Tenerse logo

Legal

Privacy Policy

This Privacy Policy explains how Tenerse collects, uses, shares, retains, and protects personal data, and the rights you have over your information under GDPR, UK GDPR, CCPA, and other applicable privacy laws.

Last updated: 1 January 2025

Tenerse is built on a privacy-first model. We collect only what is necessary to verify identity, operate the society, and protect members. We do not sell personal data. We do not run public member directories. We treat verification data with elevated safeguards.

1. Data controller

Tenerse is the controller of personal data processed in connection with the Tenerse services. For any privacy enquiry, including exercising your rights, contact privacy@tenerse.com. If you are in the European Economic Area or the United Kingdom and require a representative, contact us at the same address and we will direct you appropriately.

2. Categories of personal data we process

  • Account data: email, password hash, account preferences, authentication logs.
  • Identity verification data: government-issued identification, date of birth, facial biometric template used solely for authentication, address, and related verification metadata.
  • Profile and membership data: profile fields you choose to provide inside the application.
  • Payment data: billing details processed by our payment partners; we do not store full card numbers.
  • Device and usage data: IP address, device identifiers, browser type, language, pages accessed, timestamps, and diagnostics.
  • Communications data: messages you send to us, support tickets, and customer service records.
  • Risk and fraud signals: sanctions screening results, fraud indicators, and security telemetry.

3. Purposes and legal bases

We process personal data on the following legal bases under the GDPR and UK GDPR:

  • Contract: to provide the services, create and manage your account, and process payments.
  • Legal obligation: to verify identity and age, conduct sanctions screening, prevent fraud, respond to lawful requests, and meet recordkeeping duties.
  • Legitimate interests: to secure the platform, prevent abuse, improve the services, and protect members, balanced against your rights and expectations.
  • Consent: for biometric processing, certain optional features, and non-essential cookies. You may withdraw consent at any time without affecting prior lawful processing.
  • Vital and public interest: in rare circumstances, to protect life or assist competent authorities.

Where we rely on consent for biometric processing under Article 9 GDPR, refusing or withdrawing consent means we cannot complete identity verification and you cannot proceed to verified membership.

4. How we share data

We share personal data only with:

  • identity verification, biometric, and KYC providers acting as our processors;
  • cloud hosting, database, email, and analytics providers acting as our processors;
  • payment processors acting as independent controllers for payment compliance;
  • professional advisers, auditors, and insurers under duties of confidentiality;
  • competent authorities, courts, and regulators when legally required;
  • a successor entity in connection with a merger, acquisition, or reorganisation.

We do not sell personal data and we do not share personal data for cross-context behavioural advertising.

5. International transfers

Tenerse operates globally. Personal data may be transferred to and processed in countries outside your country of residence, including the United Kingdom, the European Economic Area, and the United States. Where data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful transfer mechanisms. A copy of the relevant safeguard is available on request.

6. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, regulatory, tax, accounting, fraud-prevention, and dispute-resolution requirements. Verification records are typically retained for the duration of your membership and for a period afterwards as required by applicable identity, anti-fraud, and financial-crime laws. When retention is no longer required, we delete or anonymise the data.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit and at rest where appropriate, access controls, segregation of verification data, audit logging, vendor due diligence, and incident response procedures. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your rights

Depending on your jurisdiction, you may have the following rights:

  • access to the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure (the "right to be forgotten"), subject to legal retention duties;
  • restriction or objection to certain processing, including based on legitimate interests;
  • portability of data you have provided to us in a structured, commonly used format;
  • withdrawal of consent at any time where processing is based on consent;
  • the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save where permitted by law;
  • the right to lodge a complaint with your local supervisory authority, including the UK Information Commissioner's Office (ICO) or your national EU data protection authority.

Residents of California, Colorado, Virginia, Connecticut, Utah, and other US states with applicable privacy laws have rights to know, access, correct, delete, and opt out of sale or sharing and targeted advertising. Tenerse does not sell personal data or share it for cross-context behavioural advertising. To exercise any right, contact privacy@tenerse.com. We will verify your request before acting and respond within the timeframes required by law.

9. Automated decision-making

Identity verification involves automated checks, including biometric facial matching and sanctions screening. A human reviewer is involved in adverse decisions that materially affect your ability to become a member. You may request human review, express your view, or contest a decision by contacting privacy@tenerse.com.

10. Children

Tenerse is strictly for adults. We do not knowingly collect personal data from anyone under the age of majority. If you believe a minor has provided personal data to us, contact us and we will take prompt steps to delete it.

11. Cookies and similar technologies

We use strictly necessary cookies to operate the services and may use limited analytics or preference cookies where you consent. You can manage cookies through your browser settings and, where shown, through our in-app consent controls. Disabling strictly necessary cookies may impair the services.

12. Marketing communications

We send service messages required to operate your membership. Marketing communications, where offered, are sent only with your consent or as otherwise permitted by law, and you can unsubscribe at any time using the link in the email or by contacting us.

13. Member visibility and privacy by design

Verified members can only see other verified members in accordance with the visibility rules described in the application. Unverified accounts cannot see member photos, names, bios, or contact details. We do not publish a public member directory. We do not allow scraping or external aggregation of member data.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated through the application, by email, or by updating the "Last updated" date above. Continued use of the services after changes take effect constitutes acceptance of the updated Policy.

15. Contact

For privacy enquiries, including to exercise your rights or to contact our data protection team, write to privacy@tenerse.com.