nnGRNDTOKEN SALE
SaleBuyDashboardReferralKYC

Privacy Policy

Version 1.1.0 · Last updated September 30, 2026

1. Who we are and what this covers

This policy explains what personal data the nGRND Gold Protocol token sale interface (the "Sale Interface") collects about you, why we collect it, how long we keep it, who we share it with, and the rights you have over it.

For the purposes of data protection law, the issuer of the NGRND token is the data controller in respect of the personal data described here.

This policy covers the Sale Interface and the off-chain services behind it (identity verification, consent recording, and the administrative back office). It does not cover the public blockchain itself, your wallet software, or any third-party site you reach from here — those are outside our control and have their own policies.

Please read this policy alongside the Terms of Token Sale.

2. What we collect

Wallet and transaction data. Your public wallet address, the chain you are connected to, and the on-chain record of your purchases — amounts, payment currency, USD value at the time of purchase, timestamps, and transaction hashes. Blockchain data is public by design; we read it, we do not create it.

Identity verification data (only if you verify). Your full legal name, date of birth, country of residence, residential address, identity document type (passport, national identity card, or driving licence), and document number. Where you attach a document image, the file is not uploaded to or stored on our servers — only its filename is recorded, together with your confirmation that a selfie check was completed.

Consent records. For each purchase for which you give consent, we record your wallet address, the version numbers of the Terms of Token Sale and this Privacy Policy that you accepted, your acknowledgement of the risk disclosure, and the date and time.

Technical data. Your IP address and browser user-agent string, captured at the moment you submit a consent or a verification application. We use these as evidence of consent and as an anti-fraud and jurisdictional-screening signal.

Administrative records. An audit log of actions taken by our administrators in relation to your application — for example an approval, a rejection with its reason, or an on-chain verification sync.

Correspondence. Any message you send us and our reply.

We do not collect your name, email address, or any identity document unless you choose to complete identity verification. A purchase within the no-KYC allowance requires none of it.

We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

3. Why we use it, and our lawful basis

Performance of a contract. To process your purchase, to operate the sale, and to provide your dashboard. Without your wallet address we cannot do any of this.

Compliance with a legal obligation. To meet anti-money-laundering and counter-terrorist-financing duties, to run sanctions and jurisdictional screening, and to retain records that law requires us to keep. Identity verification data is processed on this basis.

Consent. Where you tick the consent boxes at checkout, we process the record of that consent to evidence that it was given. You may withdraw consent for future purchases at any time; withdrawal does not affect the lawfulness of processing already carried out, and does not erase a record we are legally required to retain.

Legitimate interests. To secure the Sale Interface, prevent and investigate fraud and abuse, enforce the Terms, maintain an audit trail, and establish, exercise, or defend legal claims. We have assessed that these interests are not overridden by your rights, in part because the data used is limited and retained only as long as needed.

We do not use your data for automated decision-making that produces a legal or similarly significant effect on you without human involvement. In automatic verification mode an initial screening result may be generated automatically, but a rejection is reviewable by a person on request, and you may contest it.

We do not sell your personal data, and we do not use it for advertising or behavioural profiling.

4. How long we keep it

Identity verification data. Retained for five years from the date of your last purchase, or from the date your application was rejected or withdrawn, in line with standard anti-money-laundering record-keeping periods. It is then deleted or irreversibly anonymised.

Consent records. Retained for six years from the date of the relevant purchase, so that we can evidence the terms you accepted for as long as a claim could be brought.

Technical data (IP address, user-agent). Retained for twelve months, except where it forms part of a consent or verification record, in which case it follows that record’s period.

Administrative audit logs. Retained for six years.

Correspondence. Retained for two years after the matter is closed.

On-chain data. Data written to a public blockchain — your wallet address, purchase amounts, staking and vesting records — is permanent and immutable. We cannot delete, amend, or anonymise it, and no exercise of your rights can compel us to do so. Please take this into account before transacting.

Where a longer period is required by law, or where data is needed for a live legal claim, we retain it until that requirement or claim ends.

5. Who we share it with

Identity verification providers. Where identity verification is operated by a third-party provider, the data you submit is shared with that provider to perform the check. In the demonstration configuration of this interface no data is sent to any provider — the verification flow is simulated and is clearly labelled as such in the user interface.

Blockchain networks. When a wallet is approved for verification, that approval is written on-chain by a transaction that records the wallet address and its approved status. No identity data is ever written on-chain.

Infrastructure and hosting providers. Suppliers that host the application and its database, acting as processors under contract and only on our instructions.

Wallet and connectivity providers. When you connect a wallet, the wallet provider and the connection service (for example a WalletConnect-compatible relay) receive the technical data necessary to establish the session, under their own privacy policies.

Professional advisers, auditors, and insurers. Where necessary and under a duty of confidence.

Law enforcement, regulators, and courts. Where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims.

A successor. If our business or its assets are transferred, your data may transfer with it, subject to this policy continuing to apply.

Where data is transferred outside your jurisdiction, we rely on an adequacy decision or on standard contractual clauses, together with appropriate technical and organisational safeguards.

6. Your rights

Subject to the limits described below, you have the right to:

  • Access — obtain a copy of the personal data we hold about you and information about how we process it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where we no longer have a lawful basis to keep it.
  • Restriction — ask us to limit processing while a dispute about accuracy or lawfulness is resolved.
  • Objection — object to processing carried out on the basis of legitimate interests, on grounds relating to your particular situation.
  • Portability — receive the data you provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible.
  • Withdraw consent — at any time, for processing based on consent, without affecting the lawfulness of prior processing.
  • Complain — to your local data protection supervisory authority. We would ask that you raise it with us first so we can try to resolve it.

Two limits apply. First, we cannot erase or alter anything recorded on a public blockchain. Second, we cannot delete identity verification or consent records that anti-money-laundering or limitation-period law requires us to retain, until that period expires.

To exercise a right, contact us using the details in section 9. We will ask you to demonstrate control of the relevant wallet — typically by signing a message — so that we do not disclose your data to someone else. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

7. Cookies and local storage

We use a small number of strictly necessary cookies and browser storage entries. We do not use advertising, analytics, or cross-site tracking cookies, and there is no third-party marketing tag on this interface.

  • Wallet session storage. The wallet connection library stores your connection state so that your wallet stays connected across page reloads. This is set in a cookie and read during server-side rendering to avoid a flash of a disconnected state.
  • Administrative session cookie. If you sign in to the administrative back office, an httpOnly, same-site session cookie identifies your session. It is not set for ordinary visitors.
  • Interface preferences. Small local-storage entries remembering non-identifying interface state, such as your last selected payment currency.

Because these are strictly necessary for a service you have requested, they do not require consent. You can clear or block them through your browser, but the Sale Interface may then not work — in particular, your wallet may disconnect on every page load.

8. Security

We apply technical and organisational measures appropriate to the risk, including transport encryption, access control over the administrative back office, and an audit log of administrative actions.

We minimise what we hold. Identity document images are never uploaded to or stored on our servers — only the filename is recorded. No identity data is ever written to a blockchain.

No system is perfectly secure. We cannot guarantee the security of data transmitted over the internet, and any transmission is at your own risk. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.

You are responsible for the security of your own wallet and keys. We will never ask for your seed phrase or private key, and no legitimate message from us will ever request one.

9. Contact and changes to this policy

For any privacy question, to exercise a right, or for verification-specific questions, contact compliance@ngrndrewards.com.

We may update this policy. Changes are published here with a new version number and effective date. Where a change is material, we will make it prominent in the Sale Interface before it takes effect.

The version of this policy you accepted at the time of a purchase is recorded with your consent record, so it is always possible to establish which text applied to you.

This document is provided for the nGRND Gold Protocol token sale and is recorded by version number against every consent given at checkout. It is not legal advice. If anything here is unclear, obtain independent professional advice before purchasing.

Base Sepolia testnet — tokens have no value
Terms of SalePrivacy PolicyRisk DisclosureKYC / AML

© 2026 nGRND Gold Protocol. Purchases below USD 1,000 need no KYC/AML.

Nothing on this site is an offer of securities or investment advice. NGRND is a utility token. Digital assets carry a risk of total loss — read the Terms of Sale and Risk Disclosure before purchasing.

◈Sale◆Buy▤Wallet⇗Refer✓KYC