EliteCompanion
PrijavaObjavi profil

GDPR Declaration

Last updated: 26 August 2026

1. Data Controller

The controller of the personal data processed through elitecompanion.cc ("the Platform") is EliteCompanion OÜ, a private limited company registered in Estonia under registry number 17305780, with its registered office at Tornimae tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, Estonia.

Data protection contact: [email protected], or the support section of your dashboard. No Data Protection Officer has been appointed; the company is not required to appoint one, and data protection matters are handled at the contact above.

This declaration is issued under Regulation (EU) 2016/679 ("GDPR").

2. Scope

This declaration covers all personal data processed in connection with the Platform, for Advertisers, for Clients, and for visitors. It supplements our Privacy Policy, which sets out in detail what is collected, from where, and for how long. Where the two describe the same processing, they are written to say the same thing.

3. Legal Bases

Contract, Art. 6(1)(b): operating your account, publishing the profile you submit, and sending transactional email.

Legal obligation, Art. 6(1)(c): verifying that Advertisers are adults, keeping records we are required to keep, and responding to lawful requests from authorities.

Legitimate interests, Art. 6(1)(f): fraud prevention, duplicate-account detection, moderation, and platform security. We balance these against your interests and you may object at any time.

Explicit consent, Art. 6(1)(a) with Art. 9(2)(a): the biometric part of identity verification, described below. Substantial public interest, Art. 9(2)(g), additionally supports processing aimed at preventing the advertising of minors and trafficking.

4. Biometric Data And Explicit Consent

Verifying an Advertiser involves data that is biometric within the meaning of Art. 9(1) GDPR: the face in your identity document, the face in your verification video, a single frame taken from that video, and a face vector derived from it.

You give explicit consent before verification begins, on the verification screen, separately from accepting the Terms. The purpose is limited to confirming that you are a real person, at least 18 years old, advertising yourself, and not already verified under another account.

Biometric data is never published, never used for marketing, never used to profile you, and never shared other than with the processors named in section 6.

5. Withdrawing Consent

You can withdraw consent to biometric processing at any time through the support section of your dashboard or at [email protected].

On withdrawal we delete the verification video and any frame taken from it, and we remove your face vector from the duplicate-detection collection. Your verified status and badge are removed, and because verification is a condition of advertising, the profile can no longer remain published.

Withdrawal does not make earlier processing unlawful, and it does not remove records we are separately required to keep, such as the audit record showing that a deletion took place.

6. Processors

Didit — identity document and age verification. The document is submitted to Didit directly; we do not receive or store it.

Amazon Web Services — facial comparison between your verification frame and your photos, and the face-vector collection used for duplicate-identity detection.

Cloudflare — hosting, media delivery, and outbound email relay.

Hostkey — the servers on which the Platform runs, located in the Netherlands.

TronGrid — a public blockchain API, queried for transfers arriving at our own payment address. No personal data is sent to it.

Each is bound by a data processing agreement and acts only on our instructions.

7. Payments

Paid features are settled in USDT on the TRON network. No payment service provider is involved and no card or bank data is processed at any point.

We store an invoice against your account: what was bought, the price, the amount expected, the address it was payable to, and — once the transfer arrives — its transaction hash, amount and time. The wallet you pay from is not requested or retained by us.

Invoice records are kept for the period required by Estonian accounting and tax law, which is longer than the life of your account. This is a legal obligation under Art. 6(1)(c) GDPR, so it survives a deletion request.

Transactions on a public blockchain cannot be erased by anyone. Where you exercise the right to erasure we delete our own records on the schedule above; we cannot delete the on-chain transaction, and Art. 17(3)(b) preserves the accounting records regardless.

8. Transfers Outside The EEA

The servers on which the Platform runs are located in the Netherlands, inside the European Economic Area, so the hosting itself involves no third-country transfer.

Amazon Web Services and Cloudflare process personal data outside the European Economic Area, including in the United States. Those transfers are made under the European Commission Standard Contractual Clauses, supported by encryption in transit and at rest and by access controls limiting who can read verification media. A copy of the safeguards is available on request.

9. Retention

Account and profile data is kept while the account exists and is deleted when the account is deleted.

The verification video frame is deleted automatically 30 days after capture. The file is removed from storage, the reference is cleared, and the deletion is recorded in the audit log. This is enforced by a scheduled job, not by manual housekeeping.

Perceptual hashes of photos outlive the photos themselves, so that an image already identified as stolen cannot be re-uploaded. A hash cannot be used to reconstruct the image.

Audit records are retained as evidence of what was done to an account and by whom, including after deletion.

10. Automated Decision-Making

Automated comparison produces the scores used in verification, and a photo can be marked as matching without human involvement. No decision that publishes a profile, refuses one, or removes verified status is taken by automation alone. Every profile is reviewed by a person before it becomes public, an administrator can overrule any automated result and must record a reason, and you may ask for the reasoning and contest the outcome. Art. 22(1) GDPR therefore does not apply to these decisions.

11. Your Rights

Access, Art. 15. Rectification, Art. 16. Erasure, Art. 17. Restriction, Art. 18. Portability, Art. 20. Objection to processing based on legitimate interests, Art. 21. Withdrawal of consent at any time, Art. 7(3).

Exercise any of these through the support section of your dashboard or at [email protected]. We reply within one month and will tell you if we need longer, as Art. 12(3) permits. We do not charge for this.

12. Complaints

If you believe our processing breaches the GDPR you may lodge a complaint with the supervisory authority in the EU member state where you live, where you work, or where the alleged breach took place.

Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — [email protected], www.aki.ee.

13. Personal Data Breaches

If a breach is likely to result in a risk to your rights and freedoms we notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Art. 33. Where the risk is high, we also tell the people affected directly and without undue delay, under Art. 34.

See also our Privacy Policy and Terms of Service.