Data Processing Agreement — FruityDate

Data Processing Agreement

Last updated: 15 June 2026

1. Parties

This Data Processing Agreement ("DPA") forms part of the contract for the use of FruityDate between you ("Data Subject") and Sparkle5, LLC ("Controller"), and supplements the Privacy Policy.

2. Subject Matter

The Controller processes personal data — profile information, photos, messages, and technical/usage data — to provide and operate the FruityDate dating service.

3. Legal Basis (GDPR Art. 6)
4. Processors and Sub-processors
ProcessorPurposeLocationData shared
Hetzner Online GmbHApplication hosting + object storageGermany (EU)All persisted data
Stripe Payments Europe Ltd. (EU contracting entity)
Receives data via Stripe Inc. (USA), Stripe Payments UK Ltd, and regional affiliates (Stripe Singapore, Stripe Canada, Stripe Australia)
Card & subscription billing worldwide; fraud prevention (Stripe Radar); KYC/AML Ireland (EU) primary; transfers to USA, UK and the cardholder's regional Stripe affiliate Cardholder name; tokenised card details (the raw PAN is handled by Stripe Elements — we never see or store it); billing & shipping address; IP address; device fingerprint (Radar); 3D-Secure / PSD2-SCA data
Sergel Kredittjenester ASMobile direct-carrier billing (Sweden only)Norway / SwedenMSISDN, charge events
SMTP2GO Inc.Transactional email deliveryEU regionEmail address + message body
Mailgun Technologies Inc.Transactional email delivery (fallback)EU regionEmail address + message body
Plausible Analytics (self-hosted)Aggregate, cookieless web analyticsSparkle5, LLC infrastructure — analytics.luvu.plusPageview events, daily IP-hash (rotated)
AbuseIPDBIP reputation check at signupUSASignup IP only — not linked to user record

We may swap Plausible Analytics for an equivalent self-hosted Matomo instance, run on our own infrastructure under the same cookieless configuration, without changing the nature, scope, or purpose of analytics processing. No analytics data is forwarded to any third party.

4a. Stripe — Special Disclosures

Because we accept card payments worldwide via Stripe, additional disclosures apply on top of the row above:

5. International Transfers

The bulk of personal-data processing happens inside the EU/EEA. Cross-border transfers happen in two contexts:

6. Security Measures (Art. 32)
7. Data Subject Rights (Art. 12–22)

To exercise access, rectification, erasure, restriction, portability, or objection, contact our Data Protection Officer at hello@fruitydate.com. We respond within one calendar month per Art. 12 (3).

8. Retention

Profile data is retained while your account is active. On account deletion via account-deletion, personal data is anonymised within 30 days. Payment records are retained for the statutory period (10 years under German HGB §147). Analytics is aggregate only — no record can be linked back to you.

9. Breach Notification (Art. 33)

We notify the competent supervisory authority within 72 hours of becoming aware of a personal-data breach, and notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights.

10. Changes

Material changes to this DPA are announced via in-app notice and email at least 30 days before they take effect.