Privacy statement
Welcome to Breeze’s Privacy Statement! We’ve kept it clear and concise so you can quickly find what you need. Your trust is essential to us, and we’re committed to transparency—no confusing language or hidden fine print.
This Statement outlines what personal information we collect, how we process and protect it, and with whom we may share it. It applies to the Breeze app, available on the Apple App Store and Google Play Store (“App”), but also to our contractors, job applicants, leads and website visitors. We adhere to GDPR legislation as a standard for everyone, but we also specifically mention the rights of users within the European Union (EU) and the United Kingdom (UK).
We recommend reading this Privacy Statement alongside our User Terms, as they complement each other.
Table of Contents
- About Us
- Information We Collect About You
- Legal Justifications We Rely on to Use Your Data
- How We Use Your Data – App Users
- How We Use Your Data – Contractors
- How We Use Your Data – Job Applicants
- How We Use Your Data – Leads
- How We Use Your Data – Website Visitors
- How Your Personal Data Is Collected
- Data sharing with Third Parties: Recipients & Processors
- International Transfers
- Data Security
- Data Retention
- Automated Decision Making and Profiling
- Your Legal Rights within the EU and UK
- Do Not Track Settings
- Rights Of California Residents
- Third-Party Links
- Amendments to this Statement
Cookie Statement Table of Contents:
1. About Us
The App is provided through two legal entities, depending on your location, and is operated from the EU:
- Europe and United Kingdom: Breeze Social B.V., Stationsplein 45, 3013 AK Rotterdam, The Netherlands
- United States: Breeze Social Inc., 228 East 45th Street, Suite 9E, New York, NY 10017, United States
Breeze Social Inc. does not receive or have access to the personal data of users in Europe and the United Kingdom. We apply GDPR standards to the processing of personal data, regardless of where you are located. Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, we implement appropriate safeguards as described in the section “International Transfers”.
We take privacy seriously and have dedicated contacts to ensure your data is handled responsibly:
- General privacy questions and data protection complaints: privacy@breeze.social. We will acknowledge complaints promptly, and no later than 30 calendar days from receipt.
- Privacy rights requests (including access, correction, deletion, restriction, objection, or data portability requests): please use our secure GDPR Request Portal, run by EUverify, an independent party that verifies your identity and monitors how we handle your request: https://gdpr.euverify.com/verify/5d7a9302-6cda-46d9-a7d0-bd6129df6293
- Data Protection Officer (DPO): Our DPO independently oversees our compliance with data protection laws and can be contacted regarding privacy concerns or complaints at breeze.dpo@techgdpr.com.
UK GDPR Representative (Article 27)
If you are located in the United Kingdom, you may also contact our appointed UK GDPR Representative:
Euverify Ltd (UK) 3rd Floor, 86-90 Paul Street London EC2A 4NE United Kingdom
Email: gdpr@euverify.com
2. Information We Collect About You
We may collect and process the following general categories of personal data:
| Category | Examples |
|---|---|
| Contact Details | Name, email address, mobile number, address, phone numbers you add to your personal blocklist. |
| Financial Data | Billing address, payment details (handled by our payment providers), bank account details. |
| Activity and Behavioural | Clicks, (dis)likes, interests, preferences, date availability. |
| Personal Characteristics | Gender (man, woman or non-binary), pronouns (so we can address you correctly in our messages), date of birth, education, physical attributes like height. |
| Location Data | GPS-location, preferred cities to date in. |
| Communications Data | Messaging data, match communication, social media post comments. |
| Images and Recordings | Photos, videos, profile pictures, the selfie used for profile verification. |
| Views and Opinions | Survey responses, testimonials, feedback and ratings you give about dates, and opinions or free text you share. |
| Technical Identifiers | IP address, advertising ID and other device identifiers (e.g. Android ID), passwords (partner accounts), device information (e.g., operating system, language). |
| Work-related Data | For contractors and job applicants: CV, work experience, occupation, completed tasks and timesheets. |
| Identifiers and Legal Documents | For contractors: identity documents and tax or social-security numbers needed for payment and payroll. |
| Aggregated Data | Statistical data or usage patterns not directly identifying you. |
We also collect and process certain special-category (sensitive) personal data that you explicitly provide, and only with your explicit consent. You provide it through designated profile fields and preferences that you complete yourself — for example by selecting a tag, picking an option from a list, or indicating the gender(s) of the people you would like to meet. All of these fields are optional ways to express yourself or your preferences — you can leave them blank and add, edit or remove them at any time — with a single exception: the gender(s) you would like to be matched with (men, women and/or non-binary people), which we need for matchmaking and so cannot be left empty. If you would rather not express a preference there, you can simply select all options.
The special-category data you can provide is listed below. We aim to keep this list up to date, but the exact fields available may vary slightly depending on your app version:
- Sexual Orientation and Sex Life: your sexual orientation (for example straight, gay, bisexual, pansexual, asexual or demisexual), your gender identity (an optional tag, for example cisgender, transgender, non-binary or intersex), whether you identify as LGBTQI+, your relationship style (for example monogamous, non-monogamous or polyamorous), and the gender(s) of the people you would like to be matched with.
- Health-related Data: options you select from dedicated profile fields about disability or accessibility (for example use of a wheelchair or mobility aid, a visual or hearing impairment, a chronic illness, or being immunocompromised), neurodiversity and mental health (for example ADHD, autism, being highly sensitive, a learning disability, or mental-health challenges), your vaccination status, and your use of alcohol, tobacco, cannabis or drugs.
- Religious or Philosophical Beliefs: the religion or belief you select from a dedicated profile field (for example Christian, Muslim, Jewish, Hindu, Buddhist, Sikh, agnostic or atheist), including dietary choices that may reveal them (for example halal or kosher).
- Political Opinions: the political view you select from a dedicated profile field (for example left- or right-leaning, centrist, progressive, conservative, liberal or green).
- Biometric Data: the facial comparison made from the selfie you take for profile verification.
You may also choose to include information in open-text fields, such as your bio or your answers to our profile questions. The profile questions and prompts we offer are open-ended and do not ask you to reveal special-category data. However, if the text you provide itself reveals information such as your racial or ethnic origin, political opinions, religious or philosophical beliefs, health, or sexual orientation, that information may still constitute special-category personal data. We do not try to detect such information in open text and treat it like the rest of your open text: we show it to the people we suggest your profile to, we check it against our User Guidelines when your profile is reviewed, and we use it, together with the rest of your profile, to predict who you may like. We do not use open text to filter who you are shown.
Before your profile is published or used for matchmaking, we show you the profile you have created and ask for your explicit consent to process any special-category data it contains. You give this consent for one purpose: finding the best matches for you over time and showing your profile to them. You can edit your profile at any time. You can withdraw your consent at any time. For the optional fields, remove the information from your profile and we stop processing it. For the gender(s) you would like to be matched with, at least one must stay selected, because we need it to match you; to withdraw your consent for this completely, delete your Account and we will delete this data.
What that consent does not cover is just as important: we never use special-category data for advertising or to build advertising audiences, and we never sell it. The special-category data you select in our dedicated profile fields reaches only the recipients named at the end of Section 10, each for the specific purpose stated there.
If you voluntarily use our profile-verification feature, we process your selfie solely to confirm that you are the person shown in your profile photos. This feature is optional and is based on your explicit consent. You are not verified unless you choose to be: we may suggest profile verification, and you can also choose to verify from your profile at any time. Skipping it only means you don't get the verified badge and aren't shown to people who chose to see verified profiles only, and you can't choose to see only verified profiles yourself. If you have verified and change your mind, removing verification in the app withdraws that consent. The comparison is performed within the EU (Amazon Web Services, Ireland) and is momentary — we do not create or keep a facial template ("faceprint"), and no biometric data is retained after the check. We keep the verification selfie itself, as an ordinary photo, for as long as your profile is verified. When you remove verification or delete your Account, we delete it within 15 days, including from our backups.
In the coming sections, we break down how we use these categories of personal data, alongside the purpose for processing and the legal basis we rely on.
Information When Younger Than 18 Years
Our User Terms state that only people who are 18 years or older may use our App. If you are younger, we ask that you do not provide us with personal information. We do not knowingly collect personal information about individuals under 18. If we discover that someone under 18 has shared personal information, we will delete it and take steps to prevent circumvention of our age limit. This may mean keeping information such as your mobile number to prevent new account creation.
3. Legal Justifications We Rely on to Use Your Data
We process your information for the purposes described in this policy, based on the following legal bases:
- Consent: The individual has given clear consent for us to process their personal data for a specific purpose.
- Explicit Consent: For special-category data (see Section 2), you expressly agree to its use for a stated purpose. For example, at the end of creating your profile you tick "I agree that my profile, including sensitive details, will be published on the app and used for matching." You can withdraw this consent at any time.
- Legitimate Interests: We have a business or commercial reason to use your information, balanced against your rights.
- Contractual Obligations: Processing is necessary for a contract we have with you or steps requested by you before entering into a contract.
- Legal Obligations: Processing is necessary for us to comply with the law.
4. How we use your data – App Users
Regarding personal data:
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| B2C Email/Text Digital Marketing (existing customers) | Contact Details, Personal Characteristics, Views and Opinions | Legitimate Interests |
| Account Creation | Contact Details, Personal Characteristics | Contractual Obligations |
| Payment Processing & Financial Management | Contact Details, Financial Data | Contractual Obligations |
| Address Lookup | Contact Details, Location Data, Technical Identifiers | Contractual Obligations |
| Email Communications & Marketing | Contact Details, Personal Characteristics, Views and Opinions | Consent |
| Business Intelligence & Analytics | Contact Details, Technical Identifiers, Activity and Behavioural | Legitimate Interests to improve or update our services |
| Post-Date Feedback Collection | Contact Details, Views and Opinions | Legitimate Interests to improve or update our services |
| Conform with local law enforcement | Activity and Behavioural, Communications Data, Contact Details, Personal Characteristics, Views and Opinions | Legal Obligations |
| Dating Profile Creation & Customization | Contact Details, Images and Recordings, Personal Characteristics, Views and Opinions, Work-related Data | Contractual Obligations |
| Transactional Communications & Account Management | Contact Details, Personal Characteristics, Activity and Behavioural, Technical Identifiers | Contractual Obligations |
| Customer Support Services | Views and Opinions, Contact Details, Personal Characteristics, Images and Recordings | Contractual Obligations |
| IP-Based Localization | Technical Identifiers | Legitimate Interests to show location-appropriate content before you provide your address |
| IP-Based Tax Compliance (VAT) | Technical Identifiers | Legal Obligations (determining your country of payment for VAT) |
| Technical Error Monitoring | Activity and Behavioural, Technical Identifiers | Legitimate Interests to ensure service reliability |
| Content Moderation & Safety | Contact Details, Images and Recordings, Views and Opinions | Legitimate Interests to ensure user safety, platform integrity, and prevent violations of user terms & guidelines |
| Generate Personalized Profile Feedback | Views and Opinions, Images and Recordings | Consent |
| Maintain Blocked Account List | Contact Details | Legitimate Interests to ensure user safety, platform integrity, and prevent violations of community guidelines |
| Personal Blocklist | Contact Details | Legitimate Interests to let a user control who can see or be matched with them |
| Suggesting Compatible Profiles | Activity and Behavioural, Personal Characteristics | Contractual Obligations |
| Enable Checked Communication between Matched Users | Communications Data | Contractual Obligations |
| Improving and testing our matchmaking over time | Activity and Behavioural, Personal Characteristics | Contractual Obligations |
| Phone Number Authentication | Contact Details, Technical Identifiers | Contractual Obligations |
| User & Product Development Research | Views and Opinions, Contact Details, Technical Identifiers, Personal Characteristics | Legitimate Interests to improve or update our services |
| Profile Photo Verification | Images and Recordings | Consent |
| App Distribution Management | Activity and Behavioural, Technical Identifiers | Contractual Obligations |
| Date Reservation at Partnered Venues | Contact Details, Location Data, Technical Identifiers | Contractual Obligations |
| Date Scheduling | Activity and Behavioural, Contact Details, Views and Opinions | Contractual Obligations |
| Website/Webapp Tracking | Activity and Behavioural, Personal Characteristics, Technical Identifiers | Consent (see our Cookie Statement at the bottom of this Statement) |
| Organizing Events | Contact Details, Activity and Behavioural, Personal Characteristics, Financial Data | Contractual Obligations |
| Group Date Invitations & Curation | Personal Characteristics, Activity and Behavioural, Contact Details | Contractual Obligations |
| Objection & Moderation Case Management | Contact Details, Views and Opinions, Activity and Behavioural | Legitimate Interests to handle objections to our moderation decisions |
| Data Subject Rights Request Handling | Contact Details, Technical Identifiers | Legal Obligations (responding to your privacy rights requests) |
| Accounts Receivable | Contact Details, Financial Data, Technical Identifiers | Contractual Obligations |
Regarding special categories of personal data:
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| Account Creation | Sexual Orientation and Sex Life | Explicit Consent (matchmaking consent, Section 2) |
| Dating Profile Creation & Customization | Religious or Philosophical Beliefs, Political Opinions, Sexual Orientation and Sex Life, Health-related Data | Explicit Consent (matchmaking consent, Section 2) |
| Suggesting Compatible Profiles | Religious or Philosophical Beliefs, Political Opinions, Sexual Orientation and Sex Life, Health-related Data | Explicit Consent (matchmaking consent, Section 2) |
| Improving and testing our matchmaking over time | Religious or Philosophical Beliefs, Political Opinions, Sexual Orientation and Sex Life, Health-related Data | Explicit Consent (matchmaking consent, Section 2) |
| Profile Photo Verification | Biometric Data | Explicit Consent (verification consent, Section 2) |
| Business Intelligence & Analytics (evaluating how well our matchmaking works) | Religious or Philosophical Beliefs, Political Opinions, Sexual Orientation and Sex Life, Health-related Data | Explicit Consent (matchmaking consent, Section 2) |
| Group Date Invitations & Curation | Religious or Philosophical Beliefs, Political Opinions, Sexual Orientation and Sex Life, Health-related Data | Explicit Consent (matchmaking consent, Section 2) |
5. How we use your data – Contractors
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| Accounts Payable | Contact Details, Financial Data, Personal Characteristics | Legal Obligations |
| Ad-hoc Internal Generative AI Queries | Views and Opinions | Legitimate Interests for marketing or service purposes |
| Code Hosting & Collaboration | Contact Details, Technical Identifiers | Contractual Obligations |
| Digitally Signing Documents | Contact Details, Technical Identifiers | Contractual Obligations |
| Password and Credential Management | Technical Identifiers, Contact Details | Legitimate Interests |
| Payroll | Contact Details, Financial Data, Identifiers and Legal Documents | Contractual Obligations |
| Project Management | Work-related Data | Contractual Obligations |
| Timesheet & Shift Management | Contact Details, Work-related Data | Legal Obligations |
| Internal Communication | Communications Data, Contact Details | Legitimate Interests to communicate and collaborate with you |
6. How we use your data – Job Applicants
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| Candidate Assessment & Testing | Contact Details, Views and Opinions, Work-related Data | Legitimate Interests to process and review the application |
| Recruitment | Communications Data, Contact Details, Personal Characteristics, Work-related Data | Contractual Obligations |
| Talent pool | Contact Details, Personal Characteristics, Work-related Data, Communications Data | Consent |
| Recruitment Advertising & Candidate Sourcing | Contact Details, Work-related Data, Activity and Behavioural | Legitimate Interests to find suitable candidates |
7. How we use your data – Leads
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| B2B Email/Text Digital Marketing (prospective customers) | Contact Details, Views and Opinions | Consent |
| User & Product Development Research | Contact Details, Personal Characteristics, Technical Identifiers, Views and Opinions | Consent |
| Targeted Advertising | Activity and Behavioural, Contact Details, Location Data, Personal Characteristics | Consent |
| Partner Acquisition Outreach (cold outbound) | Contact Details, Views and Opinions | Legitimate Interests to contact businesses about a partnership |
8. How we use your data – Website visitors
| Purpose | Personal Data Category | Legal Justification |
|---|---|---|
| Consent Management | Activity and Behavioural, Technical Identifiers | Legal Obligations |
| Tag Management | Activity and Behavioural, Technical Identifiers | Consent (see our Cookie Statement at the bottom of this Statement) |
| Targeted Advertising | Activity and Behavioural, Contact Details, Location Data, Personal Characteristics | Consent (see our Cookie Statement at the bottom of this Statement) |
| Website Tracking/Webapp tracking | Activity and Behavioural, Technical Identifiers | Consent (see our Cookie Statement at the bottom of this Statement) |
9. How your personal data is collected
We use different methods to collect data from and about you, including through:
Direct interactions with you - you may give us information on inter alia your Contact Details, Financial Data, Personal Characteristics, Images and Recordings and the special-category profile fields described in Section 2 (all the categories that come through direct interactions) by filling in forms or by corresponding with us by post, phone, email, via our website, via our App or otherwise. This includes for example personal data you provide when you:
- apply for our products or services;
- use a device to access our services;
- create an account with us;
- subscribe to newsletters;
- request marketing to be sent to you; or
- give us feedback or contact us.
Automated technologies or interactions. - As you interact with our website, App and other services, we will automatically collect Technical Identifiers and Activity and Behavioural data about your equipment, browsing actions, and patterns.
From third parties and public sources. - We may also receive personal data about you from third parties, for example a service provider that determines your approximate location from your IP address, or from publicly available sources, for example a business's own website when we contact venues about a partnership. We only do this where we have a legal basis for it.
From other users. - If a user adds your phone number to their personal blocklist, we store that number so that you are not shown to or matched with that user, including if you join Breeze later.
10. Data sharing with Third Parties: Recipients & Processors
At Breeze, we understand that the personal information and data you share with us can be sensitive. That's why we handle sharing App User data carefully. Unlike some other dating apps, we do not sell data to third parties.
We only share personal data with third parties in the context of performing and improving our services and to comply with any legal obligations. If third parties are designated as processors, we have entered into a data processing agreement with them that regulates security, confidentiality, and your rights. We remain responsible for these processing activities. These various third parties are listed below:
The "Purpose" column states what we use each recipient for; Sections 4 to 8 set out, per purpose, which data we use and on which legal basis. All recipients in this table process personal data. If you use the Breeze app, the recipients marked "Yes" in the column "Processes app users' data?" are the ones that may process your data. Those marked "No" only process data of other people, such as our staff, contractors, job applicants or business contacts. Note that encrypting data does not take it outside the scope of the GDPR.
| Third Party | Purpose | Encryption | Data Residency | Processes app users' data? | Transfer Mechanism |
|---|---|---|---|---|---|
| Adyen (as independent controller) | Acquiring, KYC/AML and legal obligations; Adyen's own fraud and risk use of transaction data | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Adyen (as processor) | Accounts Receivable — processing payments on Breeze's instructions | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Airtable | Objection & Moderation Case Management, Partner Sign-up & Onboarding Management | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs 2021/914 Mod 2/3 + UK ICO IDTA + Swiss FADP |
| Amazon Web Services | Profile verification (momentary face comparison) | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Anthropic | Business Intelligence & Analytics, Ad-hoc Internal Generative AI Queries | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Mod 2/3 + UK Addendum + Swiss |
| AppsFlyer | Website Tracking/Webapp tracking | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Mod 2 + UK IDTA |
| BIJBVO | Accounts Payable, Accounts Receivable, Payroll | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Bookable | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | United Kingdom | Yes | N/A – within EEA/UK |
| Braze | B2C Email/Text Digital Marketing (existing customers), Customer Relationship Management (CRM), Transactional Emails, App messages (group-date invitations & reminders) | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | Hosted in the EU; DPF + EU SCCs Mod 2/3 + UK for access from the US |
| Brevo | Transactional & Marketing Emails | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| ClickUp | Internal Communication, Project Management | Encryption in Transit, Encryption at Rest | United States | No | EU SCCs Mod 2/3 + UK IDTA + Swiss |
| Cloudflare | Infrastructure & CDN (image caching & delivery) | Encryption in Transit, Encryption at Rest | Global edge | Yes | DPF-certified (EU/UK/Swiss) + EU SCCs Mod 2/3 + UK Addendum |
| DesignMyNight | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | United Kingdom | Yes | N/A – within EEA/UK |
| DocuSign | Digitally Signing Documents | Encryption in Transit, Encryption at Rest | United States | No | BCR-P + EU SCCs Mod 2/3 + UK/Swiss addenda |
| Dovetail | User research and customer insights hub | Encryption in Transit, Encryption at Rest | Australia | Yes | EU SCCs 2021/914 Mod 2/3 + UK IDTA |
| Euverify | UK Art. 27 GDPR representative & DSR request portal | Encryption in Transit, Encryption at Rest | United Kingdom | Yes | N/A – within EEA/UK |
| Eventbrite | Events Management and Promotion | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Mod 2 |
| Exact Online | Accounts Payable, Accounts Receivable, Payroll | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Facebook Pixel | Website & in-app conversion tracking (Meta Pixel + App Events SDK) | Encryption in Transit, Encryption at Rest | United States | Yes | Meta Controller Addendum (joint controllers, Art. 26) + UK Controller Addendum; EU SCCs Mod 3 where Meta acts as processor; DPF-certified |
| Firebase App Check | App-integrity verification | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Formitable | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Github | Code Hosting & Collaboration, Project Management | Encryption in Transit, Encryption at Rest | United States | No | EU SCCs Mod 2 + GitHub DPF-certified (EU-US) |
| Google Ads | Targeted Advertising, Website Tracking/Webapp tracking | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Google Ads Conversion | Website Tracking/Webapp tracking | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Analytics | Website Tracking/Webapp tracking | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Cloud | Account Creation, Matchmaking and Profile Suggestions, Improving and testing matchmaking over time, Optional Profile Personalisation, Scheduling offline dates, Image/media storage & backups, Internal analytics database, Verification photo storage | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Firebase | Transactional & CRM Push Notifications (Firebase Cloud Messaging), Deep Links | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Gmail | Customer Support, Internal Communication | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Maps | Address Lookup | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Meets | Internal Communication | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Google Play Store | Publish App to Google Play Store | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google reCAPTCHA | Bot / abuse protection on verification | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Google Tag Manager | Tag Management | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Guestplan | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Homerun | Recruitment | Encryption in Transit, Encryption at Rest | Netherlands | No | N/A – within EEA/UK |
| Hubspot | Partner CRM & Interaction Tracking, B2B Email Marketing (existing & prospective partners), B2B Outbound Partner Acquisition | Encryption in Transit, Encryption at Rest | European Economic Area | No | Hosted in the EU; EU SCCs Mod 1/2/3 + UK Addendum + Swiss + DPF for access from the US |
| IP API | Data Enrichment | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Lemlist | B2B outbound lead emailing (cold email sequences) | Encryption in Transit, Encryption at Rest | France | No | N/A – within EEA/UK |
| LinkedIn Ads | Recruitment advertising / candidate sourcing (candidates only) | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Make.com | Partner registration & email/password automation webhooks | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Mollie (as independent controller) | Executing payment transactions, fraud detection, AML/KYC obligations, improving Mollie's own services | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Mollie (as processor) | Accounts Receivable — payment services on Breeze's instructions | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Open AI | Ad-hoc Internal Generative AI Queries, Customer Support, Content Moderation & Safety, Generate Personalized Profile Feedback | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Mod 2/3 + UK Addendum |
| Paypal | Accounts Receivable | Encryption in Transit, Encryption at Rest | United States | Yes | Independent controller; EU SCCs Module 1 + UK IDTA |
| Pitch | Internal Communication, Investor Reporting | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Posthog | Website Tracking/Webapp tracking, Business Intelligence & Analytics | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | DPF + EU SCCs Mod 2 + UK IDTA + Swiss |
| Prelude | OTP / phone verification & anti-abuse | Encryption in Transit, Encryption at Rest | European Economic Area | Yes | N/A – within EEA/UK |
| Rinkel | Customer Support | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Sentry | Error & Log Management | Encryption in Transit, Encryption at Rest | United States | Yes | DPF + EU SCCs Mod 2/3 + UK + Swiss |
| SevenRooms | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs + UK Transfer Addendum |
| Shiftbase | Timesheet & Shift Management | Encryption in Transit, Encryption at Rest | European Economic Area | No | N/A – within EEA/UK |
| Slack | Internal Communication | Encryption in Transit, Encryption at Rest | United States | No | BCR + DPF + EU SCCs Mod 2/3 + UK + Swiss |
| Snapchat Pixel | Targeted advertising & website/app conversion tracking | Encryption in Transit, Encryption at Rest | United States | Yes | Independent controller for pixel data (processor for data we provide); EU SCCs in Snap's advertising terms |
| Spryng | Transactional & reservation SMS (match first name + date/time) | Encryption in Transit, Encryption at Rest | Netherlands | Yes | N/A – within EEA/UK |
| Stripe (as independent controller) | Fraud and loss prevention, AML/KYC obligations, choosing banks and payment partners, improving Stripe's own services | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Module 1 + UK IDTA + DPF-certified |
| Stripe (as processor) | Accounts Receivable (event tickets & group bookings) — operating the Stripe services on Breeze's behalf | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs Module 2 + UK IDTA + DPF-certified |
| TestGorilla | Candidate testing | Encryption in Transit, Encryption at Rest | Netherlands | No | N/A – within EEA/UK |
| TestPortal | Candidate testing | Encryption in Transit, Encryption at Rest | Poland | No | N/A – within EEA/UK |
| TikTok Advertising | Targeted advertising + app conversion signals (via AppsFlyer) | Encryption in Transit, Encryption at Rest | United States | Yes | Controller-to-controller terms (independent controllers); EU SCCs in TikTok's terms |
| Typeform | Product Surveys and Gathering Insights | Encryption in Transit, Encryption at Rest | Spain | Yes | N/A – within EEA/UK |
| Vonage | Transactional & reservation SMS (backup) | Encryption in Transit, Encryption at Rest | United States | Yes | DPF-certified (Vonage America LLC) + EU SCCs + UK IDTA |
| Voyage AI | Matchmaking and profile suggestions | Encryption in Transit, Encryption at Rest | United States | Yes | EU SCCs 2021/914 Module 2 + UK IDTA |
| Wise | Accounts Payable | Encryption in Transit, Encryption at Rest | United Kingdom | No | N/A – within EEA/UK |
| Zenchef | Restaurant reservations (shares match first name + date/time) | Encryption in Transit, Encryption at Rest | France | Yes | N/A – within EEA/UK |
Special-category (sensitive) data from your dedicated profile fields is used only by the following recipients, each for the purpose stated and only on our instructions under a data processing agreement: Google Cloud, which hosts our databases, including our internal analytics database, and stores your profile photos and media; Cloudflare, which stores some of those images (such as older photos and video thumbnails) and caches and delivers them through its network; Amazon Web Services, which performs the momentary profile-verification comparison; Voyage AI, which converts profile information into the signals our matchmaking uses to suggest people to you; Anthropic, whose AI assistant our team uses to query our internal analytics database, for example to understand how well our matchmaking works; and Braze, which sends our app messages, such as invitations and reminders for the group dates we suggest, and receives the gender(s) you want to be matched with so that these messages are relevant. None of these recipients may use the data for its own purposes. No other recipient in the table receives data from these dedicated fields, and we never use it for advertising. Special-category information you choose to write in open text is handled as described in Section 2.
Disclosure of data to other users
It's important to remember that you, as a user, are also responsible for your own personal data. If you are careless with your own personal data, it can not only have consequences for yourself, but also for the personal data of other users. Therefore, we recommend that you do not give your phone to others when you are signed in to Breeze. In addition, it is also prohibited to share screenshots of profiles, as we are not responsible for the information that is distributed in that way.
11. International Transfers
Some of our external third parties are based outside the UK and EEA, so their processing of your personal data will involve a transfer of data outside the UK and EEA. Whenever we transfer your personal data out of the UK and EEA, we ensure a similar degree of protection is afforded by implementing at least one of the following safeguards:
- The country to which personal data is being transferred has been deemed to provide an adequate level of protection for personal data by the European Commission.
- We use specific contracts approved by the European Commission, which provide personal data with the same protection it has in the UK and Europe.
Section 10 lists the safeguard we use for each recipient. Please contact privacy@breeze.social if you would like more information about the safeguards we have implemented for international transfers.
12. Data Security
We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to employees, agents, contractors, and other third parties with a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
We have procedures to deal with any suspected personal data breaches and will notify you and any applicable regulator of a breach where legally required. If you have questions about the security of your personal data or believe your data has been compromised, please contact privacy@breeze.social.
Since your Account and personal data can be accessed via your mobile phone and can be recovered via your email, it is important that you take appropriate measures to secure them. Let us know immediately if any of these has been compromised.
We do not assume any responsibility or liability for breaches of security, damage to your device, or unauthorised use of your information that result from circumstances outside our control, such as the security of your own device or of the networks you use.
13. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation with respect to our relationship with you.
When determining the appropriate retention period, we consider:
- The amount, nature, and sensitivity of the personal data.
- The potential risk of harm from unauthorised use or disclosure.
- The purposes for processing your personal data and whether we can achieve these purposes through other means.
- Applicable legal, regulatory, tax, accounting, or other requirements.
In this respect, we apply the following retention periods:
-
Personal data of App Users:
- Your account and profile, including the special-category information in your profile, and data about how you use the App, such as your likes, matches, messages and date planning: until you delete your Account, or earlier if you remove information from your profile.
- Marketing emails: until you unsubscribe, object or withdraw your consent.
- Research interviews and surveys you take part in: until you withdraw your consent, and at most 1 year.
- Payment data: 7 years after the contract ends (tax law).
- Technical error and diagnostic logs, and advertising attribution data held by our measurement provider: up to 90 days after they were created.
- Records of objections to moderation decisions: 1 year after our last contact.
- A minimal record of a blocked account: 10 years.
The periods for logs and attribution data run from when the data was created, not from when you delete your Account, so this data can remain for a short time after deletion.
-
Personal data of Contractors: These data are stored for a maximum period of 24 months after our last contact. Payment data necessary for accounting and tax purposes is stored until 7 years after contract ends.
-
Personal data of Job Applicants: We keep your application for 1 month after our last contact with you. If you agree to join our talent pool, we keep it for 12 months after our last contact, or until you withdraw your consent. If you take a skills test as part of your application, we delete your results 1 month after our last contact with you, except at TestGorilla, which keeps them for 2 years (webcam pictures and video answers for 6 months).
-
Personal data of Leads: These data are stored as long as necessary to determine whether we enter into an agreement with a potential client and for a maximum period of 24 months after our last contact.
-
Personal data of website visitors: Please see our Cookie Statement below.
When you update your profile, it may take some time before all users (including your old matches) see the latest version of your information. This is because we cache profile data locally to improve performance. As a result, even after making changes, older versions of your profile may still be visible to other users until the cache is refreshed.
If you delete your Account, we will make reasonable efforts to ensure that your account is no longer visible to other users in the App. We are not responsible for lost information, content, or photos as a result of your decision to delete your data.
When you delete your Account, we keep a minimal record of the phone number linked to it so that we can enforce a block where one applies, for example after a breach of our User Terms or of other laws or regulations. If your Account was never blocked, we delete that record 30 days after you delete your Account. If it was blocked, we keep it for 10 years, so that the account cannot simply be recreated. Phone numbers that a user adds to their personal blocklist are kept until that user removes the block or deletes their account.
One effect of this is worth knowing in advance. Once that record is gone, and the technical records described above have expired, we can no longer look up a deleted Account by phone number or email address. If you contact us after that point and ask what data we hold about you, we will not be able to confirm whether you ever had an Account with us, because nothing linking you to one remains.
Backups
We keep encrypted backups so that we can restore our systems after a failure or a security incident. When you delete your Account, your personal data is deleted or anonymised in our live systems, except where this section says that we keep it for longer. A copy can remain in our backups for a limited period after that. We keep backups of our databases for 30 days. We occasionally take a separate one-off copy of a database, for example before maintenance, and we delete those after 90 days. Earlier versions of photos you have deleted are removed within 15 days.
Retention of your personal data by others
Please note that after you have deleted data from your profile or Account, copies or (part of) your data may be available to others, to the extent that this data has been previously shared with them. For example, it is possible that other users have copied or stored certain personal data (for example, through a screenshot). This is beyond our control, and we therefore take no responsibility or liability for this.
14. Automated Decision Making and Profiling
We use profiling and automated checks to provide our dating services. We do not reject profiles by automated means alone.
Automated profile checks
For our automated profile checks, we use large-language models to check new profiles against our User Guidelines. If the model finds that a profile follows them, the profile is normally approved automatically; a share of approved profiles is also checked by a person. If it finds a possible problem, a person at Breeze reviews the profile and makes the decision, so a profile is never rejected by automated means alone. This is to ensure the safe, transparent and fair dating environment that our User Guidelines prescribe, and we do it on the basis of our legitimate interest in keeping the App safe. Below, we explain how it works, why it is necessary and how we limit its impact.
How the automated check works
The data categories used include the user's photos and their captions and stories, first name, all Q&A pairs the user has completed and their bio. These categories are used as input for the large-language model and are considered relevant by Breeze as they include the first input the User provides in their profile. The large-language model checks this input against our User Guidelines, which describe what content is and is not allowed on the App, and either approves the profile or passes it to a person at Breeze, who decides.
We do not use the information from the dedicated special-category fields for this review, and the decision is about whether your profile follows our User Guidelines, not about any sensitive information it may contain.
Why it is necessary and how we limit its impact
To ensure a fair and objective approval process, Breeze uses AI-based decision-making instead of a fully manual review. This approach is necessary due to the volume of User profiles that Breeze needs to assess daily. In our experience, it also leads to more consistent decisions than manual review. Additionally, Breeze has implemented measures to mitigate risks associated with automated processing:
- Human Oversight: Every rejection is decided by a person, and we periodically sample automatically approved profiles to ensure accuracy and fairness. Human reviewers checked the system's decisions before it went live, and check them again whenever we make a significant change, adjusting the settings where needed.
- Data Minimization: We only use the profile information needed to check a profile against our User Guidelines, as listed above. We use your first name to check for fake or offensive names.
- Data Accuracy & Fairness: We continuously test AI output and perform human checks to improve decision accuracy and avoid biased results.
- Data Retention: see Section 13.
- No training by the provider: we use the business service of the large-language model provider, under a data processing agreement. The provider does not use the data we send it to train, fine-tune or otherwise improve its models. It keeps that data for at most 30 days, only to detect and investigate misuse of its service, and then deletes it.
User rights and appeal mechanisms
- Contest a decision: if your profile is rejected, you can ask for a second review by another person, give your point of view and contest it.
- Object to the automated review: you can also ask us not to review your profile automatically; we will then review it manually instead.
For both, contact objections@breeze.social; a link is included when we tell you about the decision. (Your right to object follows from Article 21 GDPR.)
Profiling, not qualifying as automated decision making
Breeze further conducts the following profiling activities:
- use our Cupid service to suggest relevant profiles based on User profiles and like behavior. The suggestions are partly based on the logic of "similar Users have also liked this profile" and "Users with this characteristic like Users with a certain characteristic". You can influence the selection process by choosing where you want to date, as well as the ages and sexualities of the Users you want to date. To find the best matches for you over time, we continuously train and test different versions of our matching models, on live and historical data, to see which gives better matches;
- use your User preferences and residential area, which are linked to your Account, to determine the date location and deal. We only select overlapping deals and choose the location in a way that gives preference to the User who lives there. This may mean that you sometimes have to travel further if your place of residence does not have an overlapping city.
Here you can find more information on how our recommendation systems works.
In respect of the above, we only take personal data into account that you directly provide and we actively try to avoid any discriminatory decision-making. In case you feel disadvantaged by any automated decision-making or profiling activities, please contact us in the App or email our DPO.
15. Your Legal Rights within the EU and UK
Under the GDPR, you have the right to:
- Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of your data and check its lawful processing.
- Request correction of the personal data we hold about you. Users can always view and adjust or delete your personal information through the App.
- Request erasure of your personal data where there is no good reason for us to process it. This right also applies if you object to processing, we processed your data unlawfully, or we must erase your data to comply with local law.
- Object to processing of your personal data, especially when we rely on legitimate interest or use your data for direct marketing purposes.
- Request restriction of processing under specific scenarios, such as when you contest the accuracy of the data or need it for legal claims.
- Request data transfer of your personal data to you or a third party in a structured, machine-readable format.
- Withdraw consent at any time if processing relies on consent. This will not affect the lawfulness of processing before consent withdrawal.
- Make a complaint by contacting our DPO at breeze.dpo@techgdpr.com. You also have the right to lodge a complaint with the relevant supervisory authority.
Please note that feedback that other users give about a match or interaction may contain personal data relating to you. It is, however, provided confidentially by the other user to us — in the same way as a report about you may provide personal data relating to you. To protect the rights, freedoms and privacy of the person who provided it, and to preserve the candour and integrity of the feedback and reporting process, we do not share who gave the feedback or anything that could identify them, so that people can review a date candidly. If you ask for access, we may give you a summary of what was said about you instead of the feedback itself (GDPR Art. 15(4)).
General privacy questions can be sent to privacy@breeze.social. If you have concerns regarding our compliance with data protection laws, you may contact our DPO at breeze.dpo@techgdpr.com.
We aim to respond to all legitimate requests as soon as possible but in any case within one month. Complex requests may take longer to resolve, and we will keep you updated. To prevent your data from falling into the wrong hands, we will ask you a number of verification questions after receiving your request.
In some cases, we may limit your rights, for example in the context of preventing, investigating, detecting and prosecuting criminal offenses, such as fraud.
16. Do Not Track Settings
The website or our App do not recognize Do Not Track signals. Some third parties may collect aggregate information about the users’ online activities over time and across websites when they use the website or our App. While this information does not include personally identifiable information, certain processing activities that combine aggregate information with other information in possession of such third parties could result in the identification of users.
17. Rights Of California Residents
Pursuant to California Civil Code Sec. 1789.3, California resident users are entitled to know that they may file grievances and complaints with the California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834; or by telephone at (800) 952-5210; or by email to dca@dca.ca.gov. For more information about protecting your privacy, you may wish to visit: www.ftc.gov.
If you are a resident of California, you may request that we do not share your information with certain affiliates or third-party providers for marketing purposes, and/or you may inquire as to how we have shared your information with third-party providers for marketing purposes. In connection with such request, we will identify the types of information shared and provide you with the names and addresses of the third parties with whom the information was shared. If you would like to receive any such information, please contact us at privacy@breeze.social.
18. Third-Party Links
This website or our App may include links to third-party websites, plug-ins, and applications. Clicking on these links or enabling connections may allow third parties to collect or share data about you. We do not control these websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
19. Amendments to this Statement
We may revise this Statement from time to time. The most recent version can be found on our website: breeze.social/en/privacy. We recommend that you consult this privacy and cookie statement regularly so that you are kept informed of the changes. If we make changes that are, in our sole discretion, substantive, then we will notify you by sending an email to the email address associated with your Account or by posting a message in the App. By continuing to use the App after these changes have become effective, you agree to the modified Statement.
Effective date
This privacy statement was last updated on October 3rd, 2026.
Cookie Policy
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer's hard drive.
1. Type of cookies we use
We use three types of cookies, matching the three choices in our cookie banner:
- Strictly necessary cookies: needed for our website to work, for example to remember your language and your cookie choices. These are always on.
- Analytics cookies: help us count visits and traffic sources and see how visitors use our website, so we can improve it. We only place these if you allow analytics.
- Marketing cookies: used to measure and improve our advertising campaigns on other websites and apps. Our advertising partners may also use them to build a profile of your interests and show you relevant ads elsewhere. We only place these if you allow marketing.
2. Cookies used on our website
The tables below list the cookies used on our website, grouped by type. Some are set by Breeze itself, others by third-party services we use on our website. For those, the third party's own privacy policy also applies. Except for strictly necessary cookies, none of them are placed until you give your consent in our cookie banner.
Tag management
| Provider | Purpose | More Information |
|---|---|---|
| Google Tag Manager | Loads the analytics and marketing services below, and only once you have given the related consent. | Google privacy policy |
Strictly Necessary Cookies
| Provider | Purpose |
|---|---|
| Breeze | Remembers your language. |
| Breeze | Remember whether you accepted cookies, and when. |
Analytics cookies
| Provider | Purpose | More Information |
|---|---|---|
| Google Analytics | Statistics on how visitors use our website. | Google privacy policy |
Marketing cookies
| Provider | Purpose | More Information |
|---|---|---|
| Google Ads | Measures the results of our Google ad campaigns. | Google privacy policy |
| Meta (Facebook) | Measures the results of our ads on Facebook and Instagram. | Meta privacy policy |
| Snapchat | Measures the results of our ads on Snapchat. | Snap privacy policy |
| AppsFlyer | Links visits to our website with downloads of our app, to measure our campaigns. | AppsFlyer privacy policy |
3. Managing Your Preferences
When you first visit our website, our cookie banner lets you accept all cookies, decline all optional cookies, or choose per type. You can change your choice at any time using the cookie icon in the bottom right corner of our website, or via "Cookie settings" at the bottom of every page. Changing your choice stops new optional cookies from being placed, but cookies that were already placed may stay on your device until they expire. You can delete them, or block cookies on all websites, in your browser settings; www.internetcookies.com explains how to do this for most browsers and devices.
If you decline optional cookies, our website keeps working. You will simply not see the related features, and we will not be able to measure your visit.