1. Controller
treuetest-online.eu® / Blunck - IT Services OÜ
Narva mnt 5 · Kesklinna linnaosa · 10117 Tallinn · Harju maakond · Estland
Email: support@treuetest-online.eu
Phone: +49 (0)711 / 40 180 648
Authorised representative: Tobias Christian Blunck, member of the management board
Further provider information is available in the Legal Notice. Privacy requests may be sent to the email address above.
2. Data categories, sources, purposes and legal bases
Name/pseudonym, email address, password hash, role and account status, registration time, security and 2FA data and—if selected—trusted-device information. Processing is for registration, authentication, account management and contract performance (Art. 6(1)(b) GDPR) and to protect against misuse (Art. 6(1)(f) GDPR).
For decoy/detective profiles, in particular profile details, region/postcode area, voluntary contact methods, description, prices, photos, videos, review status and moderation results. Processing is for providing and reviewing the profile and performing the user contract (Art. 6(1)(b) GDPR) and for platform safety/quality (Art. 6(1)(f) GDPR).
Internal messages, attachments, conversation assignment, read/time information, favourites, blocks and voluntarily provided direct contact methods. When a signed-in customer actively opens an approved direct contact method (for example WhatsApp, phone or email), the customer, profile, contact method and timestamp are logged for support, evidence and abuse-resolution purposes; the contact value itself is not stored again in this access log. These access logs are routinely limited to a maximum of twelve months. Processing is for communication and safety functions and for resolving service cases (Art. 6(1)(b) and (f) GDPR).
Package, duration, amount, discount/coupon, payment method, order reference, payment status, timestamps and legal acknowledgements. Processing is for contract and payment handling (Art. 6(1)(b) GDPR), statutory documentation/retention duties (Art. 6(1)(c) GDPR) and, where necessary, legal claims (Art. 6(1)(f) GDPR).
For technical and commercial evaluation of the platform, page views, pseudonymous visitor/session identifiers, time, viewed page, external referrer domain, website language, and device type, operating system and browser derived from the user agent are recorded. Full IP addresses are not stored in these statistics and no external GeoIP service is called for this purpose. Country assignment primarily uses existing member details or coarse hosting/CDN information. If these are unavailable, the website may use the browser timezone or an explicitly transmitted browser country/region setting as a data-minimising approximation; browser-based values are not an exact location measurement and may differ. Gender is used only for signed-in members from a self-provided profile field and is never guessed. Processing serves improvement, stability and needs-based development of the platform (Art. 6(1)(f) GDPR).
Other voluntary information—for example “How did you find us?” or newsletter consent—is processed only for the stated purpose. Newsletters are based on consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time for the future.
Data about other people and sensitive content
In messages or assignment discussions, users may provide information about other people. The source of such information is generally the respective user. The platform is not designed for systematic collection of personal data about uninvolved third parties. Users should transmit only information strictly necessary for lawful communication and must not submit special categories of personal data under Art. 9 GDPR or criminal-offence data under Art. 10 GDPR unless there is a clear legal basis.
The allocation of data-protection roles and any information duties toward a third person depend on the specific processing activity. Where third-party personal data is processed without that person’s involvement, Art. 14 GDPR may in particular be relevant.
3. AI assistant, automated profile review and external checks
If you use the AI assistant, your entered question is transmitted to the OpenAI service configured for the platform to generate an answer. Do not enter passwords, payment data, intimate information or unnecessary personal data about third parties.
When Clarity Compass AI is used, the selected answers and an optional free-text note are transmitted to the configured OpenAI service where the AI function is available. The Clarity Compass function does not permanently store these inputs in a dedicated platform table; they are used for the assessment requested at that moment. Describe third parties only where necessary and avoid passwords, payment data or unnecessary intimate information.
With Smart Match, search criteria selected by the customer and relevant approved profile information from several decoy/detective profiles may be transmitted to OpenAI to produce a ranking. This may include age, gender, country/city, available contact methods, remote/in-person service, short profile text and a relative indication of recent activity. Direct contact details such as phone numbers, WhatsApp numbers or email addresses are not required and are not part of the implemented Smart Match request.
For decoy/detective profiles, profile text and images may be automatically reviewed through OpenAI functions for safety, plausibility and quality. Profile content, images and metadata required for the review may be transmitted to OpenAI. The review status may affect whether a profile becomes visible immediately or first requires further/manual review. A flagged decision can be submitted for manual review through the available contact/appeal options.
For API customer data, OpenAI’s Data Processing Addendum provides for processing on behalf of the customer. Where EEA data is further processed outside the EEA, OpenAI describes adequacy decisions and/or Standard Contractual Clauses as transfer mechanisms.
For postcode/city plausibility checks, the platform may also send country and postcode to Zippopotam.us. Under the implemented function, names or email addresses are not transmitted in this query.
Payment providers
Depending on the selected and enabled payment method, data required for payment processing is transmitted to the relevant payment provider or bank. With Stripe, this may include email address, order reference, product/price information and payment status; full card details in the checkout used are generally processed directly by Stripe and are not stored in the platform database. With PayPal, order and amount information required for payment is provided to PayPal. For bank transfer and cash payment, the operator processes payment and reference data required for allocation.
Email notifications and newsletters
Transactional and security emails—such as registration confirmation, 2FA code, password reset, order confirmation, activation or withdrawal confirmation—are sent for contract performance or account security. For privacy reasons, full internal message content is not sent in notification emails. Newsletters are sent only with separate voluntary consent and can be disabled at any time in settings or via the unsubscribe link.
Recipients and processors
Access to personal data is limited to persons and service providers where necessary for operation, support, hosting, email delivery, payment processing, security/profile review or legal duties. Depending on the configuration actually enabled, this may include hosting providers, SMTP/email providers, payment providers such as Stripe and PayPal, OpenAI for AI functions and technical validation services. Where required, processor agreements under Art. 28 GDPR must be in place. Authorities receive data only on a legal basis or binding order.
Transfers outside the EEA
Some technical or payment service providers may process data outside the European Economic Area. Such transfers may only take place under the conditions of Arts. 44 et seq. GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Which transfers actually occur depends on the enabled providers and their current infrastructure.
5. Retention and account deletion
Personal data is generally stored only as long as necessary for the relevant purpose. Account and profile data is processed while the account is active. Following a regular deletion request, direct account data is anonymised after completion of the deletion process; for decoy/detective accounts, published profile, contact, photo and video data is deleted unless retention is required or justified. Message and order records may remain in anonymised or minimised form where necessary for conversation integrity, statutory retention duties or the establishment, exercise or defence of legal claims.
Security data is retained for limited periods according to its purpose: login security codes are valid only briefly and old 2FA challenges are technically cleaned up. Trusted devices expire after the configured period (30 days by default). Tax, commercial or payment-related records are retained for the applicable statutory retention periods. Data is then deleted or anonymised unless further legal grounds require retention.
Internal usage-statistics records are routinely limited to a maximum of 13 months. When an account is permanently deleted, any direct user association is removed through the database relationship; statistical pseudonymous usage data may remain without the deleted account association until the end of that period.
6. Your data-protection rights
Subject to the GDPR, you have in particular the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Consent may be withdrawn at any time for the future under Art. 7(3) GDPR.
You also have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the alleged infringement. For the controller established in Estonia, the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) is a competent authority: Tatari 39, 10134 Tallinn, Estonia · info@aki.ee.
Required/optional data and automated decisions
Required fields are necessary to create an account, provide the requested function or process a contract. Without them, the relevant function may not be available. Fields marked optional are not required to conclude a contract. The platform uses automated checks for profile approval and moderation; these may affect the visibility of a decoy/detective profile. Flagged cases can be reviewed manually. In the described standard configuration, no other solely automated decision producing legal effects for customers or similarly significantly affecting them is intended.
Changes to this privacy information
This privacy information will be updated when functions, service providers or the legal framework materially change. The current version published on the website applies; where material changes require additional notice or consent, this will be provided in accordance with legal requirements.