1. Who we are (controller)
The operator of the Interface is the data controller for the processing described in this Policy. The operator's legal name, registered office, and contact address are published on the Interface. Where the operator is required under MiCA to appoint or identify a representative or designated contact, that information is also published on the Interface.
For any data-protection request, write to the operator at the contact address shown on the Interface. If the operator has appointed a Data Protection Officer or EU representative, their contact details are included there.
2. What data we process
The Interface is designed to minimize collection. We process:
- Wallet address. When you connect a wallet, your public blockchain address is read by the Interface to display your balances, stake, and rewards. We do not link this address to any real-world identity unless you voluntarily provide that information.
- On-chain transaction metadata. Transactions you sign through the Interface are broadcast to a public blockchain. By their nature, blockchain transactions are public, immutable, and outside our control once submitted.
- Technical data. When you load the Interface, our servers and infrastructure providers record standard technical information — IP address, user-agent string, referring URL, request time, and the resource requested — in short-lived server logs used to operate the service and detect abuse.
- Aggregated, non-identifying usage. Where we measure traffic or performance, we use aggregated counters that do not allow us to identify an individual user.
We do not ask for your name, email address, phone number, postal address, government ID, or photograph as a condition of using the Interface. We do not run KYC checks. If you contact us by email or social channel, we will process the contact details and message contents you choose to share.
3. Cookies and similar technologies
The Interface uses only the cookies and local-storage entries that are strictly necessary for it to work. These do not require your consent under Article 5(3) of the ePrivacy Directive, but we list them here so you know what they do:
- Wallet-session storage (set by the wallet-connect tooling, e.g. RainbowKit/WalletConnect): remembers your active wallet provider and connection state between page reloads. Cleared when you disconnect or clear browser storage.
- UI preference storage: remembers small UI choices such as the network chip you last interacted with so the page does not flicker on reload.
We do not set advertising, profiling, or cross-site-tracking cookies. We do not use Google Analytics, Facebook Pixel, or comparable third-party tracking. If we add an analytics tool that uses non-essential cookies in the future, we will surface a consent banner first.
You can clear cookies and local storage at any time through your browser settings; doing so will disconnect any active wallet session.
4. Legal bases (GDPR Article 6)
- Performance of a contract (Art. 6(1)(b)). Reading your wallet address, displaying your position, and routing your transaction to the smart contract are necessary to provide the Interface you have asked to use.
- Legitimate interests (Art. 6(1)(f)). Operating the site, keeping it secure, detecting and preventing abuse, and understanding aggregate usage in a privacy-preserving way are our legitimate interests. We balance these against your rights.
- Legal obligation (Art. 6(1)(c)). Where applicable law (including MiCA, anti-money-laundering, and sanctions screening obligations) requires us to keep records or block specific addresses, we do so on that basis.
- Consent (Art. 6(1)(a)). For any processing that requires consent (none today), we will ask you first and you may withdraw at any time.
5. Sharing with third parties
We use a small number of carefully chosen providers to operate the Interface. They process technical data on our behalf or as independent controllers for their own clearly scoped purposes:
- Cloud hosting and CDN providers: serve the Interface and protect it against attack. They see IP addresses and request metadata in transit.
- RPC and blockchain-data providers: relay your signed transactions to the blockchain and serve on-chain reads; they will see wallet addresses and request metadata.
- Wallet-connection providers (e.g. WalletConnect, RainbowKit): facilitate the cryptographic handshake between your wallet and the Interface.
- Market-data providers (e.g. CoinGecko): supply aggregate price and volume data that we display. They do not receive personal data about you.
We do not sell personal data. We do not share personal data with advertisers or data brokers. We may disclose data to law-enforcement or regulatory authorities where compelled by valid legal process and to the minimum extent required.
6. International transfers
Some of our providers are located outside the European Economic Area. Where personal data is transferred to such a provider, we rely on the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful mechanism under GDPR Chapter V. You may request a copy of the safeguards in place by contacting us.
7. Retention
We retain server logs for no longer than necessary to operate and secure the Interface (typically up to 30 days, longer where required for security investigations or by law). On-chain data, by the nature of public blockchains, is permanent and outside our control. Wallet sessions are local to your browser and are cleared when you disconnect or clear browser storage. We will keep correspondence and records relating to a legal claim for as long as needed to handle the claim.
8. Your rights
Subject to applicable conditions and exceptions, you have the right to access, rectify, erase, restrict, and port the personal data we hold about you; to object to processing based on legitimate interests; and to withdraw consent at any time where processing is based on consent. To exercise these rights, contact the operator at the address on the Interface. We will respond within the timeframes required by GDPR (one month, extendable by two further months for complex requests).
You also have the right to lodge a complaint with a supervisory authority — typically the authority of the EU Member State of your habitual residence or place of work. A directory is available at edpb.europa.eu.
Because the Interface is non-custodial, requests for erasure cannot affect on-chain transactions you have signed. We can delete records we hold (such as logs and correspondence) but cannot alter or remove public blockchain data.
9. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that produces legal or similarly significant effects on you. We do not build behavioural profiles for advertising or scoring purposes.
10. Children
The Interface is not intended for, and we do not knowingly process personal data of, anyone under 18. If you believe a child has interacted with the Interface, please contact us so we can take appropriate action.
11. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date at the top. If a change is material, we will take reasonable steps to bring it to your attention through the Interface.