Roles and scope
For personal data a business customer submits or directs MoonHold to process, the customer is the controller or business and Moonsters DAO LLC is the processor or service provider. MoonHold may act as an independent controller for account administration, billing, security, fraud prevention, and legal compliance.
Processing instructions
MoonHold processes customer data only to provide the contracted service, follow documented workspace configuration, maintain security, comply with law, and meet the customer's documented instructions. Instructions that violate law or platform rules may be refused.
Processing details
- Subject matter: wallet ownership verification, eligibility evaluation, community access management, feeds, support, billing, and security.
- Duration: the subscription plus the retention and deletion periods in the Privacy Notice.
- People: customer administrators, community members, wallet holders, and people interacting with connected Discord or Telegram destinations.
- Data: identifiers, public wallet addresses and holdings, eligibility evidence, membership and role state, integration destinations, marketplace events, support, billing references, and operational records.
Security and confidentiality
MoonHold maintains role and tenant access controls, server-only provider credentials, encrypted transport, audit trails, monitoring, dependency checks, backups subject to provider configuration, and incident procedures. People authorized to process customer data must be bound to confidentiality appropriate to their role.
Subprocessors
The customer authorizes the providers in MoonHold's subprocessor list. MoonHold remains responsible for appropriate contractual protections and will provide reasonable notice of material additions where required.
Requests, incidents, and audits
Taking account of the nature of processing, MoonHold will reasonably assist with verified data-subject requests, security incidents, deletion, and legally required assessments. MoonHold will notify affected customers of a confirmed personal-data breach without undue delay as required by law. Reasonable documentation is the default audit method; intrusive audits require advance agreement and appropriate safeguards.
Return, deletion, and transfers
Customers may export available data. At termination or valid request, MoonHold deletes eligible data under its retention schedule, subject to legal holds, disputes, accounting duties, and backup expiration. International-transfer terms, including any required standard contractual clauses or UK addendum, must be added after launch geography and qualified legal review are confirmed.
Order of precedence
Once approved and executed, this addendum will control over conflicting service terms for its subject matter. This review draft is not yet an executed agreement.