1. Who we are and when this policy applies
Decennium Platforms Limited (Decennium, Moduly, we, us, or our) is incorporated in Hong Kong SAR. For account, website, billing, security, support, product-improvement, and our own marketing data, Decennium is normally the controller or equivalent responsible organisation.
A business customer may be a controller or processor of personal data placed in its Brand Brain, campaign, evidence library, customer list, approval workflow, or connected channel. Where we process that data only on the customer’s documented instructions, we act correspondingly as processor or subprocessor, or as the equivalent service provider. The customer must give its own notices and establish a lawful basis, or have the relevant controller's authority to instruct us. The Data Processing Addendum incorporated into the Terms, or a signed replacement, controls if it conflicts with this policy for processor data.
This policy covers moduly.club, Moduly workspaces, supported APIs, and Moduly-controlled support and communications. It does not govern a third-party site, channel, payment page, identity provider, or published post once that third party processes data for its own purposes.
2. Personal data we handle
Depending on how Moduly is used, we may handle:
- identity and account data, such as name, work email, profile image, language, authentication provider identifier, verification status, and security events;
- organisation data, including company name, role, invitations, membership, approvals, audit actions, and authorised contacts;
- Brand Brain and campaign data, including prompts, product facts, evidence, sources, audiences, drafts, comments, images, audio, video, approvals, and publishing destinations;
- connector data, such as channel account identifiers, granted scopes, encrypted or otherwise protected credentials, destination metadata, publish receipts, and disconnect events;
- billing and transaction data, such as plan, currency, tax location, Stripe customer and subscription identifiers, invoice status, refunds, and limited payment metadata—but not full card numbers held by Stripe;
- usage, device, and diagnostic data, including IP address, browser, timestamps, pages and functions used, generation units, error logs, security signals, and support correspondence; and
- essential cookie and local-storage data for session security, language, fraud prevention, and requested functionality.
3. Where data comes from
We receive data from you, your organisation’s users and administrators, your browser or device, Stripe, Google or Peqaboo sign-in, connected publishing services, support interactions, and service providers operating on our behalf.
We may also use public or licensed pet-product, brand, safety, regulatory, and editorial sources to build Catalog and Radar candidates. Public-source records are kept separate from owner-confirmed brand truth. If public-source data identifies a person, we use it only where lawful and provide required notices or exceptions under applicable law.
4. Purposes and legal bases
We process personal data only for defined purposes and under a legal basis available in the relevant jurisdiction, including:
- performing a contract: creating accounts, providing workspaces, generating requested material, enforcing roles, publishing approved content, billing, and support;
- legitimate interests: securing the Service, preventing abuse, maintaining audit integrity, improving reliability, measuring business performance, and communicating with business customers, balanced against individual rights;
- legal obligations: tax and accounting records, lawful requests, sanctions, fraud prevention, consumer rights, privacy requests, and incident response; and
- consent: optional communications, non-essential tracking, or connector permissions where consent is required and can be withdrawn.
5. AI processing and human decisions
When you request generation or review, relevant prompts, brand instructions, product facts, source extracts, and draft material may be sent to configured AI and media providers. We limit the data sent to what the task requires and apply contractual, configuration, access, and logging controls appropriate to the provider. The active provider and subprocessor inventory must be approved before this policy can be activated and is available on request.
AI is used to draft, classify, extract, transform, and flag risk. Moduly does not treat AI output as veterinary, legal, or regulatory approval. P0 rules can automatically block publishing, but final approval and publication require an authorised person. We do not make solely automated decisions that produce legal or similarly significant effects about individual consumers through the marketing-content workflow.
7. International transfers
Decennium is based in Hong Kong and providers or customers may operate in other countries. Data may therefore be accessed or processed outside your location. Protection and government-access rules can differ by country.
Before enabling or relying on any restricted transfer, we will put in place an available lawful mechanism, such as an adequacy decision, completed European Commission Standard Contractual Clauses, a completed UK International Data Transfer Agreement or Addendum, and any required supplementary security measures. Until the applicable mechanism and customer-specific schedules are completed, we will not enable or rely on that restricted transfer. You may request information about the mechanism relevant to your data, subject to necessary redaction of confidential information.
8. Retention and deletion schedule
We retain data only while needed for the purpose described, a customer instruction, security, dispute resolution, or law. Before this policy can take effect, production retention jobs and operating procedures must match the following schedule:
- active account, Brand Brain, campaign, and asset data: for the subscription or account life, then normally deleted or de-identified within 90 days after a verified closure request;
- rolling disaster-recovery backups: normally expire within 35 days and are restored only for continuity or security;
- authentication, diagnostic, and ordinary security logs: normally up to 12 months, longer only for an active incident, abuse investigation, or legal duty;
- connector credentials: revoked or deleted after disconnect, subject to short-lived caches and backup expiry;
- billing, tax, refund, approval, claim-review, usage-settlement, publish-receipt, privacy-request, and legal audit records: up to seven years, or longer only where law or a live dispute requires; and
- support records: normally up to three years after the case closes, unless attached to a longer-lived legal, billing, security, or privacy record.
9. Your choices and privacy rights
Depending on your location and our role, you may ask to access, receive a copy of, correct, delete, restrict, or object to processing of personal data; withdraw consent; opt out of certain marketing; or complain to a privacy regulator. You may also have rights concerning portability, international-transfer safeguards, or appeal of a denied request. Hong Kong and Taiwan users may exercise applicable access, copy, correction, cessation, and deletion rights.
Signed-in users can request a personal export, authorised owners or administrators can request an organisation export, and users can create an account-deletion request in Settings → Data & privacy. A deletion request is not immediate deletion: we verify identity, organisation authority, active subscriptions, sole-owner status, security, legal holds, and records that must be retained. You can also email privacy@decennium.app. We may request proportionate identity evidence and will respond within the legally required period.
We do not sell personal data for money. Before using personal data for cross-context behavioural advertising, targeted advertising, or another activity treated as a sale or sharing under applicable law, we would provide required notice and opt-out controls. Moduly does not currently use non-essential advertising cookies.
11. Security and incidents
We use proportionate technical and organisational safeguards such as scoped access, server-side authorisation, encryption in transit, protected secrets, audit records, approval hashes, backup and recovery controls, dependency review, and monitoring. Security measures evolve with risk, and no service can promise absolute security.
If a personal-data incident occurs, we investigate, contain, preserve evidence, assess risk, and notify affected customers, individuals, or authorities when required. Customers must notify us promptly of compromised accounts, connector credentials, or unlawfully uploaded data at privacy@decennium.app.
12. Children
Moduly is a business service and is not directed to children. A person under 18 may not create or administer an account. Do not upload children’s personal data unless your organisation has a documented lawful purpose, all required permission and safeguards, and the data is necessary for the requested service. Contact us if you believe a child created an account or data was uploaded improperly.
13. Changes, complaints, and contact
We may update this policy when our services, providers, or legal duties change. We will publish the new version and provide additional notice of material changes where required. A newly edited version cannot become effective until its version is separately approved through the release gate.
Privacy questions, requests, and complaints: privacy@decennium.app. General contact: Decennium Platforms Limited, Entrepreneurship Centre, Level 5, Core F, Cyberport 3, 100 Cyberport Road, Hong Kong; hello@decennium.app. You may also complain to the privacy authority where you live or work, subject to its jurisdiction.