Back to Secret Community legal hub
Automated Risk Assessment Information
Transparency notice for internal Community Trust Score and related profiling used for safety and abuse prevention, including safeguards and human-review requirements for significant decisions.
This text is a draft for counsel review. Screens alone do not make Picom “KVKK compliant” or “GDPR certified”.
Controller information
This notice cannot be published as active until required controller fields are configured. Missing: legalName, registeredAddress, tradeRegistry
- Legal name
- —
- Registered address
- —
- Trade registry
- —
- General contact
- info@picom.gg
- KVKK contact
- info@picom.gg
- GDPR contact
- info@picom.gg
- DPO
- —
- EU representative
- —
- TR representative
- —
Summary
- Picom may analyse community and account activity to identify spam, fraud, harmful conduct, invitation abuse and security risks.
- Indicators may contribute to an internal Community Trust Score used to prioritise review and protect users.
- The numeric score and related internal signals are visible only to authorised Root trust-and-safety personnel — not to community members or admins.
- The score must not by itself automatically cause permanent termination, permanent community deletion, law-enforcement disclosure, or similarly significant effects.
- Significant enforcement decisions require human review, evidence review, reason logging and appeal or re-review pathways.
- Safeguards prohibit use of special-category data and discriminatory proxies as scoring factors.
Full notice
Internal-only visibility
The Community Trust Score is internal and visible only to authorised Root trust-and-safety personnel. Community owners, administrators, moderators and members must not see the numeric score, risk category, scoring weights, internal fraud signals, internal investigation notes, or other users’ personal data derived from scoring.
What may be analysed
This analysis may use indicators such as confirmed reports, spam patterns, invitation abuse, malicious links, suspicious joining patterns, account and community age, moderation history, verified creator status, security incidents and repeated rule violations. These indicators may contribute to an internal Community Trust Score.
How the score is used
The score is used to:
- Prioritise security review
- Detect abuse
- Support moderation investigations
- Protect users and the service
- Recommend proportionate safety measures
Limits on automated effects
The score must not, by itself, automatically cause permanent account termination, permanent community deletion, disclosure to law enforcement, or a decision producing similarly significant legal or practical effects. Significant enforcement decisions require human review, review of relevant evidence, reason logging, proportionality assessment, an appeal or re-review mechanism, and protection against discriminatory proxies.
Safeguards summary
Picom implements safeguards for Trust Score processing, including the following principles:
- No special-category personal data may be used as a scoring factor.
- Do not infer race, religion, health, sexuality or political beliefs.
- Do not use nationality alone as a negative risk signal.
- Do not penalise users solely for using privacy-protective technology; VPN use may trigger additional verification but must not automatically establish wrongdoing.
- Reports alone must not be treated as confirmed violations; coordinated false reporting must be detected.
- Positive and negative factors must be documented; scoring weights must be versioned.
- Every score change must have a machine-readable reason; Root manual adjustments require a reason and must be auditable.
- Trust scores must have an expiry or decay model; old incidents must not penalise a community indefinitely without review.
- Incorrect data must be correctable.
- Significant restrictions require human review; appeals must be handled by a reviewer other than the original reviewer where operationally possible.
Information about adverse decisions
Users must be given meaningful information about adverse moderation decisions without revealing information that would compromise security systems or the rights of others.