Logo Agapé Back
🇪🇸 ¿Prefieres leer esto en español? Haz clic aquí

Privacy Policy

Version: 3.0 (Masterpiece Edition) Last Updated: January 19, 2026 Effective: Immediately
Table of Contents (24 Sections)
  • 0. Legal Definitions
  • 1. Introduction and Scope
  • 2. Data Controller
  • 3. Data We Collect
  • 4. Legal Bases (GDPR/UK)
  • 5. Purposes and Algorithms
  • 6. AI & Machine Learning
  • 7. Recipients and Transfers
  • 8. Sub-Processors
  • 9. Data Retention
  • 10. Your Global Rights
  • 11. Multi-Jurisdictional (11 countries)
  • 12. Children's Protection
  • 13. Security Measures
  • 14. Cookies & Technologies
  • 15. Apple & Google Requirements
  • 16. User Representations
  • 17. Limitation of Liability
  • 18. Indemnification
  • 19. Arbitration & Class Action Waiver
  • 20. Dispute Resolution
  • 21. Miscellaneous Provisions
  • 22. Policy Changes
  • 23. Contact & DPO
  • 24. Acceptance & E-Signature
TL;DR Executive Summary in 60 seconds
🔒 We don't sell data. Ever. Zero. Never.
🌍 Compliant with 12+ global privacy laws.
⛪ Religious data only with your explicit consent.
📍 GPS only if you enable it. No history stored.
🗑️ Full deletion available anytime from Settings.
🛡️ AES-256 encryption at rest, TLS 1.3 in transit.
🤖 No invasive AI. Rule-based algorithm, not ML.
👶 18+ only. Strict age verification enforced.
Certifications & Regulatory Compliance
🇪🇺 GDPR
🇬🇧 UK GDPR
🇺🇸 CCPA/CPRA
🇧🇷 LGPD
🇨🇦 PIPEDA
🇦🇺 Privacy Act
🇯🇵 APPI
🇸🇬 PDPA
🇨🇭 Swiss DPA
🇦🇪 UAE PDPL
🇨🇳 PIPL*
🇮🇳 DPDP 2023
🍎 Apple ATT
🤖 Google Safety

*PIPL: Service not currently available in mainland China. Ready for future compliance.

EXECUTIVE SUMMARY: Agapé is a global faith-based social connection platform. This Privacy Policy comprehensively describes how we collect, use, store, share, and protect your personal information —including special category data about religious beliefs— under the strictest international privacy standards.
⚠️ IMPORTANT NOTICE: By creating an Agapé account, you confirm that: (i) you are at least 18 years of age; (ii) you have read and understood this Policy; (iii) you explicitly consent to the processing of your special category data (religious beliefs) for the purposes described; (iv) you accept international data transfers under the safeguards established herein; and (v) you have read and understand the Arbitration and Class Action Waiver clause in Section 19.

0. Legal Definitions

For the purposes of this Policy, the following terms shall have the meanings indicated:

"Personal Data" Any information relating to an identified or identifiable natural person ('Data Subject').
"Special Category Data" Data revealing religious beliefs, as defined in Article 9 GDPR. Also known as "sensitive data."
"Processing" Any operation on personal data: collection, storage, use, disclosure, or deletion.
"Data Controller" The natural or legal person who determines the purposes and means of processing. In our case: Iván Rojas Manzano.
"Data Processor" Entity that processes data on behalf of the Controller (e.g., Firebase, Google Cloud).
"Sub-Processor" Third party engaged by a Processor to assist in data processing.
"Service" The Agapé mobile application, website meetagape.com, and all related services.
"User" or "You" Any natural person who accesses or uses the Service.
"Consent" Freely given, specific, informed and unambiguous indication of your wishes to accept data processing.
"Adequacy Decision" European Commission determination that a third country provides adequate data protection level.

1. Introduction and Scope

This Privacy Policy applies to your use of the Agapé mobile application ("App"), the website meetagape.com, and any related services (collectively, the "Service"). By accessing or using the Service, you acknowledge that you have read and understood this Policy.

We are committed to protecting your privacy and ensuring that you have full control over your data, regardless of your geographical location.

2. Data Controller

For the purposes of the General Data Protection Regulation (GDPR) of the EU, the UK Data Protection Act, and other applicable laws, the Data Controller of your data is:

  • Owner: Iván Rojas Manzano
  • Postal Address: CL DOCE DE OCTUBRE, 21, 7, 14001, CÓRDOBA, Spain.
  • Data Protection Officer (DPO) Contact: support@meetagape.com

3. Categories of Data We Collect

We collect and process different types of personal data to provide our Service. Below, we detail what we collect:

A. Data Provided Directly by You

Category Specific Data
Identity Data Username (DisplayName), date of birth (for +18 age verification), and gender.
Contact Data Email address and authentication credentials (securely managed via Firebase Auth).
Profile Data (Sensitive) Special Category (Art. 9 GDPR): Congregation, spiritual privileges, and beliefs. You provide this data under your explicit consent so that we can show your profile to like-minded individuals.
User Content Biography, interests, photographs, and messages sent via chat.
👤 Identity Data
Username (DisplayName), date of birth (+18 verification), and gender.
📧 Contact Data
Email address and authentication credentials (managed via Firebase Auth).
⛪ Profile Data (Sensitive)
Special Category Art. 9 GDPR: Congregation, spiritual privileges, and beliefs. Requires your explicit consent.
📝 User Content
Biography, interests, photographs, and chat messages.

B. Data Collected Automatically (Usage and Device)

Category Specific Data
Location Data Precise geolocation (GPS: Latitude/Longitude). Only with your active permission. It is used to calculate relative distance with other users ("10 km away"). We do not store a history of your movements.
Technical Data IP address, device ID, mobile model, operating system, notification token (FCM), and crash logs (Crashlytics).
Usage Data Registration date, last connection, interactions (swipes, likes, blocks), and usage time.
📍 Location Data
GPS geolocation (Lat/Long). Only with your active permission. Used to calculate relative distance. We do not store movement history.
📱 Technical Data
IP, device ID, model, operating system, FCM token, and crash logs (Crashlytics).
📊 Usage Data
Registration date, last connection, interactions (swipes, likes, blocks), and usage time.

C. Data We Do NOT Collect

Privacy by Design Commitments

  • ❌ We do not collect biometric data (fingerprint, facial recognition)
  • ❌ We do not access your phone contact list
  • ❌ We do not track your browsing history outside the App
  • ❌ We do not sell or share data with advertising brokers
  • ❌ We do not use third-party tracking pixels

4. Legal Bases for Processing (GDPR)

We only process your data when we have a valid legal basis under European legislation:

  • Performance of a Contract (Art. 6.1.b): To create your account, provide chat services, display profiles, and process subscriptions.
  • Explicit Consent (Art. 9.2.a): To process your special category data (religion) and your precise geolocation. You have the right to withdraw this consent at any time (by deleting the data or disabling GPS).
  • Legitimate Interest (Art. 6.1.f): To ensure network security, prevent fraud, detect bots, and technically improve the application.
  • Legal Obligation (Art. 6.1.c): To keep records of tax transactions or cooperate with law enforcement if we receive a valid court order.

5. Purposes and Automated Decisions

We use your data to:

  • Service Provision: Create accounts, facilitate matching, and messaging.
  • Security: Verify accounts, moderate content, and combat abusive behavior.
  • Communication: Send you push notifications about new messages or matches (you can disable these in settings).

Information on the Matching Algorithm

Agapé uses automated processes to recommend profiles to you. This algorithm analyzes your preferences (age range, maximum distance, interests, and spiritual data) to show compatible people. This profiling is necessary for the core functionality of the App, but does not produce legal effects nor significantly affect you negatively.

6. Artificial Intelligence & Machine Learning

In compliance with the EU AI Act (Regulation 2024/1689) and best practices for algorithmic transparency, we inform you about our use of automated systems:

A. AI Systems Used

  • Recommendation Algorithm: Rule-based system that ranks profiles by preference compatibility (age, distance, interests). Does not use machine learning or neural networks.
  • Content Moderation: Google Cloud Vision API to detect inappropriate content in photographs (nudity, violence). Classification: limited-risk AI system.
  • Fraud Detection: Firebase App Check to verify application integrity and prevent bots.

B. Your Rights Regarding Automated Decisions (Art. 22 GDPR)

  • Right to Human Intervention: You may request a human operator review any automated decision affecting you.
  • Right to Explanation: You may request information about the logic applied in your profile recommendations.
  • Right to Contest: You may contest an automated decision by contacting support@meetagape.com.

Responsible AI Commitment

  • ✅ We do not use AI to infer sensitive characteristics not provided by you
  • ✅ We do not employ facial recognition for identification
  • ✅ We do not create psychological profiles or hidden "compatibility scores"
  • ✅ Our systems are auditable and explainable

7. Recipients and International Transfers

Your personal data is confidential. We do not sell, rent, or trade your data to third parties under any circumstances. We only share it in the following limited situations:

A. Service Providers (Data Processors)

We use third-party infrastructure selected under strict security and privacy criteria:

  • Google Cloud Platform / Firebase (USA): Database hosting (Firestore), authentication, file storage, crash analytics (Crashlytics), and push notifications (FCM). Google acts as a Data Processor under a Data Processing Agreement (DPA) compliant with Art. 28 GDPR.
  • Google Play / Apple App Store: In-app payment processing. We do not store credit card data or financial information.

B. Transfers Outside the EEA/UK

Since our technology providers are based in the United States, your data may be transferred internationally. We ensure an adequate level of protection through:

  • The EU-US Data Privacy Framework, adequacy decision C(2023) 4745 by the European Commission (July 10, 2023).
  • The UK Extension to the Data Privacy Framework for transfers from the United Kingdom.
  • Standard Contractual Clauses (SCCs) approved by Implementing Decision (EU) 2021/914 for providers without an adequacy decision.
  • UK International Data Transfer Agreement (IDTA) Addendum when required.

C. Mandatory Legal Disclosure

We may disclose your personal data when legally required:

  • In response to a valid court order, subpoena, or legitimate governmental request.
  • To protect user safety against imminent threats of harm.
  • To investigate, prevent, or take action against illegal activities, fraud, or abuse.
  • In proceedings of merger, acquisition, or asset sale (with prior notice).
🔒 Transparency Report: Agapé commits to publishing transparency reports on governmental data requests when legally permitted. To date, we have not received any National Security Letter (NSL) or FISA order.

8. Sub-Processors and Authorized Service Providers

Below is the complete list of third-party providers who process personal data on our behalf:

Provider Function Location Legal Guarantees
Google Firebase Database, Authentication, Cloud Functions 🇺🇸 USA DPF + SCCs + DPA
Google Cloud Storage Photos and files storage 🇺🇸 USA / 🇪🇺 EU DPF + SCCs + DPA
Google Cloud Vision Image moderation (AI) 🇺🇸 USA DPF + SCCs
Firebase Crashlytics Crash reporting 🇺🇸 USA DPF + SCCs
Firebase Cloud Messaging Push notifications 🇺🇸 USA DPF + SCCs
Google Play / Apple Payment processing 🇺🇸 USA Platform policies
Hosting/CDN Website content delivery 🌐 Global SCCs
Email Provider Transactional emails 🇪🇺 EU GDPR native
📈 Simplified Data Flow
📱 Your Device → 🔒 TLS 1.3 → ☁️ Firebase → 🗄️ Firestore (Encrypted) → 👥 Other Users (only public data)

Important: Sub-processors may only use your data to provide us the contracted services and are contractually obligated to maintain equivalent confidentiality and security levels.

9. Retention Periods

We apply the principle of storage limitation. Your data is not kept indefinitely:

✅ Active Account
Data retained while you use the Service. Minimum processing.
⚠️ Deletion Requested
Immediate removal from public view. Profile no longer visible.
🔒 Security Retention (90 days)
Data in restricted backup. Purpose: prevent abuse evidence destruction and re-registration.
🗑️ Permanent Deletion
After 90 days: irreversible cryptographic deletion. Backups overwritten.
💼 Legal Retention (up to 10 years)
Tax transaction records only, if direct payments were processed.

10. Your Global Privacy Rights

Regardless of your nationality, Agapé grants you the following rights over your data:

  • Right of Access: Know what data we have about you and obtain a copy.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data when it is no longer necessary.
  • Right to Object: Object to data processing based on legitimate interest.
  • Right to Portability: Receive your data in a structured and readable format.
  • Withdrawal of Consent: You can withdraw your consent for geolocation or religious data processing at any time.

To exercise these rights, contact us at support@meetagape.com. We will respond within a maximum of 30 days.

If you reside in the European Economic Area, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local authority.

11. Multi-Jurisdictional Compliance

Agapé is designed to comply with the world's strictest privacy laws. Below, we detail your specific rights based on your jurisdiction:

🇪🇺
European Union
GDPR
🇬🇧
United Kingdom
UK GDPR
🇺🇸
California
CCPA/CPRA
🇧🇷
Brazil
LGPD
🇨🇦
Canada
PIPEDA
🇦🇺
Australia
Privacy Act
🇯🇵
Japan
APPI
🇸🇬
Singapore
PDPA
🇨🇭
Switzerland
nDSG
🇮🇳
India
DPDP 2023
🇦🇪
UAE
Federal PDPL

🇺🇸 United States (California, Virginia, Colorado, Connecticut, Utah)

  • Notice at Collection (CCPA §1798.100): In the last 12 months, we have collected the categories of personal information listed in Section 3.
  • No Sale/No Share: Agapé DOES NOT SELL your personal information to third parties nor "share" it for cross-context behavioral advertising as defined by CPRA.
  • Sensitive Data: We use your sensitive data (religion) solely to provide the requested service, not to infer other characteristics.
  • Right to Opt-Out: Not applicable since we do not sell data, but you may request information at any time.
  • Authorized Agent: You may designate an authorized agent to exercise your rights by presenting a valid power of attorney.
  • Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights.

🇧🇷 Brazil (LGPD - Lei 13.709/2018)

  • Legal Basis for Sensitive Data: Explicit consent (Art. 11, I).
  • General Legal Basis: Contract performance (Art. 7, V).
  • Encarregado de Dados: Contact: support@meetagape.com
  • LGPD Rights: Confirmation, access, correction, anonymization, portability, deletion, information about sharing, consent revocation, and petition to ANPD.

🇨🇦 Canada (PIPEDA)

  • You have the right to access your personal information and request corrections.
  • You may withdraw your consent at any time, subject to legal restrictions.
  • You may file complaints with the Office of the Privacy Commissioner of Canada.

🇦🇺 Australia (Privacy Act 1988 + APPs)

  • You have the right to access your personal information and request corrections.
  • You may request anonymity or use of a pseudonym where practicable.
  • You may file complaints with the Office of the Australian Information Commissioner (OAIC).

🇯🇵 Japan (APPI - Act on Protection of Personal Information)

  • Special Care-Required Information: Your religious data qualifies as "special care-required" under APPI and is processed only with consent.
  • Rights: Access, correction, cessation, disclosure of third-party transfers.
  • PPC: You may file complaints with the Personal Information Protection Commission.

🇸🇬 Singapore (PDPA - Personal Data Protection Act)

  • Consent: We collect and use your data based on your consent.
  • Rights: Access, correction, and data portability.
  • PDPC: You may file complaints with the Personal Data Protection Commission.

🇨🇭 Switzerland (nDSG - new Data Protection Act)

  • We apply protections equivalent to GDPR for Swiss residents.
  • Transfers are protected by SCCs or adequacy decisions.
  • You may file complaints with the FDPIC (Federal Data Protection and Information Commissioner).

🇮🇳 India (DPDP Act 2023)

  • Consent: We process your data based on express consent.
  • Rights: Access, correction, erasure, and grievance redressal.
  • Data Fiduciary: Agapé acts as Data Fiduciary for Indian users.

🇦🇪 United Arab Emirates (Federal Decree-Law 45/2021)

  • We apply protections compliant with UAE data protection law.
  • Cross-border transfers are conducted with appropriate safeguards.
  • You may exercise rights of access, rectification, and erasure.

12. Children's Protection

Agapé is intended exclusively for users 18 years of age and older. We take children's protection extremely seriously:

🚫 STRICT POLICY ON MINORS: We do NOT knowingly collect, solicit, or store personal information from anyone under 18 years of age. If we discover that we have collected data from a minor, we will immediately delete it from our systems.
  • Age Verification: We require date of birth during registration to verify legal age.
  • COPPA (USA): We comply with the Children's Online Privacy Protection Act. We do not collect data from children under 13 under any circumstances.
  • UK Age Appropriate Design Code: Our service is not directed at children and we do not implement features that would attract them.
  • Report Minors: If you suspect a minor is using the application, please report immediately to support@meetagape.com.

13. Security Measures

We implement a comprehensive security program based on industry standards:

A. Technical Measures

  • Encryption in Transit: TLS 1.2/1.3 for all communications.
  • Encryption at Rest: AES-256-GCM on Google Cloud servers.
  • Password Hashing: Secure algorithms managed by Firebase Auth (scrypt).
  • App Check: Application integrity verification to prevent attacks.
  • Firestore Security Rules: Granular document-level access control.

B. Organizational Measures

  • Principle of Least Privilege: Access restricted only to necessary personnel.
  • Logging and Auditing: Recording of access to sensitive data.
  • Incident Policy: Security breach response procedure compliant with Art. 33-34 GDPR (72-hour notification).
⚠️ DISCLAIMER: While we implement industry-leading security measures, no system is 100% secure. We recommend: using unique and strong passwords, not sharing credentials, and reporting suspicious activity immediately.

14. Cookies and Tracking Technologies

Our native mobile application does not use cookies in the traditional sense. However, we employ similar technologies:

  • Firebase Analytics: SDK that collects anonymous usage data to improve the application. You can disable it in Settings → Privacy.
  • Crashlytics: Collects error reports to improve stability.
  • FCM Tokens: Identifiers for delivering push notifications.
  • Local Storage: We store preferences locally on your device.

Our website may use essential cookies for basic functionality. We do not use third-party cookies for advertising.

15. Apple & Google App Store Requirements

In compliance with app store policies:

🍎 Apple App Store (iOS)

  • App Tracking Transparency (ATT): Agapé does NOT request ATT tracking permission because we do not track users across third-party apps or websites. We do not use the IDFA.
  • Privacy Nutrition Label: Our App Store privacy label accurately reflects the data collected per Section 3 of this Policy.
  • Sign in with Apple: If you use this option, we respect your choice to hide your real email. We only receive Apple's relay email.
  • Account Deletion: You can delete your account directly from Settings → Account → Delete Account, per Apple requirements.
  • HealthKit/HomeKit/SiriKit: We do not use these APIs or access health or home data.

🤖 Google Play Store (Android)

  • Data Safety Section: Our data safety declaration in Play Console accurately reflects the practices described in this Policy.
  • Permissions: We only request essential permissions (camera, gallery, location, notifications) and clearly explain their use.
  • Families Policy: Not applicable. Our app is exclusively for users 18 years and older.
  • Account Deletion: Available in-app and via web at meetagape.com/delete-account.html
  • Advertising ID: We do not use Google's Advertising ID for advertising purposes.

App Store Declarations

  • ✅ Data is NOT shared with third parties for advertising
  • ✅ Data is NOT sold to data brokers
  • ✅ User CAN request data deletion
  • ✅ Sensitive data is treated ONLY with explicit consent
  • ✅ App complies with both platforms' developer policies

16. User Representations and Warranties

By using the Service, you represent, warrant, and declare that:

🎂 You are at least 18 years of age and have full legal capacity to accept these terms.
✅ All information you provide is truthful, accurate, and up-to-date.
👤 Only you will use your account. You will not share credentials with third parties.
📸 Photographs you upload are yours or you have rights to use them.
🚫 You will not impersonate another person or create fake profiles.
⚖️ You have no legal prohibition from using the Service in your jurisdiction.
📜 You have read and accept this Policy and Terms of Service in their entirety.
⛪ You expressly consent to the processing of your religious data for the Service's operation.

Breach of these representations may result in suspension or termination of your account without prior notice or refund.

17. Limitation of Liability

LEGAL DISCLAIMER: Please read this section carefully. It contains important limitations on our liability.

To the maximum extent permitted by applicable law:

  • No Warranties: The Service is provided "AS IS" and "AS AVAILABLE," without warranties of any kind, express or implied.
  • Third-Party Content: We are not responsible for content posted by other users, including inaccurate, offensive, or fraudulent information.
  • User Interactions: We are not responsible for interactions, meetings, or relationships arising from use of the application.
  • Indirect Damages: In no event shall we be liable for indirect, incidental, special, consequential, or punitive damages.
  • Monetary Cap: Our total cumulative liability shall not exceed the amount you have paid for the Service in the last 12 months, or €100, whichever is greater.

Some jurisdictions do not allow the exclusion of certain warranties or limitations of liability. In such cases, the limitations shall apply to the maximum extent permitted.

18. Indemnification

You agree to defend, indemnify, and hold harmless Agapé, its owner, employees, contractors, and agents from any claim, damage, obligation, loss, liability, cost, or debt, and expenses (including reasonable attorney fees) arising from:

  • Your use of or access to the Service;
  • Your breach of this Privacy Policy or Terms of Service;
  • Your violation of any third-party rights, including privacy, intellectual property, or publicity rights;
  • Any content you upload or transmit through the Service;
  • Your interactions with other users of the Service, online or offline.

This indemnification obligation shall survive the termination of your account and this Policy.

19. Binding Arbitration and Class Action Waiver

⚠️ READ THIS SECTION CAREFULLY — IT AFFECTS YOUR LEGAL RIGHTS

This section contains a binding arbitration agreement and a class action waiver. By accepting this Policy, you agree to resolve disputes through individual arbitration rather than jury trials or class actions.

A. Arbitration Agreement

You and Agapé agree that any dispute, claim, or controversy arising out of or relating to this Policy or the Service ("Disputes") shall be resolved exclusively through binding arbitration, rather than in courts of general jurisdiction, except that you may bring claims in small claims court if your claims qualify.

B. Class Action Waiver

You and Agapé agree that each party may only bring claims against the other in an INDIVIDUAL capacity, and not as a plaintiff or class member in any class or representative proceeding.

Unless both parties agree otherwise in writing, the arbitrator may not consolidate claims of more than one person and may not preside over any form of class or representative proceeding.

C. Arbitration Administration

  • For EU/EEA/UK users: Arbitration shall be administered pursuant to the Arbitration Rules of the Court of Arbitration of the Madrid Chamber of Commerce, or alternatively the ICC.
  • For US users: Arbitration shall be administered by JAMS pursuant to its Streamlined Arbitration Rules and Procedures.
  • Seat: Madrid, Spain (for EU users) or the most convenient location for the user (US).
  • Language: Spanish or English, at the claimant's choice.

D. Right to Opt-Out

📧 YOU HAVE THE RIGHT TO OPT OUT OF THIS ARBITRATION AGREEMENT.

You may opt out of this arbitration clause by sending us written notice at support@meetagape.com with the subject line "ARBITRATION OPT-OUT" within 30 days of your first use of the Service. Your notice must include your name, account email address, and a clear statement that you wish to opt out of this arbitration agreement.

E. Exceptions

This arbitration clause does not apply to:

  • Intellectual property claims;
  • Requests for urgent injunctive relief;
  • Small claims court proceedings;
  • Any claim where the mandatory law of the user's country of residence prohibits mandatory arbitration.

F. Survival

This arbitration agreement shall survive termination of your relationship with Agapé.

20. Dispute Resolution and Governing Law

A. Governing Law

This Policy shall be governed by and construed in accordance with the laws of Spain, without giving effect to any principles of conflicts of laws, except to the extent that the mandatory laws of your jurisdiction of residence provide otherwise.

B. Subsidiary Jurisdiction

To the extent binding arbitration is not applicable (by user opt-out or legal provision), the parties submit to the exclusive jurisdiction of the Courts of Córdoba, Spain, expressly waiving any other venue that may correspond to them, except:

  • EU/EEA users may bring claims in the courts of their country of residence;
  • Consumers protected by mandatory laws of their jurisdiction retain their legal rights.

C. Statute of Limitations

Any claim arising out of or relating to this Policy or the Service must be brought within ONE (1) year from when the cause of action arose, or it shall be permanently barred, to the maximum extent permitted by applicable law.

D. Informal Resolution First

Before initiating any formal proceeding, the parties agree to attempt to resolve the dispute amicably for a period of 60 days from written notice of the dispute, by contacting support@meetagape.com.

E. Alternative Dispute Resolution (ODR)

The European Commission offers an online dispute resolution platform available at: https://ec.europa.eu/consumers/odr

21. Miscellaneous Provisions

A. Severability

If any provision of this Policy is held invalid, illegal, or unenforceable by a court or competent authority, such invalidity shall not affect the remaining provisions, which shall remain in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable.

B. Survival

Sections of this Policy that by their nature should survive termination shall continue in effect, including without limitation: Definitions, Data Retention, Your Rights, Limitation of Liability, Indemnification, Arbitration, Dispute Resolution, and this Miscellaneous Provisions section.

C. Waiver

The failure to exercise or delay in exercising any right under this Policy shall not constitute a waiver of such right. No waiver shall be effective unless in writing and signed by the waiving party. A one-time waiver does not constitute a continuing waiver or a waiver of other rights.

D. Entire Agreement

This Privacy Policy, together with the Terms of Service, Legal Notice, and EULA (if applicable), constitute the entire agreement between you and Agapé regarding the processing of your personal data and use of the Service, and supersede any prior agreement, communication, or representation, oral or written.

E. Assignment

You may not assign or transfer your rights or obligations under this Policy without our prior written consent. Agapé may assign its rights and obligations to any successor, acquirer, or entity resulting from merger, acquisition, or reorganization, upon notice per Section 22.

F. Force Majeure

Agapé shall not be liable for any failure caused by circumstances beyond its reasonable control, including without limitation: natural disasters, pandemics, acts of government, war, terrorism, civil unrest, power outages, telecommunications failures, cyberattacks, or third-party service interruptions.

G. Prevailing Language

This Policy is available in Spanish and English. In case of discrepancy between versions, the Spanish version shall prevail as it is the jurisdiction of the data controller, except where local law of the user requires their language to prevail.

H. Headings

Section headings are for convenience only and do not affect the interpretation of this Policy.

I. No Third-Party Beneficiaries

This Policy does not confer rights upon third parties, except as expressly stated regarding Sub-processors and their contractual obligations.

22. Changes to this Policy

We may update this Privacy Policy periodically. We will notify you of material changes through:

  • In-App Notification: We will display a prominent notice when you open the application.
  • Email: For changes that significantly affect your rights.
  • Update Date: The "Last Updated" date at the beginning of this document will always reflect the current version.

We recommend reviewing this Policy periodically. Continued use of the Service after the publication of changes constitutes your acceptance of them.

Version History

  • v3.0 (Jan 19, 2026): Masterpiece Edition - Complete legal shield: Arbitration, Class Action Waiver, Indemnification, App Store compliance, 11 jurisdictions, legal definitions.
  • v2.0 (Jan 15, 2026): Added AI, multi-jurisdiction, cookies, limitation of liability sections.
  • v1.2 (Dec 24, 2025): Updated for CCPA/CPRA and UK GDPR compliance.
  • v1.0 (Oct 01, 2025): Initial version.

23. Contact and Data Protection Officer

For any inquiries related to this Privacy Policy or the exercise of your rights:

Official Contact Information

  • Data Controller: Iván Rojas Manzano
  • Primary Email: support@meetagape.com
  • Legal Matters: legal@meetagape.com
  • Postal Address: CL DOCE DE OCTUBRE, 21, 7, 14001, CÓRDOBA, Spain
  • Response Time: Maximum 30 days (per GDPR Art. 12.3)

For GDPR Rights Exercise

Include in your request:

  • Your full name and email address associated with the account
  • The specific right you wish to exercise (access, rectification, erasure, portability, objection, restriction)
  • Copy of identity document (for verification)
  • Any additional relevant information

Complaints to Authorities

If you believe the processing of your data violates regulations, you may file a complaint with:

  • Spain: Spanish Data Protection Agency (AEPD)
  • Your country: The data protection authority of your jurisdiction of residence

24. Acceptance and Electronic Signature

By creating an Agapé account, checking the acceptance box during registration, or continuing to use the Service after the publication of changes to this Policy, you declare that:

  • ✅ You have read and understood this Privacy Policy in its entirety;
  • ✅ You accept all its terms and conditions without reservation;
  • ✅ You acknowledge that this electronic acceptance has the same legal validity as a handwritten signature;
  • ✅ You confirm that you comply with all Representations in Section 16;
  • ✅ You expressly consent to the processing of sensitive data (religious) for the Service's operation.

Your acceptance is recorded with a timestamp in our systems as evidence of consent.

© 2026 Iván Rojas Manzano / Agapé App. All rights reserved.

Document ID: PP-EN-v3.0-20260119 | International Legal Shield

This document has been drafted in accordance with the strictest legal standards of Silicon Valley, the European Union, and international jurisdictions. Complies with: GDPR, UK GDPR, CCPA/CPRA, LGPD, PIPEDA, Privacy Act 1988 (AU), APPI (JP), PDPA (SG), nDSG (CH), DPDP 2023 (IN), UAE PDPL, Apple App Store Guidelines, Google Play Developer Program Policies.