Data Processing & Compliance

Legal bases, retention, and international transfers

A rigorous, audit-ready statement of how MatchGen.ai processes personal data across every category. Written for regulators, corporate due-diligence teams, and any user who wants the full picture.

Legal bases for processing

Performance of a Contract

GDPR Art. 6(1)(b)

Account creation, authentication, chat + memory functionality, subscription fulfilment, payment settlement.

We can't process your subscription or serve replies from a companion without executing our Terms of Service.

Consent

GDPR Art. 6(1)(a) + Art. 9(2)(a) for sensitive data

Long-term memory extraction, marketing emails, non-essential cookies, any processing of preference data linked to gender/orientation.

A tick-box during onboarding. Withdrawable at any time from Settings, with no impact on core functionality.

Legitimate Interest

GDPR Art. 6(1)(f)

Service security (fraud/abuse detection), performance analytics, debugging, direct marketing of our own similar products to existing customers.

A balancing test is performed and documented for each use. Users can object at privacy@matchgen.ai.

Legal Obligation

GDPR Art. 6(1)(c)

Tax and accounting records, age-verification records, responding to lawful requests from courts or supervisory authorities.

Overrides erasure requests where retention is mandated by law (e.g. financial records must be kept for 10 years).

Retention schedule by data category

CategoryLegal basisRetention
Account DataContract3 years standard — shortened to 1 year on inactivity
Content DataContract + consent (memory)For the life of the account; deleted on account closure
Generated MediaContractFor the life of the account, cached in MongoDB GridFS
Payment DataContract + legal obligation10 years (tax law)
Technical DataLegitimate interest30 days
Marketing DataConsent2 years from last engagement, or until consent is withdrawn
Sensitive DataExplicit consent (Art. 9(2)(a))Deleted immediately on consent withdrawal

International data transfers & subprocessors

Some processing happens outside the European Economic Area (mainly the US, for AI inference). Every transfer is covered by Standard Contractual Clauses (SCCs) approved by the European Commission, or by an active adequacy decision, plus technical safeguards (encryption in transit + at rest).

Sub-processorPurposeJurisdictionSafeguard
GroqPrimary LLM inference (chat)USASCCs
Google (Gemini API)Secondary LLM inferenceUSASCCs
PollinationsFallback LLM + image inferenceEUEU direct
ElevenLabsText-to-speech synthesisUSASCCs
Fal.aiHigh-quality image generation (LoRA)USASCCs
MongoDB AtlasApplication database + file storage (GridFS)EU (primary)EU direct
PaystackPayment processing (Africa)Nigeria (adequate)Contract
RazorpayPayment processing (India)IndiaSCCs
StripePayment processing (Global)USASCCs

Technical & organisational measures

TLS 1.3 for all data in transit
MongoDB Atlas encryption at rest (AES-256)
Bcrypt-hashed passwords (cost factor 10)
HttpOnly + Secure + SameSite cookies for session tokens
Rate limiting on authentication + generation endpoints
No PII in log files (structured logging with redaction)
Principle of least privilege on all sub-processor credentials
Automated backup rotation with 30-day recovery window

Change management

Substantial changes to this document are notified to logged-in users at least 30 days before taking effect. Minor editorial changes are logged in a public changelog available on request.

Data Protection Officer: dpo@matchgen.ai · General: privacy@matchgen.ai