Yes, and more than many operators expect. Under EU law, whoever helps determine why and how personal data is processed is a controller — and the label in a contract does not decide it. The Court of Justice has read this broadly since the Wirtschaftsakademie ruling in 2018, which treated the administrator of a Facebook page as a joint controller alongside the platform.
Why this is relevant even if you run everything yourself. In December 2025, the Court's Russmedia judgment (C-492/23) set out a detailed catalogue of preventive obligations for platforms hosting user-generated content, and observers note it may be demanding to implement for smaller operators in particular.
What you are actually deciding on an ATRIUM network. Your storage provider and its region, your SMTP configuration, what member groups exist and what they can see, and what data your network collects. Those are controller decisions, made by you.
Where Web4's architecture helps you. Members sign in with their own UIID, everyday activity runs through anonymous aliases, and there is no password database for you to hold or lose. The less personal data you hold, the smaller the problem you have to manage.
Three practical steps before launch: publish a privacy notice telling members what you collect and why; choose a storage provider and region that match your members' expectations; and decide in advance how you will respond if a member asks for their data or its deletion.
Then get advice. This is exactly the area where an hour with your own advisor is worth more than a help center article.