Privacy Policy
Ichötà Privacy Policy
Effective Date: 21 February 2026
Version: 2.0
Last Updated: 21 February 2026
INTRODUCTION
Ichötà Limited (company number 15530216), registered at 53 Stonefall Avenue, Harrogate, HG2 7NR, United Kingdom ("Ichötà", "we", "us", "our") is committed to protecting your privacy and upholding the highest standards of discretion, dignity, and safety in the matchmaking process.
This Privacy Policy explains how we collect, use, disclose, store, and safeguard your personal information when you use our services, including:
- Our website at www.ichota.co
- Our mobile applications (iOS and Android)
- Concierge interviews and matchmaking services
- Events, retreats, and experiences
- All related features and functionalities
This Privacy Policy should be read alongside our Terms of Service and Member Consent Form.
WHO WE ARE
Data Controller: Ichötà Limited
ICO Registration Number: ZB847331
Registered Office: 53 Stonefall Avenue, Harrogate, HG2 7NR, United Kingdom (Ichötà operates remotely; this address is for legal correspondence only)
Contact: hi@ichota.co
Phone: +44 7351 384310
We are registered with and fully compliant with the UK Information Commissioner's Office (ICO), adhering to the UK GDPR and Data Protection Act 2018.
PRIVACY POLICY AT A GLANCE
Key Points You Should Know:
- ✓ We collect identity information, relationship preferences, and special category data (religious beliefs, sexual orientation) for matchmaking
- ✓ We use facial recognition technology (AWS Rekognition) to verify your identity
- ✓ We record concierge interviews for quality and matchmaking purposes
- ✓ We conduct background screening including fraud checks and publicly available records checks
- ✓ We share data with service providers (AWS, Stripe, Twilio, Agora, etc.) and potential matches (with your consent)
- ✓ We do NOT sell your personal information to anyone
- ✓ We retain your data for 6-7 years after membership ends for legal compliance
- ✓ You have extensive rights including access, deletion, correction, and data portability
- ✓ Your data may be transferred internationally (primarily to the United States)
1. WHAT INFORMATION WE COLLECT
We collect different categories of information depending on how you interact with our services:
1.1 INFORMATION YOU PROVIDE DIRECTLY
Identity & Contact Information:
- Full legal name
- Date of birth
- Email address
- Phone number
- Postal address
- Government-issued photo ID (passport, driving licence, national ID card, biometric residence permit)
- Profile photographs
- Voice recordings (from concierge interviews)
Demographic & Lifestyle Information:
- Nationality and citizenship
- Religious beliefs and values
- Cultural background and traditions
- Education level and institutions attended
- Occupation and professional background
- Income range
- Family background and living situation
- Interests, hobbies, and lifestyle preferences
- Languages spoken
Matchmaking & Relationship Information:
- Relationship goals and intentions
- Dating preferences and deal-breakers
- Past relationship history
- Partner preferences (age, location, values, etc.)
- Personality assessments (e.g., Enneagram, love language, attachment styles)
- Compatibility scores and insights
- Communication preferences
- Feedback on matches and dates
- Messages and communications within the platform
Special Category Personal Data:
Under data protection law, certain types of information are considered "special category" and require specific legal bases for processing:
- Religious or philosophical beliefs
- Health information (voluntarily shared for compatibility purposes)
- Sexual orientation and partner gender preferences
- Racial or ethnic origin
- Biometric data (facial geometry for identity verification)
We process this data with your explicit consent (as provided in our Member Consent Form) and/or where necessary for performing our matchmaking contract with you.
1.2 INFORMATION WE COLLECT AUTOMATICALLY
Device & Technical Information:
- Device type, model, and operating system
- IP address and approximate location
- Browser type and version
- App version
- Device identifiers (IDFA on iOS, Advertising ID on Android)
- Time zone and language settings
Usage Information:
- Pages visited and features used
- Time spent on different sections
- Button clicks and interactions
- Search queries within the app
- Date and time of access
- Crash reports and error logs
Location Information:
- Approximate location based on IP address
- Precise location (only if you grant permission) for showing distance to potential matches, event location services, and reverse geocoding
Communications Data:
- In-app messages (content, timestamp, read/unread status)
- Voice and video call metadata (duration, participants, quality)
- SMS and text message delivery status
- Push notification delivery status
1.3 INFORMATION FROM THIRD-PARTY SOURCES
Background Checks & Verification:
We work with trusted third-party providers to conduct:
Identity Verification:
- Document verification using AWS Rekognition (automated facial recognition) and AWS Textract (automated text extraction from identity documents)
- Photo verification to confirm profile photos match identity documents
- Detection of digitally manipulated images
- Address verification
Background Screening:
- Fraud and financial database checks
- Checks against publicly available registers (where legally permitted and proportionate, such as sex offender registers)
- Social media footprint analysis (publicly available information only)
IMPORTANT LIMITATIONS ON CRIMINAL RECORD CHECKS:
We do NOT conduct:
- Standard or Enhanced DBS checks (we do not have legal authority for these)
- Comprehensive criminal history searches
- Checks on spent convictions under the Rehabilitation of Offenders Act 1974
Our screening is designed to identify serious safeguarding risks using publicly available information and fraud databases, but cannot guarantee a complete history.
Social Media & OAuth Providers:
If you sign up using Google or LinkedIn, we receive:
- Name
- Email address
- Profile picture
- Basic profile information (as permitted by the provider)
1.4 BIOMETRIC DATA & FACIAL RECOGNITION
We use AWS Rekognition technology to:
- Verify that your profile photos match your ID document photo
- Detect if photos have been digitally manipulated
- Identify potential duplicate accounts
This involves automated facial recognition technology that processes biometric data (facial geometry).
IMPORTANT DISCLOSURES ABOUT FACIAL RECOGNITION:
- Facial recognition is not 100% accurate and may produce false matches or false rejections
- We use this technology solely for verification purposes
- Biometric templates (facial geometry data) are deleted after verification is complete and are not stored permanently
- You explicitly consent to this processing in our Member Consent Form
- You can request manual verification instead by contacting hi@ichota.co
1.5 VOICE RECORDINGS (CONCIERGE INTERVIEWS)
All concierge interviews are audio recorded. You will be notified at the start of each interview that recording is taking place.
Interview recordings are used for:
- Quality assurance and service improvement
- Training of concierge staff
- Matchmaking assessment and compatibility analysis
- Dispute resolution and complaint investigation
Recording Details:
- Recordings are stored securely and encrypted
- Access is restricted to authorised concierge staff only
- Recordings are retained for the duration of your membership plus 6 years
- You can request a copy of your interview recording by emailing hi@ichota.co
- You can request that interviews are NOT recorded (we will take detailed written notes instead)
2. LEGAL BASIS FOR PROCESSING YOUR DATA (UK GDPR)
We process your personal data under the following lawful bases:
2.1 CONTRACT PERFORMANCE (Article 6(1)(b) UK GDPR)
To provide matchmaking services, facilitate introductions, manage your account, process payments, and deliver the services outlined in our Terms of Service.
Examples:
- Processing profile information to identify matches
- Facilitating communication between matched members
- Managing your subscription and billing
- Providing concierge interview services
2.2 CONSENT (Article 6(1)(a) UK GDPR)
For certain processing activities where we require your explicit opt-in consent:
- Recording concierge interviews
- Sending marketing communications
- Using certain non-essential cookies
- Processing some aspects of background checks
You provide this consent in our Member Consent Form and can withdraw it at any time by contacting hi@ichota.co.
2.3 LEGITIMATE INTERESTS (Article 6(1)(f) UK GDPR)
For ensuring platform safety, preventing fraud, improving our services, conducting internal analytics, and maintaining business operations.
Examples:
- Fraud detection and prevention
- Service improvement and development
- Internal research and analytics
- Network and information security
2.4 LEGAL OBLIGATION (Article 6(1)(c) UK GDPR)
Where required by law, such as:
- Responding to court orders and legal processes
- Complying with regulatory requests
- Meeting tax and accounting requirements (7-year retention of financial records)
- Reporting to law enforcement where legally required
2.5 SPECIAL CATEGORY DATA - ADDITIONAL LEGAL BASES
For processing special category personal data (religious beliefs, health, sexual orientation, racial/ethnic origin, biometric data), we rely on:
- Explicit Consent (Article 9(2)(a) UK GDPR): You provide explicit consent via our Member Consent Form
- Contractual Necessity (Article 9(2)(b) UK GDPR): Processing certain special category data is necessary for performing our matchmaking contract
- Substantial Public Interest (Article 9(2)(g) UK GDPR): For safeguarding vulnerable individuals and preventing fraud
3. HOW WE USE YOUR INFORMATION
3.1 MATCHMAKING & INTRODUCTIONS
- Identifying compatible matches based on preferences, values, and compatibility assessments
- Facilitating introductions between mutually interested members
- Sharing profile information with potential matches (with your consent)
- Providing personalised matchmaking recommendations
- Delivering concierge-led dating support and guidance
3.2 SAFETY & VERIFICATION
- Conducting identity verification and background screening
- Screening for fraud, misrepresentation, and prohibited conduct
- Monitoring compliance with our Terms of Service and Community Standards
- Investigating reports of misconduct or safety concerns
- Protecting members from harm and abuse
3.3 SERVICE DELIVERY & ACCOUNT MANAGEMENT
- Creating and managing your account
- Processing payments and subscriptions
- Scheduling and conducting concierge interviews
- Organising events and experiences
- Providing customer support
- Communicating service updates and changes
3.4 COMMUNICATIONS
- Sending transactional messages (match notifications, appointment reminders, account updates, payment confirmations)
- Providing customer support responses
- Sending marketing communications (only with your consent)
- Delivering push notifications about matches and messages
- Sending SMS notifications (via Twilio) for important account activities
3.5 IMPROVEMENT & DEVELOPMENT
- Analysing usage patterns to improve matching algorithms
- Conducting internal research and development
- Testing new features and services
- Measuring service performance and quality
- Ensuring technical functionality and security
- A/B testing and feature optimisation
3.6 LEGAL & COMPLIANCE
- Complying with legal obligations
- Enforcing our Terms of Service
- Defending legal claims and disputes
- Protecting our rights and property
- Responding to lawful requests from authorities
3.7 AUTOMATED DECISION-MAKING AND MATCHING ALGORITHMS
We use automated systems and algorithms to assist with matchmaking decisions, including:
- Calculating compatibility scores between members
- Suggesting potential matches
- Prioritising introductions based on compatibility factors
- Analysing communication patterns and engagement
- Predicting match success likelihood
HOW OUR ALGORITHMS WORK:
- Your stated preferences (age range, location, values, interests, lifestyle)
- Personality assessment results (Enneagram, attachment styles)
- Behavioural patterns and engagement history
- Communication style and preferences
- Historical match success data (anonymised and aggregated)
- Compatibility scores based on shared values and interests
IMPORTANT: HUMAN OVERSIGHT
- No match introductions are made by algorithm alone
- All matches are reviewed and approved by our concierge team
- You can request human review of any algorithmic decision
- You can contest or appeal any matching decision
YOUR RIGHTS REGARDING AUTOMATED DECISIONS:
- Right to obtain human intervention in the decision-making process
- Right to express your point of view on algorithmic matching
- Right to contest and appeal algorithmic decisions
- Right to receive meaningful information about the logic, significance, and consequences of automated processing
4. HOW WE SHARE YOUR INFORMATION
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
We share your information only in the following circumstances:
4.1 WITH YOUR CONSENT
- With potential matches when there is mutual interest
- When you choose to participate in shared experiences or events
- When you explicitly authorise us to share specific information
4.2 WITH SERVICE PROVIDERS (DATA PROCESSORS)
We work with trusted third-party service providers who process data on our behalf:
- App Infrastructure: Expo (app framework, push notifications)
- Cloud Storage & Hosting: AWS S3, Railway
- Identity Verification: AWS Rekognition, AWS Textract
- Communications: Agora (voice/video calls), Socket.IO (chat), Twilio (SMS)
- Payment Processing: Stripe
- Authentication: Google, LinkedIn (OAuth)
- Chat Features: Giphy (GIF sharing)
- Push Notifications: Apple (APNs)
- Location Services: Apple Maps, Expo Location
- Background Screening: Third-party verification providers
All service providers are contractually bound to process data only on our instructions and implement appropriate security measures.
4.3 FOR LEGAL REASONS
We may disclose your information when required by law or to:
- Comply with legal processes (court orders, subpoenas, search warrants)
- Respond to lawful requests from public authorities
- Enforce our Terms of Service
- Protect the safety, rights, or property of Ichötà, our members, or the public
- Detect, prevent, or investigate fraud, security issues, or illegal activities
4.4 BUSINESS TRANSFERS
If Ichötà is involved in a merger, acquisition, asset sale, or business transfer, your information may be transferred. We will notify you via email and/or prominent notice in the app.
4.5 WITH CONCIERGE TEAM (INTERNAL SHARING)
Your information is shared internally with:
- Relationship concierges and matchmakers
- Customer support staff
- Safety and compliance teams
- Technical staff (on a strict need-to-know basis)
All internal staff are bound by strict confidentiality agreements and trained on data protection.
5. INTERNATIONAL DATA TRANSFERS
Your information may be transferred to, stored in, and processed in countries outside the United Kingdom and European Economic Area, including the United States.
5.1 TRANSFERS TO THE UNITED STATES
We transfer data to the United States for services provided by AWS, Stripe, Agora, Twilio, Expo, Giphy, and other US-based providers.
SAFEGUARDS FOR US TRANSFERS:
- UK-US Data Bridge: For organisations certified under the UK-US Data Bridge (including AWS and Stripe)
- Standard Contractual Clauses: For organisations not covered by adequacy decisions
- Additional Technical Measures: Encryption in transit and at rest, access controls, data minimisation
5.2 TRANSFER IMPACT ASSESSMENTS
We have conducted Transfer Impact Assessments to ensure adequate protection for international transfers. Our assessments conclude that the level of protection is essentially equivalent to UK GDPR standards.
5.3 YOUR RIGHTS REGARDING TRANSFERS
- Request information about safeguards for specific international transfers
- Obtain a copy of the Standard Contractual Clauses
- Object to international transfers where processing is based on legitimate interests
6. DATA SECURITY
We implement physical, technical, and administrative security measures to protect your information.
6.1 TECHNICAL SECURITY MEASURES
Encryption:
- Data in transit: SSL/TLS encryption
- Data at rest: AES-256 encryption
- End-to-end encryption for certain sensitive communications
Access Controls:
- Multi-factor authentication for staff access
- Role-based access control (RBAC)
- Strong password policies
- Regular access reviews
Network Security:
- Firewall protection and intrusion detection
- DDoS protection and rate limiting
- Regular penetration testing and vulnerability assessments
6.2 ORGANISATIONAL SECURITY MEASURES
- Background checks on all staff with access to personal data
- Confidentiality and non-disclosure agreements
- Regular privacy and security training
- Clear data handling procedures
6.3 SERVICE PROVIDER SECURITY
Our service providers maintain industry-standard certifications:
- AWS S3: ISO 27001, SOC 2 Type II, PCI-DSS
- Stripe: PCI-DSS Level 1, SOC 2 Type II
- Railway: SOC 2 compliance
6.4 IMPORTANT SECURITY LIMITATIONS
No system is 100% secure. We commit to:
- Promptly investigating any suspected security incidents
- Notifying the ICO within 72 hours of becoming aware of a data breach
- Notifying affected users without undue delay when a breach poses a high risk
- Taking immediate action to contain breaches and mitigate harm
If you suspect a security issue, contact us immediately at hi@ichota.co.
7. DATA RETENTION
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy and comply with legal obligations.
7.1 RETENTION PERIODS FOR ACTIVE MEMBERS
- Profile and matchmaking data: Duration of active membership
- Communications and messages: Duration of membership + 90 days
- Usage and analytics data: Duration of membership + 2 years
7.2 RETENTION PERIODS FOR FORMER MEMBERS
- Core Profile Data: 6 years (Limitation Act 1980)
- Financial & Payment Records: 7 years (HMRC requirements)
- Safety & Compliance Records: 7 years
- Verification & Background Check Records: 6 years
- Communications & Messages: 6 years
- Consent Records: Indefinitely (or until consent is withdrawn + 3 years)
- Marketing Consent Records: Until withdrawn or 3 years of inactivity
7.3 EXTENDED RETENTION
Data may be retained longer if required by law, necessary for ongoing legal claims, needed for safety and fraud prevention, or subject to legal hold.
7.4 ANONYMISED AND AGGREGATED DATA
We may retain anonymised, aggregated data indefinitely for research, service improvement, and industry benchmarking.
8. CHILDREN'S PRIVACY & AGE VERIFICATION
Ichötà is exclusively for adults aged 25 and over. We do NOT knowingly collect, process, or store personal information from anyone under the age of 25.
Age Verification Measures:
- Self-declaration of age during registration
- Government-issued ID verification (which includes date of birth)
- Facial recognition verification against ID documents
- Manual review by concierge team where age is uncertain
If we discover we have collected data from someone under 25, we will immediately delete their account and all associated data.
If you believe a minor or someone under 25 has registered, please contact us immediately at hi@ichota.co.
9. YOUR DATA PROTECTION RIGHTS (UK GDPR)
Under UK GDPR, you have the following rights regarding your personal data:
9.1 RIGHT OF ACCESS (Article 15)
You have the right to request a copy of the personal information we hold about you. We will provide this within one month of your request (extendable by two months for complex requests).
9.2 RIGHT TO RECTIFICATION (Article 16)
You have the right to request correction of inaccurate or incomplete personal information. You can update most information directly in your profile settings, or contact us for assistance.
9.3 RIGHT TO ERASURE / "RIGHT TO BE FORGOTTEN" (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary, you withdraw consent, or the processing is unlawful.
Limitations: We may retain certain data where required by law, necessary for legal claims, or for other legitimate purposes.
9.4 RIGHT TO RESTRICTION OF PROCESSING (Article 18)
You can request that we limit how we use your data in certain circumstances, such as when you contest accuracy or object to processing.
9.5 RIGHT TO DATA PORTABILITY (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV) and to transmit it to another controller.
9.6 RIGHT TO OBJECT (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
9.7 RIGHTS RELATED TO AUTOMATED DECISION-MAKING (Article 22)
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. Our matchmaking algorithms involve meaningful human oversight.
9.8 RIGHT TO WITHDRAW CONSENT
Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
HOW TO EXERCISE YOUR RIGHTS
To exercise any of these rights, contact us at:
- Email: hi@ichota.co
- Phone: +44 7351 384310
- Post: Ichötà Limited, 53 Stonefall Avenue, Harrogate, HG2 7NR, United Kingdom
We will respond within one month. We may request verification of your identity before processing your request.
10. COOKIES AND TRACKING TECHNOLOGIES
Our website and app use cookies and similar technologies. Please refer to our Cookie Policy at www.ichota.co/cookiepolicy for detailed information.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will notify you of changes by:
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification for material changes
- Displaying a prominent notice in our app or website
- Requesting renewed consent where required by law
We encourage you to review this Privacy Policy periodically.
12. COMPLAINTS AND REGULATORY CONTACT
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint/
We encourage you to contact us first at hi@ichota.co so we can try to resolve your concerns directly.
13. CONTACT US
For any questions, concerns, or requests regarding this Privacy Policy or your personal data:
Ichötà Limited
53 Stonefall Avenue, Harrogate, HG2 7NR, United Kingdom
Email: hi@ichota.co
Phone: +44 7351 384310
Website: www.ichota.co
— END OF PRIVACY POLICY —
Version 2.0 — Effective: 21 February 2026
