diff --git a/src/app/dsa/page.tsx b/src/app/dsa/page.tsx new file mode 100644 index 00000000..f1904644 --- /dev/null +++ b/src/app/dsa/page.tsx @@ -0,0 +1,291 @@ +export default function DsaPage() { + return ( +
Last updated: March 14, 2026
+ ++ This page provides information required under the Digital Services Act (Regulation + (EU) 2022/2065) ("DSA") regarding the hosting services operated by the + Hypercerts Foundation in connection with Certified. +
++ Certified operates AT Protocol Personal Data Servers (PDS) that store and serve + identity records and associated user data. Under the DSA, this qualifies as a{" "} + hosting service as defined in Article 3(g)(iii). +
+
+ Hypercerts Foundation
+
A Delaware nonstock corporation
+
+ Contact:{" "} + + legal@hypercerts.org + +
++ In accordance with Article 13 of the DSA, the Hypercerts Foundation has designated + the following legal representative in the European Union: +
+
+ Holke Brammer
+
+ Holzmarktstraße 25, 10243 Berlin, Germany
+
+
+ legal@hypercerts.org
+
+
+ In accordance with Article 11 of the DSA, the single point of contact for + communications with EU member state authorities, the European Commission, and the + European Board for Digital Services is: +
+ +Communications may be submitted in English.
++ The same address serves as the point of contact for recipients of the service in + accordance with Article 12 of the DSA. +
++ Any individual or entity may notify the Hypercerts Foundation of the presence of + specific items of information that the notifier considers to be illegal content, in + accordance with Article 16 of the DSA. +
+ +Notices should be sent to:
+ ++ To enable effective processing, a notice should include: +
+Upon receipt of a notice, the Hypercerts Foundation will:
+Decisions are made on the basis of applicable law.
++ The Hypercerts Foundation does not routinely monitor the information stored on + Personal Data Servers and has{" "} + no general obligation to monitor information stored through the + services in accordance with Article 8 of the Digital Services Act. +
++ The Hypercerts Foundation may take appropriate measures to address{" "} + + manifestly unfounded notices or repeated abusive submissions + + , including limiting the ability of the notifier to submit future notices where + permitted by applicable law. +
++ As described in the{" "} + + Terms of Service + + , the Hypercerts Foundation may restrict access to content or suspend accounts in + the following circumstances: +
++ Certified operates as infrastructure within a federated network architecture. + Content stored through Personal Data Servers may be replicated, cached, indexed, or + displayed by independent servers or applications outside the control of the + Hypercerts Foundation. +
++ The Hypercerts Foundation does not apply editorial content policies, operate + recommendation systems, or curate user content. Certified is infrastructure, not a + social media platform. +
++ In accordance with Article 17 of the DSA, when the Hypercerts Foundation restricts + access to content or suspends an account, it will provide the affected user with a + clear and specific statement of reasons, including: +
++ In accordance with Article 20 of the DSA, users who are affected by a content + restriction or account suspension decision may submit a complaint to: +
+ ++ Complaints will be processed in a timely and non-discriminatory manner. Users will + be informed of the outcome and the reasoning behind the decision. +
++ Where the Hypercerts Foundation receives notices from entities designated as{" "} + trusted flaggers under Article 22 of the Digital Services Act, such + notices will be prioritized and processed without undue delay. +
++ The Hypercerts Foundation will publish{" "} + annual transparency reports in accordance with Article 15 of the + DSA, including information on: +
++ The Hypercerts Foundation is not responsible for content moderation decisions made by + third-party applications that access data through the AT Protocol. +
++ Moderation policies applied by other services are outside our control and do not + reflect actions taken by the Hypercerts Foundation. +
+Last updated: March 14, 2026
+ ++ This Privacy Policy explains how the Hypercerts Foundation ("Hypercerts + Foundation", "we", "our", or "us") processes + personal data in connection with the Certified services. +
+Certified consists of:
++ The Hypercerts Foundation operates these services as identity and data hosting + infrastructure for the AT Protocol ecosystem. +
+This Privacy Policy explains:
++ For the purposes of the EU General Data Protection Regulation (GDPR), the data + controller is: +
+
+ Hypercerts Foundation
+
+ 1209 Orange St.
+
+ Wilmington, DE 19801
+
+ United States
+
+ Phone: +1 302 658 7581
+
+ Contact:{" "}
+
+ legal@hypercerts.org
+
+
+ For data stored on Personal Data Servers, the Hypercerts Foundation acts as an{" "} + + infrastructure provider operating the server environment in which user-controlled + data is stored + + . +
+ ++ In accordance with Article 27 of the GDPR, the Hypercerts Foundation has designated + the following representative in the European Union: +
+
+ Holke Brammer
+
+ Holzmarktstraße 25
+
+ 10243 Berlin
+
+ Germany
+
+ The personal data processed by Certified depends on how you use the services. +
+ ++ When you create or manage an account using certified.app, we may process: +
++ certified.one operates Personal Data Servers that store records associated with AT + Protocol identities. +
+These records may include:
++ This data is stored at the direction of users and may contain personal data depending + on how the user uses the service. +
+ +To operate the services, we may process:
++ System logs and security-related operational data may be retained for limited periods + necessary to detect abuse, investigate incidents, and maintain service reliability. +
++ We process personal data only where necessary for the operation of the services. +
+This may include processing necessary to:
++ Where the GDPR applies, personal data is processed on the following legal bases: +
+ +Processing necessary to provide the services requested by the user.
+ +Processing necessary to:
++ Processing required to comply with applicable laws or regulatory requirements. +
+ ++ Where applicable, certain processing may be based on your consent. Where consent is + the legal basis, you have the right to withdraw consent at any time. Withdrawal of + consent does not affect the lawfulness of processing carried out before the + withdrawal. +
++ The infrastructure supporting certified.one Personal Data Servers is currently hosted + on cloud infrastructure located within the{" "} + European Union. +
++ Operational service providers may process limited data outside the European Union. + Where this occurs, appropriate safeguards are implemented in accordance with + applicable data protection laws. +
++ Certified operates within the AT Protocol, a federated network + architecture. +
++ When users publish records through their Personal Data Server, those records may be: +
++ by independent servers or applications participating in the network. +
++ Once data is shared through the federated network, the Hypercerts Foundation cannot + control how third-party services process or store that information. Those services act + as independent data controllers for any processing they perform. +
+We do not sell personal data.
++ Personal data may be shared only in limited circumstances, including: +
++ certified.app uses only cookies that are strictly necessary for the operation of the + service, such as session management and authentication. +
++ We do not use advertising cookies, third-party tracking pixels, or analytics cookies + that track individual users across websites. +
++ If our use of cookies changes in the future, we will update this policy and provide + appropriate notice and controls. +
++ We retain personal data only for as long as necessary to operate the services and + fulfill legal obligations. +
++ Retention periods may vary depending on the type of data and applicable legal + obligations. +
++ If you close your account, we will delete account-related data from our infrastructure + within a reasonable period, subject to: +
++ As described above, data previously shared through the AT Protocol network may + continue to exist on third-party systems. +
++ We implement reasonable technical and organizational measures to protect the security + of the services and the data stored on them. +
++ However, no system can guarantee complete security. Users are responsible for + protecting their account credentials and cryptographic keys associated with their AT + Protocol identities. +
++ The services are not directed at individuals under the age of 16. The Hypercerts + Foundation does not knowingly collect personal data from individuals under 16 years of + age, or under the minimum age required to consent to data processing under applicable + law in the user's jurisdiction. +
++ If we become aware that personal data has been collected from an individual under the + applicable minimum age without appropriate authorization, we will take steps to delete + that data. +
++ Where applicable under data protection laws such as the GDPR, individuals may have + the right to: +
+Requests may be submitted to:
+ ++ We will respond to requests within one month, or inform you if an extension is + necessary in accordance with applicable law. +
++ Certified is operated from infrastructure located primarily within the European Union + but may be accessed globally. +
++ If you access the services from outside the European Union, your data may be processed + in jurisdictions outside your country of residence, subject to the safeguards + described in Section 6. +
+We may update this Privacy Policy from time to time.
++ When changes are material, we will provide notice through certified.app or other + appropriate communication channels. +
++ The most recent version of this policy will always be available on the Certified + website. +
++ For privacy inquiries, data protection requests, or questions about this policy, + contact: +
+
+ Hypercerts Foundation
+
+ 1209 Orange St.
+
+ Wilmington, DE 19801
+
+ United States
+
+ Phone: +1 302 658 7581
+
+ Email:{" "}
+
+ legal@hypercerts.org
+
+
Last updated: March 14, 2026
+ ++ Certified is operated by the Hypercerts Foundation ("Hypercerts + Foundation", "we", "our", or "us"), a Delaware + nonstock corporation that develops and maintains open infrastructure for the + hypercerts ecosystem. +
+The Certified services consist of two components:
++ These services provide identity and data hosting infrastructure for the AT Protocol + ecosystem. +
++ Certified is not a social media platform. We do not operate feeds, rank content, + recommend posts, or curate speech. Applications that display or process user data are + operated independently by third parties. +
++ Certified is part of an evolving technical ecosystem built on the AT Protocol, an + open and developing standard. +
++ Features, interoperability, and functionality may change as the protocol evolves. The + Hypercerts Foundation does not guarantee that the services will remain compatible with + all future versions or implementations of the protocol. +
++ The services are provided as technical infrastructure for identity and data hosting, + not as a platform for transactions or agreements between users. +
++ The Hypercerts Foundation is not a party to any agreements, interactions, or + transactions between users or between users and third-party applications. +
++ By creating an account, accessing certified.app, or using certified.one, you agree to + be bound by these Terms of Service and the Certified Privacy Policy (together, the + "Agreement"). +
++ If you do not agree to these Terms, you may not use the services. +
++ You must be at least 16 years old, or the minimum age required to consent to data + processing under applicable law in your jurisdiction. +
++ Certified provides tools and infrastructure that allow users to operate an AT Protocol + identity. +
++ You retain ownership of the content, records, and data associated with your account. + The Hypercerts Foundation does not claim ownership of user content. +
+Users are solely responsible for:
++ You determine which applications or services may access your data. +
++ Because the AT Protocol operates as a federated network, data published through your + Personal Data Server may be made available to other servers and + applications as part of normal protocol operation. This includes replication, caching, + indexing, and display by third-party services you interact with. +
++ The Hypercerts Foundation is not responsible for how third-party services process, + display, or use such data. +
++ The Hypercerts Foundation retains all rights, title, and interest in the services, + including all software, interfaces, trademarks, and other intellectual property + associated with Certified. +
++ Nothing in these Terms grants you any right, title, or interest in the Hypercerts + Foundation's intellectual property, except the{" "} + + limited, non-exclusive, non-transferable right to use the services in accordance + with these Terms + + . +
++ User content remains the property of the user, as described in Section 4. +
++ You may use Certified only for lawful purposes and in a manner that does not + interfere with the operation or stability of the services. +
+You agree not to:
++ The Hypercerts Foundation may implement technical measures such as rate limiting, + automated abuse detection, traffic filtering, or temporary access restrictions in + order to protect the stability and security of the services. +
++ Where necessary to comply with law or protect infrastructure integrity, the Hypercerts + Foundation may restrict access to certain data, limit functionality, or suspend + accounts. +
++ certified.one hosts Personal Data Servers that store AT Protocol identity records and + related user data. +
++ The infrastructure supporting these servers is{" "} + currently hosted on cloud infrastructure located within the European + Union. +
++ To operate the services, we may rely on specialized third-party providers for + operational tasks such as: +
++ Some of these providers may process limited data outside the European Union. Such + processing occurs in accordance with applicable data protection laws and appropriate + safeguards. +
++ The services may interact with or reference third-party applications, websites, or + services. +
++ These services are operated independently and governed by their own terms and + policies. The Hypercerts Foundation does not control and is not responsible for the + operation or content of third-party services. +
+Your use of such services is at your own discretion.
++ Personal data is processed in accordance with applicable data protection laws, + including the EU General Data Protection Regulation (GDPR) where applicable. +
+Our Privacy Policy explains:
++ The Hypercerts Foundation does not routinely monitor all information stored on Personal + Data Servers. +
+However, we may take action where necessary to:
++ Such actions may include restricting access to specific records or suspending accounts. +
++ The Hypercerts Foundation may rely on{" "} + automated systems or third-party services to assist in identifying or + responding to unlawful content, infrastructure abuse, or security threats. +
++ The Hypercerts Foundation is not responsible for content moderation decisions made by + third-party applications that access data through the AT Protocol. Moderation policies + applied by other services are outside our control and do not reflect actions taken by + the Hypercerts Foundation. +
++ Reports of illegal content may be submitted in accordance with the notice-and-action + procedure described in our{" "} + + DSA Compliance Page + + . +
++ Reports and legal notices may also be sent to:{" "} + + legal@hypercerts.org + +
+Certified services are provided on a best-effort basis.
++ Maintenance, system updates, or security work may result in temporary interruptions. +
++ The Hypercerts Foundation may modify, suspend, or discontinue all or part of the + services at any time. Where reasonably possible, we will provide advance notice of + material changes or service discontinuation. +
++ Because the AT Protocol operates as a federated network, data published through the + services may be copied, cached, or stored by other servers or applications. +
++ The Hypercerts Foundation cannot guarantee that data removed from its infrastructure + will also be removed from third-party systems. +
++ You are responsible for protecting your account credentials and authentication + information. +
++ If you believe your account has been compromised, you must notify us promptly at{" "} + + legal@hypercerts.org + + . +
++ Access to accounts may be temporarily restricted while security investigations are + conducted. +
++ Because AT Protocol identities rely on cryptographic credentials, recovery of accounts + may not be possible if credentials are permanently lost. +
++ You may close your account at any time by using the account closure functionality + provided through certified.app, or by contacting us at{" "} + + legal@hypercerts.org + + . +
+ ++ The Hypercerts Foundation may suspend or terminate your account if: +
++ Where reasonably possible, we will provide notice before terminating an account. In + cases involving security threats, legal obligations, or infrastructure abuse, immediate + action may be taken without prior notice. +
+ ++ Upon termination, your access to the services will cease. The Hypercerts Foundation + will delete your account data from its infrastructure within a reasonable period, + subject to any legal retention obligations. +
++ As described in Section 12, data previously published through the AT Protocol may + continue to exist on third-party servers or applications. The Hypercerts Foundation + cannot ensure deletion of such data from federated systems. +
+ ++ Sections 5 (intellectual property), 12 (data persistence), 15 (feedback), 16 + (disclaimer of warranties), 17 (limitation of liability), 18 (indemnification), 19 + (consumer protections), and 23 (governing law) survive termination of these Terms. +
++ If you provide suggestions, ideas, or feedback regarding the services, the Hypercerts + Foundation may use such feedback{" "} + for any purpose, without restriction or compensation. +
++ The services are provided "as is" and "as available." +
++ The Hypercerts Foundation makes no representations or warranties regarding the + reliability, availability, or accuracy of the services. +
++ To the maximum extent permitted by law, we disclaim all warranties, express or + implied, including warranties of merchantability, fitness for a particular purpose, and + non-infringement. +
++ You understand that your use of the services is at your own discretion and risk. +
++ Nothing in these Terms limits liability where such limitation is prohibited by law. +
++ To the maximum extent permitted by law, the Hypercerts Foundation is not liable for + indirect, incidental, or consequential damages arising from the use of the services. +
++ Where liability cannot be excluded, the Hypercerts Foundation's total liability{" "} + arising out of or relating to the services is limited to: +
++ To the extent permitted by applicable law, you agree to indemnify and hold harmless + the Hypercerts Foundation from claims, damages, losses, and expenses (including + reasonable legal fees) arising from: +
++ This indemnification obligation does not apply to consumers where prohibited by + applicable consumer protection law. +
++ If you use the services as a consumer, you may have mandatory rights under applicable + consumer protection laws. Nothing in these Terms limits those rights. +
++ If any provision of these Terms is found unenforceable by a court of competent + jurisdiction, the remaining provisions will continue to apply. +
++ The failure of the Hypercerts Foundation to enforce any provision of these Terms does + not constitute a waiver of that provision or any other provision. +
++ The Hypercerts Foundation may update these Terms from time to time. We will notify + users of material changes by posting a notice on certified.app and, where practicable, + by email or other direct communication at least 30 days before the changes take + effect. +
++ The updated Terms will indicate the date of the most recent revision. Your continued + use of the services after the effective date of the updated Terms constitutes + acceptance of the changes,{" "} + to the extent permitted by applicable law. +
++ If you do not agree with the updated Terms, you may close your account in accordance + with Section 14. +
++ Users may not transfer their rights or obligations under these Terms without the prior + written consent of the Hypercerts Foundation. +
++ The Hypercerts Foundation may assign or transfer its rights or obligations as part of + organizational restructuring or transfer of the services. +
++ These Terms are governed by the laws of the State of California, regardless of + conflict of laws rules. +
++ Any disputes arising out of or relating to these Terms will be resolved exclusively in + the federal or state courts located in San Francisco County, California, and you + consent to the personal jurisdiction of those courts. +
++ If you are a consumer in the European Union, this section does not affect any mandatory + consumer protections or jurisdictional rights available to you under the laws of your + country of residence. +
++ These Terms of Service and the Certified Privacy Policy constitute the entire + agreement between you and the Hypercerts Foundation regarding the services and + supersede all prior understandings, communications, or agreements relating to the + subject matter. +
++ For all inquiries — including support, legal notices, Digital Services Act + communications, and privacy matters: +
+ +