PRIVACY POLICY

How we collect, use, and protect your personal data on the VTT platform.

VERSION 1.1 — EFFECTIVE DATE: APRIL 2026
LAST UPDATED — 18 APRIL 2026

DATA CONTROLLER

The data controller for the VTT platform is:

Name: Alessandro Vettor
P.IVA: IT05586730268
Country: Italy

For purposes of the EU General Data Protection Regulation (GDPR — Regulation 2016/679), the Italian Privacy Code (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018), and the California Consumer Privacy Act (CCPA), Alessandro Vettor is the data controller (titolare del trattamento) responsible for your personal data processed through the VTT platform, including the website, dApp, launchpad, DEX, bridge, and staking services.

The competent supervisory authority is the Garante per la Protezione dei Dati Personali (Italian Data Protection Authority), reachable at gpdp.it.

DATA COLLECTED

We collect and process the following categories of personal data depending on how you interact with the VTT platform:

WALLET & BLOCKCHAIN DATA

  • //Public wallet addresses (generated client-side via the VTT wallet)
  • //Blockchain transaction data (transfers, swaps, staking, governance votes) — this data is permanently recorded on the public blockchain
  • //Wallet connection state stored in localStorage (vtt-wallet)

KYC / IDENTITY DATA

  • //Full legal name
  • //Identity document (passport, national ID, or driver's license)
  • //Selfie photograph for identity verification
  • //Country of residence and nationality
  • //Date of birth
  • //Proof of address (utility bill or bank statement, when required)

When identity verification is handled by our external compliance partner Sumsub, these documents are collected directly by Sumsub and stored on its EU-based infrastructure as our processor. In that flow no document images are stored on our own servers — we retain only the verification status, the Sumsub applicant reference and the minimum PII needed to enforce jurisdiction rules on-chain.

PAYMENT DATA

  • //Payment information is processed by Stripe and is never stored on our servers
  • //We receive transaction confirmation data from Stripe including order amounts, payment method type, and transaction status
  • //We store order records (amount, token quantity, wallet address, payment status) for accounting and delivery purposes

TECHNICAL DATA

  • //IP address (collected for security and anti-fraud purposes)
  • //Browser type and version
  • //Device information
  • //Cloudflare Turnstile tokens (bot protection — no tracking)

BLOCKCHAIN DATA

IMPORTANT — BLOCKCHAIN IMMUTABILITY
Blockchain transactions are public and permanent. Wallet addresses and transaction data are recorded on the VTT blockchain and cannot be deleted or modified. This is a fundamental property of distributed ledger technology.
  • //We cannot exercise the right to erasure (GDPR Art. 17) over data stored on the blockchain as it is technically immutable. This limitation is recognized under Recital 26 GDPR, as blockchain addresses are pseudonymous identifiers.
  • //Transaction data (transfers, swaps, staking, governance votes) is permanently visible on the public VTT blockchain explorer.
  • //We recommend not associating your real identity with your wallet address publicly. Avoid publishing your wallet address alongside personally identifiable information.
  • //While wallet addresses are pseudonymous, correlation of on-chain activity with off-chain data (such as KYC records) may allow re-identification. We implement strict data separation measures to minimize this risk.

We process your personal data based on the following legal grounds under GDPR Article 6(1):

LEGAL BASISGDPR ARTICLEPURPOSE
Contract performanceArt. 6(1)(b)Processing payments via Stripe, delivering purchased VTT tokens, executing swaps and bridge transfers
Legitimate interestArt. 6(1)(f)Platform security, fraud prevention, bot protection via Cloudflare Turnstile, infrastructure monitoring
ConsentArt. 6(1)(a)Cookie storage for non-essential purposes (if any are added in future)
Legal obligationArt. 6(1)(c)KYC/AML identity verification as required by EU AMLD5/AMLD6 and Italian D.Lgs. 231/2007, tax reporting obligations

DATA SHARING

We do not sell, rent, or trade your personal data to third parties. We share data only with the following service providers who process data on our behalf:

  • //Stripe (payments): processes payment card and SEPA data for token purchases. Stripe acts as an independent data controller for payment data. See Stripe's privacy policy at stripe.com/privacy.
  • //Sumsub (identity verification): acts as our data processor under GDPR Art. 28. When you complete KYC via the accelerated verification flow, your identity document, selfie and PII (name, date of birth, nationality, country of residence) are uploaded directly to Sumsub's EU-based infrastructure. Sumsub performs document authenticity checks, liveness detection and sanctions screening and returns an approval decision via webhook. We do not store your documents or selfie on our servers — they remain with Sumsub. See Sumsub's privacy policy at sumsub.com/privacy-notice.
  • //Cloudflare (CDN & security): provides content delivery, DDoS protection, and Turnstile bot protection. Cloudflare processes IP addresses and request metadata. See cloudflare.com/privacypolicy.
  • //Alchemy (blockchain RPC): provides blockchain node infrastructure for reading on-chain data. Alchemy may process IP addresses of API requests. See alchemy.com/privacy-policy.
NO DATA SALES
We do not sell your personal data. We do not share your data with advertisers. We do not use analytics or tracking cookies. Your data is used exclusively to provide and secure the VTT platform services.

DATA RETENTION

In accordance with the storage limitation principle (GDPR Art. 5(1)(e)), we retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:

DATA TYPERETENTION PERIODREASON
KYC documents10 years after the end of the business relationshipItalian D.Lgs. 231/2007, Art. 31 (AML obligations)
Payment records10 yearsItalian tax and accounting obligations
Blockchain dataPermanentImmutable public ledger — cannot be deleted
Technical logs90 daysSecurity and debugging purposes
Support communications2 yearsCustomer service quality

Please note that blockchain transaction data is permanently recorded on the public VTT blockchain and cannot be modified or deleted. This is a fundamental property of blockchain technology and is not within our control.

YOUR RIGHTS

Under the GDPR and Italian D.Lgs. 196/2003, you have the following rights regarding your personal data:

  • //Right of access (Art. 15): request a copy of the personal data we hold about you and information about how it is processed.
  • //Right to rectification (Art. 16): request correction of inaccurate or incomplete personal data.
  • //Right to erasure (Art. 17): request deletion of your personal data, subject to legal retention requirements. Note: blockchain data cannot be erased due to the technical immutability of distributed ledgers.
  • //Right to restriction of processing (Art. 18): request that we limit how we use your data while a dispute is being resolved.
  • //Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • //Right to object (Art. 21): object to processing based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
  • //Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing performed before withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by GDPR Art. 12(3).

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) at gpdp.it, or with the supervisory authority in your EU Member State of habitual residence, in accordance with GDPR Art. 77.

US PRIVACY RIGHTS

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • //Right to know: request disclosure of the categories and specific pieces of personal information we have collected about you.
  • //Right to delete: request deletion of personal information we have collected, subject to legal exceptions.
  • //Right to opt-out of sale: we do not sell personal information, so this right is automatically satisfied.
  • //Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at [email protected]. We will verify your identity before processing your request and respond within 45 days.

INTERNATIONAL TRANSFERS

Your personal data may be transferred to and processed in countries outside of your country of residence, including the United States and countries within the European Union. This occurs because our service providers operate globally:

  • //Stripe: processes payment data in the US and EU, with appropriate safeguards under GDPR (Standard Contractual Clauses).
  • //Sumsub (Sum and Substance Ltd): KYC data is processed primarily in the EU and the United Kingdom. Transfers to the UK rely on the EU Commission's adequacy decision for the UK (28 June 2021); any onward transfer is governed by Sumsub's Data Processing Addendum and Standard Contractual Clauses.
  • //Cloudflare: operates a global CDN network. Data may be processed at any Cloudflare edge location worldwide.
  • //Alchemy: provides blockchain RPC infrastructure with servers in the US and EU.

Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, or reliance on the service provider's adequacy decisions or certifications.

CONTACT

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Data Controller: Alessandro Vettor
Country: Italy

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Garante per la protezione dei dati personali at gpdp.it (GDPR Art. 77), or with the supervisory authority in your EU Member State of habitual residence. See also GDPR Art. 79 for the right to an effective judicial remedy.