Privacy Policy

1. GENERAL PROVISIONS

1.1. This Nikahova Privacy Policy (the “Policy”) sets out the procedures governing the collection, receipt, recording, organization, accumulation, storage, use, modification, disclosure, transfer, restriction, deletion, destruction, and other processing of personal data of users of the Nikahova Service.

1.2. Nikahova is a matchmaking service for adults intended to facilitate the search for a potential husband or wife for the purpose of forming a family and entering into marriage (nikah).

1.3. For the purposes of this Policy, the “Service” means the Nikahova mobile application, the nikahova.app website, the admin.nikahova.app administration panel, server infrastructure, data storage systems, moderation tools, and other information technology systems and resources through which Nikahova functions are provided.

1.4. This Policy applies to the processing of Users’ personal data regardless of the device used and shall apply subject to the laws of the relevant jurisdiction to the extent such laws apply to the particular processing activity.

1.5. When processing personal data, the Controller takes into account, in particular, Federal Law of the Russian Federation No. 152-FZ dated July 27, 2006 “On Personal Data,” the applicable provisions of the European Union General Data Protection Regulation (“GDPR”), the UK GDPR and other applicable laws of the United Kingdom, the applicable provisions of the Privacy and Electronic Communications Regulations (“PECR”), the California Consumer Privacy Act and California Privacy Rights Act (“CCPA/CPRA”), as well as mandatory app store requirements and other mandatory provisions of the laws of the User’s jurisdiction.

1.6. This Policy is an informational document and does not replace a separate User consent where applicable law requires separate consent or a specific form of consent.

2. PERSONAL DATA CONTROLLER

2.1. The Personal Data Controller is Fatima Imamshapieva (FATIMA IMAMSHAPIEVA), a foreign resident of the Arab Republic of Egypt, acting on the basis of a Foreign Residence Card issued by the competent authorities of the Arab Republic of Egypt.

2.2. Controller’s address: Madinaty, New Cairo, Cairo, Arab Republic of Egypt.

2.3. Official website: nikahova.app.

2.4. Email address for requests relating to the processing of personal data, withdrawal of consent, exercise of data subject rights, and privacy matters: support@nikahova.app.

2.5. This email address shall remain available to the User regardless of the status of the User’s Account, including following suspension, blocking, or submission of an Account deletion request.

3. AGE RESTRICTIONS

3.1. Nikahova is intended exclusively for persons who are at least 18 years of age.

3.2. By creating an Account, the User confirms that the User is at least 18 years of age and must provide an accurate date of birth.

3.3. Intentionally providing a false date of birth constitutes a violation of the User Agreement.

3.4. Where there are reasonable grounds to doubt the accuracy of the information provided, the Controller may apply reasonable additional age-verification measures, provided that such verification is permitted by applicable law.

3.5. If the Controller becomes aware that an Account belongs to a person under the age of 18, access to the Account shall be terminated and the related personal data shall be deleted in accordance with the procedure established by applicable law and this Policy.

3.6. Establishing an age restriction and verifying a date of birth do not constitute an absolute guarantee that a User has not provided false information. The User’s responsibility for knowingly misleading the Service does not exclude the Controller’s own obligations relating to the protection and safety of minors.

4. PRINCIPLES OF PROCESSING

4.1. The Controller processes personal data lawfully, fairly, and transparently.

4.2. The personal data processed shall be limited to data necessary for specified and lawful purposes.

4.3. Personal data shall not be retained for longer than necessary for the purposes of processing, compliance with mandatory legal requirements, prevention of abuse, and protection of the legitimate rights of the Controller and Users.

4.4. Additional organizational and technical safeguards are applied to data of heightened sensitivity.

4.5. Access by employees, moderators, and administrators is granted on the basis of their roles and the need for access in order to perform their respective functions.

5. ACCOUNT DATA

5.1. For the purpose of creating and maintaining a Nikahova Account, the Service may process the User’s email address, password hash, email verification code hash, password recovery token hash, preferred language, User role, Account status, verification status, blocking status, suspension status, payment status, date of last activity, date of password change, date of Account deletion request, and the device FCM token.

5.2. Passwords are not stored by the Controller in plaintext.

5.3. Verification codes and recovery tokens are also stored in hashed form.

6. SOCIAL SIGN-IN

6.1. If the User signs in through Google or another available provider, the Service may process the provider’s name, the User’s identifier with the provider, Firebase UID, email address, and other information objectively necessary to verify and link the Account.

6.2. Use of social sign-in is voluntary to the extent that the Service provides an alternative registration method.

7. PROFILE DATA

7.1. When completing a Profile, the User may provide their name, date of birth, sex, country, city, nationality, height, weight, languages, education, profession, employment information, interests, personality traits, photographs, videos, “About Me” information, “Who I Am Looking For” information, and other data provided for by the interface.

7.2. Certain Profile information is intended for matching the User with a potential husband or wife and may be displayed to other registered Users in accordance with this Policy, the Service settings, and the consents provided by the User.

8. SPECIAL AND SENSITIVE CATEGORIES OF DATA

8.1. Given the nature and purpose of Nikahova, the Service processes data of heightened sensitivity.

8.2. Information concerning religious beliefs and religious practices may include information as to whether the User was born Muslim, the User’s status in Islam, religious denomination or branch, number of years in Islam, performance of salah (prayer), mosque attendance, observance of fasting during Ramadan, reading of the Quran, number of memorized surahs, Hafiz status, self-assessed level of religiosity, wearing of the hijab or niqab, willingness to observe covering, wearing of a beard, and adherence to a halal diet.

8.3. The Service may also process information concerning nationality, marital status, being in a polygamous marriage, attitude toward polygamy, number of wives, desire to have children, willingness to relocate, and intended timeframe for marriage.

8.4. For female Users, the Service functionality may allow the provision of information concerning virginity. Such information relates to the User’s intimate life and requires a heightened level of legal protection.

8.5. The Service may additionally process information concerning alcohol consumption, smoking, housing, height, and weight.

8.6. For Users in the European Union and European Economic Area, religious beliefs and information concerning a person’s sex life constitute special categories of personal data under Article 9 GDPR. For such processing, the Controller identifies a lawful basis under Article 6 GDPR and a separate condition under Article 9 GDPR.

8.7. Where the processing of special categories of personal data is based on explicit consent, such consent shall be provided separately, freely, specifically, on an informed basis, and through an unambiguous affirmative action.

8.8. For Users in the Russian Federation, the processing of information concerning nationality, religious beliefs, and intimate life shall be carried out only where a legal basis provided for by Article 10 of Federal Law No. 152-FZ exists.

8.9. Where the laws of the Russian Federation require written consent for the processing of special categories of personal data, the Controller shall obtain such consent in a form compliant with Articles 9 and 10 of Federal Law No. 152-FZ.

8.10. Acceptance of the User Agreement or acknowledgment of this Privacy Policy does not, in itself, constitute separate consent to the processing of special categories of personal data.

9. DATA RELATING TO CHILDREN, SPOUSES, AND OTHER THIRD PARTIES

9.1. A User may provide information about their children, including the child’s name, sex, date of birth, and information regarding whom the child lives with, as well as information about a spouse or spouses as provided for by the Service functionality.

9.2. By providing information about a third party, the User represents and warrants that the User has a legal basis under applicable law to provide such information to the Controller and, where such information will be accessible to other Users, to disclose it to such other persons.

9.3. If the User acts as the legal representative of a minor, the User confirms that the User has the relevant authority.

9.4. With respect to spouses and other adult third parties, the User must not provide direct identifiers, photographs, contact details, or other information unless the necessary consent or another lawful basis exists.

9.5. The Controller may request evidence of the relevant legal basis, restrict processing, or delete a third party’s data where there are grounds to believe that such data have been provided unlawfully.

9.6. A third party may contact the Controller directly to request rectification, restriction, or deletion of data relating to that person where such right is provided by applicable law.

9.7. The User’s representation regarding the lawful provision of third-party information does not relieve the Controller of its own obligations under applicable data protection laws.

10. COMMUNICATIONS AND MEDIA CONTENT

10.1. As part of Nikahova’s communication functions, the Service processes text messages, photographs, videos, voice messages, video messages, reactions, sender and recipient information, and read statuses.

10.2. The contents of private communications are not publicly available.

10.3. Communications and attachments may be automatically processed by Nikahova’s security and moderation systems.

10.4. Contact information may be automatically detected and masked in communications, Profile text, and posts. The mechanism may detect links and website addresses, email addresses, usernames in the form @username, long sequences of digits that may constitute a telephone number, and references to third-party messaging services.

11. AUTOMATED AND HUMAN MODERATION OF PRIVATE MESSAGES

11.1. Photographs and videos, including video messages sent through private communications, may be automatically reviewed by the moderation system regardless of whether another User has submitted a complaint.

11.2. Videos may be analyzed by automatically extracting individual frames and subsequently analyzing those frames.

11.3. If the automated system detects indications of a potential violation of the rules, the relevant image or video may automatically be referred to a restricted queue for human review by an authorized moderator.

11.4. No prior complaint by a participant in the communication is required for such review.

11.5. An authorized moderator may view material referred to the review queue and related information only to the extent necessary to verify compliance with the rules, ensure safety, identify prohibited content, prevent abuse, and apply measures provided for by the Service.

11.6. The User is informed through this Policy of the existence of the above procedure. The Controller is not required to provide a separate notification each time the automated system is triggered unless such notification is expressly required by applicable law.

11.7. Automated moderation of images and videos is performed on Nikahova’s infrastructure. As of the date of this version of the Policy, AWS Rekognition is not used for this purpose.

11.8. Text content analysis is also performed using Nikahova’s local systems. As of the date of this version of the Policy, the toxicity assessment model does not independently make a final decision to block an Account.

11.9. Moderator actions are recorded in an audit log.

12. PRIVATE NOTES

12.1. Nikahova functionality may allow a User to save a private note about another User.

12.2. Such note is accessible only to its author and is not displayed to the person to whom it relates or to other Users.

12.3. Because the contents of a note may contain another person’s personal data, the User must use this functionality in good faith and must not include unlawfully obtained, excessive, or irrelevant information.

12.4. The Controller processes the contents of such notes only for the purpose of providing the relevant functionality, ensuring security, and complying with mandatory legal requirements.

13. USER ACTIVITY DATA

13.1. Nikahova may process information concerning Profile impressions, expressions of interest, likes, hides, rejections, blocks, complaints, saved search filters, actions within Discovery, read statuses, and other interactions with Service functionality.

13.2. Saved search filters may include preferences relating to the religious characteristics of a potential husband or wife.

13.3. Various technical records are used to display activity. The “currently online” indicator is retained for approximately 60 seconds. Information concerning the time the User was last online may be retained for up to 30 days. The date of the Account’s last activity may be retained until the Account is deleted.

14. TECHNICAL DATA AND ERROR REPORTS

14.1. When technical errors occur, the Service may process the application version, build number, platform, operating system version, device model, interface language, screen resolution, application environment, information concerning the screen or route on which the error occurred, error description, error code, stack trace, severity indicator, User identifier, number of occurrences of the relevant error, and dates of its first and most recent occurrence.

14.2. Error reports are transmitted to Nikahova’s own system.

14.3. As of the date of this version of the Policy, Firebase Crashlytics, Sentry, and similar third-party error collection services are not used.

14.4. The IP address is not stored in the primary User database; however, it may be present in nginx access logs and may be used for information security and abuse-prevention purposes.

15. GEOLOCATION AND SYSTEM PERMISSIONS

15.1. Nikahova does not determine the User’s precise or approximate geolocation through GPS and does not maintain a location history.

15.2. Country and city are provided by the User in the Profile.

15.3. To provide certain functionality, the Service may request permission to access the camera, microphone, media library, save images, and send push notifications.

15.4. Nikahova does not access the User’s address book, contacts, calendar, or system health data as part of the functionality described in this Policy.

16. PURPOSES OF PROCESSING

16.1. Personal data are processed for User registration and identification, email verification, access recovery, creation and maintenance of the Account, creation and display of the Profile, search for a potential husband or wife, generation of matching results, operation of interest and communication features, transmission of messages and media, message translation, moderation, prevention of prohibited content, masking of contact information, handling of complaints, ensuring security, prevention of fraud and abuse, technical support, error diagnostics, processing of payments and subscriptions, compliance with legal requirements, and protection of the rights of the Controller and Users.

16.2. Special categories of personal data are not used for third-party advertising targeting.

17. LEGAL BASES FOR PROCESSING

17.1. Depending on the purpose, nature of the data, and applicable jurisdiction, the legal bases for processing may include performance of a contract with the User, the User’s consent, explicit consent to the processing of special categories of personal data, compliance with a legal obligation, the legitimate interests of the Controller or third parties where permitted by applicable law, the establishment, exercise, or defense of legal claims, and other legal bases provided by law.

17.2. For Users in the EU and EEA, the Controller determines the applicable legal basis under Article 6 GDPR for each processing purpose.

17.3. For special categories of personal data, a separate condition under Article 9 GDPR is also identified.

17.4. Where data of heightened sensitivity are processed for the purposes of matching the User with a potential husband or wife, displaying relevant criteria, moderation, or security, and the Controller relies upon explicit consent, such consent must expressly cover the relevant processing activity.

18. DISPLAY OF PROFILES TO OTHER USERS

18.1. Internal processing of data by the Controller and disclosure of information to other Users are separate processing activities.

18.2. Data required solely for registration, payments, security, or technical operation do not become accessible to other Users merely because they have been provided to the Controller.

18.3. Profile data may be displayed to other registered Nikahova Users in accordance with the Service functionality and consents provided.

18.4. Information displayed may include name, age, country and city, nationality, photographs and videos, education, profession, interests, characteristics, religious information, marital status, lifestyle information, “About Me” information, and “Who I Am Looking For” information.

18.5. Information about children and spouses may be displayed to other Users only to the extent provided by the interface and where an appropriate legal basis exists.

18.6. Given the heightened risks to third parties, the Controller may restrict the visibility of direct identifiers of children and spouses or hide individual fields where such restriction is necessary to comply with applicable law or protect the relevant persons.

19. DISSEMINATION OF PERSONAL DATA IN THE RUSSIAN FEDERATION

19.1. For the purposes of this Policy, the Controller distinguishes between disclosure of information to a specific recipient or a limited, defined group of persons and dissemination of personal data to an indefinite or not predetermined group of persons.

19.2. If Profile data become accessible to an indefinite or not predetermined group of persons in such a manner that Article 10.1 of Federal Law No. 152-FZ applies, the Controller obtains separate consent to the processing of personal data authorized by the data subject for dissemination.

19.3. Such consent shall be obtained separately from any other consent.

19.4. The User shall be given the opportunity to determine the specific categories and list of personal data authorized for dissemination, as well as any prohibitions and conditions provided for by law.

19.5. Silence, failure to act, Account registration, or completion of a Profile alone shall not be regarded as consent to dissemination where the law requires separate consent.

20. SAVING, COPYING, AND SCREENSHOTS BY OTHER USERS

20.1. A recipient of Profile information or communications may technically save such information using the recipient’s device, including by taking a screenshot or otherwise recording it.

20.2. Nikahova prohibits Users, without a lawful basis, from copying, publishing, disseminating, disclosing to third parties, or using outside the purposes of matchmaking any personal data, photographs, videos, voice messages, communications, or other information relating to other Users.

20.3. In particular, the use of another person’s information for harassment, blackmail, extortion, public humiliation, discrimination, or causing harm is prohibited.

20.4. Violation of this requirement may result in Content removal, restriction of functionality, suspension, or blocking of the Account in accordance with the User Agreement and the User-Generated Content Rules.

20.5. The Controller shall not be liable for independent unlawful acts of one User following the lawful disclosure of another User’s data to that User through the Service functionality, provided that the Controller has complied with its legal obligations and no fault of the Controller has been established. Nothing in this clause limits any liability that cannot lawfully be excluded.

21. MESSAGE TRANSLATION

21.1. Google ML Kit Translation and Language Identification are used to translate messages.

21.2. Language models are downloaded to the User’s device from Google servers, and the device may therefore establish a technical connection with Google infrastructure.

21.3. The contents of the message being translated are not transmitted to Google for the purpose of translation; translation is performed on the User’s device.

22. PUSH NOTIFICATIONS

22.1. Firebase Cloud Messaging is used to deliver push notifications.

22.2. Google/Firebase may receive the FCM token and the contents of the technical push request.

22.3. Under the current technical implementation, certain notifications may contain the sender’s name and an excerpt from the message.

22.4. The User should be aware that, depending on the device settings, a push notification may be displayed on the lock screen and may be accessible to a person with physical access to the device.

22.5. The User may manage push notifications through the Nikahova settings and the device’s system settings.

22.6. Nikahova provides separate notification settings for different types of events, including likes, mutual interests, chat requests, messages, news, digests, inactivity notifications, and a “Do Not Disturb” mode, within the available functionality.

22.7. Reminders concerning an upcoming subscription charge are treated as service communications relating to an existing relationship and payment.

22.8. Notifications intended to encourage an inactive User to return to the Service or to increase User engagement may be regarded as marketing communications in jurisdictions where they are classified as such by law. In such cases, they are sent only where a legal basis required by applicable law exists and an appropriate opt-out mechanism is provided.

22.9. In the United Kingdom, where a notification constitutes electronic mail direct marketing, Nikahova applies PECR requirements, including obtaining separate, freely given consent where such consent is required. The ICO requires consent to electronic marketing to be separate, specific, and demonstrated by an affirmative action.

23. FIRST-PARTY ANALYTICS

23.1. Nikahova does not use Firebase Analytics, Google Analytics, AppsFlyer, Amplitude, or the other identified third-party advertising or product analytics systems.

23.2. Nikahova does, however, calculate aggregated product statistics on its own infrastructure, including User activity metrics and moderation queue volumes.

23.3. Nikahova may also retain Profile impression history necessary for Discovery and matching functionality.

23.4. Aggregated internal statistics are not disclosed to third-party advertising networks for behavioral advertising purposes.

24. ADVERTISING AND TRACKING

24.1. Nikahova does not sell Users’ personal data.

24.2. Nikahova does not use religious beliefs, intimate information, or the contents of private communications for third-party advertising profiling.

24.3. As of the date of this version of the Policy, Nikahova does not use advertising networks or cross-service advertising tracking of Users.

25. THIRD-PARTY SERVICE PROVIDERS

25.1. The Controller may engage service providers only for purposes related to the operation of the Service and where a legal basis provided by applicable law exists.

25.2. Hetzner Online GmbH is used for server infrastructure and object storage.

25.3. Google/Firebase is used for push notifications and social sign-in.

25.4. Resend is used to send transactional emails, including email verification and access recovery messages.

25.5. Apple and Google are used in the mobile applications to process in-app purchases and subscriptions through the App Store and Google Play.

25.6. For in-app purchases, Apple or Google independently processes the User’s payment details. Nikahova transmits and receives information necessary to confirm the transaction, including the transaction identifier, purchased product identifier, purchase or subscription status, and technical receipt information.

25.7. Stripe is used for payment transactions made through the website and is not used as a payment mechanism within the mobile application where the relevant payment is processed through the app store’s in-app payment system.

25.8. Stripe independently processes payment details. Nikahova may receive the transaction identifier, User identifier, amount, and payment status.

25.9. The Controller does not represent that a third-party recipient provides any particular international data transfer mechanism unless such mechanism has been confirmed by the applicable agreement or the recipient’s applicable status.

26. DATA PROCESSING AGREEMENTS AND INTERNATIONAL SAFEGUARDS

26.1. Where applicable law classifies a service provider as a processor acting on behalf of the Controller, the Controller ensures that an agreement required by law or other necessary processing arrangements are in place.

26.2. Where GDPR applies, such relationships are governed in accordance with the requirements of Article 28 GDPR.

26.3. Where personal data are transferred from the EEA to a country for which no applicable adequacy decision exists, the Controller uses an international transfer mechanism permitted under GDPR, such as the applicable Standard Contractual Clauses, where that is the mechanism actually used by the parties.

26.4. Transfers from the United Kingdom are made using mechanisms provided for under UK GDPR, including applicable contractual international transfer mechanisms.

26.5. The specific mechanism must correspond to the agreement actually in force with the relevant service provider; this Policy does not replace verification of the relevant DPA, SCCs, UK Addendum/IDTA, or other applicable document.

27. DATA STORAGE AND LOCATION

27.1. Nikahova’s primary server infrastructure is provided by Hetzner Online GmbH.

27.2. Photographs, videos, voice messages, and other media are stored in Hetzner Object Storage.

27.3. The location of the hel1 object storage confirmed by the technical documentation is Helsinki, Finland.

27.4. The specific physical location of the primary leased server shall be specified in the relevant documentation once it has been documented and confirmed by the Controller.

28. USERS IN THE RUSSIAN FEDERATION AND DATA LOCALIZATION

28.1. When collecting personal data of citizens of the Russian Federation, the Controller complies with the requirements of Part 5 of Article 18 of Federal Law No. 152-FZ concerning the use of databases located within the territory of the Russian Federation where that provision applies to the relevant processing.

28.2. Where, following localization required by law, data are transferred to a foreign service provider, such transfer is assessed separately for compliance with cross-border data transfer requirements.

28.3. This Section must correspond to Nikahova’s actual technical architecture. Before commencing the processing of personal data of citizens of the Russian Federation, the Controller must ensure that the infrastructure used complies with applicable localization requirements.

29. CROSS-BORDER DATA TRANSFERS — RUSSIAN FEDERATION

29.1. When transferring personal data to foreign recipients, the Controller complies with Article 12 of Federal Law No. 152-FZ.

29.2. Before commencing the relevant cross-border transfer, the Controller submits the notification required by law to Roskomnadzor where such obligation applies.

29.3. A transfer is carried out only after applicable preliminary requirements have been satisfied and provided that no effective prohibition or restriction has been imposed by the competent authority.

29.4. The volume of data transferred is limited to information necessary for the relevant function.

30. RETENTION PERIODS

30.1. The Controller determines retention periods taking into account the purposes of processing, the volume and sensitivity of the data, mandatory statutory retention periods, the need to prevent abuse, and the possibility of establishing, exercising, or defending legal claims.

30.2. An unverified Account is technically retained for approximately 24 hours following expiration of the verification code and is then deleted.

30.3. An email verification code remains valid for up to 24 hours and is stored in hashed form.

30.4. An access token remains valid for approximately 30 minutes, and a refresh token for up to 30 days.

30.5. The indicator showing that a User is currently online is retained for approximately 60 seconds; the “last seen” information may be retained for up to 30 days; and the date of the Account’s last activity is retained until the relevant Account is deleted.

30.6. Application technical logs are retained for approximately 30 days unless a particular record is required for the investigation of a security incident or a legal dispute.

30.7. An active User’s Profile, photographs, videos, and posts are retained until deleted by the User, the relevant functionality is discontinued, or the Account is deleted.

30.8. A chat deleted by both parties may technically be retained for up to 182 days, after which it is subject to deletion through an automated process.

30.9. If at least one participant retains the chat, the communications may be retained until the relevant processing purpose ceases or the Account is deleted, unless otherwise required by law.

30.10. Payment information and transaction logs are retained for the period necessary to comply with accounting, tax, and payment obligations, handle refunds and disputes, and comply with other mandatory legal requirements, after which they are deleted or anonymized.

30.11. Complaints and information concerning measures taken may be retained for the period necessary to ensure security, prevent repeated violations, and defend against claims. Such records are subject to periodic review and must not be retained indefinitely solely because a technical deletion mechanism is unavailable.

30.12. Moderator action logs and Account enforcement logs are retained for the period necessary for security auditing, investigation of abuse, and protection of the parties’ rights, and shall subsequently be deleted or anonymized once the relevant purpose has ceased.

30.13. Profile impression history is retained only for the period necessary for matching functionality, prevention of repeated impressions, analytics, and security, after which it is deleted or anonymized.

30.14. Error reports are retained only for the period necessary to reproduce, analyze, and correct the relevant technical error, after which they are deleted or anonymized unless another lawful basis for retention exists.

30.15. A User’s private notes are retained until deleted by their author, the relevant functionality is discontinued, or the author’s Account is deleted, unless another lawful basis exists.

30.16. nginx access logs are retained for a limited technical period established by internal information security rules unless specific records are required for the investigation of an incident or the defense of legal claims.

30.17. The Controller must ensure that technical deletion procedures are implemented in accordance with the retention periods and criteria established by this Policy.

31. ACCOUNT DELETION AT THE USER’S REQUEST

31.1. The User may independently initiate Account deletion through the Nikahova functionality.

31.2. Following submission of the request, the Account is deactivated and a 30-day waiting period begins.

31.3. During this period, the User may cancel their own deletion request through the recovery functionality provided by the Service, including by signing in again where such functionality is available.

31.4. Upon expiration of the waiting period, the Account and associated data are deleted to the extent technically and legally permissible.

31.5. Data subject to deletion include, in particular, the Account, Profile, photographs, information about children, chats to the extent that there is no need to retain them for another participant or pursuant to law, notifications, filters, reactions, interaction history, and information concerning linked social accounts.

32. DELETION INITIATED BY THE CONTROLLER

32.1. Deletion or termination of an Account by the Controller due to a violation of the rules, a security threat, or other grounds provided for by the User Agreement constitutes a separate procedure.

32.2. Such deletion is not automatically reversed by a subsequent attempt by the User to sign in.

32.3. The possibility of restoring such an Account is determined exclusively by the Controller, taking into account the outcome of the review of the violation and mandatory legal requirements.

33. DATA THAT MAY BE RETAINED AFTER ACCOUNT DELETION

33.1. Following final deletion of an Account, certain data may be retained only where there is a separate purpose and lawful basis for doing so.

33.2. A cryptographic hash of the email address may be retained where necessary to record the fact of deletion, prevent abuse, or comply with legal requirements.

33.3. Payment information may be retained for mandatory accounting, tax, or payment record-keeping periods.

33.4. Complaints in which the deleted User was the subject of an enforcement action may be retained in anonymized or minimized form where necessary for security, investigation of violations, or defense of legal claims.

33.5. Once the relevant purpose has ceased, the data shall be deleted or irreversibly anonymized.

33.6. The Controller may not retain personal data indefinitely solely because a technical deletion mechanism has not been implemented.

34. USER RIGHTS

34.1. Depending on applicable law, the User may have the right to obtain information about processing, access their data, request rectification or deletion, restrict processing, obtain data portability, object to certain processing, withdraw consent, obtain information concerning recipients, and lodge a complaint with a competent supervisory authority.

34.2. The Controller may request information reasonably necessary to verify the identity of the person making the request and prevent unauthorized access to another person’s data.

34.3. A request must not require more personal data than is objectively necessary to identify the applicant.

35. TIME LIMITS FOR RESPONDING TO REQUESTS

35.1. For Users in the Russian Federation, information concerning the existence and processing of personal data is provided within the period established by Federal Law No. 152-FZ.

35.2. Rectification or destruction of data is carried out within the time limits established by the laws of the Russian Federation for the relevant legal basis.

35.3. For Users in the EU and EEA, requests are handled without undue delay and within the time limits established by GDPR, including the general period of one month from receipt of the request and any extension permitted by law in complex cases.

35.4. For Users in the United Kingdom, the applicable UK GDPR time limits apply.

35.5. For other jurisdictions, the time limits prescribed by mandatory local law apply.

36. WITHDRAWAL OF CONSENT

36.1. The User may withdraw consent where the relevant processing is based on consent.

36.2. Consent may be withdrawn through the relevant Service functionality or by submitting a request to the address specified in Section 2.4 of this Policy.

36.3. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal was received.

36.4. If no other lawful basis for processing exists following withdrawal, the relevant processing shall cease and the data shall be deleted in accordance with applicable law.

36.5. If special category data are objectively necessary for functionality requested by the User, withdrawal of the relevant consent may result in such functionality becoming unavailable.

37. PERSONAL DATA SECURITY

37.1. The Controller implements technical and organizational measures appropriate to the nature and risks of the processing of personal data.

37.2. Measures actually used include secure HTTPS connections, TLS, HSTS, secure WebSocket connections, hashing of passwords and verification codes, private file storage, temporary signed URLs for media, restricted network access to PostgreSQL and Redis, access controls, secure token storage using operating system mechanisms, and logging of moderator actions.

37.3. Access to data is provided only to persons who require such access to perform their respective functions.

37.4. The Controller assesses the risks associated with processing special categories of personal data and implements additional measures appropriate to the level of such risks.

37.5. The Controller improves its security measures taking into account changes in technology, the nature of the data processed, and identified threats.

37.6. No method of data storage or transmission can guarantee the complete absence of risk; however, this does not relieve the Controller of its obligation to implement security measures required by law.

38. PERSONAL DATA BREACHES AND SECURITY INCIDENTS

38.1. A security incident includes, in particular, unlawful or accidental access to, transfer, dissemination, disclosure, alteration, destruction, or loss of personal data.

38.2. Upon discovering an incident, the Controller takes measures to contain it, terminate unauthorized access, preserve necessary evidence, assess the scope of the affected data and potential harm, restore security, conduct an internal investigation, and prevent recurrence.

38.3. The Controller documents material circumstances of the incident and the measures taken where and to the extent required by applicable law.

38.4. Where GDPR applies to an incident and the personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the relevant supervisory authority shall be notified without undue delay and, where feasible, no later than 72 hours after the Controller becomes aware of the breach.

38.5. Where a breach under GDPR is likely to result in a high risk to the rights and freedoms of the affected persons, the affected Users shall be informed without undue delay unless an exception provided by law applies.

38.6. A similar approach applies under UK GDPR: where the risk threshold prescribed by law is met, the ICO is notified within the applicable period, and where there is a high risk, the affected person is informed without undue delay. The ICO confirms the 72-hour time limit for notifiable breaches and the obligation to inform individuals where there is a high risk.

38.7. In the event of an incident falling within Federal Law No. 152-FZ, the Controller complies with Part 3.1 of Article 21, including initial notification to Roskomnadzor within 24 hours and submission of the results of the internal investigation within 72 hours.

38.8. With respect to California residents, the Controller complies with mandatory California security breach notification requirements to the extent applicable to the specific data and incident. California law provides for notification of residents in certain circumstances involving unauthorized acquisition of unencrypted personal information.

39. REQUESTS FROM GOVERNMENT AND LAW ENFORCEMENT AUTHORITIES

39.1. Nikahova does not disclose personal data to government authorities solely on the basis of an informal request.

39.2. Disclosure is permitted where there is a lawful, duly issued and binding request applicable to the Controller, a court order, or another legal basis provided by law.

39.3. Before providing information, the Controller may verify the authority of the requesting body, the form and legal validity of the request, the scope of its powers, and the extent of the information requested.

39.4. The Controller provides only the amount of information objectively required by the relevant lawful request.

39.5. If a request is excessively broad, legally insufficient, or exceeds the requesting party’s authority, the Controller may request clarification, challenge the request, or refuse to disclose data where permitted by law.

39.6. The User may be notified of the relevant request where such notification is permitted by law and is not prohibited by a competent authority or court order.

40. USERS IN THE EU AND EEA

40.1. Where GDPR applies to the processing, the User has the rights provided by the Regulation, including the rights to information, access, rectification, erasure, restriction of processing, objection, portability where applicable, withdrawal of consent, and lodging a complaint with a supervisory authority.

40.2. With respect to the processing of special categories of personal data, Nikahova identifies both a lawful basis under Article 6 GDPR and a separate condition under Article 9 GDPR.

40.3. Where Nikahova relies on explicit consent, the Controller must be able to demonstrate the fact, content, date, method of provision, and applicable version of the consent.

40.4. If Nikahova’s activities in the EEA are subject to the requirement to appoint an EU representative, the Controller shall appoint such representative before commencing the relevant activities and shall publish the representative’s contact details.

40.5. Where the nature and scale of processing give rise to an obligation to appoint a Data Protection Officer or conduct a Data Protection Impact Assessment, the Controller shall comply with the relevant requirements before or during processing within the time limits prescribed by GDPR.

41. USERS IN THE UNITED KINGDOM

41.1. Where UK GDPR applies, the User has the corresponding rights to information, access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and lodging a complaint with the Information Commissioner’s Office.

41.2. A separate condition for processing special category data is identified for the processing of religious beliefs and information relating to intimate life.

41.3. Where explicit consent is relied upon, such consent must comply with UK GDPR requirements.

41.4. Electronic marketing communications are carried out in accordance with PECR.

41.5. Where the law requires the appointment of a representative in the United Kingdom, the Controller shall make such appointment and publish the relevant contact details.

42. CALIFORNIA USERS

42.1. This Section applies to the extent that the CCPA/CPRA applies to Nikahova’s activities.

42.2. Sensitive personal information under California law may include, in particular, religious or philosophical beliefs, certain information concerning racial or ethnic origin, information concerning a person’s sex life, and the contents of private communications where the business is not the intended recipient of such communications.

42.3. Where applicable, the User has the right to know the categories and purposes of processing personal information, access personal information, correct inaccurate information, request deletion, obtain information concerning categories of recipients, exercise any applicable right to limit the use of sensitive personal information, and not be discriminated against for exercising rights provided by law.

42.4. Nikahova does not sell Users’ personal information.

42.5. Nikahova does not use sensitive personal information to create third-party advertising profiles.

42.6. If Nikahova in the future engages in activities constituting a “sale” or “sharing” under the CCPA/CPRA, the applicable opt-out mechanisms shall be implemented before such processing begins.

43. CALOPPA AND DO NOT TRACK

43.1. For California Users, this Policy discloses the categories of data collected, categories of third parties, material uses of the data, and the procedure for changes to the Policy.

43.2. Nikahova does not engage in third-party cross-service advertising tracking; therefore, a change to the browser’s Do Not Track signal does not, in itself, alter the processing of data within the Service.

44. USERS IN OTHER COUNTRIES

44.1. Where the mandatory laws of the User’s jurisdiction provide additional rights or impose additional requirements concerning processing, such mandatory provisions apply notwithstanding the wording of this Policy.

44.2. The Controller may restrict the availability of Nikahova in a jurisdiction where compliance with the mandatory requirements of that jurisdiction cannot be technically or legally ensured.

45. CHANGE OF OWNERSHIP OR BUSINESS STRUCTURE

45.1. In the event of reorganization, transfer of the business, sale of the project, or other legal succession, personal data may be transferred to a successor only where a lawful basis exists and the requirements of applicable law are complied with.

45.2. The new controller or other successor responsible for the data must comply with applicable personal data protection obligations and inform Users where required by law.

46. CHANGES TO THIS POLICY

46.1. The Controller may update this Policy where there are changes in applicable law, categories of personal data processed, Nikahova functionality, moderation methods, infrastructure, service providers, retention periods, or app store requirements.

46.2. The current version shall be published on nikahova.app and must be directly accessible from the Service.

46.3. Material changes affecting the User’s rights or the purposes of processing shall be communicated to the User in the manner required by applicable law.

46.4. Where separate consent is required for new processing, such processing shall not commence until the relevant valid consent has been obtained.

47. RELATIONSHIP WITH OTHER DOCUMENTS

47.1. This Policy applies together with the Nikahova User Agreement, the User-Generated Content Posting and Moderation Rules, the Consent to the Processing of Personal Data, the separate Consent to the Processing of Special Categories of Personal Data, the Consent to the Processing of Personal Data Authorized for Dissemination, and any other consents required by applicable law.

47.2. The User Agreement does not replace consent to the processing of special categories of personal data.

47.3. Consent to the ordinary processing of personal data does not replace consent to the dissemination of personal data.

47.4. Consent to marketing communications, where required, is provided separately and is not a mandatory condition for using Nikahova’s core functionality unless otherwise expressly permitted by law.

47.5. All documents shall use consistent definitions of the Controller, Service, data categories, retention periods, deletion procedures, moderation, and the list of third-party service providers.

48. RECORDING AND EVIDENCING CONSENTS

48.1. The Controller must be able to demonstrate that each consent relied upon as a lawful basis for processing has been obtained.

48.2. The information system shall record, at a minimum, the User identifier, type of consent, version of the document, date and time consent was provided, method by which it was provided, and evidence of the User’s affirmative action.

48.3. For special categories of personal data, dissemination of personal data, and other circumstances for which applicable law establishes a specific form of consent, the Controller shall ensure that the consent is obtained in the required form.

48.4. Pre-ticked checkboxes, silence, or inactivity shall not be used as evidence of consent where applicable law requires an affirmative expression of the User’s wishes.

49. FINAL PROVISIONS

49.1. This Policy shall be made available before the relevant processing begins and shall remain available to the User throughout the User’s use of Nikahova.

49.2. If any provision of this Policy conflicts with a mandatory provision of applicable law, the applicable mandatory provision shall prevail.

49.3. No contractual provision or consent may deprive the User of rights that cannot lawfully be waived under applicable law.

49.4. The Controller shall ensure that this Policy corresponds to the actual operation of the Service and shall update it whenever there are changes to the technical architecture, data recipients, or processing methods.