Privacy Policy
Last updated: 16 September 2026
§ 1 Introduction
Gnosis Service GmbH, Glogauer Straße 6, 10999 Berlin, Germany (“Gnosis”, “we”, “us”, “our”) operates the Lokal App, a service that enables eligible users to discover and redeem offers from participating local merchants in a designated Berlin neighbourhood (“Kiez”) using a points-based system, as part of a limited pilot programme (the “Pilot”). The Lokal App is currently available as a web application at https://app.lkl.berlin/, as a mobile application for Android distributed via Google Play, and as a mobile application for iOS distributed via the Apple App Store (each a “Channel”). We may add or withdraw Channels at any time on reasonable notice.
This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Lokal App. It supplements our Terms of Participation.
Gnosis is the data controller within the meaning of Art. 4(7) GDPR for all processing described in this Privacy Policy.
For questions about this Privacy Policy or to exercise your data subject rights, contact us at: hello@lkl.berlin
§ 2 Information we collect
2.1 Account Data
When you access the Lokal App, a local account is automatically generated. You do not create a username or password; your access credentials are stored locally on your device (in your browser’s local storage on the web app, or in the operating system’s secure keystore on the mobile apps). Clearing your browser data or uninstalling a mobile app will destroy these credentials, and your account will be permanently inaccessible unless you have activated email-based account recovery. During registration you are required to provide an email address through our Authentication Service Provider (Privy). Your email address is stored by Privy and is accessible to Gnosis. It is processed for account recovery, Pilot-related communications, user support, and, with your separate consent, our newsletter.
2.2 Location Data
The Lokal App verifies your location to confirm you are within the designated Kiez. Verification occurs at account creation and may recur in connection with earning Lokal Points or redeeming Merchant Offers. You verify your location by sharing it through the Lokal App or by scanning a QR code at a Merchant location. Location verification via the Lokal App requires you to explicitly grant location access when prompted by your browser or device. On the mobile apps, your operating system will request permission to use precise location; the Lokal App requires precise location because an approximate position may fall outside the Kiez boundary. You may grant or revoke this permission at any time through your device or browser settings.
Your precise coordinates are evaluated on your device and are not transmitted to or stored on Gnosis’ servers. When verification is successful, a presence record is stored on our servers that includes your account identifier, the verification method used, the neighbourhood, and a timestamp, but not your coordinates. If you verify your presence at a Merchant location by scanning a QR code, the presence record will also include the merchant, which means it reveals your approximate location at that time. This record is retained for the duration of your participation and deleted upon account deletion (see § 7). Merchants do not receive your precise location data through the Lokal App.
2.3 Pilot Activity Data and Distributed Ledger Data
Certain Pilot activity, including account creation and offer redemption events, is recorded on publicly accessible distributed ledger infrastructure. This data is associated with pseudonymous addresses that are not displayed in the Lokal App and are not linked to your name or email address. It is immutable and cannot be modified or erased once recorded. See § 8 for the implications for your data subject rights.
2.4 Authentication Data (via Privy)
Our Authentication Service Provider, Privy (operated by Horkos, LLC d/b/a Privy), processes the following data in connection with account creation and login:
- Online identifiers: email address (if provided), wallet address
- Device and IP data: IP address, IP-based location information, device type, operating system, browser type
- Web analytics data: referring webpage or source
- Session data: authentication tokens used to maintain your session
- Cryptographic key material: if you activate account recovery, encrypted key shares generated and held within a secure enclave to protect your wallet
Privy acts as a processor on behalf of Gnosis.
2.5 Analytics Data (via PostHog)
We use PostHog (PostHog, Inc.) for product analytics to understand how users interact with the Lokal App. This includes session replay technology that records your on-screen interactions (such as clicks, scrolling and navigation). Where you have given your consent and are logged in, we may associate a pseudonymous account identifier with your analytics sessions to link activity across multiple sessions. PostHog may collect:
- Technical information: IP address, browser type and version (web app), device model, operating system and version, app version (mobile apps), and pseudonymous account identifier (where you have given consent)
- Usage information: referring website (web app), screens and pages visited, time spent on screens, session data, clicks, taps, swipes, form submissions, scroll behaviour, session replay recordings, and other interactions
For details on PostHog’s hosting location and cookie usage, see §§ 4.2 and 5.
2.6 Aggregate Visitor Metrics
We maintain a server-side counter, within the Lokal App, that records aggregate visitor metrics (such as total page visits and whether a visit is from a new or returning device) without placing any tracking technology on your device and without collecting personal identifiers. This counter operates independently of the cookie banner and of PostHog. The resulting data is not linked to your account or any other information we hold about you.
§ 3 How we use your information
We process your personal data for the following purposes and on the following legal bases under Art. 6(1) GDPR:
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Operating the Lokal App, authentication, and session management | Account data, session data, authentication data (via Privy), Pilot activity data | Art. 6(1)(b) (performance of contract) |
| Location verification | Location data (transient, not stored) | Art. 6(1)(b) (performance of contract) |
| Account recovery, user support, and Pilot-related communications | Email address | Art. 6(1)(b) (performance of contract); Art. 6(1)(a) (consent) for the newsletter |
| Product analytics and service improvement | Analytics data (via PostHog) including session replay recordings, crash reports and diagnostic data, pseudonymous account identifiers, and app-specific technical data (device model, OS version, app version on mobile apps) | Art. 6(1)(a) (consent) for analytics and session replay; Art. 6(1)(f) (legitimate interest in service stability) for crash reports and diagnostics |
| Recording Pilot activity on distributed ledger | Pseudonymous on-chain identifiers, transaction data | Art. 6(1)(b) (performance of contract) |
| Enforcing our Terms; compliance with legal obligations | Account data, Pilot activity data; as required | Art. 6(1)(f) (legitimate interest); Art. 6(1)(c) (legal obligation) |
Your email address will not be shared with Merchants. We will use your email address to send you a newsletter only with your separate consent, which you may withdraw at any time.
§ 4 Third-Party Service Providers
4.1 Privy (Authentication)
Provider: Horkos, LLC d/b/a Privy Role: Data processor on behalf of Gnosis Purpose: Account creation, authentication, session management, account recovery
Privy’s privacy policy is at https://www.privy.io/privacy-policy. Privy’s subprocessor list is at https://trust.privy.io/subprocessors. Privy has appointed GDPR Art. 27 representatives: DP-Dock GmbH in Hamburg (EU) and DP Data Protection Services UK Ltd. in London (UK).
4.2 PostHog (Analytics)
Provider: PostHog, Inc. Role: Data processor on behalf of Gnosis Purpose: Product analytics, usage analysis, service improvement Hosting: PostHog Cloud EU, Frankfurt, Germany
All analytics data is processed and stored on PostHog Cloud EU infrastructure in Frankfurt. Your analytics data does not leave the European Union. PostHog does not use third-party cookies or third-party tracking services. PostHog Cloud EU defaults to disabling IP data capture for EU organisations; where disabled, IP addresses are not stored alongside analytics events.
PostHog’s privacy policy is at https://posthog.com/privacy.
4.3 Infrastructure Services
The Lokal App uses the following services to operate the points and wallet system:
Blockchain infrastructure (Gnosis Chain RPC, Circles RPC and Profile Service, Safe Transaction Service, Pimlico): these services receive your IP address and pseudonymous on-chain account identifiers in connection with account creation, wallet operations, and transaction processing. They do not receive your name or email address. Data flows occur before and independently of your analytics consent.
4.4 Loops (Newsletter)
Provider: Loops (United States)
Role: Data processor on behalf of Gnosis
Purpose: Newsletter delivery
Data received: Your email address is transmitted to Loops on a server-to-server basis if you have opted in to the newsletter. Loops processes and stores this data in the United States.
4.5 OpenFreeMap (Map Tiles)
Provider: OpenFreeMap
Purpose: Displaying map tiles within the Lokal App
Data received: IP address and map viewport on each map load. This occurs before and independently of your analytics consent. OpenFreeMap does not set cookies or store identifiers on your device.
4.6 Unsplash (Merchant Images)
Provider: Unsplash
Channels: Mobile apps only
Purpose: Displaying fallback merchant photographs
Data received: IP address on each image request
4.7 Browser Push Notifications (Web App)
If you enable browser push notifications, notification delivery is handled by your browser vendor’s push service (operated by Google, Mozilla, or Apple, depending on your browser). These services receive a push token associated with your device. Push notifications are not enabled by default.
4.8 Hosting and Infrastructure
Provider: Netlify (web app and API hosting); DigitalOcean (application database, Frankfurt, Germany)
Data received: Netlify hosts the web app and processes all API requests, including those from the mobile apps. Netlify’s server request logs, which include IP addresses, are stored in the United States. The application database on DigitalOcean stores the data described in §§ 2 and 7.
§ 5 Cookies, Device Storage and similar Technologies
The Lokal App uses cookies (on the web app) and device storage (on the mobile apps) for authentication and analytics. The mobile apps do not set cookies; they store data using the operating system’s secure keystore (for your account key) and ordinary application storage (for your account address, language preference, consent status, presence stamp, notification preferences, onboarding status, location-sharing preference, and, temporarily, the email address provided for the newsletter until confirmed by the server).
5.1 Essential / Authentication Cookies (Privy)
Privy sets essential cookies (session and functional) to maintain your authenticated session. These are strictly necessary and cannot be disabled without losing access to your account.
5.2 Analytics Cookies (PostHog)
PostHog uses a single first-party cookie (ph_<project_api_key>_posthog, 365-day expiry) to store your session identifier, device identifier, and configuration data. PostHog may also use your browser’s localStorage. These technologies support all PostHog analytics features described in § 2.5, including session replay. No third-party cookies are set. All data collected through these cookies is sent to PostHog Cloud EU in Frankfurt (see § 4.2).
5.3 Managing Your Cookie Preferences
Essential cookies are required for the Lokal App to function. Disabling them may prevent access.
Analytics: PostHog analytics tracking, including session replay, is activated only after you consent via our cookie banner (web app) or the equivalent consent prompt (mobile apps). If you decline, no analytics data will be collected and no session replays will be recorded.
You can also manage cookies in the app and through your browser settings. Clearing your browser data may result in loss of access to your account if you have not activated email-based account recovery.
5.4 Cookie Summary
| Cookie / Technology | Provider | Purpose | Type | Duration | Data Residency |
|---|---|---|---|---|---|
| Authentication session cookies | Privy | Login and session management | Essential (first-party) | Session | US (see § 10) |
| Functional cookies | Privy | Preferences and auth state | Essential (first-party) | Session / persistent | US (see § 10) |
| ph_<key>_posthog | PostHog | Product analytics | Analytics (first-party) | 365 days | EU (Frankfurt) |
| localStorage entries | PostHog | Analytics data persistence | Analytics (first-party) | Until cleared | EU (Frankfurt) |
§ 6 Data Sharing and Disclosure
We share personal data with: (a) our processors as described in § 4; (b) public distributed ledger infrastructure, as described in § 2.3; (c) authorities, where required by applicable law, regulation, legal process, or governmental request; and (d) an acquiring entity in connection with a reorganisation, merger, acquisition, or transfer of the Pilot.
Merchants do not receive your personal data through the Lokal App. We do not sell your personal data.
§ 7 Data Retention
We retain personal data only as long as necessary for the purposes described in this Privacy Policy:
- Account data and email address: retained for the duration of your participation. Deleted upon account termination or Pilot discontinuation, subject to legal retention obligations.
- Precise location data: not stored. Processed transiently on your device and discarded immediately. Presence records (which may reveal approximate location): retained for the duration of your participation and deleted upon account termination or Pilot discontinuation (see § 2.2).
- Analytics data: retained on PostHog Cloud EU (Frankfurt) per our analytics configuration. You may request deletion at any time (see § 8).
- Distributed ledger data: recorded permanently and cannot be modified or erased (see § 2.3).
- Authentication data (Privy): retained as long as you have an active account or as necessary to provide the service, with longer retention where required by law.
§ 8 Your Rights as a Data Subject
Under Articles 15–21 GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data, subject to legal retention obligations (Art. 17)
- Restrict processing under certain circumstances (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interests, including analytics (Art. 21)
To exercise these rights, contact us at hello@lkl.berlin.
Distributed ledger limitation: On-chain data is immutable (see § 2.3). Where you exercise your right to erasure, we will delete all personal data within our control, including the mapping between your account and your pseudonymous on-chain address, rendering the on-chain data practically unidentifiable.
Supervisory authority: You may lodge a complaint with the Berliner Beauftragte für Datenschutz und Informationsfreiheit, or the supervisory authority of your habitual residence.
§ 9 Security Measures
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit, access controls, and the data minimisation measures described in § 2 (local credential storage, transient location processing, pseudonymous on-chain identifiers). Our service providers maintain their own security and compliance programmes.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at hello@lkl.berlin.
§ 10 International Data Transfers
Privy (Authentication): Privy’s services are hosted in the United States. International transfers are carried out on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR and transfer impact assessments.
PostHog (Analytics): Analytics data is processed and stored exclusively within the EU (see § 4.2). No international transfer safeguards are required.
Netlify (Hosting and API): Netlify’s serverless functions that process API requests are hosted in Frankfurt, Germany. Server request logs containing IP addresses are stored in the United States on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Loops (Newsletter): Newsletter email addresses are processed and stored in the United States on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Distributed ledger: Data recorded on a public distributed ledger is accessible globally. This data consists of pseudonymous identifiers as described in § 2.3.
§ 11 Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our data practices or applicable law. Material changes will be notified at least 7 days in advance by email or in-app notice.
§ 12 Governing Law
This Privacy Policy is governed by the laws of the Federal Republic of Germany. Your rights under the GDPR and applicable German data protection law (including the BDSG) remain unaffected.