Privacy Policy
1. Who we are and what this covers
This policy explains what personal data the nGRND Gold Protocol token sale interface (the "Sale Interface") collects about you, why we collect it, how long we keep it, who we share it with, and the rights you have over it.
For the purposes of data protection law, the issuer of the NGRND token is the data controller in respect of the personal data described here.
This policy covers the Sale Interface and the off-chain services behind it (identity verification, consent recording, and the administrative back office). It does not cover the public blockchain itself, your wallet software, or any third-party site you reach from here — those are outside our control and have their own policies.
Please read this policy alongside the Terms of Token Sale.
2. What we collect
Wallet and transaction data. Your public wallet address, the chain you are connected to, and the on-chain record of your purchases — amounts, payment currency, USD value at the time of purchase, timestamps, and transaction hashes. Blockchain data is public by design; we read it, we do not create it.
Identity verification data (only if you verify). Your full legal name, date of birth, country of residence, residential address, identity document type (passport, national identity card, or driving licence), and document number. Where you attach a document image, the file is not uploaded to or stored on our servers — only its filename is recorded, together with your confirmation that a selfie check was completed.
Consent records. For each purchase for which you give consent, we record your wallet address, the version numbers of the Terms of Token Sale and this Privacy Policy that you accepted, your acknowledgement of the risk disclosure, and the date and time.
Technical data. Your IP address and browser user-agent string, captured at the moment you submit a consent or a verification application. We use these as evidence of consent and as an anti-fraud and jurisdictional-screening signal.
Administrative records. An audit log of actions taken by our administrators in relation to your application — for example an approval, a rejection with its reason, or an on-chain verification sync.
Correspondence. Any message you send us and our reply.
We do not collect your name, email address, or any identity document unless you choose to complete identity verification. A purchase within the no-KYC allowance requires none of it.
We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
3. Why we use it, and our lawful basis
Performance of a contract. To process your purchase, to operate the sale, and to provide your dashboard. Without your wallet address we cannot do any of this.
Compliance with a legal obligation. To meet anti-money-laundering and counter-terrorist-financing duties, to run sanctions and jurisdictional screening, and to retain records that law requires us to keep. Identity verification data is processed on this basis.
Consent. Where you tick the consent boxes at checkout, we process the record of that consent to evidence that it was given. You may withdraw consent for future purchases at any time; withdrawal does not affect the lawfulness of processing already carried out, and does not erase a record we are legally required to retain.
Legitimate interests. To secure the Sale Interface, prevent and investigate fraud and abuse, enforce the Terms, maintain an audit trail, and establish, exercise, or defend legal claims. We have assessed that these interests are not overridden by your rights, in part because the data used is limited and retained only as long as needed.
We do not use your data for automated decision-making that produces a legal or similarly significant effect on you without human involvement. In automatic verification mode an initial screening result may be generated automatically, but a rejection is reviewable by a person on request, and you may contest it.
We do not sell your personal data, and we do not use it for advertising or behavioural profiling.
4. How long we keep it
Identity verification data. Retained for five years from the date of your last purchase, or from the date your application was rejected or withdrawn, in line with standard anti-money-laundering record-keeping periods. It is then deleted or irreversibly anonymised.
Consent records. Retained for six years from the date of the relevant purchase, so that we can evidence the terms you accepted for as long as a claim could be brought.
Technical data (IP address, user-agent). Retained for twelve months, except where it forms part of a consent or verification record, in which case it follows that record’s period.
Administrative audit logs. Retained for six years.
Correspondence. Retained for two years after the matter is closed.
On-chain data. Data written to a public blockchain — your wallet address, purchase amounts, staking and vesting records — is permanent and immutable. We cannot delete, amend, or anonymise it, and no exercise of your rights can compel us to do so. Please take this into account before transacting.
Where a longer period is required by law, or where data is needed for a live legal claim, we retain it until that requirement or claim ends.
6. Your rights
Subject to the limits described below, you have the right to:
- Access — obtain a copy of the personal data we hold about you and information about how we process it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have a lawful basis to keep it.
- Restriction — ask us to limit processing while a dispute about accuracy or lawfulness is resolved.
- Objection — object to processing carried out on the basis of legitimate interests, on grounds relating to your particular situation.
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible.
- Withdraw consent — at any time, for processing based on consent, without affecting the lawfulness of prior processing.
- Complain — to your local data protection supervisory authority. We would ask that you raise it with us first so we can try to resolve it.
Two limits apply. First, we cannot erase or alter anything recorded on a public blockchain. Second, we cannot delete identity verification or consent records that anti-money-laundering or limitation-period law requires us to retain, until that period expires.
To exercise a right, contact us using the details in section 9. We will ask you to demonstrate control of the relevant wallet — typically by signing a message — so that we do not disclose your data to someone else. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.
8. Security
We apply technical and organisational measures appropriate to the risk, including transport encryption, access control over the administrative back office, and an audit log of administrative actions.
We minimise what we hold. Identity document images are never uploaded to or stored on our servers — only the filename is recorded. No identity data is ever written to a blockchain.
No system is perfectly secure. We cannot guarantee the security of data transmitted over the internet, and any transmission is at your own risk. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.
You are responsible for the security of your own wallet and keys. We will never ask for your seed phrase or private key, and no legitimate message from us will ever request one.
9. Contact and changes to this policy
For any privacy question, to exercise a right, or for verification-specific questions, contact compliance@ngrndrewards.com.
We may update this policy. Changes are published here with a new version number and effective date. Where a change is material, we will make it prominent in the Sale Interface before it takes effect.
The version of this policy you accepted at the time of a purchase is recorded with your consent record, so it is always possible to establish which text applied to you.
This document is provided for the nGRND Gold Protocol token sale and is recorded by version number against every consent given at checkout. It is not legal advice. If anything here is unclear, obtain independent professional advice before purchasing.