Privacy Policy

Last updated: 2026-07-27

This is a template document and should be reviewed by a qualified lawyer and completed with full Controller details before a public launch.

This Privacy Policy explains how HypeDeck (the “Service”), operated by [operator / company name] (the “Controller”), processes Users' personal data in line with the GDPR.

1. Data controller

The data controller is [operator / company name]. For data protection matters, contact: [contact e-mail address].

2. Data we process

Account data: e-mail address, display name, hashed password, optional avatar.

Third-party sign-in data: account id and name, and access tokens (stored to run integrations and the bot).

Configuration data: commands, module settings, page content, overlays and automations.

Bot-related data: viewer statistics (e.g. points, watchtime) associated with chat usernames.

Technical data: session cookies and basic logs necessary for operation and security.

3. Purposes and legal bases

Providing the Service and performing the contract (Art. 6(1)(b) GDPR).

Security, abuse prevention and improvement of the Service – the Controller's legitimate interest (Art. 6(1)(f) GDPR).

Legal obligations, e.g. accounting (Art. 6(1)(c) GDPR), where applicable.

4. Recipients and processors

Infrastructure and database hosting providers (e.g. a managed PostgreSQL provider), acting under data processing agreements.

Third-party platforms (e.g. Twitch, Kick) – only as needed for the integration you authorise.

Payment provider – once payments launch, only to handle subscriptions.

We do not sell data. Transfers to third countries occur only with the safeguards required by the GDPR.

5. Cookies

The Service uses essential cookies, in particular a session cookie (keeping you signed in) and a language preference.

We do not use marketing cookies without your consent.

6. Retention

Account data is kept while your Account exists. After deletion it is removed or anonymised, except data we must retain by law.

Third-party access tokens are deleted when you disconnect the integration.

7. Your rights

You have the right to access, rectify, erase, restrict and port your data, and to object to processing.

You may lodge a complaint with the competent supervisory authority (in Poland: the President of the Personal Data Protection Office, PUODO).

To exercise your rights, contact: [contact e-mail address].

8. Security

We apply technical and organisational measures to protect data, including password hashing, restricted access and secure connections.

No system is fully immune to threats; we work to minimise risk.

9. Changes to this policy

This policy may be updated. We will announce material changes in the Service. The last-updated date is shown at the top.

10. Contact

For privacy and data protection matters: [contact e-mail address].