Privacy policy
Last updated : 2026-07-04
Baza is a service strictly reserved for adults (18 years old or over).
This English translation is provided for your convenience. The legally binding version is the French one. Read the French version
Data controller
The data controller is GELMIX (see the Legal notice). You can write to bonjour@baza.fr.
Data processed
The service processes only the data necessary for it to work:
- mobile phone number (account identifier, verified by SMS);
- email address (mandatory at registration — login and account recovery);
- password (stored using a secure hash — scrypt —, never in clear text and never in a reversible form);
- date of birth (adulthood check — only the calculated age is shown, and this display can be turned off);
- nickname, profile type (woman, man, couple), presentation sentence, selected dating preferences;
- profile photo, photos sent in messaging and photos in your private albums;
- approximate position (only with your explicit consent);
- private messages and messages exchanged in groups;
- favourites, hidden profiles and blocks;
- reports sent and received, and any attachments you choose to add to them;
- the certification status of your profile (certified or not, method and date);
- certification photo, only if you request certification AND the automated analysis leaves a doubt: it is then kept temporarily, in a private area, so that a member of the team can review it (see ‘Retention periods’);
- push notification subscription, only if you enable it (the subscription address supplied by your browser, the associated public encryption keys, a hashed fingerprint of the browser and the platform type);
- technical connection data (server logs, session identifiers).
Minimisation
No real name or first name, no postal address and no identity document are requested: only the data necessary for account security and adulthood verification is collected.
Purposes and legal bases
Processing relies on the following legal bases:
- providing the service (profiles, messaging, favourites) — performance of the contract;
- displaying nearby profiles — consent (geolocation);
- security, abuse prevention, moderation of the profile photo, handling of reports — legitimate interest and legal obligations;
- photo certification of the profile — consent (you alone request it; the service works without it);
- push notifications — consent (permission granted to your browser, revocable at any time);
- transactional emails (account recovery, security notifications) — performance of the contract.
Geolocation
Your position is recorded only with your explicit consent. It is never shown: no exact coordinate or address is displayed, neither to you nor to other members.
Other members see only a rounded distance (a multiple of 100 m), computed on the server side. ‘Discreet’ mode fully hides your position (no distance shown).
Withdrawing consent immediately erases your position: no position is kept after withdrawal.
Private messages and private media
Messages exchanged privately — text as well as photos — are never read or automatically moderated: they fall under the confidentiality of correspondence. They are accessible only to the participants in the conversation.
Photos sent in messaging are never passed to any moderation or analysis service. They are compressed and refused if they contain metadata (EXIF/GPS) — technical protections only.
The same rule applies to the photos in your private albums and to group messages: none of this content is analysed automatically or passed to any external analysis service. It is served only to the people you have authorised, through an authenticated address, and is neither public nor indexable.
Profile photo: automated moderation then human review
The profile photo is PUBLIC: it is the only photo subject to automated moderation, before any publication. The image is passed to OpenAI for analysis — first to a classification service, then, if necessary, to an image analysis model. If the analysis is unavailable, the photo is refused: no photo is ever published by default.
Where the refusal concerns content, the photo is never published but may be kept temporarily in a private area so that a member of the moderation team can review it. If it is accepted, it becomes your profile photo; if it is refused, the file is deleted. Without a human decision, it is automatically destroyed at the latest 3 days after it was submitted.
A photo refused because there is a doubt as to whether the person shown is a minor never enters that queue: it is destroyed immediately.
Profile certification (optional)
Certification is a VOLUNTARY step: you alone can request it, and the service works fully without it. It consists in taking a photo of yourself there and then, with your phone camera, reproducing a code shown on screen for a limited time.
That photo is passed to OpenAI for a single question: does it show a real, sharp, properly lit and properly framed face? It is NEVER compared with your profile photo, involves NO identity facial recognition, NO identity document, NO video and NO location data (image metadata is refused). Certification attests to a level of confidence; it does not guarantee a member’s civil identity.
If the analysis accepts the photo, your profile is certified and the photo is NOT kept. If it refuses it, you are told the reason and the photo is NOT kept. If it leaves a doubt, the photo is kept in a private area so that an authorised person can review it, then automatically destroyed when the retention period ends (3 days by default, 30 days at most). Only the result (certified or not) is visible to other members.
Push notifications
Push notifications are optional and work only with your permission, granted to your browser. When you enable them, the service records the subscription address supplied by your browser, the associated public encryption keys, a hashed fingerprint of the browser and the platform type — never your phone number, your email or your position.
The content of a notification is MINIMAL: an event type, the sender’s nickname, the conversation identifier and, where applicable, your total number of unread messages. The text of your messages NEVER appears in it, nor does any photo.
That content is encrypted according to the Web Push standard: the notification service of your browser (provided by your browser or system vendor) delivers the message without being able to read it. You can disable notifications at any time; the subscription is then deleted.
Recipients and processors
Your data is neither sold nor used for advertising purposes. It is passed only to the strictly necessary technical processors:
- Hetzner Online GmbH (Germany) — hosting of the servers, within the European Union;
- Mailjet — delivery of transactional emails;
- OpenAI — image analysis: automated moderation of the profile photo only, and, if you request certification of your profile, analysis of the certification photo (never your messages, never your messaging photos, never your private albums, never your position);
- Capitol Mobile — sending verification codes by SMS;
- the notification service of your browser or system vendor (Apple, Google or Mozilla depending on the device) — delivery of push notifications, if you have enabled them: it receives the subscription address and an encrypted payload it cannot read.
Transfers outside the European Union
The servers hosting the service and your data are located within the European Union (Germany).
Two processing operations involve a provider established outside the European Union: moderation of the public profile photo and, if you request it, analysis of the certification photo, both entrusted to OpenAI, a company established in the United States. These transfers are strictly limited to the image concerned and to that sole purpose: neither your messages, nor your messaging photos, nor your private albums, nor your position are transferred.
Delivery of push notifications, if you enable them, goes through the notification service of your browser or system, which may be established outside the European Union; the payload transmitted is encrypted and cannot be read by that service.
For any question about the safeguards framing these transfers, write to bonjour@baza.fr.
Retention periods
- account data: kept for as long as the account is active;
- account deletion: immediate erasure of the data (see the Account deletion page);
- SMS verification codes: ephemeral, stored only in hashed form, single-use;
- profile photo refused by automated moderation and awaiting human review: destroyed (file and record) at the latest 3 days after submission if no decision is taken, and immediately once a decision is taken;
- certification photo left in doubt: kept for the time of the human review then automatically destroyed when the retention period ends — 3 days by default, 30 days at most; if the automated analysis accepts or refuses it, it is not kept at all;
- push notification subscription: kept for as long as you leave notifications enabled, deleted when you unsubscribe, when the account is deleted, or when the notification service reports that the subscription no longer exists;
- technical logs: kept for at most 12 months (legal obligations), never beyond the applicable legal periods; backups: purged at the latest 30 days after their creation.
- permanent suspension of an account: irreversible fingerprints (hashes) of the phone and email are kept for the sole purpose of preventing re-registration (legitimate interest — security of the service); they are deleted if the account is reinstated.
Your rights (GDPR)
You have the rights of access, rectification, erasure, restriction, objection and portability over your data. You can exercise them through the Contact page.
You may also lodge a complaint with the CNIL (cnil.fr).
Security
Exchanges with the service are encrypted in transit. Sessions are revocable (logging out invalidates the token). Verification codes are never stored in clear text.
Your password is not encrypted: it is HASHED (scrypt function, with a unique salt per password). A hash is not reversible — nobody, ourselves included, can recover your password from what is stored.
Photos are stored outside any public folder and are served only to authorised people (you for your profile photo, the participants for a messaging photo, authorised members for a private album).
Cookies and local storage
The service does not use advertising cookies. Only storage strictly necessary for it to work is used (session, display preferences).
If audience-measurement tools were to be added, they would be the subject of dedicated information and, if required, a prior consent banner.
Minors
The service is forbidden to minors. Any ‘Presumed minor’ report is handled as a priority and leads to deletion of the account if minority is confirmed.