TrustDAGBlockchain 3.0

Privacy Policy

Privacy Policy

TrustDAG does not collect personal or private information to access, use, read, or operate the TrustDAG Layer 1 blockchain ecosystem.

Privacy Policy TrustDAG Technologies Foundation #1811582-6 Canadian Not-for-Profit organization Version 2.3 Effective date for review: July 31, 2026

This Privacy Policy is written for visitors, donors, investors, operators, developers, regulators, auditors, partners, and media. It explains the TrustDAG privacy model in plain language. The central rule is simple: TrustDAG does not collect personal or private information to access, use, read, or operate the TrustDAG Layer 1 blockchain ecosystem.

The TrustDAG blockchain, backend, Explorer, Fair Trust System, DAO, DDRS, staking, launchpads, faucet, operator systems, governance tools, and hardcoded protocol features operate without raw personal or private information. Personal identity records, identity documents, biometric files, KYC files, KYB files, raw AML files, and raw PEP screening files are managed by selected third-party verification providers outside the TrustDAG ecosystem.

1. Core privacy position

TrustDAG does not collect personal or private information from visitors or users for access to the public website or for use of the TrustDAG ecosystem. The blockchain and its hardcoded features do not require raw personal identity information, and the backend does not receive raw personal identity information.

The only normal situation where a person, business, regulator, auditor, partner, donor, operator, developer, media contact, or other visitor provides personal information directly to TrustDAG is voluntary email contact. In that situation, the sender chooses what to include in the message. Email content stays off-chain and outside the TrustDAG ecosystem.

Voluntary contact information sent by email is used only for the context in which it was provided. It is kept only for the period needed to answer, document, or complete that specific context. During that period, TrustDAG keeps the data in a secured offline database. The information does not enter the blockchain, the backend ecosystem, the Fair Trust System, the Explorer, DAO, DDRS, staking, launchpads, faucet, operator systems, or any hardcoded protocol feature.

2. Scope of this policy

This policy applies to the public TrustDAG website, public communications with TrustDAG, and the TrustDAG ecosystem design. It covers the privacy position for website visitors, voluntary email contacts, and participants interacting with TrustDAG features through public or verified access paths.

This policy also explains how TrustDAG handles derived verification outcomes received from selected third-party verification providers. Those outcomes are not raw personal identity files. They are limited signals used to support verified access, abuse prevention, and the Fair Trust System without bringing personal identity records into the TrustDAG ecosystem.

3. TrustDAG ecosystem features do not collect personal or private information

The following TrustDAG features are designed to operate without collecting, processing, storing, or exposing raw personal or private information: TrustDAG blockchain and hardcoded protocol rules, backend services, Explorer, Fair Trust System, DAO, DDRS, staking, operators, launchpads, faucet, Coins Supply and Economy rules, public website sections, and public documentation.

These features use public, aggregate, cryptographic, root-bound, behavioral, or derived status information. They do not use raw legal identity records, identity documents, biometric files, home addresses, government identification numbers, KYC files, KYB files, raw AML files, raw PEP screening files, or third-party provider raw payloads.

4. Backend privacy rule

TrustDAG backend services follow the same privacy rule as the blockchain. The backend does not request, collect, store, or manage raw personal or private information. It receives only limited derived information from selected third-party verification providers when verified access is involved.

The backend security system verifies that incoming verification messages originate from the selected third-party provider before using those messages. This authentication layer protects the ecosystem against forged messages, impersonation attempts, and hacker attacks against the verification flow.

A provider message sent to the backend is limited to operational verification information such as a provider user reference, verification status, eligibility result, restricted-region status, compliance status, wallet-binding authorization, timestamped outcome, PEP screening outcome where applicable, and provider-authenticated attestation. These values support safe access without moving personal identity records into TrustDAG.

5. Third-party verification providers and PEP screening

Selected third-party verification providers handle and manage personal identity information when identity verification is required. Identity documents, biometric checks, business documents, KYC files, KYB files, AML materials, PEP screening materials, and source databases remain with the selected provider. TrustDAG does not receive those raw materials.

PEP screening means screening related to politically exposed persons, heads of international organizations, and related or closely associated persons where applicable under the provider process and applicable law. A PEP status by itself is not a statement of wrongdoing. It is a compliance-screening category that can require additional review, risk treatment, or eligibility decisioning.

The provider sends TrustDAG a limited result, not the underlying personal file. The result supports verified ecosystem access, permanent Fair Trust System identity creation authorization, wallet-binding authorization, restricted-region screening, PEP screening outcome where applicable, and compliance status checks.

6. Fair Trust System

FTS means Fair Trust System. It is composed of a main score and sub-scores. The Fair Trust System is designed to help protect the TrustDAG ecosystem and its participants without using raw personal or private information.

The Fair Trust System works from a permanent TrustDAG identity reference, verified-access status, wallet-binding status, provider-authenticated verification outcomes, and network behavior events. It does not use legal names, addresses, government ID documents, biometric data, KYC files, KYB files, raw AML files, raw PEP files, or private contact details.

Public FTS information is limited to safe public views such as score and sub-scores, rankings, aggregate metrics, and public trust-status context. Hidden formulas, abuse thresholds, raw evidence, and provider payloads stay private and outside public views.

7. Voluntary email contact

A visitor or organization can voluntarily contact TrustDAG by email. Examples include support questions, privacy questions, security reports, partnership inquiries, media requests, career inquiries, donor questions, operator interest, developer questions, legal requests, and regulator or auditor communications.

When someone contacts TrustDAG by email, the sender controls the content. The message can include a name, business name, email address, phone number, role, organization, documents, or other details chosen by the sender. TrustDAG treats that information as voluntary contact information provided for the specific context of the message.

Voluntary email information is not used by the blockchain or by ecosystem features. It does not become part of chain state, transaction state, Fair Trust System score, DAO record, DDRS record, staking record, operator record, launchpad record, faucet record, or public Explorer record.

8. Use, retention, and offline storage

TrustDAG uses voluntary email information only for the purpose connected to the message. TrustDAG does not sell, rent, trade, broker, or advertise with voluntary email information. TrustDAG does not use voluntary email information to build advertising profiles or for third-party behavioral advertising.

Voluntary email information is kept only for the duration needed in the context for which it was provided. During that period, TrustDAG keeps the data in a secured offline database. Offline storage reduces exposure to internet-facing attacks and keeps voluntary contact records separated from blockchain systems, backend ecosystem systems, Explorer systems, and public website features.

9. Website access and public pages

Public TrustDAG website pages are designed for open public reading. Reading the website does not require personal or private information. Public pages do not require visitors to submit identity documents, personal profile details, biometric data, or KYC/KYB records to TrustDAG.

TrustDAG does not use public website visits to create personal identity profiles. TrustDAG does not use public website visits to feed the Fair Trust System, DAO, DDRS, staking, operator systems, launchpads, faucet, or any chain-level feature.

10. Cookies, analytics, and tracking

TrustDAG public website pages are designed without personal tracking for ecosystem access. TrustDAG does not use website cookies to build personal identity profiles, does not use cookies to feed the Fair Trust System, and does not use cookies to grant or deny blockchain access.

If TrustDAG later adds analytics, consent tools, or optional website features that involve personal information, this policy will be updated before those features are used. The update will explain the exact information involved, the purpose, the retention period, and the available choices.

11. No sale or sharing of personal information

TrustDAG does not sell personal information. TrustDAG does not rent personal information. TrustDAG does not trade personal information. TrustDAG does not share personal information for cross-context behavioral advertising.

Voluntary email information is disclosed only in narrow circumstances connected to the original context, such as a response to the sender, legal counsel review, security investigation, regulator or law-enforcement request, service provider support for offline record security, or another lawful situation directly connected to the specific communication.

12. Security safeguards and post-quantum design

TrustDAG separates voluntary email records from chain systems and ecosystem systems. This separation is a core safeguard. Voluntary contact information does not enter blockchain state, Explorer state, Fair Trust System state, DAO state, DDRS state, staking state, operator state, launchpad state, faucet state, or public website feature state.

TrustDAG is also designed to align critical security paths with NIST-standardized post-quantum cryptography where those controls are implemented. ML-KEM-1024 protects communication paths that require post-quantum key establishment. ML-DSA-87 protects high-value signing workflows, including DAO voting and Treasury multisig voting where post-quantum digital signatures are required. SLH-DSA acts as a stateless hash-based fallback signing family.

This security design does not convert personal information into chain data. It protects communications and signing workflows while preserving the zero-collection ecosystem model.

13. Rights and privacy requests

A person who voluntarily sent personal information to TrustDAG by email can contact the Privacy-Laws Officer to request access, correction, deletion, or information about how the message was handled. TrustDAG reviews each request according to the context, the identity of the requester, applicable law, legal record needs, security needs, and the nature of the record.

Requests can relate only to information actually held by TrustDAG. TrustDAG does not hold raw identity files managed by selected third-party verification providers. Requests about provider-held identity files are handled through the provider process and the provider privacy notice.

14. Quebec, Canada, and United States privacy context

TrustDAG Technologies Foundation is a Canadian Not-for-Profit organization. This policy is designed for visitors and contacts in Quebec, Canada, the United States, the United Kingdom, and other jurisdictions where TrustDAG communications are received.

For Quebec and Canadian privacy expectations, this policy explains what information is collected, the purpose, retention, safeguards, contact rights, and the person responsible for privacy questions. TrustDAG also applies the principle of limiting voluntary contact information to the context for which it was provided.

For United States visitors, including California residents where applicable, TrustDAG provides a practical request channel for access, correction, deletion, and questions about voluntary email information held by TrustDAG. TrustDAG does not sell personal information and does not share personal information for behavioral advertising.

15. European Union and EEA privacy context

For visitors and contacts in the European Union or European Economic Area, this policy supports the transparency principles used under GDPR. TrustDAG identifies the organization responsible for this policy, provides contact information for privacy requests, describes the categories of information handled, explains the purpose of each handling context, and describes retention, safeguards, and request channels.

For voluntary email contact, the handling context is based on the sender choosing to contact TrustDAG, TrustDAG responding to that contact, TrustDAG protecting its legal and security interests, and TrustDAG keeping records where a lawful obligation or legitimate accountability need applies.

EU and EEA contacts can request access, correction, deletion, restriction, objection, portability, and information about automated decision-making where those rights apply to information actually held by TrustDAG Technologies Foundation. Provider-held identity information is handled through the provider process and provider privacy notice.

16. United Kingdom privacy context

For United Kingdom visitors and contacts, this policy supports transparency under the UK GDPR and the Data Protection Act 2018.

TrustDAG identifies the organization responsible for this policy, explains the limited voluntary email-contact context, describes the purpose of that contact handling, describes retention and offline safeguards, and provides a privacy request channel.

United Kingdom contacts can request information about voluntary email information actually held by TrustDAG Technologies Foundation, request access, correction, deletion, restriction, objection, portability where applicable, and information about automated decision-making where those rights apply. Provider-held identity information is handled through the selected provider process and provider privacy notice.

TrustDAG does not use voluntary email information for the blockchain, backend ecosystem, Explorer, Fair Trust System, DAO, DDRS, staking, operators, launchpads, faucet, or any hardcoded protocol feature. 17. Singapore privacy context

For Singapore contacts, this policy reflects purpose explanation, consent through voluntary contact, limited use, access and correction channels, retention limits, safeguards, and accountability.

A Singapore contact can request access to voluntary email information held by TrustDAG Technologies Foundation, request correction of that information, or withdraw future consent for continued handling of voluntary contact information. TrustDAG handles each request according to the contact context, security needs, legal record needs, and information actually held by TrustDAG.

18. Philippines privacy context

For Philippines contacts, this policy reflects transparency, legitimate purpose, proportionality, security, rights handling, and a contact point for requests.

A Philippines contact can ask to be informed about voluntary email information held by TrustDAG Technologies Foundation, request access, request correction, object to continued handling, request deletion or blocking where the request applies, and raise a concern through the privacy contact listed below.

19. Children and minors

TrustDAG services are not directed to children. Children and minors are not the intended senders of personal information to TrustDAG by email. A parent, guardian, or legally authorized representative can contact TrustDAG if a minor sent personal information voluntarily by email and a privacy request is needed.

20. Changes to this policy

This policy is updated when TrustDAG changes its public privacy model, contact practices, verification provider flow, website features, or legal requirements. A revised version replaces the prior version on the TrustDAG website.

Any future feature that changes the zero-collection ecosystem model will be described before activation. TrustDAG will not quietly convert personal or private information into chain data, backend ecosystem data, Fair Trust System data, Explorer data, DAO data, DDRS data, staking data, operator data, launchpad data, or faucet data.

21. Contact channels

General contact: contact@trustdag.com Support: support@trustdag.com Security reports: security@trustdag.com Privacy questions and privacy requests are handled by the Privacy-Laws Officer listed below.

Privacy-Laws Officer Shela Habay privacy@trustdag.com

This officer information is provided only for privacy questions and privacy requests related to TrustDAG Technologies Foundation.