Privacy Policy
UK GDPRLast updated: {{updated}}
How {{company}} processes personal data, in accordance with the UK GDPR and the Data Protection Act 2018.
Template document, aligned with the UK GDPR, the Data Protection Act 2018 and the Online Safety Act 2023. Have it reviewed by UK legal counsel before official publication.
1. Controller
{{company}}, registered in England and Wales under number {{company_number}}, registered office {{registered_office}}, registered with the Information Commissioner's Office (ICO) under reference {{ico_reg}}.
2. Privacy contact / DPO
Where required, we will appoint a DPO. Privacy contact: {{email_privacy}}. If you are outside the United Kingdom, we operate under the UK GDPR representative rules.
3. Data we collect
- Account: e-mail, phone, social login, passkey, Web3 wallet address
- Profile: nickname, photo, age, city, bio, interests, intents
- Interaction: messages, media, votes, likes, reports, blocks
- Technical: IP, device, language, logs and metadata
- Safety: fraud, abuse, moderation and age-assurance signals
4. Sensitive data and inferences
Using a dating platform can reveal, or allow inferences about, social life, relationships and preferences. We treat this data with enhanced care, data minimisation and privacy by design. Where the law requires, we rely on explicit consent or another lawful condition under the DPA 2018.
5. Legal bases (Art. 6 and 9)
- Performance of contract — operating account, profile, chat and matches
- Consent — location, special category data and marketing
- Legitimate interest — safety, anti-fraud and moderation
- Legal obligation — Online Safety Act 2023 duties and other laws
6. Automated decisions (Art. 22)
Messages, images and audio may be analysed automatically before they appear. Material decisions can be contested and routed to human review via the privacy contact, save for urgent temporary measures.
7. Sharing
We do not sell your data. We share only with essential processors (hosting, authentication, anti-fraud, moderation, support) under contract, and with authorities where required by law. See Sub-processors.
We use Google reCAPTCHA Enterprise to protect account access against abuse and automated login attempts. It runs invisibly at that step and sends usage data to Google — IP address, device and browser information, and on-page interactions — to compute a risk score; we do not use it for advertising. That processing is governed by Google's Privacy Policy and Terms of Service (policies.google.com/privacy and policies.google.com/terms).
8. International transfers
Restricted transfers rely on UK GDPR safeguards: adequacy decisions, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the SCCs, or another valid mechanism.
9. Retention
We keep data for as long as needed for the service and legal duties. Safety records and Online Safety Act-relevant logs are kept for the applicable period; after that we anonymise or delete.
10. Your rights (Art. 15-22)
- Access a copy of your data
- Correct incomplete or out-of-date data
- Request erasure
- Restrict or object to processing
- Portability
- Withdraw consent
- Complain to the ICO at ico.org.uk
11. Security and breaches
We use encryption in transit and at rest, access control and continuous moderation. In the event of a breach with material risk, we will notify the ICO within 72 hours and inform you where required. Contact: {{email_privacy}}.