Privacy Policy
UK GDPRLast updated: 2026-08-20
How GOMO CAPITAL MANAGEMENT LTD processes personal data, in accordance with the UK GDPR and the Data Protection Act 2018.
Template document, aligned with the UK GDPR, the Data Protection Act 2018 and the Online Safety Act 2023. Have it reviewed by UK legal counsel before official publication.
1. Controller
GOMO CAPITAL MANAGEMENT LTD, registered in England and Wales under number 16395341, is the controller of the personal data processed across every brand of this platform. The corporate details are on the public Companies House register.
2. Privacy contact / DPO
Where required, we will appoint a DPO. Privacy contact: [email protected]. If you are outside the United Kingdom, we operate under the UK GDPR representative rules.
3. Data we collect
- Account: e-mail, phone, social login, passkey, Web3 wallet address
- Profile: nickname, photo, age, city, bio, interests, intents
- Interaction: messages, media, votes, likes, reports, blocks
- Technical: IP, device, language, logs and metadata
- Safety: fraud, abuse, moderation and age-assurance signals
4. Sensitive data and inferences
Using a dating platform can reveal, or allow inferences about, social life, relationships and preferences. We treat this data with enhanced care, data minimisation and privacy by design. Where the law requires, we rely on explicit consent or another lawful condition under the DPA 2018.
5. Legal bases (Art. 6 and 9)
- Performance of contract — operating account, profile, chat and matches
- Consent — location, special category data and marketing
- Legitimate interest — safety, anti-fraud and moderation
- Legal obligation — Online Safety Act 2023 duties and other laws
6. Automated decisions (Art. 22)
Messages, images and audio may be analysed automatically before they appear. Material decisions can be contested and routed to human review via the privacy contact, save for urgent temporary measures.
7. Sharing
We do not sell your data. We share only with essential processors (hosting, authentication, anti-fraud, moderation, support) under contract, and with authorities where required by law. See Sub-processors.
We use Google reCAPTCHA Enterprise to protect account access against abuse and automated login attempts. It runs invisibly at that step and sends usage data to Google — IP address, device and browser information, and on-page interactions — to compute a risk score; we do not use it for advertising. That processing is governed by Google's Privacy Policy and Terms of Service (policies.google.com/privacy and policies.google.com/terms).
8. The HZION group and centralised identity
ParLocal is a white-label brand served by HZION, the group's core platform. Your account, your identity and your profile data are created and held ONCE on HZION's central infrastructure — there is no per-brand copy — even though you registered and sign in on parlocal.com.br.
HZION is operated by the SAME controller, GOMO CAPITAL MANAGEMENT LTD: this centralisation is not disclosure to a third party, which is why it does not appear in the processor list in the previous section. The infrastructure is globally distributed, so processing may take place in more than one country — see the international transfers section.
In practice: an account created on any brand in the group is the same account before HZION; a data-subject right you exercise applies to all of them at once; and deleting your account deletes the central record, not just the brand you signed up on. Questions: [email protected].
9. International transfers
Restricted transfers rely on UK GDPR safeguards: adequacy decisions, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the SCCs, or another valid mechanism.
10. Retention
We keep data for as long as needed for the service and legal duties. Safety records and Online Safety Act-relevant logs are kept for the applicable period; after that we anonymise or delete.
11. Your rights (Art. 15-22)
- Access a copy of your data
- Correct incomplete or out-of-date data
- Request erasure
- Restrict or object to processing
- Portability
- Withdraw consent
- Complain to the ICO at ico.org.uk
12. Security and breaches
We use encryption in transit and at rest, access control and continuous moderation. In the event of a breach with material risk, we will notify the ICO within 72 hours and inform you where required. Contact: [email protected].