defi.comClose

PRIVACY NOTICE

Effective date: 17 July 2026

About this notice

This privacy notice (“Notice”) explains how and why defi.com, Inc. and its group companies (also referred to as “defi.com”, “COMPANY”, “we”, “our” and “us”) uses personal data about those individuals that either:

  • register your interest in our DeFi services (“Services”);
  • communicate with us in relation to the Services and other related matters; or
  • visit or use our website defi.com (the “Website”) in relation to the above, or to review our news pages or where you are considering using our Services;

(in each case, referred to as “you”).

You should read this Notice, so that you know what we are doing with your personal data. Please also read any other privacy notices that we make available to you, that might apply to our use of your personal data in specific circumstances outside the scope of this Notice, which primarily concerns our processing of your personal data in relation to or in connection with the Website and use of the Services.

This Notice also explains how we use cookies, pixels, tags and similar technologies to operate and secure the Website, understand how it is used, measure the effectiveness of our marketing and, where you permit this or applicable law otherwise allows, create and use advertising audiences. Further information about the individual technologies, their providers and their duration is set out in our Cookie Policy.

Who we are and our contact details

defi.com, Inc. whose address is 1209 Orange Street, City of Wilmington, County of New Castle, 19801, USA, a Delaware corporation.

Our contact for data protection purposes is data privacy manager, legal@defi.com.

Our data protection responsibilities

In this notice we refer to the following terms, which have the following meanings:

  • “Personal data” is any information that relates to an identifiable natural person. Your name, address and contact details are all examples of your personal data, if they identify you.
  • The term “process” means any activity relating to personal data, including, by way of example, collection, storage, use, consultation and transmission.
  • The Company is a so-called “controller” of your personal data. This means that we make decisions about how and why we process your personal data and, because of this, we are responsible for making sure it is used in accordance with applicable data protection laws.

What types of personal data do we collect and where do we get it from?

We collect your personal data from various sources. The table below sets out the different types of personal data that we collect and the sources we collect it from. Typically, you provide us with personal data directly when you communicate with us (including via the Website) and when you use or seek to use our Services. We also obtain some personal data from other sources, and create some personal data ourselves, as set out in the table.

CategoryType of personal dataCollected from
Contact Information
  • Email address
  • User name
  • Country (optional)
  • Your marketing preferences
You
Service Information
  • Contact Information (see above)
  • You
  • Systems used for the Services
Communications Data
  • Contact Information (see above)
  • Optional information included in your communications and support requests
  • Your preferences in receiving marketing from us
  • Your preferences regarding cookie, social media marketing advertisements and tracking technologies (see our Cookie Policy for more information)
  • You
  • Systems used for the Services
Website Information
  • Contact Information (see above)
  • IP address and other online identifiers, browser/device type, operating system, language, approximate location, date/time of use
  • Usernames
  • Analytics data (aggregated usage metrics)
  • Server logs, security logs, analytics signals
  • Cookies/pixels/tags and similar technologies
  • Referral source and campaign information
  • Information generated through our use of cookies, tags and pixels and similar technologies (where they are essential or you have consented to them)
  • You
  • Device used to access the Website
  • Our Website

Please be aware that we cannot communicate with you or administer the Services and your transactions without your personal data. Where we don't need your personal data, we will make this clear, for instance we will explain if any forms you are required to complete are optional or contain sections that can be left blank.

If any of the personal data you have given to us changes, such as your contact details, please inform us without delay by contacting legal@defi.com.

What do we do with your personal data, and why?

We process your personal data for particular purposes in connection with the Services or your engagement with us, and the management and administration of our business.

We are required by law to always have a so-called “lawful basis” (i.e. a reason or justification) for processing your personal data. The table below sets out the purposes for which we process your personal data and the relevant lawful basis on which we rely for that processing.

Please note that where we have indicated in the table that our processing of your personal data is either:

  1. (a) necessary for us to comply with a legal obligation; or
  2. (b) necessary for us to take steps, at your request, to enter into or potentially enter into a contract with you, or to perform it,

if you choose not to provide the relevant personal data to us, we may not be able to provide our Services to you.

Website tracking information

When you visit the Website, we and our service providers may collect your IP address and approximate location, cookie and similar identifiers, browser, device and operating-system information, pages and URLs viewed, referral source and campaign information, the date, time and duration of visits, and interactions with the Website, including whether a waitlist registration, referral or defi ID claim was completed. We receive this information from your browser or device, our consent-management provider and our analytics and advertising partners.

We configure these technologies so that email addresses, defi IDs, wallet addresses, financial information and the contents of forms are not intentionally disclosed to advertising platforms.

Purposes of processingYour consentTo perform a contract with youTo comply with a legal obligationFor our legitimate interests
Contact Information
a) Responding to your communications with us✓✓ (It's important that we can respond to your enquiries, complaints or other communications)
b) Confirming registration and notifying you in relation to your proposed use of the Services✓ (It's important that we keep you informed of matters related to your use or proposed use of the Services)
c) Sending you information as set out in the section “How do we communicate with you?”, below✓✓ (It is important to keep you updated of our Services)
d) To send you relevant marketing communications✓✓ (It is necessary for our legitimate interests to develop our products/services and grow our business)
Website Information
e) Ensure the operation and performance of the Website and respond to support queries✓ (We need to ensure the Website functions correctly)
f) To improve the functionality of the Website✓ (It is in our interest to keep the Website up to date and improve its functionality for the benefit of users)
g) To enable you to register your interest in the Services and access content✓✓ (It is in our interests to grant you access to a private log-in where you can access information relevant to you)
h) To produce statistics about Website use, traffic sources, performance and user journeys, and to improve the Website and its content✓
i) To measure advertising performance, attribute visits and registrations, and create or retarget advertising audiences through Google, LinkedIn, X and TikTok✓
Services Information
j) Providing you with the Services✓
k) Sharing relevant information in relation to your use of the Services✓✓ (It is important that we keep you updated)
l) Authenticating your access to the platform and content✓✓
m) Provide security measures, detect malicious use, rate limiting, investigate incidents✓ (It is important that we keep the Website and your use of the Services secure)
Marketing and communications data
n) To send you information about us and our products and services that may be of interest to you through your preferred method(s)✓
o) To send you service-related operation notifications relating to our products and services✓ (It is in our and your interest to keep you informed of product and service developments)
p) To process information from cookie and analytics technology✓
q) To process information from X pixel tracking✓
r) To process information from X ads for targeted advertising✓
All categories
s) Establishing and enforcing our legal rights and obligations and monitoring to identify and record fraudulent activity✓
t) Complying with instructions from law enforcement agencies, any court or otherwise as required by law✓
u) For our general record-keeping and customer relationship management✓✓ (We need to store customer related information so we can refer back to it)
v) Managing the proposed sale, restructuring or merging of any or all part(s) of our business, including to respond to queries from the prospective buyer or merging organisation✓✓ (We have a legitimate interest in being able to sell any part of our business)
w) Resolving any complaints from or disputes with you✓✓ (We need to be able to try and resolve any complaint or dispute you might raise with us)

For visitors in the UK, EEA, Switzerland, Nigeria and Argentina, we rely on consent for non-essential analytics and advertising technologies. For visitors elsewhere, we process this information as permitted by applicable local law and subject to any applicable right to object or opt out.

We may also collect data in from your use of the Website or Services in statistical or aggregated form; this will not identify you and cannot be linked back to you. We may use it to conduct research and analysis, including to produce statistical research and reports. For example, to help us understand the input spread of our users.

We do not make decisions in relation to you based solely on the use of automated technologies.

Cookies, pixels and similar technologies

We use strictly necessary technologies to operate, secure and remember choices made on the Website. We also use analytics technologies and, where enabled, advertising pixels. Where applicable law requires prior consent, analytics and advertising technologies will not be activated unless you accept the relevant category.

You can accept, reject or customise non-essential technologies and change your choices at any time using the “Cookie Settings” link available on the Website. Our Cookie Policy identifies the individual technologies, providers, purposes and durations.

Sensitive Information

We do not need to process ‘special categories of personal data’, criminal-offence data and/or other sensitive personal data (together, “Sensitive Information”) to provide the Services and request that you do not send it.

Direct marketing

During registration, you may choose to receive marketing communications from defi.com. Where consent is required, we will send these communications only if you actively opt in. You may withdraw your consent or object to marketing at any time by using the unsubscribe link in the communication, changing your account preferences where available, or contacting legal@defi.com. Your cookie choices do not subscribe you to email marketing.

We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.

You can ask to stop sending you marketing communications at any time by logging into the Website and checking or unchecking relevant boxes to adjust your marketing preferences or by following the opt-out links within any marketing communication sent to you or by contacting us legal@defi.com.

If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.

Who do we share your personal data with, and why?

Sometimes we need to disclose your personal data to other people.

Inside the defi.com Group:

We are part of a group of companies. Therefore, we will need to share your personal data with other companies in our group for our general business purposes, to manage the Services and, in some cases, for authorisations/approvals with relevant decision makers, reporting and where systems and services are provided on a shared basis.

Access rights between members of our group are limited and granted only on a need to know basis, depending on job functions and roles.

Outside the defi.com Group

From time to time we may ask third parties to carry out certain business functions for us, such as Website hosting and systems support and data aggregation, logging and monitoring. These third parties will process your personal data on our behalf (as our processor). We will disclose your personal data to these parties so that they can perform those functions. Before we disclose your personal data to these third parties, we will seek to ensure that they have appropriate security standards in place to protect your personal data. Examples of these third-party service providers include service providers and/or sub-contractors, which provider systems support and maintenance, and hosting of the Website.

We disclose online identifiers and Website-activity information to our analytics and advertising partners, currently Google for Google Tag Manager, Google Analytics 4 and related advertising measurement, LinkedIn for the Insight Tag, X for the X pixel and TikTok for the TikTok pixel.

Depending on the service and its configuration, these providers may act as our processor, a joint controller with us or an independent controller. They may associate information received from the Website with information held through their own services, where permitted by applicable law and your choices. Our Cookie Policy and consent tool identify the relevant provider, purpose and privacy information.

We will add Meta to this list only if the Meta pixel is activated by you.

In certain circumstances, we will also disclose your personal data to third parties who will receive it as controllers of your personal data in their own right, for example where:

  1. (a) we buy, sell or transfer our business (or part of it) in connection with a share or asset sale or outsourcing, we may disclose or transfer your personal data to the prospective seller, buyer or transferor and their advisors; and
  2. (b) we need to disclose your personal data in order to comply with a legal obligation, to enforce a contract or to protect the rights, property or safety of our employees, customers, or others.

We have set out below a list of the categories of recipients with whom we are likely to share your personal data:

  1. (a) data monitoring, cloud platform and data hosting providers;
  2. (b) security logging and monitoring provider;
  3. (c) public blockchain networks and related infrastructure providers;
  4. (d) consultants and professional advisors including legal advisors and accountants;
  5. (e) courts, court-appointed persons/entities, receivers and liquidators; and
  6. (f) governmental departments and statutory and/or regulatory bodies.

We may also use third party controllers to provide part of the services, such as authentication, but do not share any personal data with them. They are responsible for their own use of your personal data, so you should check their privacy notices to understand their data practices.

Where in the world is your personal data transferred to?

In providing the Services, we may transfer your personal data to members of the defi.com group and to external recipients that are established in jurisdictions other than your own.

Please be aware that the data protection laws in some jurisdictions may not provide the same level of protection to your personal data as is provided to it under the laws in your jurisdiction.

We will always seek to ensure that adequate protections are put in place when transferring your personal data to recipients within other jurisdictions, particularly where legislation such as (UK) GDPR may apply, for example using the EU standard contractual clauses (with UK addendum where applicable) for transfers of personal data from the UK or EU to so-called third countries. For more information regarding the transfers undertaken by us and the protections put in place, please contact us using the details set out at the end of this Notice.

Our analytics and advertising providers may process personal data in the United States and other countries outside your jurisdiction. Transfers of personal data to X Corp. in the United States are made on the basis of X Corp.'s certification under the EU-US Data Privacy Framework (DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework, as applicable. Where DPF certification does not cover the relevant category of data, transfers are made on the basis of Standard Contractual Clauses approved by the European Commission. Where UK or EEA restricted-transfer rules apply, we use an applicable adequacy arrangement or appropriate contractual safeguards, such as the EU Standard Contractual Clauses together with the UK Addendum or another approved UK transfer mechanism, and carry out any required transfer-risk assessment. A copy of the applicable transfer safeguards is available on request by contacting us at legal@defi.com.

How do we keep your personal data secure?

We will take specific steps (as required by applicable data protection laws) to ensure we take appropriate security measures to protect your personal data from unlawful or unauthorised processing and accidental loss, destruction or damage.

How long do we keep your personal data for?

We will only retain your personal data for a limited period of time (for example, web/server/security logs generally for 60 days (or longer if needed for incident investigation), error diagnostic logs generally for 90 days; support communications will generally be kept up to 24 months from the last interaction with the user. These are all guidelines that we work to but we may keep data for longer based on the factors below. As a general rule we keep data for no longer than is necessary for the purposes for which we are processing your personal data. On-chain records (public blockchain) are stored indefinitely in the public domain. How long data is kept will depend on a number of factors, including:

  1. (a) any laws or regulations that we are required to follow;
  2. (b) whether we are in a legal or other type of dispute with each other or any third party;
  3. (c) the type of information that we hold about you; and
  4. (d) whether we are asked by you or a regulatory authority to keep your personal data for a valid reason.

We generally retain identifiable analytics event data accessible to us for no longer than 14 months. Advertising audience and attribution information is retained for the periods identified in our Cookie Policy or the relevant provider's privacy information, and we configure the shortest period reasonably required for the relevant campaign. Consent and preference records are retained for as long as reasonably necessary to demonstrate the choices made and our compliance with applicable law.

How do we communicate with you?

We will use your personal data to communicate with you:

  • in relation to any use of the Services you make and to inform you of anything which may affect your use of the Services;
  • to administer our relationship with you;
  • to respond to any questions or complaints that you may have; and
  • to invite you to take part in market research or request feedback on our products and services or intended products and services.

From time to time and with your consent (where required), we will provide you with information about services, promotions and/or offers which may be of interest to you.

Where you have subscribed to our online newsletter, we will also provide a copy by email.

Please note that you may opt-out of receiving the newsletter and any other marketing materials that we send you, by unsubscribing.

What are your privacy rights and how can you exercise them?

Where our processing of your personal data is based on your consent (please see the tables above), you have the right to withdraw your consent at any time. If you do decide to withdraw your consent we will stop processing your personal data for that purpose, unless there is another lawful basis we can rely on – in which case, we will let you know.

You may withdraw consent for analytics or advertising technologies at any time through Cookie Settings. This will stop future collection through the technologies concerned and will not affect the lawfulness of processing before withdrawal. Where applicable law gives you a deletion right, you may also request deletion of relevant personal data, subject to applicable exceptions.

In certain US states, disclosing online identifiers and internet activity to advertising partners for cross-context behavioural or targeted advertising (including the X pixel and X ads described in this Notice) may be considered a “sale”, “sharing” or processing for targeted advertising, even though we do not sell personal information for money. Where these rights apply, you may opt out through the “Your Privacy Choices” link. We also honour legally recognised browser-based opt-out preference signals, including Global Privacy Control.

Do Not Track Signals. Certain web browsers may transmit “Do Not Track” signals. At this time, we do not respond to “Do Not Track” signals or similar mechanisms. However, you may opt out of tracking technologies as described in our Cookie Policy.

Where our processing of your personal data is based on the legitimate interests (please see the tables above), you can object to this processing at any time. If you do this, we will need to show either a compelling reason why our processing should continue, which overrides your interests, rights and freedoms or that the processing is necessary for us to establish, exercise or defend a legal claim.

Where we are processing your personal data for direct marketing purposes, you have the right to object to that processing at any time. You can do this by unsubscribing to the address specified in a direct marketing email or by notifying us at legal@defi.com.

Laws in certain jurisdictions may provide individuals with rights relating to personal data, such as those listed below. We will honour these rights to the extent required by law. You have the right to (subject to applicable laws and certain limitations):

  1. (a) access your personal data and to be provided with certain information in relation to it, such as the purpose for which it is processed, the persons to whom it is disclosed and the period for which it will be stored;
  2. (b) require us to correct any inaccuracies in your personal data without undue delay;
  3. (c) require us to erase your personal data;
  4. (d) require us to restrict processing of your personal data;
  5. (e) receive the personal data which you have provided to us, in a machine-readable format, where we are processing it on the basis of your consent or because it is necessary for your contract with us (please see the tables above) and where the processing is automated;
  6. (f) object to a decision that we make which is based solely on automated processing of your personal data (however, we do not currently conduct any such decision making); and
  7. (g) make a complaint to us regarding the way we use your personal data.

If you wish to exercise any of these rights please contact legal@defi.com in the first instance. We will aim to respond to all legitimate requests within one month of receipt.

You may also have the right to lodge a complaint with the relevant data protection regulator.

Updates to this Notice

We may update this Notice from time to time to reflect changes to the type of personal data that we process and/or the way in which it is processed. We will notify you of material changes to this Notice. We also encourage you to check this Notice regularly. Updated copies can be found at defi.com/privacy.

Where can you find out more?

If you want more information about any of the subjects covered in this Notice or if you would like to discuss any issues or concerns with us, you can contact legal@defi.com.

General

This Notice should be read together with our Cookie Policy.