← Back to legal

Community privacy policy

Updated July 22, 2026

Introduction

This policy explains how Vzla.io (“Vzla.io”, “we”, “us”) handles personal data when you take part in our community channels — the spaces we use to talk with users, answer questions, and gather feedback, primarily a group and community on Telegram (our “community channels”). Taking part in these channels means you understand how we handle information here.

We are a company registered in the United States. Even so, we have chosen to hold our community channels to the standard of the European Union’s General Data Protection Regulation (GDPR) and European data-protection law, because we believe it is the strongest, clearest privacy standard available and it reflects how we think privacy should work. We apply it to every member, wherever you are.

Our approach is privacy by default: we collect the minimum data we need to run the community and improve our products, we do not sell or rent personal data, and we do not use community data for advertising or profiling. “You” refers to any member or participant in our community channels.

Who is responsible for your data

Vzla.io is the data controller for the personal data described in this policy. Our legal entity name, registered address, and contact details are published in our imprint. For any privacy question or request, see the Contact section below.

Our community channels and third-party platforms

Our community channels run on third-party platforms — primarily Telegram. When you join and use such a platform, that platform is an independent data controller for the data it processes about you: your account, the messages you send, your device and connection data, and how you use the app. That processing is governed by the platform’s own privacy policy and terms, not by us, and we do not control it. We encourage you to read Telegram’s privacy policy to understand what it collects and how.

This policy covers only what we do with information within those channels. It does not, and cannot, change how the underlying platform handles your data.

Data we collect

We keep data collection deliberately small. Within our community channels we may process the following.

Information visible to us because you share it in the channel:

  • Your platform username or display name and, if you choose to show it, your profile picture — as the platform makes them visible to other members.
  • The content of the messages, questions, comments, suggestions, and discussions you post in the channel.
  • Feedback and survey responses — the input you choose to share about our tools, features, and ideas.

Information we may keep outside the platform:

  • Feedback, ideas, and suggestions we record so we can act on them (for example, a note of a feature request), together with the context needed to follow up.
  • Moderation records — where we need to note a rule violation, a warning, a mute, or a removal to keep the community safe (see Moderation).

Aggregate insight:

  • General trends, needs, and usage patterns drawn from community activity, analysed in aggregate and, wherever possible, without identifying any individual.

We do not ask for, and do not want, special-category data (such as data about your health, ethnicity, religion, or political views). Please do not share it in the channel. We also ask you not to post other people’s personal data.

Lawful bases for processing

Under Article 6 of the GDPR, we process personal data only where we have a lawful basis to do so:

  • Legitimate interests (Art. 6(1)(f)) — to run and moderate the community, respond to members, understand aggregate feedback, and improve our products and services. We limit this processing to what is necessary and balance it against your rights and freedoms.
  • Consent (Art. 6(1)(a)) — where you voluntarily share feedback, ideas, or survey responses for us to use in developing our products. Joining and posting in the channel is entirely voluntary; you can stop and leave at any time.
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with the law.

How we use data

We use the information we process to:

  • Run the community, answer questions, and respond to members.
  • Understand feedback, ideas, and aggregate needs so we can improve our products and services and identify what to build next.
  • Moderate the channel and keep it safe and welcoming.
  • Comply with legal obligations.

We do not use community data to build advertising profiles, we do not sell or rent it, and we do not make decisions about you based solely on automated processing.

Moderation

To keep the community safe, respectful, and useful, we and our moderators may read messages posted in the channel and act on them — for example by removing content that breaks our rules, warning, muting, or removing a member. Where necessary we keep a limited record of such actions (for example, the reason for a removal) so we can apply our rules consistently. The lawful basis for this is our legitimate interest in maintaining a safe community. See also our code of conduct.

Sharing your data

We do not sell or rent your personal data, and we never share it for advertising.

We share personal data only when necessary and only with:

  • The platform provider (for example, Telegram), which processes your data as an independent controller under its own policy, as described above.
  • Service providers who process data on our behalf under a data-processing agreement, limited to what they need to perform their service.
  • Authorities or advisors where we are required to disclose data by law, or to establish, exercise, or defend legal claims.

Please also remember that anything you post in a community channel is visible to other members of that channel. Treat it as public.

International data transfers

We are based in the United States, and our community platform and service providers may be located in the United States or elsewhere. Taking part in the community can therefore involve transferring personal data from the European Economic Area (EEA) or the United Kingdom to countries outside them.

For transfers to providers that process data on our behalf, we apply appropriate safeguards required by GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum where relevant).
  • Reliance on the EU–U.S. Data Privacy Framework (and its UK extension) where a provider is certified under it.
  • Data minimisation.

Transfers carried out by the community platform itself are governed by that platform’s own policy and safeguards. You can contact us for more information about the safeguards that apply to a specific transfer we control.

Data retention

We keep personal data only for as long as we need it for the purpose it was collected, or as required by law:

  • Messages in the channel — these live on the platform and are retained under the platform’s own policy. We do not keep our own copy of conversation history beyond what is relevant to running the community and developing our products.
  • Feedback and ideas we record — kept for as long as they are useful to product development, then deleted or fully anonymised.
  • Moderation records — kept only for as long as needed to apply our rules and address repeat issues, then deleted.
  • Aggregate insight — anonymised, so it is not tied to you.

When data is no longer needed, we delete or anonymise it. If you leave the community, deleting your account or messages on the platform is governed by the platform’s controls; we will delete personal data we hold outside the platform on request, subject to any legal obligation to retain it.

Your rights

Under the GDPR you have the following rights over the personal data we control:

  • Access — to know whether we process your data and to obtain a copy of it (Art. 15).
  • Rectification — to have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — to have your data deleted in the circumstances the law provides (“right to be forgotten”, Art. 17).
  • Restriction — to limit how we process your data in certain cases (Art. 18).
  • Data portability — to receive data you provided in a structured, commonly used, machine-readable format (Art. 20).
  • Objection — to object to processing based on our legitimate interests (Art. 21).
  • Withdraw consent — at any time, where processing is based on your consent, without affecting prior processing (Art. 7).

These rights apply to data we control. For data held by the community platform (such as your account and the messages stored on it), you exercise your rights directly with that platform. To exercise your rights with us, contact us. We respond without undue delay and within one month at the latest, as the GDPR requires. Exercising your rights is free of charge in normal cases.

Security

We use appropriate technical and organisational measures to protect the personal data we hold against loss, misuse, and unauthorised access, including restricted access to feedback and moderation records. The security of the community platform itself is provided by the platform. No method of transmission or storage is completely secure, but we work to keep our safeguards current.

Children’s privacy

Our community channels are not directed at children, and we do not knowingly collect personal data from children. Many platforms, including Telegram, set their own minimum age. If you believe a child has shared personal data with us, contact us and we will delete it.

Changes to this policy

We keep this policy under periodic review. When we make material changes, we update the date at the top of this page and, where appropriate, announce it in the community channel.

Contact

For privacy questions or to exercise your data-protection rights, use the privacy contact in our website privacy policy. For general community matters, contact us at community@vzla.io.

Right to lodge a complaint

If you are in the EEA or the UK and believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data-protection supervisory authority. A list of EEA authorities is available from the European Data Protection Board (edpb.europa.eu); in the UK, the authority is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first, so please consider contacting us before you do.