Legal
Privacy Policy
Welcome to Azizam, a Persian dating app for Iranians around the world. This Privacy Policy outlines how we collect, use, store, and protect your personal information. By using our app or website, you consent to the terms outlined in this policy.
1. Introduction and Purpose
The data controller responsible for your personal data under this policy is:
- Company Name: Inno Lynx UG
- Address: Lerchenweg 40, 50829 Köln, Germany
- Email: support@azizamapp.com
- Managing Director: Ali Kroll
We value your privacy and are committed to protecting your personal information. This privacy policy explains how we collect, use, and safeguard your data when you use our app and website.
This Privacy Policy applies to all users of Azizam and governs the collection, processing, and use of personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
As a small startup, we are not currently required to appoint a Data Protection Officer. However, we are committed to safeguarding your personal data and ensuring compliance with all relevant regulations.
2. Types of Data Collected
We collect the following types of data when you use Azizam:
2.1 Personal Information Provided by Users
- Account Information: When you create an account, we collect your name, email address, date of birth, gender, profile photos, and any other information you voluntarily provide on your profile.
- Location Data: We collect your GPS location (optional but mandatory for profile creation) and your IP-based location to suggest matches nearby and manage access to the app in certain regions.
- User Communications: Any messages and communications within the app may be processed to provide the service, ensure security, and facilitate matching.
2.2 Automatically Collected Data
- Device and Usage Information: This includes IP address, device type, operating system, app usage statistics, browser type, and time spent on our website or app.
- Cookies and Tracking Technologies: We use cookies through Google Analytics and Cloudflare to track analytics and statistics. Users can opt-in or opt-out of each cookie category on our website.
2.3 Payment Information
We process payments using third-party payment processors, such as Google Pay, and Apple Pay. We do not store your payment information on our servers.
2.4 Analytics and Technical Data
We use Google Analytics, Cloudflare and New Relic for analytics and technical monitoring, such as tracking app performance and resolving technical issues.
3. Purpose of Data Collection
We collect and process user data for the following purposes:
- Account Creation and Maintenance: To allow users to create and maintain a profile on Azizam.
- Matching and Introductions: To match and introduce users to each other based on their profile information and location.
- User Communication: To enable communication between users through the app.
- Customer Support: To respond to inquiries, provide support, and resolve any issues users may encounter.
- Payment Processing: To facilitate payments for premium services through third-party payment processors.
- Authentication: To verify user identity and ensure account security.
- Marketing and Communications: To send marketing materials and other communications (only with user consent).
- Compliance with Legal Obligations: To comply with laws, prevent fraud, and meet other legal requirements.
4. Legal Basis for Processing Data
We process your personal data based on the following legal grounds:
4.1 Consent
We rely on your explicit consent to process certain types of data. This includes:
- Collecting your GPS location for matching purposes.
- Sending you marketing communications, newsletters, or notifications.
- Using cookies and similar tracking technologies for analytics, where you can opt-in or opt-out.
4.2 Contractual Necessity
We process your data as necessary to provide the services outlined in our terms of service, including:
- Creating and maintaining your account.
- Matching you with other users and enabling communication.
- Processing payments for premium features.
4.3 Legal Obligations
We are legally required to process certain data to comply with laws and regulations, such as:
- Retaining transaction data for tax and accounting purposes.
- Complying with anti-fraud laws and other legal obligations.
- Securing your personal data as required by data protection laws.
4.4 Legitimate Interests
We process data based on our legitimate interests, provided such interests do not override your privacy rights. Examples include:
- Improving our app performance and user experience through analytics (e.g., Cloudflare, Google Analytics, New Relic).
- Monitoring for fraudulent activities or breaches of our terms of service.
- Providing customer support and ensuring the security of your data.
4.5 Vital Interests
In rare cases, we may process your data to protect your vital interests or those of another person. This includes sharing information with law enforcement in emergency situations, such as when a serious crime is reported or imminent threats are identified.
4.6 Public Interest
In certain circumstances, we may be required to process your data for tasks carried out in the public interest, such as cooperating with authorities for public health or law enforcement purposes.
5. Data Sharing and Disclosure
We may share your personal data with the following third parties under specific circumstances:
5.1 Payment Processors
We use third-party payment processors to handle transactions for premium features. These processors handle your payment information securely and in compliance with their own privacy policies. The processors we use are:
- Google Pay
- Apple Pay
For more information, please review their respective privacy policies:
5.2 Cloud and Hosting Providers
We use the following cloud and hosting services to store and process user data:
- Google Cloud, Hetzner, and Cloudflare: We store sensitive user data (such as personal information) on servers located within the European Union to comply with data protection regulations.
- Cloudflare: Publicly shared user data, such as profile photos, is stored internationally on a Content Delivery Network (CDN) for improved global performance.
For more information, please review the privacy policies of these providers: - Google Cloud Privacy Policy
- Hetzner Privacy Policy
- Cloudflare Privacy Policy
5.3 Marketing and Advertising Partners
We use the following platforms to conduct marketing and deliver ads:
- Google Ads
- Facebook Ads
These services may receive non-personally identifiable information to help us reach users interested in our services. For more details, please review their privacy policies:
5.4 Legal Compliance and Security
We may also share data when required by law or to protect the rights, safety, or property of Azizam, its users, or others. This includes:
- Complying with legal obligations or court orders.
- Investigating and preventing fraud or security breaches.
6. User Rights
As a user of Azizam, you have several rights regarding your personal data, in accordance with data protection laws such as the General Data Protection Regulation (GDPR). These rights include:
6.1 Right to Access
You have the right to request access to the personal data we hold about you. This includes the right to receive a copy of your data and understand how we process and use it.
6.2 Right to Rectification
If any of your personal information is inaccurate or incomplete, you have the right to request corrections or updates to ensure its accuracy.
6.3 Right to Erasure (“Right to be Forgotten”)
You can request the deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected, or if you withdraw your consent for processing.
6.4 Right to Restrict Processing
You have the right to request the restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data or object to its processing.
6.5 Right to Data Portability
You can request a copy of your personal data in a structured, commonly used, and machine-readable format, and ask for it to be transferred to another service provider where technically feasible.
6.6 Right to Object
You have the right to object to the processing of your personal data for certain purposes, such as direct marketing or processing based on legitimate interests.
6.7 Right to Withdraw Consent
If we process your data based on your consent, you have the right to withdraw that consent at any time. This will not affect the legality of any processing based on your consent before its withdrawal.
6.8 Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to file a complaint with a data protection authority in your country or the country where your data is being processed.
7. Data Retention Policy
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, or contractual obligations. The retention periods for different types of data are as follows:
7.1 Account Information
We retain your account data, including your profile information, for as long as your account is active. If you choose to delete your account, we will delete or anonymize your personal data, except where retention is required by law (e.g., for tax purposes or legal claims).
7.2 Communications and Messages
Messages exchanged between users are retained while your account is active to ensure the proper functioning of the app. If your account is deleted, we will delete these communications unless retention is legally required or permitted.
7.3 Payment Information
Payment data is retained for a period necessary to complete the transaction and comply with legal obligations, such as tax and accounting requirements. Typically, financial records are retained for a minimum of 6 years as required by law.
7.4 Usage Data and Analytics
Data collected for analytics purposes, such as usage statistics from Google Analytics, Google Cloud and Cloudflare, is retained for as long as necessary to analyze trends and improve our services. This data is generally anonymized and retained for up to 26 months, as recommended by industry standards, unless a longer retention period is necessary.
7.5 Legal Obligations
We may retain your personal data to comply with legal obligations, such as:
- Tax records: Retained for a minimum of 6 years to comply with tax regulations.
- Fraud prevention and security: Retained for as long as required to detect, prevent, or mitigate fraud and ensure the security of the platform.
- Disputes and legal claims: If required, we may retain data to defend or pursue legal claims for the duration of the dispute and any applicable statute of limitations.
7.6 Marketing Data
Data collected for marketing purposes, such as email subscriptions, is retained for as long as you remain subscribed to our marketing communications. You may withdraw your consent or unsubscribe at any time, and your data will be deleted or anonymized unless otherwise required by law.
8. Security Measures
We implement a variety of robust security measures to ensure your personal data is protected from unauthorized access, alteration, or disclosure. Our security strategy includes the use of advanced encryption technologies and secure communication protocols.
8.1 Encryption
We use industry-standard encryption algorithms to protect your data:
- AES (Advanced Encryption Standard): Employed for secure data transmission.
- RSA (Rivest-Shamir-Adleman): Employed for secure data transmission.
- SSL/TLS (Secure Sockets Layer / Transport Layer Security): Communications between the app, website, and our servers are encrypted using these protocols to ensure secure data exchange.
8.2 Access Control
- We apply strict access controls, ensuring that only authorized personnel have access to your data. All access to sensitive information is logged and monitored.
8.3 Data Anonymization and Pseudonymization
Where possible, we anonymize or pseudonymize your data to reduce exposure in case of any unauthorized access.
8.4 Regular Security Audits
We conduct regular audits and vulnerability assessments to identify potential security risks and address them proactively.
8.5 Incident Response
In case of any suspicious activities or security incidents, we have procedures in place to investigate, mitigate, and respond promptly to ensure minimal impact on users.
9. Data Breach Notification
At Azizam, we prioritize the security of your personal data. However, in the unlikely event of a data breach, we have procedures in place to respond promptly and mitigate any potential harm.
9.1 Breach Identification and Assessment
If a data breach is suspected or identified, we will immediately investigate to determine the nature and extent of the breach, including which data has been compromised and the potential risks to affected users.
9.2 User Notification
If the breach is likely to result in a high risk to your rights and freedoms (e.g., identity theft, financial loss, or damage to your reputation), we will notify you without undue delay. This notification will include:
- A description of the breach and the type of data affected.
- Steps you should take to protect yourself, such as changing passwords or monitoring account activity.
- Our contact information for further assistance.
9.3 Authority Notification
In compliance with GDPR, we will report any significant data breaches to the relevant data protection authority within 72 hours of becoming aware of the breach. This will include the nature of the breach, the number of affected users, and the measures taken or planned to address it.
9.4 Remediation and Containment
Upon discovering a breach, we will take immediate action to contain the issue and prevent further unauthorized access. This may include:
- Securing affected systems.
- Resetting user account credentials.
- Enhancing our security measures to prevent similar incidents.
9.5 User Support
We will offer guidance and assistance to affected users, providing instructions on how to protect their accounts and personal data. Additionally, we will remain available for any further questions or support you may need during the process.
10. Children’s Privacy
Azizam is not intended for use by individuals under the age of 18. We do not knowingly collect or process personal data from anyone under 18 years of age. If we become aware that a user is under 18, we will take immediate steps to delete their account and remove any associated personal data from our systems.
If you believe that we may have inadvertently collected data from a minor, please contact us at support@azizamapp.com, and we will take prompt action to address the issue.
11. International Data Transfers
While the majority of personal data collected by Azizam is stored and processed within the European Union to comply with EU data protection regulations, we do utilize Content Delivery Networks (CDN) to improve the performance and availability of our services.
11.1 Public Data on CDN
Certain public data, such as user profile pictures, may be stored and cached on Cloudflare CDN servers located internationally. This allows for faster load times and improved access to our app and website across different regions. Although this data is available worldwide, it does not include any sensitive or private information.
11.2 Safeguards for International Transfers
We ensure that any international data transfers are conducted in accordance with the requirements of GDPR. Data is transferred using adequate safeguards, such as Standard Contractual Clauses (SCCs), to protect your information and ensure it receives an appropriate level of protection even when transferred outside the EU.
12. Changes to the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for any other operational reasons. When we make changes, we will:
- Post the updated policy on our website and app, along with the effective date of the revisions.
- Notify you of significant changes via email, using the address you provided during registration.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please feel free to contact us:
- Company Name: Inno Lynx UG
- Address: Lerchenweg 40, 50829 Köln, Germany
- Email: support@azizamapp.com
- Managing Director: Ali Kroll
We are here to assist you with any inquiries related to your privacy or data protection.
14. Supervisory Authority
If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority. In Germany, the relevant authority is:
Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Website: www.bfdi.bund.de
Address: Graurheindorfer Str. 153, 53117 Bonn, Germany
Telephone: +49 (0)228 997799-0
Email: poststelle@bfdi.bund.de
Alternatively, you can contact the data protection authority in your country of residence.