ASSA

Privacy Policy

ASSA is a service that lets streamers who broadcast to YouTube, Twitch and Kick at the same time manage their moderators' permissions in one place. This policy explains what personal data ASSA processes, why, and what rights you have over it.

ASSA is a preunec GmbH product. Because the company is an EU entity and the service is also offered to users in Türkiye, both the General Data Protection Regulation (GDPR) and Turkish Law No. 6698 on the Protection of Personal Data (KVKK) apply.

Data controller

The data controller is preunec GmbH. [preunec GmbH — registered address to be added]

For any request or question about your personal data: [privacy contact address to be added]

What we process

ASSA collects only what it needs to provide the service. The table below lists every category of data we hold, what it is for, and the legal basis for holding it.

DataWhat forLegal basis
Email address, first and last nameCreating your account, verifying your sign-in, and sending you service notificationsPerformance of a contract
Your passwordStored only as an irreversible argon2id hash. The password itself is never recordedPerformance of a contract
Linked platform accounts (platform id and username)Matching your account on a streaming platform to your ASSA accountPerformance of a contract
Platform access and refresh tokensAssigning moderators and reading the moderator list on your behalf. Stored encrypted with AES-256-GCMPerformance of a contract
Workspace, memberships and granted capabilitiesDetermining who holds which permission — the core of the servicePerformance of a contract
Audit eventsA record of moderator actions taken on the streaming platforms. Contains data about third parties — see the separate section belowLegitimate interest
IP address and security logsDetecting abuse and rate-limit violationsLegitimate interest

Third parties affected by a moderation action

This is the part of ASSA that needs the most care, and it deserves its own explanation.

ASSA observes moderator activity on the streaming platforms. When a moderator times out or bans a viewer, that action is recorded in ASSA's audit trail — and that viewer never signed up for ASSA and in most cases does not know it exists.

We deliberately keep what we hold about those people to a minimum: their platform user id and display name, and nothing else. We do not store message history, conversation content or profile information.

The legal basis is legitimate interest: a broadcaster needs to know what happens on their own channel and to be able to detect actions taken outside somebody's permissions. Audit events are deleted after 12 months.

If you believe you appear in such a record and want your data removed, contact us at [privacy contact address to be added].

Google user data

When you link your YouTube account, ASSA accesses it through Google APIs. ASSA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: we use data from your Google account only to do the job ASSA does for you — identifying your channel and, when you ask for it, assigning moderators. We do not use it for advertising, do not sell it, do not allow humans to read it, and do not process it for any other purpose.

How we protect platform tokens

Platform access tokens carry the authority to act on your behalf, so they get special treatment.

Tokens are stored encrypted with AES-256-GCM and the encryption key is held outside the application. They never appear in a log line, an error message or an API response.

When you unlink a platform, ASSA forgets the token. There is a limit to what that means and we would rather say it plainly: ASSA deleting the token does not withdraw the permission the platform granted. To remove it completely you also need to revoke ASSA's access in that platform's own account settings.

Who we share data with

ASSA does not sell your personal data and does not share it for advertising.

Data is passed only to the parties the service needs to function:

How long we keep it

We do not keep data for longer than it is needed.

Your rights

Under GDPR and KVKK you have the following rights over your personal data:

How to exercise them

You can change your account details — your name, email address, password and linked platform accounts — directly in the account settings screen inside the application.

For full deletion of your account, or a copy of your data, write to [privacy contact address to be added]. We will respond within one month.

What ASSA cannot do

We state this as part of the policy because setting the right expectation is part of privacy.

ASSA is a governance layer: it decides who is permitted to do what, projects that intent onto the platforms, and records what happened. It cannot **prevent** an action that takes place on a streaming platform. Platforms grant moderators full native powers and ASSA cannot narrow them. When an action falls outside somebody's permissions, ASSA detects and reports it — it does not stop it in advance.

Changes to this policy

We may update this policy from time to time. If a change is significant we will notify the email address on your account. The date at the top of the page is when the text was last updated.