Biometric Data Notice and Policy
Version 1.0 · Aggiornato il 2026-08-04
Biometric Data Notice and Policy
iDeal DP — operated by Dynamic Dating Group, Inc.
Version 1.0 — Effective August 4, 2026
Published pursuant to the Illinois Biometric Information Privacy Act (740 ILCS 14/15), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), Chapter 19.375 RCW of the State of Washington, Article 9 of Regulation (EU) 2016/679 (GDPR), and applicable U.S. state privacy laws.
This American English version is the reference version.
1. Why This Notice Exists
iDeal DP's Identity Certification relies on analysis of your face. This is especially sensitive data, so we owe you a complete explanation and must obtain your explicit permission before any collection.
This notice describes exactly what we collect, why, how long we keep it, and how we destroy it.
Certification is entirely optional. You can use iDeal DP without ever going through it. You will not have access to certain features — notably reel publishing — and you will not carry the certified member badge.
2. What We Collect
| Item | Description | Legal characterization |
|---|---|---|
| Liveness selfies | Two images captured during a challenge: eyes open, then eyes closed | Facial image — biometric data |
| Facial template | A numerical representation of your facial geometry, in the form of a 512-dimension vector | Biometric identifier under BIPA and CUBI; biometric data under Article 9 GDPR |
| Government ID (optional) | Photograph of an official identity document, and the facial image it contains | Identity data and facial image |
The liveness challenge runs on your device. Face and eye-state detection is performed locally by an embedded library. Only the retained images and the computed template are transmitted to our servers.
3. Why We Collect It
We use this data for two purposes, and nothing else:
- To confirm that you are a real, living person, and that you match the document presented. This eliminates fake profiles built from stolen photos.
- To detect duplicate accounts — that is, to prevent the same person, particularly after a ban, from creating another account under a different identity. This is the role of the facial template: it is compared against templates already on file.
4. What We Do Not Do
These commitments are binding and enforceable.
- We do not sell, lease, trade, or otherwise profit from your biometric data. (Expressly prohibited by 740 ILCS 14/15(c).)
- We do not use it for any advertising, marketing, or targeting purpose.
- We do not use it to identify you outside the Service, in public spaces, or on other platforms.
- We do not use it to infer your ethnicity, age, health, emotions, orientation, or any other characteristic.
- We do not use it to train any general-purpose artificial intelligence model, and we prohibit our providers from doing so by contract.
- We do not disclose it, except in the limited cases listed in Section 6.
5. Your Consent
5.1 How it is obtained
Before any capture, a dedicated screen presents: the nature of the data, the purposes, the retention period, the destruction method, and your rights. You must take an affirmative action to consent. No box is pre-checked, and biometric consent is separate from acceptance of the Terms of Service.
This constitutes the written release required by 740 ILCS 14/15(b) and the explicit consent required by Article 9(2)(a) of the GDPR.
5.2 Proof of consent
We retain a record of your consent: the version of the notice accepted, the date and time, and the account identifier. This record is kept for the duration of processing plus the applicable limitations period.
5.3 Withdrawal
You may withdraw your consent at any time, from Settings → Privacy → Certification, or by writing to privacy@idealdp.com.
Effects of withdrawal: your biometric data is destroyed within the periods in Section 7, your certified status is revoked, and the badge is removed from your profile. Your account remains active. Withdrawal does not apply retroactively.
6. Who Can Access It
Internally: a limited number of named, authorized members of the verification team, with every access logged.
Externally, only:
| Recipient | Role | Safeguards |
|---|---|---|
| IONOS SE (Germany) — Hetzner Online GmbH (Germany) | Encrypted hosting and storage | Data processing agreement; no access to content for any other purpose |
| Identity verification provider (where applicable) | Technical processing of the application | Data processing agreement; reuse prohibited |
We disclose biometric data to a third party only in the following cases, consistent with 740 ILCS 14/15(d):
- with your consent;
- where disclosure completes a financial transaction you requested or authorized;
- where required by law or ordinance;
- pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
We do not voluntarily provide biometric data to law enforcement outside these cases.
7. How Long We Keep It — Retention and Destruction Schedule
This schedule is published pursuant to the requirement of 740 ILCS 14/15(a). It is binding.
| Data | Retention period | Destruction trigger |
|---|---|---|
| Liveness selfies | 30 days maximum | The certification decision, whether granted or denied |
| Government ID | 90 days maximum | The certification decision; extended where a dispute or appeal is pending, until it closes |
| Facial template (512 dimensions) | 1 year after certification expires, and in any event within one year of the date the initial purpose for collection has been satisfied | Expiry of certification, withdrawal of consent, or account deletion |
| Proof of consent | Duration of processing plus the applicable limitations period | — |
Early destruction. If you withdraw consent or delete your account, destruction occurs within 30 days, except where retention is required by law or by a pending proceeding.
How we destroy. Permanent deletion of files and database records, including within backups, following the backup rotation cycle — no later than 90 days after primary deletion. Destruction is irreversible: no recovery is possible.
8. How We Protect It
We apply to biometric data a standard of care at least as protective as, and in practice more protective than, the standard we apply to our other confidential information — the requirement of 740 ILCS 14/15(e).
- Storage in private buckets, encrypted at rest, accessible only through time-limited signed links.
- Servers located in Germany, in data centers certified to ISO/IEC 27001.
- Encryption in transit (TLS) across all exchanges.
- Role-restricted access, mandatory two-factor authentication, full logging of every access.
- Logical separation of templates from source images.
- No public exposure: this data is never displayed on a profile or visible to another member.
9. Your Rights
| You can | How |
|---|---|
| Learn whether we hold biometric data about you | privacy@idealdp.com |
| Obtain a copy or description of it | privacy@idealdp.com |
| Withdraw your consent | Settings → Privacy → Certification |
| Request its deletion | privacy@idealdp.com, or delete your account |
| Contest a certification denial | In-app appeal form |
Illinois. BIPA provides a private right of action: any person aggrieved by a violation of that statute may bring suit.
Texas and Washington. These statutes are enforced by the state Attorney General, with whom you may file a complaint.
European Union, EEA, United Kingdom, and Switzerland. You have all the rights described in Section 12 of our Privacy Policy, and the right to lodge a complaint with your supervisory authority.
Canada and Quebec. You may contact the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
10. Certification Decisions
A certification request is processed with the support of automated comparison tools, but the decision is always made by a person. No denial, revocation, or enforcement action results from solely automated processing.
A denial is explained and may be appealed to a person who did not make the original decision.
11. Changes to This Notice
Any material change is notified at least 30 days before it takes effect. Any expansion of purposes or extension of retention periods requires fresh explicit consent: your prior consent does not extend to it.
12. Contact Us
Dynamic Dating Group, Inc. 1111B S Governors Ave #3153, Dover, Delaware 19904, United States — +1 415 417-0755
| Purpose | Contact |
|---|---|
| Biometric data, access, deletion | privacy@idealdp.com |
| Legal matters | legal-eu@idealdp.com |
| European Union representative | Inga Metra — Latvia — — contact-us@idealdp.com |
Biometric Data Notice and Policy — version 1.0, effective August 4, 2026. This document supplements the Terms of Service and the Privacy Policy.