1. Controller
ARVN. Email: [email protected].
2. Website access and hosting
When you access ARVN, the hosting infrastructure necessarily processes technical connection data such as IP address, date and time, requested URL, referrer, browser, operating system and response status. We process this data to deliver the service, maintain security, diagnose errors and prevent abuse (Art. 6(1)(f) GDPR). Security logs are retained only as long as required for these purposes, unless an incident or legal obligation requires longer retention.
A production hosting provider disclosure has not yet passed the internal verification gate. Production processing remains blocked; no provider identity or location is asserted here.
3. Accounts, authentication and support
To register and manage an account we process email address, username, password hash, verification and password-reset data, account roles, security events and a seven-day authentication session. Passwords are not stored in plain text. The legal basis is performance of the contract and pre-contractual steps (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR) and our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
If you contact us or use a configured support workspace, we process your contact details, request, messages, ticket metadata and any content you submit to answer and document the request. The legal basis is Art. 6(1)(b) GDPR or, for other enquiries, Art. 6(1)(f) GDPR.
4. Discord integration and community features
When you connect Discord, we process your Discord user ID, username, avatar, OAuth access and refresh tokens, token expiry data and information about servers you administer. These Discord credentials are protected by authenticated database-level encryption (AES-256-GCM), like the TikTok integration; access is additionally restricted at the technical level through database and application permissions. Depending on enabled modules, ARVN also processes server, channel, role, member and message-related data, moderation signals, incidents, tickets, onboarding events, XP/activity events and configuration data to provide the features selected by the server administrator.
The legal basis for account and bot functionality is Art. 6(1)(b) GDPR. Security and abuse prevention rely on Art. 6(1)(f) GDPR. A server administrator is responsible for informing community members about its use of ARVN and for establishing any additional legal basis required for its configuration.
The Discord provider entry is not rendered until its legal entity, role, transfers, DPA and retention have been verified.
5. Billing and payments
For subscriptions and purchases we process customer and account identifiers, selected plan, server assignment, price, billing interval, subscription status, payment/provider identifiers and transaction timestamps. Stripe processes checkout and payment details; ARVN does not receive full card or bank credentials. The legal bases are Art. 6(1)(b) GDPR and statutory retention duties under Art. 6(1)(c) GDPR.
Stripe remains TEST-only and its public provider entry is withheld until the internal registry is complete and verified. PayPal is disabled and is not presented as active.
6. Creator integrations
Creator Nexus supports Twitch, YouTube, TikTok and Instagram. Depending on the feature you enable, we process creator identifiers, account or channel names, profile links and images, public profile information and statistics, public video, upload or stream metadata, notification settings and delivery history. Processing is necessary to provide the requested integration (Art. 6(1)(b) GDPR).
For Twitch and YouTube, ARVN stores the creator or channel identifiers you provide and retrieves the public creator, stream or upload information needed for notifications. Instagram is currently handled through profile links entered by the user; ARVN does not currently connect to an Instagram account through Meta OAuth. For TikTok connections, we store encrypted OAuth access and refresh tokens, granted scopes and expiry information. TikTok permissions currently cover basic profile information, profile details and statistics, and the public video list.
No TikTok legal-entity or international-transfer assertion is published until its registry evidence is verified. Other creator providers require equivalent registry entries before production enablement.
You can disconnect an integration in the relevant module. This revokes or removes stored credentials where supported; records required for security, accounting or proof of delivery may remain for the applicable retention period.
X is not currently connected as an active provider. This policy will be updated before an X integration that transfers personal data is enabled.
7. AI features
When you deliberately use an AI-enabled feature, ARVN may send your prompt and strictly necessary Discord server or configuration context to a configured AI provider and process the generated output, usage data and safety telemetry. Context can contain identifiers or Discord content needed for the selected feature. Secrets and obvious credentials are filtered, but you should not submit confidential information or special-category personal data.
No AI provider is publicly identified as production-enabled until each provider's entity, role, DPA, transfer and retention evidence passes the registry gate.
8. Transactional email
Essential messages include verification, password-reset, security, payment and cancellation confirmations. Recipient address, content and delivery metadata are processed for delivery.
The email provider's entity, transfers, DPA and retention are not published until verified in the registry.
9. Cookies and local storage
ARVN uses strictly necessary storage only: the HTTP-only token cookie keeps you signed in for up to seven days; short-lived OAuth state cookies protect Discord and TikTok connection flows; configured support workspaces may use a necessary session cookie. Local storage may retain unfinished AI operator drafts on your device. These technologies are required to provide functionality you expressly request and are used under section 25(2) no. 2 TDDDG. No advertising or cross-site analytics cookies are currently documented in the application.
If optional analytics, marketing or other non-essential technologies are added, they must not run before valid consent is obtained.
10. Recipients and international transfers
Verified enabled recipients: none approved for production disclosure. DNS/CDN, backup, database and monitoring providers are subject to the same registry gate. Professional advisers and legally authorised public authorities may receive data only where required.
ARVN currently creates compressed daily copies of the application database and transfers them to Cloudflare R2 for disaster recovery. These copies can contain the personal data stored in the primary database. A 30-day local and offsite retention limit has been technically implemented but is not represented as operationally verified until deployment evidence and a restore test have been recorded. Encryption settings, processing location, transfer safeguards and the processor agreement remain subject to internal verification.
11. Retention and deletion
We retain personal data only for as long as it is needed for the stated purpose or a legal obligation applies. Account, server configuration, subscription and active support data is generally retained for the life of the account, server workspace or contract. When the relevant account or workspace is deleted, associated data is deleted or anonymised unless it must be retained for legal claims, security evidence or statutory accounting and tax obligations.
Current implementation status: the owner-approved retention policy plans to make user-deletable AI conversations and summaries automatically eligible for deletion after one year of inactivity; that automatic, effectively irreversible deletion mechanism is technically prepared but not yet enabled in production. Until it is enabled, equivalent deletion happens only manually, for example on your request through the support contact. Planned target periods are: billing data and consent evidence for ten years, audit logs for two years, moderation events for one year, webhook operational payloads and error logs for 90 days, and rate-limit logs for 30 days — each subject to legal/dispute holds and final legal review. Provider-side retention is disclosed only after provider settings and agreements are verified.
Commercial and tax documents are retained for the applicable statutory periods. Security incidents, audit records and support tickets are retained for as long as necessary to investigate the event, resolve the request, establish or defend legal claims, or comply with legal duties. Production database backups currently exist locally and in Cloudflare R2. The intended maximum retention is 30 days; automatic enforcement has been implemented in the backup script but must be deployed and verified before it is described as active.
12. Your rights
Subject to the statutory conditions, you may request access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21). You may withdraw consent at any time for the future. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, workplace or the alleged infringement — for users in Germany, typically the data protection authority of the relevant federal state.
Send requests to [email protected]. We may request information necessary to verify your identity.
13. Requirement to provide data and automated decisions
Data marked as required is necessary to create an account or provide the selected service. Without it, we cannot conclude or perform the contract. ARVN does not currently make decisions producing legal or similarly significant effects solely by automated means within Art. 22 GDPR. Automated moderation suggestions or risk scores should be reviewed by authorised server staff where they may materially affect a person.
14. Security and updates
We use appropriate technical and organisational measures designed to protect personal data, including access controls, password hashing, restricted credentials and transport encryption. We update this policy when our processing or the legal framework changes. Material changes will be communicated where required.