Privacy Policy

Last updated: 26/09/2026

Norsk versjon (Personvernerklæring)

1. Introduction and scope

This Privacy Policy explains how News Targeted (operating at newstargeted.com) processes personal data when you use the Enhanced Webhook Proxy at webhook.newstargeted.com (the "Service"). It is written for users in the European Economic Area (EEA), the United Kingdom, and others who receive protection under the EU General Data Protection Regulation (GDPR) or equivalent law.

We do not sell your personal data. We process data only as described here and in our Terms of Service.

2. Data controller and processor roles

2.1 News Targeted as controller

For account sign-in, dashboard use, abuse prevention, billing-related records (if any), and Service-wide security logs, News Targeted is the data controller.

Controller contact: [email protected]

2.2 News Targeted as processor

When you or your organisation sends webhook payloads through the Service to Discord or other destinations, you decide what personal data is included. In that flow News Targeted typically acts as a data processor, forwarding data on your documented instructions (your webhook calls and configuration). You remain responsible for having a lawful basis to collect and send that data, and for your relationship with Discord and end users.

2.3 Discord and other recipients

Discord Inc. and other platforms you target via webhooks are separate controllers for data they receive. Their policies apply once data is delivered.

3. Legal bases (GDPR Article 6)

We rely on the following legal bases, depending on the processing activity:

  • Contract (Art. 6(1)(b)): Providing the webhook proxy, authentication, delivery, queues, and account features you request.
  • Legitimate interests (Art. 6(1)(f)): Securing the Service, rate limiting, fraud and abuse detection, minimal operational logging, and aggregated performance metrics, balanced against your rights.
  • Legal obligation (Art. 6(1)(c)): Where we must retain or disclose data to comply with applicable law or valid authority requests.
  • Consent (Art. 6(1)(a)): Only where required, for example non-essential analytics cookies where consent is mandated. Essential cookies and strictly necessary processing do not depend on consent.

4. Categories of personal data

4.1 Account and identity (controller processing)

  • Discord or Roblox user identifiers, display name, avatar URL, and OAuth tokens needed for login
  • Admin preferences, ban lists you manage, and dashboard activity tied to your account

4.2 Webhook and request data (often processor processing)

  • Discord webhook URLs and internal webhook identifiers
  • HTTP metadata: source IP, timestamps, method, path, status codes, response times, User-Agent
  • Queue payloads temporarily held for delivery (may contain any content you send, including possible personal data)
  • Aggregated statistics (counts, success rates, lane/class labels)

4.3 Technical and security logs

  • Error and diagnostic messages (stack traces may appear in server logs; we avoid logging full message bodies where possible)
  • Cloudflare and edge security signals (for example bot scores, country, TLS fingerprints) as processed by our providers

4.4 What we do not aim to store long term

We do not intend to keep full webhook message content in analytics databases after delivery. Payloads exist primarily in transit and in short-lived queues. You should not send special category data (health, biometric, etc.) unless you have an explicit legal basis and appropriate safeguards.

5. Purposes of processing

  • Authenticate users and authorise admin access
  • Receive, queue, rate-limit, and forward webhooks to Discord (and configured destinations)
  • Operate durable delay/retry without arbitrary discard on HTTP 429 where policy allows
  • Enforce bans, ingress limits, and dead-destination rejection
  • Maintain status, changelog, and support channels
  • Prune old logs and queue rows to limit retention
  • Comply with law and respond to data subject requests directed to us as controller

6. Retention

We keep data no longer than necessary for the purposes above. Actual times may vary with configuration and load; indicative policy targets include:

  • Queued webhook work (max_age examples): bulk lane about 5 minutes; normal lane about 30 minutes; critical lane about 2 hours. After max_age, work expires observably instead of being retried indefinitely.
  • Delivered queue rows: removed when processing completes or on expiry pruning.
  • Database logs and analytics tables: rotated and pruned on a schedule (for example hourly prune jobs for activity, application, and webhook analytics logs, plus terminal queued message cleanup). Retention windows are configured to balance security investigation with minimisation.
  • Account data: kept while your account is active and for a limited period afterward where needed for disputes, security, or legal obligations.

You may request erasure of controller data we hold about you (see Section 9). Processor requests from integrators should identify the data subject and lawful scope; we will assist within reasonable technical limits.

7. Recipients and international transfers

We use subprocessors that may process data outside the EEA, including:

  • Discord Inc. (United States and global infrastructure): OAuth and webhook delivery. Transfers rely on Discord's terms, privacy policy, and applicable transfer tools such as Standard Contractual Clauses (SCCs) where Discord makes them available.
  • Cloudflare, Inc. (global edge and security): DDoS protection, WAF, TLS, and optional analytics. Transfers rely on Cloudflare's Data Processing Addendum and SCCs under their enterprise/cloud terms.
  • Roblox Corporation (where OAuth or bidirectional features are used): authentication per Roblox policies.
  • Hosting providers operating our origin servers (location depends on deployment; contracts require appropriate safeguards).

We do not legitimise these transfers solely through a blanket "by using the Service you consent" clause. Where GDPR requires a transfer mechanism, we rely on adequacy decisions, SCCs, or other approved safeguards offered by the provider, plus supplementary measures where appropriate.

We do not sell personal data. We disclose data to authorities only when legally required or to protect rights and safety in line with law.

8. Security

Measures include, among others:

  • HTTPS for data in transit
  • Session hardening, admin access controls, and rate limiting
  • Cloudflare WAF and abuse tooling
  • Rejection of known-dead webhook destinations at ingress
  • Operational monitoring and phased reliability improvements (see internal risk documentation)

No method of transmission or storage is 100% secure; we work to reduce risk consistent with the nature of the Service.

9. Your rights (EEA/UK)

Where GDPR applies and News Targeted is controller, you may have the right to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent where processing is consent-based. You may lodge a complaint with your supervisory authority (in Norway: Datatilsynet).

Data subject and privacy requests (controller): email [email protected]. We may need to verify identity. We respond within one month unless extension is permitted by law.

If your data was sent through the Service by another developer, contact that developer first as controller; we will support them as processor when contractually required.

10. Cookies and similar technologies

10.1 Strictly necessary (essential)

Required for login sessions, security tokens, load balancing, and abuse prevention. Legal basis: legitimate interests and/or contract. These cannot be disabled without breaking core features.

10.2 Analytics and performance

We may use privacy-oriented or aggregated analytics (for example Cloudflare Web Analytics or similar) to understand traffic and errors. Where law requires consent for non-essential cookies, we will ask before setting them. You can also use browser controls to block cookies; essential cookies may still be needed for authenticated areas.

11. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16 without appropriate parental authority. If you believe we have such data, contact [email protected] and we will delete it promptly where we are controller.

12. Changes

We may update this policy for legal, technical, or operational reasons. Material changes will be posted here with a new "Last updated" date. Continued use after the effective date may indicate acceptance where permitted by law; where consent is the sole basis, we will seek renewed consent.

13. Contact