Privacy Notice
Last updated 24.07.2026
Data protection and data security are important to us. Your Personal Data is collected and processed in accordance with applicable laws and in accordance with this Privacy Notice.
We invite you to read this document (the "Privacy Notice") carefully. If you have any questions about our Privacy Notice and, in general, about the collection and processing of your Personal Data in relation to the RFQ trading interface available at this website (the "Interface"), please do not hesitate to contact us at: privacy@zama.org
Scope
This Privacy Notice governs and details the main principles that apply to the Personal Data collected and processed in relation to the Interface during its closed testing (beta) phase, in which access is granted only to users who have been manually approved (whitelisted) by us.
The purpose of this Privacy Notice is to provide you with all the important information and explanations about how and why some of your Personal Data may be collected and processed when you register for and use the Interface, and to remind you about your data protection rights and how to exercise them.
This Privacy Notice does not apply to the Super App (governed by its own privacy notice) or to any products, services, websites, or content offered by third parties that have their own privacy notice. It applies to the closed beta only; when the product is made publicly available on the Super App, the applicable notice will be updated accordingly.
Important Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that identifies the person directly (e.g. a name or an e-mail address) or indirectly (e.g. an IP address or a wallet address in context).
- "Processing" means any operation performed on Personal Data, such as collection, recording, organisation, storage, disclosure by transmission, etc.
- "Controller" means an entity that determines the purposes and means of Processing.
- "Processor" means an entity that processes Personal Data on behalf of and on the instructions of the Controller.
How Your Personal Data is Collected and Processed
Data you provide when registering for the testing program:
To take part in the closed testing program, you register through a landing page and an associated form. In doing so, the following data is collected and stored in HubSpot:
- E-mail address: captured via the landing page.
- Wallet address, affiliation, and free-text responses: collected via the follow-up registration form, comprising your Ethereum public wallet address, your affiliation (the organisation you represent), and two free-text responses regarding your trading needs.
Data arising automatically from your use of the Interface:
- Wallet address: when you connect your wallet to the Interface, your wallet address (a public on-chain identifier) is processed. Authentication is handled by Privy (wallet login only).
- IP address: your IP address is collected as a technical by-product of standard HTTP exchanges with the Interface's infrastructure (Vercel hosting and the QuickNode RPC provider), and is seen transiently by our server-side proxies and by Upstash (EU region) for rate limiting and abuse prevention. IP addresses are used solely for the technical operation and protection of the Interface and are not retained directly.
- Error and diagnostic data (Sentry): Sentry is configured to exclude wallet addresses and amounts from error reports. Publicly visible on-chain data may appear in error logs for debugging purposes. Error report data does not directly identify any individual.
- FHE decryption (Zama relayer): a Zama-operated relayer performs the fully homomorphic encryption (FHE) decrypt round-trip required for the Interface to function. This touches the ciphertext handles, your requesting wallet address, and the transient request IP. No off-chain identity data (such as e-mail or name) is involved, and no identity-level data is persisted.
- Wallet screening (Hypernative): your wallet address and related transaction data are submitted to Hypernative for anti-money-laundering (AML) risk checks and sanctions/blacklist screening. Hypernative acts as an independent controller, processing the address against its own risk database.
- Client-side storage: the Interface keeps your FHE decrypt permits and transport key pairs in your own browser (IndexedDB); these are cleared when you disconnect your wallet. Our RFQ backend and internal market-maker quoting service operate on-chain and transiently, and do not store or log wallet addresses or other personal data off-chain.
Why Your Personal Data is Collected and Processed
When you register for and use the Interface, some of your Personal Data is collected and processed for the following purposes and on the following legal bases:
To administer the closed testing program
Your e-mail address, wallet address and affiliation are processed to register you, verify eligibility, and administer the program you signed up for. Your free-text responses are used to understand testers' needs and to develop and improve the product. Legal basis: performance of contract (nFADP Art. 31(1)(b) / GDPR Art. 6(1)(b)) for administering the program, and legitimate interest (nFADP Art. 31(1)(e) / GDPR Art. 6(1)(f)) for product development.
To provide and operate the Interface
Your wallet address and IP address are processed to authenticate your session, enable functionality, and operate and protect the technical infrastructure. Legal basis: performance of contract (nFADP Art. 31(1)(b) / GDPR Art. 6(1)(b)) and legitimate interest (nFADP Art. 31(1)(e) / GDPR Art. 6(1)(f)).
To detect and fix software errors
Sentry is used for error tracking and diagnostic purposes; wallet addresses and amounts are excluded. Legal basis: legitimate interest (nFADP Art. 31(1)(e) / GDPR Art. 6(1)(f)).
To provide customer support
Privy logs wallet address and session timestamp data, which may be used to identify and assist with support requests. Legal basis: legitimate interest (nFADP Art. 31(1)(e) / GDPR Art. 6(1)(f)).
To screen wallets and transactions
Your wallet address and related transaction data are submitted to Hypernative for AML risk checks and sanctions/blacklist screening. Legal basis: legitimate interest (nFADP Art. 31(1)(e) / GDPR Art. 6(1)(f)) in preventing illicit or high-risk actors from using the protocol and in protecting the platform and its users; the sanctions/blacklist screening is additionally grounded in compliance with a legal obligation (nFADP Art. 31(1)(c) / GDPR Art. 6(1)(c)).
To manage requests to exercise data protection rights
Your information is processed to handle and respond to your data protection rights requests. Legal basis: compliance with a legal obligation (nFADP Art. 25 / GDPR Art. 6(1)(c)).
Who Are the Recipients of Your Personal Data?
Internal recipients: our authorised staff and, where strictly necessary, the authorised staff of affiliated entities. For registration data held in HubSpot, access is limited to our Head of Marketing and the product lead.
External recipients acting as Processors within the meaning of the nFADP/GDPR, processing data on our behalf, according to our instructions and under appropriate security and confidentiality measures:
- Privy, Inc. (wallet authentication and session management) 2640 E 26th St, Vernon, CA 90058-1218, US: wallet addresses, session timestamps.
- Vercel, Inc. (hosting and CDN) 340 Pine Street, 5th Floor, San Francisco, CA 94104, USA: IP addresses (via HTTP traffic).
- QuickNode (RPC provider) Florida, USA. Transfers to the US governed by the EU Standard Contractual Clauses in QuickNode's Data Processing Agreement; provider-side retention up to seven (7) years per QuickNode's privacy policy: IP addresses (seen transiently) and on-chain request data.
- Goldsky (subgraph / indexing) 9450 SW Gemini Dr, PMB 68694, Beaverton, Oregon 97008, USA: on-chain activity data (publicly available blockchain data).
- Sentry (Functional Software, Inc.) (error tracking) 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA: error logs (no wallet addresses, no amounts).
- Upstash, Inc. (rate limiting on server-side proxies) San Jose, CA, USA (incorporated in Delaware); our deployment is in the EU region. Upstash is certified under the EU-U.S. Data Privacy Framework (and the UK Extension and Swiss-U.S. DPF), and its DPA incorporates the EU SCCs (upstash.com/trust/dpa.pdf): IP addresses seen transiently for rate limiting, not retained.
- HubSpot Ireland Limited (registration and consent store) HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, Ireland (company no. 515723); portal hosted in the EU data centre (Frankfurt), so registration data is stored in the EEA. Some processing may occur in the US via HubSpot and its sub-processors, covered by the EU-U.S. Data Privacy Framework and the EU SCCs in HubSpot's DPA (legal.hubspot.com/dpa): e-mail address, wallet address, affiliation, free-text responses, and acceptance records.
- Zama relayer (FHE decryption) Zama-operated (intra-group): ciphertext handles, requesting wallet address, and transient request IP; no off-chain identity data and no identity-level data persisted.
External recipients acting as independent Controllers within the meaning of the nFADP/GDPR:
- Hypernative Inc. (wallet screening; AML risk checks and sanctions/blacklist screening) 850 New Burton Road, Suite 201, Dover, DE 19904, USA (per its published privacy policy; R&D in Israel). Transfers governed by the EU SCCs / recognised transfer mechanisms per its privacy policy: wallet addresses and transaction data.
Authorities: only to the extent required by applicable laws and regulations.
For How Long Is Your Personal Data Stored?
Your Personal Data is retained only for as long as strictly necessary for the purposes declared above, and in any event within the limits imposed by applicable law:
- Registration data (HubSpot — e-mail, wallet address, affiliation, free-text responses): retained for the duration of the closed beta and permanently deleted within thirty (30) days of its conclusion. Any data kept beyond that point for aggregate product analysis is irreversibly anonymised, with e-mail address and wallet address stripped.
- Acceptance / consent records (clickwrap): the wallet-signed acceptance of the Interface Terms and this Privacy Notice (recording document versions and timestamp) is stored against your HubSpot record.
- Wallet addresses (Privy): retained for the duration of the service relationship plus any applicable statutory retention period; users may request deletion.
- Error logs (Sentry): typically retained for ninety (90) days.
- On-chain transaction data: publicly recorded on the blockchain, permanent by nature; we have no ability to delete on-chain records.
- IP addresses: processed transiently for technical transport and abuse-prevention purposes; we do not retain IP addresses directly.
- Data protection rights requests: retained for five (5) years (prescription).
At the end of the relevant retention periods, we undertake to delete or anonymise your Personal Data from our systems, subject to any overriding legal, accounting, or tax obligations.
Are Your Personal Data Transferred Across Borders?
Several of our sub-processors are based outside Switzerland and the EEA, so cross-border transfers of Personal Data are required. In such cases, appropriate safeguards are in place. The standard mechanism is the adoption of Standard Contractual Clauses (SCCs) as adopted by the European Commission (2021 version), supplemented, where required, by a Transfer Impact Assessment.
- Transfers to the United States (Privy, Vercel, Goldsky, Sentry, QuickNode): governed by Standard Contractual Clauses and the applicable Data Processing Agreements with each provider.
- HubSpot: registration data is stored in the EU data centre (Frankfurt). Some processing may occur in the US via HubSpot and its sub-processors, covered by the EU-U.S. Data Privacy Framework and the EU SCCs in HubSpot's DPA.
- Upstash: deployed in the EU region; its DPA incorporates the EU SCCs where any transfer arises.
- Wallet screening (Hypernative): Hypernative Inc. is US-based (Dover, Delaware); transfers are governed by the EU SCCs / recognised transfer mechanisms per its privacy policy.
- Intra-group transfers: appropriate intra-group data sharing arrangements are in place.
How Your Personal Data is Protected
To prevent unauthorised access, disclosure, modification, damage, or destruction, appropriate technical and organisational security measures are implemented, including:
- Privacy-by-design architecture: the Interface is largely stateless, driven by wallet login and on-chain data. Confidential values are encrypted on-chain using TFHE; we cannot access them.
- Proxied egress: the browser communicates via our proxies, which strip cookies and IP-forwarding headers before forwarding requests upstream, minimising data exposure to upstream providers.
- Client-side key handling: FHE decrypt permits and transport key pairs are held in your own browser (IndexedDB) and cleared on wallet disconnect.
- Minimised backend footprint: the RFQ backend and internal quoting service store no off-chain personal data.
- Standard security measures: HTTPS throughout, access controls on backend systems, and regular security reviews.
Children's Privacy
The Interface is not directed at individuals under the age of 18. We do not knowingly collect Personal Data from minors. If you believe that we have inadvertently collected Personal Data relating to a child, please contact us at privacy@zama.org and we will promptly delete such data.
Cookies
During the closed beta, the Interface uses strictly necessary cookies and local storage only. No analytics, advertising, or tracking cookies are used. Because these technologies are strictly necessary to provide the service you have requested, they are exempt from consent, and no consent banner is displayed. We nonetheless list them below for transparency:
| Name / type | Purpose | Category |
|---|---|---|
| Wallet session | Maintains your authenticated wallet session while you use the Interface. | Strictly necessary |
| Consent / preference | Stores your interface preferences (e.g. session state). | Strictly necessary |
When analytics are introduced for the public launch, a full cookie consent banner (with equal-prominence "Accept All" and "Refuse All" options) and a separate Cookies Notice will be deployed at that time.
What Are Your Rights and How Can You Contact Us?
Regarding your use of the Interface, you have the following rights under the conditions provided for in the applicable regulations:
- The right of access, rectification, and erasure of your Personal Data (nFADP Art. 25 / GDPR Arts. 15–17). Note: on-chain transaction data is publicly recorded and immutable; we cannot delete blockchain records.
- The right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- The right to restriction of Processing of your Personal Data (GDPR Art. 18).
- The right to object to Processing based on legitimate interest, on grounds relating to your particular situation (GDPR Art. 21 / nFADP Art. 30).
- The right to Personal Data portability (GDPR Art. 20) for data processed by automated means on the basis of consent or contract.
- The right to lodge a complaint with the competent supervisory authority (see below).
Additional information for specific jurisdictions:
- If you are located in Switzerland: the Swiss Federal Act on Data Protection (nFADP/DSG) applies. You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch.
- If you are located in the European Economic Area (EEA): the GDPR also applies. You may lodge a complaint with the supervisory authority of the EU Member State of your habitual residence or place of work.
- If you are located in the United Kingdom: the UK GDPR applies. You may lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
- If you are located in the United States (California): the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies. California residents have the right to know what personal data we collect and how it is used, to request deletion or correction of their personal data, and to opt out of the "sale" or "sharing" of personal data. We do not sell personal data for monetary consideration; however, our use of Google Analytics 4 may constitute "sharing" for cross-context behavioural advertising purposes under the CCPA/CPRA. To opt out, click the "Do Not Sell or Share My Personal Information" link in the persistent footer of the App, or enable a Global Privacy Control (GPC) signal in your browser or device (honoured automatically, with no further action required). You also have the right not to be discriminated against for exercising these rights. Opt-out requests are processed within 15 business days of receipt. The supervisory authority is the California Privacy Protection Agency (CPPA) at cppa.ca.gov.
- If you are located in Brazil: the Lei Geral de Proteção de Dados Pessoais (LGPD) applies. You have the right to confirm the existence of processing, and to access, correct, delete, port, or object to the processing of your personal data. You may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.
- If you are located in Canada (Québec): Québec's Act respecting the protection of personal information in the private sector (Law 25) applies to residents of Québec. You have the right to access, correct, and request the deletion of your personal data, and to withdraw your consent at any time. You may lodge a complaint with the Commission d'accès à l'information (CAI) at www.cai.gouv.qc.ca.
You can exercise your rights by email at privacy@zama.org, specifying the right you wish to exercise and attaching proof of your identity if requested.
If you exercise these rights, we will endeavour to respond to your request as soon as possible.
Changes to This Privacy Notice
This Privacy Notice will be updated when processing activities change or when required by applicable law. Material changes will be communicated via an in-Interface notice. We recommend checking this Privacy Notice periodically. The version date at the top of this document indicates when it was last updated.
Contact
For any questions or requests regarding this Privacy Notice or the processing of your Personal Data, please contact us at: privacy@zama.org