Data Processing Agreement
Last updated: 16 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between EXCLUSIO LTD (6 Burrows Court, Liverpool, United Kingdom, L3 6JZ; the "Processor") and the business customer identified in the applicable order (the "Controller" or "Client") for the provision of the Apericor white-label dating platform service (the "Service"). It applies whenever Apericor processes personal data on behalf of the Client and is entered into pursuant to the UK GDPR and Regulation (EU) 2016/679 ("GDPR").
1. Roles and subject matter
The Client is the controller of end-user personal data processed on its dating project; Apericor is the processor. Processing lasts for the term of the Service. Its subject matter and purpose are the hosting and operation of the Client's white-label dating project and provision of related support.
2. Categories of data and data subjects
- Data subjects: end users of the Client's dating project; the Client's staff using the administration panel.
- Personal data: account and profile data (name, photos, age, location, preferences), communications (messages, chat, video call metadata), transaction and payout data, technical and usage data, moderation records.
- Special categories: profile and usage data on a dating service may reveal information about a data subject's sex life or sexual orientation; identity verification materials (identity documents, verification video, liveness selfies) are processed for agency-verified and self-registered profiles as configured by the Client.
3. Processor obligations
Apericor shall:
- process personal data only on the Client's documented instructions, including as configured by the Client in the platform, unless required otherwise by law (in which case Apericor will inform the Client unless prohibited);
- ensure persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures in Section 6;
- assist the Client, taking into account the nature of processing, in responding to data subject requests (access, erasure, portability, objection) using the export, deletion and consent-management tools built into the platform;
- assist the Client with security, breach notification, data protection impact assessments and prior consultation obligations;
- notify the Client without undue delay after becoming aware of a personal data breach affecting the Client's data, providing information reasonably required for the Client's own notification obligations;
- at the end of the Service, at the Client's choice, delete or return all personal data and delete existing copies (subject to backup cycles of up to 30 days and any legal retention duties);
- make available information necessary to demonstrate compliance and allow for audits, no more than once per year on reasonable notice, at the Client's cost, without prejudicing the security or confidentiality of other clients.
4. Controller obligations
The Client warrants that it has a lawful basis for the processing it instructs; that its end-user privacy policy accurately describes the processing; that it obtains any required consents (including for special category data inherent in dating services and for verification media); that it enforces its 18+ policy; and that its instructions comply with applicable law. The Client is responsible for day-to-day moderation decisions made with the tools provided.
5. Sub-processors
The Client grants general authorisation to engage sub-processors. Current sub-processors:
- Hetzner Online GmbH — hosting and infrastructure (EU data centres, Germany/Finland);
- [Payment provider] — billing and payment processing (card data is processed on the provider's PCI DSS-compliant infrastructure);
- [Email provider] — transactional email delivery;
- [Analytics provider] — aggregated usage analytics.
Apericor will notify the Client of intended additions or replacements at least 14 days in advance; the Client may object on reasonable data-protection grounds, in which case the parties will seek a solution in good faith. Apericor imposes data protection obligations on sub-processors equivalent to this DPA and remains liable for their performance.
6. Security measures
- encryption in transit (TLS) for all traffic;
- encryption at rest for data stored on production servers (hardware-accelerated, negligible performance overhead);
- identity verification documents stored on a separate encrypted volume with strictly limited, role-based access and a defined retention policy (deletion after verification or on schedule, as configured by the Client);
- password storage using strong adaptive hashing (bcrypt/argon2);
- role-based access control to the administration panel; access logging;
- 24/7 infrastructure monitoring; DDoS, anti-fraud and anti-spam protections;
- daily automated backups stored on a separate server, retained for 30 days, with tested restore procedures;
- payout KYC processes for user withdrawals where the Client's monetization model includes user earnings.
7. International transfers
Personal data is hosted in EU data centres. Transfers between the UK and EU rely on adequacy decisions. Any transfer to a third country will only take place with appropriate safeguards (EU Standard Contractual Clauses and/or the UK International Data Transfer Addendum), which the parties agree to execute where required.
8. Liability and governing law
Liability under this DPA is subject to the limitations of liability in the Terms of Service, except where applicable data protection law provides otherwise. This DPA is governed by the laws of England and Wales.
9. Contact
Data protection enquiries: privacy(at)apericor(dot)net. EXCLUSIO LTD, 6 Burrows Court, Liverpool, United Kingdom, L3 6JZ, +44 151 457 0170.