1. Who is responsible
Varun Mishra is the controller of personal data processed by Neeed. Contact: iris@neeed.app, Bürgermeister-Prechtl-Str. 10, 92637 Weiden in der Oberpfalz, Germany. You can use this email to ask questions or exercise your privacy rights.
2. Visiting and securing the site
Cloudflare delivers the site and processes connection information such as your IP address, requested URL, time and browser information. Necessary security controls use hashed IP and mailbox identifiers to limit abuse and repeated requests. Fonts, styles, icons and the city/postcode catalogue are served by Neeed.
We process this information to deliver the site reliably, prevent misuse and protect accounts: Article 6(1)(f) GDPR. These are our legitimate interests. Opening ordinary pages does not enable analytics or advertising trackers.
3. Sign-in and private contact details
Sign-in uses your email address, verification challenge, verified session and related security information. Codes are valid for ten minutes; validity is different from deletion, and expired challenges are cleaned up during later authentication activity. Verified sessions remain valid until revoked. The sign-in cookie lasts up to 400 days and is renewed after successful authenticated use.
When you provide or expressly save a name, email or phone number, we use it for the feature you request, such as publication, replies, account basics or service matching. Account basics are private. Your email and phone number are not included in public board posts. Processing necessary to provide these services is based on Article 6(1)(b) GDPR; protecting them against abuse is based on Article 6(1)(f).
4. Public posts and private conversations
A board post publishes your chosen display name, text and accepted task details, including any location, route, time, price or exchange terms you choose to include. Posts are available in English and German. Provider offers also publish the provider’s display name. The separate service-request directory keeps customer contact names private.
Public information can be read, copied and indexed by others. Do not include sensitive information, exact private addresses or personal details about other people in public text. You review the post before publication.
Private conversation messages and participant names are accessible to their verified participants. The operator can process submission contacts and relevant records to operate the service, answer support requests and moderate misuse. These functions rely on Article 6(1)(b) GDPR and, for protecting participants and resolving abuse, Article 6(1)(f).
5. AI assistance
When you use the writing assistant, your authored text and accepted answers are sent to the OpenAI API to understand the task, suggest questions, check appropriateness and prepare English and German wording. Dedicated private email, phone and contact fields are excluded from drafting payloads. Your chosen public display name and authored places may be sent for publication translation and content checks. Personal information you type into the task text may also be included.
We use this processing to provide the writing and publication service you request under Article 6(1)(b) GDPR. Our API requests disable stored response objects. OpenAI states that API data is not used to train its models by default, but abuse-monitoring records can generally be retained for up to 30 days, with legal and security exceptions. This is not a promise of zero retention or EU-only processing.
AI may refuse unsafe text or produce incorrect suggestions. You review the output before publishing. Eligibility and content checks can prevent publication; you can email the operator to ask for human review. The assistant does not decide legal rights or enter a service contract for you.
6. Transactional email and enquiries
Resend processes recipient addresses and email content for verification codes, publication confirmations, replies and service notifications. Reply notices include a post or subject and a link, rather than the full private conversation. Email delivery involves the recipient’s own mail provider as well.
Requested service messages use Article 6(1)(b) GDPR; security notices and enquiries use Article 6(1)(f), where needed to protect the service or answer you. Privacy requests and legally required notices also use Article 6(1)(c). These service emails are not a newsletter subscription.
7. Ambassador applications
The application form collects the name, email, city or campus, motivation, interests and availability that you submit, together with your acknowledgement and submission time. Applications are private and used to assess and discuss your requested involvement under Article 6(1)(b) GDPR. Optional information can be omitted. Contact the operator if you withdraw your application or want it erased. Applications are not automatically deleted after a fixed number of days.
8. Cookies and browser storage
Neeed uses cookies and browser storage for requested functions, rather than analytics or advertising. The storage table below describes their purposes and lifetimes. Necessary storage is used under § 25(2)(2) TDDDG; associated personal data is processed on the grounds described above. Acknowledging the cookie notice does not consent to optional services.
You can reopen Cookie settings in the footer. Your browser can clear or block stored information; doing so can sign you out or remove drafts and saved items. Theme and language choices are remembered when you select them. No optional tracking category is currently enabled.
9. Optional external maps
The radius picker works with local city/postcode and distance controls before any external map is loaded. Only choosing “Load external map” requests OpenStreetMap tiles. The OpenStreetMap Foundation then receives your IP address, browser/request information and the requested map area. A tile request does not itself send your saved post or sign-in details.
This optional transfer is based on your choice and consent under Article 6(1)(a) GDPR. Hide the map or reopen Cookie settings to stop further tiles and remove the loaded map. The choice is not saved for later visits. Withdrawal does not undo information already transmitted. OpenStreetMap’s privacy policy applies to its processing.
10. Recipients and international processing
The current technical recipients are Cloudflare (hosting, database and security), OpenAI (writing assistance and content checks), Resend (email delivery) and, only if enabled, the OpenStreetMap Foundation (map tiles). Participants receive the public or private information described above. Relevant information can also be disclosed where legally required or necessary to establish or defend legal claims.
Application records are stored in EU-configured Cloudflare D1 and Durable Objects. This does not mean every network request, support operation, AI request or email stays within the EEA. Our service providers describe international processing and transfer safeguards in their privacy and data processing terms, including standard contractual clauses and, where applicable, adequacy decisions. You can ask the operator for information about the safeguards applicable to your data. Links to the providers’ notices appear below.
11. Retention and deletion
We retain posts, contact and profile records, conversations and applications for the relevant requested service, support and moderation. These records currently have no fixed automatic deletion timer. Marking a post completed or a ride expired changes its status; it does not erase the post, contact record or conversation. Email the operator to request removal or erasure.
When an erasure request applies, data must be deleted or restricted subject to legal obligations and the need to establish, exercise or defend legal claims. Retention is assessed by the purpose of the record, whether the service or enquiry is still active, and any applicable statutory obligation or claim. Short-lived rate-limit events expire, while hashed registry and accounting metadata can remain for security and recovery; no blanket 24-hour deletion is promised.
Browser-storage lifetimes are listed below. Sign-out revokes the current device’s session; it does not delete your posts, profile or other devices’ sessions. External recipients and copies made by other readers are subject to their own retention and legal responsibilities.
12. Your rights
Subject to the conditions in the GDPR, you may request access, a copy, correction, erasure, restriction or portability of your personal data. You may object to processing based on legitimate interests, for reasons relating to your situation. You can withdraw consent for optional processing at any time, without affecting its earlier lawfulness.
Send your request to iris@neeed.app, ideally from the email used for the service, and identify the relevant record. We may ask for proportionate evidence of identity to protect private data. The statutory response period is generally one month, with a possible extension in the cases provided by law.
You may complain to a data protection supervisory authority, especially where you live or work. The local authority for private-sector processing in Bavaria is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA); its complaint link is below.
13. Required and optional information
Browsing does not require an account. Email verification and the relevant task/contact fields are needed to publish or use private messaging; without them those features cannot be provided. Optional phone and profile details are voluntary. External maps are optional. Privacy acknowledgement is information about processing and does not replace the legal basis for a required service.
Browser storage inventory
| Name / storage | Purpose | Lifetime |
|---|---|---|
neeed_connection_session · cookie | Verified sign-in; HttpOnly, SameSite=Lax, Secure on HTTPS. | Up to 400 days, renewed on successful authenticated use; revoked on sign-out. |
neeed_language · cookie | Language explicitly selected by you. | 365 days. |
neeed.connection.session / .email / .epoch · localStorage | Sign-in fallback, verified email and synchronization between tabs. | No automatic browser expiry; token and email cleared on sign-out, synchronization marker retained. |
neeed.connection.session · sessionStorage | Compatibility sign-in fallback. | Tab session; cleared on sign-out. |
neeed.language.v1 / neeed.theme.v1 · localStorage | Selected language and appearance. | Until cleared in the browser. |
neeed.campus.saved.v1 / neeed-request-directory-saved-v1 / neeed-provider-directory-saved-v1 · localStorage | Items you choose to save, including disclosed fictional examples. | Until removed or cleared in the browser. |
neeed.campus.compose.v1.* / neeed.request-starter.v1.* · sessionStorage | Authored task and accepted answers, without dedicated contact fields or sign-in codes. | Tab session; composer draft removed after publication. |
neeed.campus.display-name · sessionStorage | Reply display-name convenience. | Tab session; cleared on sign-out. |
neeed.help.* / neeed.need-provider.* / neeed.need-provider.ids · sessionStorage | Public service/location hints for an intake you choose to start. | Tab session. |
neeed.privacy.notice.v1 · localStorage | Remember that you acknowledged the storage information; no optional-service consent. | Acknowledgement valid for six months; stored until replaced or cleared in the browser. The notice appears again after expiry. |