This is a courtesy translation. The German version is the legally binding one; in case of any discrepancy, the German text prevails.
Last updated: August 2026
Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 GDPR.
Controller
Dominik Lenart-Aogo, Fabgoods Vending
Agathenstr. 5, 76189 Karlsruhe, Germany
Email: legal@nocturne-app.de
There is no obligation to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG).
Two roles — please read this first
Nocturne is software for clubs, venues and promoters. For all data a club enters into its account — artists, bookings, riders, travel and fee data, guest lists, crew — that club is the controller under the GDPR. We process such data solely on its behalf and on its instructions, on the basis of a data processing agreement under Art. 28 GDPR.
We are the controller within the meaning of this policy only for what operating the application itself requires: user accounts, sign-in, billing and operational security. If you want to know what a particular club does with your data, please contact that club.
Account and sign-in
For a user account we process email address, name, role and club affiliation, together with the technical data of the sign-in. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Without this data no access is possible.
The session is maintained by a strictly necessary cookie. It contains only the session token, serves no analytics purpose and is set without consent under § 25(2)(2) TTDSG. In addition, the application stores your display preferences (colour scheme, language) and your decision about external maps in your browser's local storage. These values never leave your device.
Artist, travel and passport data
To advance a show, travel data and — where a flight booking is requested — identity document data of the travelling person may be processed. These are held encrypted in the vault of our database and are not readable in plain text through the normal application interface.
Stated explicitly: if a flight is booked through the travel agent, the passenger data required for the booking, including the passport number, is transmitted to the flight booking service Duffel in the United Kingdom. Without this transmission a flight booking is technically impossible. An adequacy decision of the European Commission is in place for the United Kingdom. If you do not want this transmission, book flights outside Nocturne; the travel agent can be switched off per club.
Inbound email and the AI assistant
Incoming booking requests and riders are read by an AI model from Anthropic and returned in structured form. Likewise, the Noctura assistant processes the questions you ask it together with a current excerpt of your club's data. Both run on Anthropic servers in the United States, on the basis of the EU Standard Contractual Clauses.
Noctura is an AI system. You are informed of this before first use (Art. 50 AI Act). Answers may be wrong and are no substitute for professional or legal review. Every action an agent proposes is executed only after explicit human approval — there is no automated decision-making within the meaning of Art. 22 GDPR.
Maps and address lookup
Transfer planning can display a map. The map tiles come from CARTO (USA); when they load, CARTO learns your IP address and the map section you are viewing. The map is therefore loaded only after you have agreed. Without your agreement the area stays empty and the list of transfers and locations keeps working. You can change your decision at any time in the privacy settings.
Turning addresses into coordinates uses OpenStreetMap Nominatim, but exclusively from our server. Your IP address is not transmitted to OpenStreetMap. Only the address being searched is transmitted; results are cached so the same address does not have to be looked up again.
Public links (advance and intake)
A club can send a link that lets an artist agency view the running order of a show or upload documents. These links are not publicly discoverable, are excluded from search engines and expire automatically — as a rule fourteen days after the event date. The club can withdraw or renew a link at any time.
Payments
Subscriptions are handled through Stripe. Payment details are entered directly with Stripe; we neither see nor store full card or account details, only the status of the subscription. The legal basis is Art. 6(1)(b) GDPR.
Logs and operational security
To secure operations we log agent actions and security-relevant events and limit the number of requests per account and per link. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against abuse and traceability of automated processes.
Retention
- Account data: for the duration of the contractual relationship
- A club's content data (bookings, artists, travel data): 30 days after termination, then fully deleted
- Identity document data: deleted once the respective trip is complete, at the latest together with the account
- Billing records: statutory retention periods under German commercial and tax law
- Security logs: as a rule 90 days
Recipients
A complete list of the service providers we use, with location and purpose, is available under “Subprocessors”. Data storage and the application are located in the EU; individual processing steps run via providers in third countries, on the basis of the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
Your rights
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Please write to legal@nocturne-app.de. If your data forms part of a club's account content, we will forward the request to the responsible club or tell you which body is responsible.
Independently of this, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
