1. Home
  2. Privacy Policy

Privacy Policy

Privacy Policy

Site: uksocials.club
Operator: CMP Technologies Ltd
Last updated: the 31st of July 2026
Version: 2.0


1. Who we are and how to contact us

Trader name: CMP Technologies Ltd
Trading as: UK Socials (the website at uksocials.club)
Companies House registration: Company registration number to be added on completion of Companies House lookup
Registered office: Registered office address: this is being procured. In the meantime, please contact us at info@uksocials.club for any postal correspondence.
Data Protection Lead: the operator of UK Socials, contactable via info@uksocials.club, contactable via the email below
Contact for all privacy queries: info@uksocials.club
ICO registration: ICO registration in progress

We are the data controller for the personal data processed when you use UK Socials. “We”, “us” and “our” mean CMP Technologies Ltd; “you” means anyone using the UK Socials website or service.

If you think we have got something wrong with your data, you have a legal right to complain to us directly, and we must deal with your complaint properly: we acknowledge within 30 days and respond without undue delay. Email info@uksocials.club with the subject “Privacy complaint”, or use the Complaints Procedure.

You can also complain at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection, although we would appreciate the chance to sort it out first:

  • ICO website: https://ico.org.uk/concerns/
  • ICO helpline: 0303 123 1113
  • ICO post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

2. What information we collect

2.1 Information you give us when you register

  • Account basics: username, display name, email address, and password (stored as a one-way hash; we never see the plain text).
  • Date of birth, used to enforce our minimum age of 13 and the age-safety rules in §10. Your date of birth and your age are never displayed to anyone, anywhere on the platform.
  • Gender, used for balanced group composition at curated events (for example pairing a host and a hostess).
  • Postcode, used to show you events, venues and people near you, and to enforce the minimum-distance safety rule at curated events. When you type it we check it is a real postcode with a postcode lookup service and store its map coordinates. Your postcode is never displayed to other members and we never collect your street address.
  • Email verification state. Registration is only complete when you click the link we email you. Unverified signups are removed automatically.

2.2 Optional information you may add

  • Profile content: photos, cover image, bio, quote, hobbies and interests, social links, profile layout and colours, and any widgets you place. What appears on your profile is what you choose to put there.
  • Questionnaire answers, if you choose to complete the matching questionnaire: up to 37 questions across 10 sections covering social style, interests, music, food, activity level, availability, budget, travel distance, and loneliness indicators. Three sections (loneliness, budget, and location or travel) are private: they are never shown to other members and are used only by the matching system. The personality archetype other members can see is computed only from the public sections, so private answers can never leak through it.
  • Political affiliation, entirely optional and only for members aged 18 or over. See §4.1 for exactly how this works, because it has stronger protection than anything else on the platform.

2.3 Information you generate by using the service

  • Messages you send through our internal messaging system.
  • Activity: events you RSVP to or buy tickets for, invitations you send and receive (with sent, opened and responded timestamps), members you show interest in, favourite or wish-list, matches, blocks, family links, and attendance you record for yourself.
  • Peer reviews you write and receive after paired events, and replies to them (see §2.6).
  • Reports you make about content or members, and the content reported.
  • Host registers at curated events: the two hosts confirm to us who was present, confidentially.

2.4 Information we collect automatically

  • Device and connection data: IP address, browser and device type, operating system, and login records.
  • Usage data: which pages you open, when, for how long and how many clicks, never anything typed. This is purely mechanical and it helps us run the platform well: see §2.7.
  • Safety signals: the behavioural patterns described in §3.1, such as counters of attempted contact outside the age bands.
  • Cookies and similar technologies: see the Cookie Policy.

2.5 Information from third parties

  • Payment information: Stripe processes every payment. We never see or store your card number; we receive a masked reference (card brand, last four digits, expiry), customer and subscription identifiers, and payment outcomes. If the card or payout details you use match ones already in use on another account, Stripe gives us a non-reversible fingerprint match so we can run the authorisation check described in the Terms of Service §3.1; we never see the underlying numbers.
  • We do not buy data about you from anyone, and we do not collect data about you from social networks.

2.6 Peer reviews and reputation

After an event where you and another member were paired by an accepted invitation and both attended, each of you may be asked to review the other. This is personal data about both of you, so here is exactly how it moves:

  • The two of you see each other’s reviews. A review of you is shown to you, signed by its author, and you can reply. Reviews between the pair are not anonymous: you met in person, and the review is part of that same interaction.
  • No other member ever sees the review text. Other members see only your aggregate reputation score, and only once you have enough reviews that no individual review can be identified from it.
  • A small set of safety-related answers is admin-only. These never appear to you or anyone else; they feed the safety systems in §3.1 and are reviewed by humans.
  • Reviews feed the matching system: review quality influences who the platform suggests you meet again.
  • Your rights over review data are in §8. On account deletion, reviews you wrote are anonymised (your name removed) and reviews about you are deleted with your account, per §7.

We process peer-review data on the basis of legitimate interests (Article 6(1)(f)): running a platform where members can rely on each other’s reputation when deciding who to meet in person. The design (text private to the pair, aggregate public only above a minimum count, safety answers admin-only, human review of flags) is the balancing of that interest against your privacy. You can object under Article 21: see §8.

2.7 How we measure use of the platform

We track member usage of the platform so that we can deliver the best service we can, just like every other website and platform. This is purely mechanical and has nothing to do with you as an individual: we record which pages are opened, when, for how long and how many clicks, never anything typed, and we keep those records for 90 days.


3. How we use your information, and the lawful basis for each use

What we do Why Lawful basis (UK GDPR Article 6)
Create and run your account, authenticate you, show you the platform The service you signed up for Contract (6(1)(b))
Verify your age and enforce the age-safety rules Protecting children on the platform Legal obligation (6(1)(c)) under the Online Safety Act 2023, and legitimate interests (6(1)(f))
Match you with compatible members and compose curated event groups The core service: introductions that lead to real-world meetups Legitimate interests (6(1)(f)): see §12 for how matching works and what it never does
Show you events, venues and members near you using your postcode The core discovery service Contract (6(1)(b))
Take subscription payments and ticket payments, process refunds Payments you have asked to make Contract (6(1)(b)); legal obligation (6(1)(c)) for financial records
Run the anti-fraud check on reused payment details Preventing fraudulent multi-account signups Legitimate interests (6(1)(f)): fraud prevention
Send transactional email (verification, password change, receipts, export links, breach notices) Operating your account and meeting legal duties Contract (6(1)(b)) and legal obligation (6(1)(c))
Send you platform messages (invitations, match notifications, event updates) Part of the service; these stay in-app, we do not send marketing email Contract (6(1)(b))
Operate moderation, reporting, blocking, the panic button, and safety reviews Keeping members safe Legitimate interests (6(1)(f)) and legal obligation (6(1)(c)) under the Online Safety Act 2023
Monitor behavioural patterns that suggest misconduct (§3.1) Detecting harm that individual reports miss Legitimate interests (6(1)(f)): member safety, especially children’s
Operate the peer-review and reputation system Trustworthy introductions Legitimate interests (6(1)(f)): §2.6
Improve the service using aggregate analytics Understanding what works Consent (PECR) for analytics cookies; aggregate reporting thereafter
Defend legal claims, respond to lawful requests Legal compliance Legal obligation (6(1)(c)) and legitimate interests (6(1)(f))
Show you advertising We do not. No advertising, no data sales, ever Not applicable

If we ever want to use your data for a new purpose, we will tell you first and identify the lawful basis before we start.

3.1 Behavioural safety monitoring, in plain terms

The platform watches for patterns associated with harm: attempts to reach or repeatedly interact with members outside the permitted age bands, and patterns of behaviour associated with harassment, exploitation of other members, misuse of invitations, or fraud. Three things are always true:

  1. It watches patterns of actions, not the content of your private messages. Admin access to message content happens only on a trigger (§5.1).
  2. A flag never punishes you automatically. Every flag is advisory input to a human administrator who reviews before anything happens.
  3. Flags are never visible to other members.

4. Special-category data (UK GDPR Article 9)

Some data gets extra legal protection. Here is every piece of it we may hold, and how it is protected.

4.1 Political affiliation: a live poll you control completely

Members aged 18 or over can optionally show support for a political party. It works as a toggle, and the design is deliberately all-or-nothing:

  • Never touched: nothing is recorded. There is no entry anywhere.
  • Toggled on: your choice is recorded and counts in our internal, anonymised live poll (admin sees aggregate support levels alongside broad demographics). No other member can see it.
  • Toggled on and placed on your profile: you have chosen to show it to other members. You can take it off your profile again at any time, which returns it to the private state above.
  • Toggled off: the record is deleted. Not hidden: deleted, including from the admin poll. We forget it completely.

The note beside the toggle says exactly this before you touch it, and turning it on is your explicit consent (Article 9(2)(a)) to this processing. Under-18s cannot see or use the feature at all. We never use political affiliation in matching, never share it, and never make any decision about you based on it.

4.2 Answers that can imply special-category data

Two kinds of optional questionnaire answers could indirectly reveal protected characteristics:

  • Dietary requirements (for example halal or kosher) can imply religious belief.
  • Loneliness and wellbeing answers shade towards health information.

Both are optional, and by choosing to provide them you consent to us processing them for matching and event planning only. The loneliness section is one of the private sections in §2.2: it is never shown to any other member, and nothing visible on your profile is derived from it.

4.3 What we deliberately do not collect

We do not ask for your race or ethnicity, religion, sexual orientation, health conditions, trade-union membership, or biometric data. If you choose to write something like that in your own bio, you have chosen to publish it to other members; we still do not use it for anything.


5. Who we share your information with

We share personal data only with the recipients below, only as needed to run the service:

Recipient What they get Why
Stripe (payment processor) Name, email, payment amounts, and payment identifiers Subscriptions, ticket payments, refunds, fraud prevention. For ticket sales, Stripe Connect routes the organiser’s share to the organiser’s own Stripe account
Our hosting provider (currently GoDaddy) All site data, as the servers it lives on Hosting. They act only on our instructions
Google Workspace (Gmail API) The recipient address and content of transactional emails we send you Delivering verification, password-change and receipt emails. We send no marketing email
Google Maps and Places Address and venue searches typed by organisers and venues when creating listings Venue lookup and maps on event pages
Google Analytics Usage analytics, only if you consent to analytics cookies Aggregate site statistics. Off until you opt in
postcodes.io (postcode lookup) The postcode you type, and nothing else Confirming the postcode is real and obtaining its coordinates
CookieYes Your cookie choices, stored in your own browser Running the consent banner
The Internet Watch Foundation and the National Crime Agency Reports of suspected child sexual abuse material and the uploading account Child protection; reporting duties under the Online Safety Act 2023
Police, regulators, courts What a valid legal order requires Legal obligation

We do not share your data with advertisers, data brokers, marketing networks, or social-media tracking pixels, and we do not sell data. The live processor list, with locations, is kept at /sub-processors/.

5.1 When our own administrators can look at your data

Administrators have technical access to the platform; whether they actually look is governed by a trigger policy:

Routине operation involves no reading of your private content. Running the site, fixing bugs and viewing aggregate statistics does not involve opening anyone’s messages.

Triggered access, which is logged with who, when and why:

  • You report someone, or someone reports you: the administrator reviews the reported content and enough context to judge it, and no more.
  • You ask us for help with your own account or data.
  • A safety flag from §3.1 needs human review.
  • A court, regulator or law-enforcement agency lawfully requires it.
  • A security incident affects the platform.

Every administrator access to private content is recorded in an audit log kept for 6 years, and you can ask us whether your data has been accessed and why (unless telling you would prejudice a live investigation).


6. International transfers

Most data stays in the UK. Where a processor is a US company (Stripe, Google), we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Agreement or Addendum with a transfer risk assessment. Whatever the mechanism, your data gets protection essentially equivalent to UK GDPR.


7. How long we keep your data

The principle: once you are gone, you are gone. We believe in the right to be forgotten and the right to live offline.

7.1 What happens when you delete your account

  • Immediately: your profile goes offline, your login is disabled, other members can no longer find you, and any subscription is cancelled.
  • For 90 days: your data is retained, invisible to everyone, purely so that a report raised about conduct (for example by someone you met at an event) can still be investigated. Nobody reads anything during this window unless such a trigger opens; there are no fishing expeditions.
  • After 90 days: everything is deleted from our active systems: profile, photos, questionnaire answers, matches, invitations, and messages. Conversations are deleted from both sides: because messaging is internal, we remove every conversation you were part of from all participants’ inboxes, not just your copy. Backup copies are overwritten in the normal backup cycle.
  • Reviews you wrote about events and venues are kept but anonymised, because other members relied on them; ask us if you want them deleted outright. Contact-form submissions are deleted.
  • If an investigation is open at the 90-day point, deletion waits until it concludes, then completes.

7.2 The narrow exceptions

Trigger What we keep How long
An open report, moderation case or investigation about you The relevant content and records Until it concludes, then deleted
A legal claim between us, actual or notified Data relevant to the claim Until resolved or time-barred
A preservation order from police, a court or a regulator What the order specifies As long as it requires
Payment records Transaction records only (not profile or messages) 6 years, as tax law requires
Reports we made about child sexual abuse material The report and its hash record Indefinitely, for crime-reporting integrity

7.3 While your account is open

Data Kept for Why
IP addresses and login records 12 months Security and abuse prevention
Usage records: which pages and features you use, and the sign-in sessions they belong to Page and feature records 90 days; sign-in session records 365 days Running the platform well, as described in §2.7
Moderation records (reports, actions, suspensions) 6 years from the action Defending legal claims; spotting repeat patterns
Admin access audit logs 6 years Accountability for §5.1
Cookie consent records Duration of your consent choice Demonstrating PECR compliance
Expired invitations and similar operational leftovers Reviewed and cleared periodically Housekeeping
Aggregated, anonymised statistics Indefinitely No longer personal data

7.4 Want it gone sooner?

Email info@uksocials.club after closing your account and we will delete sooner unless one of the §7.2 triggers applies, in which case we will tell you which one and why. While your account is open you can delete individual photos, answers and profile content yourself at any time.


8. Your rights

You have all of the following rights, free of charge. We respond within one month, extendable by two further months for genuinely complex requests (we tell you within the first month if so, and where we need clarification the clock pauses until you provide it, as the law provides).

Right What it means How
Access (Article 15) A copy of the personal data we hold about you The Export Data tool in your account produces an immediate, machine-readable download covering every part of the platform (profile, questionnaire, messages, invitations, events, reviews and more). Or email us
Rectification (Article 16) Correct wrong or incomplete data Edit your profile and account yourself, or email us
Erasure (Article 17) Delete your data Delete your account (§7), or email us
Restriction (Article 18) Pause processing while something is disputed Email us
Portability (Article 20) Your data in a reusable format The same Export Data tool
Object (Article 21) Object to processing based on legitimate interests, including the matching and reputation systems Email us; we stop unless compelling legitimate grounds override, and we will explain either way
Automated decisions See §12: no solely-automated decision with significant effects is made about you
Withdraw consent (Article 7(3)) For political affiliation: toggle it off, which deletes it. For cookies: Cookie Settings in the footer. For anything else consent-based: email us
Complain to us Your statutory right to complain directly to the controller: we acknowledge within 30 days and respond without undue delay info@uksocials.club, subject “Privacy complaint”
Complain to the ICO (Article 77) The regulator, at any time https://ico.org.uk/concerns/

To exercise any right: info@uksocials.club. We may need to verify you are you before releasing data; that protects you.


9. Security

  • HTTPS everywhere; passwords stored as one-way hashes; optional two-factor authentication on every account.
  • Card numbers never touch our systems: Stripe holds them.
  • Location metadata is stripped from every uploaded photo: EXIF and GPS data are removed from the stored file itself, so a photo you upload can never silently reveal where it was taken.
  • No public profile browsing: profiles are only visible to logged-in members, and members outside your age band cannot see you at all.
  • Production access is restricted to named administrators; administrative access to private content is audit-logged (§5.1).
  • Backups are encrypted; software is kept patched.

If a breach occurs that risks your rights and freedoms, we notify the ICO within 72 hours, and if the risk to you is high we notify you directly without undue delay, by email.

If you think your account has been compromised: change your password, then email info@uksocials.club.


10. Children and the protection of young members

UK Socials is for people aged 13 and over, which means 13-to-17-year-olds are on the platform alongside adults, and the whole design accounts for that. We follow the ICO’s Age Appropriate Design Code and the Online Safety Act 2023, and we keep internal children’s access, children’s risk, and illegal-content risk assessments, available to Ofcom on request.

10.1 The structural protections

  • The age gates. Contact between members aged 21 or over and members aged 17 or under is blocked, and so is contact between members aged 18 or over and members aged 15 or under: messages, invitations, matching and profile visibility. Members outside your band do not appear to you at all, and where an age cannot be established the platform blocks contact rather than allowing it.
  • Ages are never displayed. No member’s age or date of birth is shown to anyone, so nobody can browse members by youth.
  • Event age groups are absolute. Every event carries an age group and nobody can book, RSVP or be invited outside it. No exceptions, including family.
  • Family Link is the single, narrow exception to the contact gates: genuine family members (parent and child, siblings, cousins) can both explicitly opt in to contact. It never overrides event age groups, and misuse is treated as a serious safety breach.
  • The panic button. Members under 18 have a one-tap panic control on every page that sends an urgent report straight to us, and only to us, so a young member can get help without having to tell anyone around them first.
  • No political affiliation for under-18s (§4.1), and the private questionnaire sections are private for everyone.
  • Matching for under-18s stays inside their own age band, the contact gates always apply to its results, every curated group is approved by a human, and we never use any member’s data for advertising or marketing profiling, adult or child.

10.2 The ICO Children’s Code, standard by standard

Standard How we meet it
Best interests of the child The age gates, absolute event age groups, and the panic button exist because of this principle, and feature decisions consider under-18 impact explicitly
Data protection impact assessment Held internally, reviewed at least annually and on significant change
Age-appropriate application Date of birth verified at signup; 13-to-17-year-olds get the protections on this page
Transparency This policy, the Children’s Safety Statement, and short in-context notes at the point of use
Detrimental use No advertising, no data sales, no marketing profiling, no attention-farming features
Policies and community standards Published, and applied consistently (Terms §9, §13)
Default settings Private by design: nothing optional is visible until a member chooses to place it, profiles are invisible to non-members, and under-18s are invisible to out-of-band adults entirely
Data minimisation Postcode not address; date of birth collected but never displayed; card numbers never held
Data sharing §5 only; never for advertising
Geolocation Coordinates derived from postcode only; no GPS tracking, and GPS metadata is stripped from photos
Parental controls Family Link (mutual opt-in), and a parent or guardian can ask us to delete their child’s account: email info@uksocials.club
Profiling Matching for under-18s stays in-band, is human-approved for curated events, and no marketing profiling exists for anyone
Nudge techniques We do not nudge anyone, let alone children, toward lower privacy, longer sessions, or spending
Connected toys and devices Not applicable
Online tools Report controls everywhere, the panic button, block, Cookie Settings, Export Data and account deletion all work identically for under-18s

10.3 Age assurance

We verify the 13 minimum by declared date of birth plus behavioural signals, which is the proportionate approach for a service like ours: UK Socials hosts no pornography and no content promoting suicide, self-harm or eating disorders (all prohibited and removed), so the higher “highly effective age assurance” bar for services carrying that content does not apply. We keep this position under review against Ofcom and ICO guidance, and our internal children’s access assessment records the reasoning.

10.4 Under 13?

We do not knowingly hold an account for anyone under 13. If you believe a member is under 13, email info@uksocials.club and we will investigate and, where confirmed, delete the account. If you are under 13: we are sorry, but this platform is not for you yet.

10.5 Worried about a child?

Email info@uksocials.club with the subject “URGENT: child safety” and it is handled as same-day priority by a human. If a child is in immediate danger, call 999 first.


11. Cookies

Covered in the separate Cookie Policy. The short version: strictly necessary cookies run the site; analytics cookies are off unless you opt in; we use no advertising or marketing cookies at all; and the Cookie Settings link in the footer reopens your choices at any time.


12. Automated decision-making and profiling

The matching system (we call it the Social Engine) is profiling: it scores questionnaire answers, interests, location and review quality to suggest people and compose curated event groups. Here is what keeps it fair:

  • No decision with legal or similarly significant effects about you is ever made solely by a machine. Every curated group is approved by a human before invitations go out, every safety flag is reviewed by a human before anything happens, and moderation actions are taken by humans.
  • Matching output is suggestions: an invitation you can decline, never a restriction on what you can do.
  • The age gates in §10.1 are automated, and deliberately so: they only ever block contact for child-safety reasons, which is exactly what the law expects them to do. Family Link is the review route if a genuine family relationship is being blocked.
  • Political affiliation never feeds matching (§4.1), and the private questionnaire sections never surface publicly (§2.2).

You can ask for human review of anything the platform has done that affects you: info@uksocials.club.


13. Changes to this policy

The date at the top tells you the current version. Substantial changes (new data categories, new recipients, a new lawful basis, a change of controller) are notified at least 30 days ahead by internal message and, where possible, email. Minor clarifications take effect on publication. Previous versions are archived: email us if you want one.


14. Contact

All privacy matters: info@uksocials.club
Post: CMP Technologies Ltd, Registered office address: being procured (contact info@uksocials.club for postal correspondence)
The regulator: ICO, https://ico.org.uk/concerns/, 0303 123 1113