Data Protection

How We Protect
Your Data

Your trust is our priority. This Data Protection Policy details the comprehensive technical and organizational measures we implement to safeguard your personal information at every stage of its lifecycle.

End-to-end encrypted
GDPR, CCPA & DPDPA compliant
72-hour breach notification
Last Updated: September 2026 · Effective Date: September 2026
Section 1

Our Commitment to Data Protection

At SetWed, we understand that trust is the foundation of any meaningful relationship — and that includes the relationship between our platform and our users. We are committed to the highest standards of data protection and privacy, ensuring your personal information is handled with the utmost care, transparency, and security.

This Data Protection Policy outlines how we implement technical and organizational measures to safeguard your data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Digital Personal Data Protection Act (DPDPA) of India.

Section 3

Data Minimization & Purpose Limitation

We adhere to the principle of data minimization, collecting only the personal data that is strictly necessary for the purposes for which it is processed. We do not collect excessive data, and we regularly review our data collection practices to ensure ongoing compliance.

  • We only collect data that is directly relevant to providing and improving our matchmaking services
  • We clearly define the purpose of each data collection point before implementation
  • We do not repurpose your data for uses incompatible with the original collection purpose without your explicit consent
  • We conduct regular data audits to identify and securely delete data that is no longer necessary
  • Profile data is compartmentalized — your sensitive preferences are never exposed to other users without your explicit control
Section 4

Technical Safeguards

We implement robust technical measures to protect your data against unauthorized access, alteration, disclosure, or destruction. Our security infrastructure is designed to meet and exceed industry standards.

  • AES-256 Encryption: All personal data is encrypted at rest using Advanced Encryption Standard with 256-bit keys
  • TLS 1.3 Protocol: All data transmitted between your device and our servers is encrypted using the latest Transport Layer Security protocol
  • End-to-End Encryption: In-app messages, voice calls, and video calls are protected with end-to-end encryption, meaning even SetWed cannot access your private conversations
  • Screenshot Prevention: Our application includes built-in screenshot prevention technology to protect your profile photos and conversations from unauthorized capture
  • Zero-Knowledge Architecture: Sensitive verification documents (e.g., ID uploads) are processed and immediately discarded after verification — we do not store copies
  • Intrusion Detection Systems: 24/7 automated monitoring detects and responds to potential security threats in real-time
  • Regular Penetration Testing: Independent security firms conduct quarterly penetration tests to identify and address vulnerabilities
Section 5

Organizational Measures

Beyond technical safeguards, we maintain comprehensive organizational measures to ensure data protection is embedded in our company culture and operations.

  • Data Protection Officer (DPO): We have appointed a dedicated Data Protection Officer who oversees all data protection activities and serves as the primary point of contact for data protection authorities
  • Staff Training: All employees undergo mandatory data protection training upon hiring and receive annual refresher training
  • Access Controls: Access to personal data is restricted to authorized personnel on a strict need-to-know basis, with role-based access controls (RBAC) enforced across all systems
  • Vendor Management: All third-party vendors and processors are subject to rigorous data protection assessments and are bound by Data Processing Agreements (DPAs)
  • Privacy Impact Assessments (PIAs): We conduct PIAs for all new features, products, or processes that involve the handling of personal data
  • Incident Response Plan: We maintain a comprehensive data breach response plan with defined roles, procedures, and escalation paths
Section 6

International Data Transfers

SetWed operates globally, and your data may be transferred to and processed in countries other than your country of residence. When transferring data internationally, we ensure appropriate safeguards are in place.

  • Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses for transfers to countries without an adequacy decision
  • Adequacy Decisions: Where possible, we transfer data only to countries that have been deemed to provide an adequate level of data protection
  • Binding Corporate Rules: Our internal data transfer framework ensures consistent protection across all SetWed entities
  • Data Localization: Where required by local law (e.g., India's DPDPA), we ensure that certain categories of data are stored and processed within the relevant jurisdiction
  • Transfer Impact Assessments: We conduct assessments for each international transfer to evaluate the laws and practices of the receiving country
Section 7

Data Retention & Deletion

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our data retention schedule is regularly reviewed and updated.

  • Active Account Data: Retained for the duration of your account's active status plus 30 days after account deletion to allow for account recovery
  • Communication Logs: In-app messages are retained for 90 days after deletion by both parties, then permanently erased
  • Verification Documents: Processed and deleted immediately after identity verification is complete — never stored long-term
  • Analytics Data: Anonymized and aggregated after 12 months — individual-level data is not retained beyond this period
  • Legal Hold Data: Data subject to legal proceedings or regulatory investigations is retained as required by law
  • Backup Data: Encrypted backups are retained for a maximum of 30 days and then permanently destroyed
Section 8

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we are committed to transparent and timely notification.

  • Regulatory Notification: We will notify the relevant data protection authority within 72 hours of becoming aware of a qualifying breach, as required by GDPR Article 33
  • User Notification: If the breach is likely to result in a high risk to your rights, we will notify affected users without undue delay via email and in-app notification
  • Breach Report: Notifications will include the nature of the breach, categories of data affected, estimated number of users impacted, likely consequences, and measures taken to address the breach
  • Remediation: We will take immediate steps to contain, investigate, and remediate any breach, and will implement measures to prevent recurrence
Section 9

Your Data Protection Rights

You have comprehensive rights regarding your personal data. We make it easy for you to exercise these rights directly through your SetWed account settings, or by contacting our Data Protection Officer.

  • Right of Access (Article 15 GDPR): Request a complete copy of all personal data we hold about you, delivered in a portable format within 30 days
  • Right to Rectification (Article 16 GDPR): Correct any inaccurate or incomplete personal data at any time through your profile settings
  • Right to Erasure (Article 17 GDPR): Request complete deletion of your personal data ("Right to be Forgotten") — we will process your request within 30 days
  • Right to Restrict Processing (Article 18 GDPR): Request that we limit the processing of your data while a complaint or request is being resolved
  • Right to Data Portability (Article 20 GDPR): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV)
  • Right to Object (Article 21 GDPR): Object to the processing of your personal data for direct marketing, profiling, or processing based on legitimate interests
  • Right Not to be Subject to Automated Decision-Making (Article 22 GDPR): Request human review of any significant decision made solely by automated processing, including our AI matching algorithm
Section 10

Regulatory Compliance

SetWed is committed to full compliance with all applicable data protection regulations worldwide. Our compliance framework covers:

  • GDPR (EU/EEA): Full compliance with the General Data Protection Regulation for all users in the European Union and European Economic Area
  • CCPA/CPRA (California): Compliance with the California Consumer Privacy Act and California Privacy Rights Act for California residents
  • DPDPA (India): Compliance with the Digital Personal Data Protection Act for Indian users
  • POPIA (South Africa): Compliance with the Protection of Personal Information Act for South African users
  • LGPD (Brazil): Compliance with the Lei Geral de Proteção de Dados for Brazilian users
  • PDPA (Southeast Asia): Compliance with applicable Personal Data Protection Acts across Southeast Asian jurisdictions
Section 11

Contact Our Data Protection Officer

If you have any questions, concerns, or requests regarding this Data Protection Policy or the handling of your personal data, please reach out to our Data Protection Officer.

dpo@setwed.com

Our Data Protection Officer is available to assist you with any data protection inquiry. We process all requests within 30 calendar days in accordance with applicable regulations.