Definica DAO

Definica Privacy Policy

Download PDF

Privacy information for definica.com, official Definica interfaces, wallet connection flows, governance resources, and protocol-related communications.

Privacy contact
privacy@definica.com
Security contact
security@definica.com
Legal contact
legal@definica.com

1. Purpose and Scope

This Privacy Policy explains how personal data and related information are processed in connection with:

  • definica.com and official Definica subdomains (the “Website”);
  • any official Definica application or user interface (the “Interface”);
  • wallet connection and protocol-position display features;
  • governance resources, proposals, voting, delegation, and community participation;
  • contact, legal, security, partnership, and support communications; and
  • security, fraud-prevention, sanctions-screening, monitoring, and incident-response activities.

Definica is a DAO-governed Ethereum protocol initiative under phased development. The Website may describe planned pooled staking, osETH, aEthosETH-related liquidity, locks, incentives, and borrowing features that are not active. This Privacy Policy applies only to actual data processing carried out through official Definica-controlled services. It does not make a planned feature active and is not consent to smart contract or financial risk.

Public blockchain data is different from off-chain data controlled through the Website. Ethereum records are public and persistent, but Definica remains responsible, where applicable, for off-chain copies, enrichment, storage, and use that it controls.

2. Controller and DAO Structure

For off-chain personal data processed to operate the Website and official Interface, Definica DAO, acting through the contributors responsible for determining the purposes and means of that processing, is described in this Policy as the “Controller,” unless an official Definica Legal Notice identifies a legal wrapper or Website operator as the controller or joint controller for a specified activity.

Definica DAO is a decentralized governance arrangement and may not have separate legal personality or a registered office in every jurisdiction. Privacy requests can be submitted to privacy@definica.com. If a legal wrapper, foundation, company, representative, or Website operator is designated, its identity, address, jurisdiction, and role will be published in the official Legal Notice and incorporated into the next revision of this Policy. The notice applicable to a specified processing activity controls where it identifies a different or additional controller.

The Definica DAO governance process, public smart contracts, Ethereum validators, independent node operators, wallets, block explorers, RPC providers, and public blockchain participants do not automatically form one controller. Their roles depend on who actually determines why and how personal data is processed.

3. Important Data-Protection Limits

Definica does not request or store wallet private keys, seed phrases, recovery phrases, or credentials that allow Definica to sign transactions on your behalf. Never send this information to Definica or anyone claiming to represent Definica.

A public wallet address and its transaction history may be personal data when it can be linked to an identifiable individual. Connecting a wallet may allow the Website and selected infrastructure providers to associate a wallet address with an IP address, device data, session information, and on-chain activity.

Do not place names, contact details, identification documents, or other unnecessary personal information in a blockchain transaction, governance proposal, memo field, or other permanent public record.

4. Information We Process

4.1 Website and technical data

When you visit the Website or use the Interface, the Controller and its infrastructure providers may process:

  • IP address and approximate location derived from it;
  • browser type, device type, operating system, language, and time-zone settings;
  • pages, referrer, timestamps, session events, and navigation data;
  • server, performance, error, security, rate-limit, and diagnostic logs;
  • cookie, local-storage, consent, or similar identifiers; and
  • network, chain ID, RPC request, and interface-configuration information.

4.2 Wallet and public blockchain data

If you connect a wallet, request a position display, or interact through the Interface, the Controller may process:

  • public wallet address, ENS name, or other public profile linked to the address;
  • transaction hashes, contract calls, approvals, signatures used for authentication, and network information;
  • public ETH and token balances;
  • Vault-share and Definica Core position information;
  • staking deposits, requests, withdrawals, claims, locks, and related status information;
  • osETH and, where activated, aEthosETH-related position information;
  • governance proposals, votes, delegations, and public participation; and
  • information derived from public blockchains, indexers, or risk-screening services.

Connecting a wallet does not give the Controller access to private keys. Transactions require authorization through your wallet unless a previously signed permission lawfully permits a specified action.

4.3 Communications and submissions

If you contact Definica or submit information, the Controller may process:

  • name, pseudonym, email address, organization, and role;
  • message content, attachments, and correspondence history;
  • support, legal, media, partnership, contributor, or governance inquiries;
  • newsletter choices and consent records, if communications are offered;
  • feedback, survey responses, proposals, and public community submissions; and
  • vulnerability reports, proof-of-concept material, threat information, and responsible-disclosure communications.

4.4 Security, fraud, and compliance data

To protect users, the Website, and Protocol-related infrastructure, the Controller may process:

  • wallet or IP risk indicators;
  • sanctions, exploit, stolen-funds, fraud, or illicit-finance screening results;
  • indicators of phishing, malware, Sybil behaviour, abuse, or attacks;
  • access-control, geolocation, and rate-limit signals;
  • investigation, incident-response, and threat-intelligence information; and
  • information required to enforce the Terms of Service or respond to lawful requests.

Definica does not intentionally request special-category data, government identification, or criminal-conviction data through ordinary Website use. If such information is required by law or for a specific process, Definica will provide additional notice and identify an appropriate legal basis before collecting it where required.

5. How Information Is Obtained

Information may be obtained:

  • directly from you when you connect a wallet, contact Definica, submit a form, or participate in governance or community activity;
  • automatically from browsers, devices, servers, cookies, and security tools;
  • from Ethereum and other public blockchain records;
  • from RPC providers, wallet connection tools, indexers, block explorers, analytics, hosting, and security providers;
  • from sanctions, blockchain analytics, fraud-prevention, and threat-intelligence providers; and
  • from public governance, social media, community, and security channels.

Where information is not obtained directly from you, the relevant categories and sources are described above.

6. Public Blockchains

Ethereum wallet addresses, transactions, token transfers, contract calls, validator-related activity, governance actions, and other on-chain records are generally visible worldwide. Nodes, validators, indexers, explorers, researchers, analytics providers, and other third parties may independently copy, analyze, and retain them.

Definica does not control Ethereum or independent copies of public records and generally cannot erase, correct, hide, or restrict data written to the blockchain. This limitation does not automatically apply to off-chain databases, support records, analytics profiles, or wallet-to-identity links controlled by the Controller. Rights requests concerning controlled off-chain data will be assessed separately.

Where an Interface asks you to submit information for validation or storage on a public blockchain, Definica will provide a concise transaction-stage notice where required, so you can understand the categories involved, intended purpose, public visibility, persistence, and relevant recipients before authorizing the transaction.

You should avoid publicly linking your identity to a wallet when you do not want that association to become persistent. Separate wallets may reduce linkability but do not guarantee anonymity.

8. Cookies and Similar Technologies

The Website may use cookies, local storage, session storage, pixels, and similar technologies.

Strictly necessary technologies may be used for security, network routing, fraud prevention, consent management, wallet-interface state, and essential operation where permitted without consent.

Preference technologies may remember language, display, network, and interface choices.

Analytics technologies may measure traffic, performance, errors, and feature use. Where consent is required, they must remain disabled until consent is given.

Marketing technologies may measure campaigns or support cross-site advertising. They must not be used without the legally required choice and notice.

Where a cookie settings tool is available, you can use it to accept, reject, or change non-essential choices. Rejecting must be as accessible as accepting where required. You may also use browser controls, although blocking necessary storage can impair functionality.

Before enabling non-essential technologies, the Website will identify the relevant providers, storage names, purposes, and durations in its cookie settings or cookie notice where required. Definica will honor legally required opt-out preference signals, such as Global Privacy Control, where applicable to the deployed technology and jurisdiction.

9. Wallet Connections and Infrastructure Providers

Depending on the deployed Interface, connecting a wallet or requesting blockchain data may transmit your wallet address, IP address, device data, selected network, and request data to a wallet connection provider, RPC provider, indexer, hosting provider, or security service.

Wallets and some infrastructure providers act under their own terms and privacy policies and may be independent controllers. Review those policies before use. Disconnecting a wallet stops the current Interface connection but does not erase on-chain records, prior logs, or data retained by an independent provider.

Definica will never ask you to disclose a seed phrase to verify a privacy request. Wallet ownership may be verified through a narrowly scoped message signature, transaction evidence, correspondence information, or another proportionate method. Do not sign a transaction or broad token approval merely to exercise a privacy right.

10. Governance, Community, and Social Media

Governance actions may be public. Proposals, votes, delegations, wallet addresses, forum posts, and transaction history can reveal interests, associations, and behaviour.

Third-party community platforms and social media services process data under their own policies. Information posted publicly may be copied and retained by others. Do not post private keys, seed phrases, identification documents, confidential security information, or personal data you do not want disclosed.

11. Recipients and Service Providers

Personal data may be disclosed, where necessary and lawful, to:

  • hosting, content-delivery, domain, and infrastructure providers;
  • wallet connection, RPC, indexing, and blockchain data providers;
  • consent-management, analytics, diagnostics, performance, and error-monitoring providers;
  • security, fraud-prevention, sanctions-screening, and blockchain analytics providers;
  • email, newsletter, support, form, and communications providers;
  • authorized contributors and contractors subject to role-based access and confidentiality duties;
  • auditors, insurers, accountants, lawyers, tax advisers, and other professional advisers;
  • courts, regulators, law enforcement, sanctions authorities, and other recipients where legally required or necessary to protect rights; and
  • a successor Website operator, legal wrapper, or reorganization participant subject to appropriate safeguards.

Some recipients process data as processors under instructions. Others, such as wallets, public blockchain participants, social platforms, and certain RPC or analytics providers, may act as independent controllers. Where required, current provider-specific information will be made available through the Website’s cookie settings, cookie notice, or legal notices.

12. Sale, Sharing, and Advertising

The Controller does not sell personal data for monetary consideration. The Controller does not knowingly share personal data for cross-context behavioural advertising or use it for targeted advertising unless the Website provides the notices and opt-out controls required by applicable law.

If deployed technology changes these practices, this Policy and the relevant controls must be updated before the new use begins. Disclosure to processors for security, hosting, requested functionality, or other limited business purposes is not treated as a sale where applicable law provides such an exception.

13. International Data Transfers

Definica operates in a global environment. Contributors and providers may process information outside your country. Public blockchain information is globally available independently of Definica.

Where legally required for controlled off-chain transfers, the Controller will rely on an applicable adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or Addendum, another recognized safeguard, or a lawful derogation. You may request information about applicable safeguards at privacy@definica.com.

A data-processing agreement alone is not necessarily an international-transfer mechanism. Transfer arrangements depend on the actual provider, destination, and law.

14. Retention

The Controller retains off-chain personal data only for as long as reasonably necessary for the stated purpose, security, legal compliance, and claims. Retention is determined using the following criteria:

  • routine contact and support correspondence is retained while the request is active and for a limited period afterwards to document the response and manage follow-up;
  • security and server logs are retained for the shortest period reasonably needed to detect abuse, investigate incidents, preserve evidence, and defend claims;
  • vulnerability reports and incident records are retained until remediation and follow-up are complete and for any additional period justified by security, audit, insurance, or limitation requirements;
  • marketing contact data is retained until consent is withdrawn or you unsubscribe, with a limited suppression record retained to respect the opt-out;
  • cookie, consent, and privacy-choice records are retained for the period needed to operate the choice and demonstrate compliance;
  • analytics data is retained according to the configured provider period, which must be limited to what is necessary for the stated measurement purpose;
  • compliance and risk-screening records are retained for the period required by applicable law or, where based on legitimate interests, only while necessary for the relevant risk, investigation, or claim; and
  • legal and governance records are retained for the applicable limitation period or while needed to document decisions, authority, and rights.

Backups may persist for a limited rotation period before deletion. Public blockchain data and independent copies may remain available indefinitely. The Controller will review retention when providers, laws, processing purposes, or risk conditions change.

15. Security

The Controller uses technical and organizational measures appropriate to the processing risk. Depending on the system, these may include encryption in transit, access controls, least-privilege permissions, multifactor authentication, logging, monitoring, environment separation, code review, dependency management, vendor review, backups, incident response, and responsible disclosure.

Definica’s privacy-by-design approach is to avoid placing names, contact details, support content, identification documents, or other unnecessary personal data on-chain; minimize links between off-chain identities and wallet addresses; and assess controller roles, data flows, and deletion or anonymization options before introducing new blockchain-based processing. Where processing is likely to create a high risk to individuals, the Controller will conduct a data-protection impact assessment where required by law.

No system is completely secure. Definica cannot guarantee the security of the Internet, public blockchains, wallets, smart contracts, third-party providers, or information transmitted through them.

Report suspected personal-data or security incidents to security@definica.com. Do not include private keys or seed phrases.

16. Profiling, Screening, and Automated Decisions

The Interface may use automated signals to identify sanctioned addresses, exploit-linked funds, fraud, attacks, location restrictions, or other risk. This may result in a warning, request for review, or restricted access to the Interface.

Definica does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing, logic, significance, consequences, legal basis, and available rights are separately disclosed. Where required by law, you may request human review or challenge an automated access decision by contacting privacy@definica.com.

An Interface restriction may not prevent direct access to public contracts and does not alter the public blockchain record.

17. Your Privacy Rights

Depending on your jurisdiction and the legal basis, you may have the right to:

  • obtain confirmation and access to personal data;
  • correct inaccurate personal data;
  • request deletion of controlled off-chain personal data;
  • restrict or object to processing;
  • receive portable data in an applicable format;
  • withdraw consent without affecting earlier lawful processing;
  • object to direct marketing at any time;
  • opt out of legally defined sale, sharing, targeted advertising, or certain profiling;
  • request review of certain automated decisions;
  • use an authorized agent where permitted;
  • appeal a refusal where applicable; and
  • complain to a competent data-protection or privacy authority.

Requests may be submitted to privacy@definica.com. The Controller may request proportionate verification and information needed to locate the relevant data. You will not be asked for a private key or seed phrase. Definica will not discriminate against you for exercising a privacy right.

Rights are not absolute. A request may be limited by legal obligations, security, fraud prevention, third-party rights, legal claims, or inability to verify the requester. Technical design does not, by itself, remove an applicable privacy right. Where a request concerns a public blockchain, the Controller will assess its actual role and control and apply legally required measures to the systems it controls, which may include off-chain copies, indexes, links, enrichment, Interface displays, and future processing design. Where possible, the Controller will explain a refusal and any available appeal or complaint route.

17.1 Data-protection complaints

You may submit a data-protection complaint to privacy@definica.com. The Controller will provide an electronic route, investigate the complaint appropriately, and communicate the outcome without undue delay. Where United Kingdom complaint-handling law applies, the Controller will acknowledge the complaint within 30 days. Using this internal route does not affect your right to contact a competent supervisory authority.

18. EEA, United Kingdom, and Switzerland

Individuals in the European Economic Area, United Kingdom, or Switzerland may have rights under the GDPR, UK GDPR, Swiss data-protection law, or related national law.

You may object to processing based on legitimate interests. The Controller will stop the processing unless it demonstrates compelling legitimate grounds or the processing is needed for legal claims. You have an unconditional right to object to direct marketing.

You may complain to the supervisory authority in your place of residence, work, or alleged infringement. Any representative or data protection officer required for a relevant jurisdiction will be identified in the official Definica Legal Notice.

19. United States Privacy Rights

Residents of certain U.S. states may have rights to know, access, correct, delete, obtain a copy, opt out of legally defined sale, sharing, targeted advertising, or profiling, use an authorized agent, appeal a decision, and receive equal service when exercising rights.

The availability of a right depends on whether the relevant law applies to the Controller and the processing. Requests may be sent to privacy@definica.com. If a state-specific notice or opt-out mechanism is legally required, it will be made available through the Website before the relevant processing begins.

20. Children

The Website and Interface are not directed to persons under 18. The Controller does not knowingly collect personal data from children. If you believe a child has provided personal data, contact privacy@definica.com so controlled off-chain information can be assessed and, where appropriate, deleted.

22. Changes to This Policy

The Controller may revise this Privacy Policy when processing, providers, legal requirements, or Definica services change. The current version will be made available through the Website. Material changes may also be announced through the Interface, governance forum, or another official channel.

This Privacy Policy is a transparency notice, not a request for blanket consent. Where consent or another action is legally required for a new use, the Controller will seek it separately before beginning that use.

23. Contact

Privacy questions and rights requests: privacy@definica.com

Security and incident reports: security@definica.com

Legal questions: legal@definica.com

Website: https://definica.com