Last updated 16 September 2026

Privacy notice

This notice explains how ATÉ CHÁ handles personal data across the festival websites, the Everywhere Passport, QR stamps, the Cha-Cha Telegram bot and its Telegram Mini App. It is the information required when we collect data from you under Article 13 of the GDPR.

Here for the Telegram bot? Section 8 is the privacy notice for Cha-Cha and its Mini App, and everything else on this page applies to it too.

Launch gate. This draft must not be published at a live registration point until the Association's exact registered legal name, registered address and registration number are confirmed.

1. Controller and contact

The controller is the Portuguese cultural association organising ATÉ CHÁ, exact registered identity pending, operating under the ATÉ CHÁ name. The Association decides why and how the festival, Passport and Cha-Cha process personal data. Éric and the technical team act for the Association and are not separate controllers when doing this work.

Privacy contact: ola@atecha.co. Whether the Association has designated a data protection officer must be confirmed before launch. If one is designated, their contact details will appear here.

2. Services and surfaces covered

  • atecha.co, including its legacy Get Involved form.
  • tea.everywhere.now, including registration, account access, the web and PWA Passport, venue pages, QR scanning and the admin-supported event service.
  • Cha-Cha, the ATÉ CHÁ Telegram bot, and the associated Telegram Mini App. Section 8 covers both in detail.
  • Printed Passport and venue QR codes. A printed QR contains a venue reference, not your identity. Personal data is created when an identified account uses it.
  • The Societea Telegram community and direct contact through ola@atecha.co.

3. Data we process and where it comes from

  • Account and identity: name, email address, login records, internal account ID and consent records.
  • Passport activity: Passport ID, venue QR reference, stamp time, venue, points, contest position and fraud-prevention signals.
  • Telegram: numeric user and chat IDs, username, display name, interface language, commands, button actions, messages you send to Cha-Cha and verified Mini App initData. Telegram may make other public profile data available, but we do not take or keep your Telegram profile photo.
  • Optional Passport photo: a photo you may choose to add when you register, or later from inside your Passport. It is stored in a private storage folder that only you can read. It is never shown on any public board or member listing. You can replace or remove it from inside your Passport at any time, and it is deleted with your Passport under the same criteria as the rest of your account data.
  • Applications and enquiries: name, artist name, email, city or places lived, optional contact handles, company, interests and free text you submit.
  • Technical data: IP address, browser or app details, request time, security events, errors and diagnostic logs produced when the websites, bot or API are used.
  • City lookup: text typed into the Passport city search and the requesting IP address are sent directly to OpenStreetMap's Nominatim service.

Most data comes directly from you. Telegram supplies account and interaction data when you use Cha-Cha or the Mini App. Venue and staff systems add the stamp connected to a QR scan. We do not ask for special-category data such as health, religion or political views. Please do not put it in free-text messages.

4. Purposes and legal bases

Purpose Legal basis
Create and operate your account, Passport, stamps, QR verification, leaderboard and requested Cha-Cha service. GDPR Article 6(1)(b), performance of the user service or steps you request before using it.
Answer event, venue, application and support enquiries. Article 6(1)(b) where connected to a requested service, otherwise Article 6(1)(f), the Association's legitimate interest in organising the event and replying to people who contact it.
Send optional news, reminders or promotional updates. Article 6(1)(a), consent. You can withdraw it at any time without affecting earlier lawful processing.
Protect accounts, stop duplicate or fraudulent stamps, investigate errors and secure the service. Article 6(1)(f), legitimate interests in service security, integrity and abuse prevention.
Meet tax, accounting, legal, regulatory and rights-request obligations. Article 6(1)(c), legal obligation.

Where we rely on legitimate interests, we limit the data to what is needed, restrict access and consider your rights. You may object as explained below.

5. Recipients and service providers

Provider Role and data
Supabase Processor for database, authentication, storage and Edge Functions. It holds primary account, Passport, stamp and service records. The specific EU project region is a launch blocker and must be verified before collection.
Telegram Independent platform provider and recipient when you use Cha-Cha, its Telegram Mini App or Societea. Telegram sends the bot your account and interaction data and processes data for its own messaging service under its own privacy policy.
Z.ai Processor for Cha-Cha AI replies. Only the message and context needed to answer are sent. Z.ai states in its API DPA that API content is processed in real time, is not stored, and is generally processed in Singapore. DeepSeek may be used for non-personal knowledge-base tasks only and must not receive user messages or identifiers under this design.
Formspree Legacy processor for the atecha.co Get Involved form, which collected name, email, location, company, interests and free text. Existing submissions are treated as enquiries, not Passport accounts, and will not be bulk-imported into Supabase. People must register again under this notice.
Netlify and Cloudflare Website hosting and delivery for atecha.co and tea.everywhere.now. They may process IP addresses, request metadata and security logs.
OpenStreetMap Foundation Its Nominatim city-search service receives the city query and technical request data directly from your browser.
ATÉ CHÁ staff and approved contractors Only people who need access for registration, support, event operations, security or rights requests. They are subject to confidentiality and access controls.

We do not sell personal data. We disclose data to public authorities only where the law requires it, or where needed to establish, exercise or defend legal claims.

6. International transfers

The primary Supabase project is hosted in Supabase's Central EU region (Frankfurt, Germany), so account, Passport and stamp data is stored inside the EEA. Some provider support, security and subprocessor activity may take place outside the EEA. Telegram operates internationally and describes transfers within its group, including to the British Virgin Islands and Dubai, using European Commission standard contractual clauses. Formspree hosts its service on AWS in the United States and states that it relies on standard contractual clauses as a processor. Z.ai generally processes API data in Singapore and commits in its API DPA to use legally recognised transfer safeguards.

Copies of or information about the applicable safeguards can be requested at ola@atecha.co. See the providers' own terms: Telegram privacy, Supabase DPA, Formspree security and transfers, and Z.ai API DPA.

7. Retention

We have not fixed a single number of days or months for each record yet. Article 13(2)(a) of the GDPR allows a notice to publish the criteria used to determine the storage period when a fixed period is not yet possible, and that is what the table below does. A retention schedule with exact periods will be set after data-protection legal review and will replace these criteria here, dated at the foot of this notice.

Record How long we keep it
Account, Passport and stamps While the account is active. When you delete the account, identifiable account data is removed without undue delay, keeping only what an active legal claim or a legal obligation requires. The optional Passport photo, including any upload left in your private storage folder, is removed with the account. An anonymous stamp count may remain for event statistics.
Cha-Cha messages For as long as needed to hold the conversation, answer support requests and investigate abuse. Saved preferences remain with the account until you change or delete them. You can ask for bot data to be deleted at any time.
Security and diagnostic logs For as long as needed to detect, investigate and resolve a security, abuse or reliability problem, and to keep a record of one that was resolved.
Event enquiries and earlier atecha.co form submissions For as long as needed to answer or follow up the enquiry and to organise the editions of the event it relates to. Contact details collected through the earlier atecha.co form may be carried into the new platform so that we can invite you to register. No Passport account is created from them: an account exists only once you register yourself and accept the terms and any consent at that point.
Optional updates Until you withdraw consent or ask to be removed from the list.
Rights, consent and legal records For the period needed to demonstrate compliance or to meet an applicable legal limitation period.
Backups Deleted data may persist in protected rolling backups until those backups age out of the rotation. It is not restored except for disaster recovery.

8. Cha-Cha bot and Telegram Mini App

This section is the privacy notice for Cha-Cha, the ATÉ CHÁ bot on Telegram, and for the Telegram Mini App it opens. It is the policy published for the bot under Telegram's Bot Developer Terms. It adds detail; it does not replace the rest of this notice, so the controller, legal bases, recipients, transfers, retention and rights sections above apply to the bot as well.

What Cha-Cha receives about you

  • Your Telegram numeric user ID and chat ID, username, display name and interface language. Telegram sends these with every message you direct at the bot.
  • The content of what you send the bot: text, commands, button presses and any photo or file you choose to send it. Cha-Cha is a conversational assistant, so what you type is the input it answers.
  • In the Mini App, the signed initData that Telegram provides, which we verify to confirm the session is really yours, plus the Passport actions you take inside it.
  • Security and diagnostic events produced by the bot's own server.

We do not receive your phone number, your contact list or your Telegram profile photo, and we do not ask Telegram for them. In a group chat, Telegram's bot privacy mode means Cha-Cha normally only sees messages addressed to it, unless a group administrator turns that mode off.

Why the bot processes it

  • To answer you and run the Passport features you ask for. Article 6(1)(b), performance of the service you requested.
  • To link your Telegram account to your Passport account through a one-time code, so your stamps and progress follow you between the bot and the website. Article 6(1)(b).
  • To hold short-term conversation context so a reply makes sense in a thread. Article 6(1)(b).
  • To prevent spam, abuse and duplicate stamps. Article 6(1)(f), legitimate interests.

The AI model that writes the replies

Cha-Cha's answers are generated by a large language model operated by an external provider. Your message, and the short conversation context needed to answer it, are sent to that provider so it can produce the reply. The provider, its role and where it processes data are listed in sections 5 and 6 above. Your messages are not used to train that provider's models. Please do not send the bot special-category data such as health, religion, political views or sexual orientation, and do not send other people's personal data.

Controlling your bot data

  • /privacy in the bot opens this notice.
  • /delete asks for your bot data to be deleted, including the link between your Telegram account and your Passport account.
  • Blocking or removing the bot in Telegram stops further messages reaching us, but it does not by itself delete what we already hold. Use /delete, or write to ola@atecha.co.
  • Deleting your Passport account also removes the Telegram link held against it.

Telegram's own role

Telegram is a separate controller for your Telegram account and for delivering messages to and from the bot. Chats with a bot are ordinary cloud chats, not secret chats, so Telegram holds them under its own terms: Telegram privacy policy. The bot is operated under the Telegram Bot Developer Terms.

9. Your rights

Depending on the processing, you may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. You also have the right to complain to Portugal's supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).

Send a request to ola@atecha.co. We may ask for the minimum information needed to verify that the account is yours. We normally respond within one month. You can also delete bot data with the /delete command in Cha-Cha, as described in section 8.

10. What is required

The registration form will mark required fields. An email address is required for account access, and a Telegram user ID is required only when you choose to bind or use Cha-Cha and the Mini App. A QR scan, venue and time are required to issue a digital stamp. Without those details we cannot provide that part of the service. Marketing consent, optional profile fields and free-text information are not required.

11. Automated processing

Cha-Cha uses an AI model to generate conversational answers from the festival knowledge base. Answers may be incomplete or wrong and are not human decisions. Stamp totals, duplicate checks and leaderboard positions are calculated automatically. None of these processes makes a decision that produces legal or similarly significant effects under GDPR Article 22. A person reviews contested stamps or account restrictions.

12. Questions and changes

Questions and rights requests go to ola@atecha.co. We will update this notice before adding a materially different purpose, provider, category of data, location feature or data-sharing arrangement. Where required, we will notify affected users or ask for new consent before the change takes effect.