Privacy Policy

Last updated: September 30, 2026

Data Controller

NOVERA WEB SRL (CUI 55616130)
Reg. Com. J2026055293008, Romania
Contact: [email protected]

1. Who we are

This Privacy Policy explains how NOVERA WEB SRL(“we”, “us”, “our”), acting as data controller within the meaning of the EU General Data Protection Regulation (GDPR), collects and processes your personal data when you use Herzmeet(the “Service”).

2. Personal data we collect

  • Account data: email address, display name, date of birth, gender, city, country, language preference, password (hashed).
  • Profile data: bio, public and private (unlockable) photos, selfie submitted for verification.
  • Activity data: matches, likes, messages, reactions, calls initiated / received, profile visits, blocks, reports.
  • Payment data: purchase history, ledger of credits, active subscriptions. Card data is handled directly by CCBill; we never see or store full card numbers.
  • Technical data: IP address (stored 30 days), device type, user-agent, last seen timestamp.
  • Consent data: your cookie preferences and separate profiling and marketing choices, their version and withdrawal timestamps.

User profile information and uploaded content are provided directly by Users. While we may apply moderation and safety measures, we do not independently verify every profile or every item of user-generated content. Herzmeet is an online platform that hosts content created and uploaded by its Users. Users are solely responsible for the information, photographs, messages and other content they publish. While we employ reasonable technical, organizational and moderation measures to promote safety and detect abuse, we cannot guarantee the authenticity, accuracy or legality of every profile or every item of user-generated content. We reserve the right to investigate and remove content that violates our policies or applicable law.

A limited number of authorized employees and contractors may access message content when necessary for support, safety, fraud prevention or moderation. For profiles clearly marked as platform-operated, authorized operators may also respond through that profile, including with AI assistance. These actions are access-controlled and logged. Messages are not end-to-end encrypted.

3. Purposes and legal bases

  • Contract performance (Art. 6(1)(b) GDPR) — account, profile, chat, calls, matches, payments.
  • Legitimate interest (Art. 6(1)(f)) — fraud prevention, security logs (IP, 30 days), content moderation, service improvement.
  • Consent (Art. 6(1)(a)) — analytics (PostHog), personalized matching/profiling, optional marketing emails and non-essential cookies. Each consent is collected and withdrawable separately.
  • Legal obligation (Art. 6(1)(c)) — compliance with GDPR, DSA, tax law (invoice retention 10 years).

4. Sub-processors

The following partners process personal data on our behalf under GDPR-compliant data processing agreements (DPAs). Region indicates where the data is stored or processed.

NamePurposeLegal basisRegion
CCBill, LLCPayment processing for credits and subscriptions (card data, billing address, transaction history)Contract performanceUnited States (SCCs + additional safeguards)
PostHog Cloud EUProduct analytics (events, funnels, retention)ConsentEU
Cloudflare R2Media storage (photos, video, chat attachments)Contract performanceMulti-region (EU primary)
AblyRealtime notifications (messages, match events, presence)Contract performanceEU (eu-central)
Agora.ioAudio / video calls (signaling and media relay)Contract performanceGlobal (EU preferred)
PostmarkTransactional email (verification, password reset, notifications)Contract performanceEU
SentryError monitoring (frontend + backend)Legitimate interestEU
MaxMind GeoLite2City / country detection from IP (local DB, no data transfer)Legitimate interestLocal DB on our servers
RailwayApplication hosting (compute, database, Redis)Contract performanceEU (eu-west)

5. Your GDPR rights

  • Access (Art. 15) — request a copy of the personal data we hold about you.
  • Rectification (Art. 16) — edit your profile data directly under Settings, or email us.
  • Erasure (Art. 17) — delete your account from Settings → Account → Delete account, or email us.
  • Portability (Art. 20) — request an export in machine-readable JSON.
  • Objection and restriction (Art. 18, 21) — email us.
  • Withdrawal of consent — at any time, via Settings → Privacy or by unsubscribing from marketing emails.
  • Complaint — you may also lodge a complaint with your local data protection supervisory authority.

6. Retention

  • Profile, messages, matches — as long as the account is active.
  • Audit logs (regulatory compliance) — 24 months, then automatically erased.
  • IP logs (fraud detection) — 30 days.
  • Generated data exports stored in R2 — 72 hours (signed link), then erased.
  • Invoicing and accounting records — 10 years (Romanian tax law).
  • After account deletion — irreversible purge is queued without undue delay for profile, messages, media and analytics identifiers. Payment records are detached from the profile and retained only where accounting, tax or legal-defense rules require it.

7. International transfers

Most data is processed in the EU. For sub-processors operating outside the EU (e.g. CCBill in the United States, Cloudflare, Agora), transfers are covered by the European Commission Standard Contractual Clauses (SCCs) and supplementary technical measures (encryption in transit and at rest, pseudonymization where feasible).

8. Security

We apply appropriate technical and organizational measures including TLS 1.2+ for all traffic, encryption at rest for media (R2) and database backups, hashed passwords (bcrypt), HttpOnly Secure session cookies, role-based access control, audit logging of sensitive operations, and periodic security reviews. No online service can guarantee absolute security. Messages are protected in transit but are not end-to-end encrypted because the limited access described above is required for operation and safety.

9. Children

The Service is strictly intended for adults (18+). We do not knowingly collect personal data from minors. If we become aware that a minor has created an account, we immediately suspend and delete it and notify the relevant authorities.

10. Contact

For any privacy-related request, contact us: