← back to home

Privacy Policy

Last updated: 18 June 2026

This policy explains what personal data Tempo collects, why we collect it, how we use it, and the rights you have over it. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Dutch implementation (Uitvoeringswet AVG).

1. Who we are (the controller)

Optim Enterprises BV — a private limited company incorporated in the Netherlands — operates Tempo (the website at tempo.optimcloud.com). Optim Enterprises BV is the data controller for the personal data described in this policy.

Registered as a besloten vennootschap in the Netherlands — KvK 70926638. BTW (VAT) number and postal address are listed in our Terms of Service §1.

Privacy questions, data-subject access requests, and complaints: [email protected].

2. What we collect, and why

We collect only what we need to run a small, careful dating platform. Each category below lists the data, the purpose, and the GDPR legal basis we rely on under Article 6 (and Article 9 where the data is "special category" — sexual orientation, biometric, etc.).

2.1 Account data

Email address, hashed password (Argon2id — we never see the plain text), display name, date of birth, gender, dating intent, timezone, and city.

Purpose: create your account, deliver matches, enforce minimum age (18).
Legal basis: Art. 6(1)(b) — performance of the contract you enter into with us when you sign up.

2.2 Profile data

Photos, prompt answers, interests, values, location radius, the city or cities you've added to your profile, and any free-text fields you choose to fill in.

Purpose: present your profile to matches; help matches find you.
Legal basis: Art. 6(1)(b) — contract performance. Where this includes sexual orientation, Art. 9(2)(a) — your explicit consent given when you fill in those fields (the fields are optional).

2.3 Identity-verification data

When you complete identity verification, our verification provider receives a copy of your government-issued ID and a short selfie video. The provider returns to us only a pass/fail signal and the minimum metadata (name match, age match, document type). The ID image and selfie are not stored on Tempo's servers; they are held by the verification provider under their own retention policy.

Purpose: confirm you are a real person of age, deter catfishing and impersonation.
Legal basis: Art. 6(1)(b) — contract performance; Art. 9(2)(g) — substantial public interest (protection from online identity fraud, child safety) supported by Dutch law.

2.4 Messages, prompts, and posts

The content of conversations with matches, group-room posts, board threads, voice notes, and any other content you publish on Tempo.

Purpose: deliver messages to their recipients; moderate abuse reports.
Legal basis: Art. 6(1)(b) — contract performance. Moderation review of reported content relies on Art. 6(1)(f) — our legitimate interest in keeping the platform safe and complying with the EU Digital Services Act.

2.5 Image-block list (NCII)

If you submit an image at /safety/submit-hash to block it from being uploaded to Tempo, the image content is hashed in memory on our server and immediately discarded. We persist only a 64-bit perceptual fingerprint of the image, not the image itself.

Important: the fingerprint is retained even if you later delete your Tempo account. The protection should outlive your presence on the platform — your consent to be protected was given once, and walking away from Tempo does not revoke it. If you want the fingerprint removed, email [email protected] and we will remove it within 30 days.
Legal basis: Art. 6(1)(a) — your explicit consent when you submit the hash; Art. 9(2)(a) — explicit consent for processing data potentially related to your sex life.

2.6 Technical and security data

IP address, browser user-agent, session cookies, rate-limiting counters, audit-log entries (login, profile change, moderation action). We do not use third-party analytics, advertising pixels, or behavioural tracking. We do not sell, share, or trade your data with advertising networks.

Purpose: security, fraud prevention, debugging.
Legal basis: Art. 6(1)(f) — our legitimate interest in operating a secure service.

2.7 AI-coach data (optional feature)

If you use the AI coach, your prompt to the coach is sent to our inference provider for the purpose of generating a suggestion. Per Tempo's AI posture (ADR-0011), the AI never authors messages on your behalf and never modifies the content you send — it only suggests. The provider does not retain the prompt beyond the inference call. The coach's suggestions are stored briefly in your account so you can revisit them.

Legal basis: Art. 6(1)(a) — your consent (you initiate each coach call).

3. Who we share data with

We share personal data only with the third parties we need to operate the service. Each is a processor bound by a Data Processing Agreement under GDPR Art. 28.

We do not share data with advertisers, data brokers, social networks, or marketing partners.

4. International transfers

Where a processor (e.g. Airwallex, push gateways, AI inference) is located outside the EU/EEA, transfers rely on Standard Contractual Clauses (Module Two, controller-to-processor) and the supplementary measures required by the Schrems II ruling. The list of recipient countries is in our Article 30 register, available on request.

5. How long we keep your data

6. Your rights (GDPR Articles 15–22)

You have the right to:

We respond to verified data-subject requests within 30 days (extendable by 60 days for complex requests, with notice).

7. Cookies and similar technologies

Tempo organises its cookies into five categories and asks for your consent on first visit. You can revisit and change your choice any time from cookie settings.

The full list of cookies, providers, and retention windows is at /cookies. Per GDPR Art. 7(3) withdrawal of consent is as easy as the original consent — same page, same checkboxes, save.

8. Children

Tempo is for adults only. The minimum age is 18 and we enforce it at signup and at identity-verification. If we learn an account belongs to a minor we suspend it immediately, delete the data within 7 days, and where required by law report the case to authorities.

9. Security

Passwords are hashed with Argon2id. Sessions are tied to a server-side store. Database connections are encrypted in transit. Photos are stored in object storage with private ACLs and served only to authorised viewers. We publish our security disclosure policy at /security and our security.txt at /.well-known/security.txt.

If a personal-data breach affecting you occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours and you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms (Art. 33, 34).

10. Changes to this policy

When we materially change this policy we will notify you by email and surface a banner on next sign-in. The "Last updated" date at the top of this page always reflects the current version. Older versions are kept in our git history; we can provide a diff on request.

Questions about this policy? Email [email protected].

Terms of Service · Acceptable Use Policy · Security Policy