TamilFunction
Privacy Policy
This policy explains which personal data TamilFunction processes, why it is needed and which rights affected people have.
English translation dated 13 August 2026. German original dated 13 August 2026.
1. Controller
Sanjchayan MahendranSchmemannstr. 2-4
45326 Essen
Germany
Email: info@tamilfunction.com
Further contact details are available in the legal notice.
2. Principles and legal bases
We process only data that is necessary to operate the platform, provide requested services, communicate, maintain security or meet legal obligations. Depending on the process, the legal basis is performance of a contract or steps taken before entering into a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR), consent (Article 6(1)(a) GDPR) or our legitimate interests (Article 6(1)(f) GDPR).
Our legitimate interests include secure and reliable operation, prevention of misuse, review of Vendor applications and claims, delivery of inquiries and the establishment, exercise or defence of legal claims.
3. Website access and hosting
When the website is accessed, technically necessary connection and log data is processed. This may include the IP address, date and time, requested address, referrer address, browser and device information, HTTP status, and error and security events. Processing is necessary to deliver the website, maintain stability, analyse errors and defend against attacks. The legal basis is Article 6(1)(f) GDPR.
The website, global delivery network and server-side functions are provided by Vercel Inc., USA. Production server functions are configured for Frankfurt, Germany. Vercel's global delivery network and support, security and operational services provided by Vercel and its subprocessors may nevertheless require processing in other countries. Further information: Vercel Privacy Policy.
Fonts are included by Next.js when the website is built and are served from our own delivery environment. Merely accessing the website therefore does not establish a connection to Google Fonts.
The TamilFunction mobile app displays the marketplace and protected workspaces through an embedded browser view. The same server connections, account controls and processing described in this policy therefore apply in the app. The app does not use an advertising identifier or third-party advertising tracker. Device files, photos or videos are processed only when a user deliberately selects them for an available upload feature.
5. Accounts and private planning features
Registration and login
For an account, we process in particular your name, login email address, account role, internal identifiers, confirmation status and security data. The authentication service processes the password; TamilFunction cannot view it in plain text. Email confirmation, login, password reset and changes to the login email help keep the account secure. The legal bases are Article 6(1)(b) and (f) GDPR. An account cannot be provided without a login email address and a sufficiently secure password.
One login may connect a customer area and a Vendor area. Vendor data is treated separately from private customer data. Admin rights are assigned internally only.
While a signed-in user keeps a visible TamilFunction page open, we update one latest-activity timestamp at most every two minutes. This lets authorised Super-Admins support accounts and recognise whether an account was active within the previous five minutes. We do not retain visited routes, clicks or a movement history for this purpose. The legal bases are Article 6(1)(b) and (f) GDPR.
Planning data
In the customer area, users may store the event type and date, country, city, guest count, budgets, notes, checklists, required services and favourites. Customers may also keep a private Gift Book for a function. This may contain names or family labels, relationship or family-side information, cash amounts and currencies, gift descriptions and optional private notes. These records are not shared with Vendors. A Function owner and an accepted partner can access the shared Function planning records, including budget, checklist and Gift Book. Helpers can see only the Function name and date, the shared Function-day team, assigned tasks and completion status; they cannot access the budget, Gift Book or other owner-only financial planning records. The assignment of a favourite to an individual customer account remains private and is processed only to provide the selected planning features (Article 6(1)(b) GDPR). For approved public Vendor profiles, TamilFunction may display only the anonymous aggregate number of customer favourites. No customer identity is disclosed and the count does not affect search ranking. This limited public signal supports transparent profile engagement (Article 6(1)(f) GDPR).
For partner and helper invitations, we process the invited email address, selected role, inviting account, Function, invitation status and expiry time. The invitation is shown only to an account with the same verified email address and becomes unusable after seven days if it is not accepted. People who add another person's email address must be authorised to invite that person and should direct them to this Privacy Policy. Where Article 14 GDPR applies, TamilFunction provides the information when the invitation is presented or in the first communication, and no later than the statutory deadline unless an exception applies.
Shared Function-day tasks may contain a title, note, location, scheduled time, reminder time, assignee and completion history. These records are visible to the Function owner, partner and active helpers. Helpers may update only the completion status of tasks assigned to them. Processing is necessary to provide the deliberately selected collaborative planning feature (Article 6(1)(b) GDPR).
After a customer marks a function as completed, TamilFunction stores a private, immutable snapshot of the function details, completed checklist and final paid budget entries. This snapshot is used only to provide the customer's downloadable final Function PDF. The customer may reopen the function, which removes the snapshot and unlocks the planner (Article 6(1)(b) GDPR).
Optional AI planning assistant
Signed-in customers may deliberately start the AI planning assistant. The event type and date, country, city, guest count, currency, selected services, a free-text note limited to 600 characters and a pseudonymous account identifier are then sent to the OpenAI API. The login email address and telephone number are not sent to OpenAI for this purpose. Please do not enter sensitive personal data in the free-text field.
Processing provides the requested editable planning draft with a cost range, checklist and matching public Vendor suggestions (Article 6(1)(b) GDPR). The result is neither a binding quote nor a solely automated decision with legal or similarly significant effect. TamilFunction does not automatically save the inputs or result to the customer account. Only when the customer expressly imports the draft into the private planner do the general rules for private planning data apply.
General Terms acceptance
When a registered user accepts the General Terms of Use, we store private evidence consisting of the pseudonymous account identifier, context, document version, checksum, language and database time. We do not store an IP address, user agent or device fingerprint for this purpose. The record is necessary to form and administer the account agreement and to document the applicable terms (Article 6(1)(b), (c) and (f) GDPR).
Account deletion
A customer may submit a reviewed deletion request in account settings, including through the in-app Legal & account area. TamilFunction aims to complete the permanent account deletion within 48 hours. The deletion removes the customer account, its own private planning data, memberships and favourites. Collaborative records that also concern another Function member are reviewed so that the rights of that person and necessary evidence are protected. Inquiries that have already been sent remain as separate communication records and are detached from the deleted customer account. A Vendor profile is handled through the separate, reviewed Vendor deletion process so that an existing customer area is not accidentally deleted with it.
6. Vendors, applications, claims and public profiles
Vendor application and claim
For a Vendor application or a claim to an existing Basic listing, we process in particular the account and business relationship, business name, owner or representative details, category, country, city and profile information, a required private registration phone number, the application text, and review and decision data. The private registration phone number is not public and is not currently verified by SMS. Public telephone, WhatsApp, business email, website and social-media links are separate, optional profile fields. A Vendor application or claim cannot be reviewed without a login email, the required private registration phone number and the business information marked as required in the form.
Where the Vendor Terms are displayed and accepted in the relevant application or claim process, we also store the confirmed business status and acceptance evidence with the document version, checksum, language and time. We do not store an IP address, user agent or device fingerprint for this purpose. Processing is necessary for the application and contract process, manual authority review, platform security and evidence (Article 6(1)(b), (c) and (f) GDPR).
Basic listings created by TamilFunction
TamilFunction may create a free Basic listing from publicly available business information. Sources may include the business's own website, public business profiles, directories or registers. We process only information needed for discoverability, in particular the business name, category, location and business contact details already made public. Where this information relates to a natural person, processing is based on Article 6(1)(f) GDPR. Our interest is to operate a useful and factually accurate marketplace.
To prepare such a listing, an Admin may use an AI form helper to structure publicly visible business information. Either a public Instagram link or handle, or a screenshot of the public profile area together with the visible business information, is sent once to the OpenAI API for that request. The screenshot is not stored in TamilFunction's database or Storage. Suggestions are reviewed manually; they neither publish a listing nor contact anyone automatically. Processing is based on Article 6(1)(f) GDPR and our interest in recording public business data accurately and with data minimisation. The access, correction and objection rights described below remain unaffected.
Where Article 14 GDPR applies, we provide the required information at the first communication, no later than one month after collection or before the first disclosure, unless a statutory exception applies or the person already has the information.
Affected people may request information about the specific source at any time, have information corrected or object for reasons relating to their particular situation. A disputed listing is reviewed and taken offline where a removal request is justified. Contact us at info@tamilfunction.com.
Publication and moderation
After approval, the business name, profile description, category, city and country, service area, languages, images, videos and optional business contacts may be publicly visible worldwide. Search engines and other third parties may index or cache public content. The private registration phone number, login email, claim notes, review documents, moderation processes and deletion requests are not public.
Changes to approved profiles, claims, owner confirmations, suspensions and deletion requests are reviewed by a person. TamilFunction does not make solely automated decisions that produce legal or similarly significant effects.
Vendor workspace, team access and offer drafts
An authorised Vendor owner may invite managers or staff using their email address. We process the invited email address, role, invitation status and expiry, the accepting profile and membership status. An invitation can be accepted only by an account with the same verified email address and becomes unusable after seven days. Active Vendor team members can see the business team, calendar, jobs and shared tasks according to their role. Staff can update only the status of tasks assigned to them; owners and managers have wider organisational access. Processing provides the requested business workspace (Article 6(1)(b) GDPR) and protects it against unauthorised access (Article 6(1)(f) GDPR).
Vendor tasks and jobs may contain titles, notes, customer references, dates, locations, reminder times, assignments and completion history. Notification preferences record whether an individual team member wants available inquiry, task-reminder or offer-update messages. A preference does not itself prove that a notification was delivered.
Where the Premium offer tool is available, authorised owners and managers may store private quotation drafts with customer name and optional contact details, offer number, event details, line items, prices, discount, currency, validity date, notes and status. TamilFunction does not treat these drafts as invoices or payment records. A draft is not sent automatically; the Vendor remains responsible for reviewing and deliberately sending it through an enabled channel. Customer data may be used only for the relevant inquiry or business relationship.
Vendor deletion request
A Vendor may submit a reviewed deletion request. The public profile is taken offline; final deletion takes place only after the necessary review of inquiries, media, contractual evidence and statutory retention duties. An optional callback request is based on consent and may be withdrawn at any time with effect for the future. Cancellation of an open deletion request is also documented. The private customer area remains unaffected.
7. Contact, customer inquiries and emails
Depending on the form, a contact or Vendor inquiry may include the name, email address, optional telephone number, WhatsApp preference, event type and date, city, guest count, requested service and message. A Vendor inquiry is made available to the selected Vendor for handling. A general contact inquiry is received by the TamilFunction team. The legal basis is Article 6(1)(b) GDPR and, for reliable delivery, abuse prevention and evidence of legitimate communication, Article 6(1)(f) GDPR.
A signed-out person can submit a Vendor inquiry without creating an account. TamilFunction first stores it in a server-only pending area and sends a single-use confirmation link to the supplied email address. The selected Vendor receives the inquiry only after that link is confirmed. Unconfirmed requests expire after 60 minutes and are not shown to the Vendor. A pseudonymous technical fingerprint is used temporarily to limit automated abuse; the raw IP address is not stored in the inquiry table. A daily cleanup removes expired pending requests after a short operational grace period, normally within 25 hours.
A person may also send one general request to TamilFunction and expressly consent to being contacted by selected Vendors. The email address must first be confirmed through a single-use link. TamilFunction reviews the verified request and decides which Vendors to invite. Before accepting, an invited Vendor receives only an anonymous summary containing event details, date, location, guest count and requested service. The customer's name, email address, optional telephone number and full message become available to that Vendor only after the Vendor accepts. TamilFunction then informs the customer that the Vendor may contact them directly. Declining Vendors do not receive those contact details.
Transactional emails such as confirmations, password emails and inquiry notifications are sent through Resend, operated by Plus Five Five, Inc., USA. In particular, the sender and recipient address, subject, content, sending time, delivery status and technical log data are processed. Resend states that email data is retained for 30 days on standard plans. Further information: Resend Privacy Policy.
8. Location feature
The search feature accesses the device's current location only after you actively select the feature and grant browser permission. The coordinates are added to the search address and processed on the server to calculate distance. They may therefore appear temporarily in browser history and technically necessary server logs. They are not stored as a permanent part of the customer profile. You can select a country and city instead at any time. The legal basis is the location search you expressly request under Article 6(1)(b) GDPR and section 25(2), no. 2 TDDDG.
Vendors may voluntarily provide location coordinates for more accurate distance calculation. These coordinates are stored internally but are not published as coordinates in the public profile. Without exact coordinates, TamilFunction uses the centre of the selected city.
9. Recipients, processors and international transfers
Personal data is disclosed only where necessary for the relevant purpose to:
- accepted Function partners and helpers for the role-limited shared records described above,
- authorised Vendor owners, managers and staff for their role-limited business workspace records,
- the selected Vendor where a customer sends a direct inquiry to that Vendor,
- Vendors selected by TamilFunction for a general request, with contact details disclosed only after the individual Vendor accepts,
- Supabase for authentication, database and media-storage services,
- Vercel for hosting, delivery and server-side functions,
- Resend for sending transactional emails,
- OpenAI for deliberately initiated AI form and planning functions,
- authorities, courts or advisers where this is required by law or necessary for legal defence.
Authentication, database and Storage are provided by Supabase Pte. Ltd., Singapore. The active database is located in the eu-central-1 region in Frankfurt. Supabase and its subprocessors may process limited support, security or operational data in other countries. Further information: Supabase Privacy Policy.
The AI functions use the API provided by OpenAI Ireland Ltd. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in to data sharing. TamilFunction disables application-state response storage withstore: false. Independently of that setting, content may generally remain in OpenAI abuse-monitoring logs for up to 30 days under the OpenAI API terms; longer retention is possible where OpenAI considers it necessary for legal or safety reasons. Further information: OpenAI Privacy Policy.
For transfers to countries outside the European Economic Area, we use the contractual safeguards provided for by law, in particular the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions. Data processing agreements are in place with Supabase, Vercel, Resend and OpenAI. Despite these safeguards, another level of data protection may apply in a third country and access by its authorities cannot be completely ruled out.
10. Retention and deletion
We delete personal data when the relevant purpose no longer applies and no legal duty or legitimate reason requires further, where appropriate restricted, retention. Some deletions are implemented through controlled manual reviews. The following criteria are particularly relevant:
- Accounts and private planning data are generally stored until the user deletes them or account use ends.
- Partner, helper and Vendor-team invitations become unusable after seven days. Invitation, membership and shared-task records remain only while needed to manage the relevant Function or Vendor workspace, handle access security or document an accepted invitation, and are removed with the corresponding workspace unless a legal reason requires limited further retention.
- The latest account-activity timestamp is overwritten rather than stored as a history and is deleted together with the account.
- TamilFunction does not store a temporary AI planning-assistant result. Only a draft that the customer expressly imports is treated as private planning data.
- Screenshots used by the Admin AI form helper are not stored in the database or Storage. For both AI functions, OpenAI may generally retain API content for up to 30 days for abuse monitoring.
- An active Vendor profile is stored for the Vendor relationship. After a deletion request, it is taken offline; after the final decision is approved, profile data that is no longer needed is generally deleted within 30 days.
- Vendor jobs, tasks, notification preferences and unsent offer drafts are generally kept until the Vendor deletes them or the Vendor relationship ends. A deliberately sent or accepted offer and related customer data may be retained for the applicable contractual, tax or legal-defence period where required.
- Rejected or withdrawn Vendor applications and claims are generally deleted or anonymised twelve months after the final decision unless a specific security or legal matter requires longer retention.
- Ordinary platform contact inquiries are generally deleted six months after completion. Vendor inquiries are generally retained for twelve months after completion; necessary parts of a specific legal dispute may be restricted until the applicable limitation period expires.
- Rejected or failed media uploads are marked for technical deletion; published images and videos remain stored only while needed for an active profile.
- Evidence of acceptance of the General Terms is generally retained for six years from the end of the calendar year in which the registered account relationship ends.
- Evidence of acceptance of the Vendor Terms is generally retained for six years from the end of the calendar year in which the Vendor relationship ends.
- Resend states that sent email data is retained for 30 days on standard plans.
- Technical logs are retained only for the short operational and security period provided by the relevant service provider.
- Encrypted backups are protected separately and retained only as long as needed for reliable restoration. Deletions already completed must not be put back into productive use after a restoration.
Depending on the document, tax and commercial-law records may have to be retained for six, eight or ten years. This duty does not justify continued active use of the entire account or profile.
11. Your rights
Subject to the legal conditions, you have in particular the right to:
- access your processed data (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on legitimate interests (Article 21 GDPR),
- withdraw consent with effect for the future (Article 7(3) GDPR).
To exercise your rights, email info@tamilfunction.com. We may request additional information to securely identify the request. Rights may be restricted where the rights of other people or statutory retention duties prevent fulfilment.
You may also lodge a complaint with a data protection supervisory authority. The authority responsible for our establishment is in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
12. Security and changes
We use technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. These measures include encrypted transmission, access restrictions, role-based permissions, secured uploads and controlled review and deletion processes. Absolute security cannot be guaranteed.
We update this policy when features, providers or legal requirements change. Where a material change requires participation or new consent, affected people will be informed separately.
