EliteCompanion
Iniciar sesiónPublicar perfil

Privacy Policy

Last updated: 26 August 2026

1. Who Is Responsible For Your Data

elitecompanion.cc ("the Platform", "we", "us") is an advertising directory for independent adult service providers. This policy explains what personal data we process, why, how long we keep it, and what you can require of us. It applies to Advertisers, to Clients with accounts, and to visitors.

The Platform is operated by EliteCompanion OÜ, a private limited company registered in Estonia under registry number 17305780, with its registered office at Tornimae tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia. It is the controller of the personal data described here.

Data protection contact: [email protected], or the support section of your dashboard. We have not appointed a Data Protection Officer, as we are not required to; data protection matters are handled at the address above.

2. Data You Give Us

Account: your email address, a password stored only as a bcrypt hash, and optionally a phone number. A phone number does not have to be unique to you, because agencies advertise several people from one number.

Advertiser profile: everything you choose to publish — working name, age, city, description, rates, services, languages, availability, contact details, photos and video. This is published deliberately and is visible to anyone.

Client accounts: the profiles you save, and any review you write.

Support: whatever you write to us, including attachments.

3. Data We Create About You

Verification results: whether each check passed, when, a confidence score, and the reason for any failure.

Photo analysis: a perceptual hash of every uploaded photo, used to detect the same image being reused across accounts, and a similarity score between each photo and your verification video.

Technical and security records: IP address, browser user agent, and administrative actions taken on your account, written to an audit log. Approximate country from your IP address, used to show relevant cities.

We do not run advertising trackers, cross-site tracking, or third-party analytics.

4. Identity And Age Verification

Advertisers must show they are a real adult advertising themselves. This is the only part of the Platform that processes biometric data, and it works as follows.

Your identity document is checked by Didit, our verification partner. We never receive or store the document itself. We keep the outcome and the fact that you are over 18.

You record a short verification video. One frame is taken from it and compared with your profile photos, so that the person advertised is the person verified. The video and the frame are held in private storage, are never published, and never appear on your profile.

A mathematical representation of your face — a face vector, not an image — is held in an Amazon Rekognition collection so we can tell whether the same person is already verified under a different account. It cannot be turned back into a photograph.

5. Why We Are Allowed To Process It

Running your account, publishing what you submit, and sending transactional email: performance of a contract, Art. 6(1)(b) GDPR.

Verifying that Advertisers are adults advertising themselves: legal obligation and substantial public interest in preventing the exploitation of minors and trafficking, Art. 6(1)(c) and Art. 9(2)(g). The biometric element additionally relies on your explicit consent, Art. 9(2)(a), which you give before verification starts.

Fraud prevention, duplicate detection, moderation and platform security: legitimate interests, Art. 6(1)(f).

Responding to law enforcement: legal obligation, Art. 6(1)(c).

6. Who Else Sees It

Cloudflare, for hosting, media delivery and email relay. Amazon Web Services, for facial comparison and duplicate-identity detection. Didit, for identity document and age verification. Hostkey, which provides the servers the Platform runs on, located in the Netherlands. TronGrid, a public blockchain API we query about transfers to our own payment address.

Each acts on our instructions under a data processing agreement. We do not sell personal data, and we do not share it for anyone else's marketing.

We disclose data to public authorities where the law requires it, or where it is necessary to protect someone from serious harm.

7. Payments

Paid features are bought with USDT on the TRON network. There is no card, bank account, or hosted checkout involved, so we never see or hold payment credentials of any kind.

When you buy something we create an invoice recording what it was for, the price, the exact amount to send, and the address to send it to, which is ours. A background process watches for transfers arriving at that address and matches yours by its exact amount. We record the transaction hash, the amount and the time.

We do not ask for, collect, or store the wallet you pay from.

What we cannot control is the blockchain itself. A TRON transaction is public and permanent by design: the transfer, its amount, and the wallet it came from are visible to anyone, forever, and no one — including us — can delete or amend that. Bear it in mind when choosing which wallet to pay from.

We query TronGrid, a public blockchain API, for transfers to our own address. We do not send TronGrid anything about you.

8. Transfers Outside The EEA

The servers running the Platform are located in the Netherlands, within the European Economic Area.

Amazon Web Services and Cloudflare process data outside the European Economic Area, including in the United States. Those transfers rely on the European Commission Standard Contractual Clauses, together with encryption in transit and at rest. Ask us and we will provide a copy of the safeguards that apply.

9. How Long We Keep It

Your account and profile: while the account exists. Deleting the account deletes the profile, its photos and its videos.

The verification video frame: deleted automatically 30 days after it is captured, together with the stored file, and the deletion is written to our audit log. This runs on a schedule rather than depending on anyone remembering.

Photo hashes: kept after a photo is removed, so an image already found to be stolen cannot simply be uploaded again.

Audit records: kept as a security and accountability record, including after an account is deleted.

Reviews: a review is content about an Advertiser as well as about its author, so it is not automatically removed with the author's account.

10. Automated Processing

Face comparison and duplicate detection run automatically and produce scores, and a photo can be marked as matching without a person looking at it. No profile is published, refused, or has its verified status settled by automation alone: a person reviews every profile before it goes live, and an administrator can overrule any automated result and must record a reason for doing so. You may ask for the reasoning behind a decision and contest it.

11. Your Rights

You may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. You may withdraw consent to biometric processing at any time. Because verification is a condition of advertising, withdrawing it means a profile can no longer stay published.

Advertisers can edit or remove a profile at any time, hide individual photos, or blur a face while leaving the photo published.

Ask through the support section of your dashboard or at [email protected]. We answer within one month. You can also complain to the data protection authority where you live or work.

12. Security

Traffic is encrypted with TLS and the Platform is served with HSTS preloading. Passwords are hashed with bcrypt. Verification media is held in private storage with no public address, reachable only through short-lived signed links issued to you or to a reviewer. Published photos are watermarked. Administrative actions are logged against the administrator who took them.

A vulnerability disclosure contact is published at /.well-known/security.txt.

13. Changes

The date below changes whenever this policy does. Where a change materially affects how we use data you have already given us, we will say so on the Platform rather than rely on you noticing.

See also our GDPR Declaration and Terms of Service.