Privacy Policy

Version 1 · Last updated: 17 July 2026

Courtesy translation. This English version is provided for convenience only. The Portuguese original, available at vimperio.org/privacidade, is the legally binding text and prevails in the event of any discrepancy.

This Privacy Policy explains how VIMPERIO LIMITED processes your personal data when you use V Império, whether through the iOS and Android application or through the website vimperio.org. It has been drawn up in compliance with Articles 13 and 14 of the European Union General Data Protection Regulation (GDPR).

We ask that you read it carefully. This policy should be read together with our Terms and Conditions and with the Legal Notice.

1. Controller

The controller of your personal data is:

VIMPERIO LIMITED has not appointed a Data Protection Officer (DPO). The single point of contact for any matter relating to data protection, including the exercise of your rights, is the address [email protected].

2. Scope and definitions

This policy applies to the processing of personal data of Candidates ("Candidatos"), Members ("Membros") and visitors in connection with the use of the V Império application and website.

For clarity, we use the following terms:

3. What data we process

We process the following categories of personal data.

3.1. Identification and contact data

3.2. Application data

3.3. Identity verification (KYC) data

Where you choose identity verification as an alternative to the video, data relating to your identification document and biometric data are processed through our processor Didit. The fields processed include your date of birth, obtained only when you complete this verification. Those who choose the introduction video do not provide these data. These data are described in detail in section 5.

3.4. Profile and networking data

3.5. Transactional and payment data

3.6. User Content

Forum posts, chat messages, reviews, comments and votes on Applications, as well as private notes.

3.7. Technical and usage data

3.8. Support communications

The content of the messages you send us when requesting support, as well as our replies.

3.9. Whether the provision of data is mandatory or optional

The provision of certain data is necessary in order to join and use the service. Verification of your mobile number by SMS is necessary to create an account. The biography and one identification route, either the introduction video or identity verification (KYC), are necessary to complete the Application. Without these data, the Application and the use of the service cannot proceed. The processing of biometric data through KYC verification is optional, since the alternative route of the introduction video is always available to you.

4. Purposes and legal bases

We only process your data where there is a legal basis for doing so. We rely on four, depending on the purpose:

Where the basis is legitimate interest, we always weigh that interest against your rights and freedoms. You may object to this processing, as described in section 10.

5. Identity verification (KYC) and biometric data

Admission to V Império always requires a biography. As the identification route, you may choose between submitting an introduction video or completing an identity verification (KYC). Identity verification is therefore an alternative. You are not required to submit biometric data in order to apply.

Where you choose identity verification, it is carried out by our processor Didit (didit.me). In this process:

The legal basis for this biometric processing is your explicit consent (Art. 6(1)(a) GDPR, in conjunction with Art. 9(2)(a) GDPR), which is requested in the application before the process begins. You may withdraw your consent at any time, without affecting the lawfulness of the processing carried out before its withdrawal. If you do not wish to give this consent, the alternative route of the introduction video is available to you.

It is important to distinguish what remains with each entity:

6. Processors and recipients

We use a limited number of third parties that process data on our behalf, under contracts imposing confidentiality and security obligations. We do not sell your personal data.

By category, those processors are: identity verification and biometric processing (Didit); processing of card payments and pre-authorisations in Auctions (Revolut); sending of verification SMS messages (Twilio); application distribution and push notifications (Apple, through the App Store and APNs; Google, through Google Play and Firebase Cloud Messaging); and infrastructure hosting in data centres in Germany.

We may also disclose data to competent public authorities where required by law, or to professional advisers in the course of managing our business.

7. International transfers

We seek to keep the processing of your data within the European Economic Area (EEA). Hosting takes place in Germany, through Hetzner, and payment processing by Revolut takes place within the EEA.

Some of our processors, namely Twilio, Apple and Google, may process data outside the EEA. In those cases, transfers are carried out under appropriate safeguards provided for in the GDPR, such as the Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions.

As regards identity verification by Didit, the exact location of the processing is subject to confirmation. Should it involve a transfer outside the EEA, it is carried out under the appropriate safeguards referred to above.

You may request further information about these safeguards via [email protected].

8. Retention periods

We retain your data only for as long as necessary for the purposes for which they were collected, or for the period required by law.

Category of data Retention period
Account and profile (name, city, avatar, User Content). For as long as the account remains active. Erased or anonymised within 90 days of account closure.
Identity verification result (verdict and minimum KYC fields). Duration of membership, plus 12 months after closure, after which it is erased. The document images and the selfie remain with Didit, in accordance with Didit's retention policy; VIMPERIO LIMITED does not store them.
Financial records and invoices. 6 years, under the duty of retention for tax purposes.
Support messages. 24 months.
Server and security records (logs). 90 days.

9. Cookies and similar technologies

The website vimperio.org does not use cookies or any tracking or analytics technologies. We do not collect browsing data on the website, nor do we use third-party analytics services. For that reason, the website does not display a cookie consent banner, as none is required.

The application uses only technical storage essential to its operation, such as the authentication token that keeps you signed in. This storage is strictly necessary to provide the service you have requested and is not used to track you.

10. Your rights

Under the GDPR, you have the following rights:

How to exercise your rights: simply contact us at [email protected]. We may need to confirm your identity before acting on your request.

Response time: we respond within one month of receiving your request. This period may be extended by a further two months where the complexity or number of requests so justifies, in which case we will inform you.

Limits to erasure: the right to erasure is not absolute. Some data must be retained to comply with legal obligations. For example, financial records and invoices are retained for 6 years, even after account closure. In such cases, we restrict processing to the minimum necessary and, wherever possible, anonymise the data we no longer need to associate with you.

11. Right to lodge a complaint

If you consider that the processing of your data infringes the law, you have the right to lodge a complaint with a supervisory authority.

The competent authority for VIMPERIO LIMITED is the Cyprus Commissioner for Personal Data Protection (Office of the Commissioner for Personal Data Protection).

You may also lodge a complaint with the supervisory authority of the country of your habitual residence.

12. Data security

We adopt appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or improper disclosure. These measures include minimising the data we store and delegating sensitive operations, such as payment processing and identity verification, to specialised processors.

We remind you, in particular, that we do not store full payment card numbers, nor the identification document images and the selfie used in identity verification.

No system is entirely impenetrable. In the event of a personal data breach likely to result in a high risk to your rights, we will comply with the notification duties provided for in the GDPR.

13. Minors

V Império is a service intended for persons aged 18 or over. We do not knowingly collect data from persons under 18. If we become aware that we have collected data from a minor without an adequate basis, we will erase them. If you believe this has happened, contact us at [email protected].

14. Automated decision-making

Identity verification (KYC) includes automated verification components, performed by Didit, which produce a verdict. The logic of this verification rests on the automated analysis of the identification document, a liveness check and a face match, the combination of which produces the verdict. The consequence of that verdict is the approval or refusal of the KYC identification route. If it is refused, the alternative route of the introduction video remains available.

That verdict is not applied in an entirely automated manner: there is a reconciliation and review process on the side of VIMPERIO LIMITED. You have the right to request human intervention, to express your point of view and to contest the outcome of any verification. To do so, contact us at [email protected].

15. Changes to this policy

We may update this Privacy Policy whenever necessary, for example as a result of legal changes or new features. The version in force is always available at vimperio.org. Where changes are significant, we will seek to inform you through the application or by other appropriate means. The date of the last update appears at the top of this document.

16. Contact

For any question about this policy or about the processing of your data, contact: