GoFundNode — Privacy Policy
Superseded by ADR-046 (2026-06-03). This document reflects the prior crypto-first posture, which is no longer GA scope. See ADR-046.
TEMPLATE — REQUIRES RETAINED COUNSEL REVIEW BEFORE PRODUCTION USE. NOT LEGAL ADVICE.
Effective date: TBD upon counsel sign-off and execution.
Document owner: JuiceVendor Labs inc. (operating the GoFundNode service) (the "Platform").
Audience: any natural person whose personal data the Platform processes directly (tenant account holders, operators primarily; visitors to the Platform's owned-and-operated marketing surfaces secondarily).
Source-of-truth: docs/architecture/GOFUNDNODE_ADRS.md, CLAUDE.md, docs/legal/terms/DPA_TEMPLATE.md.
1. Scope of this Policy
1.1 This Privacy Policy explains how the Platform processes personal data where the Platform acts as a controller.
1.2 The Platform processes some personal data as a processor on behalf of a tenant (notably, applicant PII transiting via apply.fun for task execution). That processing is governed by the Data Processing Agreement at docs/legal/terms/DPA_TEMPLATE.md, not by this Policy. Architectural basis: ADR-042 (D-7).
1.3 If you are an applicant whose data is being processed through apply.fun's use of the Platform, apply.fun is the controller of your data. Direct your privacy queries to apply.fun. The Platform handles those queries only as a processor on apply.fun's documented instructions.
2. Who we are
2.1 Controller: JuiceVendor Labs, a Delaware C corporation, registered address [TBD on counsel finalization].
2.2 Data Protection contact: dpo@gofundnode.com (or successor address published on the website).
2.3 EU representative (if required, depending on counsel review of Article 27 applicability): [TBD].
3. Categories of data we collect
3.1 Tenant account data (controller)
- Tenant entity legal name, country of organization.
- Tenant primary contact name, email, and (optional) phone.
- Billing contact + invoice address.
- API tenant ID, HMAC and webhook secrets (encrypted at rest).
3.2 Operator account data (controller)
- Operator email, account display name.
- Operator's Solana wallet address (public on chain by design).
- Operator's home country (for sanctions screening and tax-ID jurisdiction).
- Operator account-side telemetry (heartbeat times, status transitions).
3.3 Operator KYC + tax data (controller, collected at first cashout per D-5)
- Tax identification number (SSN, EIN, VAT-ID, or jurisdictional equivalent).
- Form W-9 (U.S.) or W-8BEN (non-U.S.) or jurisdictional equivalent.
- Identity verification artifacts where required for sanctions screening or 1099 reporting (e.g., ID document image, processed via a regulated KYC provider when threshold-triggered).
3.4 Operational logs (controller)
- HMAC-keyed request logs (
X-GFN-Timestamp, signing-method, endpoint, status, latency). Bodies are not logged. - Dispatch decisions and outcomes (
gfn_task_leases,gfn_operator_rewards, sanctized for the controller view). - Webhook delivery audit (
gfn_webhook_deliveries). - Sanctions screening hits (
gfn_sanctions_screening_events) when material.
3.5 Cookies / marketing surface
- The Platform's marketing site uses essential cookies only at launch. If non-essential cookies are introduced (analytics, advertising), this Policy will be updated and prior consent collected where required.
3.6 Categories we do NOT collect as controller
- Applicant resumes, ATS form contents, application history — these are processor data (DPA).
- Operator personal browsing data, saved passwords, clipboards, personal files — the master-node does not collect these (
ADR-009). - Special-category data (race, ethnic origin, political opinions, religion, trade union membership, genetics, biometrics for identification, health, sex life, sexual orientation) — not collected as controller. Note: applicant data may contain some of these categories where the applicant chooses to provide them to an ATS; that is processor data subject to the DPA.
4. Lawful basis (GDPR Article 6) for each category
| Category | Lawful basis |
|---|---|
| Tenant account data | Contract performance (Customer TOS). |
| Operator account data | Contract performance (Operator Contractor Agreement). |
| Operator KYC + tax data | Legal obligation (tax reporting, sanctions screening) + contract performance. |
| Operational logs (security, fraud) | Legitimate interest (fraud detection, security incident response, platform integrity). |
| Cookies — essential | Legitimate interest. |
| Cookies — non-essential | Consent (none collected at launch). |
We do not rely on consent as the lawful basis for any contractual processing — the Platform's view is that contract performance and legal obligation are the correct bases and that "consent" for processing that is necessary to provide the contracted service would be illusory under EDPB guidance.
5. How long we retain data
| Category | Retention |
|---|---|
| Tenant account data | Duration of contract + 7 years (tax / accounting). |
| Operator account data | Duration of relationship + 7 years (tax / accounting). |
| Operator KYC + tax data | 7 years post-final-cashout (tax records retention). |
| Operational logs (hot) | 90 days. |
| Operational logs (cold archival) | 1 year, then purge. |
| Webhook delivery audit | 6 months. |
| Sanctions screening event log | 5 years (compliance audit). |
| Idempotency keys | 90 days post-settle (per ADR-028). |
When retention expires, data is purged or de-identified according to the architecture documented at docs/CREDIT-SYSTEM.md and the implementation in L1's data-management workstream.
6. Recipients of the data
We share data with:
- Cloud infrastructure providers (database hosting, RPC providers, object storage). Listed at
docs/legal/SUBPROCESSORS.md(maintained by L4). - Payment infrastructure (Solana RPC providers, KYC providers, regulated payout providers per
ADR-037). Subprocessor list as above. - Tax authorities (statutory information returns — see Operator Agreement §5).
- Sanctions authorities (where a sanctions hit triggers reporting per
ADR-038and applicable law). - Courts and law enforcement (in response to lawful legal process).
We do not sell personal data.
7. International transfers
7.1 The Platform is operated by JuiceVendor Labs, a Delaware (US) corporation. Personal data of individuals in the EEA may be transferred outside the EEA, including to:
- The United States (RPC providers, cloud hosting, treasury settlement infrastructure).
- Jurisdictions where regulated payout providers (
ADR-037) operate. - The Solana blockchain itself, which is globally replicated and immutable; on-chain data (operator wallet addresses, payment transactions) is by design public and cannot be deleted.
7.2 Transfers outside the EEA rely on:
- EU–U.S. Data Privacy Framework where the receiving party is certified.
- Standard Contractual Clauses (SCCs) as updated by EC implementing decision 2021/914 otherwise.
- The Platform's documented Transfer Impact Assessment for high-risk transfers.
7.3 Solana acknowledgment. The Operator and the Tenant acknowledge that the Platform's chosen settlement rail is a public blockchain, that transactions are public and irreversible by design, and that on-chain data cannot be erased on request. The Platform's processing of on-chain settlement data is necessary for contract performance.
8. Your rights (GDPR Articles 15–22)
You have the right to request:
- Access to the personal data we process about you.
- Rectification of incorrect data.
- Erasure ("right to be forgotten"), subject to legal-retention and contractual-performance exceptions (e.g., we cannot erase 1099-NEC records during the 7-year retention period; we cannot erase on-chain data).
- Restriction of processing.
- Portability in a machine-readable format.
- Objection to processing based on legitimate interest.
- Withdrawal of consent where consent is the basis.
- Lodge a complaint with the Estonian Data Protection Inspectorate (
https://www.aki.ee/en).
To exercise any of these rights, email dpo@gofundnode.com with sufficient identifying information to verify your identity. We respond within 30 days (extendable to 60 days for complex requests, with notice).
9. Security
9.1 We maintain technical and organizational measures appropriate to the risk, including:
- Three-layer key envelope for tenant payloads (
ADR-015). - TLS for transport with pinned certificates for control-plane traffic.
- HMAC-SHA256 for API authentication.
- Segregated treasury (
ADR-043). - Sanctions screening (
ADR-038). - Dual-partition canary supervisor updates (
ADR-034). - Personnel access controls and audit logs.
9.2 We notify controllers (in the processor context) of personal data breaches without undue delay, and at most within 72 hours of becoming aware, per Article 33 GDPR. We notify supervisory authorities and, where required, data subjects per Articles 33-34.
10. Changes to this Policy
10.1 Material changes to this Policy require 30 days' notice to tenants and operators with active accounts.
10.2 Continued use of the Platform after the notice period constitutes acceptance of the updated Policy.
11. Subprocessor list
11.1 The current subprocessor list is maintained at docs/legal/SUBPROCESSORS.md by the L4 (GDPR/sovereignty) workstream. New subprocessors are added per the change-notice mechanics described in §11.2 of the DPA template.
11.2 Operators are subprocessors with respect to applicant PII transiting their machines (see DPA §2). Their per-operator identifiers are not published in the public subprocessor list, but the category is documented.
12. Contact
- Privacy / DSAR: dpo@gofundnode.com
- General legal: legal@gofundnode.com
- Registered address: JuiceVendor Labs, [TBD on counsel finalization].
13. References
CLAUDE.md(governing principle).docs/architecture/GOFUNDNODE_ADRS.md:- ADR-009 (no operator profile bleed)
- ADR-015 (three-layer envelope)
- ADR-027 (credit blocks)
- ADR-034 (supervisor update pipeline)
- ADR-038 (sanctions screening)
- ADR-040 (tax-ID at cashout)
- ADR-042 (controller/processor split)
- ADR-043 (treasury segregation)
docs/legal/terms/DPA_TEMPLATE.md(processor-context obligations).docs/legal/SUBPROCESSORS.md(L4 maintained).docs/legal/COUNSEL_QUESTIONS.md.
END — TEMPLATE — REQUIRES RETAINED COUNSEL REVIEW BEFORE PRODUCTION USE. NOT LEGAL ADVICE.