Privacy Policy
Last updated: 18 June 2026
This policy explains what personal data Tempo collects, why we collect it, how we use it, and the rights you have over it. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Dutch implementation (Uitvoeringswet AVG).
1. Who we are (the controller)
Optim Enterprises BV — a private limited company incorporated in the Netherlands — operates Tempo (the website at tempo.optimcloud.com). Optim Enterprises BV is the data controller for the personal data described in this policy.
Registered as a besloten vennootschap in the Netherlands — KvK 70926638. BTW (VAT) number and postal address are listed in our Terms of Service §1.
Privacy questions, data-subject access requests, and complaints: [email protected].
2. What we collect, and why
We collect only what we need to run a small, careful dating platform. Each category below lists the data, the purpose, and the GDPR legal basis we rely on under Article 6 (and Article 9 where the data is "special category" — sexual orientation, biometric, etc.).
2.1 Account data
Email address, hashed password (Argon2id — we never see the plain text), display name, date of birth, gender, dating intent, timezone, and city.
Purpose: create your account, deliver matches,
enforce minimum age (18).
Legal basis: Art. 6(1)(b) — performance of the
contract you enter into with us when you sign up.
2.2 Profile data
Photos, prompt answers, interests, values, location radius, the city or cities you've added to your profile, and any free-text fields you choose to fill in.
Purpose: present your profile to matches; help
matches find you.
Legal basis: Art. 6(1)(b) — contract performance.
Where this includes sexual orientation, Art. 9(2)(a) — your explicit
consent given when you fill in those fields (the fields are
optional).
2.3 Identity-verification data
When you complete identity verification, our verification provider receives a copy of your government-issued ID and a short selfie video. The provider returns to us only a pass/fail signal and the minimum metadata (name match, age match, document type). The ID image and selfie are not stored on Tempo's servers; they are held by the verification provider under their own retention policy.
Purpose: confirm you are a real person of age,
deter catfishing and impersonation.
Legal basis: Art. 6(1)(b) — contract performance;
Art. 9(2)(g) — substantial public interest (protection from
online identity fraud, child safety) supported by Dutch law.
2.4 Messages, prompts, and posts
The content of conversations with matches, group-room posts, board threads, voice notes, and any other content you publish on Tempo.
Purpose: deliver messages to their recipients;
moderate abuse reports.
Legal basis: Art. 6(1)(b) — contract performance.
Moderation review of reported content relies on Art. 6(1)(f) — our
legitimate interest in keeping the platform safe and complying with
the EU Digital Services Act.
2.5 Image-block list (NCII)
If you submit an image at /safety/submit-hash to block it from being uploaded to Tempo, the image content is hashed in memory on our server and immediately discarded. We persist only a 64-bit perceptual fingerprint of the image, not the image itself.
Important: the fingerprint is retained even if you
later delete your Tempo account. The protection should outlive your
presence on the platform — your consent to be protected was given
once, and walking away from Tempo does not revoke it. If you want
the fingerprint removed, email
[email protected]
and we will remove it within 30 days.
Legal basis: Art. 6(1)(a) — your explicit consent
when you submit the hash; Art. 9(2)(a) — explicit consent for
processing data potentially related to your sex life.
2.6 Technical and security data
IP address, browser user-agent, session cookies, rate-limiting counters, audit-log entries (login, profile change, moderation action). We do not use third-party analytics, advertising pixels, or behavioural tracking. We do not sell, share, or trade your data with advertising networks.
Purpose: security, fraud prevention, debugging.
Legal basis: Art. 6(1)(f) — our legitimate interest
in operating a secure service.
2.7 AI-coach data (optional feature)
If you use the AI coach, your prompt to the coach is sent to our inference provider for the purpose of generating a suggestion. Per Tempo's AI posture (ADR-0011), the AI never authors messages on your behalf and never modifies the content you send — it only suggests. The provider does not retain the prompt beyond the inference call. The coach's suggestions are stored briefly in your account so you can revisit them.
Legal basis: Art. 6(1)(a) — your consent (you initiate each coach call).
3. Who we share data with
We share personal data only with the third parties we need to operate the service. Each is a processor bound by a Data Processing Agreement under GDPR Art. 28.
- Identity-verification provider — receives the ID document and selfie video for the duration of the verification check. Returns only a pass/fail signal. (Provider details on request; named in the controller's Article 30 register.)
- Payment processor (Airwallex) — handles Premium subscription billing. Airwallex receives your email, billing country, and card details directly; Tempo never sees full card numbers.
- Email delivery provider — delivers verification emails, match notifications, account-security alerts. Sees only your email address and the email content.
- Push-notification gateways (Apple APNs, Google FCM, Mozilla autopush) — deliver browser/device push notifications you've opted into. Receive an opaque endpoint token, not your account identity.
- Hosting infrastructure — Tempo runs on our own Kubernetes infrastructure operated by Optim Enterprises BV. Database backups are encrypted at rest.
- Databunker PII vault — self-hosted open-source vault running in our own cluster, also operated by Optim Enterprises BV. Stores your identity fields (email, display name, birthdate, phone, ID-verification metadata) encrypted with per-user keys; Tempo's main database holds only opaque tokens. No third-party processor — vault and operator are the same legal entity.
- AI inference provider (for the AI coach feature) — receives the text of the prompt you submit to the coach; does not retain it after the call.
- Law enforcement — only when compelled by a valid court order or where required by law (e.g. mandatory reporting of suspected child sexual abuse material to authorities). We publish an annual transparency report listing the volume of such requests.
We do not share data with advertisers, data brokers, social networks, or marketing partners.
4. International transfers
Where a processor (e.g. Airwallex, push gateways, AI inference) is located outside the EU/EEA, transfers rely on Standard Contractual Clauses (Module Two, controller-to-processor) and the supplementary measures required by the Schrems II ruling. The list of recipient countries is in our Article 30 register, available on request.
5. How long we keep your data
- Account data: until you delete your account.
- Profile data and photos: until you delete them (individually) or your account (in bulk). On account deletion, photo files are removed from object storage within 30 days; database rows are anonymised immediately and purged after 90 days to allow for legal-hold requests.
- Messages: kept while the conversation is active. After both participants leave the conversation or one deletes their account, the messages are removed within 90 days.
- Identity-verification metadata (pass/fail and check date only): retained for the life of your account so we don't ask you to re-verify on every login. The ID image and selfie are not held by Tempo — see §2.3.
- Audit log (login events, moderation actions): retained 2 years for fraud-investigation and DSA compliance, then anonymised.
- NCII image fingerprints: retained indefinitely — see §2.5 for the rationale and how to request removal.
- Backups: rotated on a 30-day cycle; deleted account data is purged from active backups within that window.
6. Your rights (GDPR Articles 15–22)
You have the right to:
- Access — receive a copy of the personal data we hold about you (Art. 15). Request at /me → Privacy → Export, or email [email protected].
- Rectification — correct inaccurate data (Art. 16). Most profile fields are editable directly in the app.
- Erasure — delete your account and the personal data we hold (Art. 17). Use /me → Delete account. See §5 for the retention windows that survive deletion and why.
- Restriction of processing — pause processing while a dispute is resolved (Art. 18).
- Data portability — receive your data in a machine-readable format (Art. 20). The export at /me → Privacy → Export returns JSON.
- Object — object to processing based on legitimate interest (Art. 21).
- Not be subject to automated decision-making — Tempo's match scoring is algorithmic but does not produce legal or similarly significant decisions about you (Art. 22). Account suspension decisions are always reviewed by a human.
- Withdraw consent — where we rely on consent (marketing communications, AI coach use, NCII submission), you can withdraw it at any time without affecting prior processing.
- Lodge a complaint — with your local Data Protection Authority. Ours is the Dutch Autoriteit Persoonsgegevens. You can complain to them directly, but we'd prefer you give us a chance to fix it first — [email protected].
We respond to verified data-subject requests within 30 days (extendable by 60 days for complex requests, with notice).
7. Cookies and similar technologies
Tempo organises its cookies into five categories and asks for your consent on first visit. You can revisit and change your choice any time from cookie settings.
- Strictly necessary (always on):
tempo_sessionkeeps you signed in;tempo_consentremembers your choice here. These don't require consent under ePrivacy Directive Article 5(3) — without them the service cannot be provided. - Functional: stored only when you opt into a feature that needs to remember something locally (e.g. push notifications). None are set by default.
- Analytics: none today. Reserved for any future, privacy-respecting usage measurement.
- Marketing: none today, and none planned. Tempo does not run ad pixels, retargeting, or affiliate trackers.
- Third-party CDN: Cloudflare may set
__cf_bmandcf_clearancefor bot management. We surface this category honestly because it's Cloudflare's tooling, not ours.
The full list of cookies, providers, and retention windows is at /cookies. Per GDPR Art. 7(3) withdrawal of consent is as easy as the original consent — same page, same checkboxes, save.
8. Children
Tempo is for adults only. The minimum age is 18 and we enforce it at signup and at identity-verification. If we learn an account belongs to a minor we suspend it immediately, delete the data within 7 days, and where required by law report the case to authorities.
9. Security
Passwords are hashed with Argon2id. Sessions are tied to a server-side store. Database connections are encrypted in transit. Photos are stored in object storage with private ACLs and served only to authorised viewers. We publish our security disclosure policy at /security and our security.txt at /.well-known/security.txt.
If a personal-data breach affecting you occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours and you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms (Art. 33, 34).
10. Changes to this policy
When we materially change this policy we will notify you by email and surface a banner on next sign-in. The "Last updated" date at the top of this page always reflects the current version. Older versions are kept in our git history; we can provide a diff on request.
Questions about this policy? Email [email protected].