Legal
Privacy Policy
This policy explains what personal data DanceFinder holds, why we hold it, who else can see it, how long we keep it, and what you can ask us to do about it.
Last updated 7 September 2026.
1. Who is responsible for your data
DanceFinder is operated by Finders OÜ, a company registered in Estonia. We are the data controller for the personal data described in this policy.
- Legal name
- Finders OÜ
- Registry code
- 17493573
- Registered address
- Tartu mnt 16b-17, 10117 Tallinn, Estonia
- Data protection requests
- info@dancefinder.eu
We have not appointed a data protection officer, because the scale and nature of our processing does not require one under GDPR Art. 37.
2. Who this policy is about
DanceFinder holds personal data about two groups of people, and the same rules do not apply to both.
People who use DanceFinder. If you create an account, you give us your data yourself. Section 3 is about you.
People named in events we collect. Part of our calendar is built from public posts and event listings on Facebook. If your name appears in one of those listings as the organizer or teacher, we hold data about you that you never gave us. Section 4 is about you, and it includes how to have the listing removed.
3. If you have a DanceFinder account
What we collect
- Your email address, and your display name if you set one.
- Your sign-in credentials, handled by Supabase Auth. Passwords are stored as hashes by Supabase. We never see or store the password itself.
- If you sign in with Google, the email address and account identifier Google returns to us. We receive nothing else from your Google account.
- The preferences you set: favourite dance styles, favourite schools, favourite weekdays, and which emails you want to receive.
- What you do in the product: the classes you register for, the waitlists you join, and any correction request you send us about a class or school.
- A record of the emails we sent you, kept so the same alert is not sent twice.
- Your IP address, used briefly to rate limit sign-in and write requests. It is held in server memory only and is never written to our database.
Why we are allowed to
- To provide the service you asked for, GDPR Art. 6(1)(b). Your account, your registrations and your waitlist entries exist because you asked us to create them.
- Our legitimate interest, GDPR Art. 6(1)(f). Keeping the service secure, rate limiting requests, preventing abuse, and sending you reminders and alerts about the classes and schools you chose to follow. You can turn every one of those emails off at any time, and each message carries a one-click unsubscribe link.
- Your consent, GDPR Art. 6(1)(a). Anything optional we store in your browser beyond what is needed to sign you in. Today we use no analytics or advertising cookies at all. If that changes, we will ask before loading them, and you can withdraw at any time through the Cookie settings link in the footer.
- Legal obligation, GDPR Art. 6(1)(c). Where we have to keep or disclose something to comply with Estonian or European law.
What we never do
We do not sell your personal data. We do not share it with advertisers. We do not build a profile of you beyond the preferences you set yourself, and we make no automated decision that produces a legal effect for you.
4. If your name appears in an event we collected
DanceFinder collects public posts and event listings from Facebook groups and pages about dance in the Nordic and Baltic countries, so the calendar shows what is actually happening. This section is the notice required by GDPR Art. 14, which applies because the data did not come from you.
Where the data comes from and what we keep
The source is always a post, page event listing or event page that was publicly visible on Facebook. We keep the facts needed to describe the event: its title, date and time, venue, price, and the organizer name where the listing states one.
We record the address of the announcement so that we can act on a removal request and keep the listing from being collected again, but we do not publish it and we do not link readers to it. We do not copy the flyer image either.
We deliberately do not copy the identity of the person who posted. Our collection step discards the author fields before anything is stored. The only name that can reach our records is one written into the listing itself as the organizer or teacher of the event.
Why we are allowed to
We rely on our legitimate interest under GDPR Art. 6(1)(f): maintaining a complete public calendar of dance events in the Nordic and Baltic countries. We have weighed that against your interests. The data was already published by you or on your behalf in a public group or page, it relates to your public activity as an organizer rather than to your private life, we hold no special category data, and we add no contact details that were not in the listing.
We publish the facts of the event and name you as its organizer. We keep only what describes the event: not your flyer, not your account, and not the words you wrote, which are yours. You can object at any time using the route below, and we act on it.
Why you did not hear from us directly
GDPR Art. 14(5)(b) removes the duty to notify each person individually where that would take disproportionate effort. Events reach us in bulk from public groups, often with no contact address at all, and writing to the organizer of every listing is not something we can do. Publishing this notice, linking it from every page, and naming a removal route that works within days is what we do instead.
How to have a listing corrected or removed
Write to info@dancefinder.eu with a link to the listing. You do not have to explain why. We remove or correct it, and we also record the original source so the same post is not collected again on the next scan. Without that second step the listing would come back, so removal on request means removal for good.
5. Who else processes your data
We use a small number of service providers. Each one acts on our instructions under a data processing agreement, and none of them may use your data for their own purposes.
| Provider | What they do | What personal data they see |
|---|---|---|
| SupabaseUnited States, with the database hosted in the region set for our project | Database and user authentication | All account data, including your email address, sign-in credentials, registrations, waitlist entries and email preferences |
| VercelUnited States | Application hosting and delivery | Anything sent to the website while you use it, including your IP address in short-lived server logs |
| ResendUnited States | Sending the emails you have asked for | Your email address and the content of the message being sent to you |
| ZohoEuropean Union, in Zoho's European data centre | Hosting the mailbox you write to when you contact us | Your email address and whatever you write to us, which for a removal or a data protection request includes the details of the request itself |
| GoogleIreland, for users in the European Economic Area | Sign in with Google, used only if you choose it | The email address and account identifier Google returns when you sign in. We receive this from Google; we do not send Google your activity on DanceFinder |
| ApifyCzech Republic | Collecting public posts and event listings from Facebook groups and pages we monitor | Nothing about you as a user. Apify receives the address of a public group, page or event and returns what is published there, which can include an organizer name |
| AnthropicUnited States | Reading a collected public post with Claude to work out the date, place and type of the event it describes | Nothing about you as a user. Only the text and image address of the collected public post are sent |
| OpenStreetMapUnited Kingdom, with tile servers in Europe | Showing the map of an event venue or a school | Your IP address and browser details, because the map is loaded by your browser directly from OpenStreetMap. We send them nothing about you, and no map loads until you open a page that shows one |
| GitHubUnited States | Running our scheduled jobs on GitHub Actions, which call our own endpoints on a timetable | None. GitHub triggers the jobs and never receives the records they work on |
Some of these providers are established outside the European Economic Area. Where personal data is transferred to them, the transfer relies on the safeguards set out in that provider data processing agreement, such as the standard contractual clauses approved by the European Commission or the EU-US Data Privacy Framework.
We may also disclose data where the law requires it, for example to a court or a supervisory authority.
6. How long we keep things
| Record | How long |
|---|---|
| Your account, profile and email preferences | Until you delete your account. Deletion is immediate and cannot be undone. |
| Registrations, waitlist entries and correction requests you send | Deleted together with your account. While the account exists, they are kept for as long as the class they belong to is listed. |
| Records of emails we sent you | Deleted together with your account. They exist so the same alert is not sent to you twice. |
| Email you send us, and our reply | Kept for as long as it takes to answer, and for up to twelve months afterwards so we can show what was asked and what we did about it. Ask us and we delete the exchange sooner. |
| Events collected from public sources, and the source records behind them | Kept while the event is listed and for up to twelve months after it has taken place. Removal on request is immediate; the twelve month clear-out is currently carried out during review rather than by an automatic job. |
| IP addresses used to rate limit sign-in and write requests | Held in server memory for the length of the rate limit window, which is under a minute, and never written to the database. |
| How many times a class page was opened | Kept indefinitely as a counter. No user identifier, IP address or other personal data is recorded with it. |
7. Cookies and what we store in your browser
We use cookies that are strictly necessary to sign you in and keep you signed in. These are set by Supabase Auth and the service cannot work without them, so they do not require consent.
We store your answer to the cookie banner in your browser local storage, so we do not have to ask again. That answer never leaves your device.
We use no analytics, advertising or tracking cookies today. You can change or withdraw your answer at any time using the Cookie settings link in the footer, which is as easy as giving it in the first place.
8. How we protect your data
Access to the database is restricted by PostgreSQL row level security, so a signed-in user can only read the rows they are entitled to read. Our server routes check the session and ownership again independently, rather than relying on those policies alone.
The site is served over HTTPS with strict transport security, a content security policy, and clickjacking protection. Administrative access is limited to a fixed list of addresses. Secret keys are held as server-side environment variables, are never sent to the browser, and are never written to our logs.
No service can promise perfect security. If a breach ever puts your rights at risk, we will report it to the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) within 72 hours and tell you directly where GDPR Art. 34 requires it.
9. Automated processing and artificial intelligence
We use Claude, an AI model from Anthropic, to read collected public posts and work out what event each one describes. It is used only on that public content. It is never used on your account data, and it makes no decision about you.
The model proposes an event, and a person reviews it before it is published, unless the listing is complete and unambiguous enough to meet our rules for publishing without review. Either way, no automated decision produces a legal effect or a similarly significant effect on anyone, so GDPR Art. 22 does not apply.
10. Your rights
Under GDPR you can ask us to:
- give you a copy of the personal data we hold about you, Art. 15;
- correct anything that is wrong, Art. 16;
- delete it, Art. 17;
- restrict how we use it while a question is being resolved, Art. 18;
- send it to you or another provider in a machine readable format, Art. 20;
- object to processing we base on our legitimate interest, Art. 21, including everything described in section 4;
- withdraw consent you gave, Art. 7(3), without affecting what happened before you withdrew it.
You can delete your account yourself at any time from your account settings. That removes your account record and everything that depends on it.
For anything else, write to info@dancefinder.eu. We answer within one month, as GDPR Art. 12 requires, and we do not charge for it.
If you are not satisfied with our answer, you can complain to the Estonian supervisory authority, Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate): https://www.aki.ee/en/contact
11. Children
DanceFinder is not aimed at children. GDPR Art. 8 sets 16 as the age at which a person can agree to an online service on their own behalf, and lets each country lower it to no less than 13. Estonia has lowered it to 13, and the other countries we list events from have each made their own choice, so the age that applies to you is the one set where you live.
If you believe a child below that age has created an account, write to us and we will delete it.
12. Changes to this policy
If we change how we handle personal data, we update this page and the date shown at the top. Where a change materially affects something you agreed to, we ask you again rather than assuming your earlier answer still stands.