We write policies like human beings. Pick a document below — all of them are worth reading.
These guidelines explain how law enforcement and other authorities can request information from Ontryst, what data we hold, and how we respond. We require valid legal process, and we cooperate with lawful requests while protecting our members' rights.
Ontryst is operated by Nevolut S.A.R.L.U. (head office, Democratic Republic of Congo) together with its European Union branch Nevolut S.R.L. (Romania). Legal process should be directed to the entity that operates the service in the relevant territory:
The Ontryst service is governed by the laws of the Democratic Republic of Congo. Where our EU branch processes personal data, we also act in accordance with the EU General Data Protection Regulation (GDPR) and applicable Romanian law.
Law enforcement and government agencies should submit requests in writing, on official letterhead, from an official government email domain, to support@ontryst.com. To help us locate the correct records and respond quickly, every request should include:
Overly broad or vague requests may be narrowed or returned for clarification. We may decline requests that are not supported by valid legal process.
We disclose member information only where we are legally required to do so, or where a valid and properly scoped legal request compels disclosure. The level of legal process required depends on the sensitivity of the data (see section 04).
Requests from outside the Democratic Republic of Congo may need to be submitted through a Mutual Legal Assistance Treaty (MLAT), a letter rogatory, or another recognised channel of international cooperation, unless an applicable law or emergency provision allows a direct request. Requests concerning personal data of individuals in the European Union are handled in accordance with the GDPR.
The information available depends on how the member has used Ontryst. Broadly, we may hold the following, in ascending order of sensitivity:
Two important limits: passwords are stored only as a secure one-way hash and cannot be produced in readable form; and we do not store full payment-card numbers — we hold only confirmation of purchase and subscription status, as card data is held by our regulated payment processors.
Where we believe in good faith that an emergency involving an imminent risk of death or serious physical harm to a person requires disclosure without delay, we may disclose information necessary to prevent that harm. Emergency requests should be clearly marked "EMERGENCY DISCLOSURE REQUEST" in the subject line and sent to support@ontryst.com, and must describe the nature of the emergency, the person at risk, and the specific information needed to address it.
If a person is in immediate danger, contact your local emergency services first.
On receipt of a valid preservation request from law enforcement, we will take reasonable steps to preserve the specified records that exist at the time of the request for a period of 90 days, extendable once on renewed request, pending service of formal legal process. A preservation request does not by itself require us to disclose any information.
We keep personal data only for as long as needed to provide the service and to meet our legal obligations. When a member deletes their account, we delete or anonymise their personal data within thirty (30) days, except where we must retain certain information for longer to comply with legal, tax, or accounting obligations. Some records are short-lived by design — for example, verification codes are kept for only a few minutes and profile-view records for around 30 days.
Because relevant data may be deleted in the ordinary course, authorities are encouraged to submit a preservation request (section 06) promptly where records may be needed.
Ontryst has zero tolerance for child sexual abuse and exploitation (CSAE). We report apparent child sexual abuse material (CSAM) to the U.S. National Center for Missing & Exploited Children (NCMEC) CyberTipline and to local law enforcement in the relevant jurisdiction, and we cooperate fully with lawful requests from law enforcement and child-protection agencies. Reports, escalations, and cooperation requests relating to a minor should be sent to our designated child-safety contact at child-safety@ontryst.com. Full details are set out in our Child Safety Standards.
We verify the authenticity of every request and the identity of the requesting authority before responding, and we may seek clarification where a request is unclear or overly broad. Where permitted by law, we may seek reimbursement of the reasonable costs of responding to a request. We may object to, narrow, or challenge requests that are legally deficient, overbroad, or inconsistent with applicable law or our members' rights.
Our policy is to notify members of requests for their information before disclosure, so that they may seek to protect their rights, unless we are legally prohibited from doing so (for example by a court order or non-disclosure provision), or unless doing so would be counterproductive in an emergency, a child-safety matter, or a case involving a credible risk to a person or to the integrity of an investigation.
Where we disclose records in response to valid legal process, we provide them in a reasonable electronic format together with a certificate of authenticity where required. We aim to acknowledge properly submitted requests promptly and to respond within the timeframe stated in the request or otherwise required by law.
All legal requests, preservation requests, and emergency disclosure requests should be sent to support@ontryst.com. Child-safety matters should be sent to child-safety@ontryst.com, and data-protection enquiries to privacy@ontryst.com.
These guidelines should be read together with our Privacy Policy and Terms of Service. They do not constitute a waiver of any objection, nor consent to any jurisdiction or legal process not otherwise applicable. Nevolut S.A.R.L.U. reviews these guidelines periodically and updates them as the service evolves or as legal requirements change; the effective date at the top of this page reflects the most recent update.