1. Controller and scope
TVK Labs & Technologies Ltd acts as controller for personal data processed for the ENTELΞKRON website and investor-platform activities unless a separate notice identifies another controller. Some vendors act as processors; certain regulated or verification providers may act as independent or joint controllers for their own legal obligations.
2. Data we may collect
- Identity and contact data: name, date of birth, address, email, telephone number and nationality.
- KYC/AML data: identity documents, liveness/biometric verification outputs where used, sanctions/PEP screening results, beneficial ownership and source-of-funds information.
- Account and security data: authentication events, IP address, device/browser data, session records, fraud signals and audit logs.
- Transaction and wallet data: public wallet addresses, chain/network, transaction hashes, allocation records and payment verification metadata.
- Application data: investor classification, jurisdiction, eligibility responses, acknowledgement records and supporting documents.
- Communications: support, legal, partnership, investor and marketing correspondence.
- Technical data: cookies, consent state, diagnostics, performance and security telemetry where enabled.
3. Purposes and lawful bases
We process data to provide and secure services, manage accounts, assess eligibility, conduct KYC/AML and sanctions screening, prevent fraud, meet legal obligations, administer token-sale and allocation processes, maintain records, respond to enquiries, defend legal claims and improve service reliability. Depending on the activity, lawful bases may include contract, legal obligation, legitimate interests and consent. Special-category or biometric processing, where applicable, requires an additional lawful condition.
4. KYC and identity providers
Identity verification may be performed through approved third-party providers such as Sumsub. The provider may receive identity documents, biometric/liveness data and screening information necessary for verification. Provider-specific privacy terms may apply. ENTELΞKRON application servers should retain only the compliance data reasonably required for platform and legal records, rather than unnecessary copies of raw identity media.
5. Blockchain data
Public blockchain records may be permanent, globally accessible and outside our ability to erase or modify. Do not place unnecessary personal data on-chain. A wallet address may become personal data where it can be linked to an identifiable individual.
6. Recipients and processors
Data may be shared with hosting, database, identity/KYC, email, security, analytics, professional-adviser, payment, blockchain-infrastructure and compliance providers on a need-to-know basis, subject to appropriate contractual and security controls. We may also disclose information to regulators, courts, law-enforcement authorities or other competent bodies where legally required.
7. International transfers
Some providers may process data outside the UK or EEA. Where a restricted transfer is made, we assess the applicable transfer mechanism and safeguards, which may include adequacy regulations/decisions, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses and transfer-risk/data-protection assessments where required.
8. Retention
We retain personal data only for as long as reasonably necessary for the purpose collected, legal and regulatory record-keeping, dispute handling, fraud prevention and security. KYC/AML, transaction and contractual records may require longer retention than ordinary website data. Retention periods are reviewed according to the applicable legal basis and jurisdiction.
9. Security
We apply proportionate technical and organisational measures including access control, authentication, encryption in transit, role-based permissions, audit logging, data minimisation, secure development and incident-management controls. No system can be guaranteed absolutely secure.
10. Your rights
Subject to applicable law and exemptions, individuals may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. Certain data cannot be erased where retention is legally required or where immutable public blockchain records are outside our control.
11. Automated decision-making
Fraud, sanctions, KYC or eligibility tools may generate automated risk signals. Where applicable law grants rights in relation to solely automated decisions producing legal or similarly significant effects, we will provide the required safeguards and human review process.
12. Cookies and electronic communications
Cookies and similar technologies are governed by the separate Cookies & Electronic Communications Policy. Non-essential technologies should be activated only where the required consent or other lawful basis exists.
13. Children
Investor and token-sale functionality is not directed to children. We do not knowingly accept participation from persons below the applicable age of legal capacity for the relevant transaction.
14. Data breaches
Suspected personal-data incidents are assessed under the applicable UK/EU data-breach notification rules and other relevant law. Where notification thresholds are met, required authorities and affected individuals will be notified within the legally applicable timeframe.
15. Contact and complaints
Privacy and legal enquiries: legal@tvk.group. Individuals may also have the right to complain to the UK Information Commissioner's Office or another competent supervisory authority depending on jurisdiction.
الامتثال
يُقدَّم هذا المستند لأغراض إعلامية ويجب مراجعته من قبل مستشار قانوني مؤهل قبل الاعتماد العام عليه.