Legal

Privacy Policy

Effective · 25 June 2026 · Version 1.0

This page is maintained by The Aris Group to explain what data the staff workspace at tag.royce.ltd handles, why we handle it, where it lives and what rights you have over it. It is written for members of staff, not the general public. It is not a certification, audit report or legal advice, and it does not create obligations beyond those set out in the Terms of Service.

1. Who is responsible

The Aris Group, an in-game holding company operating within MYSverse on Roblox, is the controller of personal data processed through the workspace at tag.royce.ltd. The Office of the Chairman is accountable for decisions about how that data is collected and used. The Secretariat is the day-to-day contact point for privacy requests.

2. What we collect

The workspace deliberately collects the minimum needed to run it. From Discord, at sign-in, we receive your Discord user ID, your username (and global display name where set), and a URL to your avatar. We do not request email, phone number, friends list, guild list, message content or payment information. From your activity inside the workspace we record the content you post (notices, tasks, agenda items, documents, calendar entries, reactions and RSVPs), the time of each action, and the role under which it was performed. From your session we record technical metadata such as the IP address of the request and a session identifier used to keep you signed in.

3. Avatars and the 'always fetch latest' rule

We do not cache or store a copy of your Discord profile picture. The workspace stores only the avatar reference returned by Discord at sign-in and resolves it against Discord's CDN at display time, so when you change your avatar on Discord it changes here on your next session refresh. If your Discord account is deleted, the avatar will no longer resolve.

4. Why we collect it (legal bases)

We process this data on the basis of your consent(given when you choose to sign in with Discord), our legitimate interests in running a secure internal workspace, and where applicable our need to perform the internal governance contract implied by your appointment to a role. Purposes are limited to: identifying you across the workspace, applying role-based permissions, attributing contributions for audit, securing the service against abuse, and communicating Group business to you.

5. Where it lives

Workspace data is stored in a managed Postgres database operated by our backend provider. Every public-schema table has row-level security enabled and access policies are written against the authenticated user. Service-level keys never leave the server. The web application is served from an edge runtime; static assets and server functions execute close to the requesting region.

6. Who can see what

Visibility follows role. Holding-wide notices and Board material are visible only to members assigned a holding-level role (Chairman, Deputy Chairman, CEO, COO, Governors, General Secretary). Each subsidiary's notices, tasks, documents and calendar items are visible only to members of that subsidiary, plus the Office of the Chairman in its oversight capacity. The Chairman and Governors may view audit metadata (who posted, when, from where) for governance purposes.

7. How long we keep it

Account records (Discord ID, username, avatar reference, role history) are retained for as long as your access is active. After revocation we keep an attributed record of your workspace contributions indefinitely for governance and audit purposes; personal identifiers (handle, avatar reference) may be replaced with a pseudonymous reference on written request to the Secretariat, unless retention is required to defend a governance decision. Session records and request logs are retained for up to 90 days and then deleted or aggregated.

8. Sharing and subprocessors

We use the following categories of third-party processor: Discord (authentication and avatar hosting), our managed backend provider (database, auth tokens, server functions, file storage), and our edge hosting provider (delivery of the website and execution of server functions). We do not sell workspace data. We do not share workspace data with advertisers. We do not load third-party advertising or analytics scripts on the workspace.

9. International transfers

Because the workspace runs on global edge infrastructure, data may be processed in regions outside your own. We rely on the contractual and security commitments of our subprocessors to keep data protected during such transfers.

10. Children

The workspace is not intended for children under 13. Discord's own Terms of Service prohibit accounts under that age, which is the effective floor for access here.

11. Your rights

You may request: a copy of the personal data we hold on you; correction of inaccurate data; deletion of personal identifiers (subject to clause 7); export of your contributions; or withdrawal of consent (which will end your access). Send requests to the Secretariat via the Office of the Chairman from within the workspace. We aim to respond within 30 days.

12. Breach notification

If we become aware of a security incident affecting your personal data, we will notify affected members through the Notice Board and, where possible, by direct message on Discord, within a reasonable period after confirming the scope of the incident.

13. Changes to this policy

We may revise this policy from time to time. Material changes will be announced on the Notice Board and reflected in the "Effective" date at the top of this page.