Skip to main content
LAST UPDATED: JULY 2026

Privacy Policy

How Adina Labs collects, uses, and protects your information - Adina Labs is committed to compliance across all operating jurisdictions under the European Union General Data Protection Regulation (GDPR), California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Australian Privacy Principles (APPs) under the Privacy Act 1988, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

This Privacy Policy applies to our websites, applications, and Web3 services including native token interactions.

GDPR CompliantCCPA CompliantAPPS CompliantDPDP Act Compliant

Compliance

Applicable Laws

  • European Union General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
  • Australian Privacy Principles (APPs - Privacy Act 1988)
  • India Digital Personal Data Protection Act, 2023 (DPDP Act)
  • EU-U.S. Data Privacy Framework (DPF)

Core User Rights

  • Right to Access & Delete
  • Right to Withdraw Consent
  • Right to Opt-Out of Data Sharing & Sale

1. Information We Collect

Personal Information

We may collect the following personal information (which may include "personal data" under the GDPR and DPDP Act or "personal information" under the CCPA/CPRA and APPs):

  • Name, email address, phone number, and postal address (if provided)
  • Account credentials, authentication data (e.g., public wallet addresses, cryptographic signatures), and professional details (e.g., work history for verified resume attestations)
  • Payment and billing information (e.g., transaction hashes, fiat or crypto payment details)
  • Communications with our support team, including details from petitions, subscriptions, donations, or inquiries
  • Inferred or derived data, such as engagement with campaigns or token usage patterns, where linked to your identity

Technical and Usage Information

  • IP address, device information (e.g., browser type, version, operating system), and geolocation data (approximate)
  • Usage patterns, analytics data (e.g., pages visited, time spent, interactions with Web3 features)
  • Cookies, web beacons, and similar tracking technologies
  • Blockchain-related data (e.g., on-chain transaction details, Zero-Knowledge attestation hashes, smart contract interactions), which are pseudonymous and public by nature

We do not knowingly collect sensitive personal information (e.g., health data) unless explicitly provided for a specific purpose (e.g., Nutraceuticals Hub inquiries) with express consent. Users must be at least 18 years old (or the legal age of digital majority in your jurisdiction) to use this Service.

2. How We Use Your Information

We use your information for legitimate purposes, always balancing our operational needs with your individual rights. For Web3 platforms, this includes enabling token-based interactions while ensuring operational transparency.

Service Provision

  • Account management, authentication, and Web3 wallet integration
  • Processing transactions, payments, subscriptions, donations, and token-related activities
  • Providing customer support and personalized content
  • Analyzing engagement to improve Service features and Web3 user experience

Legal Compliance & Security

  • Complying with applicable legal obligations (e.g., Anti-Money Laundering and Know Your Customer obligations where required for custodial or fiat gateways)
  • Preventing fraud, abuse, smart contract exploits, and unauthorized system access
  • Enforcing our Terms of Service and protecting user safety
  • Responding to lawful regulatory requests from authorities in relevant operating jurisdictions

Marketing and Advocacy

  • Sending newsletters, campaign updates, or event invitations (with explicit opt-in consent; you can unsubscribe at any time)
  • Aggregating anonymized data for advocacy reports on digital rights

3. Legal Basis for Processing

  • Under the European Union General Data Protection Regulation (GDPR): Consent (Article 6(1)(a)), Contractual Necessity (Article 6(1)(b)), Legitimate Interest (Article 6(1)(f)), and Legal Obligation (Article 6(1)(c)).
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA): Notice and choice, providing statutory rights to know, delete, correct, and opt-out of sales/sharing of personal information.
  • Australia's Australian Privacy Principles (APPs): Consent, contractual necessity, or where authorized/required by law under the Privacy Act 1988.
  • India's Digital Personal Data Protection Act, 2023 (DPDP Act): Consent and legitimate uses, operating as a Data Fiduciary and integrating with registered Consent Managers as required by the DPDP Rules.

4. Your Privacy Rights

We respect your privacy rights under applicable laws. To exercise them, contact us (see Section 8). We respond within statutory timelines (30 days under GDPR and APPs, 45 days under CCPA/CPRA, or via our designated Grievance Officer under the DPDP Act) upon verification of your identity.

  • Under GDPR (EU/EEA Residents): Right of access, rectification, erasure, restriction of processing, data portability, objection, and consent withdrawal.
  • Under CCPA/CPRA (California Residents): Right to know, right to delete, right to opt-out of sale/sharing, right to correct inaccurate data, right to limit sensitive data use, and right to non-discrimination.
  • Under Australia's APPs: Access and correction rights; option for pseudonymity where practicable; right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
  • Under India's DPDP Act: Right to access information, right to correction and erasure, right of grievance redressal, and right to nominate a representative.
  • Global Rights & Web3 Data: You may opt-out of cookies and tracking via our cookie consent banner. For Web3 data: information published to public blockchains (such as transaction records and immutable smart contract hashes) cannot be modified or deleted due to underlying protocol immutability. However, we will permanently un-link and erase off-chain personal data tied to your wallet address upon request.

5. Data Retention and Security

Data Retention: We retain personal information only as long as necessary for the purposes described, or as required by statutory record-keeping laws (e.g., financial and tax compliance obligations). Off-chain account data is securely deleted, de-identified, or anonymized once no longer needed. Blockchain-based public records remain on-chain perpetually but are unlinked from your off-chain identity.

Security Measures:

  • End-to-end encryption for sensitive data in transit and at rest
  • Hardware-backed Secure Enclave integration for local client-side wallet key management
  • Strict access controls, multi-factor authentication, and regular third-party security audits
  • Incident response procedures, including regulatory breach notifications within 72 hours (GDPR) or applicable statutory frameworks

6. Disclosure and International Transfers

Disclosure: We disclose personal data only to service providers bound by strict confidentiality and data processing agreements, for legal compliance, or with your explicit consent. We do not sell personal information. Public blockchain transactions are visible on chain but are not tied to personal identity by Adina Labs without consent.

International Transfers:

  • European Union / GDPR: Transfers utilize Adequacy Decisions (including the EU-U.S. Data Privacy Framework), Standard Contractual Clauses (SCCs), and Transfer Impact Assessments (TIAs).
  • India / DPDP Act: Transfers comply with central government notifications and cross-border data flow regulations.
  • Australia / APPs: Reasonable steps taken under APP 8 to ensure overseas recipients uphold equivalent privacy protections.
  • United States / CCPA/CPRA: Compliance with cross-border obligations and user opt-out rights.

7. Cookies and Tracking

We use cookies and similar tracking technologies for essential service operations, Web3 wallet sessions, performance analytics, and security verification. Users may manage preferences via our cookie banner or browser settings. Disabling technical cookies may affect Web3 platform functionality.

8. Contact and Data Protection Officer

For privacy inquiries, rights exercises, or complaints, contact us with the subject line "Privacy Request - [Your Name/Right]":

  • Data Protection Officer / Privacy Officer: info@adinalabs.com
  • General & Legal Inquiries: info@adinalabs.com
  • Regulatory Authorities: EU Supervisory Authorities | United States: California Privacy Protection Agency (cppa.ca.gov) | Australia: Office of the Australian Information Commissioner (oaic.gov.au) | India: Data Protection Board of India

9. Updates to This Privacy Policy

We may update this Policy to reflect operational, legal, or regulatory developments. The "Last Updated" date indicates the current active version. Material changes will be communicated via website notices or direct electronic communications where required.

10. Additional Notes for Web3 Platforms

  • Non-custodial interactions (e.g., our proprietary wallet) do not require or collect personal private keys. Private keys never leave your local device.
  • Public blockchain interactions are irreversible; users are encouraged to maintain privacy through pseudonymous wallet addresses.
  • Third-party links or decentralized applications (dApps) accessible via the platform are governed by their respective independent privacy policies.