Privacy Policy
How OjoosCo Ltd collects, uses, stores, and protects
your personal data when you use the Xparience
platform — in full compliance with UK GDPR and the
Data Protection Act 2018.
Section 01
Who We Are
OjoosCo Ltd is the data controller for personal data collected through the Xparience platform. This means we determine the purposes and means by which your personal data is processed.
If you have any questions about this policy or how we handle your data, please contact us at the email address above.
Section 02
Personal Data We Collect
We collect the following categories of personal data when you use Xparience:
2.1 Account and Identity Data
- Full name
- Date of birth
- Email address
- Phone number
2.2 Identity Verification Data Special Category
As part of our mandatory onboarding verification process, we collect:
- Government-issued photo ID (e.g., passport, driving licence)
- A real-time selfie or facial scan for identity matching
- Biometric data derived from facial recognition processing, used solely to verify your identity and confirm you are 18 or over
2.3 Profile Data
- Profile photographs uploaded by you
- Biography and personal description
- Gender identity and sexual orientation (provided voluntarily)
- Relationship preferences and intentions
- Location (city or general area, as provided by you)
- Occupation and lifestyle information (provided voluntarily)
2.4 Matching and Usage Data
- Profiles you match with
- Messages and communications sent through the platform
- Preferences and filters you apply
- Features and pages you interact with
- Time and frequency of platform use
2.5 Technical Data
- IP address
- Device type, operating system, and browser information
- Unique device identifiers
- Cookies and similar tracking technologies (see Section 10)
- App version and crash reports
2.6 Payment Data
If you subscribe to a paid tier, payment is processed by our third-party payment provider. We do not store your full card details. We retain only transaction records (amount, date, and subscription tier) for accounting and fraud-prevention purposes.
2.7 Communications and Support Data
- Messages you send to our support team
- Reports you submit about other users
- Feedback and survey responses
Section 03
Special Category Data
Xparience processes certain categories of personal data classified as “special category data” under Article 9 of the UK GDPR. These require a higher level of protection and a specific legal basis.
The special category data we process includes:
- Sexual orientation and relationship preferences — provided voluntarily by you as part of your profile
- Biometric data — facial images and derived biometric identifiers used solely for identity and age verification during onboarding
- Inferred data about sex life or sexual preferences — which may be inferred from your matching behaviour and preferences on the platform
Section 04
How and Why We Use Your Data
The table below sets out the purposes for which we process your personal data, together with our legal basis under Article 6 of the UK GDPR and, where applicable, the special category condition under Article 9.
| Data Category | Purpose | Legal Basis (Art. 6) | Special Category (Art. 9) |
|---|---|---|---|
| Account & Identity Data | Creating and managing your account; authentication | Contract (Art. 6(1)(b)) | N/A |
| Identity Verification (Biometric & ID) | Age verification; identity confirmation; fraud prevention; Online Safety Act compliance | Legal obligation + Legitimate interests (Art. 6(1)(c)(f)) | Explicit consent (Art. 9(2)(a)) |
| Profile Data (general) | Displaying your profile to other users; enabling matching | Contract (Art. 6(1)(b)) | N/A |
| Sexual orientation / relationship preferences | Enabling compatibility matching; personalising experience | Explicit consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| Matching & Usage Data | Improving match quality; platform analytics; personalisation | Legitimate interests (Art. 6(1)(f)) | N/A |
| Technical Data | Platform security, bug fixing, and performance monitoring | Legitimate interests (Art. 6(1)(f)) | N/A |
| Payment Data | Processing subscriptions; fraud prevention; financial records | Contract + Legal obligation (Art. 6(1)(b)(c)) | N/A |
| Communications Data | Responding to support queries; resolving disputes; ensuring safety | Legitimate interests + Legal obligation (Art. 6(1)(f)(c)) | N/A |
| Messages between users | Enabling communication on the platform; safety moderation | Contract (Art. 6(1)(b)) | N/A |
We will only use your personal data for the purposes set out above. If we need to use your data for a new purpose, we will notify you and seek fresh consent where required.
Section 05
Identity and Age Verification
Xparience requires all users to complete a mandatory identity and age verification check before accessing the platform. This is a legal requirement under the UK Online Safety Act 2023 and Ofcom’s age assurance guidance.
5.1 How Verification Works
We use a hybrid verification model to confirm user identity. Some submissions are processed automatically through a trusted third-party identity verification provider, while others are reviewed manually by our internal team.
As part of the verification process, you may be required to:
- Upload a valid government-issued photo ID (such as a passport, driving licence, or national identity card); and
- Complete a real-time selfie check, which will be compared against your ID using facial recognition technology.
We may also carry out additional manual reviews where necessary to verify authenticity or investigate potential issues.
5.2 How Biometric Data Is Handled
- Your facial biometric data is processed by our third-party provider solely to verify your identity and confirm you are 18 or over
- Our third-party provider operates as a data processor on our behalf under a written Data Processing Agreement
- Biometric templates and raw facial data are not retained by OjoosCo Ltd beyond what is necessary for the verification process
- A record that verification was completed, and its outcome, is retained on your account
- Your ID document image is retained only for the minimum period required for compliance and dispute resolution, after which it is deleted
5.3 Your Consent
Before submitting your verification documents, you will be asked to provide explicit consent to the processing of your biometric data. This consent is separate from your general account consent and is specific to identity verification.
Section 06
Who We Share Your Data With
We share your data only in the following limited circumstances:
6.1 Other Xparience Users
Your profile information (photos, bio, preferences, and general location) is visible to other verified users. Your full name, contact details, and identity documents are never visible to other users.
6.2 Service Providers (Data Processors)
We share data with trusted third-party providers who process data on our behalf under written Data Processing Agreements. These include:
- Identity verification provider
- Cloud hosting and infrastructure providers
- Payment processing provider
- Email and communications platform
- Analytics and performance monitoring tools
- Customer support platform
All processors are required to handle your data securely, only for the purposes we specify, and in compliance with UK GDPR.
6.3 Human Matchmakers and Coaches
Xparience offers an Elite tier that includes bespoke human-assisted matchmaking and coaching services. If you subscribe to this tier, we may share relevant profile information with our vetted matchmaking and coaching team (with your consent). These team members are bound by confidentiality obligations and data protection policies.
6.4 Legal and Regulatory Obligations
We may disclose your personal data where required by law, including in response to lawful requests from law enforcement or regulatory authorities, or to protect the rights and safety of our users.
6.5 Business Transfers
In the event of a merger, acquisition, or sale of our business, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Section 07
International Data Transfers
OjoosCo Ltd is incorporated in the United Kingdom. Some of our service providers may process data outside the UK. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- Transfer to countries with a UK adequacy decision; or
- Use of the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses; or
- Other appropriate safeguards recognised under UK GDPR Article 46.
You may request details of the safeguards we use for international transfers by contacting us at the email address in Section 15.
Section 08
How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account data | Duration of active account, plus 2 years after account closure |
| Identity verification records | Verification outcome: retained while account is active. ID document images: deleted within 30 days of successful verification |
| Biometric data | Deleted by third-party provider immediately after verification is complete. Not retained by OjoosCo Ltd. |
| Profile and matching data | Duration of active account. Deleted within 30 days of account closure |
| Messages between users | Retained for 12 months after the conversation ends, then deleted |
| Payment records | 6 years— required by UK tax and financial regulations |
| Support and communications data | 3 years from the date of the communication |
| Legal hold data | Duration of legal proceedings or regulatory investigation, then deleted |
When your data is no longer required, we will securely delete or anonymise it in accordance with our internal data retention policy.
Section 09
Your Rights
Under UK GDPR, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month.
Right 9.1
Right of Access
Request a copy of the personal data we hold about you (a Subject Access Request). This is free of charge.
Right 9.2
Right of Rectification
If data we hold is inaccurate or incomplete, you have the right to ask us to correct it. Most profile data can be updated directly in the Xparience app.
Right 9.3
Right of Erasure
Request deletion of your personal data in certain circumstances — where data is no longer necessary, you withdraw consent, or you object to processing.
Right 9.4
Right of Restrict Processing
Ask us to restrict processing of your personal data in certain circumstances, for example while we verify the accuracy of disputed data.
Right 9.5
Right of Data Portability
Where processing is based on consent or contract and carried out by automated means, receive your data in a structured, machine-readable format.
Right 9.6
Right of Object
Object to processing based on legitimate interests or for direct marketing purposes. If you object to marketing, we will stop immediately.
Right 9.7
Automated Decision-Making
Our compatibility matching assists in suggesting profiles but does not make final decisions about who you can connect with. You have the right not to be subject to purely automated decisions with significant effects.
Right 9.8
Right to Withdraw Consent
Where we rely on your consent, you have the right to withdraw it at any time. Contact us or use your account settings.
9.9 Right to Lodge a Complaint
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact us first.
Section 10
Cookies and Tracking Technologies
Xparience uses cookies and similar tracking technologies on our website and in our app. We use:
- Essential cookies — necessary for the platform to function (e.g., keeping you logged in)
- Analytical cookies — help us understand how users interact with the platform so we can improve it
- Preference cookies — remember your settings and preferences
We do not use advertising or tracking cookies for third-party marketing purposes.
When you first visit our platform, you will be shown a cookie consent banner. You can manage your cookie preferences at any time through your account settings or browser settings. Rejecting non-essential cookies will not prevent you from using the platform.
Section 11
Data Security
We implement appropriate technical and organisational measures to protect your personal data. Our security measures include:
- Encryption of data in transit (TLS) and at rest
- Strict access controls and role-based permissions for staff
- Regular security assessments and vulnerability testing
- Secure password storage using industry-standard hashing algorithms
- Data Processing Agreements with all third-party processors
- Staff training on data protection obligations
Section 12
Children’s Data
Xparience is strictly an adults-only platform. We do not knowingly collect or process data from anyone under the age of 18. Our mandatory identity and age verification process is specifically designed to prevent minors from accessing the platform.
Section 13
Third-Party Links and Services
The Xparience platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing any personal data.
Section 14
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by displaying a prominent notice on the platform before the changes take effect.
The effective date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically.
Section 15
How to Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please contact us:
We aim to respond to all privacy-related enquiries within five business days, and to resolve them fully within one calendar month.