AVG / GDPR compliance statement
Arcnode Network is operated from Netherlands and is subject to the AVG / General Data Protection Regulation (Regulation (EU) 2016/679). If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in section 9. We process personal data only where a lawful basis under Article 6 GDPR exists, as set out in section 5.
01 Who we are
Arcnode Network is a software studio established in Netherlands. It builds and operates a family of applications, websites, APIs, and services under the Arcnode brand, reachable at arcnode.dev.
For all matters relating to personal data, Arcnode Network acts as the data controller within the meaning of Article 4(7) GDPR. You can reach our privacy and compliance contact at legal@arcnode.dev.
02 Scope of this policy
This policy is a network-wide framework. It applies to every service operated under the Arcnode Network brand, including:
- The arcnode.dev website and all associated subdomains, including visit analytics, the contact form, and update sign-ups.
- The Arcnode account and identity provider (backboard.arcnode.dev), which handles sign-in, two-factor authentication, passkeys, and account management, and the Client Portal, status page, and community surfaces that rely on it.
- Linking a Discord account to your Arcnode account to earn a Verified badge, as described in section 3.5.
- Public surveys and market research published at arcnode.dev/surveys and arcnode.dev/s, described in detail in section 4.
- All current and future Arcnode Network applications, web tools, desktop applications, APIs, and SaaS products that adopt this framework.
This policy does not cover third-party websites or services linked from our products. Review their own privacy policies independently.
03 What data we collect and why
3.1 Website visit analytics
When a page on arcnode.dev is loaded, our infrastructure may record technical request data to understand how the website is used and to keep it secure and reliable. Where this data can identify a visitor, it is treated as personal data.
| Data Point | Value / Format | Purpose |
|---|---|---|
| IP address | IPv4 or IPv6 | Personal data under the GDPR. Used to distinguish visitors, derive approximate location, and protect against abuse. |
| Location | Country and city | Derived from the IP address by our hosting infrastructure. |
| Page path | e.g. "/projects" | Which page was visited. |
| Referrer | Referring URL, if present | The page you navigated from, if any. |
| Device data | User agent, browser, OS, device type | Parsed to understand the platforms our visitors use. |
| Timestamp | Date and time | When the visit occurred. |
An IP address is personal data
Under Article 4(1) GDPR, an IP address constitutes personal data because it can be used, in combination with other information, to identify a natural person. We rely on the legitimate-interests basis (Article 6(1)(f) GDPR) for visit analytics, as described in section 5, and we do not sell this data to third parties.
3.2 Update sign-ups (voluntary)
If you submit your email address to receive product updates, we store the address you provide together with limited metadata recorded at sign-up time for administrative record-keeping. Sign-ups made directly on the website may include the IP address and derived location; waitlist opt-ins collected through a survey store the consent record (exact wording, version and timestamp) and the source survey, but not an IP address. Email delivery is handled by Resend (see section 6). You may withdraw consent and unsubscribe at any time by contacting legal@arcnode.dev. Waitlist sign-ups made through a survey use double opt-in, and the resulting emails contain a direct unsubscribe link (see section 4.2).
3.3 Contact form submissions (voluntary)
When you use a contact form, your name, email address, and message are transmitted via Resend as an email to our team so we can respond. We retain that correspondence only for as long as needed to handle your enquiry, then delete it.
3.4 Your Arcnode account and sign-in
You use a single Arcnode account across the whole network. Sign-in and account management are handled by our identity provider at backboard.arcnode.dev. When you create or use an account, we process the data you submit to provide the Service. This may include:
- Content you create within a Service.
- Preferences and settings.
- Your name and email address.
- Sign-in credentials. If you set a password, it is stored only as a salted bcrypt hash and is never stored or transmitted in plain text. Some accounts, such as those created by linking Discord, have no password at all.
- If you enable two-factor authentication (2FA), a TOTP secret and a set of recovery codes. Recovery codes are stored only as hashes.
- If you register a passkey (WebAuthn), the passkey's public key, credential identifier, sign-in counter, supported transports, and an optional label you give it. The private key never leaves your device; we can never see it.
After you sign in, the identity provider issues a signed session that is verified by each Service using public keys, so your password, passkey, and 2FA secrets are never shared with the individual Services. All data is transmitted over HTTPS. We do not use your content for any purpose other than operating the Service for you.
3.5 Discord account linking
You may connect (link) your Discord account to your Arcnode account to earn a Verifiedbadge in our community server. Linking is optional and is never required to use the Platform. When you link through Discord's OAuth, Discord shares a limited profile with us, which we store together with the moment you linked:
| Data Point | Value / Format | Purpose |
|---|---|---|
| Discord user id | Numeric identifier of your Discord account | Stored so that one Discord account links to at most one Arcnode account. |
| Discord username | Your Discord handle | Shown on your profile and used by moderators. |
| Global (display) name | Your Discord display name, if set | Shown on your profile. |
| Avatar hash | Reference to your Discord avatar image | Used to display your avatar. We store the reference, not the image file. |
| Linked-at timestamp | Date and time you linked Discord | Recorded for administration and to log the linking event. |
Community role information (for example the Verified role) is maintained by our Discord bot and mirrored so that role-based access stays current. You can unlink Discord at any time; a moderator or administrator can also link, unlink, or moderate an account. Discord is listed as a processor in section 6.
3.6 Client portal data
The Arcnode Client Portal is a private, authenticated environment accessible only to invited clients and their team members. The following categories of personal data are processed within the portal:
| Data Point | Value / Format | Purpose |
|---|---|---|
| Account data | Name, email address, bcrypt password hash, account creation and last-update timestamps, mustResetPassword flag | Passwords are stored exclusively as a bcrypt hash and are never stored or transmitted in plain text. |
| Team membership | Team membership record, role (Owner, Admin, Member, or Viewer), join timestamp | Used to enforce role-based access control within a team. |
| Team invitations | Email address of the invitee, assigned role, invitation token | Collected when a team member invites a colleague. The token is deleted immediately after it is accepted or after 7 days if unused. See the note on third-party data below. |
| File uploads | Filename, file type, file size, description, Cloudflare R2 object key, upload timestamp, uploader identity | File content is stored in Cloudflare R2 object storage in the EU (EEUR region). Arcnode application servers never handle file content directly; uploads are performed via pre-signed URLs direct from the client browser to R2. |
| Form answers | Free-text responses (up to 10,000 characters) or file references linked to admin-defined questions | Stored for the duration of the associated project. |
| Password reset tokens | One-time cryptographic token with a 1-hour expiry | Deleted immediately after use. Expired unused tokens are deleted when a new reset is requested or on account deletion. |
| Security events | Login event type (success or failure), submitted email address, anonymized IP address (IPv4 /24, IPv6 /48), User-Agent string, timestamp | Logged for fraud and abuse prevention. Raw IP addresses are not stored; only the anonymized subnet prefix is retained. |
Team invitations and third-party data
When a team member invites a colleague who does not yet have an account, their email address is collected and stored as a TeamInvite record. The recipient is contacted at first opportunity via the invitation email. The legal basis is legitimate interests (Art. 6(1)(f)). Unused invitation records are deleted after 7 days.
Email address changes
The Client Portal does not provide a self-service email address change facility. To update the email address associated with your account, contact legal@arcnode.dev.
04 Surveys and market research
Arcnode Network publishes surveys for market research and public engagement at arcnode.dev/surveys and on individual survey pages under arcnode.dev/s. You can complete a survey without creating an account. Surveys come in three visibility types:
- Public surveys: listed in the public survey directory and open to anyone.
- Unlisted surveys: not listed or indexed, but open to anyone who has the link.
- Invite-only surveys: accessible only with a personal invitation link sent by email.
4.1 Data we collect when you respond
| Data Point | Value / Format | Purpose |
|---|---|---|
| Name or nickname | Free text, as you choose to provide it | Identifies your response. A nickname is acceptable; it may still be personal data when it identifies you. |
| Email address | The address you enter, normalized (trimmed, lowercased) | Used to identify duplicate responses where the survey enables this, and, only with your separate opt-in, to send you email. |
| Survey answers | Your answers to the survey questions | Analysed for the research purpose stated in the survey. Treated as personal data because they are linked to your name and email address. |
| Duplicate-prevention key | Keyed cryptographic hash of the survey and your email address | Set only when the survey has duplicate prevention enabled. Prevents repeat submissions without storing your address as a lookup key. |
| Consent records | Exact consent wording, wording version, timestamp, source survey and response | Kept as evidence of any email opt-in you give. |
| Invitation records | Invitee email address, optional name, hashed invitation token, expiry, usage count | Only for invite-only surveys. The invitation link token is stored exclusively as a cryptographic hash. |
| Moderation data | Flag status, flag reason, private administrative notes | Used internally to review response quality and abuse. Never published. |
Surveys are not anonymous
Because a survey response includes your name or nickname and your email address, survey participation is not anonymous, and we never describe it as such. Published results contain only aggregated statistics, as described in section 4.5.
4.2 Optional email subscriptions (separate consent)
Submitting a survey response never subscribes you to email. A survey may offer up to two separate, optional checkboxes, both unchecked by default:
- Arcnode Network waitlist: news about Arcnode Network products and launches.
- Survey-specific updates: messages about that survey only, such as published results or a follow-up study.
Both use double opt-in: after selecting a checkbox you receive a single confirmation email, and the subscription only becomes active once you confirm it. If you do not confirm, you receive nothing further. We record the exact consent wording, its version, the timestamp, and the survey and response it came from. Every subscription email contains a working unsubscribe link and supports one-click unsubscribe headers, and a token-based preferences page lets you manage the subscription without an account.
Delivery failures (bounces) and spam complaints reported by our email provider automatically suppress future email to the affected address. We do not use open or click tracking in these emails.
A survey may additionally offer an optional follow-up permission checkbox allowing us to contact you once about your answers. This is not a subscription and sends no recurring email.
4.3 Invitations
For invite-only surveys we process the email address (and optional name) of invitees in order to send and manage invitations. Invitation links are personal, expire, can be revoked, and have a limited number of uses. The link token is stored only as a cryptographic hash; opening a valid invitation places a short-lived, strictly necessary cookie (see the Cookie Policy) and removes the token from the address bar. A response submitted through an invitation is linked to that invitation.
4.4 Spam and abuse prevention
Because public surveys accept submissions without a login, we apply layered protection: rate limiting (IP addresses are used transiently as rate-limit keys and expire within the rate-limit window; they are not stored with your response, which never records an IP), Cloudflare Turnstile verification on submission, a honeypot field, and a minimum completion-time check. Turnstile is provided by Cloudflare and is listed as a processor in section 6.
4.5 Who runs each survey, and publication of results
Every survey displays its own privacy notice stating the purpose of the survey, who runs it (Arcnode Network or a named commissioning organisation), the retention period for responses, whether results may be published, and whether response data is shared with a third party. Where a survey is commissioned by another organisation, that organisation is named in the survey itself.
Published survey results contain only aggregated statistics compiled by an administrator. Raw responses are never published automatically, and free-text answers are only ever published after manual review and anonymisation.
Unfinished responses can, where the survey enables it, be kept temporarily in your own browser's local storage so you can continue later. This draft never leaves your device and is deleted when you submit or choose to start over. See the Cookie Policy for details.
05 Legal bases for processing (Art. 6)
Article 6 GDPR requires a lawful basis for every processing activity that involves personal data. The following bases apply across the network:
| Processing activity | Lawful basis |
|---|---|
| Website visit analytics, including IP address | Legitimate interests (Art. 6(1)(f)), to understand and maintain the website. We have assessed that this interest is not overridden by visitors’ fundamental rights, given the limited, non-commercial purpose. |
| Update sign-up email collection | Consent (Art. 6(1)(a)). You actively submit your email address. You may withdraw consent at any time. |
| Contact form processing | Legitimate interests (Art. 6(1)(f)), to respond to your enquiry. |
| Account and application data | Performance of a contract (Art. 6(1)(b)), as processing is necessary to provide the Service you signed up for. |
| Security, fraud prevention, and legal compliance | Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicable. |
| Arcnode account creation, sign-in, two-factor authentication, and passkeys | Performance of a contract (Art. 6(1)(b)). |
| Linking a Discord account (Discord id, username, display name, avatar) | Consent (Art. 6(1)(a)); you actively choose to link Discord to earn a Verified badge, and you may unlink at any time. |
| Password reset token generation and delivery | Performance of a contract (Art. 6(1)(b)). |
| Team invitation email collection (non-users) | Legitimate interests (Art. 6(1)(f)) - facilitating access to the portal for invited colleagues. |
| File upload storage in Cloudflare R2 | Performance of a contract (Art. 6(1)(b)). |
| Form answer storage | Performance of a contract (Art. 6(1)(b)). |
| Security event logging for fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)). |
| Survey participation (name or nickname, email address, answers) | Consent (Art. 6(1)(a)); you actively choose to submit a response after reading the survey privacy notice. Analysing submitted responses for the stated research purpose is additionally supported by legitimate interests (Art. 6(1)(f)). |
| Survey duplicate prevention (keyed hash of survey and email address) | Legitimate interests (Art. 6(1)(f)), to protect the integrity of research results. |
| Survey email opt-ins (waitlist and survey-specific updates) | Consent (Art. 6(1)(a)), given through a separate, unchecked checkbox and confirmed through double opt-in. You may withdraw at any time via the unsubscribe link. |
| Survey invitations (invitee email address and optional name) | Legitimate interests (Art. 6(1)(f)) - inviting selected respondents to participate in research. |
| Survey spam and abuse prevention (rate limiting, Turnstile, honeypot, minimum completion time) | Legitimate interests (Art. 6(1)(f)). |
Right to object to legitimate-interests processing
Where we rely on legitimate interests, you have the right under Article 21 GDPR to object at any time. If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests and rights. Contact legal@arcnode.dev to exercise this right.
06 Third-party processors
We use the following processors, each of which handles personal data on our behalf under an Article 28 GDPR data-processing arrangement. We do not sell personal data to any of them.
| Processor | Purpose and location |
|---|---|
| Railway | Application hosting for the identity provider and other network services, and managed PostgreSQL database hosting. (European Union / United States) |
| Vercel | Hosting for the arcnode.dev website and Client Portal, plus cookieless performance and audience analytics. (European Union / United States) |
| Cloudflare R2 | Object storage for client portal file uploads (images, videos, documents, and other project files submitted by clients). (European Union (EEUR region)) |
| Resend | Transactional and notification email delivery. (United States / European Union) |
| Discord | Hosting of the Arcnode community server and Discord OAuth used to link a Discord account to an Arcnode Account (to earn a Verified badge). When you link, we receive your Discord user id, username, global display name, and avatar. (United States) |
| Sentry | Error monitoring and performance tracing. Configured with personal-data collection disabled (sendDefaultPii is off) and session replay disabled, so request bodies, cookies, and end-user identifiers are not sent. (European Union) |
| Upstash Redis | Rate limiting and request throttling, where configured. IP addresses are processed transiently as rate-limit keys and expire automatically within the rate-limit window; they are not retained. (European Union / Global edge) |
| Cloudflare Turnstile | Spam and abuse prevention on public forms, in particular public survey submissions. Verification requests are processed by Cloudflare when a protected form is submitted. (European Union / Global edge) |
07 International transfers
Some of our processors operate infrastructure outside the European Economic Area, in particular in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, such as the European Commission Standard Contractual Clauses and, where applicable, an adequacy decision.
File uploads are stored in Cloudflare R2 object storage in the EU (EEUR region). No international transfer of stored file objects occurs. Cloudflare's DPA and Standard Contractual Clauses govern any residual management-plane processing.
You may request information about the safeguards that apply to a specific transfer by contacting legal@arcnode.dev.
08 Data retention
Under Article 5(1)(e) GDPR, personal data must not be kept longer than necessary. The following retention periods apply:
| Data type | Retention period |
|---|---|
| Website visit records, including IP addresses | Up to 12 months from the date of the visit. Individual records can be deleted earlier on request. |
| Update subscriber records | Until you unsubscribe or withdraw consent, then deleted on request. |
| Contact form correspondence | Retained only as long as needed to manage the communication, then deleted. Not stored in our application database. |
| Account and application data | For the duration of your account. Permanently deleted within a reasonable time after an account deletion request. |
| ClientUser account data | Retained for the duration of the account. Deleted immediately on account deletion, including all associated R2 file uploads. |
| Passkeys and two-factor authentication secrets | Retained until you remove the passkey or disable 2FA, and in any case deleted on account deletion. |
| Discord link data (id, username, display name, avatar, linked-at) | Retained while your Discord account is linked. Deleted when you unlink Discord or on account deletion. |
| PasswordResetToken | Deleted immediately after use. Expired unused tokens are deleted when a new reset is requested or on account deletion. |
| TeamInvite | Active invites expire after 7 days. Expired unused invites are deleted by automated purge. |
| File uploads (R2 objects) | Deleted when the associated project or account is deleted. |
| Form answers | Retained for the duration of the associated project. Deleted with the project or account. |
| SecurityEvent logs | 90 days. |
| AuditLog records | 12 months. |
| Email delivery logs (recipient, subject, delivery status) | 12 months, removed by automated purge. |
| Webhook delivery logs | 12 months, removed by automated purge. |
| Cookie consent records (choices, hashed IP) | 24 months, removed by automated purge. |
| Survey responses and answers | For the retention period stated in the privacy notice of the individual survey. A concrete retention period must be configured before a survey can be published. |
| Survey invitation records | Until the invitation expires or is revoked; records linked to a submitted response are retained with that response. |
| Survey email consent records | Retained as evidence of consent for as long as the related subscription or response exists. |
| Survey email subscriptions and waitlist records | Until you unsubscribe or withdraw consent. Unsubscribed records are retained in suppressed form so we do not email you again, and are deleted on request. |
09 Your rights
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights:
- Right of access (Art. 15): to confirm whether we process personal data about you and to receive a copy.
- Right to rectification (Art. 16): to correct inaccurate or incomplete data.
- Right to erasure (Art. 17): to request deletion of your personal data, subject to any legal retention obligation.
- Right to restriction (Art. 18): to limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): to receive a copy of the data you provided in a structured, machine-readable format where processing is based on consent or contract.
- Right to object (Art. 21): to object to processing based on legitimate interests at any time. See section 5.
- Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint (Art. 77): with a supervisory authority. See section 14.
To exercise any of these rights, contact legal@arcnode.dev. We will respond within one month as required by Article 12(3) GDPR. We may verify your identity before acting on a request.
10 Account deletion, export, and correction
You can ask us to export, correct, or permanently delete your account and associated personal data at any time. Send your request to legal@arcnode.dev from the email address linked to your account, or include enough information for us to verify your identity.
On a verified deletion request, we permanently remove your account and the personal data we hold about you within a reasonable time, except where we are legally required to retain specific records.
Client portal users may delete their account directly from Settings → Danger zone within the portal. Account deletion immediately deletes all associated personal data and R2 file uploads. Team membership records are also deleted; team projects and their content remain accessible to other team members.
Client portal users can also export their own data directly from Settings → Export your data. We email a secure link that is valid for 7 days and only works after you sign in; it lets you download a machine-readable zip archive of your profile, teams, projects, tasks, comments, form answers, and file list. To prevent abuse, an export can be requested once every 30 days, and the download link never stores a copy of your data.
Survey respondents can request access to, correction of, or deletion of their survey responses, consent records, and subscriptions by contacting legal@arcnode.dev, preferably from the email address used in the response so we can verify the request.
11 Cookies and analytics
We use only strictly necessary and privacy-respecting analytics cookies by default. The categories we use, their purposes, their retention periods, and how to manage your consent are described in full in our Cookie Policy. Analytics are processed in aggregated form and are not used to build advertising profiles.
12 Security measures
We apply technical and organisational measures including:
- HTTPS encryption for all data in transit between your device and our servers.
- Passwords stored only as salted bcrypt hashes, never in plain text.
- Optional two-factor authentication (TOTP) and passkeys (WebAuthn), giving phishing- resistant sign-in. A passkey's private key never leaves your device.
- A single sign-on session issued by our identity provider. The session is a signed token (RS256) that each Service verifies against the identity provider's public keys, so no shared secret is distributed to individual Services. The session cookie is httpOnly, Secure, and SameSite=Lax. Signing out and password or credential changes revoke existing sessions everywhere.
- Access to data restricted to authorised infrastructure components.
- Automatic account lockout after repeated failed sign-in attempts, and rate limiting on sensitive authentication endpoints such as sign-in, password reset, and account deletion.
- Security event logging for all authentication events in the client portal, including both successful and failed login attempts.
- Pre-signed upload URLs: file content transfers directly from the client's browser to Cloudflare R2. Arcnode's application servers never handle file content.
- Survey invitation, confirmation, and unsubscribe tokens are stored exclusively as keyed cryptographic hashes; the raw token exists only in the link sent to the recipient.
- Public survey submissions are protected by rate limiting, Cloudflare Turnstile verification, a honeypot field, and minimum completion-time checks.
No system is perfectly secure. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay as required by Article 34 GDPR.
13 Children's privacy
Our products are not directed at children under the age of 16 within the EEA (Article 8 GDPR), or under 13 elsewhere. We do not knowingly collect personal data from children below these ages.
If you are a parent or guardian and believe your child has provided personal data to us, contact legal@arcnode.dev and we will delete it promptly.
14 Complaints
You have the right to lodge a complaint with a supervisory authority. In Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), reachable at autoriteitpersoonsgegevens.nl. You may also contact the supervisory authority in your country of residence. We would appreciate the chance to address your concern first, so please consider contacting legal@arcnode.dev before lodging a complaint.
15 Changes to this policy
We may update this policy when our practices change or when required by law. The effective date at the top reflects the most recent version. For material changes, we will provide notice on the website or within the relevant application.
Continued use of our website or applications after the effective date of a revised policy constitutes your acknowledgement of the changes.
16 Contact
For any privacy-related question, request, or complaint:
Arcnode Network, Netherlands
legal@arcnode.dev