Legal & Privacy

CryptoChain Privacy Policy

Effective Date: [07/14/2026]Last Updated: [07/14/2026]

Effective Date: [07/14/2026]

Last Updated: [07/14/2026]

This Privacy Policy describes how [CRYPTOCHAIN, INC., a Delaware corporation — COUNSEL TO CONFIRM ENTITY FORM; "S Corporation" is a US federal tax election rather than an entity form, and an S corporation may not have non-resident alien shareholders, which is inconsistent with the stated global footprint], doing business as CryptoChain ("CryptoChain," "we," "us," or "our"), collects, uses, discloses, and otherwise processes information when you access or use our websites, mobile applications, software, application programming interfaces ("APIs"), wallet connectivity services, blockchain transaction routing and optimization services, merchant payment functionality, and other products and services that link to this Privacy Policy (collectively, the "Services").

This Privacy Policy also explains the choices and rights that may be available to you regarding your personal information.

By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.

Where applicable data protection law requires a lawful basis or consent for processing, CryptoChain relies on the bases described in Section 4A and obtains consent where required. Acknowledgement of this Privacy Policy is not, by itself, treated as consent for those purposes.

AT A GLANCE

This summary is provided for convenience and does not replace the full Privacy Policy.

  • CryptoChain provides non-custodial software. We never ask for, and never store, your seed phrase, recovery phrase, or private keys.
  • We collect account and contact details, public wallet and blockchain data, transaction and routing data, device and usage data, and information from compliance and analytics providers.
  • We use that information to operate the Services, route and optimise transactions, prevent fraud and sanctions violations, improve our products, and meet legal obligations.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising, as those terms are defined under US state privacy laws.
  • Information written to a public blockchain is permanent, public, and outside our control. We cannot delete or correct it.
  • You have rights of access, correction, deletion, portability, objection, and complaint, described in Sections 10 to 12 and exercisable at privacy@cryptochainai.io or through the in-app privacy centre.

CONTROLLER AND CONTACT DETAILS

For the purposes of the EU and UK General Data Protection Regulation, Brazil’s LGPD, and comparable laws, the controller of your personal information is [CRYPTOCHAIN, INC.], [REGISTERED ADDRESS]. Where CryptoChain processes personal information on behalf of a Merchant or API customer, CryptoChain acts as a processor (or "operator"/"service provider") and that customer is the controller; the CryptoChain Data Processing Addendum governs that processing.

1. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to personal information that CryptoChain processes in connection with the Services.

This Privacy Policy does not apply to information processed independently by third parties, including digital asset wallet providers, blockchain networks, decentralized applications, exchanges, liquidity providers, payment processors, fiat on-ramp or off-ramp providers, financial institutions, identity verification providers, analytics providers, or other third-party services.

Third parties may process information under their own privacy policies and terms. We encourage you to review the privacy practices of any third-party service with which you interact.

Public blockchain networks operate independently of CryptoChain. Information recorded on a public blockchain may be publicly accessible and may not be capable of being modified or deleted by CryptoChain.

2. INFORMATION WE COLLECT

The information we collect depends on how you interact with CryptoChain and which Services you use.

A. Information You Provide Directly to Us

We may collect information that you provide directly to us, including:

  • your name;
  • email address;
  • telephone number;
  • username or account identifier;
  • company or business name;
  • job title or business role;
  • account registration information;
  • merchant or business information;
  • communications with CryptoChain;
  • customer support requests;
  • feedback, survey responses, or product research information;
  • information submitted through forms, applications, waitlists, or demonstrations; and
  • other information that you choose to provide.

If you create an account, we may collect information necessary to establish, authenticate, maintain, and secure that account.

We do not knowingly collect information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation, and ask that you do not provide such information to us.

B. Wallet and Blockchain Information

When you connect a supported digital asset wallet or use blockchain-related features, we may collect or process information associated with that interaction, including:

  • public wallet addresses;
  • blockchain network information;
  • token and Digital Asset balances;
  • public transaction history;
  • transaction hashes or transaction identifiers;
  • token holdings;
  • smart contract interactions;
  • staking or liquidity-related information;
  • NFT or other digital asset metadata, where applicable;
  • transaction status and confirmation information;
  • blockchain network activity; and
  • other information that is publicly available on supported blockchain networks.

Some blockchain information is publicly available and may be obtained directly from public blockchain networks or through third-party blockchain infrastructure and data providers.

Depending on applicable law and the circumstances, public wallet addresses and blockchain activity may constitute personal information when they are associated or reasonably capable of being associated with an identifiable individual.

C. Connected Wallet Information and Smart Connect

CryptoChain may provide wallet connectivity and aggregation functionality, including functionality referred to as "Smart Connect."

When you connect a wallet, we may process information necessary to establish and maintain the connection and provide requested functionality.

Depending on the Services you use and the permissions you authorize, this may include:

  • the identity or type of connected wallet;
  • public wallet addresses;
  • supported blockchain networks;
  • Digital Asset balances;
  • transaction history;
  • token and asset information;
  • staking or liquidity positions;
  • connection status;
  • authorization and permission information; and
  • technical information necessary to maintain or secure the connection.

CryptoChain does not request or store your wallet seed phrase or recovery phrase.

CryptoChain does not take custody of your Digital Assets merely because you connect a wallet to the Services.

Where CryptoChain provides persistent, scoped, or revocable wallet permissions, we may maintain information necessary to identify, administer, secure, and revoke those permissions.

When you use CryptoChain to evaluate, initiate, route, or facilitate a blockchain transaction or Digital Asset payment, we may collect or process information such as:

  • transaction amount;
  • Digital Asset or token involved;
  • sending and receiving public wallet addresses;
  • blockchain network;
  • transaction route;
  • transaction hash;
  • transaction status;
  • estimated and actual network fees;
  • estimated transaction processing time;
  • transaction timestamps;
  • liquidity information;
  • estimated slippage or price impact;
  • conversion or pricing information;
  • merchant identifier;
  • merchant settlement preferences;
  • user-selected transaction preferences; and
  • technical information related to transaction execution.

CryptoChain may process transaction-related information before, during, and after a transaction to provide the Services, improve transaction routing, troubleshoot errors, prevent fraud, maintain security, and comply with applicable legal obligations.

Unless expressly disclosed otherwise for a specific service, CryptoChain does not itself take custody of your Digital Assets or receive or hold your fiat currency.

Where a transaction involves an independent third-party payment provider, fiat on-ramp or off-ramp provider, exchange, financial institution, liquidity provider, or other service provider, that third party may independently collect and process information under its own privacy policy.

E. Merchant and Business Information

If you use CryptoChain as a merchant, developer, business customer, or commercial partner, we may collect:

  • business name;
  • business contact information;
  • business address;
  • authorized representative information;
  • merchant account information;
  • business preferences;
  • payment and settlement preferences;
  • API and integration information;
  • customer support communications;
  • billing information, where applicable; and
  • compliance or verification information where required.

If merchant verification, identity verification, Know Your Customer ("KYC"), Know Your Business ("KYB"), sanctions screening, or similar services are required, such services may be performed by CryptoChain or an independent third-party provider.

Where a third-party provider performs such verification, the provider may collect information directly from you under its own privacy policy.

F. Device and Technical Information

When you access or use the Services, we and our service providers may automatically collect certain technical information, including:

  • Internet Protocol ("IP") address;
  • device type;
  • operating system;
  • browser type and version;
  • device identifiers;
  • application version;
  • language settings;
  • approximate location derived from IP address;
  • referring URLs;
  • pages or screens viewed;
  • dates and times of access;
  • session information;
  • crash reports;
  • diagnostic information;
  • performance information; and
  • security-related technical data.

We may use this information to operate, secure, maintain, troubleshoot, and improve the Services.

G. Usage and Interaction Information

We may collect information about how you interact with the Services, including:

  • features used;
  • pages or screens viewed;
  • buttons or functions selected;
  • wallet connection activity;
  • transaction workflow activity;
  • API usage;
  • session duration;
  • error events;
  • application performance;
  • interaction with product features; and
  • other information regarding use of the Services.

H. API and Developer Information

If you use CryptoChain APIs, software development kits, or developer tools, we may collect:

  • developer account information;
  • API credentials and identifiers;
  • API requests;
  • timestamps;
  • IP addresses;
  • request and response metadata;
  • error logs;
  • usage volume;
  • rate-limit information; and
  • security and authentication information.

We may use this information to provide and secure API access, monitor performance, prevent misuse, enforce applicable terms, and improve developer services.

I. Information From Third Parties

We may receive information from third parties, including:

  • wallet providers;
  • blockchain networks;
  • blockchain infrastructure providers;
  • blockchain analytics providers;
  • RPC providers;
  • data providers;
  • merchants;
  • business partners;
  • identity or business verification providers;
  • fraud prevention and security providers;
  • analytics providers; and
  • other service providers.

The information received depends on the third party, the Services used, and the permissions or authorizations involved.

3. INFORMATION WE DO NOT REQUEST OR INTEND TO COLLECT

CryptoChain does not request that you provide your wallet seed phrase or recovery phrase.

You should never provide your seed phrase or recovery phrase to CryptoChain, CryptoChain personnel, customer support representatives, or any person claiming to represent CryptoChain.

CryptoChain personnel will not ask you to disclose a wallet seed phrase or recovery phrase.

CryptoChain does not take custody of Digital Assets merely because a wallet is connected to the Services.

CryptoChain has confirmed that its architecture does not include embedded wallets, delegated transaction permissions, key shares, multi-party computation infrastructure, session keys, or automated execution on your behalf. If CryptoChain introduces any such functionality, this Privacy Policy and the Terms of Use will be updated and advance notice will be given.

4. HOW WE USE INFORMATION

We may use information for the following purposes:

Where the GDPR, UK GDPR, LGPD, PIPEDA, Quebec Law 25, the Australian Privacy Act, the Singapore PDPA, Japan’s APPI, or a comparable law applies, CryptoChain relies on the following legal bases. Where more than one basis is available, CryptoChain identifies the primary basis below.

  • Performance of a contract (GDPR Art. 6(1)(b)) — creating and maintaining accounts, authenticating you, connecting wallets, displaying blockchain information, facilitating and routing transactions, providing merchant and API functionality, and providing customer support.
  • Compliance with a legal obligation (GDPR Art. 6(1)(c)) — sanctions screening, anti-money laundering and counter-terrorist financing measures, tax information reporting, records retention, and responding to lawful requests from authorities.
  • Legitimate interests (GDPR Art. 6(1)(f)) — securing the Services, detecting and preventing fraud and abuse, debugging and improving performance and reliability, developing and evaluating transaction routing algorithms, conducting analytics and research on an aggregated or de-identified basis, enforcing our Terms, establishing and defending legal claims, and corporate transactions. Where we rely on legitimate interests, we have carried out a balancing assessment and you may object at any time as described in Section 10.
  • Consent (GDPR Art. 6(1)(a) and, for special category data, Art. 9(2)(a)) — non-essential cookies and similar technologies, marketing communications where consent is required, biometric identity verification, any use of your personal information to train or improve AI models where consent is required, and any other processing for which we ask for your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Vital interests and public interest (GDPR Art. 6(1)(d) and (e)) — in rare cases, to protect the life or safety of an individual or to assist in the investigation of serious crime.

B. Providing the Services

We may use information to:

  • create and maintain accounts;
  • authenticate Users;
  • connect supported wallets;
  • display blockchain and Digital Asset information;
  • aggregate information across supported blockchain networks;
  • facilitate transaction workflows;
  • provide transaction routing and optimization functionality;
  • process User and merchant preferences;
  • provide merchant payment functionality;
  • provide APIs and developer services;
  • provide customer support; and
  • otherwise operate the Services.

C. AI-Assisted Routing and Optimization

Certain CryptoChain Services may use artificial intelligence, machine learning, algorithms, automated systems, or other computational methods to support transaction routing, optimization, risk assessment, or product functionality.

Depending on the feature, these systems may process information such as:

  • transaction characteristics;
  • Digital Asset information;
  • blockchain network conditions;
  • transaction fees;
  • estimated processing times;
  • network congestion;
  • liquidity conditions;
  • estimated slippage;
  • price information;
  • transaction size;
  • merchant preferences;
  • settlement preferences;
  • historical transaction performance;
  • technical performance information; and
  • other relevant operational or market data.

We may use this information to identify, rank, recommend, or facilitate potential transaction routes, blockchain networks, Digital Assets, execution paths, or other transaction-related options.

CryptoChain does not use your wallet seed phrase or recovery phrase to train AI systems.

Automated decision-making and profiling. Certain screening described in Section 4D is automated and may result in a transaction not being facilitated or in restriction of your access to the Services. Where such a decision produces legal effects concerning you or similarly significantly affects you, CryptoChain relies on the exception in Article 22(2)(b) of the GDPR (authorised by Union or Member State law to which the controller is subject, including anti-money laundering and sanctions law) or, where applicable, Article 22(2)(a). You have the right to obtain human intervention, to express your point of view, and to contest the decision by contacting privacy@cryptochainai.io; CryptoChain may be legally prohibited from disclosing the detailed basis of a sanctions or suspicious-activity decision. Residents of Quebec, Colorado, Connecticut, Oregon, Texas, and other jurisdictions with profiling opt-out or explanation rights have the additional rights described in Sections 11 and 12.

AI transparency. Where you interact directly with an AI System or receive AI-generated content, CryptoChain will disclose that fact and, where required, mark the output in a machine-readable format, in accordance with Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), which applies from 2 August 2026.

D. Security, Fraud Prevention, and Platform Integrity

We may use information to:

  • authenticate Users;
  • secure accounts and wallet connections;
  • detect suspicious or unauthorized activity;
  • prevent fraud;
  • identify cybersecurity threats;
  • investigate abuse;
  • enforce our Terms of Use;
  • monitor the security and integrity of the Services;
  • detect potential sanctions or illicit-finance risks; and
  • protect CryptoChain, our Users, merchants, partners, and others.

E. Product Development and Improvement

We may use information to:

  • analyze how the Services are used;
  • troubleshoot technical problems;
  • improve performance and reliability;
  • develop new features;
  • evaluate transaction routing performance;
  • improve algorithms and AI-assisted functionality;
  • conduct research and analytics; and
  • understand User and merchant needs.

Where appropriate, we may use aggregated or de-identified information for research, analytics, product development, and other lawful business purposes.

F. Communications

We may use contact information to:

  • provide service-related communications;
  • respond to inquiries;
  • provide customer support;
  • communicate security alerts;
  • provide administrative notices;
  • notify you of material changes to the Services or our policies; and
  • send marketing communications where permitted by applicable law.

You may opt out of marketing communications using the unsubscribe mechanism provided in the communication or by contacting us.

You may continue to receive non-marketing communications that are necessary to provide the Services.

We may use information to:

  • comply with applicable laws and regulations;
  • respond to lawful governmental or regulatory requests;
  • establish, exercise, or defend legal claims;
  • investigate potential violations of law or our Terms;
  • comply with sanctions and other legal requirements; and
  • protect the rights, safety, and property of CryptoChain and others.

5. HOW WE DISCLOSE INFORMATION

We may disclose information in the following circumstances.

A. Service Providers

We may disclose information to vendors and service providers that perform services on our behalf, including providers of:

  • cloud hosting and infrastructure;
  • cybersecurity;
  • analytics;
  • customer support;
  • communications;
  • blockchain infrastructure;
  • blockchain data;
  • RPC services;
  • fraud prevention;
  • compliance;
  • identity or business verification;
  • AI or machine learning services; and
  • other technical and operational services.

These providers may process information as necessary to perform services for CryptoChain and subject to applicable contractual or legal requirements.

B. Blockchain Networks

When you authorize a blockchain transaction, information necessary to execute the transaction may be submitted to a public blockchain network.

Information recorded on a public blockchain may become permanently and publicly accessible.

CryptoChain does not control public blockchain networks and generally cannot alter, delete, or remove information that has been confirmed and recorded on a blockchain.

C. Third-Party Services and Integrations

When you choose to interact with a third-party wallet, payment provider, exchange, fiat on-ramp or off-ramp, financial institution, decentralized application, smart contract, or other third-party service, information may be shared with or made available to that third party as necessary to complete the requested interaction.

Third parties process information under their own terms and privacy policies.

D. Merchants and Transaction Participants

Where necessary to facilitate a payment or transaction, we may disclose relevant transaction information to the participating merchant, customer, wallet provider, settlement provider, or other transaction participant.

The information disclosed will depend on the transaction and the Services used.

We may disclose information if we reasonably believe disclosure is necessary to:

  • comply with applicable law;
  • respond to a subpoena, court order, legal process, or lawful governmental request;
  • protect the rights, property, or safety of CryptoChain, our Users, or others;
  • investigate fraud, cybersecurity incidents, or illegal activity;
  • enforce our agreements; or
  • comply with applicable sanctions or regulatory requirements.

F. Corporate Transactions

We may disclose or transfer information in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or other corporate transaction.

We may disclose information when you direct us to do so, authorize the disclosure, or otherwise consent.

H. We Do Not Sell or Share Personal Information

6. PUBLIC BLOCKCHAIN INFORMATION

Public blockchain networks are designed to maintain publicly accessible transaction records.

Information recorded on a public blockchain may include:

  • wallet addresses;
  • transaction amounts;
  • transaction timestamps;
  • transaction hashes;
  • token information; and
  • smart contract interactions.

Blockchain information may be visible to anyone and may be analyzed by third parties.

Although a wallet address may not directly identify a person by name, it may become associated with an individual or organization through other information.

Because CryptoChain does not control public blockchain networks, CryptoChain generally cannot modify, erase, restrict, or delete information recorded on those networks.

Privacy rights relating to information stored on a blockchain may therefore be technically limited.

7. COOKIES AND SIMILAR TECHNOLOGIES

We and our service providers may use cookies, software development kits, pixels, local storage, and similar technologies to operate and improve the Services.

These technologies may be used for:

  • essential functionality;
  • authentication;
  • security;
  • remembering preferences;
  • performance monitoring;
  • analytics; and
  • other purposes described at the time of collection.

Where required by applicable law, we will request consent before using non-essential cookies or similar technologies.

Managing cookies. You may manage your preferences at any time through the CryptoChain cookie preference centre, through your browser settings, and, on mobile, through your device advertising and tracking settings. Blocking essential cookies may prevent the Services from functioning.

Opt-out preference signals. CryptoChain treats the Global Privacy Control and other recognised universal opt-out preference signals as a valid request to opt out of the sale or sharing of personal information and, where applicable, of targeted advertising, as required by California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, Texas, and other states that mandate recognition of such signals.

8. DATA RETENTION

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • provide the Services;
  • maintain accounts;
  • comply with legal obligations;
  • resolve disputes;
  • enforce agreements;
  • maintain security;
  • prevent fraud; and
  • establish or defend legal claims.

Retention periods may vary depending on the type of information, the purpose for which it was collected, legal requirements, and operational needs.

Our current retention criteria are set out below. Where a longer period is required by law or necessary to establish or defend a legal claim, the longer period applies.

  • Account and profile information — for the duration of the account and five (5) years after closure.
  • Transaction and routing records — five (5) years from the date of the transaction, reflecting anti-money laundering record-keeping requirements in the United States, the European Union, and other launch markets.
  • Identity and business verification records — five (5) years after the end of the relationship, or longer where required by applicable law.
  • Sanctions screening and compliance investigation records — five (5) years from the date of the screening or the closure of the investigation.
  • Customer support communications — three (3) years from the date of the last communication.
  • Device, technical, and usage logs — thirteen (13) months, except where retained longer for security investigation purposes.
  • Security and access logs — twelve (12) months, or longer where an investigation is ongoing.
  • Marketing contact information and consent records — until you withdraw consent, and three (3) years thereafter as a record of the withdrawal.
  • Cookie and similar technology data — as stated in the cookie preference centre, and in no case longer than thirteen (13) months for non-essential technologies.

Information recorded on public blockchain networks may remain permanently available and is not controlled by CryptoChain.

We may retain aggregated or de-identified information where permitted by applicable law.

9. DATA SECURITY

CryptoChain uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure.

These measures may include, as appropriate:

  • encryption in transit;
  • access controls;
  • authentication controls;
  • secure development practices;
  • security monitoring;
  • logging;
  • vulnerability management; and
  • other technical and organizational safeguards.

However, no information system, blockchain network, internet transmission, or method of electronic storage is completely secure.

You are responsible for maintaining the security of your devices, accounts, authentication credentials, connected wallets, private keys, and recovery phrases.

Security incidents. If CryptoChain becomes aware of a personal data breach that is likely to result in a risk to your rights and freedoms, CryptoChain will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to them, in each case as required by applicable law, including GDPR Articles 33 and 34, US state breach notification statutes, the Australian Notifiable Data Breaches scheme, PIPEDA, Quebec Law 25, Japan’s APPI, Singapore’s PDPA, and Brazil’s LGPD.

Vulnerability disclosure. Security researchers may report suspected vulnerabilities to security@cryptochainai.io. CryptoChain will acknowledge reports within five (5) business days and will not pursue legal action in respect of good-faith research conducted in accordance with our published disclosure policy at [URL].

10. YOUR PRIVACY RIGHTS AND CHOICES

Depending on where you reside and applicable law, you may have the right to:

  • request access to personal information we maintain about you;
  • request correction of inaccurate personal information;
  • request deletion of certain personal information;
  • request a copy or portability of certain personal information;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent; and
  • appeal certain decisions regarding a privacy rights request.

These rights may be subject to exceptions and limitations under applicable law.

To exercise a privacy right, contact us using the information provided in the "Contact Us" section below.

We may need to verify your identity before processing a request.

CryptoChain may be unable to modify or delete information recorded on a public blockchain because CryptoChain does not control the blockchain network.

10.1 How to Submit a Request

You may submit a privacy rights request through the in-app privacy centre, by emailing privacy@cryptochainai.io, or by writing to the address in Section 18. Please tell us which right you wish to exercise and provide sufficient information for us to locate your records, such as the email address associated with your account or the relevant public wallet address.

10.2 Verification

We will take reasonable steps to verify your identity before acting on a request, in a manner proportionate to the sensitivity of the information and the risk of harm from unauthorised disclosure. Verification may involve confirming control of the email address associated with your account or requesting a cryptographic signature from the relevant wallet. We will not require you to create an account solely to submit a request, and we will not retain verification information for longer than necessary.

10.3 Authorised Agents

You may use an authorised agent to submit a request on your behalf. We may require written authorisation signed by you, or a valid power of attorney, and may separately verify your identity.

10.4 Timing and Fees

We will acknowledge a request promptly and respond within forty-five (45) days under US state privacy laws (extendable once by a further forty-five (45) days with notice), within one (1) month under the GDPR and UK GDPR (extendable by two (2) further months for complex requests with notice), within thirty (30) days under PIPEDA, and within the period required by other applicable law. Requests are free of charge, except that we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, in which case we will explain why.

10.5 Appeals

If we decline your request, we will explain the reason and how you may appeal. To appeal, reply to our decision or write to privacy-appeals@cryptochainai.io within a reasonable period. We will respond to an appeal within forty-five (45) days (or sixty (60) days where permitted) and, if the appeal is denied, will provide a method to contact the relevant supervisory authority or attorney general.

10.6 Limits Arising From Blockchain Technology

Personal information written to a public blockchain — including public wallet addresses, transaction amounts, timestamps, and transaction hashes — cannot be erased, rectified, or restricted by CryptoChain, because CryptoChain does not control any public blockchain network. Where you exercise a right of erasure, CryptoChain will delete or de-identify the information held in its own systems and will sever the association between your identity and on-chain data where technically feasible, but the on-chain record itself will persist. You should take this into account before transacting.

11. UNITED STATES PRIVACY RIGHTS

Residents of certain U.S. states may have additional privacy rights under applicable state privacy laws.

Depending on the law and the circumstances, these rights may include rights to:

  • know or access personal information;
  • correct personal information;
  • delete personal information;
  • obtain a portable copy of personal information;
  • opt out of certain targeted advertising;
  • opt out of certain sales or sharing of personal information;
  • opt out of certain profiling or automated decision-making; and
  • limit the use and disclosure of sensitive personal information;
  • opt out of the processing of personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects; and
  • appeal the denial of a privacy request.

CryptoChain will not discriminate against you for exercising privacy rights available under applicable law.

11.1 California Notice at Collection

The categories of personal information CryptoChain collects, the sources, the business purposes, and the categories of recipients are described below. CryptoChain does not sell or share personal information, as described in Section 5H.

  • Identifiers — name, email address, telephone number, account identifier, IP address, device identifier, public wallet address. Sources: you, your device, wallet providers, blockchain networks. Purposes: providing the Services, security, fraud prevention, communications, legal compliance. Recipients: cloud and infrastructure providers, security and fraud vendors, blockchain analytics providers, communications providers, merchants and transaction participants, legal and regulatory recipients.
  • Customer records and commercial information — transaction and routing records, merchant and settlement preferences, billing information, support communications. Sources: you, merchants, blockchain networks, payment and settlement providers. Purposes and recipients: as above, plus product development on an aggregated or de-identified basis.
  • Internet and network activity — usage, interaction, API request, session, and diagnostic data. Sources: your device and our systems. Purposes: operating, securing, and improving the Services. Recipients: analytics, security, and infrastructure providers.
  • Geolocation data — approximate location derived from IP address. Sources: your device. Purposes: security, fraud prevention, sanctions and geographic restriction compliance. Recipients: security and compliance providers.
  • Professional or employment information — company name, job title, business role. Sources: you. Purposes: providing merchant, developer, and business services.
  • Sensitive personal information — government identifier and, where identity verification is performed, document images and biometric identifiers. Sources: you and verification providers. Purposes: only to comply with legal obligations, verify identity, and prevent fraud. Recipients: identity verification and compliance providers. CryptoChain does not use or disclose sensitive personal information for purposes other than those permitted by California Civil Code § 1798.121, and therefore is not required to offer, but will honour, a right to limit its use.
  • Inferences — transaction routing preferences and risk indicators derived from the above. Purposes: providing and improving routing functionality and managing risk.

11.2 De-Identified Information

Where CryptoChain maintains de-identified information, it takes reasonable measures to ensure the information cannot be associated with an individual or household, publicly commits to maintain and use it only in de-identified form and not to attempt re-identification, and contractually obliges recipients to do the same.

11.3 Financial Incentives and "Shine the Light"

CryptoChain does not offer financial incentives or price or service differences in exchange for the retention or sale of personal information. California residents may request information about disclosures of personal information to third parties for their direct marketing purposes under California Civil Code § 1798.83; CryptoChain does not make such disclosures.

11.4 Metrics and Nevada

12. INTERNATIONAL USERS

If you access the Services from outside the country where CryptoChain or its service providers operate, your information may be transferred to, stored in, or processed in another country.

Those countries may have data protection laws that differ from the laws of your jurisdiction.

Where required by applicable law, CryptoChain will use appropriate safeguards for international transfers of personal information.

12.1 Transfer Mechanisms

12.2 European Economic Area, United Kingdom, and Switzerland

If you are in the EEA, the UK, or Switzerland, you have the rights set out in Section 10 and, in addition, the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ico.org.uk). In Switzerland, it is the Federal Data Protection and Information Commissioner. Our lead supervisory authority in the European Union is [TO BE DETERMINED BY REFERENCE TO THE MAIN ESTABLISHMENT — COUNSEL TO CONFIRM]. Contact details for our EU and UK Article 27 representatives appear in the "Controller and Contact Details" section above.

Where processing is based on consent you may withdraw it at any time, and where it is based on legitimate interests you may object at any time on grounds relating to your particular situation; we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests or the processing is necessary for legal claims. You may object to direct marketing at any time without giving reasons. Where we carry out processing likely to result in a high risk to your rights, we conduct a data protection impact assessment under GDPR Article 35.

12.3 Canada

CryptoChain handles personal information in accordance with the Personal Information Protection and Electronic Documents Act and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25. You may withdraw consent subject to legal or contractual restrictions and reasonable notice, request access to and correction of your personal information, and complain to the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information du Québec. Quebec residents additionally have the right to data portability, the right to be informed when a decision is based exclusively on automated processing and to submit observations to a member of our personnel able to review that decision, and the right to request that dissemination of their personal information cease. Personal information may be transferred outside Quebec and Canada; before any such transfer we conduct a privacy impact assessment as Law 25 requires.

12.4 Brazil

CryptoChain processes personal data of individuals in Brazil in accordance with the Lei Geral de Proteção de Dados (Law No. 13,709/2018). The legal bases in Section 4A map to Articles 7 and 11 of the LGPD. You have the rights of confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about shared use, information about the consequences of refusing consent, revocation of consent, review of decisions taken solely on the basis of automated processing, and to petition the Autoridade Nacional de Proteção de Dados. International transfers are made on the bases permitted by Article 33. Our encarregado is identified above.

12.5 Australia

CryptoChain handles personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Personal information may be disclosed to overseas recipients in the United States and other countries in which our service providers operate, and we take reasonable steps to ensure those recipients do not breach the Australian Privacy Principles. You may access and correct your personal information, complain to us, and, if dissatisfied, complain to the Office of the Australian Information Commissioner. We will notify you and the Commissioner of any eligible data breach as required by Part IIIC of the Privacy Act.

12.6 Singapore

CryptoChain handles personal data in accordance with the Personal Data Protection Act 2012. You may withdraw consent on reasonable notice, request access to and correction of your personal data, and complain to the Personal Data Protection Commission. Our Data Protection Officer is identified above. Personal data transferred out of Singapore is protected to a standard comparable to the Act.

12.7 Japan

CryptoChain handles personal information in accordance with the Act on the Protection of Personal Information. Where personal information is provided to a third party in a foreign country, CryptoChain provides in advance information about the country concerned, the data protection system in that country, and the measures taken by the recipient, and obtains consent where required. You may request disclosure, correction, suspension of use, and deletion, and may complain to the Personal Information Protection Commission.

12.8 Other Jurisdictions

13. CHILDREN'S PRIVACY

The Services are directed to adults. Users must be at least eighteen (18) years of age under the CryptoChain Terms of Use, and CryptoChain does not knowingly collect personal information from any person under eighteen (18). CryptoChain does not knowingly collect personal information from a child under thirteen (13) within the meaning of the US Children’s Online Privacy Protection Act, or from a child below the age of digital consent in the relevant EEA Member State (which is between thirteen (13) and sixteen (16) depending on the Member State) or below the age of thirteen (13) in the United Kingdom.

If we learn that we have collected personal information from a child in violation of applicable law, we will take appropriate steps to delete the information.

A parent or guardian who believes a minor has provided personal information to CryptoChain may contact privacy@cryptochainai.io and we will delete it. CryptoChain does not sell or share the personal information of consumers under sixteen (16) years of age.

The Services may contain links to or integrations with third-party websites, applications, wallets, blockchain protocols, and other services.

CryptoChain is not responsible for the privacy practices of independent third parties.

We encourage you to review the privacy policies of third parties before providing information or using their services.

15. MERCHANT AND DEVELOPER CUSTOMERS

Where CryptoChain processes personal information about a Merchant’s or developer’s end customers on that customer’s instructions, CryptoChain acts as a processor, service provider, or operator, and the Merchant or developer acts as controller or business. In those circumstances the CryptoChain Data Processing Addendum governs the processing, and end customers should direct privacy rights requests to the relevant Merchant or developer in the first instance. CryptoChain will assist the customer in responding to such requests as required by GDPR Article 28 and comparable law.

16. ACCESSIBILITY AND LANGUAGE

This Privacy Policy is provided in English. Translations may be provided for convenience; where applicable law requires a local-language version to prevail, that version prevails. If you require this Privacy Policy in an accessible format, contact privacy@cryptochainai.io.

17. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our Services, technology, legal requirements, or business practices.

When we update this Privacy Policy, we will revise the "Last Updated" date above.

Where required by applicable law, we will provide additional notice of material changes.

18. CONTACT US

If you have questions about this Privacy Policy or wish to exercise a privacy right, contact us at:

Doing business as: CryptoChain

Email: founders@cryptochainai.io

Mailing Address: [BUSINESS MAILING ADDRESS]

Privacy requests: privacy@cryptochainai.io

Privacy appeals: privacy-appeals@cryptochainai.io

Security reports: security@cryptochainai.io

Data Protection Officer / Privacy Officer: [NAME], privacy@cryptochainai.io

EU Representative: [NAME AND ADDRESS]. UK Representative: [NAME AND ADDRESS]. Brazil encarregado: [NAME].

For privacy-related requests, please include sufficient information for us to understand and respond to your request.