Last modification date: Jan 2nd 2023
This Privacy Policy is part of the Hathor Labs Terms of Service at https://hathor.network/terms-and-conditions/. All terms, conditions, and terminology are consistent with the Terms of Service, and the Terms of Service are incorporated into this document by reference.
Collectively, the website and the associated tools and services are referred to as the “Services” in these terms. The operator may offer other products and services.
In addition to the Hathor website, the Services include the Hathor API documented at https://docs.hathor.network, the Hathor Wallet apps linked from https://hathor.network/get-started/, the Hathor Explorer at https://explorer.hathor.network, the Hathor Documentation at https://hathor.gitbook.io/hathor/, and certain public “nodes” run by the operator and listed at https://hathor.network/mainnet/. The Hathor Wallet apps may also be subject to an “End User License Agreement” (“EULA”). In the event of any conflict between these terms and an applicable EULA, the EULA controls.
The Services do not include the Fiat on-ramp solutions on the Simplex or Transak platforms. The Simplex platform has its own privacy policy available at https://www.simplex.com/privacy-policy. The Transak platform has its own privacy policy available at https://transak.com/privacy-policy.
Hathor Labs, a Cayman Islands corporation, operates the Services. It and its affiliates are referred to in this document as the “operator,” “we,” or “us.” The operator is located at: PO Box 31489, Whitehall Chambers, Whitehall House, 238 North Church Street, George Town, Cayman Islands, KY1-1206.
Blockchain technology, also known as distributed ledger technology (or simply ‘DLT’), is at the core of our business. Blockchains are decentralized and made up of digitally recorded data in a chain of packages called ‘blocks’. The manner in which these blocks are linked is chronological, meaning that the data is very difficult to alter once recorded. Since the ledger may be distributed all over the world (across several ‘nodes’ which usually replicate the ledger) this means there is no single person making decisions or otherwise administering the system (such as an operator of a cloud computing system), and that there is no centralized place where it is located either.
This means that by design, a blockchain’s records cannot be changed or deleted and is said to be ‘immutable’. This may affect your ability to exercise your rights such as your right to erasure (‘right to be forgotten’), or your rights to object or restrict processing, of your personal data. Data on the blockchain can’t be erased or changed. Although smart contracts may be used to revoke certain access rights, and some content may be made invisible to others, it is not deleted.
In certain circumstances, in order to comply with our contractual obligations to you (such as delivery of tokens) it will be necessary to write certain personal data, such as your wallet address, onto the blockchain; this requires you to execute such transactions using your wallet’s private key.
In most cases ultimate decisions to (i) transact on the blockchain using your wallet address, as well as (ii) share the public key relating to your wallet address with anyone (including us) rests with you.
If you want to ensure your privacy rights are not affected in any way, you should not transact on blockchains as certain rights may not be fully available or exercisable by you or us due to the technological infrastructure of the blockchain. The blockchain is available to the public and any personal data shared on the blockchain will become publicly available.
As per our Terms of Service, individuals under the age of 18 are not permitted to use the Services. As such, we do not knowingly collect, solicit or maintain personal data from anyone under the age of 18 or knowingly allow such persons to register for the Services.
In the event that we learn that we have collected personal data from an individual under age 18, we will use commercially reasonable efforts to delete that information from our database. Please contact us if you have any concerns. If you are a parent or guardian and you are aware that your child has provided personal data to the Services, please contact us so that we may remove such data. Note that we cannot delete information stored on public cryptographic blockchains.
We, and our partners, use cookies and similar technologies to give you the best possible content and experience. Cookies are used to remember you and to collect information about how you interact with the Services. If you have an account with the Services, we may link this usage data with other information. You may have the option to either accept or refuse these cookies. If you choose to refuse, you may not be able to use some portions of the Services.
As described below, we collect information from and about the computers, phones, and other web-connected devices you use that interact with our Services, and we combine this information across different devices you use.
Information we obtain from these devices includes:
When using the Services, we may collect and process personal data. The data will be stored in different instances. We collect and use this information to provide you the Services and to debug issues and provide support.
The data will be stored on the Blockchain. Given the technological design of the blockchain, this data will become public and it will not likely be possible to delete or change the data at any given time.
In our web servers, we will store the following data:
Log Data
We use the information we have (subject to choices you make) as described below and to provide and support the Services. Here's how:
We use the information we have to deliver our Services, including to personalize features and content.
We use the information we have (including your activity on our Services) to help advertisers and other partners measure the effectiveness and distribution of their ads and services, and understand the types of people who use their services and how people interact with their websites, apps, and services.
The Services use Google Analytics to gather information about their use. Google Analytics collects information such as how often users visit this site, what pages they visit when they do so, and what other sites they used prior to coming to this site. The Services use the information we get from Google Analytics only to improve this site. Google Analytics collects only the IP address assigned to you on the date you visit this site, rather than your name or other identifying information.
We use the information we have to verify accounts and activity, combat harmful conduct, detect and prevent spam and other bad experiences, maintain the integrity of our Services, and promote safety and security.
We use the information we have to send you marketing communications, communicate with you about our Services, and let you know about our policies and terms. We also use your information to respond to you when you contact us.
Because recognition of the Do Not Track HTTP header feature of your web browser is not standardized, the Services don’t recognize it for tracking purposes.
Third parties may collect or receive certain information about you and/or your use of the Services to provide content, ads (including personalized ads), or functionality, or to measure and analyze ad performance, in or through the Services. You may choose whether to receive certain personalized (also known as targeted) advertising from participating ad networks, audience segment providers, ad serving vendors, other service providers or entities by visiting websites operated by the Network Advertising Initiative and Digital Advertising Alliance or if you are a user in the European Economic Area, Your Online Choices. We adhere to the Self-Regulatory Principles for Online Behavioral Advertising.
The Services may keep the information we gather about you an unlimited length of time.
To request that information collected about you be deleted, please contact us at the email provided in this policy. A valid request must include sufficient information to identify your personal data. Note that we cannot delete information stored on public cryptographic blockchains.
The Services do not share any information about you with advertisers, marketing companies, or anyone else, except as necessary to run this site.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
If you have comments or questions about the privacy policies of the Services, contact contact@hathor.network.
The Services may change their privacy policy at any time. Check this page for the latest.
You agree to do your respective parts to comply with the California Consumer Privacy Act and its regulations, consistent with the operator’s role as a “service provider”, and not as a “third party”, under that law.
Whenever it is feasible and legal to do so, both the operator and You will give the other prompt notice of user rights requests, regulatory inquiries, and other communications under the California Consumer Privacy Act. Both sides agree to cooperate in good faith to respond to and honor such communications, and to meet other obligations under the California Consumer Privacy Act.
The operator may not:
The operator understands the restrictions in Prohibitions and will comply with them.
Both You and the operator agree to limit use of personal information covered by the California Consumer Privacy Act to that reasonably necessary and proportionate to achieve the purpose of the Terms of Service, consistent with the meaning of “business purpose” under that law.
The operator agrees to ensure that each subcontractor that processes Your information covered by the California Consumer Privacy Act will also qualify as a “service provider”, and not as a “third party”, under that law.
Of the following categories of personal information:
the operator has not collected, used for a business purpose, or sold any data within the last 12 months, as of the date of this agreement.
To request access or changes to information previously submitted, please contact the operator at the address provided above (under the “Contact” heading).
If the terms of this addendum conflict with terms of the Terms of Service or Privacy Policy, the terms of this addendum take precedence.
The data mentioned in this document will be stored in the United States. We use Amazon Web Server, which is based in the US. Amazon is certified under the EU-US Privacy Shield.
But, when interacting with the blockchain, as explained above in this Policy, the blockchain is a global decentralized public network and accordingly any personal data written onto the blockchain may be transferred and stored across the globe.
You have certain rights under applicable legislation, and in particular under Regulation EU 2016/679 (General Data Protection Regulation or ‘GDPR’). We explain these below. You can find out more about the GDPR and your rights by accessing the European Commission’s website.
You have a right to be informed about the processing of your personal data (and if you did not give it to us, information as to the source). This document provides that information, and you may contact us for additional information.
You have the right to have any inaccurate personal information about you rectified and to have any incomplete personal information about you completed. You may also request that we restrict the processing of that information. The accuracy of your information is important to us. If you do not want us to use your Personal Information in the manner set out in this Privacy Policy, or need to advise us of any changes to your personal information, or would like any more information about the way in which we collect and use your Personal Information, please contact us at the above details.
You have the general right to request the erasure of your personal information in the following circumstances:
But, when interacting with the blockchain we may not be able to ensure that your personal data is deleted. This is because the blockchain is a public decentralized network and blockchain technology does not generally allow for data to be deleted and your right to erasure may not be able to be fully enforced. In these circumstances we will only be able to ensure that all personal data that is held by us is permanently deleted.
We will proceed to comply with an erasure request without delay unless continued retention is necessary for:
You have a right to restrict processing of your personal information, such as where:
You also have the right to object to processing of your personal information under certain circumstances, such as where the processing is based on your consent and you withdraw that consent. This may impact the services we can provide and we will explain this to you if you decide to exercise this right.
But, when interacting with the blockchain, as it is a public decentralized network, we will likely not be able to prevent external parties from processing any personal data which has been written onto the blockchain. In these circumstances we will use our reasonable endeavors to ensure that all processing of personal data held by us is restricted, notwithstanding this, your right to restrict to processing may not be able to be fully enforced.
The Data Protection Officer of the operator is Marcelo Brogliato and may be contacted at security@hathor.network.
Where the legal basis for our processing is your consent or the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, you have a right to receive the personal information you provided to us in a structured, commonly used and machine-readable format, or ask us to send it to another person.
We do not use automated decision-making, but where any automated decision-making takes place, you have the right in this case to express your point of view and to contest the decision, as well as request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers.
You have a choice about whether or not you wish to receive information from us. We will not contact you for marketing purposes unless:
You can change your marketing preferences at any time by contacting us on the above details. On each and every marketing communication, we will always provide the option for you to exercise your right to object to the processing of your personal data for marketing purposes (known as ‘opting-out’) by clicking on the ‘unsubscribe’ button on our marketing emails or choosing a similar opt-out option on any forms we use to collect your data. You may also opt-out at any time by contacting us on the below details.
Please note that any administrative or service-related communications (to offer our services, or notify you of an update to this Privacy Policy or applicable terms of business, etc.) will solely be directed at our clients or business partners, and such communications generally do not offer an option to unsubscribe as they are necessary to provide the services requested. Therefore, please be aware that your ability to opt-out from receiving marketing and promotional materials does not change our right to contact you regarding your use of our Services or as part of a contractual relationship we may have with you.
You also have a right to access information we hold about you. We are happy to provide you with details of your Personal Information that we hold or process. To protect your personal information, we follow set storage and disclosure procedures, which mean that we will require proof of identity from you prior to disclosing such information. You can exercise this right at any time by contacting us on the above details.
Where the legal basis for processing your personal information is your consent, you have the right to withdraw that consent at any time by contacting us on the above details.
If you wish to raise a complaint on how we have handled your personal data, you can contact us as set out above and we will then investigate the matter.
Should you wish to report a complaint or if you feel that we have not addressed your concern in a satisfactory manner, you may contact the Information Commissioner’s Office in your jurisdiction.