Privacy Policy
Axiome Privacy Policy
Last Updated: 01.02.2024
Introduction
This Privacy Policy governs the practices of how Axiome (the Axiome entities listed in Section 2 below, referred to herein as “we”, “our”, “ours” or “us”) collects, uses, transfers, and shares personal information related to the use of our Services by our Users (referred to herein as “you”, “your”, or “yours”). This Policy is designed to ensure the transparent, lawful, equitable, and secure management of the personal data of our Users.
Our Privacy Policy explains what kind of personal data we gather through Services, which include services you access through Axiome websites and any other sites associated with Axiome (collectively referred to as “the Website”), Axiome applications and software developed by Axiome independently or through contractual third parties, including the self-custodial wallet, web applications, mobile applications, decentralized applications (dApps), and any other applications and software associated with Axiome (collectively referred to as “the App”) as well as all products, smart contracts, protocols, Axiome Chain ecosystem and the Axiome Chain network (“Network”) and the delegation program for earning rewards by delegation of the native AXM token (“Token”) through the 'delegated proof of stake' (“DPoS”) mechanism. It demonstrates how and why we collect personal data, our purposes for its use, and the third parties with whom we may share it. Moreover, it explains how you as a data subject may exercise your rights in relation to your personal data.
If you reside outside of the UK and the European Economic Area (the “EEA”), your access to and use of our Services shall mean your acceptance of this Policy.
Should any alterations be made to this Policy (alongside other policies, including our Terms of Use), we will notify you of such changes through our official communication channels, including email, our official Telegram channel, and in-app notifications, as well as directly on this page.
We strongly encourage you to read this Policy in its entirety to understand the processes involving your data and your associated rights. For inquiries related to this Privacy Policy, data collection and usage, data disclosure, and sharing, or any other concerns or requests related to your personal data, please do not hesitate to get in touch with us by writing to us at [email protected].
1. Definitions
The following section covers the basic definitions used in this Privacy Policy. It describes what is meant by your personal data and who controls and processes your personal data.
Personal Data: Personal data means any information that relates to an identified or identifiable natural person. This includes details like names, addresses, email addresses, identification numbers, and even things like IP addresses or cookie identifiers, as well as any information found online that may reveal your physical, genetic, mental, economic, cultural or social identity.
Data Subject: The data subject is the person who the personal data is about. In simpler terms, it’s you or any other individual whose personal information is being collected and processed.
Data Controller: The data controller is the one who determines the purposes and means of processing personal data. In other words, they're the boss when it comes to deciding why and how your data is used. In this case, it would be us.
Data Processor: The data processor, on the other hand, processes personal data on behalf of the data controller. In our case, they are vendors and partners we collaborate with that process your personal data for purposes determined by us.
2. Axiome Entities and Relationship with You
For Users residing in the EEA and Switzerland: AXIOME HOLDINGS S.R.L., CRYPTOLINK MARKETING SOLUTIONS S.R.L. and DeTech Global Inc. are joint controllers of your personal data.AXIOME HOLDINGS S.R.L acts as a primary controller, meaning that it is responsible for providing you with relevant information under the GDPR as well as responding to your requests and inquiries submitted to us.
Please see the table below for detailed information on the range of services provided to you by each of the Axiome entities and the contact information of each entity. You can see more about how you can exercise your rights as a data subject under Section [number] of this Policy.
3. Information We Collect
In order to provide our Services, we need to gather information about you. Due to the decentralized nature of our Services, we strive to collect as little personal information from you as possible, minimizing it to the information strictly necessary to provide our Services. This information may be collected by various means, for example, directly from you when you reach out to us by email or through our Telegram channel, or, in some cases, through third parties, to an extent necessary to provide our Services. Below you will find information about personal data that we may collect through the aforementioned means.
We will never request information related to your racial or ethnic background, personal life, sexual orientation, political views, philosophical or religious beliefs, biometric or genetic data, or trade union membership.
Information that You Provide
This category covers content and details that you provide while accessing and using our Services. We collect the following personal information as outlined in the table below:
Information from Third Parties
In our continuous effort to provide you with our Services, we may obtain personal data from third-party partners and vendors. In case of such integration, the information collected by our partners is shared with us. We require our partners to have lawful purposes to collect, process, and use your personal data before sharing it with us. There are multiple instances in which we may collect personal information from third-party partners and vendors, which you can see in the table below.
Information Collected Automatically
This type of information is collected from you without the involvement of us or our third–party partners, mainly by your access to the Website and App and the use of our Services. Such information includes the following categories and examples:
Communications
If you reach out to us directly, we may request additional information such as your name, email address, personal address, phone number, and other relevant personal details. Whenever we ask for this information during communication, we will clearly explain the reasons behind it.
Please note that we will never ask you to provide your private key when communicating with you. You should exercise caution and responsibility regarding the handling and safeguarding of your private keys. In the event of a private key loss or compromise, we cannot intervene or rectify the situation, as there is no mechanism for altering the private key post-compromise, as all account-related data is connected to the original private key. You are solely responsible for the protection and retention of your private keys.
4. How We Use Your Data
Lawful Basis and Legitimate Interest
Our collection, use, and sharing of your personal data are founded on various lawful bases, depending on the context. The following scenarios represent the circumstances in which we engage in data collection:
Consent: We process your personal data when you grant your explicit consent. This typically occurs when you have reviewed our data processing purposes and willingly agreed to them. Examples include subscribing to our marketing notifications and campaigns or permitting the use of your personal information to enhance your experience while using our Services.
Performance of a contract: We process your information when it is essential to perform a contract with you (for example, our Terms of Use). This encompasses situations where your data is required for processing and finalizing your orders or adhering to the terms of any other contractual agreement we have entered into with you. It also includes enforcing the terms of this Policy and other agreements, providing our Services, ensuring the quality of our Services, and offering customer service and support.
Legal Obligation: We use your data when there is a legal obligation that necessitates data disclosure. This occurs when compliance with legal requirements imposed by law or legal orders is mandatory.
Legitimate Interests: We may process your personal data when we have a legitimate interest that aligns with the operation and provision of our Services. This includes activities aimed at improving our Services, maintaining proper security measures, and preventing illegal activities related to your data. Our legitimate interests are pursued only when they do not infringe upon your fundamental rights.
In the table below you will find the list of purposes for which we use your data, and what lawful bases we invoke for its use.
5. How We Share Your Data
We may share the information we collect with various third parties to support and enhance our business operations.
For users located in the EEA and Switzerland, please be aware that certain service providers operate outside of the EU/EEA area. For detailed information on how your data is handled when shared with third parties located outside of the EU/EEA, please refer to the section on Data Transfers Outside EU/EEA below. This section clarifies the types of third parties with whom we share information and highlights the presence of non-EU/EEA service providers for transparency regarding data handling practices.
Vendors and Service Providers
We collaborate with vendors and service providers who assist us in maintaining and optimizing our business. These service providers encompass a range of functions, including web and mobile analytics services, advertisers, IT partners, such as hosting and software providers as well as sales and marketing products.
Advertisers
In our commitment to providing you with a seamless experience, we may share certain information with advertisers who play a role in enhancing our Services. These advertisers assist us in delivering relevant content and promotions tailored to your interests. The information shared with advertisers may include user preferences, interaction patterns, engagement with advertising campaigns, and interest-based data. Our collaboration with advertisers aims to provide you with advertisements that align with your preferences and interests.
Business Partners
To jointly deliver integrated services, promotions, or joint initiatives, we may share specific information with our trusted business partners in various fields. The data shared with business partners can encompass a variety of relevant information to support our shared objectives. Any information shared is handled in compliance with data protection laws and regulations, and it is used exclusively for the purposes of delivering the intended services and enhancing your overall experience.
Law Enforcement
In exceptional circumstances and as required by applicable laws and regulations, we may share your information with law enforcement agencies and competent authorities. This is done to support investigations, maintain legal compliance, and ensure the safety and security of our Services and Users. It may be necessary in the case of court proceedings, complying with a legal order or other legal process, as well as for the purposes of financial crime, money laundering and terrorism financing prevention, if we have strong grounds to believe any natural or legal person to be involved in or associated with the said forms of crime.
Transfers, Mergers and Acquisitions
In cases of our insolvency, bankruptcy, acquisition, transfer of ownership, sale of assets or succession, your personal information may be disclosed to the new owner, acquirer or successor of the company or other relevant third parties.
6. How Your Data Is Secured
We consider the security of your personal information to be of paramount importance. We employ a range of technical, organizational, and administrative measures designed to safeguard your data against unauthorized access, disclosure, alteration, and destruction. These security measures include:
Data Encryption: We utilize industry-standard encryption protocols to protect data during transmission and storage. This ensures that your information remains confidential and secure.
Access Controls: Access to your personal information is restricted to authorized personnel who require access for legitimate business purposes. Access controls and authentication mechanisms are implemented to verify and restrict access.
Employee Training: Our team is trained in data security best practices to ensure they handle your information with care and adhere to strict data protection guidelines.
Data Backups: Regular data backups are performed to prevent data loss in case of unexpected events or system failures.
Incident Response: We have established incident response procedures to promptly address and mitigate any security incidents or breaches, should they occur.
Blockchain Technology: Our Services operate on blockchain technology, which inherently provides transparency, immutability, and decentralization. This ensures that your transactional and personal data is stored securely across multiple nodes, reducing the risk of unauthorized alterations or data breaches.
User-Controlled Data: As a User, you maintain control over your personal information through private keys to your Axiome Wallet. Your data is encrypted and accessible only by you, reducing the exposure to external threats.
Regular Audits and Updates: Our team conducts regular security audits and updates to identify and mitigate potential vulnerabilities or weaknesses in the Website’s and the App's infrastructure.
Data Minimization: We collect and store only the minimum amount of personal information necessary to facilitate your transactions and provide our Services. Unnecessary data is not retained, reducing the potential impact of any security incidents.
User Education: We encourage users to educate themselves about blockchain security best practices and the responsible management of private keys and digital assets. We provide resources and guidance to help you protect your data effectively.
If you ever have concerns about the security of your data, suspect any unauthorized activity, or would like to know the specific measures undertaken to secure your personal data, please don't hesitate to contact us via email at [email protected].
7. Data Retention
Your personal information is held and stored securely for the duration of your active account with us. We are committed to retaining your personal information only for the period necessary to fulfill the specific purposes for which it was collected. The retention periods may vary depending on the type of personal information and the purposes for which it was initially gathered. Here's an outline of our data retention practices:
8. Your Rights as Data Subject
As a User of our Services, you have certain rights regarding the personal data that we collect and use. These rights are designed to provide you with control and transparency over your data. The following are your rights as a data subject:
Right to Access: You have the right to request access to the personal data we hold about you. This includes the right to obtain confirmation of whether we are processing your personal data and, if so, access to specific details of that processing.
Right to Rectification: If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to request the correction or completion of such data.
Right to Erasure (Right to Be Forgotten): You have the right to request the deletion of your personal data under certain circumstances. This right is not absolute and may be subject to legal requirements or legitimate interests that override your request.
Right to Restriction of Processing: You can request the restriction of processing of your personal data in certain situations. This means that we will limit the way in which we use your data, but we may continue to store it.
Right to Data Portability: In some cases, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another data controller.
Right to Object: You have the right to object to the processing of your personal data, including for direct marketing purposes or when we rely on legitimate interests as our legal basis for processing.
Rights Related to Automated Decision-Making and Profiling: We commit to transparent and fair automated decision-making processes. If you are subject to automated decision-making that produces legal effects or significantly affects you, you have the right to request human intervention and reconsideration of the decision.
Exercising Your Rights
To exercise any of the rights outlined above or if you have any questions or concerns regarding the processing of your personal data, please contact us via our official communication channels. Our dedicated personnel will assist you in addressing your data-related inquiries and ensuring that your rights as a data subject are respected and upheld.
You will not be charged a fee for accessing your personal data or exercising any of the rights outlined above. In the rare event that your request is manifestly unfounded or excessive, we reserve the right to charge a reasonable fee. This fee, if applicable, will be based on the administrative costs associated with processing your request. Alternatively, we may choose to refuse to comply with your request in these exceptional circumstances. If such a situation arises, we will provide a clear and transparent explanation for our decision. Please note that we will always act in accordance with applicable data protection laws and regulations when assessing the reasonableness of any fees or the validity of requests.
We are committed to responding promptly to legitimate requests regarding your personal data. The statutory period for us to reply to such requests is one month from the date of receipt. However, in situations where the request is particularly complex or there is a high volume of requests, we may extend this period by up to two further months as necessary. This extension will be based on a careful consideration of the complexity and number of requests received.
In addition to the means of exercising your rights outlines above, you have the right to lodge a complaint about our practices with the competent authorities of the country where you reside:
- If you reside in the EEA, the UK, or Switzerland, you have the right to lodge a complaint with the data protection authority of your country. You can find the list of data protection authorities of the EU and EEA countries with contact details here: https://dataprivacymanager.net/list-of-eu-data-protection-supervisory-authorities-gdpr/. In the UK, the supervisory authority is the Information Commissioner’s Office, see the ICO’s official website for more detailed information at https://ico.org.uk/.
- If you reside outside of the EEA, the UK, or Switzerland, you may turn to your local supervisory authorities for lodging a complaint about our privacy practices.
9. Data Transfers Outside of the EU/EEA
If you reside in the EEA, the UK, or Switzerland, this section is relevant for you. As some of our business partners, vendors, and service providers are located outside of the European Union or European Economic Area, we may need to transfer your personal data to countries outside of the EU/EEA zone.
We take stringent measures to ensure that such transfers are conducted in compliance with applicable data protection laws and that your data remains adequately protected.
Transfers to and from Processors in Countries with Adequacy Decisions
Some of our data processing activities may involve transfers to and from data processors located in countries that have received adequacy decisions from the European Commission. Adequacy decisions confirm that these countries provide a level of data protection that is deemed equivalent to EU/EEA standards. When such transfers occur, your data is adequately protected by the recipient's legal framework.
Transfers from and to Other Countries
In cases where data is transferred to countries that do not have adequacy decisions or other recognized mechanisms, we utilize Standard Contractual Clauses (SCCs) as provided by the European Commission. SCCs are a set of contractual terms and conditions approved by the European Commission, providing a framework for the lawful transfer of personal data that imposes data protection obligations on both parties involved in the data transfer and ensuring that your data remains protected according to EU/EEA standards. These clauses include provisions that require the recipient to provide an adequate level of data protection.
10. Policy Changes and Contact Details
We may periodically update this Privacy Policy to reflect changes in our data processing practices, legal requirements, or to improve transparency and clarity. When we make significant changes to this policy, we will notify you through the following channels:
Telegram Channel: We will use this channel to provide information about updates to our Privacy Policy, ensuring that you have immediate access to relevant details and can seek clarification on any concerns.
Website and In-App Communication: Changes to the Privacy Policy will be communicated within our Website as well through the App interface. Notifications may be displayed prominently within the interface to alert users to policy updates. These notifications will provide a summary of the changes and a link to the updated Privacy Policy for your review.
For any inquiries, requests, or concerns related to this Privacy Policy or our data processing practices, you may always submit written notifications at [email protected]—we’ll be happy to answer your questions.