Privacy Policy

Pursuant to Art. 13, 14 GDPR and § 13 TMG (German Telemedia Act)

1. Controller

Arne Werner
Hauptstr. 234B
26639 Wiesmoor
Germany
Email: arne.werner87@gmail.com

2. Data Processing Principles

TrustCord is designed as a privacy-minimised service following a process-and-purge model. We process personal data only to the strictly necessary extent (data minimisation pursuant to Art. 5(1)(c) GDPR).

3. Verification Data Processed by TrustCord

TrustCord may process:

TrustCord does not store:

4. Purpose and Legal Basis

Processing occurs for the purpose of realness, anti-bot, and (where enabled) age-threshold verification for Discord server access.

5. Third-Party Provider – Didit

Verification sessions are processed via the third-party provider Didit (didit.me). Didit processes the user's identity document and selfie as part of the verification process where the enabled workflow requires it. TrustCord receives from Didit only the sanitised verification result described in section 3 above, together with an opaque session/vendor reference that does not itself contain Discord identifiers. Raw data (documents, images, decision payloads) remain with the third-party provider and are never stored, logged, or displayed by TrustCord. Where technically supported and permitted by the connected API key, TrustCord attempts to delete the Didit-side session immediately after processing.

Didit maintains its own security and compliance certifications, including SOC 2 Type I (SOC 2 Type II in progress), ISO 27001, ISO 27017, and ISO 27018, iBeta Level 1 (ISO 30107-3) liveness/anti-spoofing testing, and states that it is compliant with the GDPR in its role as data processor. These certifications and compliance claims are made and maintained by Didit; TrustCord does not independently audit or certify Didit's infrastructure.

Please refer to Didit's privacy policy: didit.me/privacy

6. Automated Decision-Making

The verification result (e.g. verified / declined) is generated by Didit's automated, AI-assisted checks (document authenticity analysis, face-match, and liveness/anti-spoofing detection) without a review step by TrustCord itself. This may constitute automated decision-making within the meaning of Art. 22 GDPR. Where Didit's own process flags a session for manual review, the result is not finalised automatically - the verification remains in review until that process concludes.

You may contact us at the address in section 1 to request review of a verification decision as it applies to your access to a Discord server. TrustCord itself does not access, alter, or override Didit's underlying document or biometric assessment, since that data is not transmitted to or stored by TrustCord (see section 3) - any request to review the verification assessment itself must be directed to Didit as the entity that performed it.

7. International Transfers

Where third-party providers (e.g. Didit) process data outside the European Economic Area, this is done on the basis of appropriate safeguards pursuant to Art. 46 GDPR (standard contractual clauses). Please refer to the respective provider's privacy policy for details.

8. Retention Period

Verification records are stored by default for 12 months (configurable per server between 1 and 36 months). After expiry or upon deletion by the user, all personal data is irreversibly anonymised.

9. Your Rights (Art. 15–22 GDPR)

You have the right to:

To exercise your rights, please contact: arne.werner87@gmail.com

10. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. For Lower Saxony, Germany:

Landesbeauftragte für den Datenschutz Niedersachsen (LfD) - State Commissioner for Data Protection Lower Saxony
Prinzenstraße 5
30159 Hannover
www.lfd.niedersachsen.de

11. Data Security

All API keys are stored encrypted with AES-256-GCM. Communication between the Discord bot and API uses encrypted connections exclusively. Webhook messages are verified with HMAC-SHA256 where a webhook signature secret is configured.

12. Web Dashboard Access Data (Server Administrators)

Signing in to the web dashboard with Discord is separate from the verification data described in section 3, and applies only to server administrators who use the dashboard - not to members who verify via /verify. TrustCord stores:

TrustCord does not store your Discord username, avatar, or email address for dashboard sign-in - these are discarded before storage. Your Discord token is revoked at Discord once your last active dashboard session ends - whether by signing out, by that session expiring without further activity, or by deleting your data via /privacy - and not while another dashboard session of yours is still active.

Last updated: July 2026 · This privacy policy applies to the TrustCord service.