gofundnode legal

GoFundNode — Privacy Policy

Superseded by ADR-046 (2026-06-03). This document reflects the prior crypto-first posture, which is no longer GA scope. See ADR-046.

TEMPLATE — REQUIRES RETAINED COUNSEL REVIEW BEFORE PRODUCTION USE. NOT LEGAL ADVICE.

Effective date: TBD upon counsel sign-off and execution.
Document owner: JuiceVendor Labs inc. (operating the GoFundNode service) (the "Platform").
Audience: any natural person whose personal data the Platform processes directly (tenant account holders, operators primarily; visitors to the Platform's owned-and-operated marketing surfaces secondarily).
Source-of-truth: docs/architecture/GOFUNDNODE_ADRS.md, CLAUDE.md, docs/legal/terms/DPA_TEMPLATE.md.


1. Scope of this Policy

1.1 This Privacy Policy explains how the Platform processes personal data where the Platform acts as a controller.

1.2 The Platform processes some personal data as a processor on behalf of a tenant (notably, applicant PII transiting via apply.fun for task execution). That processing is governed by the Data Processing Agreement at docs/legal/terms/DPA_TEMPLATE.md, not by this Policy. Architectural basis: ADR-042 (D-7).

1.3 If you are an applicant whose data is being processed through apply.fun's use of the Platform, apply.fun is the controller of your data. Direct your privacy queries to apply.fun. The Platform handles those queries only as a processor on apply.fun's documented instructions.


2. Who we are

2.1 Controller: JuiceVendor Labs, a Delaware C corporation, registered address [TBD on counsel finalization].

2.2 Data Protection contact: dpo@gofundnode.com (or successor address published on the website).

2.3 EU representative (if required, depending on counsel review of Article 27 applicability): [TBD].


3. Categories of data we collect

3.1 Tenant account data (controller)

3.2 Operator account data (controller)

3.3 Operator KYC + tax data (controller, collected at first cashout per D-5)

3.4 Operational logs (controller)

3.5 Cookies / marketing surface

3.6 Categories we do NOT collect as controller


4. Lawful basis (GDPR Article 6) for each category

CategoryLawful basis
Tenant account dataContract performance (Customer TOS).
Operator account dataContract performance (Operator Contractor Agreement).
Operator KYC + tax dataLegal obligation (tax reporting, sanctions screening) + contract performance.
Operational logs (security, fraud)Legitimate interest (fraud detection, security incident response, platform integrity).
Cookies — essentialLegitimate interest.
Cookies — non-essentialConsent (none collected at launch).

We do not rely on consent as the lawful basis for any contractual processing — the Platform's view is that contract performance and legal obligation are the correct bases and that "consent" for processing that is necessary to provide the contracted service would be illusory under EDPB guidance.


5. How long we retain data

CategoryRetention
Tenant account dataDuration of contract + 7 years (tax / accounting).
Operator account dataDuration of relationship + 7 years (tax / accounting).
Operator KYC + tax data7 years post-final-cashout (tax records retention).
Operational logs (hot)90 days.
Operational logs (cold archival)1 year, then purge.
Webhook delivery audit6 months.
Sanctions screening event log5 years (compliance audit).
Idempotency keys90 days post-settle (per ADR-028).

When retention expires, data is purged or de-identified according to the architecture documented at docs/CREDIT-SYSTEM.md and the implementation in L1's data-management workstream.


6. Recipients of the data

We share data with:

We do not sell personal data.


7. International transfers

7.1 The Platform is operated by JuiceVendor Labs, a Delaware (US) corporation. Personal data of individuals in the EEA may be transferred outside the EEA, including to:

7.2 Transfers outside the EEA rely on:

7.3 Solana acknowledgment. The Operator and the Tenant acknowledge that the Platform's chosen settlement rail is a public blockchain, that transactions are public and irreversible by design, and that on-chain data cannot be erased on request. The Platform's processing of on-chain settlement data is necessary for contract performance.


8. Your rights (GDPR Articles 15–22)

You have the right to request:

To exercise any of these rights, email dpo@gofundnode.com with sufficient identifying information to verify your identity. We respond within 30 days (extendable to 60 days for complex requests, with notice).


9. Security

9.1 We maintain technical and organizational measures appropriate to the risk, including:

9.2 We notify controllers (in the processor context) of personal data breaches without undue delay, and at most within 72 hours of becoming aware, per Article 33 GDPR. We notify supervisory authorities and, where required, data subjects per Articles 33-34.


10. Changes to this Policy

10.1 Material changes to this Policy require 30 days' notice to tenants and operators with active accounts.

10.2 Continued use of the Platform after the notice period constitutes acceptance of the updated Policy.


11. Subprocessor list

11.1 The current subprocessor list is maintained at docs/legal/SUBPROCESSORS.md by the L4 (GDPR/sovereignty) workstream. New subprocessors are added per the change-notice mechanics described in §11.2 of the DPA template.

11.2 Operators are subprocessors with respect to applicant PII transiting their machines (see DPA §2). Their per-operator identifiers are not published in the public subprocessor list, but the category is documented.


12. Contact


13. References


END — TEMPLATE — REQUIRES RETAINED COUNSEL REVIEW BEFORE PRODUCTION USE. NOT LEGAL ADVICE.