unsubscribe link, and you can always reply “stop”. You can also complain to a data protection authority, for example the Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (ldi.nrw.de).
Your right to object (Art. 21 GDPR). Where we rely on our legitimate interests (campaign tags, visit counts, server logs, our record of emails sent, emails you send us, the record of removed members, keeping people apart after a report), you can object at any time by emailing hello@claras.club.
13. No automated decisions
The founders read every application themselves. Nothing about you is decided by software alone. The admin sorts applications by your answers (for example, which evenings you’d come to and how much English you speak) to make reading them quicker, but a founder chooses every invitation.
14. Changes
If this notice changes in a way that matters, we will email everyone on the founding list.