OnChain Network Privacy Policy

1. Introduction

    This Privacy Policy contains information on the rules for the processing and protection of any of your personal data as the user (the “User”) of the OnChain Network, as well as any and all other applications and features based on web3 or traditional web2 software (whereby the data are stored on servers that are our own and/or in rented cloud computing space, the “Web 2 storage”) and/or web3 protocol (i.e. the protocol based on distributed ledger technology (the “DLT”), whereby the data are is stored in many user computers participating in the network, the “Web3 Protocol”), together, the “OnChain Network”, developed by or upon the order of ●●● (the “Company”, “we,” “our,” or “us”).

    The privacy of the Users and the security of their data that are not designated to be publicly available is the overriding goal of the Company. We make best effort to protect your personal data. We want the security measures we use to be effective and guarantee confidentiality and integrity and availability of processed data.

    2. Acceptance of the Policy

      By downloading and/or registering as the user and/or using any application or feature being part of OnChain Network, you accept the terms of this Policy, and consent to our collection, use, disclosure and retention of your information as described in this Policy. If you do not agree with this Policy, you should not use the OnChain Network.

      3. No liability for information shared with other Users

        We bear no responsibility for the personal data and other information shared by you with any other User(s) with the use of or through the OnChain Network. Any collection, storage and/or processing of such information is at the exclusive discretion and responsibility of its recipient. 

        You, as the recipient of the personal data and other information relating to other Users, should make sure that your use of such data is compliant with the relevant laws.

        4. Information collected that is provided by you

          We collect the following information provided by you to us:

          5. Disclosure of information in the Web 2 storage phase

            Before the launch of Web 3 Protocol, the following information provided by you to us will be available to other Users without restriction:

            and

            6. Disclosure of information following the launch of the Candao Web 3 Protocol (i.e.  the “Token Generation Event”) 

              Following the Token Generation Event (its exact date will be determined separately), the following information provided by you to us will be available to other Users without restriction:

              7. Information collected automatically

                We use tracking technologies to automatically collect information, including the following:

                8. Public information collected

                  We may collect and process data from activity that is publicly visible and/or accessible on the DLT. This may include public key to your cryptocurrency wallet as well as any information available on the DLT relating to the operations made with the use of the cryptocurrency wallet.

                  The OnChain Network adheres to our Web3 Protocol. We will create/release other applications which also will adhere to such protocol. The data will be download from the protocol and shared with such applications. Therefore, please be informed that, as the protocol is open, such applications can also be developed by others, with or without agreement with us.

                  9. User content

                    In case the OnChain Network will allow to communicate (i.e. make calls, send and receive messages and media within such messages (including content like images, audio, video, other documents or files) to or from the other Users), they will be end-to-end encrypted, which means they will be encrypted to protect against third parties (including us) form seeing that content.

                    We will temporarily store your messages in encrypted form while they are being delivered. Once your messages are delivered, they are deleted from our servers.

                    For the avoidance of doubt, we are not nor will be involved nor will we bear any responsibility for the storage and/or processing of information shared by you with any other User. 

                    10. Use of personal data by us

                      We process your personal data for the following purposes:

                      1. to operate, manage and perform the OnChain Network, including without limitation:
                      1. to protect the security and integrity of the OnChain Network; improving the OnChain Network, including verifying your eligibility and delivering prizes in connection with your entries as well as fulfilling any other business purpose, with notice to you and upon your consent;
                      2. to communicate with you in order to inform you on changes in this Policy.

                      Notwithstanding the above, we may use information that does not identify you (including information that has been aggregated or de-identified), except as prohibited by applicable law. Please see also the “Cookies. Tracking” section below.

                      11. Period of personal data storage

                        Your personal data will be processed as long as you use the OnChain Network. Subsequently, your data will be kept by us for period resulting from legal provisions regarding the implementation of the archiving obligation and for the period of limitation of claims.  

                        The above limitation is without prejudice to the fact that any of your activities that will be recorded with the use of the DLT, while not collected or processed by us, will be permanently stored in the DLT decentralized database and accessible to anyone (for more explanation, see item 13 below. 

                        12. Your rights in connection with the processing of personal data

                          Within the limits set by the DLT (see section “DLT is permanent and immutable storage of data” below), you have the right to:

                          If at any point you wish to exercise the any of the rights indicated above, you may contact us via our email listed in the “Contact Us” section below. 

                          13. DLT is permanent and immutable storage of data

                            Nearly all data you provide and nearly all your activities will be recorded in the DLT. Therefore, irrespective of our discontinuation of storing and processing your personal data, we do not own nor control the records of your personal data stored in the DLT and no one does. Due to the decentralized technical characteristics of the DLT, all data ever recorded in the DLT, including without limitation, public key of your Wallet, information provided by you and/or automatically collected as well as details of all operations conducted by you, remain in the DLT, are immutable and accessible to and may be processed by any third party at any time, with or without your consent. In addition, without the action of any other user of the DLT, no such information can be deleted from his/her wallet, despite you delete it from your Wallet. In other words, data once stored in the DLT cease to be anyone’s property and remain there in permanence. In addition, please be aware that our Web3 Protocol is an open protocol. Consequently, any third party will be able to create and launch new application or feature that will be part of and/or will be compatible with the OnChain Network but will not be controlled by us (each, the “Third Party App”). Any such Third Party App may have an access and that can search and process the resources (including your personal data) stored in the DLT. Consequently, this Privacy Policy does not address the possible use of your personal data by any such Third Party App and/or its originator. 

                            14. Data security

                              We work to protect the security of your personal information during transmission by using encryption protocols and software. Despite all such efforts, we cannot fully guarantee against the access, disclosure, alteration, or deletion of data through events, including but not limited to hardware or software failure or unauthorized use. The OnChain Network, and most importantly, the proper functioning of it require the Internet and the security of information transmitted through the Internet can never be guaranteed. We are not responsible for any interception or interruption of any communications through the Internet or for changes to or losses of data. 

                              You are responsible for maintaining the security of your private key, any password or other form of authentication involved in obtaining access to password protected or secure areas of the OnChain Network. In order to protect you and your data, we may suspend your usage of the OnChain Network, without notice, pending an investigation, if any breach of security is suspected.

                              15. Sharing the personal data

                                We may share or disclose information that we collect in accordance with this Policy to:

                                We also share information to comply with the law or other legal process, and where required, in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may share information about you at your request or direction.

                                Notwithstanding the above, we may share information that does not identify you (including information that has been aggregated or de-identified) except as prohibited by applicable law. Please see also the “Cookies. Tracking” section below.

                                16. International transfer

                                  We have the affiliates and the service providers in other countries around the globe. Proper functioning of the OnChain Network may therefore require that your personal information may be transferred to or from Seychelles or any other location outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

                                  EU User should know that whenever we transfer their personal information out of the European Economic Area (EEA) to other countries or jurisdictions not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be based on a data transfer mechanism recognized by the European Commission as providing adequate protection for personal information.

                                  17. Third-Parties websites or services

                                    Please note that this Policy does not apply to information collected through third-party websites or services that you may access through the OnChain Network. Those third parties may independently collect information about you and solicit information from you. The information collected and stored by those parties remains subject to their own policies and practices, including what information they share with us, your rights and choices on their services and devices, and whether they store information. We encourage you to familiarize yourself with and consult their privacy policies and terms of use.

                                    18. Cookies. Tracking

                                      19. Additional Disclosures for data subjects in the European Economic Area and the United Kingdom.  

                                        This section applies if you are a resident of the European Economic Area or the UK. 

                                        A. Roles. 

                                        Under the General Data Protection Regulation in the European Economic Area and the United Kingdom (“GDPR”), we act as a “controller” with respect to personal data collected as you interact with the OnChain Network. 

                                        B. Lawful Basis for Processing. 

                                        The GDPR requires that any processing of personal data is done on a lawful basis. Our lawful bases include where: (i) you have given consent to the processing for one or more specific purposes, either to us or to our service providers or partners; (ii) processing is necessary for the performance of a contract with you; (iii) processing is necessary for compliance with a legal obligation; or (iv) processing is necessary for the purposes of the legitimate interests pursued by us or a third party, and your interests and fundamental rights and freedoms do not override those interests. Where necessary in the context of the OnChain Network, we will transfer your personal data to third parties subject to appropriate or suitable safeguards, typically standard contractual clauses. 

                                        C. Your Rights. 

                                        If you are a use the OnChain Network in the EEA or the U.K., you maintain certain rights under the GDPR. These rights include the right to (i) request access and obtain a copy of your personal data; (ii) request rectification or erasure of your personal data; (iii) object to or restrict the processing of your personal data; and (iv) request portability of your personal data. Additionally, if we have collected and processed your personal data with your consent, you have the right to withdraw your consent at any time. 

                                        Please note that in no circumstance we can edit or delete information that is stored on a particular the DLT as we do not have custody or control over any the DLT. This information includes all transaction data related to your interaction with the OnChain Network. 

                                        To exercise any of your rights under GDPR, including in cases when you have any issues with our compliance, please contact us via our email or postal address listed in the “Contact Us” section below and specify which right you are seeking to exercise. We will respond to your request within thirty (30) days. We may require specific information from you to help us confirm your identity and process your request. Please note that we retain information as necessary to fulfill the purpose for which it was collected and may continue to retain and use information even after a data subject request in accordance with our legitimate interests, including as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements. 

                                        You also reserve the right to lodge a complaint with the data protection regulator in your jurisdiction.

                                        20. Changes to the Privacy Policy

                                          We may change this Policy at any time by posting the amended Policy with the use of the OnChain Network. The amended Policy will be effective immediately. For the avoidance of doubt, your continued use of the OnChain Network will be mean that you expressed your consent to such an amended Policy.

                                          21. Change of the data processor 

                                            The managing of the Site may be transferred to our affiliate company; thus, we will also transfer the data processing. We will inform you of such change in accordance with section “Changes to the Privacy Policy” above. Your continued use of the OnChain Network will be mean that you expressed your consent to such a transfer.

                                            22. Contact Us

                                            If you have any questions or comments in connection with this Policy or our compliance with them, please contact us at privacy@candao.io.