Privacy Policy

Last updated: April 2026

1. Who We Are

Kome Together is operated by AMDS Software, Lda., registered in Portugal. We provide a platform for people to find and join outdoor and sports activities.

Data controller: AMDS Software, Lda.
Contact: hello@amdssoftware.com

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: name, email address, password (hashed), date of account creation, gender (optional)
  • Profile data: bio, profile photo, sport preferences
  • Activity data: activities you create, join, or attend; GPS coordinates of activity locations
  • Community data: communities you create or join
  • Communication data: messages sent within activity chats
  • Usage data: pages visited, features used, timestamps of actions (stored in server logs for up to 30 days)
  • Technical data: IP address, browser type and version, device type (session only)

3. Legal Basis for Processing

We process your personal data under the following legal bases (GDPR Article 6):

  • Contract performance (Art. 6(1)(b)): to provide the Kome Together service, process registrations, display activity listings, and enable participation
  • Legitimate interest (Art. 6(1)(f)): to maintain platform security, prevent fraud, and improve the service
  • Consent (Art. 6(1)(a)): for optional data such as profile photo, bio, and gender
  • Legal obligation (Art. 6(1)(c)): where required by Portuguese or EU law

4. How We Use Your Data

  • Provide and personalise the Kome Together service
  • Display your profile to other users (name, photo, activities)
  • Send transactional emails (registration, activity reminders, notifications you have enabled)
  • Enable real-time activity chat between participants
  • Show activity pins and community locations on the map
  • Enforce our Terms of Service and community guidelines
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal effects.

5. Cookies and Local Storage

We use the following cookies. See our Cookie Policy for full details.

Cookie Purpose Type
_session Keeps you logged in during your browser session Strictly necessary
ct_cookie_consent Remembers your cookie consent choice Strictly necessary

We do not use analytics, advertising, or third-party tracking cookies.

6. Data Sharing

We only share your data in the following circumstances:

  • Other users: your name, profile photo, and public activities are visible to other users of the platform
  • Infrastructure providers: hosting and database services (EU-based servers) — under data processing agreements
  • Email provider: for transactional emails only — no marketing use
  • Law enforcement: when legally required by Portuguese or EU authorities

7. Data Retention

  • Account data: retained while your account is active. Upon deletion, your personal data is anonymised immediately
  • Activity and community data: retained for 2 years after the activity date, then deleted
  • Chat messages: retained for 90 days after the activity date
  • Server logs: retained for 30 days

8. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

  • Right of access (Art. 15): request a copy of all personal data we hold about you
  • Right to rectification (Art. 16): correct inaccurate or incomplete data via your profile settings
  • Right to erasure (Art. 17): delete your account and all associated personal data from Settings
  • Right to restriction (Art. 18): request we limit processing of your data
  • Right to portability (Art. 20): request your data in a machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interest
  • Right to withdraw consent: at any time, for data processed on the basis of consent

To exercise any of these rights, email hello@amdssoftware.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD) at cnpd.pt.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including: encrypted connections (TLS/HTTPS), hashed passwords (bcrypt), JWT token invalidation on logout, and restricted database access.

9b. Cooperation with Law Enforcement

We will disclose personal data to law enforcement, judicial authorities, or competent regulators when:

  • Required to do so by applicable law, court order, or legal process
  • We detect or receive reports of Child Sexual Abuse Material (CSAM) or other illegal content — in which case we are legally obligated to report to the Polícia Judiciária, the Internet Watch Foundation (IWF), and Europol under Directive 2011/93/EU and the EU Digital Services Act
  • We believe disclosure is necessary to protect the rights, safety, or property of our users or the public

In such cases, the data disclosed may include account information, IP addresses, email addresses, and any content flagged as illegal.

10. Children and Minors

Kome Together is strictly for users aged 18 and over. We do not knowingly collect personal data from persons under the age of 18. If we become aware that a person under 18 has created an account, we will immediately terminate that account and delete the associated personal data.

We do not direct any content, advertising, or communications at minors. If you believe a minor has provided us with personal data, contact us immediately at hello@amdssoftware.com.

11. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email of any material changes at least 30 days in advance. Continued use of Kome Together after the effective date constitutes acceptance of the updated policy.

Questions?

Contact our privacy team at hello@amdssoftware.com. We typically respond within 5 business days.