โš ๏ธ Testnet only โ€” TRITO tokens have no real monetary value. Not financial advice.
Legal

Privacy Policy

Last updated: June 22, 2026ยทJordan Pobienski (Data Controller)ยทGDPR Compliant

1. Introduction

Jordan Pobienski, operator of the TRITO platform ("we", "us", "our"), is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the TRITO Token platform at tritotoken.eu.

This policy is designed to comply with the General Data Protection Regulation (GDPR) and applicable Bulgarian data protection laws.

2. Data Controller

Data Controller

Jordan Pobienski, operator of the TRITO platform

Sofia, Bulgaria

Contact for privacy matters: mr.pobienski@gmail.com

Note: A formal Data Protection Officer (DPO) has not been appointed as one is not required for this project under GDPR Article 37.

3. Data We Collect

3.1 Account Data (Required)

  • ๐Ÿ“‹

    Email address

    Account creation and authentication

  • ๐Ÿ“‹

    Display name / nickname

    Community identification

  • ๐Ÿ“‹

    Account creation date

    Eligibility verification

  • ๐Ÿ“‹

    Email verification status

    Security and eligibility

  • ๐Ÿ“‹

    Password hash

    Authentication (never stored in plain text)

3.2 Blockchain Data (Optional โ€” provided by user)

  • ๐Ÿ”—

    Ethereum wallet address

    Token gifts, staking, and reward distribution

  • ๐Ÿ”—

    Cryptographic wallet signature

    Proof of wallet ownership (no private keys collected)

  • ๐Ÿ”—

    On-chain activity reference

    CeR rank calculation and airdrop eligibility

3.3 Activity Data (Automatic)

  • ๐Ÿ“Š

    Airdrop points and activity

    Airdrop reward calculation

  • ๐Ÿ“Š

    Referral records

    Referral reward distribution

  • ๐Ÿ“Š

    Login timestamps

    Security monitoring

  • ๐Ÿ“Š

    Browser type and device info

    Platform optimization via Firebase Analytics (anonymized)

  • ๐Ÿ“Š

    IP address and request logs

    Security, fraud prevention (processed by Vercel as hosting provider)

4. How We Use Your Data

  • โœ“Account creation and authentication
  • โœ“Verifying eligibility for airdrop and registration gift
  • โœ“Calculating and distributing staking rewards
  • โœ“Computing CeR ranks and airdrop points
  • โœ“Processing referral rewards
  • โœ“Sending essential account notifications (security alerts, gift claims)
  • โœ“Preventing fraud, sybil attacks, and platform abuse
  • โœ“Improving platform performance and user experience
  • โœ“We do not send marketing emails without your explicit consent

5. Lawful Basis for Processing

PurposeLegal Basis
Account creation and authenticationContract performance
Airdrop and gift eligibility verificationContract performance
Reward calculation and distributionContract performance
Fraud prevention and securityLegitimate interests
Platform analytics and improvementLegitimate interests
Marketing communicationsConsent (opt-in only)
Legal complianceLegal obligation

6. Data Storage & Security

Your account data is stored using Google Firebase (Firestore and Authentication). Firebase provides contractual and technical measures intended to support GDPR compliance.

Storage provider

Google Firebase / Cloud Firestore

Data location

EU region (where available)

Encryption

AES-256 at rest, TLS in transit

Hosting

Vercel (may process technical data such as IP addresses and request logs to deliver the service)

7. Data Retention

Personal data is retained while your account remains active. Upon account deletion, personal data is removed from our systems. However, some records may be retained for a limited period thereafter where necessary for:

  • โ€ขSecurity and fraud prevention
  • โ€ขDispute resolution
  • โ€ขLegal compliance obligations
  • โ€ขProtection of legitimate interests

Please note that wallet addresses, transactions, and other data already recorded on public blockchains cannot be deleted as blockchain data is immutable by design.

8. Data Sharing & International Transfers

We do NOT sell your personal data. We share data only with:

  • โ–ธGoogle Firebase โ€” authentication and database provider (US company, EU data processing agreement in place)
  • โ–ธVercel โ€” hosting provider, may process technical information such as IP addresses and request logs (US company, Standard Contractual Clauses apply)
  • โ–ธEthereum blockchain โ€” wallet addresses and transaction data are public by blockchain design
  • โ–ธLegal authorities โ€” only when required by applicable law

Some service providers may process data outside the European Economic Area. Where this occurs, appropriate safeguards such as Standard Contractual Clauses (SCCs) are used.

9. Your Rights (GDPR)

As a data subject you have the following rights:

Right of Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your account and personal data

Right to Portability

Export your data in a machine-readable format (JSON)

Right to Object

Object to processing based on legitimate interests

Right to Restrict

Restrict processing of your personal data

To exercise any of these rights, contact us at mr.pobienski@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), Republic of Bulgaria, at cpdp.bg.

11. Automated Processing

Certain rewards, rankings, eligibility determinations, and anti-abuse measures are processed automatically based on platform activity and blockchain data. This includes CeR rank calculation, airdrop point scoring, and referral qualification checks.

No decisions producing legal or similarly significant effects are made solely by automated means without the possibility of human review.

12. Cookies

We use essential cookies for authentication and optional analytics cookies to improve the platform. See our Cookie Policy for full details. We use Firebase Analytics to understand platform usage and improve performance.

13. Blockchain Data

When you connect a wallet or perform on-chain transactions, certain data becomes permanently public on the Ethereum blockchain:

  • โš ๏ธYour wallet address is publicly visible on-chain
  • โš ๏ธAll token transactions are permanently recorded
  • โš ๏ธStaking activity and rewards are publicly visible
  • โš ๏ธThis data cannot be deleted โ€” it is immutable by blockchain design

While we can delete wallet addresses stored in our systems upon request, we cannot remove wallet addresses, transactions, or other information already recorded on public blockchains.

14. Wallet Verification

Wallet ownership is verified through a cryptographic signature request. This proves you control the wallet address without revealing your private key. No private keys are ever collected or stored by the platform.

15. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will comply with applicable GDPR notification obligations, including notifying the relevant supervisory authority within 72 hours where required, and notifying affected users where appropriate.

16. Children's Privacy

The TRITO Token platform is not directed at children under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at mr.pobienski@gmail.com and we will take steps to delete such information.

17. Changes to Policy

We may update this Privacy Policy from time to time. We will notify registered users of significant changes by email. The "Last updated" date at the top of this page will always reflect the most recent version.

18. Contact

Privacy Contact

Jordan Pobienski (Data Controller)

Sofia, Bulgaria

Email: mr.pobienski@gmail.com

Website: tritotoken.eu

Supervisory Authority: Commission for Personal Data Protection (CPDP), Republic of Bulgaria โ€” cpdp.bg