This policy describes the personal data that Nikaa7 processes, why, on what basis, for how long, with whom, and the rights you have. It is written to correspond to the actual operation of the service, not to an intention: what does not appear in it is not done.
It applies to members, to the trusted persons a member designates, and to visitors to the site. It forms an integral part of the general terms of use and sale.
1. Who is responsible for your data
The data controller is Beaver Data Group, Société par actions simplifiée (Société à associé unique), whose registered office is located at 43 rue de Marquillies, 59000 Lille, France, hereinafter “Nikaa7”.
For any question relating to your personal data or to exercise your rights: contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France. Aucun délégué à la protection des données n’est désigné à ce jour.
For any other question relating to the service: contact@nikaa7.com · +33 7 68 29 14 19.
2. What Nikaa7 is, and what that means for your data
Nikaa7 is a matrimonial introduction service, assisted by a deterministic compatibility calculation and guided by human counselors. The very fact of being a member reveals a matrimonial approach and, by inference, a religious belief. We therefore treat the whole of your account as sensitive: every provider that receives so much as your e-mail address receives data that we protect as such, and this policy says so wherever that is the case.
Four principles govern everything that follows:
- Nothing is public. No photo, no profile, no first name is visible outside your counselor and, within an introduction that has been engaged, the other member.
- Your consent is an act, never a pre-ticked box. It is requested for a specific purpose, with its own information notice, and is withdrawn as simply as it was given.
- No decision that significantly affects you is automated. The review of a proposal, identity verification and any moderation measure are taken by people.
- Your religious practice is never scored, ranked or compared. It is described in your own words, for your counselor and, if you agree, for the other member of an introduction.
3. The data we process
3.1 Data you give us
- Account: e-mail address, telephone number (verified by a code), interface language, date of birth (from which we derive your age — another member sees an age, never your date), declared gender, first name (never shown to another member), optional preferred name.
- Profile: country and city, free-text description, values, life project (marriage horizon, wish for children, place of living), expectations of a spouse by level (preference, important, non-negotiable), languages spoken, family situation, education, occupation, personality positions. At the end of your registration, you attest to the accuracy of your declarations; this attestation is retained with its version and date.
- Declared religious practice and aspects that matter to you: optional fields, in free text and as a list; they fall under Article 9 of the GDPR and are the subject of Article 5 below. A profile is complete without them.
- Family origins (optional): never used in the compatibility calculation.
- Trusted person / wali: see Article 9.
- Messages exchanged with the other member of an introduction; reports you make.
- Appointments: time slot, format (video call, telephone, in person, in person accompanied), video-conferencing link entered, place if entered.
- Credit purchases, where this function is offered: see Article 10.
- Requests you send us (complaint, observations, exercise of your rights).
3.2 Data produced by use of the service
- Consents: each request, grant, refusal, withdrawal and expiry, with the version of the information notice presented, the server timestamp, the originating screen and the IP address at the time of the act.
- Compatibility and proposals: the calculated assessments (score, dimensions, reason codes), the version of the engine and of its configuration, your counselor’s reviews of your proposals, your responses, the state of your introductions.
- Security: (hashed) fingerprints of your session tokens, login attempts with an IP-address fingerprint, audit log of sensitive actions concerning you (including staff access to your data).
- Support: your counselor’s internal notes, which describe their support work and are not shown to you; support, moderation and risk files, if any.
3.3 What we do not collect
- No bank-card data: payment, where offered, is made with our payment provider; we receive neither the number nor the card data.
- No password or authentication secret: they are held by our identity provider.
- No copy of an identity document as at the date of this version: identity verification is a human decision, taken by an authorised member of staff, who informs you of the procedure at the time it is initiated. If a procedure required the presentation of a document, it would be retained only for the duration of the verification, at most thirty days after its end.
- No browsing data for advertising or audience-measurement purposes: see Article 12.
- No geolocation beyond the country and city you declare.
4. Why we process your data, on what basis, for how long, with whom
The table below summarises each processing operation. The durations refer to the retention categories of Article 11. “Staff” means the members of Nikaa7 staff according to their role and scope (Article 8).
| Processing | Purpose | Legal basis | Data | Duration | Recipients |
|---|---|---|---|---|---|
| Account and login | Create and administer your account, verify your address and your number, manage your sessions and your settings | Performance of the contract (Art. 6(1)(b)); legitimate interest in account security (Art. 6(1)(f)) | Account (3.1), session and code fingerprints, IP-address fingerprint | Active account, then Account and profile category | You; support and administration (status only); identity provider; e-mail and SMS provider; Google if you choose sign-in with Google |
| Compatibility search | Check your eligibility, exclude incompatible candidates according to each person’s non-negotiable expectations, rank eligible candidates by a deterministic score, submit each proposal to a counselor | Your “profile processing” consent (Art. 6(1)(a)), requested at registration, optional and withdrawable | Profile (3.1) excluding declared religious practice, free-text description and family origins; calculated assessments | Introduction history | You (score, dimensions, “estimate, not a guarantee” notice); your counselor; administration in read-only. No provider |
| Presentation of a proposal | Show your profile to another member after human review and mutual confirmation | Your “profile sharing” consent (Art. 6(1)(a)) | Profile as projected for another member (age, never the date; never the first name) | Introduction history | The other member of the proposal |
| Declared religious practice | Allow you to describe your practice in your own words, to inform your counselor and, after sharing, the other member | Your separate explicit consent (Art. 9(2)(a) and Art. 6(1)(a)) — Article 5 | Declared practice, important aspects, free-text description | Account and profile; deleted first upon closure | You; your counselor under a sensitive permission, with a logged purpose; the other member after sharing. No provider, no AI-model supplier |
| Introduction and messaging | Open and follow an introduction after mutual interest and each person’s consents; allow written exchange; handle reports | Performance of the contract (Art. 6(1)(b)); your scoped “contact sharing” consent for each introduction; legitimate interest in moderation and personal safety (Art. 6(1)(f)) | Messages (encrypted at rest), timestamps, reports, state of the introduction | Messaging; Introduction history | Both members; your counselor in read-only; a moderator only for messages attached to a reported case, with a purpose; neither administration nor support accesses the content. No provider |
| Appointments | Propose, confirm, reschedule, cancel a meeting | Performance of the contract (Art. 6(1)(b)) | Time slot, format, link, place, participants | Introduction history | Both members; your counselor; the trusted person if their scope covers it; e-mail provider for notifications (never the link) |
| Trusted person / wali | Allow a member to designate an outside person, invite them, give them a limited view and make her first meeting conditional on their agreement or on her own derogation | Member: performance of the contract (requested option) · trusted person: the member’s legitimate interest in involving a close relation, balanced by minimisation and their right to refuse (Art. 6(1)(f)); their own acts (accepting, withdrawing): their consent | Article 9 | Account and profile | The trusted person (limited view); you; your counselor (status, derogation); e-mail or SMS provider for the invitation |
| Video conference organised by the trusted person | When this function is active: allow the wali to create, from their own Google calendar, the first-meeting conference | Performance of the contract (arranging the requested meeting); connection of their Google account by the wali themselves | Article 9.4 | Tokens and links deleted with the account; precise durations being determined | Google, as third-party provider of the video-conferencing service — never your addresses or your names; the participants for the link, within the appointment window |
| Credit purchases | Where this function is offered: sell credit packs, reserve, use and release a credit, reconcile, refund upon human decision | Performance of the contract (Art. 6(1)(b)); legal obligation of accounting retention (Art. 6(1)(c)) | Article 10 | Billing: ten years from the close of the financial year, never deleted by account deletion | You; support and administration under a dedicated permission; payment provider; chartered accountant |
| Support, assistance, moderation | Support you (assigned counselor, internal notes, tasks, work queue calculated by deterministic rules); handle your requests; investigate reports and risk situations | Performance of the contract (Art. 6(1)(b)); legitimate interest: moderation, personal safety, fraud prevention (Art. 6(1)(f)) | Internal notes, files, reasoned decisions | Notes: Account and profile · support files: Support · moderation and risk: Audit and security | Your counselor; support and moderation within their scope; administration. No provider |
| Security, audit, operations | Immutably trace every sensitive action and every denied access; detect and handle incidents; back up and restore | Legitimate interest (Art. 6(1)(f)); security and accountability obligations (Art. 6(1)(c), Art. 32 and 33(5)) | Audit log (actor, role, permission, object, result, reason, before/after, IP, browser, chaining), allow-listed technical logs, backups | Audit and security: rolling twelve months | Moderation and administration under permission; operations; host (data at rest); AWS for sealing encryption keys (never your data) |
| Proof of consents | Prove what you accepted, refused or withdrew, when, and on the basis of which text | Legal obligation to demonstrate consent (Art. 7(1), Art. 6(1)(c)); legitimate interest in the event of a dispute | Consent register (3.2) | Proof of consent: five years after withdrawal or closure, attached to a pseudonymised identifier | You; your counselor (read-only projection); support for a file; administration under an audit permission |
| Service monitoring | Track aggregated indicators (funnel, introductions, moderation, availability) | Legitimate interest (Art. 6(1)(f)) | Aggregated counters without identifiers, calculated server-side; no cell of fewer than twenty people; no breakdown by religious practice | Not retained individually | Administration; operations. No provider |
| Exercise of your rights | Handle your requests for export, deletion, rectification, objection | Legal obligation (Art. 6(1)(c), Art. 15 to 22) | Your request and its trace | Trace of the request per Audit and security | You; administration for the deletion queue |
We do not sell your data. We do not rent it. We do no targeted advertising, no profiling for commercial purposes, and we transmit nothing to an artificial-intelligence model supplier: none of our processing operations sends your data to such a service.
5. Data revealing your religious beliefs
Your declared religious practice, the aspects that matter to you and your free-text description are Article 9 GDPR data.
Basis. We process them solely on your explicit consent, collected by a dedicated box, separate from acceptance of the general terms and from acknowledgement of this policy, never pre-ticked, presented with the information text in its dated version, and with a statement of the consequences of a refusal or withdrawal. You can create an account, receive proposals and engage an introduction without filling in these fields.
What we never do with them. No score, no level, no scale, no ranking, no selection constraint derives from these fields. The compatibility calculation does not receive them: its input structurally does not contain them. Nor are they used to filter indicators, or to decide on a measure concerning you.
Who reads them. You; your counselor, who must hold a specific sensitive permission, state the purpose of their reading, and each of whose readings is logged; an administrator under the same permission and the same logging; the other member of an introduction, after you have granted the sharing of your profile. No provider receives them.
How they are protected. They are envelope-encrypted at rest, under a dedicated key, distinct from that of other data. They never appear in a technical log, a notification, a trace or an audit event, which carry only a reference to them.
Withdrawal. You can withdraw this consent at any time from your consent centre; the fields then cease to be processed and are deleted from your profile. Withdrawal has no effect on the lawfulness of past processing, and has no consequence for your account.
6. Your consents
Each consent relates to a specific purpose and is the subject of its own information notice, presented at the moment of the act. It is never presumed, never pre-ticked, never conditional on a payment, and only the member concerned can grant it: no member of staff can do so in their place, and this rule is verified by the system, not only by the screen.
As at the date of this version, the consents in service are:
| Consent | Scope | Purpose | Effect of withdrawal |
|---|---|---|---|
| Profile processing | General | Enter the compatibility search | You leave the search; ongoing proposals are closed |
| Profile sharing | General | Present your profile to the other member after mutual confirmation | No new presentation; active introductions are reassessed |
| Contact sharing | A specific introduction | Open the exchange in this introduction | The introduction ends; the other member receives a neutral notification, without any reason: “This introduction is no longer available.” |
| Photo visibility | General or a specific introduction | Make your photos visible (Article 7) | Immediate withdrawal of visibility |
| Communication with the trusted person | A specific trusted person | Allow communications with the designated person | Access revoked; communications suspended |
| Declared religious practice | General | Article 5 | Deletion of the fields concerned |
Other consent types exist in our register (notification channel by instant messaging, non-transactional communications, assistance by an artificial-intelligence model): none of these functions is in service; if one of them were offered, your consent would be requested beforehand, and nothing would be activated without it. We send you no non-transactional communications.
What is not a consent. At registration, you accept the general terms and you acknowledge this policy; these two acts are recorded with the version of the text presented and its date. They are contractual and informational acts, not consents within the meaning of the GDPR: they found no processing of your sensitive data and replace none of the consents above.
Register. Each request, grant, refusal, withdrawal and expiry is entered in a register in which nothing is modified or deleted, with the version of the text that was presented to you. If the information notice changes, your previous consent expires and you are informed; it is never tacitly extended. You view your consents and their history, and withdraw them, from your consent centre.
7. Photos
No photo is public, and none becomes public by default or by an implicit setting. Where adding photos is offered, a photo is visible to another member only if you have granted the “photo visibility” consent, for everyone or for a specific introduction; without that consent, it is visible only to you. Withdrawal takes effect immediately. Other members are represented by their initials as long as no consent of this type exists.
8. Who, at Nikaa7, accesses your data
Each role receives only what is necessary for its mission, within a defined scope, and sensitive permissions are granted one by one — being an administrator implies none of them.
- Your counselor accesses your profile and your proposals to review them and support you; they read your messages in read-only mode; they never modify a score and never grant a consent in your place.
- Support accesses the status of your account and the files concerning you, never your messages.
- A moderator accesses only the messages attached to a report or a case, with a recorded purpose.
- An administrator accesses statuses, the deletion queue, the audit log and billing under dedicated permissions; they do not access the content of your messages.
- The trusted person has no account and sees only what the member authorises (Article 9).
Every sensitive staff action requires a reason and produces an immutable audit event, in the same operation. Every denied access is logged. No member of staff can “sign in as” you.
9. Trusted person / wali
9.1 What we record
When a member designates a trusted person, she indicates their preferred name, the relationship between them (from a closed list), a means of contacting them (e-mail address or telephone number) and the language of the invitation. The means of contact is encrypted before being recorded; there is no moment at which it is stored in clear text. The trusted person does not create an account and has no role in our system.
9.2 What the trusted person receives and sees
They receive an invitation by e-mail or SMS, with the name the member has chosen to show them and a personal single-use link, valid until an indicated date. The invitation screen explains to them the relationship indicated, the purpose of their designation, what they will see if they accept, what they will never see, and that no account will be created. They are free to accept or decline; their refusal, silence or withdrawal has no effect on the member’s journey.
If they accept, they see a page limited to the scope defined by the member: the stage of the journey and, depending on the scope, the milestones of an introduction or an appointment. They never access the full profile, the proposals, the messages, the compatibility analysis, the account settings, or any data of the other member. Each viewing is recorded and visible to the member, who can revoke access at any time. The trusted person may withdraw at any time.
9.3 Basis, duration, information
With regard to the trusted person, we process their data on the basis of the member’s legitimate interest in involving a close relation of her choice in her approach, to the minimum extent necessary and with an effective right to refuse; their own acts (accepting, withdrawing) rest on their consent. The conditions of religious suitability of a wali, if the member takes them into account, are informative, never verified or recorded. Their data are retained with the member’s account and deleted with it, or as soon as access is revoked or they withdraw. They have the rights set out in Article 13, which they exercise with contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France.
9.4 Calendar and video conference of the trusted person
When this function is active, the wali can connect their own Google account to create, from their calendar, the first-meeting conference. In that case:
- we ask Google for the sole authorisation to create and manage calendar events; we retain, encrypted, the access tokens Google gives us;
- the event created with Google carries a neutral title (“Rendez-vous Nikaa7”), a time slot and a conference; no guest, no name, no e-mail address, no member reference is transmitted to it, and this property is verified by our tests;
- the conference link is retained encrypted, never logged, and is given to participants only within the appointment window; staff do not see it;
- Google processes, under its own conditions, the connection data of the participants in the conference (IP address, display name); Nikaa7 neither records nor transcribes the meeting;
- disconnecting the Google account is possible at any time; the tokens are deleted with the member’s account.
Google acts here as a third-party provider of the video-conferencing service, chosen by the wali, and not as a processor of Nikaa7.
10. Credit purchases
Where the purchase of credits is offered, payment is made with our payment provider, Stripe. We transmit to it only technical identifiers (payment reference, member reference, pack code), the amount and the currency — no name, no e-mail address, no profile data. The data you enter on the payment page (payment method, billing address, e-mail address for the receipt) are collected by Stripe, which is the controller of its own processing operations (fraud prevention, regulatory obligations), under its own policy. We receive in return the status of the payment and, where applicable, the last four digits of the payment method.
We retain the history of your payments, of your credits (reservations, uses, releases) and of refunds in a register in which nothing is modified, for ten years from the close of the financial year, pursuant to the French Commercial Code (code de commerce). This retention survives the deletion of your account, under restricted access. If you arrive on the site through a partner link, a campaign code is stored for seven days (Article 12) and attached to your first purchase for the calculation of the partner’s commission; the partner receives no data concerning you.
11. How long we keep your data
The durations below are those decided by the controller (version retention-2026-09-v1). They are read by the system from a versioned configuration; no duration is hard-coded. On expiry, the data are deleted or irreversibly anonymised, unless an identified legal obligation applies (“retention under obligation”).
| Category | Content | Duration | Starting point |
|---|---|---|---|
| Account and profile | Account, profile, expectations, values, counselor notes, trusted person, preferences | As long as the account is active; 24 months after your last meaningful activity, you are warned and then the account is deleted or anonymised | Last meaningful activity |
| Identity | Identity-verification metadata | 12 months; any documents: end of the verification, at most 30 days | Account closure |
| Proof of consent | Consent register, attestations, derogations | 5 years, restricted-access archive, attached to a pseudonymised identifier | Withdrawal, closure or end of the relationship |
| Messaging | Messages, reports | 12 months; extended retention possible for an identified dispute | Account closure |
| Introduction history | Assessments, proposals, responses, introductions, appointments | 12 months, then deletion or irreversible anonymisation | Account closure |
| Audit and security | Audit log, access to sensitive data, moderation and risk cases | Rolling 12 months; extension of an identified subset possible for a legal obligation | Recording of the event |
| Support | Support files | 3 years; ongoing litigation prevails | Closure of the file |
| Billing | Payments, credits, refunds, accounting records | 10 years; never deleted by account deletion | Close of the financial year |
Separate technical durations: the download link for your data export expires after 15 minutes and can be used only once; the grace period before an account deletion is executed is 30 days (Article 13.3); cookie durations are set out in Article 12.
12. Cookies and trackers
Nikaa7 uses only cookies strictly necessary for the operation of the service. No advertising cookie, no audience-measurement tracker, no third-party script: our pages execute only code served by Nikaa7 (strict content security policy), and our indicators are aggregates calculated server-side, without any visitor identifier. As these cookies are exempt from consent, no banner is presented to you; we inform you of them here.
| Cookie | Role | Duration | Characteristics |
|---|---|---|---|
nikaah_access, nikaah_refresh |
Keep your session signed in | Expiry set by the server for each session | Inaccessible to scripts, transmitted only over a secure connection |
nikaah_locale |
Remember the language you have chosen; never inferred from your country or your IP address | 1 year | Preference, without identifier |
nikaah_ref |
Remember the campaign code of a partner link, for the attribution of a first purchase | 7 days | Public campaign code, never personal data; inaccessible to scripts |
| Technical sign-in and calendar-return cookies | Carry, for the duration of a sign-in journey or a return from the trusted person’s calendar, a technical reference needed for the next step | A few minutes | Inaccessible to scripts; deleted at the end of the journey |
If we were one day to introduce editorial audience measurement, it would be activated only with your consent, collected before anything is placed.
13. Your rights
You have the rights of access, rectification, erasure, restriction, objection, portability and withdrawal of your consents, as well as the right to set out directives regarding the fate of your data after your death. Here is how each is exercised in practice.
13.1 Access and portability
From your privacy centre, you request an export of your data. It is produced as a structured, machine-readable file (nikaah-data-export/v1), which contains: your account (e-mail address, phone number, language, status, creation date, the versions of the terms and of the policy you accepted); your profile (member reference, status, first name, last name, date of birth, gender, country, city, description, declared ranges and your parents’ origins if you provided them); your family situation, education, occupation and personality traits; your expectations, your life project, your values and your languages; your declared religious practice and the aspects you consider important; your consents and their complete history (event, type, scope, purpose, text versions, date); your notification preferences; your responses to proposals; the messages you sent; your appointments (slot, format, status, your response); the designation of your trusted person (relationship, name, invitation status); your payments, your sales documents (invoices and credit notes) and your credit history; your deletion and export requests; the status of your identity verification.
The file itself states what it excludes and why: technical secrets; your counselor’s internal notes; identifiers that would name a third party; the profile, identity and response of the other member of a proposal or an introduction; your trusted person’s contact details (which belong to them); video-meeting links and the meeting provider’s references; the payment provider’s technical identifiers; photo files and the content of any identity documents — which you already hold. It never contains another member’s data; received messages also belong to their author and do not appear in it. For any other data concerning you, write to contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France: we provide it to you within the time limits of Article 13.6.
The download link is valid for 15 minutes and can be used only once; the file is then deleted from our storage. Only one export is prepared at a time. Each export is logged, without its content.
13.2 Rectification
You edit your profile, your expectations and your settings directly from your account area. Evidentiary registers (consents, audit, moderation decisions, attestations) cannot be modified: they are dated facts. A challenge is addressed to contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France and produces a new record, never a rewrite.
13.3 Erasure — deletion of your account
You request the deletion of your account from your privacy centre; a confirmation step is presented to you. Only you can request it — no member of staff can open it in your place — and only you can cancel it, during a grace period of 30 days displayed with its expiry date. During this period, the status of the request is visible in your account area.
On expiry of the period, the deletion is executed, category by category, starting with the most sensitive data:
- deleted: profile and associated data, trusted person and their access, sessions, preferences, tokens, exports, identity data, proposals, assessments, introductions, appointments, conversations;
- anonymised: your messages, whose author is pseudonymised so that the other participant keeps the coherence of their thread;
- retained under obligation, attached to a pseudonymised identifier and under restricted access: the register of your consents (proof that you had accepted and then withdrawn), the audit log, moderation and risk cases, and billing records for the legal duration.
Ongoing introductions come to an end; the other member receives the neutral notification of Article 6. Your account with our identity provider is deleted. An identified legal obligation (proceedings, requisition) may suspend execution: this suspension requires a reason, is logged, does not modify your request, and the request resumes when the suspension is lifted.
13.4 Withdrawal of consents
From your consent centre, at any time, with immediate effect (Article 6). Withdrawal does not call into question the lawfulness of prior processing.
13.5 Objection and restriction
You may object, on grounds relating to your particular situation, to processing based on our legitimate interest (account security measures, moderation, aggregated indicators) by writing to contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France; we comply unless there are compelling legitimate grounds, which we set out to you. We carry out no marketing; there is therefore nothing to object to on that ground. You may request the restriction of a processing operation in the cases provided for by Article 18 of the GDPR.
13.6 How we respond
Write to contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France, preferably from the e-mail address of your account. If we have reasonable doubt about your identity, we may ask you for additional information, without ever requiring a copy of an identity document where another means suffices. We respond within one month of receipt of your request; this period may be extended by two months given the complexity or number of requests, in which case we inform you within the first month with the reasons. Exercising your rights is free of charge.
13.7 Complaint
If you consider that your rights are not being respected, you may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at www.cnil.fr. If you reside in another Member State of the European Union, you may apply to the supervisory authority of your country of residence.
14. Recipients, providers and transfers
14.1 Our providers
| Provider | Role | What it receives | Location |
|---|---|---|---|
| Identity provider (ZITADEL) | Accounts, credentials, authentication factors, sessions | E-mail address, verification status, technical identifier; your credentials and authentication secrets are held with it, never with us | Instance configured in a European Union region; Google Cloud infrastructure |
| Brevo | Sending of transactional e-mails and SMS messages (verification codes, invitations, notifications) | E-mail address, telephone number, content of the transactional message | European Union; SMS routing passes through the operators of the destination country |
| Amazon Web Services | Sealing of encryption keys; temporary storage of your data export | For sealing: only key material, never your data; for the export: the encrypted file, deleted after download or expiry | Europe region (Stockholm, Sweden) |
| HOSTINGER INTERNATIONAL LIMITED | Hosting of the platform and its backups | All data at rest | European Union |
| Stripe | Payment for credit packs, where offered | Article 10 | Ireland, with entities and sub-processors outside the European Union |
| Third-party provider of the video-conferencing service chosen by the trusted person (Article 9.4); federated sign-in if you choose it | Article 9.4; for federated sign-in: Google learns that you sign in to Nikaa7 | Google’s conditions |
Each of our processors is bound by a data-processing agreement. We have no audience-analytics provider, no advertising provider, no artificial-intelligence model supplier, no external observability provider.
14.2 Sign-in with Google
You can create your account and sign in with an e-mail address, which we recommend. Sign-in with Google is optional: if you choose it, Google knows that you use Nikaa7 — which reveals, by inference, a matrimonial approach and a religious belief. Nothing else is transmitted to it by Nikaa7.
14.3 Transfers outside the European Union
Our data are hosted and processed in the European Union. Some providers (identity provider, payment provider, Google) may involve entities or sub-processors located outside the European Union, in particular in the United States. In that case, the transfer is governed by an adequacy decision or by standard contractual clauses adopted by the European Commission, supplemented where necessary by additional measures. You can obtain details of the safeguards applicable to a provider by writing to contact@nikaa7.com — Beaver Data Group, 43 rue de Marquillies, 59000 Lille, France.
14.4 Authorities
We disclose your data to an authority only upon a request based on a legal obligation, after verifying its basis, and only to the extent requested; each disclosure is logged.
15. Compatibility, human review and absence of automated decision-making
The compatibility indication is calculated deterministically, from your declarations and those of the other member, according to a versioned method: same inputs, same version, same result. No language model is involved in this calculation, and there is to date no artificial-intelligence assistance in the service. The score ranks candidates who are already eligible; it neither authorises nor prohibits a proposal. The expectations you declare as “non-negotiable” serve to exclude candidates, symmetrically for both members; your declared religious practice enters into none of these steps.
No proposal is presented to you without a counselor having reviewed it; they may set it aside, with a reason, and never modify a score. You see the score and its dimensions with a notice: it is an estimate, not a guarantee.
No decision producing legal effects or significantly affecting you is taken in an exclusively automated manner: identity verification, moderation measures, a restriction or a suspension are decided by people, with a recorded reason. An automatic signal never restricts an account on its own.
16. Security
- Encryption in transit of all communications.
- Envelope encryption at rest, under separate keys per category, whose master keys are sealed in a dedicated service separate from the hosting: your messages, your telephone number, your trusted person’s means of contact, the access tokens to the wali’s Google calendar and the video-conferencing links, as well as your declared religious practice (Article 5).
- Immutable audit log, server-timestamped, chained by fingerprints: any direct modification is detectable; evidentiary registers refuse any modification or deletion at database level.
- Least privilege: roles and scopes, explicit sensitive permissions, mandatory purpose to read sensitive data, every denied access logged.
- Authentication: credentials and factors with the identity provider; multi-factor authentication mandatory for all staff, verified by Nikaa7 at each session opening; rotating sessions with replay detection; you see your active sessions and can close them all from your account area.
- Isolation: databases are not reachable from the Internet; no production data leaves production; technical logs follow an allow-list of fields and contain no message, no religious data and no e-mail address, and a test blocks any leak.
- Backups protected in access and verified by fingerprint.
No system is infallible; that is why Article 17 describes what we do in the event of a breach.
17. Data breach
Every data breach is entered in our internal register, whether or not it is notified. Where a breach is likely to result in a risk to your rights and freedoms, we notify it to the CNIL within 72 hours of its discovery. Where it is likely to result in a high risk, we inform you without undue delay, by a message describing the nature of the breach, its likely consequences, the measures taken and how to contact us — without ever repeating the compromised data. We presume this high risk as soon as data revealing a religious belief or identity data are concerned, for even a single person.
Our internal time limits are set: immediate security escalation, information of the controller within two hours, first assessment within eight hours, decision on notification within twenty-four hours.
18. Minors
The service is reserved for persons aged eighteen or over. The date of birth is requested at registration and verified to the day; a person who is not of the required age cannot complete their registration. If we found that an account belonged to a minor, we would close it and delete their data.
19. Changes to this policy
This policy carries a version number and an effective date. Any substantial change is notified to you before it takes effect; where it affects a consent, that consent expires and is requested from you again with the new text (Article 6). Previous versions are retained and remain available on request.
20. Version
Version legal-2026-09-v1, as at the effective date indicated at the head of the document.