top of page

Privacy Policy

Last Updated: 04 July 2026

Introduction

By understanding what matters to you, SayHello allows you to match with people at events who are most compatible with you. This Privacy Policy describes what personal data we collect, how we collect and use it, how we protect it, whether we share it, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG).

When we use the terms “we”, “us” or “our”, we are referring to SayHello. When we use the term “Service”, we are referring to the SayHello application, website and related services that post or link to this Privacy Policy.

Who We Are (Data Controller)

SayHello is the controller of your personal data within the meaning of Article 4(7) GDPR. Our details are:

SayHello (vennootschap onder firma / general partnership)

Joan Muyskenweg 15 A 3, 1096 CJ Amsterdam, the Netherlands

Chamber of Commerce (KVK) number: 42089781

Email: hello@sayhellosocial.org

Phone: +31 6 26 68 28 54

What Information Do We Collect?

We collect a few types of information from you as part of your participation in SayHello. When you sign up for an event and complete the SayHello questionnaire, we collect the following data directly from you:

  • Contact information: your name, email address and phone number.

  • Profile information: information you choose to add to your profile, which may include a profile photo and a short description of yourself.

  • Demographic data: we may ask you to answer some questions about what groups you are a part of in the broader population. This may include your age, your gender identity or your sexual orientation.

  • Values data: your answers to a series of questions covering matters of principle and preference, used to compute compatibility.

  • Feedback data: after you participate, we may ask for your thoughts on the match we gave you or on other parts of your SayHello experience.

While you use the Service, we also collect limited, pseudonymous analytics data, including your IP address and whether you take certain actions in the Service. These analytics are kept separate from the responses you submit for events, and we collect only as much data as we need. To protect your privacy, we stay away from analytics platforms run by big ad-tech companies (no Google Analytics, no Facebook pixel).

How Do We Collect This Information?

This information is received via official SayHello questionnaires and forms in the Service. Your answers are only recorded when you press “Submit” at the end of a form. Providing information is voluntary; however, without certain data (such as your contact information and questionnaire answers) we cannot match you at an event.

How Do We Use This Information, & On What Legal Basis?

Under the GDPR we must have a legal basis for every use of your personal data. The table below sets out our purposes, the data used and the corresponding legal bases:

  • Creating and administering your participation in an event. For this purpose we use your contact information and account details. Legal basis: performance of a contract (Art. 6(1)(b)).

  • Matching you with compatible participants. For this purpose we use your values data, demographic data and profile information. Legal basis: consent (Art. 6(1)(a)).

  • Matching based on gender identity or sexual orientation preferences. For this purpose we use your special category data (Art. 9). Legal basis: explicit consent (Art. 9(2)(a)).

  • Communicating your match and service notifications. For this purpose we use your contact information. Legal basis: performance of a contract (Art. 6(1)(b)).

  • Improving the design and operation of the Service. For this purpose we use your anonymous analytics data and feedback data. Legal basis: legitimate interests (Art. 6(1)(f)).

  • Statistical analysis (e.g. checking questions for bias). For this purpose we use your aggregated, de-identified demographic data. Legal basis: legitimate interests (Art. 6(1)(f)).

  • Complying with legal obligations (e.g. tax and accounting). For this purpose we use your billing and payment records (hosts). Legal basis: legal obligation (Art. 6(1)(c)).

Special category data. Some questions may reveal your sexual orientation, or other data protected under Article 9 GDPR. We only process such data with your explicit consent, which we ask for separately in the questionnaire. You may refuse or withdraw this consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal.

 

Automated matching. Our matching algorithm suggests compatible participants automatically. Matches are social suggestions only and have no legal or similarly significant effect on you within the meaning of Article 22 GDPR. If you have questions about how a match was made, contact us at hello@sayhellosocial.org.

How Is This Information Protected?

Because there are sensitive questions involved, privacy is extremely important to us. We have designed privacy into our systems wherever we can. At a high level: all data is kept encrypted, no human reads individual participants’ answers to make matches, and our algorithm makes matches using a completely pseudonymised version of the required data — randomised unique identifiers for each participant take the place of personally identifiable information.

Here is how the full process looks for your data:

  • Before you submit your responses, they exist only on your device.

  • When you submit, your responses travel to our servers encrypted under TLS.

  • Your personally identifiable information (such as your name, email address, phone number and profile photo) is stored in one database, while your question responses are stored separately. The two are correlated only through randomised, unique, pseudonymous identifiers. Both databases are encrypted at rest.

  • When matches are computed, the matching algorithm receives only the pseudonymised response data and matches participants based on their pseudonymous IDs.

  • When we notify everyone of their matches, we re-combine the computed matches with contact details in memory only, to compose each notification. We do not permanently store the de-anonymised match data.

We also take care of the less glamorous parts of security: all our accounts use long, unique passphrases and multi-factor authentication wherever possible, and access to personal data is restricted to those who need it.

Do We Share This Information?

We will never sell information about you. Beyond sharing your contact information and first name with your match (see below), we will never share your responses in a way that could let you be individually identified. We will not correlate your responses with information about you from third parties, we will not give third parties access to SayHello data to correlate with external data about you, and you will never get targeted ads based on your answers.

Your match. When matches are announced, you and your match may simultaneously receive each other’s name and contact information. By participating in an event, you consent to this exchange — it is the entire point of the Service.

 

Event hosts. Hosts of events see aggregate information about their event (such as the number of participants). Hosts do not see your individual questionnaire answers.

 

Service providers (processors). We rely on service providers for critical infrastructure, such as cloud hosting, authentication, payments, and sending emails and text messages. These providers process personal data only on our documented instructions, under data processing agreements that meet the requirements of Article 28 GDPR. We transmit information to and from these providers in encrypted form.

 

Legal requirements. We may disclose personal data where required to do so by law or by a competent authority.

International Transfers

We store data within the European Economic Area (EEA) where possible. Where a service provider processes personal data outside the EEA, we ensure an adequate level of protection through an adequacy decision of the European Commission or through appropriate safeguards such as the EU Standard Contractual Clauses (Article 46 GDPR), together with additional measures where necessary. You can contact us for more information about the safeguards we use.

How Long Do We Keep Your Data?

We keep personal data no longer than necessary for the purposes described in this Policy:

  • Event responses and match data are retained for the duration of the event cycle and deleted or fully anonymised within 12 months after the event, unless you maintain an account with us.

  • Account data is retained for as long as your account exists and deleted within 3 months after account deletion.

  • Billing records of hosts are retained for 7 years, as required by Dutch tax law.

  • Pseudonymous analytics and aggregated statistics may be retained longer, as they do not identify you.

Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Access (Art. 15) — request a copy of the personal data we hold about you;

  • Rectification (Art. 16) — have inaccurate data corrected;

  • Erasure (Art. 17) — have your data deleted (“right to be forgotten”);

  • Restriction (Art. 18) — have processing of your data restricted;

  • Data portability (Art. 20) — receive the data you provided in a structured, commonly used, machine-readable format;

  • Objection (Art. 21) — object to processing based on our legitimate interests;

  • Withdraw consent (Art. 7(3)) — withdraw any consent at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, email us at hello@sayhellosocial.org with the subject line “SAYHELLO: DATA REQUEST” (for deletion, “SAYHELLO: DATA DELETION”). We will respond within one month. We may ask you to verify your identity before acting on a request.

If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, www.autoriteitpersoonsgegevens.nl, or with the supervisory authority of the EU member state where you live or work. We would, of course, appreciate the chance to address your concerns first.

Age Requirements

The Service is intended for adults. You must be at least 18 years old to use SayHello. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from a person under 18, we will delete it. If you believe a minor has provided us with personal data, please contact us.

Cookies & Similar Technologies

The Service uses only functional cookies and comparable technologies that are necessary for the Service to work (for example, to keep you logged in), and privacy-friendly, self-hosted analytics as described in Section 3. We do not use advertising or third-party tracking cookies. For any non-essential cookies we may introduce in the future, we will ask for your consent in line with the Dutch Telecommunications Act.

Our Principles

Participation is voluntary. Participating in SayHello is entirely voluntary, and you may withdraw from an event at any point.

Your privacy is not for sale. We will not sell access to you or your attention to advertisers. Your SayHello data will never be brokered or sold.

Changes To This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and notify you through the Service or by email before the changes take effect.

Contact

We have outlined the policies above because we think it is the right thing to do. If you have questions about any of this, contact us:

SayHello (vennootschap onder firma / general partnership)

Joan Muyskenweg 15 A 3, 1096 CJ Amsterdam, the Netherlands

Chamber of Commerce (KVK) number: 42089781

Email: hello@sayhellosocial.org

Phone: +31 6 26 68 28 54

bottom of page