Privacy Policy
Site: uksocials.club
Operator: CMP Technologies Ltd
Last updated: the 31st of July 2026
Version: 2.0
1. Who we are and how to contact us
Trader name: CMP Technologies Ltd
Trading as: UK Socials (the website at uksocials.club)
Companies House registration: Company registration number to be added on completion of Companies House lookup
Registered office: Registered office address: this is being procured. In the meantime, please contact us at info@uksocials.club for any postal correspondence.
Data Protection Lead: the operator of UK Socials, contactable via info@uksocials.club, contactable via the email below
Contact for all privacy queries: info@uksocials.club
ICO registration: ICO registration in progress
We are the data controller for the personal data processed when you use UK Socials. “We”, “us” and “our” mean CMP Technologies Ltd; “you” means anyone using the UK Socials website or service.
If you think we have got something wrong with your data, you have a legal right to complain to us directly, and we must deal with your complaint properly: we acknowledge within 30 days and respond without undue delay. Email info@uksocials.club with the subject “Privacy complaint”, or use the Complaints Procedure.
You can also complain at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection, although we would appreciate the chance to sort it out first:
- ICO website: https://ico.org.uk/concerns/
- ICO helpline: 0303 123 1113
- ICO post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
2. What information we collect
2.1 Information you give us when you register
- Account basics: username, display name, email address, and password (stored as a one-way hash; we never see the plain text).
- Date of birth, used to enforce our minimum age of 13 and the age-safety rules in §10. Your date of birth and your age are never displayed to anyone, anywhere on the platform.
- Gender, used for balanced group composition at curated events (for example pairing a host and a hostess).
- Postcode, used to show you events, venues and people near you, and to enforce the minimum-distance safety rule at curated events. When you type it we check it is a real postcode with a postcode lookup service and store its map coordinates. Your postcode is never displayed to other members and we never collect your street address.
- Email verification state. Registration is only complete when you click the link we email you. Unverified signups are removed automatically.
2.2 Optional information you may add
- Profile content: photos, cover image, bio, quote, hobbies and interests, social links, profile layout and colours, and any widgets you place. What appears on your profile is what you choose to put there.
- Questionnaire answers, if you choose to complete the matching questionnaire: up to 37 questions across 10 sections covering social style, interests, music, food, activity level, availability, budget, travel distance, and loneliness indicators. Three sections (loneliness, budget, and location or travel) are private: they are never shown to other members and are used only by the matching system. The personality archetype other members can see is computed only from the public sections, so private answers can never leak through it.
- Political affiliation, entirely optional and only for members aged 18 or over. See §4.1 for exactly how this works, because it has stronger protection than anything else on the platform.
2.3 Information you generate by using the service
- Messages you send through our internal messaging system.
- Activity: events you RSVP to or buy tickets for, invitations you send and receive (with sent, opened and responded timestamps), members you show interest in, favourite or wish-list, matches, blocks, family links, and attendance you record for yourself.
- Peer reviews you write and receive after paired events, and replies to them (see §2.6).
- Reports you make about content or members, and the content reported.
- Host registers at curated events: the two hosts confirm to us who was present, confidentially.
2.4 Information we collect automatically
- Device and connection data: IP address, browser and device type, operating system, and login records.
- Usage data: which pages you open, when, for how long and how many clicks, never anything typed. This is purely mechanical and it helps us run the platform well: see §2.7.
- Safety signals: the behavioural patterns described in §3.1, such as counters of attempted contact outside the age bands.
- Cookies and similar technologies: see the Cookie Policy.
2.5 Information from third parties
- Payment information: Stripe processes every payment. We never see or store your card number; we receive a masked reference (card brand, last four digits, expiry), customer and subscription identifiers, and payment outcomes. If the card or payout details you use match ones already in use on another account, Stripe gives us a non-reversible fingerprint match so we can run the authorisation check described in the Terms of Service §3.1; we never see the underlying numbers.
- We do not buy data about you from anyone, and we do not collect data about you from social networks.
2.6 Peer reviews and reputation
After an event where you and another member were paired by an accepted invitation and both attended, each of you may be asked to review the other. This is personal data about both of you, so here is exactly how it moves:
- The two of you see each other’s reviews. A review of you is shown to you, signed by its author, and you can reply. Reviews between the pair are not anonymous: you met in person, and the review is part of that same interaction.
- No other member ever sees the review text. Other members see only your aggregate reputation score, and only once you have enough reviews that no individual review can be identified from it.
- A small set of safety-related answers is admin-only. These never appear to you or anyone else; they feed the safety systems in §3.1 and are reviewed by humans.
- Reviews feed the matching system: review quality influences who the platform suggests you meet again.
- Your rights over review data are in §8. On account deletion, reviews you wrote are anonymised (your name removed) and reviews about you are deleted with your account, per §7.
We process peer-review data on the basis of legitimate interests (Article 6(1)(f)): running a platform where members can rely on each other’s reputation when deciding who to meet in person. The design (text private to the pair, aggregate public only above a minimum count, safety answers admin-only, human review of flags) is the balancing of that interest against your privacy. You can object under Article 21: see §8.
2.7 How we measure use of the platform
We track member usage of the platform so that we can deliver the best service we can, just like every other website and platform. This is purely mechanical and has nothing to do with you as an individual: we record which pages are opened, when, for how long and how many clicks, never anything typed, and we keep those records for 90 days.
3. How we use your information, and the lawful basis for each use
| What we do | Why | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Create and run your account, authenticate you, show you the platform | The service you signed up for | Contract (6(1)(b)) |
| Verify your age and enforce the age-safety rules | Protecting children on the platform | Legal obligation (6(1)(c)) under the Online Safety Act 2023, and legitimate interests (6(1)(f)) |
| Match you with compatible members and compose curated event groups | The core service: introductions that lead to real-world meetups | Legitimate interests (6(1)(f)): see §12 for how matching works and what it never does |
| Show you events, venues and members near you using your postcode | The core discovery service | Contract (6(1)(b)) |
| Take subscription payments and ticket payments, process refunds | Payments you have asked to make | Contract (6(1)(b)); legal obligation (6(1)(c)) for financial records |
| Run the anti-fraud check on reused payment details | Preventing fraudulent multi-account signups | Legitimate interests (6(1)(f)): fraud prevention |
| Send transactional email (verification, password change, receipts, export links, breach notices) | Operating your account and meeting legal duties | Contract (6(1)(b)) and legal obligation (6(1)(c)) |
| Send you platform messages (invitations, match notifications, event updates) | Part of the service; these stay in-app, we do not send marketing email | Contract (6(1)(b)) |
| Operate moderation, reporting, blocking, the panic button, and safety reviews | Keeping members safe | Legitimate interests (6(1)(f)) and legal obligation (6(1)(c)) under the Online Safety Act 2023 |
| Monitor behavioural patterns that suggest misconduct (§3.1) | Detecting harm that individual reports miss | Legitimate interests (6(1)(f)): member safety, especially children’s |
| Operate the peer-review and reputation system | Trustworthy introductions | Legitimate interests (6(1)(f)): §2.6 |
| Improve the service using aggregate analytics | Understanding what works | Consent (PECR) for analytics cookies; aggregate reporting thereafter |
| Defend legal claims, respond to lawful requests | Legal compliance | Legal obligation (6(1)(c)) and legitimate interests (6(1)(f)) |
| Show you advertising | We do not. No advertising, no data sales, ever | Not applicable |
If we ever want to use your data for a new purpose, we will tell you first and identify the lawful basis before we start.
3.1 Behavioural safety monitoring, in plain terms
The platform watches for patterns associated with harm: attempts to reach or repeatedly interact with members outside the permitted age bands, and patterns of behaviour associated with harassment, exploitation of other members, misuse of invitations, or fraud. Three things are always true:
- It watches patterns of actions, not the content of your private messages. Admin access to message content happens only on a trigger (§5.1).
- A flag never punishes you automatically. Every flag is advisory input to a human administrator who reviews before anything happens.
- Flags are never visible to other members.
4. Special-category data (UK GDPR Article 9)
Some data gets extra legal protection. Here is every piece of it we may hold, and how it is protected.
4.1 Political affiliation: a live poll you control completely
Members aged 18 or over can optionally show support for a political party. It works as a toggle, and the design is deliberately all-or-nothing:
- Never touched: nothing is recorded. There is no entry anywhere.
- Toggled on: your choice is recorded and counts in our internal, anonymised live poll (admin sees aggregate support levels alongside broad demographics). No other member can see it.
- Toggled on and placed on your profile: you have chosen to show it to other members. You can take it off your profile again at any time, which returns it to the private state above.
- Toggled off: the record is deleted. Not hidden: deleted, including from the admin poll. We forget it completely.
The note beside the toggle says exactly this before you touch it, and turning it on is your explicit consent (Article 9(2)(a)) to this processing. Under-18s cannot see or use the feature at all. We never use political affiliation in matching, never share it, and never make any decision about you based on it.
4.2 Answers that can imply special-category data
Two kinds of optional questionnaire answers could indirectly reveal protected characteristics:
- Dietary requirements (for example halal or kosher) can imply religious belief.
- Loneliness and wellbeing answers shade towards health information.
Both are optional, and by choosing to provide them you consent to us processing them for matching and event planning only. The loneliness section is one of the private sections in §2.2: it is never shown to any other member, and nothing visible on your profile is derived from it.
4.3 What we deliberately do not collect
We do not ask for your race or ethnicity, religion, sexual orientation, health conditions, trade-union membership, or biometric data. If you choose to write something like that in your own bio, you have chosen to publish it to other members; we still do not use it for anything.
5. Who we share your information with
We share personal data only with the recipients below, only as needed to run the service:
| Recipient | What they get | Why |
|---|---|---|
| Stripe (payment processor) | Name, email, payment amounts, and payment identifiers | Subscriptions, ticket payments, refunds, fraud prevention. For ticket sales, Stripe Connect routes the organiser’s share to the organiser’s own Stripe account |
| Our hosting provider (currently GoDaddy) | All site data, as the servers it lives on | Hosting. They act only on our instructions |
| Google Workspace (Gmail API) | The recipient address and content of transactional emails we send you | Delivering verification, password-change and receipt emails. We send no marketing email |
| Google Maps and Places | Address and venue searches typed by organisers and venues when creating listings | Venue lookup and maps on event pages |
| Google Analytics | Usage analytics, only if you consent to analytics cookies | Aggregate site statistics. Off until you opt in |
| postcodes.io (postcode lookup) | The postcode you type, and nothing else | Confirming the postcode is real and obtaining its coordinates |
| CookieYes | Your cookie choices, stored in your own browser | Running the consent banner |
| The Internet Watch Foundation and the National Crime Agency | Reports of suspected child sexual abuse material and the uploading account | Child protection; reporting duties under the Online Safety Act 2023 |
| Police, regulators, courts | What a valid legal order requires | Legal obligation |
We do not share your data with advertisers, data brokers, marketing networks, or social-media tracking pixels, and we do not sell data. The live processor list, with locations, is kept at /sub-processors/.
5.1 When our own administrators can look at your data
Administrators have technical access to the platform; whether they actually look is governed by a trigger policy:
Routине operation involves no reading of your private content. Running the site, fixing bugs and viewing aggregate statistics does not involve opening anyone’s messages.
Triggered access, which is logged with who, when and why:
- You report someone, or someone reports you: the administrator reviews the reported content and enough context to judge it, and no more.
- You ask us for help with your own account or data.
- A safety flag from §3.1 needs human review.
- A court, regulator or law-enforcement agency lawfully requires it.
- A security incident affects the platform.
Every administrator access to private content is recorded in an audit log kept for 6 years, and you can ask us whether your data has been accessed and why (unless telling you would prejudice a live investigation).
6. International transfers
Most data stays in the UK. Where a processor is a US company (Stripe, Google), we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Agreement or Addendum with a transfer risk assessment. Whatever the mechanism, your data gets protection essentially equivalent to UK GDPR.
7. How long we keep your data
The principle: once you are gone, you are gone. We believe in the right to be forgotten and the right to live offline.
7.1 What happens when you delete your account
- Immediately: your profile goes offline, your login is disabled, other members can no longer find you, and any subscription is cancelled.
- For 90 days: your data is retained, invisible to everyone, purely so that a report raised about conduct (for example by someone you met at an event) can still be investigated. Nobody reads anything during this window unless such a trigger opens; there are no fishing expeditions.
- After 90 days: everything is deleted from our active systems: profile, photos, questionnaire answers, matches, invitations, and messages. Conversations are deleted from both sides: because messaging is internal, we remove every conversation you were part of from all participants’ inboxes, not just your copy. Backup copies are overwritten in the normal backup cycle.
- Reviews you wrote about events and venues are kept but anonymised, because other members relied on them; ask us if you want them deleted outright. Contact-form submissions are deleted.
- If an investigation is open at the 90-day point, deletion waits until it concludes, then completes.
7.2 The narrow exceptions
| Trigger | What we keep | How long |
|---|---|---|
| An open report, moderation case or investigation about you | The relevant content and records | Until it concludes, then deleted |
| A legal claim between us, actual or notified | Data relevant to the claim | Until resolved or time-barred |
| A preservation order from police, a court or a regulator | What the order specifies | As long as it requires |
| Payment records | Transaction records only (not profile or messages) | 6 years, as tax law requires |
| Reports we made about child sexual abuse material | The report and its hash record | Indefinitely, for crime-reporting integrity |
7.3 While your account is open
| Data | Kept for | Why |
|---|---|---|
| IP addresses and login records | 12 months | Security and abuse prevention |
| Usage records: which pages and features you use, and the sign-in sessions they belong to | Page and feature records 90 days; sign-in session records 365 days | Running the platform well, as described in §2.7 |
| Moderation records (reports, actions, suspensions) | 6 years from the action | Defending legal claims; spotting repeat patterns |
| Admin access audit logs | 6 years | Accountability for §5.1 |
| Cookie consent records | Duration of your consent choice | Demonstrating PECR compliance |
| Expired invitations and similar operational leftovers | Reviewed and cleared periodically | Housekeeping |
| Aggregated, anonymised statistics | Indefinitely | No longer personal data |
7.4 Want it gone sooner?
Email info@uksocials.club after closing your account and we will delete sooner unless one of the §7.2 triggers applies, in which case we will tell you which one and why. While your account is open you can delete individual photos, answers and profile content yourself at any time.
8. Your rights
You have all of the following rights, free of charge. We respond within one month, extendable by two further months for genuinely complex requests (we tell you within the first month if so, and where we need clarification the clock pauses until you provide it, as the law provides).
| Right | What it means | How |
|---|---|---|
| Access (Article 15) | A copy of the personal data we hold about you | The Export Data tool in your account produces an immediate, machine-readable download covering every part of the platform (profile, questionnaire, messages, invitations, events, reviews and more). Or email us |
| Rectification (Article 16) | Correct wrong or incomplete data | Edit your profile and account yourself, or email us |
| Erasure (Article 17) | Delete your data | Delete your account (§7), or email us |
| Restriction (Article 18) | Pause processing while something is disputed | Email us |
| Portability (Article 20) | Your data in a reusable format | The same Export Data tool |
| Object (Article 21) | Object to processing based on legitimate interests, including the matching and reputation systems | Email us; we stop unless compelling legitimate grounds override, and we will explain either way |
| Automated decisions | See §12: no solely-automated decision with significant effects is made about you | |
| Withdraw consent (Article 7(3)) | For political affiliation: toggle it off, which deletes it. For cookies: Cookie Settings in the footer. For anything else consent-based: email us | |
| Complain to us | Your statutory right to complain directly to the controller: we acknowledge within 30 days and respond without undue delay | info@uksocials.club, subject “Privacy complaint” |
| Complain to the ICO (Article 77) | The regulator, at any time | https://ico.org.uk/concerns/ |
To exercise any right: info@uksocials.club. We may need to verify you are you before releasing data; that protects you.
9. Security
- HTTPS everywhere; passwords stored as one-way hashes; optional two-factor authentication on every account.
- Card numbers never touch our systems: Stripe holds them.
- Location metadata is stripped from every uploaded photo: EXIF and GPS data are removed from the stored file itself, so a photo you upload can never silently reveal where it was taken.
- No public profile browsing: profiles are only visible to logged-in members, and members outside your age band cannot see you at all.
- Production access is restricted to named administrators; administrative access to private content is audit-logged (§5.1).
- Backups are encrypted; software is kept patched.
If a breach occurs that risks your rights and freedoms, we notify the ICO within 72 hours, and if the risk to you is high we notify you directly without undue delay, by email.
If you think your account has been compromised: change your password, then email info@uksocials.club.
10. Children and the protection of young members
UK Socials is for people aged 13 and over, which means 13-to-17-year-olds are on the platform alongside adults, and the whole design accounts for that. We follow the ICO’s Age Appropriate Design Code and the Online Safety Act 2023, and we keep internal children’s access, children’s risk, and illegal-content risk assessments, available to Ofcom on request.
10.1 The structural protections
- The age gates. Contact between members aged 21 or over and members aged 17 or under is blocked, and so is contact between members aged 18 or over and members aged 15 or under: messages, invitations, matching and profile visibility. Members outside your band do not appear to you at all, and where an age cannot be established the platform blocks contact rather than allowing it.
- Ages are never displayed. No member’s age or date of birth is shown to anyone, so nobody can browse members by youth.
- Event age groups are absolute. Every event carries an age group and nobody can book, RSVP or be invited outside it. No exceptions, including family.
- Family Link is the single, narrow exception to the contact gates: genuine family members (parent and child, siblings, cousins) can both explicitly opt in to contact. It never overrides event age groups, and misuse is treated as a serious safety breach.
- The panic button. Members under 18 have a one-tap panic control on every page that sends an urgent report straight to us, and only to us, so a young member can get help without having to tell anyone around them first.
- No political affiliation for under-18s (§4.1), and the private questionnaire sections are private for everyone.
- Matching for under-18s stays inside their own age band, the contact gates always apply to its results, every curated group is approved by a human, and we never use any member’s data for advertising or marketing profiling, adult or child.
10.2 The ICO Children’s Code, standard by standard
| Standard | How we meet it |
|---|---|
| Best interests of the child | The age gates, absolute event age groups, and the panic button exist because of this principle, and feature decisions consider under-18 impact explicitly |
| Data protection impact assessment | Held internally, reviewed at least annually and on significant change |
| Age-appropriate application | Date of birth verified at signup; 13-to-17-year-olds get the protections on this page |
| Transparency | This policy, the Children’s Safety Statement, and short in-context notes at the point of use |
| Detrimental use | No advertising, no data sales, no marketing profiling, no attention-farming features |
| Policies and community standards | Published, and applied consistently (Terms §9, §13) |
| Default settings | Private by design: nothing optional is visible until a member chooses to place it, profiles are invisible to non-members, and under-18s are invisible to out-of-band adults entirely |
| Data minimisation | Postcode not address; date of birth collected but never displayed; card numbers never held |
| Data sharing | §5 only; never for advertising |
| Geolocation | Coordinates derived from postcode only; no GPS tracking, and GPS metadata is stripped from photos |
| Parental controls | Family Link (mutual opt-in), and a parent or guardian can ask us to delete their child’s account: email info@uksocials.club |
| Profiling | Matching for under-18s stays in-band, is human-approved for curated events, and no marketing profiling exists for anyone |
| Nudge techniques | We do not nudge anyone, let alone children, toward lower privacy, longer sessions, or spending |
| Connected toys and devices | Not applicable |
| Online tools | Report controls everywhere, the panic button, block, Cookie Settings, Export Data and account deletion all work identically for under-18s |
10.3 Age assurance
We verify the 13 minimum by declared date of birth plus behavioural signals, which is the proportionate approach for a service like ours: UK Socials hosts no pornography and no content promoting suicide, self-harm or eating disorders (all prohibited and removed), so the higher “highly effective age assurance” bar for services carrying that content does not apply. We keep this position under review against Ofcom and ICO guidance, and our internal children’s access assessment records the reasoning.
10.4 Under 13?
We do not knowingly hold an account for anyone under 13. If you believe a member is under 13, email info@uksocials.club and we will investigate and, where confirmed, delete the account. If you are under 13: we are sorry, but this platform is not for you yet.
10.5 Worried about a child?
Email info@uksocials.club with the subject “URGENT: child safety” and it is handled as same-day priority by a human. If a child is in immediate danger, call 999 first.
11. Cookies
Covered in the separate Cookie Policy. The short version: strictly necessary cookies run the site; analytics cookies are off unless you opt in; we use no advertising or marketing cookies at all; and the Cookie Settings link in the footer reopens your choices at any time.
12. Automated decision-making and profiling
The matching system (we call it the Social Engine) is profiling: it scores questionnaire answers, interests, location and review quality to suggest people and compose curated event groups. Here is what keeps it fair:
- No decision with legal or similarly significant effects about you is ever made solely by a machine. Every curated group is approved by a human before invitations go out, every safety flag is reviewed by a human before anything happens, and moderation actions are taken by humans.
- Matching output is suggestions: an invitation you can decline, never a restriction on what you can do.
- The age gates in §10.1 are automated, and deliberately so: they only ever block contact for child-safety reasons, which is exactly what the law expects them to do. Family Link is the review route if a genuine family relationship is being blocked.
- Political affiliation never feeds matching (§4.1), and the private questionnaire sections never surface publicly (§2.2).
You can ask for human review of anything the platform has done that affects you: info@uksocials.club.
13. Changes to this policy
The date at the top tells you the current version. Substantial changes (new data categories, new recipients, a new lawful basis, a change of controller) are notified at least 30 days ahead by internal message and, where possible, email. Minor clarifications take effect on publication. Previous versions are archived: email us if you want one.
14. Contact
All privacy matters: info@uksocials.club
Post: CMP Technologies Ltd, Registered office address: being procured (contact info@uksocials.club for postal correspondence)
The regulator: ICO, https://ico.org.uk/concerns/, 0303 123 1113