Original Buzzr copy prepared for design review. This is not an adopted agreement or policy. Operator, contacts and applicable legal details are pending.
01. About this draft
This is a proposed privacy notice for Buzzr. The data controller, actual data flows, processors, retention periods and applicable legal bases have not yet been confirmed. The descriptions below are requirements for review, not a statement that a particular collection or sharing practice is already operating.
The final policy must identify the responsible entity and a working privacy contact before a production service collects personal information.
02. Account and profile information
The account flow may involve a sign-in identifier and profile details you choose to provide, such as a display name, avatar and bio. A final data inventory must specify which fields are required, which are optional and why each is needed.
If a social account can be connected, the connection screen should explain the requested permissions. A connection should not be treated as permission to obtain every field available from the external service.
03. Public social activity
A social trading service needs to make the visibility of profiles, follows, posts and displayed trading activity easy to understand. Review the audience before publishing. Do not include private financial details or information about other people without permission.
The final policy must explain what is public by default, which visibility settings exist and whether profiles link people to blockchain addresses. Copies made by others may remain outside the service after a post is removed.
04. Wallets and transaction records
A wallet address can become associated with a profile or other identifying information. Blockchain records may be searchable independently of Buzzr and retained indefinitely by the network.
The final notice must distinguish information stored by Buzzr from information handled by a wallet provider or recorded on-chain. Deleting account data cannot be represented as a way to erase a public blockchain transaction.
05. Device data and storage technologies
Before launch, document any logs, device identifiers, cookies, local storage and analytics used by the website or app. Each entry should identify its purpose, provider, retention period and whether it is necessary.
If optional tracking is introduced, appropriate choices and consent controls must be implemented where required. This draft does not claim that optional analytics or advertising tracking is enabled.
06. Purposes and service providers
Potential purposes include creating accounts, showing requested social features, processing instructions, assisting with support and protecting the service against abuse. The final notice must connect actual purposes to the data used and the applicable legal basis.
Identify the providers receiving information, their roles and the limits on their use. Wallet infrastructure, hosting and support tools must be assessed against the production architecture. Another platform’s provider list cannot be assumed to apply to Buzzr.
07. Storage and retention
Data hosting and access locations, along with any required transfer safeguards, must be established before issuing the final notice. This draft does not select a hosting country or claim a transfer mechanism.
Retention should be specified by data category and purpose, including account closure, backup cycles and legally required records. Keeping information for an undefined period should not be the default.
08. Your requests and choices
Depending on applicable law, you may have rights to access, correct or delete information, request a copy or limit certain processing. The final policy must explain which rights apply and how to exercise them through a verified channel.
Requests may require proportionate identity verification. The final process must explain response periods and lawful exceptions. Never send a private key or recovery phrase as proof of identity.
09. Security and age requirements
Security measures must reflect the actual system and should not promise that unauthorised access, loss or disruption is impossible. Use unique credentials and review connected devices and accounts regularly.
The proposed service is intended for adults. The final policy must align age requirements and treatment of information about minors with the locations served.
10. Updates and contact
Before adoption, add the controller’s identity, privacy contact, effective date, rights procedures and any required regulator information. Those details remain pending.
Revisions should identify their effective date and explain how material changes will be communicated. The production notice must describe what the service actually does.
End of document
Back to top ↑