Privacy
What we collect, why we collect it, how long we keep it, and what you can make us do about it.
Draft for review — not yet legally signed off. The 4 highlighted items below still need real values before this policy can be published, and it is awaiting review by a qualified Irish/EU data-protection lawyer.
Last updated: to be confirmed before publication
Data Controller: to be confirmed before publication
Contact (Data Protection queries): privacy@kinklink.ie
Supervisory Authority: Data Protection Commission (DPC), Ireland — https://www.dataprotection.ie
1. Who we are
KinkLink (“we”, “us”, “the Service”) is a platform for the Irish kink/BDSM/alternative-lifestyle community to connect, communicate, and organise events. This policy explains what personal data we collect, why, how long we keep it, and your rights over it.
2. Special-category data — read this first
KinkLink processes data that reveals or implies your sexual orientation and sex life (kink/BDSM interests, relationship structure, profile photos, messages). Under GDPR Article 9, this is special-category data and requires a higher standard of protection and a specific legal basis.
Our legal basis for processing special-category data is your explicit consent (Article 9(2)(a)), obtained when you:
- create a profile and select interests/kinks,
- upload photos or verification documents,
- opt in to any explicit-content features.
You may withdraw this consent at any time by deleting your account or the specific content (see §8, Your Rights).
3. What we collect
| Category | Examples | Special category? |
|---|---|---|
| Account data | email, password (hashed), registration role | No |
| Profile data | display name, age/DOB, gender, location, bio, relationship structure | Partially (relationship structure may imply orientation) |
| Interests/kinks | selected tags from our interest list | Yes |
| Photos & media | profile photos, album images, posts, event images | Yes (may depict sexual context) |
| Verification data | selfie, government ID (photo/scan) | Yes (also special category under separate grounds — identity verification) |
| Messages | direct messages, group messages, reactions | Yes (content may reveal orientation/interests) |
| Usage data | login times, device/browser info, IP address | No |
| Payment data | handled by our payment processor — we do not store full card numbers | No (processor-held) |
| Cookies | session cookie (kl_token, httpOnly), preference cookies |
No |
4. Why we process your data (purposes & legal bases)
| Purpose | Legal basis |
|---|---|
| Providing the core service (profiles, matching, messaging) | Contract (Art 6(1)(b)) + Consent for special-category elements (Art 9(2)(a)) |
| Age/identity verification | Consent (Art 9(2)(a)) + Legal obligation where applicable (Art 6(1)(c)) |
| Trust & safety (moderation, abuse reports, blocking) | Legitimate interest (Art 6(1)(f)) — protecting users from harm |
| Payments (premium features) | Contract (Art 6(1)(b)) |
| Security & fraud prevention | Legitimate interest (Art 6(1)(f)) |
| Legal compliance (e.g. responding to a lawful request) | Legal obligation (Art 6(1)(c)) |
| Service communications (password reset, notifications) | Contract (Art 6(1)(b)) |
| Marketing (if opted in) | Consent (Art 6(1)(a)) |
5. Who we share data with (processors)
We use the following processors to run the Service. Each is bound by a Data Processing Agreement (DPA) — see docs/legal/DPA-TRACKER.md for status.
| Processor | Role | Location | Data involved |
|---|---|---|---|
| Hostinger | Application hosting (VPS) | Manchester, United Kingdom | All data in transit/at rest on the app server |
| MongoDB Atlas | Database hosting | AWS eu-west-1 (Ireland) | All stored account/profile/message data |
| Bunny.net | Media storage & CDN | EU (Frankfurt storage; CDN is global edge — see §6) | Photos, verification documents |
| (none — self-hosted) | Transactional email | Same VPS (Manchester, UK) | We run our own mail server; no third-party email provider receives your address or message content |
| Stripe | Payment processing | to be confirmed before publication | Payment/billing data |
We do not sell personal data. We do not share special-category data with advertisers.
6. International data transfers
Your data is stored in the European Union: the database in Ireland (MongoDB Atlas) and media in Frankfurt (Bunny.net storage).
Two elements reach beyond the EU, and we disclose both:
- Application hosting runs on a server in Manchester, United Kingdom. The UK is covered by the European Commission’s adequacy decision for the UK (2021), so no additional transfer mechanism is required.
- Media delivery. Bunny.net’s CDN copies files to edge servers worldwide so that images load quickly wherever you are, which can mean a copy of a photo is cached on a server outside the EEA. This is caching for delivery, not storage of record — the authoritative copy stays in Frankfurt. These transfers are covered by the Standard Contractual Clauses in our agreement with Bunny.net.
7. Data retention
| Data | Retention |
|---|---|
| Account data | Until you delete your account, or after 180 days without logging in. We email you at 180 days to say the account will be deleted in 30 days, again with 7 days left, and again with 1 day left. Logging in at any point during that notice period cancels the deletion, and we confirm that by email. |
| Verification documents (ID/selfie) | Deleted 30 days after the verification is approved. We keep the verified/not-verified outcome, not the documents. |
| Messages | Until account/conversation deletion |
| Deleted account data | Profile, posts and comments are hidden immediately on request and permanently erased 40 days later (cancellable by logging back in during that window). Messages the user sent are retained so the other party’s copy of the conversation stays intact. Except where retention is required by law. |
| Backups | Nightly database backups on a rolling 7-day retention. Deleted data disappears from backups as that window rolls over. |
8. Your rights
Under GDPR, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure (“right to be forgotten”) — request deletion of your data.
- Restriction — limit how we process your data.
- Portability — receive your data in a portable format.
- Object — object to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Complain — to the Data Protection Commission (dataprotection.ie) if you believe your rights have been violated.
Access and portability are self-service in the app: Settings → Download my data. Erasure is self-service too: Settings → delete your account (40-day cancellable window, then permanent erasure). Both were verified live on dev 2026-08-12. For anything else, contact privacy@kinklink.ie.
9. Data security
We use encryption in transit (HTTPS/TLS) and at rest where applicable (verification documents are encrypted with AES-256-GCM before storage). Access to production systems is restricted. to be confirmed before publication
10. Children
KinkLink is strictly for users aged 18 and over, and we do not knowingly collect data from minors.
Age is checked in two places. At registration, your date of birth is required and accounts under 18 are refused. Beyond that, verification is reviewed by a person, not by software: a member of our team looks at the submitted photo of the account holder, and where age is in any doubt, we ask for government-issued ID before the account is verified. An account that fails these checks is not verified and is removed.
If you believe a minor is using KinkLink, contact privacy@kinklink.ie and we will act on it.
11. Cookies
We use one cookie: kl_token (httpOnly, secure), which keeps you logged in. It is strictly necessary for the Service to work, so under the ePrivacy rules it does not require a consent banner — and we do not show one.
We use no analytics, advertising or tracking cookies, and no third-party trackers. If that ever changes, we will ask for your consent first.
12. Changes to this policy
We will notify you of material changes by email to your registered address and by a notice in the app, and update the “Last updated” date above.
13. Contact us
- Privacy and data-protection queries, including any request under §8: privacy@kinklink.ie
- General support: support@kinklink.ie
We have not appointed a Data Protection Officer; we are not required to at our current scale. If that changes, this section will name them.