Privacy Policy

Effective Date: 12-02-2025

Last Updated: 10-04-2025

Welcome to BastaSocial ("we," "our," or "us"). Your privacy is our top priority, and we are committed to implementing the highest security standards to protect your personal data. This Privacy Policy explains how we collect, use, share, and safeguard your information when you use our social media platform.

1. Scope of This Privacy Policy

This Privacy Policy applies to all users globally, with strict adherence to European data protection laws, including the General Data Protection Regulation (GDPR). By using BastaSocial, you consent to the practices described in this Privacy Policy.

2. Information We Collect

a. Information You Provide

  • Account details (e.g., name, email, phone number, profile picture)
  • User-generated content (photos, videos, comments, and other posts)
  • Messages and interactions with other users (encrypted for your privacy)

b. Information Collected Automatically

  • Device and usage information (IP address, device ID, operating system, app version, cookies, and analytics data)
  • Location data (only with explicit permission)
  • Behavioral data (to enhance security and prevent fraud)

c. AI-Generated and Moderated Content

  • Our AI features analyze and generate content to enhance user experience
  • AI-powered moderation ensures compliance with community guidelines while respecting user privacy

3. How We Use Your Information

We use your data to:

  • Provide, operate, and improve our services
  • Personalize content and recommendations
  • Detect, investigate, and prevent fraud and abuse
  • Ensure platform safety through AI-driven moderation
  • Respond to legal obligations and requests from authorities
  • Facilitate user interactions while respecting privacy settings

4. How We Share Your Information

We do not sell your personal data. We may share your information with:

Service Providers

We partner with trusted third-party vendors to provide essential platform features. These include:

  • img.ly – for video and image editing
  • Mux – for secure video streaming and playback
  • GetStream.io – for in-app messaging and activity feeds

All providers implement industry-standard encryption and are required to comply with strict data protection and confidentiality agreements. Data shared with them is processed securely and in compliance with GDPR and other applicable regulations.

Law Enforcement

We may disclose information if legally required to do so, in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Business Transfers

In the event of a merger, acquisition, or asset sale, user data may be transferred as part of that transaction. You will be notified in advance of any such changes.

5. Your Rights and Choices

As a European user, you have the following rights under GDPR:

  • Right to Access - Request a copy of your personal data
  • Right to Rectification - Correct inaccurate or incomplete data
  • Right to Erasure - Request deletion of your data (with certain legal exceptions)
  • Right to Restrict Processing
  • Right to Data Portability
  • Right to Object - To processing based on legitimate interests
  • Right to Withdraw Consent- At any time

To exercise your rights, contact us at Contact@basta-group.com.

6. Data Retention

We retain your data only for as long as needed to:

  • Provide our services
  • Fulfill legal obligations
  • Resolve disputes
  • Enforce agreements

Once no longer required, your data will be securely deleted or anonymized.

7. Data Security

We apply strong technical and organizational security measures, including:

  • End-to-end encryption for sensitive data and messages
  • Two-Factor Authentication (2FA) for account protection
  • Regular security audits and threat monitoring
  • Restricted internal access to user data

8. International Data Transfers

As a global platform, your data may be transferred outside the European Economic Area (EEA). To ensure its protection, we implement:

  • Standard Contractual Clauses (SCCs)
  • Data encryption during transfer and storage
  • Compliance with regional privacy regulations

9. Children's Privacy

BastaSocial is not intended for users under the age of 13 (or the minimum age in your country). We do not knowingly collect data from children. Parents or guardians can request data deletion by contacting us.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Significant changes will be communicated through:

  • Email
  • App notifications
  • Website alerts

All changes will take effect after appropriate user notice.