Article 30 GDPR Compliance Record

Record of Processing Activities

Official GDPR Article 30 Processing Register for Tremble Application. Revised August 2026.

AMS Solutions d.o.o. · Frenkova ulica 23, 6280 Ankaran, Slovenia

Contact: privacy@trembledating.com · App: Tremble (iOS & Android)

1. Processing Purposes & Legal Bases

PurposeLegal BasisDescription
Core Matching & ProfileArt. 6(1)(b) GDPRProfile creation, authentication, gender & matching preference (interestedIn) per ADR-012
Proximity RadarArt. 6(1)(a) GDPRGPS geohash & BLE signal detection for physical proximity
Special Category DataArt. 9(2)(a) GDPRVoluntary religious beliefs and ethnicity
Pulse InterceptArt. 6(1)(a) GDPREphemeral photo or phone sharing
Safe ZonesArt. 6(1)(f) GDPRUser-defined obfuscated geohash areas excluded from radar

2. Data Categories & Retention Schedule

  • Identity & Account: Firebase UID, email, DOB, profile photos → Retained until account deletion.
  • Proximity Location: Raw GPS coordinates transient in RAM only (never stored). Geohash precision 7 stored for max 24 hours (`geoHashExpiresAt`).
  • Bluetooth Events: `proximity_events` RSSI device IDs → 10-minute hard TTL.
  • Pulse Intercept: Ephemeral photo deleted on open or after 10 minutes. Phone numbers → 10-minute memory queue.
  • GDPR Audit Log: Erasure/export records → 2-year retention.
  • Moderation Reports: Anonymised reports retained for legal defense under Art. 17(3)(e) GDPR.