GDPR Compliance Statement
Last updated July 2026
Commitment
We aim to process personal data lawfully, fairly and transparently. Browsing is anonymous by default; accounts and the adults-only layer are opt-in; special-category data is processed only with your explicit consent.
Lawful bases
Contract for your account and core service; consent for location, analytics and optional features; explicit consent (Art. 9(2)(a)) for special-category Underground data; legitimate interests for security and moderation; legal obligation for payment records. See the Privacy Policy for detail.
Data subject requests
Self-service data export (Art. 15/20) and account deletion / erasure (Art. 17) are available in Privacy Settings. For anything else, email privacy@queer.bar. You may also complain to a supervisory authority (ICO in the UK; your national DPA in the EU).
Accountability
We maintain, or are building, a Record of Processing Activities (ROPA) and DPIAs for high-risk processing (special-category data, location). A Data Protection Officer is not necessarily mandatory but privacy@queer.bar is the standing contact for data-protection matters.
These documents are provided in good faith and describe how queer.bar actually works today. They are drafts, not legal advice; have them reviewed by a qualified lawyer and complete the bracketed operator details before relying on them. Compliance with the EU GDPR, UK GDPR / Data Protection Act 2018, the US state privacy laws (incl. CCPA/CPRA) and other applicable regimes is an ongoing organisational responsibility, not something software alone establishes.