Privacy Policy

Hivedec Inc. ("Company", "We", "Us", "Our") · Effective August 12, 2026 · Last updated August 12, 2026

1. Introduction and Scope

1.1 Purpose of This Policy

This Privacy Policy explains how Hivedec Inc. collects, uses, processes, stores, and protects your personal information when you access or use the Hivedec ecosystem (the "Platform"). The Platform comprises ten interoperable applications: Hfran, Hive Core, Hive Piping, Hive Studio, Hive Arcade, Hive Admin Portal, Hive Support Hub, Hive Ads, Hive Economy, and Hive Time.

By accessing or using the Platform, you consent to the data practices described in this policy. If you do not agree, please do not use the Platform.

1.2 Jurisdictional Compliance

This policy complies with:

  • General Data Protection Regulation (GDPR) – European Union (Regulation (EU) 2016/679)
  • Protection of Personal Information Act (POPIA) – Republic of South Africa (Act 4 of 2013)
  • California Consumer Privacy Act (CCPA) – California, USA (Civil Code §1798.100 et seq.)
  • Children's Online Privacy Protection Act (COPPA) – United States (15 U.S.C. §§6501-6506)
  • Brazil General Data Protection Law (LGPD) – Brazil (Law 13.709/2018)
  • Relevant local data protection laws applicable in jurisdictions where you reside

1.3 Data Controller and Processor

Data Controller: Hivedec Inc.

For EU users, our representative within the European Economic Area (EEA) is: TBC.

2. Information We Collect

2.1 Information You Provide Directly

2.1.1 Account Registration Data

When you create an account, we collect:

  • Full legal name
  • Email address (unique identifier)
  • Phone number (optional, for two-factor authentication)
  • Username/display name
  • Profile photograph or avatar
  • Date of birth (for age verification)
  • Country of residence
  • Language preference
  • Time zone
  • Password (hashed using bcrypt/argon2)

2.1.2 Creator Verification Data (KYC/AML Compliance)

For creators seeking monetization or payout capabilities:

  • Government-issued identification (passport, driver's license, national ID)
  • Proof of residential address (utility bill, bank statement dated within 3 months)
  • Tax identification number (TIN/VAT/EIN)
  • Bank account details for payouts (IBAN/account number/routing)
  • Business registration documents (if operating as entity)
  • Beneficial owner information (for corporate accounts)
  • Selfie verification for identity matching
  • Video interview record (if requested for enhanced verification)

2.1.3 Payment and Financial Data

Processed through Stripe (PCI-DSS Level 1 certified) or Hive Economy:

  • Credit/debit card numbers (not stored directly; tokenized by Stripe)
  • Billing address
  • Transaction history
  • Purchase receipts and invoices
  • Virtual currency purchase records
  • Payout history and balances
  • Currency preferences
  • Tax withholding certificates (W-8/W-9 as applicable)

2.1.4 Content You Upload

  • Videos, images, audio files, text posts
  • Metadata associated with content (titles, descriptions, tags, timestamps)
  • Live stream recordings and chat logs
  • Playlist compositions
  • Edited productions from Hive Studio
  • Remix and derivative works
  • Wishlist item submissions with supporting documentation

2.1.5 Communication Data

  • Direct messages (encrypted end-to-end in Hfran)
  • Channel/forum posts and replies
  • Customer support ticket correspondence
  • Survey responses and feedback submissions
  • Report submissions (content moderation reports)
  • Email communications with Hivedec staff

2.1.6 Preference and Settings Data

  • Notification preferences
  • Privacy settings (DM permissions, profile visibility)
  • Content rating preferences (General, Teen, Mature)
  • Geographic region locks
  • Subscription tier selections
  • Dark/light mode preferences
  • Accessibility settings (font size, color contrast, screen reader compatibility)

2.2 Information Collected Automatically

2.2.1 Device and Technical Information

  • IP address (logged for security, anonymized after 90 days unless flagged)
  • Device type (desktop, mobile, tablet)
  • Operating system version
  • Browser type and version
  • Screen resolution
  • Device identifiers (IDFA for iOS, GAID for Android, cookie IDs for web)
  • Hardware specifications (CPU, GPU, RAM for performance optimization)
  • Network connection type (WiFi, cellular, ethernet)
  • App version installed
  • Plugin/extensions detected
  • Language/locale settings

2.2.2 Usage and Behavioral Data

  • Login timestamps and session duration
  • Pages/views accessed and time spent on each
  • Scroll depth and cursor movement patterns
  • Video playback metrics (play, pause, rewind, skip, completion rate)
  • Search queries entered
  • Feature adoption rates (which tools you use and how frequently)
  • Interaction with other users (follows, likes, shares, comments, tips)
  • Commerce actions (cart additions, checkout abandonment, purchases)
  • Gamification participation (Arcade game sessions, XP earned, leaderboard positions)
  • Content consumption patterns (favorite genres, peak viewing times)

2.2.3 Location Data

  • Approximate geographic location derived from IP address
  • GPS coordinates (if you opt-in for location-based features)
  • Country, region, city-level data for content localization
  • Time zone adjustments for content scheduling

2.2.4 Cookies and Tracking Technologies

We use the following categories of cookies:

Cookie TypePurposeLifespanOpt-Out Available
EssentialSession management, authentication, securitySessionNo
FunctionalRemember preferences, accessibility settings1 yearYes
AnalyticalPerformance monitoring, usage analytics2 yearsYes
MarketingAd targeting, remarketing, conversion tracking13 monthsYes
Third-PartySocial media plugins, embedded contentVariesLimited

Browser controls may be used to reject cookies, but some Platform features may malfunction.

2.3 Information from Third Parties

2.3.1 Payment Processors (Stripe)

  • Payment success/failure status
  • Billing address verification
  • Fraud risk scores
  • Dispute and chargeback history

2.3.2 Social Media Platforms (if you link accounts)

  • Public profile information
  • Friend/follower networks (if you invite contacts)
  • OAuth tokens for single sign-on (Google, Apple, Twitter, etc.)

2.3.3 Verification Services

  • Identity verification results (government ID validation)
  • Address verification outcomes
  • Sanctions screening results (OFAC, UN, EU lists)

2.3.4 Content Moderation Services

  • Content safety classifications
  • Copyright match results
  • Prohibited content flags

2.3.5 Verified Companies (Wishlist Partners)

  • Order confirmation status
  • Shipping/delivery verification
  • Customer satisfaction ratings

3. How We Use Your Information

3.1 Primary Purposes

PurposeLegal Basis (GDPR)POPIA ConditionData Categories Used
Account creation and authenticationContract performanceConsent, ContractRegistration data, credentials
Processing payments and payoutsContract performanceContractPayment data, financial records
Content hosting and deliveryContract performanceLegitimate interestUploaded content, metadata
Personalizing user experienceLegitimate interestConsentBehavioral data, preferences
Platform security and fraud preventionLegitimate interestLegitimate interestIP addresses, device fingerprints
Moderation and AUP enforcementLegitimate interestLegitimate interestUser content, reports, logs
Customer support and communicationContract performanceConsentSupport tickets, emails
Service improvements and R&DLegitimate interestConsent (opt-in)Aggregated analytics, usage patterns
Marketing and promotionsConsentConsentEmail, notification preferences
Regulatory compliance (KYC/AML)Legal obligationLegal obligationIdentity documents, financial data
Analytics and reportingLegitimate interestLegitimate interestUsage statistics, KPIs

3.2 Specific Use Cases

3.2.1 Creator-Fan Engagement (Hfran)

  • Enabling direct messaging between creators and supporters
  • Facilitating tiered access to channels and communities
  • Managing membership subscriptions and renewals
  • Sending notifications about new content or events

3.2.2 Live Streaming and VOD (Hive Core, Hive Time)

  • Broadcasting live streams to viewers globally
  • Hosting video-on-demand content with DRM protection
  • Delivering real-time chat and reactions during broadcasts
  • Recording streams for later VOD availability
  • Generating AI-subtitles and chapters for accessibility

3.2.3 Music Distribution (Hive Piping)

  • Streaming audio tracks with adaptive bitrate
  • Managing album/track metadata and discography organization
  • Distributing royalties to artists and collaborators
  • Matching listeners with similar musical tastes
  • Generating AI-curated playlists (HiveMind mixes)

3.2.4 Production Tools (Hive Studio)

  • Providing cloud-based video editing capabilities
  • Storing project timelines and asset libraries
  • Rendering exported content for publication
  • Collaborative editing with real-time synchronization
  • Version history tracking and rollback capabilities

3.2.5 Gamification (Hive Arcade)

  • Awarding XP, coins, shields based on engagement
  • Maintaining leaderboards and achievement records
  • Running trivia games and multiplayer events
  • Calculating community rewards distribution
  • Tracking learning progression across challenges

3.2.6 Commerce and Wishlists (Hive Economy)

  • Processing payments through Stripe/Hive Economy
  • Fulfilling digital and physical merchandise orders
  • Managing wishlist items with verified company documentation
  • Calculating revenue shares and creator payouts
  • Detecting fraud and suspicious transaction patterns

3.2.7 Advertising (Hive Ads)

  • Serving targeted advertisements based on interests
  • Measuring ad impressions, clicks, and conversions
  • Protecting brand safety through content filters
  • Reporting advertiser KPIs and ROI metrics
  • Ensuring compliance with advertising disclosure rules

3.2.8 Administration and Governance (Admin Portal)

  • Monitoring platform health and uptime
  • Generating compliance reports for regulators
  • Detecting systemic fraud or abuse patterns
  • Managing content lifecycle and archival
  • Producing transparency reports on moderation actions

4. Data Sharing and Disclosure

4.1 Third-Party Service Providers

We engage trusted third parties to perform services on our behalf:

CategoryPurposeExamplesData Shared
Payment ProcessingProcess transactionsStripe, PayPalCard tokens, billing address
Cloud HostingInfrastructure storageBunnyCDNOnly data relating to content delivery
Content DeliveryGlobal media distributionCloudflare, BunnyCDNVideo/audio files, thumbnails
Email DeliveryTransactional communicationsSendGrid, MailgunEmail addresses, templates
SMS/TelephonyOTP verification, alertsTwilioPhone numbers, message content
AnalyticsUsage measurementGoogle Analytics, MixpanelAggregated event data
ModerationContent safety screeningGoogle Cloud AI, HiveModerateContent samples, metadata
Identity VerificationKYC/AML complianceStripe KYC ToolGovernment IDs, selfies
Legal/ComplianceRegulatory filingsAccounting firms, law firmsFinancial records, tax docs

All providers are bound by Data Processing Agreements (DPAs) requiring confidentiality, security standards, and GDPR/POPIA compliance.

4.2 Legal and Regulatory Disclosures

We may disclose information when required by:

  • Court orders, subpoenas, or judicial warrants
  • Government regulatory investigations
  • Law enforcement requests (with valid legal process)
  • Tax authorities (annual income reports for creators)
  • Intellectual property infringement claims
  • Child safety reports (NCMEC, law enforcement)
  • National security requests (under applicable law)

We challenge overbroad requests where legally permissible and notify affected users when possible.

4.3 Business Transfers

In the event of a merger, acquisition, sale of assets, or bankruptcy:

  • User data may be transferred as part of the transaction
  • Acquiring entity assumes our data protection obligations
  • Users will be notified via email or platform announcement
  • Data will remain subject to this Privacy Policy unless amended

4.4 Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot reasonably identify you:

  • Industry trend reports for creator economy insights
  • Benchmarking studies for platform performance
  • Research partnerships with academic institutions
  • Investor due diligence materials
  • Public transparency reports

Anonymization techniques include: k-anonymity, differential privacy, data masking.

4.5 User-Controlled Sharing

You control certain sharing activities:

  • Public profile information visible to all users
  • Content you choose to publish publicly vs. privately
  • Links shared in chats or community channels
  • Third-party integrations you authorize (OAuth connections)
  • Social media sharing buttons on your content

5. International Data Transfers

5.1 Data Localization and Cross-Border Flows

Hivedec operates globally; your data may be processed in countries outside your residence:

RegionPrimary Data CentersLegal Framework
Europe (EEA)Frankfurt, DublinGDPR adequacy decisions
North AmericaVirginia, Oregon, TorontoSCCs, Privacy Shield successor frameworks
AfricaCape Town, JohannesburgPOPIA compliance, local storage
Asia-PacificSingapore, Sydney, TokyoCross-border data flow agreements
Latin AmericaSão Paulo, Mexico CityLGPD alignment with GDPR

6. Data Retention and Deletion

6.1 Retention Periods

Data CategoryRetention PeriodJustification
Account data (active users)Duration of account + 2 yearsService provision, dispute resolution
Deleted account data2 years post-deletionLegal compliance, fraud prevention
Payment transaction records7 yearsTax and accounting requirements
Content uploadsUntil deleted by user + 30 days backupCopyright claims, moderation review
DM conversationsUntil user deletes or account terminatesPrivacy guarantee, no retention for moderation except reported content
Moderation logs10 yearsRegulatory audit requirements
Analytics data (aggregated)5 yearsBusiness intelligence
Security logs (IP, login attempts)90 days (unless flagged)Incident investigation
KYC/verification documents10 yearsAML/CFT compliance
Wishlist documentation7 yearsFinancial audit trail

6.2 Deletion Requests

6.2.1 How to Request Deletion

Submit a deletion request via:

  • Platform: Settings → Privacy → Delete Account
  • Email: data.privacy@hivedec.com (subject line: "Data Deletion Request")

6.2.2 Identity Verification Required

To prevent unauthorized deletions:

  • Confirm email address on file
  • Submit government-issued ID for high-risk deletions
  • Two-factor authentication verification
  • Response within 30 days of verification

6.2.3 Exceptions to Deletion

Some data must be retained despite deletion request:

  • Transaction records required by tax law
  • Moderation evidence for unresolved reports
  • Outstanding financial obligations or disputes
  • Legal holds (litigation, investigation)
  • Backup copies (deleted from primary within 30 days, purged from backup within 90 days)

6.2.4 Deletion Confirmation

Upon successful deletion:

  • Email confirmation sent within 30 days
  • Summary of retained data with justification
  • Option to export data before final deletion
  • Irreversible (cannot reactivate account)

7. User Rights and Choices

7.1 GDPR Rights (EU/EEA Users)

RightDescriptionHow to Exercise
Right to AccessReceive copy of your personal dataDownload from Settings or request via email
Right to RectificationCorrect inaccurate or incomplete dataEdit profile or contact support
Right to ErasureDelete your data ("right to be forgotten")Submit deletion request (Section 6.2)
Right to RestrictionLimit processing of your dataContact DPO with restriction scope
Right to PortabilityReceive data in structured, machine-readable formatExport data download (JSON, CSV)
Right to ObjectOppose processing for direct marketingUnsubscribe via email or notification settings
Right to Withdraw ConsentCancel previously given consentToggle off permissions in Privacy Settings
Right to Human ReviewContest automated decisions affecting youRequest manual review for moderation/payout decisions

7.2 CCPA/CPRA Rights (California Users)

  • Know: What personal information is collected, sold, or disclosed
  • Delete: Request deletion of personal information
  • Opt-Out: Decline sale or sharing of personal information
  • Correct: Request correction of inaccurate personal information
  • Non-Discrimination: Equal service and pricing regardless of rights exercise

California Do Not Sell/Sharing: Toggle in Settings → Privacy → "Do Not Sell My Personal Information"

7.3 POPIA Rights (South African Users)

  • Access: Request confirmation of processing and copies of data
  • Correction: Require correction of inaccurate information
  • Deletion: Demand destruction of data no longer necessary
  • Objection: Object to processing based on legitimate interests
  • Complaint: Lodge complaint with Information Commissioner (ISA)

7.4 Marketing Preferences

You control marketing communications:

  • Email: Unsubscribe link in all promotional emails
  • SMS: Reply STOP to opt-out
  • Push Notifications: Disable in device settings or Platform preferences
  • Third-Party Sharing: Opt-out via "Do Not Sell My Personal Information"

We honor global privacy controls (GPC) signals from compatible browsers.

7.5 Automated Decision-Making

Hivedec uses automation for:

  • Content recommendation algorithms
  • Fraud detection scoring
  • Payout eligibility determination
  • Moderation flagging and triage
  • Dynamic pricing in AI-negotiated deals

You have the right to:

  • Request human review of automated decisions
  • Provide additional context for algorithmic consideration
  • Opt-out of purely automated decisions (with exceptions for contract performance)

8. Data Security

8.1 Technical Safeguards

Security ControlImplementation
Encryption in TransitTLS 1.3 for all communications
Encryption at RestAES-256 for database and file storage
Access ControlsRole-based access control (RBAC) with least privilege
Multi-Factor AuthenticationTOTP, SMS, hardware keys supported
Intrusion DetectionReal-time SIEM monitoring with alerting
DDoS ProtectionCloudflare Enterprise + rate limiting

8.2 Organizational Measures

  • Employee Training: Annual privacy and security awareness training
  • Background Checks: Conducted for all employees with data access
  • Confidentiality Agreements: All staff and contractors sign NDAs
  • Incident Response Plan: Documented and tested biannually
  • Vendor Audits: Annual security reviews of critical third parties
  • Privacy by Design: New features undergo DPIA before launch

8.3 Breach Notification

In the event of a data breach:

  • Assessment: Determined within 72 hours of discovery
  • Notification: Affected users informed within 72 hours where legally required
  • Regulatory Reporting: Relevant supervisory authorities notified per GDPR/POPIA timelines
  • Public Disclosure: Significant breaches announced via platform and press release
  • Remediation: Root cause analysis and preventive measures implemented

Breached data categories are clearly described in notification (email, financial data, content, etc.)

9. Children's Privacy

9.1 Age Restrictions

  • Minimum Age: 13 years old to create an account
  • Younger Users: Minors under 13 require parental consent and supervision
  • Verification: Age gates and self-declaration during registration

9.2 COPPA Compliance (United States)

  • No knowing collection of data from children under 18 without verifiable parental consent
  • Parental rights to review, delete, and refuse further collection
  • Privacy notice directed to parents
  • Reasonable measures to prevent re-submission

9.3 Age-Gated Content

Mature content (Teen, 18+) is restricted through:

  • Date of birth verification at signup
  • Secondary verification for borderline ages
  • Content filtering based on age classification
  • Parental controls for supervised accounts

10. Tracking and Advertising

10.1 First-Party Tracking

Hivedec tracks user activity to:

  • Improve service quality and personalization
  • Measure feature adoption and engagement
  • Prevent fraud and abuse
  • Optimize content recommendations

Users may disable tracking for analytics via Settings → Privacy → "Usage Analytics"

10.2 Third-Party Advertising

We partner with advertising networks to serve targeted ads:

  • Advertisers may place cookies on your device
  • We do not share raw personal data with advertisers
  • Aggregate insights are provided to advertisers
  • You may opt-out of personalized advertising

Opt-Out Resources:

10.3 Interest-Based Advertising Categories

We classify users into interest categories for ad targeting:

  • Content preferences (music, gaming, lifestyle, etc.)
  • Demographic segments (age range, general location)
  • Behavioral clusters (frequent shopper, power user, casual browser)
  • Device types (mobile, desktop, smart TV)

These categories never include sensitive attributes (health, political views, sexuality, religion).

11. Social Media and Third-Party Integrations

11.1 Social Login Options

You may authenticate using:

  • Google OAuth
  • Apple Sign-In
  • Twitter/X OAuth
  • Facebook
  • Github
  • Proton

When you use third-party login:

  • We receive basic profile data (name, email, profile picture)
  • We cannot access your third-party account credentials
  • You may revoke access via third-party account settings

11.2 Embedded Content

Posts may include content from:

  • YouTube videos
  • Instagram photos
  • Spotify tracks
  • Twitter/X posts
  • Rumble videos
  • Twitch videos
  • TikTok videos
  • BuyMeACoffee posts

These services may set cookies independent of Hivedec. Their privacy policies apply.

11.3 Platform-to-Platform Data Exchange

If you connect Hivedec to external services (Shopify, WordPress, etc.):

  • Data flows are bidirectional based on OAuth scopes granted
  • You may disconnect at any time in Settings → Integrations
  • Disconnecting revokes future data access but does not delete historically shared data

12. Changes to This Policy

12.1 Revision Process

We may update this Privacy Policy periodically:

  • Material changes announced 30 days in advance via email and platform banner
  • Minor updates effective immediately (clarifications, administrative changes)
  • Version history maintained and accessible in Settings → Privacy

12.2 Continued Use Constitutes Acceptance

After revision notices expire, continued Platform use indicates acceptance of updated terms.

12.3 Grandfathering

Existing users retain rights under prior policy versions for data already collected, unless:

  • Expanded use is necessary for contract performance
  • Legal requirements mandate broader processing
  • Users explicitly object and exercise opt-out rights

13. Contact Information and Complaints

13.1 Data Protection Officer

Data Protection Officer (DPO)

Respond to inquiries within 14 business days.

13.2 Supervisory Authorities

You may lodge complaints with relevant data protection authorities:

RegionAuthorityWebsite
European UnionTBCedpb.europa.eu
South AfricaInformation Regulator (ISA)inforegulator.org.za
CaliforniaCalifornia Privacy Protection Agencycppa.ca.gov
BrazilNational Data Protection Authority (ANPD)gov.br/anpd

13.3 Litigation Venue

Subject to any mandatory rights or remedies available under applicable data protection law, disputes regarding privacy matters shall be resolved in:

  • the state courts of competent jurisdiction located in Travis County, Texas, or, where federal jurisdiction exists, the United States District Court for the Western District of Texas, Austin Division .

The parties consent to the jurisdiction and venue of such courts.

Mediation preferred before litigation (contact legal@hivedec.com).

BY USING THE HIVEDEC PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY. IF YOU DO NOT AGREE, PLEASE DISCONTINUE USE IMMEDIATELY AND REQUEST DATA DELETION VIA SECTION 6.2.

For ongoing questions, contact data.privacy@hivedec.com. Related documents: Terms of Service and Acceptable Use Policy.

This Privacy Policy is a living document and may be amended. Last updated: August 12, 2026.