SOLVRA
SOLVRA
Privacy
Last updated: 2026-06-20
Solvra operates a community protection registry at solvra.gg/registry.
The Public View shows only:
The Public View does NOT show:
For each Public View entry, Solvra processes internally:
This internal data is accessible only to authorized Solvra staff (Middleman Manager and higher roles) via the internal dashboard at solvra.gg/dashboard/registry. The internal data is not published, not sold, and not shared with third parties unless legally required.
Registry information comes from Solvra staff observations and reports from community members, not from the affected user directly.
The processing of Discord identifiers in the Public View and the internal data processing are based on legitimate interest (Art. 6 (1) (f) GDPR). The legitimate interest is the protection of the Solvra community from documented scam attempts and rule violations.
Active entries remain in the Public View for a maximum of 5 years from the date of the last documented violation. After this period, the entry is automatically removed from the Public View. Internal archive records may be retained longer for documentation purposes.
Solvra does not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Enforcement actions such as restrictions or bans are decided or reviewed by Solvra staff and can be appealed via dispute@solvra.gg.
You can object to the processing of your data at any time via dispute@solvra.gg. We will review your case based on the internal evidence and respond within one month (Art 12(3) GDPR; this period can be extended by two further months for complex requests, and we will tell you if that happens).
You can request information about the data we hold about you via privacy@solvra.gg.
You can request deletion of your data. Note that deletion requests for active Public View entries may be denied based on legitimate interest if evidence supports the action. We will respond to your request within one month (Art 12(3) GDPR) with a decision and reasoning.
You can ask us to correct inaccurate or incomplete data we hold about you via privacy@solvra.gg.
You can ask us to restrict processing of your data while a request or objection from you is being reviewed.
Where we process data you provided to us based on your consent or a contract by automated means (for example your Middleman application answers), you can request a copy in a structured, commonly used, machine-readable format via privacy@solvra.gg.
Where processing is based on your consent (for example optional analytics), you can withdraw it at any time via "Cookie Settings" in the footer or via privacy@solvra.gg. Withdrawing consent does not affect processing carried out before the withdrawal.
You have the right to lodge a complaint with the supervisory authority. In Austria: Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at.
Beyond the registry, Solvra processes Discord data in the normal course of Discord server operation (member list, moderation case records (see section 4.1), ticket transcripts). This processing is governed by the Discord Terms of Service and Discord Privacy Policy in combination with this notice. Legal basis: our legitimate interest in operating a safe and functional community (Art 6(1)(f) GDPR); for ticket transcripts and trade-related records, also the performance of the Middleman service you request (Art 6(1)(b) GDPR).
Retention: data under this section is kept only as long as needed for the purposes described above. Moderation notes are kept for at most 5 years after the last relevant entry; areas you exclude from logging are skipped or purged unless a ticket, dispute, enforcement case, or legal obligation requires retention. Trade-related records follow the periods in section 9.
[Founder: Aleksander Stojanovic; Geschaeftsadresse: virtuelle Adresse / Postfach, TBD nach Gewerbeanmeldung ~2026-07; contact: privacy@solvra.gg]
No data protection officer is appointed; this processing does not meet the Art 37 GDPR threshold.
We do not store non flagged message content. We keep no server wide message archive, no full chat log, no bulk export, no search index, no message embeddings, no attachment text extraction, and no voice transcription. We do not scan or store direct messages or group direct messages. We do not run AI or machine learning classification or training on your messages. We do not monitor or scrape external Discord servers. Channels or categories marked no log are never scanned for storage; use them if you want a retreat.
Legitimate interest, Art 6(1)(f) GDPR: community safety, scam and abuse prevention, network and information security (Recitals 47 and 49), fair moderation and appeals. We rely on a documented Legitimate Interest Assessment. We do not ask for your consent and we do not rely on consent. The real time scan is rule based and emits only a rule hit; it does not build, infer, label, or store any special category profile about you, and underlying content is deleted once a case decision is recorded. Whether this rule based scan engages Art 9 GDPR at all is a question not yet settled by an Austrian or EU data protection authority; we have designed the scan to avoid special category processing and we keep this under review.
Hetzner Online GmbH (Germany, case record hosting). Discord Inc. (USA, platform; independent controller). Cloudflare R2 (EU region) only if a closed case later needs evidence assets; no bulk export. Persons named or quoted in messages may be referenced; we rely on Art 14(5)(b) GDPR where direct notice is disproportionate.
Non flagged scanned content: not stored (zero retention). Flagged case records: 30 days by default; up to 90 days for bans or open investigations; longer only where needed for a specific legal claim or while a documented legal hold is active. Scan metadata without raw text: 30 days. Messages you delete are not retained unless they were already part of an open case. Anonymous aggregate statistics are kept indefinitely because they are designed to be non personal.
Access (Art 15), rectification (Art 16), erasure (Art 17), restriction (Art 18), objection (Art 21). To exercise them, contact privacy@solvra.gg or dispute@solvra.gg. We respond within one month.
This is a separate notice. You may object to this processing at any time on grounds relating to your particular situation. We will restrict the processing for you while we assess your objection, and we will reply within one month. We may continue only where we can demonstrate compelling legitimate grounds (for example, an active safety threat) or where the data is needed for legal claims. The founder carries out this assessment; there is no independent supervision of it, and you can always escalate to the Austrian Data Protection Authority.
Austrian Data Protection Authority (Datenschutzbehoerde), Barichgasse 40 to 42, 1030 Vienna, dsb.gv.at.
For Middlemen and staff, Solvra also processes ticket history, stats, performance metrics, supervisor feedback, incident records, and guide completion progress. This data is used for progression, team management, safety review, and operational reporting. Legal basis: performance of the cooperation with team members (Art 6(1)(b) GDPR) and our legitimate interest in safe, well-managed operations (Art 6(1)(f) GDPR).
If you apply for the Middleman team, we process your application answers, your Discord ID, how you reached the application (entry source), and basic processing metadata such as review status and timestamps. Legal basis: taking steps prior to entering a cooperation (Art 6(1)(b) GDPR). Rejected applications are anonymized after 6 months: the Discord ID is replaced with a neutral placeholder and internal notes and reviews are deleted. Approved applications remain part of the staff record for as long as you are on the team.
When you join the server, open a ticket, accept updated Rules, complete Middleman onboarding, or confirm a payment-method risk notice, Solvra stores a minimal proof record. This can include your Discord user ID, the policy or notice type, the policy version, the source of the acceptance, the ticket ID and guild ID where applicable, the selected payment method category, whether both traders confirmed the payment-method risk notice, and timestamps.
We do not store bank account numbers, card data, payment-account handles, wallet private keys, wallet seed phrases, screenshots, transaction payloads, or payment secrets in this proof layer.
Purpose: proving which terms, rules, guidelines, staff notices, and payment-method risk notices applied to a ticket or onboarding step; preventing fraud; handling disputes, chargebacks, fee/refund claims, appeals, and legal claims. Legal basis: performance of the service you request (Art. 6(1)(b) GDPR) and Solvra's legitimate interest in fraud prevention, dispute handling, and defending legal claims (Art. 6(1)(f) GDPR).
Retention: these proof records are kept as long as needed for open disputes, safety, chargebacks, payment-provider disputes, fee/refund claims, enforcement, and legal claims. If you request erasure, we may keep narrowly necessary proof records where retention is required for the establishment, exercise, or defence of legal claims (Art. 17(3)(e) GDPR). We will tell you which categories were retained.
Bot and user data is stored on secure servers provided by Hetzner (Germany). The website is hosted on Vercel. Trade evidence and attachments may be stored on Cloudflare R2. All data is handled in accordance with applicable data protection regulations.
We use the following first-party storage:
Optional analytics (Vercel Analytics, Speed Insights) run only if you choose "Accept All". You can change your choice anytime via "Cookie Settings" in the footer.
We use Sentry (Functional Software, Inc.) to detect technical errors. Legal basis: legitimate interest (Art 6(1)(f) GDPR) in a stable, secure service. IP addresses are removed before events are sent. Session replay is captured only for error sessions and masks text input by default.
Our hosting (Vercel) and error monitoring (Sentry) may process data in the United States. Both providers are certified under the EU-US Data Privacy Framework. Bot data and trade records stay on servers in Germany (Hetzner); assets are served via Cloudflare R2.
We use the following third-party services:
For all privacy-related inquiries: privacy@solvra.gg.
For dispute submissions: dispute@solvra.gg.
We may update this notice. The current version is always available at solvra.gg/privacy. The last updated date is shown at the top of this document.