Age Verification Policy

Estimated reading time: 7 minutes

Age Verification Policy

Samantha Dee trading as Circles.London and SwingCircles.com
Version: 1.0
Last updated: 9th August 2026
Effective from: 9thh August 2026

This large document is set out in this format for readability. click the + next to each section to read it:

Circles and SwingCircles.com are intended for people aged 18 or over. Membership and access to adult community features are not available to anyone under 18.

We do not treat a date of birth entered into a form, or a person’s appearance, as sufficient assurance for access to the private adult community where a stronger check is required.

Age verification helps us:

  • restrict access to an adult-only service;
  • reduce the risk of children encountering adult profiles, communications or content;
  • meet applicable legal and online-safety responsibilities;
  • protect members and the wider service from underage access; and
  • investigate suspected misuse of the service.

Where the service permits adult user-generated content or adult interactions, the age-assurance process must be sufficiently effective for the risks presented by the service. The exact method may change as the service, legal requirements and available technology develop.

Age verification is an access control. It is not a guarantee that a person is honest, safe, suitable or who they claim to be.

An age or identity check may be required:

  • before a person can complete registration or obtain private-community access;
  • before a person can view or use particular adult features;
  • when an existing check has expired or can no longer be relied upon;
  • when account information creates a reasonable concern about age, identity or misuse;
  • after a material change to the service or its legal requirements; or
  • as part of a proportionate safety, fraud-prevention or account-recovery process.

Circles may pause, restrict or withdraw access while a check is incomplete, failed, disputed or being reviewed

The final verification provider and method will be recorded before launch. Depending on the supplier and risk assessment, the process may use one or more of the following:

  • an age or identity document check;
  • a tokenised or third-party age-check result;
  • a selfie or facial comparison performed by the specialist provider;
  • another appropriately assessed age-assurance method; or
  • a limited manual review where an automated check is inconclusive.

We will use the least intrusive method that provides an appropriate level of confidence for the risk. A layered or “waterfall” process may be used where starting with a less intrusive check and escalating only when necessary reduces the amount of information collected.

The provider may ask you for information that Circles does not itself need to receive. Wherever reasonably possible, the provider will return only a limited result, such as verified over 18, not verified, expired, or review required.

Circles may receive and retain only what is reasonably necessary for access control, account security, auditability and legal or safety purposes. This may include:

  • verification status;
  • the date and method of the check;
  • a provider reference or transaction identifier;
  • limited attributes needed to confirm the result;
  • expiry or re-check information, where applicable; and
  • a record of a failed, disputed, appealed or manually reviewed check.

The verification provider may process identity documents, facial images, biometric information or other sensitive information while carrying out the check. Circles will not routinely store complete identity documents, facial images or biometric templates unless there is a clearly documented necessity, lawful basis and appropriate safeguard.

Verification information is separate from public profile content. It should not be displayed to other members, included in search results or used to imply that a member has been checked for character, health, criminal history or sexual safety.

The lawful basis for verification will depend on the particular processing activity and the service requirements. It may include steps requested before entering a membership contract, performance of a contract, legitimate interests, legal obligation or another lawful basis identified in the Privacy Policy and Data Protection Impact Assessment.

Some verification processes may involve special category data, biometric data or information that is otherwise highly sensitive. Where required, Circles will identify and document an additional condition for processing and apply stricter access, security and retention controls.

We will not use verification information to build advertising profiles, infer sexual interests, rank members by desirability or make unrelated decisions about a person.

We intend to use a specialist provider with appropriate technical, organisational and data-protection safeguards. Before using a provider, we will assess:

  • whether the provider can provide the level of assurance required;
  • its role as controller or processor for each part of the process;
  • its privacy information, deletion controls and retention periods;
  • security, breach-notification and subprocessor arrangements;
  • accessibility and reasonable alternatives for people who cannot complete the standard process;
  • international transfers and the safeguards used for them; and
  • relevant independent assurance, certification or audit information.

The provider will not be treated as a reason to collect or retain more information than Circles needs.

A failed or inconclusive check does not automatically mean that a person has acted dishonestly. It may result from poor image quality, an expired document, accessibility barriers, technical problems or a mismatch in the information provided.

Depending on the circumstances, we may offer a retry, an alternative method or a restricted manual review. We may ask for limited additional information only where it is necessary to resolve the issue.

If we cannot obtain sufficient assurance, we may refuse, pause or withdraw access. We may also restrict an account where there is evidence of attempted underage access, identity misuse, fraud or serious breach of our rules.

Appeals about access or account action are handled under the Complaints & Appeals Policy. A data-protection concern can also be raised under the GDPR and Data Protection Policy.

If someone appears to be under 18, or tells us they are under 18, we will restrict access while the matter is assessed. We may delete information that should not have been collected, subject to any necessary legal, safety or incident record.

Do not send us a child’s identity document or intimate material through ordinary support channels. Report the concern through Report a Violation or [SAFETY CONTACT] and provide only the information needed to identify the account and explain the concern.

We will not ask members to investigate or confront a suspected underage user themselves.

  • complete identity documents, facial images and biometric templates: not routinely stored by Circles; provider retention applies where the provider processes them;
  • verification result and limited audit record: while the account is active and normally for up to 24 months after account closure, subject to the Internal Data Retention Schedule;
  • failed, disputed or appealed verification record: for the period needed to resolve it and normally for up to 24 months afterwards;
  • suspected underage-access or fraud records: under the relevant safety, moderation or incident-retention rule; and
  • information subject to a legal hold: until the hold ends, with regular review.

The final period will be checked against the selected provider’s terms, the completed DPIA and the operational need before launch. Information will then be deleted or anonymised securely.

or incident handling. We aim to use:

  • separate storage or logical separation from profile content;
  • role-based access controls;
  • encryption in transit and at rest where available;
  • audit logging for administrative access;
  • supplier due diligence and contractual controls;
  • secure deletion and retention enforcement; and
  • incident response procedures for suspected unauthorised access.

No online verification process is completely risk-free. We will review the process as the service develops and after significant incidents, supplier changes or legal changes.

Depending on the circumstances, you may have rights to access, correct, erase or restrict the use of your personal information, object to certain processing, withdraw consent where consent is the lawful basis, and complain about how your information has been handled.

Contact support@circlestech.atlassian.net. We may need to verify your identity before responding to a request because verification information is sensitive.

More information is available in the Privacy Policy and GDPR and Data Protection Policy.

We may update this policy when our verification provider, technology, service features or legal obligations change. We will publish the current version and show its revision date. If a change materially affects how we use personal information, we will provide additional notice where required

This policy has been prepared with reference to current guidance from the Information Commissioner’s Office on age assurance, privacy by design, special category data and storage limitation, and Ofcom guidance for dating and social-discovery services. It should be reviewed by a suitably qualified adviser once the final provider and implementation are known.

Skip to toolbar