1. Who we are

HexTriage ("we," "us") provides AI-powered support services for Web3 communities. For any privacy question or request, contact us at security@hextriage.io. Based and operated in the European Union.

2. The two roles we play

When our bot answers users in a client's Discord or Telegram community, we act as a data processor on behalf of that client, who is the data controller of their community's data. When you create an account on our website dashboard or contact us directly, we are the controller of that data. This policy covers both.

3. Data we process for community support (as processor)

  • Conversations (user question and bot answer) are retained 30 days for quality assurance, then automatically deleted. Conversations flagged for review or escalated to a human are retained 90 days, then deleted.
  • User identity in conversation records is stored only as an irreversible cryptographic hash. Raw usernames are never written to conversation logs.
  • Platform user IDs are used solely to deliver messages while a support ticket or session is open, and are deleted when it closes.
  • Transaction hashes and contract addresses voluntarily shared by users are retained up to 30 days for diagnostics. These are public blockchain identifiers, visible on any block explorer.
  • Aggregate statistics (ticket counts, categories, resolution rates) contain no personal data and are retained for the duration of the client contract.

We never request or collect emails, KYC information, private keys, seed phrases, or off-chain identity from community users.

4. Data we process for clients and visitors (as controller)

  • Dashboard accounts: login email, authentication credentials, and organization name, retained for the duration of your contract plus 12 months, then deleted.
  • Direct communications: emails you send us, retained as long as needed to handle your inquiry.
  • Website: our site does not use third-party analytics or advertising trackers. The dashboard uses strictly necessary session cookies for login only.

5. Legal bases

Performance of a contract (providing the service and dashboard to clients), legitimate interest (quality assurance of bot answers, abuse prevention, service security), and legal obligations where applicable.

6. Who receives data

We use a small number of service providers: an AI provider (Anthropic, Claude API; per its commercial terms, our API inputs and outputs are not used to train models), blockchain data providers (receiving only public on-chain identifiers, never message content), a token-security screening database (contract addresses only), and EU-based hosting (Amsterdam, Netherlands). A complete, named subprocessor list is available to clients under our Data Processing Agreement. We never sell personal data.

7. International transfers

Some providers (such as our AI provider) may process data outside the EEA. Where this occurs, transfers rely on recognized safeguards such as the European Commission's Standard Contractual Clauses.

8. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing, by writing to security@hextriage.io. If you are a user in a client's community, we may redirect your request to that client as the data controller, and will assist them in fulfilling it. You also have the right to lodge a complaint with the data protection supervisory authority in your EU member state.

9. Security

Data is hosted in the EU, encrypted in transit, protected by hashed identifiers and strict per-client isolation, with automatic deletion schedules enforced daily. See our Security page for details.

10. Children

Our services are not directed at children under 16, and we do not knowingly process their data.

11. Changes

We will update this page when our practices change, and revise the date above. Material changes affecting clients will be communicated directly.

Questions about this policy?

Reach us any time at security@hextriage.io.