VEERMU · EFFECTIVE 2026-08-07
Privacy & Personal Data Usage Policy
This notice explains, in plain language, how Veermu processes personal data to run a safer dating service. It is not a substitute for advice from a privacy regulator or qualified local counsel.
1. Who is responsible and how to contact us
Orets Technologies Ltd, operating from Uganda, is responsible for the data it processes through Veermu. Use the signed-in Privacy Centre, email customer@veermu.com, or contact customer@veermu.com. We verify requests through a member’s verified contact details to reduce fraud.
2. Data we process
We process registration and contact details; profile content and photos; verification status; messages and abuse reports; device, security and technical logs; matching preferences; subscription and payment-reference records; and support communications. Payment providers process card or mobile-money credentials on their own secure payment pages. Veermu does not store raw card numbers.
3. Why we use data and our legal bases
We use account, profile and subscription data to perform our contract with you; use biometric face embeddings only with explicit consent; use limited security and abuse-prevention data for legitimate interests in protecting members; and retain limited information where legal obligations require it. We collect only what is reasonably needed for these purposes.
4. Biometric face data
With your explicit agreement at registration, Veermu derives a compact mathematical face embedding from your enrolment. It is encrypted before storage and compared with future profile-photo uploads to check that the photo depicts you. The enrolment recording is not retained as your face template. You may request deletion of the embedding; photo uploads then require fresh enrolment. Do not enrol if you do not agree to this processing.
5. Loyalty Score and profiling
Every member starts at 100% in good standing. Veermu may deduct from that score only for evidenced behaviours that default our trust standards, such as indiscriminate discovery, clearly unfocused reciprocal conversations, overlapping commitments, or staff-reviewed misconduct. Being new, inactive, single, or simply receiving a report does not reduce a score. Older reviewed incidents reduce in weight over time, and confirmed respectful conduct can support recovery. The score supports dating-quality and trust features, not legal, employment, credit, insurance, housing or similarly significant decisions. You may request a human review, correction or objection through the Privacy Centre. We do not use sensitive face embeddings as a Loyalty Score factor.
6. Sharing, transfers and security
We use carefully selected service providers to host the service, deliver verification messages, and process payments. They receive only the data needed for their service and must protect it under contract or their applicable terms. Data may be processed outside your country. We use HTTPS for data in transit, access controls, encrypted biometric templates, secret-managed credentials, rate limiting and monitoring. No system can promise absolute security; never share your password or verification code.
7. Retention
We retain account and profile data while an account is active. Verification codes expire in 10 minutes; biometric embeddings are deleted when you request deletion or close the account, unless a limited security or legal record is required. We target deletion of ordinary profile content within 30 days of a completed deletion request, subject to backups which rotate within 90 days. Payment references, consent records, abuse reports and security logs are retained only for fraud prevention, disputes, tax or legal obligations and reviewed periodically. Request deletion through the Privacy Centre.
7a. Service providers
Our processor categories include cloud hosting and security infrastructure, Twilio Verify for verification messages, PesaPal for payment checkout and payment status, and approved photo-verification/image-processing services. Each receives only the data necessary for its service. We update this list when material providers change.
8. Your choices and rights
Depending on where you live, you may have rights to be informed, access, correction, deletion, portability, restriction, objection, withdrawal of consent, and review of certain automated decisions. The Privacy Centre records requests for access/export, erasure, restriction, objection and Loyalty Score review. You may also complain to your local regulator. Withdrawal does not affect processing already carried out lawfully, and some features cannot work without necessary data.
9. Regional approach
We designed this notice to support transparency, individual rights, security and accountability principles reflected in the EU GDPR, UK GDPR, Australia’s Privacy Act and major African data-protection frameworks. Local requirements differ and may evolve; Veermu will update this policy and its safeguards as its operations and legal obligations develop.
10. Changes
For material changes, we will publish the new version before it applies and request fresh agreement where the law or the change requires it.