Privacy Notice
Last updated: 23 September 2026
1. Who we are and what this notice covers
This notice explains how we collect and use personal data when you use the websites and applications that we operate and make available subject to our Terms of Use, together with their pages and subpages (together, the "Sites"), when you submit a form on them, when you sign up to an event we hold or take part in, or when you correspond with us by email, by messaging or in any other way. It also covers personal data we hold from an earlier dealing between you and us, including from a website, an application, a form, an event or a document service that we operated or used before this notice was published, and it applies to that data as it applies to data we collect now.
The controller of the personal data described here, and the person responsible for its processing under Panamanian law, is YieldNet Labs Inc., a corporation organised under the laws of the Republic of Panama ("Yield Network", "we", "us", "our").
Questions, requests and complaints go to legal@yieldnetwork.io, wherever you are, and we deal with data protection matters at that address.
This notice replaces every privacy policy published earlier for the Sites.
2. What we collect
Information you give us
Access requests submitted on the Sites: legal entity name, email address, entity type, jurisdiction, and any message you add.
Program registrations submitted on the Sites: your name or entity name, email address, Telegram handle, entity type, jurisdiction, one or more wallet addresses, an optional expected ticket size, the confirmations you give, and any message you add.
Issuer and other enquiries, and applications submitted through any other form on the Sites: your name or entity name, your organisation, your contact details and the information the form asks for.
Event sign-ups, where we hold an event or take part in one: your name, your organisation, your contact details and anything else the sign-up asks for. Sign-ups are handled online by the event platform we use for that event.
Verification information, where we ask for it: information and documents about you, about the entity you act for and about the persons who own or control it, and about the source of the funds or digital assets you may deposit.
Correspondence: what you send us by email, Telegram or other messaging, including your contact details and the content of the exchange.
Document access: where we make program documents available to you through a document platform, that platform records the address the document was sent to or opened from, that the document was opened, and information about how it was viewed, which may include which pages were viewed, for how long, whether it was downloaded, and when it was opened again. It makes that record available to us. We use it to know that a document reached you and to follow up on your request, and section 3 says when we may use the contact details in it for program news and updates. We may switch off the page by page detail where we do not need it.
Where we ask for verification information, we do so either because a law that applies to us requires it or because we have made it a condition of taking a registration further. Otherwise, giving us information is not a legal requirement, but it is what we need in order to deal with your request. If you do not give us the information a form marks as required, we cannot review an access request or designate a wallet address for a program. If you do not give us verification information we have asked for, we may decline, defer, suspend or withdraw your access request or registration, and we may decline to make it available to an issuer. If you do not give us contact details we cannot reply to you.
Information we collect automatically
Technical fields submitted with a form: a reference to the listing you came from, and fields used to detect automated submissions.
Form security data: when you submit a form we record the submission, and we may also record technical information about the device and connection used, which may include a one-way hash of the internet protocol address and of the browser's user-agent string rather than the address itself. Where we record it, we use it only to detect abuse and duplicate submissions.
Acceptance record: where a site asks you to accept the Terms of Use before you continue, a record that an acceptance was given, which version was accepted and when. A copy of that record is kept in your browser as described in section 7. We also keep a record of the acceptance in our own systems. Where the acceptance relates to a submission you then make, we hold that record with the submission. Where it does not, we hold it without any name or contact detail and we do not use it to identify you.
Server logs: standard request logs kept by our hosting providers for a short period, for security and troubleshooting.
Information about general use of the Sites, which comes from the server request logs described above. Section 7 explains what we do and do not store in your browser.
Information about business contacts
We keep records of the organisations and people we work with in the course of our business: names, roles, business contact details, messaging handles, wallet addresses that have been shared with us or used to participate in a program, and a history of our interactions. Most of this comes from you directly, including where a person signs up to one of our applications, registers for an event we hold, registers with the organiser for an event we take part in, or asks to see documents about a program. Some comes from public sources, from an issuer or a partner, or from an introduction made by a third party. Where we obtain your details in one of those ways, we hold the same categories of data and use them for the purposes in section 3, and we tell you about it, together with the categories of data concerned and the source they came from, within a reasonable period and in any event within one month of obtaining them, or, if earlier, when we first contact you or when we first make them available to another recipient, and we may omit to do so only where one of the circumstances described in the paragraph on information about other people applies.
Information about other people
Where you give us information about another person, including a person who owns or controls the entity you act for, we hold the categories of information described in the verification paragraph above about them, obtained from you and from the verification and screening sources described in section 4, some of which are publicly available. We use it for the purposes in section 3 and keep it for the periods in section 6. Where we hold information about a person that we did not obtain from that person, we may give that person this notice and tell them what we hold, where we obtained it and why. We do so within a reasonable period and in any event within one month of obtaining it, or, if earlier, when we first communicate with that person or when we first make the information available to an issuer or to another recipient. We may not do so where the person already has the information, where giving it would prove impossible or would involve a disproportionate effort, where giving it would be likely to render impossible or seriously impair the purposes of the checks described in section 3, where obtaining or disclosing the information is expressly laid down by a law that applies to us which provides appropriate measures to protect the person's interests, or where the information must remain confidential under an obligation of secrecy. Where we do not give the information for one of those reasons, we may take other measures to protect the person's interests, which may include making this notice publicly available. If you give us information about another person, we also ask you to tell them about this notice.
Blockchain data
Where you participate in a program, deposits are made on public blockchains. Transactions from a wallet address are public by their nature and we cannot change or remove them. We read that public record to attribute participation to the programs shown on the Sites. We treat a wallet address as personal data where we hold it together with your name, entity or contact details, and also where we are able to link it to you by other means reasonably available to us, including through the blockchain analytics sources described in section 3.
3. Why we use it, and the basis on which we do
Purpose | Data involved | Basis under the GDPR and the UK GDPR | Basis under Ley 81 de 2019 (Panama) |
|---|---|---|---|
Answering an access request, enquiry or message | The information you give us | Art. 6(1)(b) where you are the person we would contract with, being steps taken at your request before entering into a contract; otherwise Art. 6(1)(f), our legitimate interest in answering the request | Art. 8(9), our legitimate interest in responding to a request you have made to us |
Handling a program registration: reviewing it, designating your wallet address with the issuer, and confirming the outcome to you | Registration data and contact details | Art. 6(1)(b) where you are the person we would contract with; otherwise Art. 6(1)(f), our legitimate interest in operating the Sites and in handling the registrations submitted on them | Art. 6(2), where the processing is necessary to perform a contractual obligation to which you are party; otherwise Art. 8(9), our legitimate interest in operating the Sites and in handling the registrations submitted on them |
Verifying who you are and who you act for, and screening you, that entity, the persons who own or control it and the wallet addresses you register against sanctions lists, politically exposed person lists, adverse media and blockchain analytics sources, and against any list of persons we have been asked not to deal with. We carry out these checks where we consider it appropriate or where a law that applies to us requires it, before we pass a registration on and again afterwards where we consider it appropriate. The issuer runs its own eligibility screening and geo-blocking at deposit | Entity name, jurisdiction, wallet addresses, the confirmations you gave, and any verification information we have asked for | Art. 6(1)(f), our legitimate interest in not dealing with a person we may not lawfully deal with; and Art. 6(1)(c) where an obligation under Union or United Kingdom law applies to us. Where a check returns information falling within a special category under Art. 9(1), the condition available to us depends on which Regulation applies. Where the UK GDPR applies, we may rely on Art. 9(2)(g), substantial public interest, on the basis of a condition in Part 2 of Schedule 1 to the Data Protection Act 2018, which may be preventing or detecting an unlawful act, preventing fraud, or suspicion of terrorist financing or money laundering, and we maintain the appropriate policy document that Schedule requires for the condition we rely on. Where the GDPR applies, we have no basis in Union or Member State law for Art. 9(2)(g), and apart from Art. 9(2)(f), the establishment, exercise or defence of legal claims, we do not consider a condition to be available to us; where no condition is available we do not process the information, and we suppress or delete it and reach our decision on the rest of the result. Where a check returns information about criminal allegations, convictions or related security measures, we may process it only where the processing is under the control of official authority or is authorised by a law that applies to us which provides appropriate safeguards; where the UK GDPR applies that means a condition in Part 1, 2 or 3 of Schedule 1 to the Data Protection Act 2018, and we maintain the appropriate policy document that Schedule requires, and where the GDPR applies we have no such official authority and no such authorisation, so we do not process the information and we suppress or delete it and reach our decision on the rest of the result. We do not rely on your consent as the condition for either kind of information | Art. 6(3) where a law that applies to us imposes the obligation; otherwise Art. 8(9), our legitimate interest in not dealing with a person we may not lawfully deal with. Where a check returns data that is sensitive within the meaning of Art. 4 of that Law, we transfer it only where a case in Art. 13 of that Law applies, which will be either your explicit authorisation, or the explicit authorisation of the person concerned, or a case in which a law that applies to us does not require that authorisation, and where no case applies we do not transfer it |
Keeping an attribution record of which wallets participated in which program, and reporting it to the issuer | Wallet addresses, public blockchain data, entity names | Art. 6(1)(f), our legitimate interest and the issuer's in accounting for the program | Art. 8(1), public blockchain data being from a source in the public domain; and Art. 8(9), our legitimate interest and the issuer's in accounting for the program |
Maintaining our records of business contacts and the programs they have taken part in | Business contact data | Art. 6(1)(f), our legitimate interest in keeping an accurate record of the counterparties we deal with | Art. 8(4), lists of a category of persons limited to their organisation, profession or activity and contact details; and Art. 8(9), our legitimate interest in keeping an accurate record of the counterparties we deal with |
Sending you program news and updates, where you have given us a specific consent to do so. We may send these only to a person whose access request or registration we have accepted and whose acceptance has not been withdrawn, and we may therefore also use the record of whether we have accepted your access request or registration, and any later change in that record, to decide whether to send them to you and whether to keep sending them. We do not use information about criminal allegations or convictions, or information falling within a special category, to decide whether to send them | Contact details, and the record of whether we have accepted your access request or registration | Art. 6(1)(a), that consent, which you may withdraw at any time; and, so far as concerns deciding who we send them to, Art. 6(1)(f), our legitimate interest in sending program information only to persons whose request or registration we have accepted | Art. 6(1), consent, which under Art. 6 may be revoked at any time without retroactive effect; and Art. 8(9), our legitimate interest in sending program information only to persons whose request or registration we have accepted, so far as concerns deciding who we send them to |
Sending program news and updates to a person whose business contact details we hold from a dealing between that person and us | Business contact details, and the record of how we came to hold them | Art. 6(1)(f), our legitimate interest in keeping the professional contacts we have dealt with informed about the programs we publish. We rely on this only where the law on electronic marketing that applies to that person allows a message of this kind to be sent without a consent, and not where that law requires one, whether because of the country the person is in or because the person is an individual subscriber such as a sole trader or an unincorporated partnership, and only where we consider that the person can reasonably expect, from the way we came to hold their details, to hear from us about those programs | Art. 8(9), the same legitimate interest |
Keeping the Sites secure, preventing abuse and troubleshooting | Technical fields, form security data, server logs | Art. 6(1)(f), our legitimate interest in protecting the Sites and the people who use them | Art. 8(9), our legitimate interest in protecting the Sites and the people who use them |
Understanding how the Sites are used in general | Server request logs | Art. 6(1)(f), our legitimate interest in understanding which pages are read | Art. 8(9), our legitimate interest in understanding which pages are read |
Keeping a record that the Terms of Use were accepted, and of which version and when | The acceptance record described in section 2 | Art. 6(1)(f), our legitimate interest in being able to show what was accepted and when | Art. 8(9), our legitimate interest in being able to show what was accepted and when |
Complying with law, and establishing, exercising or defending legal claims | Whatever is relevant to the obligation or the claim, which may include any of the categories described in section 2 | Art. 6(1)(c); and Art. 6(1)(f), our legitimate interest in defending our position | Art. 6(3); and Art. 8(9), our legitimate interest in defending our position |
Where we ask for a consent, we ask for it separately from anything else a form asks you to confirm, and you can use the form without giving it. We do not make your personal data available to anyone for money or for other valuable consideration in exchange for the data itself. Information we may pass to an issuer so that a wallet address can be designated for its program is not passed in exchange for any payment or other consideration for that information. We do not take decisions that produce legal effects for you or similarly significantly affect you solely by automated means and without meaningful human involvement: where a check of the kind described above returns a result, a person considers it before we decide what to do. We use automated means to detect and reject automated or duplicate form submissions, and we may operate automated access and geographic controls to give effect to the restrictions in our Terms of Use on who may use the Sites; neither produces a legal effect for you or similarly significantly affects you, and if a submission of yours was rejected in that way you may write to us at legal@yieldnetwork.io. Where a check may return data that is sensitive within the meaning of Article 4 of Ley 81 de 2019, we ask for your explicit authorisation, or the explicit authorisation of the person concerned, before we run it, because Article 13 of that Law restricts what may be done with such data, unless a law that applies to us requires the check and does not require that authorisation. We do not treat that authorisation as the condition on which we process information falling within a special category under the General Data Protection Regulation or the United Kingdom General Data Protection Regulation, and the screening row in the table above says what we rely on and what we do where no condition is available to us.
There are two routes to our mailing list and they are kept apart. Where you give us a consent on one of our forms, we rely on that consent. Where we hold your business contact details from a dealing between you and us, we may send you program news and updates on the basis of our legitimate interest instead, where the law on electronic marketing that applies to you allows a message of that kind without a consent, and we do not do so where that law requires one. We keep a record of which route we rely on for a person and of how we came to hold their details. Every message we send you about program news identifies us, tells you why you are receiving it, brings your right to object to your attention, and carries a simple means of stopping it, whatever the basis.
Where we rely on consent, you may withdraw it at any time. Every message we send you for marketing purposes carries a link or other simple means by which you can stop receiving them, which takes effect without your having to give a reason and at no cost to you, and you may also withdraw a consent by writing to legal@yieldnetwork.io. Withdrawing a consent is no harder than giving it. Withdrawal does not affect the lawfulness of what we did before you withdrew it. After you withdraw, we may keep a minimal record of the withdrawal so that we do not contact you again. Where we rely on our legitimate interests, you may object at any time on grounds relating to your situation, and you may object at any time and without giving reasons to the use of your details for direct marketing, in which case we stop using them for that purpose.
4. Who we share it with
Issuers. When you register for a program, we pass the issuer the entity name and the wallet addresses you registered, so that the issuer can designate them for the program. We pass contact details only where the issuer needs them to complete your participation. We keep a record of what we pass to an issuer, to which issuer, why, and when. The issuer decides for itself how it handles what it receives, under its own privacy terms and its own know-your-customer and know-your-business procedures.
Service providers. These process personal data on our instructions and under contract. They include our website and application hosting provider, our transactional email provider, our business email and document provider, the provider that hosts our own records, the cloud provider that may support some of our pages, the platform through which we may make program documents available, and the event platform we use for event sign-ups. At the date of this notice they are, in that order, Vercel, Resend, Google Workspace, DigitalOcean, Google Cloud, DocSend and Luma. We may tell you which of them handles a particular kind of information if you ask. Where we take part in an event that someone else holds, that organiser uses its own platform, and we may receive registrant details from the organiser rather than through a provider of ours.
Verification and screening providers. Where we carry out the checks described in section 3, we may use specialist providers of identity and entity verification, of sanctions and politically exposed person screening, and of blockchain analytics. Some of them act on our instructions and some maintain their own databases and decide for themselves how they hold them. Where a provider acts on our instructions, we put in place a contract governing its processing, which is what Article 28 of the General Data Protection Regulation and of the United Kingdom General Data Protection Regulation requires where those Regulations apply. Where a provider maintains its own database and decides for itself how it holds it, it does so as a controller in its own right and under the law that applies to it; we consider its published terms before we use it, and where one of those Regulations applies to our making personal data available to it we also rely on an instrument described in section 5. Before we use a provider we consider whether a condition in Article 33 of Ley 81 de 2019, or in Article 51 of Decreto Ejecutivo 285 de 2021, applies to the transfer.
Messaging services. Where you choose to contact us on Telegram, or ask us to reach you there, Telegram carries and stores that exchange under its own terms and its own privacy policy. We do not control what Telegram does with it.
Professional advisers, auditors, authorities and courts where the law requires it, where a regulator or court requires it, or where it is necessary to establish, exercise or defend legal claims.
A successor if Yield Network is involved in a merger, acquisition, reorganisation or transfer of business, in which case this notice continues to apply to the data transferred until the successor tells you otherwise.
5. International transfers
We are established in Panama. Some of our service providers process personal data in the United States and in the European Union, so personal data you give us may cross borders in the ordinary course of our dealing with you. This section explains what that means under Panamanian law and under the General Data Protection Regulation and the United Kingdom General Data Protection Regulation, which treat the question differently. There is no European Commission adequacy decision for Panama, and no United Kingdom adequacy regulations for Panama.
Where the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to our processing, we are the exporter for that processing even though we are established in Panama, and a transfer for the purposes of Chapter V of those Regulations takes place whenever we make personal data available to a service provider, to a verification or screening provider, or to an issuer. The recipients we use for that purpose may be in the United States, in the European Economic Area, in the United Kingdom, in Panama or elsewhere. We may rely on an adequacy decision or on adequacy regulations where one covers the recipient country. Where none does, we may rely on the European Commission's Standard Contractual Clauses, on the United Kingdom's international data transfer agreement or addendum, on another instrument recognised under Article 46, or, for an occasional transfer for which no such instrument is available, on a derogation under Article 49 that fits that transfer, which we do not use for transfers that are repetitive or systematic. Before we rely on an instrument we satisfy ourselves that it is available for the recipient concerned, and we carry out any assessment that instrument requires. We may also apply supplementary technical, organisational and contractual measures where we consider them appropriate. Where we make personal data available to a service provider that processes it on our instructions, and one of those Regulations applies to that processing, we put in place the contract that Article 28 requires. Where a controller or processor established in the European Economic Area or the United Kingdom makes personal data available to us in Panama, that party is the exporter for that transfer, and we may enter into the Standard Contractual Clauses or the United Kingdom's international data transfer agreement or addendum with that party as importer.
The conditions in this paragraph apply in addition to, and not instead of, those in the paragraph above, so that where both Panamanian law and one of those Regulations apply to the same transfer we satisfy both. Where Panamanian law governs a transfer, the conditions that may make it lawful are those in Article 33 of Ley 81 de 2019 and in Article 51 of Decreto Ejecutivo 285 de 2021. For the information you give us in an access request, a registration or an enquiry, and for what we pass to an issuer so that a wallet address can be designated, we may rely on Article 33(9) of that Law and Article 51(7) of that Decree, which make a transfer lawful where it is necessary to maintain or perform the legal relationship between you and us. For our own records, for anything we send to a verification or screening provider, and for information about a person other than the person dealing with us, we may rely on Article 51(2) of that Decree, which is adequate guarantees offered and evidenced by us, and which under Article 53 of that Decree may take the form of contractual clauses agreed between us and the recipient that are sufficient to demonstrate the scope of the processing, the obligations and responsibilities each party takes on, and the rights of the persons the data is about. We may also rely on your consent under Article 33(1) of that Law and Article 51(3) of that Decree. We do not treat a destination as providing a level of protection equivalent to or higher than that Law requires unless the Autoridad Nacional de Transparencia y Acceso a la Información has determined under Article 52 of that Decree that it does. Where personal data that is confidential, sensitive or restricted and that originates or is stored in Panama receives cross-border treatment, Article 5 of that Law also applies, and we may transfer such data only where we consider that we meet, and can demonstrate that we meet, the standards of protection that Article requires. Under Article 33 of that Law, both we and the recipient are responsible for the lawfulness of the processing of the transferred data.
You can ask us which safeguard applies to a particular transfer, and for a copy of it or a summary of it, by writing to legal@yieldnetwork.io, and we may redact commercial terms from what we give you.
6. How long we keep it
Access requests and enquiries: for as long as we are in contact with you about them, and for up to 24 months after the last contact.
Program registrations and attribution records: for the life of the program, and afterwards for as long as we need them to meet our obligations to the issuer and to handle any claim, which is typically up to six years after the program closes.
Business contact records: for as long as we have an active relationship with the organisation, reviewed periodically.
Verification and screening records: for as long as a law that applies to us requires us to keep them, and otherwise for the same period as the registration or the relationship they relate to.
Event sign-ups: for as long as we are in contact with you about the event, and for up to 24 months after it.
The record of your acceptance of the Terms of Use: in your browser for no longer than twelve months, or until it is cleared or removed if sooner, and in our own records for up to six years from the acceptance, and for longer only where we need a particular record to establish, exercise or defend a legal claim.
Technical fields and form security data: no longer than 90 days, unless we need to keep a particular record for longer to establish, exercise or defend a legal claim, in which case we keep only that record and only for as long as the claim requires. Server logs: no longer than 90 days in our own systems, on the same basis, and for our hosting providers, the period set by their own retention rules.
Marketing contact details: we stop using your details for marketing as soon as you withdraw a consent, object or ask us to stop, and after that we keep only a minimal record of that fact so that we do not contact you again, together with the record of any consent you gave, for as long as we may need them. Where your details are also a business contact record, that record is kept for the period given above for business contact records and is not used for marketing. If you ask us to delete or block your details rather than simply to stop contacting you, we do that instead, and we keep only what we need in order to show that you asked and to avoid contacting you again.
Data recorded on a public blockchain: we cannot change or remove it, and it remains public indefinitely.
7. Cookies and similar technologies
We do not set cookies on the Sites to measure how the Sites are used, to build a profile of you, or for advertising. We do not use advertising cookies, we do not embed third-party advertising or cross-site tracking tags in the Sites, and we do not collect information about what you do over time and across third-party websites. Where a page on the Sites is served by, or a sign-up is handled by, a third-party platform, that platform may set its own cookies or storage under its own terms and its own privacy policy, which we do not control. Where we make a document available to you through a document platform, that platform records how the document was viewed, as section 2 describes; that happens on the platform rather than on the Sites, it is not tracking across other websites, and it is not used for advertising. Section 4 says which providers we use, and section 14 applies to the sites they operate.
We may store small amounts of information in your browser where that is strictly necessary for us to provide the Sites in the way you have asked for them, and for no other purpose. In particular, where a site asks you to accept the Terms of Use before you continue, a record that you accepted, and of which version, is stored in your browser's local storage, and the site reads it on each page so that you are not asked again. The copy of that record kept in your browser holds only the fact of acceptance, the version accepted and the time of acceptance, is readable only by the site that set it, is set to last no longer than twelve months, and may be cleared at any time through your browser settings. It may also be removed by your browser without any action by you, for example where you browse privately, where you block site storage, or where your browser reclaims storage, and if it is removed the site may ask you to accept the Terms of Use again. Section 6 says how long we may keep a record of the acceptance in our own systems.
Where we decide to keep anything else in your browser for a purpose that is not strictly necessary in that sense, we ask for your consent first, and this notice will say what it is.
What we know about general use of the Sites otherwise comes from the server request logs described in section 2.
8. Your rights
Whatever your location, you may ask us to give you access to the personal data we hold about you, to correct it, to delete it, to restrict or stop a particular use of it, to object to a use we base on our legitimate interests, to receive it in a portable form where the law provides for that, and to withdraw a consent you have given.
To exercise a right, write to legal@yieldnetwork.io. You may also send a request through any form on the Sites, and we act on a request about your own personal data whatever route it reaches us by. We do not refuse a request because of the route you chose, unless that route would put us to disproportionate cost. The restrictions in our Terms of Use on who may use the Sites do not apply to a request you make about your own personal data, and nothing in this paragraph permits any person to access the Sites or to request access to a program. Your rights under a data protection law that applies to you, and the routes by which you may exercise them, are not affected by our Terms of Use. The rights in Article 15 of Ley 81 de 2019 cannot be waived, except so far as a special law provides otherwise, and an agreement between us has no effect to the extent that it limits them. Whatever our Terms of Use say about the law that governs them, about arbitration, about the form that proceedings may take, or about time limits, they do not prevent you from making a request or a complaint to us about your personal data, they do not prevent you from complaining to the Autoridad Nacional de Transparencia y Acceso a la Información or to any other supervisory authority that is competent in your case, they do not prevent you from exercising a judicial remedy that a data protection law applying to you gives you and does not allow to be taken away by agreement, or from bringing it in a court that law allows you to bring it in, and they do not shorten any period that such a law allows you for exercising a right or making a complaint. A judicial remedy preserved in that way is preserved in respect of loss caused by the processing of your personal data, and not in respect of any loss connected with a program, with an access request or registration, or with any figure, statement or document. Subject to that, our Terms of Use apply according to their own terms to any claim you bring against us, including a claim for compensation. We may ask you for information to confirm who you are before we act, and we may ask an agent acting for you to show that you authorised them.
Your right to object. You may object at any time, on grounds relating to your particular situation, to any use of your personal data that we base on our legitimate interests. You may object at any time, and without giving any reason, to the use of your personal data for direct marketing, whether we send you messages because you gave us a consent or because we rely on our legitimate interest, and if you do we stop using your details for that purpose. Every marketing message we send brings this right to your attention and gives you a way to exercise it.
Some limits apply. We may need to keep data to meet our obligations to an issuer, to comply with the law, or to establish, exercise or defend a legal claim, and we cannot change or remove data recorded on a public blockchain.
If you consider that we have not handled your personal data as the law requires, you may complain to us. You may do so by writing to legal@yieldnetwork.io, which is the route we provide for complaints and which you may use in electronic form or in any other form you choose, or through any form on the Sites, and we will treat a complaint that reaches us by any other route as validly made. We aim to acknowledge a complaint within 30 days of receiving it and to tell you the outcome, and we may keep you informed of progress while we look into it. Where your complaint is also a request to exercise a right, the periods in section 9 or in section 10 apply to that request and nothing in this paragraph extends them. Complaining to us does not affect your right to complain to a supervisory authority or to a remedy in court. You may complain to the Autoridad Nacional de Transparencia y Acceso a la Información in Panama, which supervises us, and, where a data protection law of another country applies to you, to the supervisory authority under that law.
9. Panama
We are established in Panama, and Ley 81 de 2019 applies to our processing under Article 5 of that Law because we are domiciled in Panama. That is so whatever law governs our Terms of Use or any other agreement between you and us.
Your rights under Article 15 of that Law are access, rectification, cancellation, opposition and portability, and the right of opposition includes the right to revoke a consent you have given. Those rights cannot be waived. A request to modify your data may ask us to correct it, to delete it or to block it. Where we process your personal data on a basis in Article 8 of that Law, you may at any time ask us to modify, delete or block it, and your access to that data is free of charge. You may also ask us to delete personal data where its storage has no legal basis, where it was not expressly authorised, or where it is out of date. Where you ask us to supply, modify, block or delete data, you may ask us for a record of the updated database so far as it concerns you, and we do not charge for any of this.
We answer a request for access or for information within 10 business days, and we modify, block or delete personal data within 5 business days of a request to do so, in each case free of charge. If we do not answer you in time, you may take the matter to the Autoridad Nacional de Transparencia y Acceso a la Información.
10. The European Economic Area and the United Kingdom
This section applies if the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to our processing of your personal data.
Your rights are those the Regulation that applies to you gives you: access to your personal data and the information in this notice, rectification, erasure, restriction of processing, data portability, objection, and the rights that apply where a decision that produces a legal effect for you or similarly significantly affects you is taken about you by automated means. Where we take a decision of that kind about you, a person is meaningfully involved in taking it, as section 3 describes, and where a check returns information falling within a special category we do not take a decision of that kind about you by automated means at all. You may object at any time, on grounds relating to your situation, to processing we base on our legitimate interests, and you may object at any time, without giving reasons, to the use of your personal data for direct marketing, in which case we stop using it for that purpose. Where we rely on consent you may withdraw it at any time, and withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
We answer within one month of receiving a request. Where a request is complex, or where you have made several requests, we may extend that period by up to two further months and will tell you within the first month that we have done so and why. Where we reasonably need information to confirm who you are, or need you to clarify what you are asking for, the period may not begin or may not run until you give us what we have asked for. The periods in section 9 apply to a request made under the law of Panama; where a request is made under the General Data Protection Regulation or the United Kingdom General Data Protection Regulation, the periods in this section apply, and we may answer sooner.
The legal basis for each purpose is set out in section 3, together with the legitimate interests we rely on where the basis is Article 6(1)(f). Section 5 sets out the safeguards for transfers outside the EEA and the United Kingdom.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State or country of your habitual residence, your place of work, or the place where you consider the problem arose. You may also complain to us, as section 8 describes, and complaining to us does not affect your right to complain to a supervisory authority or to a remedy in court.
11. California
This section gives the disclosures the California Consumer Privacy Act calls for. The Sites are not available to persons in the United States and we do not consider that the Act applies to us. This section is provided so that those disclosures are available in any event. It is not an admission that the Act applies, that we do business in California, or that any person in the United States may use the Sites, and it is not an undertaking to grant any right or to handle any request that the Act does not require us to handle. Where the Act requires us to respond, we respond within the period it allows.
What we collect, and why. In the twelve months before the date of this notice, the categories of personal information we have collected are identifiers, such as a name, an entity name, an email address, a messaging handle, a wallet address and, in our hosting providers' server logs, an internet protocol address; the categories of information described in subdivision (e) of section 1798.80, such as information and documents about the source of funds or digital assets; commercial information, such as an expected ticket size and a record of the programs an organisation has taken part in; internet or other electronic network activity information, such as server log data; professional or employment-related information, such as a role and an entity type; and sensitive personal information, being a government-issued identifier or an identity document where we ask for verification information. We do not collect biometric information, precise geolocation, education information, audio or visual information, or inferences drawn to create a profile about you. Section 2 says where each category comes from, section 3 says why we use it, and section 6 says how long we keep each kind of record, which is how we determine the retention period for each category.
Disclosure. We disclose the categories of personal information described above for business purposes to the recipients described in section 4, namely issuers, our service providers, our professional advisers, authorities and courts, and a successor to our business. We do not disclose personal information to a third party for a purpose other than a business purpose.
We do not sell and we do not share. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the Act, including in respect of any person we know to be under 16. Information we may pass to an issuer is not passed in exchange for any payment or other consideration for that information. Because we neither sell nor share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link, and an opt-out preference signal sent by your browser has nothing to act on.
Sensitive personal information. Where we ask for verification information, it may include a government-issued identifier or an identity document. We collect and use that information only to verify who you are and who you act for, to meet a legal obligation, and for the security and fraud-prevention purposes the Act permits. We do not collect or process personal information for the purpose of inferring characteristics about you, and we do not use or disclose sensitive personal information for any purpose that would give rise to a right to limit its use under the Act. We do not sell or share it. We therefore do not offer a "Limit the Use of My Sensitive Personal Information" link.
Tracking signals and third-party marketing. This paragraph is given under California laws other than the Act, and applies whether or not the Act applies to us. We do not collect information about what you do over time and across third-party websites, so a "Do Not Track" signal sent by your browser has nothing to act on. Section 7 sets out what the Sites allow others to collect. California Civil Code section 1798.83 applies to a business that has an established business relationship with a customer, meaning an individual California resident whose relationship with the business is primarily for personal, family or household purposes. The Sites are for professional and institutional users and we do not have customers of that kind. We do not disclose personal information to third parties for those third parties' own direct marketing. If you consider that section 1798.83 applies to you, write to legal@yieldnetwork.io.
Your rights. If the Act applies to us and you are a California resident, you may ask us to know the categories and the specific pieces of personal information we have collected about you, the categories of sources, the purposes, and the categories of recipients; to delete personal information we have collected from you, subject to the exceptions the Act allows; to correct inaccurate personal information; to opt out of the sale or sharing of personal information, which we do not carry on; and to limit the use of sensitive personal information, which does not arise here. We will not discriminate against you for exercising any of these rights.
How to make a request. Write to legal@yieldnetwork.io. We operate exclusively online. Where we have collected personal information directly from you in the course of your dealing with us online, an email address is the designated method for submitting a request to know, to delete or to correct, and that address is legal@yieldnetwork.io. Where we hold personal information about you that we did not collect from you directly, you may use the same address and we will handle your request on the same basis, and you may also ask us for another way to reach us. You may also send a request through any form on the Sites, and we may act on a request about your own personal information whatever route it reaches us by. The restrictions in our Terms of Use on who may use the Sites do not apply to a request you make about your own personal information, and nothing in this paragraph permits any person to access the Sites or to request access to a program. You may use an authorised agent, who must show that you authorised them to act. To verify a request we match the details you give us against what we already hold, such as the email address or entity name used when the information was submitted, and we may ask you for further information where the request is for specific pieces of personal information. We respond within 45 days of receiving a request, which may be extended once by a further 45 days where reasonably necessary, in which case we will tell you and say why. A request to know may cover the twelve months before the request. It may also reach back to 1 January 2022, unless doing so is impossible or would involve a disproportionate effort.
12. Security and breaches
We protect personal data with access controls on a need-to-know basis, encryption in transit, hosting in professionally managed data centres, and internal rules on who may see what. No system is perfectly secure, and information you send over the internet or record on a public blockchain carries risks we cannot remove.
If there is a breach of security affecting personal data we hold about you, we notify you and the Autoridad Nacional de Transparencia y Acceso a la Información as soon as possible, and within 72 hours of our becoming aware of the incident where Decreto Ejecutivo 285 de 2021 requires it. Where another data protection law applies to us we also notify within the periods that law sets. We tell you, in plain language, the nature of the incident, the personal data involved, what we did about it immediately, what you may wish to do to protect your interests, and how to get more information. Where a law prevents us from telling you, we tell you as soon as we are permitted to.
13. Children
The Sites are intended for professional and institutional users and are not intended for anyone under 18. We do not knowingly collect personal data from a person under 18. If you believe a person under 18 has given us personal data, write to legal@yieldnetwork.io and we will delete it unless a law that applies to us requires us to keep it.
14. Links to other sites
The Sites link to issuers' sites, vault interfaces, block explorers and other third parties. Their privacy practices are their own and this notice does not cover them. Read their notices before you give them any information.
15. Changes to this notice
We publish any change to this notice on this page and update the date at the top. Where a change materially affects how we use personal data you have already given us, we tell you directly where we have a way to reach you.
16. Contact
YieldNet Labs Inc., trading as Yield Network. Email: legal@yieldnetwork.io.