SamaChatSamaChat

GDPR Statement

Last updated: 23 July 2026

SamaChat is engineered around data minimisation. Message content is end-to-end encrypted on your device using NaCl (Curve25519 + XSalsa20-Poly1305) before it ever reaches our servers, so the personal data we can actually access is limited to account, delivery-routing and billing metadata. This statement summarises how we honour your rights under UK GDPR, EU GDPR and the Data Protection Act 2018.

Controller & Data Protection contact

SamaChat. Contact: hello@samachat.co.uk.

Lawful bases we rely on

  • Contract — providing the messaging, calling and membership service you subscribe to.
  • Legal obligation — age verification (18+), safeguarding duties under the UK Online Safety Act 2023, and tax record-keeping.
  • Legitimate interests — security, fraud prevention and abuse response, balanced against your rights.
  • Consent — for optional processing such as marketing notifications.

Your rights

  • Access (Art. 15) — obtain a copy of the personal data we hold about you. We cannot provide plaintext of your messages because we don't have it.
  • Rectification (Art. 16) — correct inaccurate account data. Most fields are self-service in Settings.
  • Erasure (Art. 17) — delete your account and every record linked to it (profile, keys, membership, reports, blocks, messages you sent).
  • Restriction (Art. 18) — pause processing while a query is investigated.
  • Portability (Art. 20) — receive your account and metadata in a structured JSON format.
  • Object (Art. 21) — object to processing based on legitimate interests.
  • No automated decision-making — we do not carry out solely automated decisions with legal or similarly significant effects (Art. 22).

How to exercise a right

Email hello@samachat.co.uk from the address associated with your SamaChat account. We may request additional verification and will respond within one month (Art. 12(3)).

Data subject to erasure

A deletion request wipes: your profile, SAMA ID, published public keys, device keys, friendships, friend requests, conversation membership, messages you sent, reports/blocks you made, subscription record and authentication account. It is immediate and irreversible. Billing records required under UK tax law are retained for the statutory 7-year period in an isolated ledger.

International transfers

We use UK/EU-hosted infrastructure by default. Onward transfers to sub-processors outside the UK/EEA (see the Privacy Policy) are governed by the UK IDTA or EU SCCs.

Data breach notification

We notify the ICO within 72 hours of becoming aware of a personal data breach likely to result in risk to your rights and freedoms, and notify you directly where required by Art. 34.

Complaints

You have the right to complain to the UK Information Commissioner's Office (ICO) at any time — ico.org.uk/make-a-complaint.