Legal
Privacy Policy
Last updated: 7 July 2026
This policy explains how your personal data is processed when you use the SlavicPartner platform (website; a mobile app is in preparation). The platform is operated in compliance with the European Union General Data Protection Regulation (GDPR).
1. Data controller
The data controller is Global Ads OÜ, a company established in Estonia. You can reach us at destek@slavicpartner.com for all privacy related requests. Our data processing is carried out in line with GDPR principles and, for our users in Türkiye, additionally in line with the principles of KVKK (Kişisel Verilerin Korunması Kanunu, Türkiye's Personal Data Protection Law No. 6698).
2. What data do we process?
- Account data: email address, password (stored as an irreversible hash), first name, date of birth, gender, country and city, language preference, marital status and declaration of intent to marry.
- Profile data: photos, your about text, physical characteristics, lifestyle statements, voice intro and privacy preferences. You provide this data so that it can be shown to other members.
- Compatibility test answers: used by the matching algorithm to calculate the compatibility score.
- Messages: your correspondence with other members is stored on the platform. To protect against fraud and abuse, your messages are automatically scanned for security purposes and reviewed by our team when necessary (details: section 4). If you use the translation feature, the message content is sent to our artificial intelligence service provider for translation.
- Identity verification documents: identity document and selfie photo (for members who complete verification). The storage conditions are explained in section 5.
- Payment data: your card details never reach us; payments are processed directly in the secure system of our payment infrastructure provider. We keep only the purchase record (plan, amount, date).
- Technical data: session cookie and IP based rate limiting records. When the mobile app is released, a push notification token will also be processed.
3. Purposes of processing and legal bases
- Performance of a contract (GDPR 6(1)(b)): creating an account, matching, messaging, providing membership and credit services, completing payment transactions.
- Legitimate interest (GDPR 6(1)(f)): preventing fraud and fake profiles, security scanning of messages, preventing banned users from returning to the platform, protecting the security of the platform and of our members.
- Consent (GDPR 6(1)(a)): participation in the verification process, optional features such as the voice intro, and marketing notifications. You can withdraw your consent at any time.
4. Message security scanning (transparency notice)
SlavicPartner is a serious marriage platform, and protecting its members against fraud is a fundamental obligation for us. For this reason your messages inside the platform are scanned by automated systems (for example, requests for money, attempts to move users to external platforms and known fraud patterns). Conversations flagged by the automated system, as well as conversations that are the subject of a complaint, may be reviewed by our security team when necessary. The legal basis for this processing is our legitimate interest in ensuring the safety of our members (GDPR 6(1)(f)). Your messages are not analysed for marketing purposes and are not sold to third parties.
5. Retention of identity documents
The identity document and selfie photo of members who complete verification are not destroyed after verification; they are retained for the duration of the membership. The reason and the legal basis are as follows: fake profiles and fraud are the most serious risk that marriage platforms face. Retaining the documents for the duration of the membership is necessary so that (a) identity can be re-verified when a fraud complaint is made about a member, (b) a person who has been permanently banned cannot return to the platform with a different profile, and (c) lawful requests from competent authorities can be answered (legitimate interest, GDPR 6(1)(f)).
The identity document and verification selfie files are stored together with the technical metadata added by the capturing device (EXIF: capture date, device information and, if present, location). This metadata is kept solely for fraud detection and for answering lawful requests from competent authorities; it is not shared with third parties. In profile photos, this metadata is completely removed during upload.
This retention is applied in a balanced way: only the authorised team can access the documents, and the documents are not kept in a publicly accessible area. When you delete your account, all your other data is permanently erased; the identity document and selfie files are retained for a further 12 months from the date of account deletion and are permanently erased at the end of that period. The purpose of this limited retention is to make it possible to establish identity in the event of fraud complaints that may arise after the account has been deleted and in response to lawful requests from competent authorities (GDPR 17(3)(e): establishment and defence of legal claims). In addition, for users whose accounts are banned for breaking the rules, an irreversible digest of the email address (SHA-256 hash) is kept so that the re-registration block can be enforced.
6. Who do we share your data with?
Your data is not sold. It is shared only with the following data processors that are necessary for the service to work, and only to the extent necessary:
- Our payment infrastructure provider (payment service): payment transactions and billing.
- Google (artificial intelligence, Gemini API): message translation, profile text translation and security scanning. Message content is processed for these purposes; under paid usage it is not permitted to be used for model training.
- Resend (email): sending verification and notification emails.
- Supabase (database hosting): hosting the platform data inside the EU (Frankfurt).
- Cloudflare R2 (file storage): storing photos and identity documents in the EU region.
- Vercel (web hosting): hosting and serving the website.
- Expo (push notifications): delivering notifications once the mobile app is released.
In addition, data may be shared with competent authorities where we are legally obliged to do so.
7. Retention periods
- Account, profile, test answers and messages: for as long as the membership continues.
- Identity documents: for as long as the membership continues (section 5); after the account is deleted they are kept for a further 12 months and are permanently erased at the end of that period.
- After account deletion: all your personal data other than the identity documents is permanently erased. For banned accounts, an email hash (a digest that does not directly identify the person) is additionally kept to enforce the re-registration block.
- Purchase records: for the period required by accounting legislation.
8. Your GDPR rights and how to exercise them
Under the GDPR you have the following rights:
- Access: to learn which of your data is being processed.
- Rectification: correction of incorrect or incomplete data.
- Erasure ("right to be forgotten"): permanent deletion of your account and your data.
- Portability: receiving your data in a machine readable format.
- Objection and restriction: objecting to processing based on legitimate interest.
You can exercise your access and portability rights instantly and by yourself with the "Download my data" button in the Settings → Account section, and your erasure right with the "Permanently delete my account" button in the same section. You can make most corrections yourself in your profile settings; for other requests write to us at destek@slavicpartner.com and we will respond within 30 days at the latest. You also retain the right to lodge a complaint with the data protection authority of the country where you reside.
9. Cookies
We use only two cookies: the mandatory session cookie that keeps your session alive (sp_session) and a cookie that remembers your language preference. We do not use advertising, tracking or analytics cookies, so no cookie consent banner is needed.
10. International data transfers
Your data is processed mainly inside the EU: our database is hosted on Supabase in Frankfurt (EU), and photos and identity documents are hosted in the EU region of Cloudflare R2. Some of our service providers (our payment infrastructure provider, Google, Resend, Vercel, Expo) are based in the United States. These transfers are made on the basis of the safeguards provided for by the GDPR, such as European Commission adequacy decisions and Standard Contractual Clauses (SCC).
11. Data belonging to third parties
- Your trusted person (emergency contact): if you use the safe meeting feature, you provide the name and contact details of the third person you choose. This information is stored only for emergency notification, is not used for any other purpose, and it is your responsibility to inform that person.
- Blocking people you know: if you use the "hide me from people I know" feature, the email addresses you enter are irreversibly hashed (SHA-256) on your device and only these digests are sent to us. The addresses themselves never reach our servers; the addresses cannot be recovered from the digests, and the digests are used solely to block visibility. When there is a match, the block is mutual: neither side sees the other. Matching by phone number is not supported.
12. Data breach notification
If we detect a data breach affecting your personal data, in accordance with Article 33 of the GDPR we will notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI) within 72 hours at the latest after becoming aware of the breach. If the breach carries a high risk to your rights and freedoms, we will also inform you directly without delay. Breach records are documented together with the measures taken.
13. Data retention for banned accounts
For users whose accounts are permanently banned for breaking the rules, a minimum data set (email address and reason for the ban) is retained on the basis of legitimate interest in order to keep the platform secure, to enforce the re-registration block and to allow appeals to be assessed (GDPR 6(1)(f)). When a banned account is deleted, the data other than this minimum record is erased as described in section 7. Ban decisions can be appealed at slavicpartner.com/itiraz.
14. Changes and contact
If we make a significant change to this policy, we will inform you through the platform. For your questions: destek@slavicpartner.com