DCZ Media Holdings LLC ("DCZ", "we", "our", "us") operates DesiCouplesZ at desicouplesz.app and desicouplesz.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our platform.
By creating an account or using DCZ, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our platform.
1. Information We Collect
1.1 Account Information
When you register, we collect your email address, date of birth (to verify you are 18+), display name, and password (stored as a bcrypt hash — never plaintext).
1.2 Profile Information
Information you choose to add to your profile: photos, bio, location (city-level only), relationship status, heritage, and preferences.
1.3 Age & Identity Verification
We use third-party age verification providers (Yoti at registration; HyperVerge for explicit content access). These providers process biometric or document data under their own privacy policies. We receive only a verification status (pass/fail) and a reference ID — we do not store your ID document images.
For 18 U.S.C. § 2257 compliance, custodial records (verified legal name, date of birth, ID type, and hashed ID number) are stored in a separate encrypted database accessible only to our designated records custodian.
1.4 Usage Data
We automatically collect IP address, browser type, device type, pages visited, and interaction data for security, analytics, and fraud prevention.
1.5 Communications
Messages sent between members are stored encrypted. We may access them only when required by law or to investigate abuse reports.
2. How We Use Your Information
- To operate and improve the platform
- To verify your age and identity
- To process payments via CCBill, Apple IAP, or Google Play Billing
- To send service communications (account updates, security alerts)
- To detect and prevent fraud, abuse, and CSAM
- To comply with legal obligations (18 U.S.C. § 2257, NCMEC reporting)
- To enforce our Terms of Service
3. Content Moderation, CSAM & Communications Monitoring
All uploaded media is scanned using PhotoDNA (Microsoft) and Hive AI for child sexual abuse material (CSAM). Any detected CSAM is immediately removed, the account is permanently banned, and a report is filed with the National Center for Missing & Exploited Children (NCMEC) CyberTipline as required by 18 U.S.C. § 2258A. We do not inform the uploader of the specific reason for removal.
3.1 Recording and review of interactive communications
Interactive video sessions conducted on the Platform — including one-to-one video calls, group video rooms and livestreams — are recorded by DCZ and may be reviewed by authorised personnel. Recording is automatic and applies to all such sessions. By initiating or joining an interactive video session you acknowledge and consent to this recording and review.
Purpose and limitation. Recordings are retained and reviewed for the sole purposes of (a) detecting, preventing and investigating unlawful conduct on the Platform, including CSAM, human trafficking, non-consensual content, coercion, extortion and the sexual exploitation of minors; (b) investigating reports made by members under our reporting mechanisms; and (c) responding to valid legal process. Recordings are not reviewed for marketing, profiling, advertising, model training, or commercial purposes of any kind, and are never shown to other members or made public.
Lawful basis (UK/EU). Where the UK GDPR or EU GDPR applies, this processing is carried out on the basis of our legitimate interests under Article 6(1)(f) — namely the prevention and detection of crime and the safety and integrity of the Platform and its users — and, where the recording contains special category data within the meaning of Article 9(1), on the basis of substantial public interest under Article 9(2)(g), as further specified in Schedule 1, Part 2, paragraphs 10, 11 and 18 of the UK Data Protection Act 2018 (prevention or detection of unlawful acts; protecting the public; safeguarding of children and of individuals at risk). We have completed a balancing assessment and consider that the interests pursued are not overridden by the interests or fundamental rights and freedoms of data subjects, given the safeguards described below. This processing also supports our obligations as an intermediary service provider under Regulation (EU) 2022/2065 (the Digital Services Act), in particular Articles 16 and 23.
Lawful basis (United States). Recording is undertaken with the consent of the parties to the communication, given through acceptance of these terms prior to use of the Platform, and in reliance on the service provider exception at 18 U.S.C. § 2511(2)(a)(i), which permits an electronic communication service provider to intercept, disclose or use communications in the normal course of employment while engaged in an activity necessarily incident to the rendition of the service or to the protection of the rights or property of the provider. This notice is provided so that recording is undertaken with the prior consent of all parties in jurisdictions imposing an all-party consent requirement, including but not limited to California (Cal. Penal Code § 632), Florida, Illinois, Maryland, Massachusetts, Montana, Pennsylvania and Washington. Nothing in this section derogates from our mandatory reporting obligation under 18 U.S.C. § 2258A.
Access controls and safeguards. Call recordings are encrypted at rest (AES-256) in private object storage, are never publicly accessible, and are retrievable only through short-lived, server-issued credentials. Access is restricted to a limited number of named personnel performing trust-and-safety review, is exercised on a least-privilege basis, and is subject to internal access controls. Recordings are not disclosed to any third party except (i) to law enforcement pursuant to valid legal process, (ii) to NCMEC where reporting is legally mandated, or (iii) where disclosure is otherwise required by law.
Retention. Call and livestream recordings are retained for the periods set out in §5 and are then automatically and permanently deleted, save where a recording is subject to a legal hold, an active investigation, or a mandatory retention obligation.
Your rights. You retain the rights described in §6 in respect of recordings, including the rights of access and erasure. Those rights are qualified to the extent that compliance would prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or a legal obligation to which we are subject. If you do not wish an interactive video session to be recorded, do not initiate or join one; all other features of the Platform remain available to you.
4. Sharing Your Information
We do not sell your personal data. We share information only with:
- Service providers (processors) — we use only the following, each bound to process data on our instructions:
- Hetzner — server hosting (United States, Finland)
- Backblaze B2 — encrypted media storage
- Cloudflare — CDN, DDoS protection and bot detection (Turnstile)
- Resend — transactional email (verification, approval, security notices)
- Twilio — SMS one-time passcodes
- LiveKit — real-time video for calls, group rooms, livestreams and verification (self-hosted by DCZ)
- Yoti / HyperVerge — age and identity verification
- Hive AI, Microsoft PhotoDNA — automated content moderation and CSAM detection
- ipwho.is — approximate city-level lookup of your IP address for the review team
- CCBill, Apple, Google — payment processing
- Law enforcement — when required by valid legal process
- NCMEC — CSAM reports as required by law
- Business transfers — in the event of a merger or acquisition, subject to the same privacy protections
5. Data Retention
- Active account data: retained while your account is active
- Verification recordings (the AI Bot / Genuine Verification video): retained for 90 days from recording, then automatically deleted. Processed on the basis of your consent, given on the verification screen, for the sole purpose of confirming your account is operated by a real adult. Never shown to other members, never made public, and never used for marketing or training. You may withdraw consent and request deletion at any time (see §6.4) — doing so may mean the Genuine badge cannot be granted or is removed.
- Call, group video and livestream recordings (see §3.1): one-to-one and group call recordings are retained for 120 days from recording; livestream recordings for 30 days. Both are then automatically and permanently deleted, save where subject to a legal hold, an active investigation, or a mandatory retention obligation.
- Deleted account data: purged within 30 days, except where required by law
- 2257 custodial records: retained for 7 years as required by 18 U.S.C. § 2257
- Payment records: retained per CCBill / Apple / Google requirements
- CSAM incident logs: retained indefinitely
6. Your Rights
DCZ has members worldwide, with a large South Asian diaspora community in the United Kingdom, European Union, United States, Canada, Australia, the Gulf and India. Your rights depend on where you live. In all cases you may contact [email protected] to exercise them, and we will respond within the timeframe your law requires. We may be unable to delete data we are legally required to retain (for example 18 U.S.C. § 2257 records or CSAM reports).
6.1 Who is responsible for your data
The data controller is DCZ Media Holdings LLC, a Wyoming limited liability company.
6.2 Legal bases we rely on (UK / EU members)
- Performance of a contract — creating your profile, matching, messaging and running the service you signed up for.
- Consent — precise (GPS) location, verification recordings, and any explicit content you choose to upload. You may withdraw consent at any time (see 6.4).
- Legitimate interests — approximate (IP-based) location, fraud and bot prevention, moderation and community safety.
- Legal obligation — age and record-keeping requirements, and mandatory CSAM reporting.
Some of what you may choose to share — for example sexuality or relationship orientation — is special category data under UK/EU law. We process it only because you have manifestly made it public on your profile and have given explicit consent by providing it. You are never required to supply it.
6.3 Where your data is stored (international transfers)
Our servers are located in the United States (Oregon), with video infrastructure in Finland. If you are in the UK, EEA, or another country with data-transfer rules, your personal data will be transferred to and processed in the United States. Where required, we rely on Standard Contractual Clauses and equivalent safeguards for those transfers. You may request details of the safeguards in place.
6.4 Withdrawing consent
Withdrawing consent is as easy as giving it. For precise location, go to Settings → Location & Privacy, where you can see whether DCZ holds your coordinates and delete them in one click. You may also revoke the permission in your browser or device settings. Withdrawal does not affect the lawfulness of processing before it, and never removes your account or approval.
6.5 Rights by region
- United Kingdom & European Economic Area (UK GDPR / GDPR) — access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), and withdrawal of consent. You may complain to your supervisory authority: in the UK the Information Commissioner's Office, or in the EEA your national authority.
- India (DPDP Act 2023) — access, correction, erasure, grievance redressal, and nomination. Complaints may be raised with the Data Protection Board of India after contacting us first.
- California (CCPA / CPRA)— know, delete, correct, and opt out of “sale” or “sharing”. We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights.
- Canada (PIPEDA) — access and challenge accuracy; complaints to the Office of the Privacy Commissioner of Canada.
- Australia (Privacy Act) — access and correction; complaints to the Office of the Australian Information Commissioner.
- Everywhere else — we extend access, correction and deletion to all members regardless of location.
7. Automated Decision-Making & Matchmaking
DCZ ranks profiles for you using an automated compatibility score. It combines what you and the other member each said you are looking for, shared interests and languages, heritage, experience level, distance between you, how recently each of you was active, and any grooming preferences you set. Verified members receive a ranking boost.
- It orders results — it does not gate access. A low score never hides you from anyone, blocks messaging, or excludes you from search. Preferences you set rank members higher or lower; they never filter people out.
- No legal or similarly significant effects. Nothing about your rights, money or account status is decided automatically, so this is not decision-making under Article 22 of the UK/EU GDPR.
- Moderation is human-reviewed. Automated tools flag content, but a person makes the decision to approve, reject, suspend or ban — except for confirmed CSAM, which is actioned and reported immediately as the law requires.
- You can ask. Contact us for an explanation of how your profile is ranked, or to object to automated ranking.
8. Making a Request
Email [email protected] from the address on your DCZ account, stating what you want (access, correction, deletion, export, objection, or withdrawal of consent).
- Identity check. We confirm you control the account email or phone number. We will not demand government ID for a routine request — asking for more data than necessary would defeat the purpose.
- Response time. Within 30 days, extendable once by a further 30 days for complex requests, in which case we will tell you why.
- Cost. Free. We charge nothing for exercising your rights, regardless of whether you are a paid member.
- Refusals. If we cannot act — for example where a record must be kept by law — we will say so and explain your right to complain.
9. Data Breach Notification
If a breach affects your personal data, we will investigate immediately, contain it, and notify you without undue delay where there is a risk to your rights. Where the law requires it we will also notify the relevant supervisory authority — within 72 hours under the UK/EU GDPR — and cooperate with law enforcement. Given the nature of this platform we treat any exposure of profile content, private media or location data as high risk by default.
10. Marketing & Communications
Service messages you cannot opt out of while your account is open — security alerts, verification codes, approval decisions and policy changes. Everything else is optional.
- Manage every notification channel in Settings → Notifications
- Use the unsubscribe link in any marketing email
- Or email [email protected] to opt out of all marketing
- We do not share your address with third-party advertisers, ever
11. Cookies
We use HTTP-only cookies for authentication (session tokens). We use Cloudflare Turnstile for bot detection. We do not use advertising cookies or third-party tracking pixels. See our full Cookie Policy for the complete list of cookies, what each one does, and how long it lasts.
12. Security & Staff Access
We use HTTPS/TLS for all data in transit, bcrypt for passwords, HTTP-only cookies for sessions, presigned short-lived links for private media, and encrypted storage for sensitive records. No system is 100% secure — if you believe your account has been compromised, contact us immediately.
12.1 Staff access
Access to member data is restricted to authorised personnel who need it to operate the service — for example to review a signup, moderate reported content, or resolve a support request. Staff are bound by confidentiality obligations, and we maintain internal controls and monitoring appropriate to the sensitivity of the data. Private media is never publicly accessible; it is served through short-lived links that expire rather than permanent public URLs.
13. Children
DCZ is strictly for adults 18 years of age or older. We do not knowingly collect information from minors. Any account found to belong to a minor will be immediately terminated and the incident reported to appropriate authorities.
14. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or an in-app notice. Continued use of DCZ after the effective date constitutes acceptance of the updated policy.
15. Contact
DCZ Media Holdings LLC
30 N Gould St Ste N
Sheridan, WY 82801, United States
Email: [email protected]