Privacy Policy
Contents
1. Introduction
Jordan Pobienski, operator of the TRITO platform ("we", "us", "our"), is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the TRITO Token platform at tritotoken.eu.
This policy is designed to comply with the General Data Protection Regulation (GDPR) and applicable Bulgarian data protection laws.
2. Data Controller
Data Controller
Jordan Pobienski, operator of the TRITO platform
Sofia, Bulgaria
Contact for privacy matters: mr.pobienski@gmail.com
Note: A formal Data Protection Officer (DPO) has not been appointed as one is not required for this project under GDPR Article 37.
3. Data We Collect
3.1 Account Data (Required)
- ๐
Email address
Account creation and authentication
- ๐
Display name / nickname
Community identification
- ๐
Account creation date
Eligibility verification
- ๐
Email verification status
Security and eligibility
- ๐
Password hash
Authentication (never stored in plain text)
3.2 Blockchain Data (Optional โ provided by user)
- ๐
Ethereum wallet address
Token gifts, staking, and reward distribution
- ๐
Cryptographic wallet signature
Proof of wallet ownership (no private keys collected)
- ๐
On-chain activity reference
CeR rank calculation and airdrop eligibility
3.3 Activity Data (Automatic)
- ๐
Airdrop points and activity
Airdrop reward calculation
- ๐
Referral records
Referral reward distribution
- ๐
Login timestamps
Security monitoring
- ๐
Browser type and device info
Platform optimization via Firebase Analytics (anonymized)
- ๐
IP address and request logs
Security, fraud prevention (processed by Vercel as hosting provider)
4. How We Use Your Data
- โAccount creation and authentication
- โVerifying eligibility for airdrop and registration gift
- โCalculating and distributing staking rewards
- โComputing CeR ranks and airdrop points
- โProcessing referral rewards
- โSending essential account notifications (security alerts, gift claims)
- โPreventing fraud, sybil attacks, and platform abuse
- โImproving platform performance and user experience
- โWe do not send marketing emails without your explicit consent
5. Lawful Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance |
| Airdrop and gift eligibility verification | Contract performance |
| Reward calculation and distribution | Contract performance |
| Fraud prevention and security | Legitimate interests |
| Platform analytics and improvement | Legitimate interests |
| Marketing communications | Consent (opt-in only) |
| Legal compliance | Legal obligation |
6. Data Storage & Security
Your account data is stored using Google Firebase (Firestore and Authentication). Firebase provides contractual and technical measures intended to support GDPR compliance.
Storage provider
Google Firebase / Cloud Firestore
Data location
EU region (where available)
Encryption
AES-256 at rest, TLS in transit
Hosting
Vercel (may process technical data such as IP addresses and request logs to deliver the service)
7. Data Retention
Personal data is retained while your account remains active. Upon account deletion, personal data is removed from our systems. However, some records may be retained for a limited period thereafter where necessary for:
- โขSecurity and fraud prevention
- โขDispute resolution
- โขLegal compliance obligations
- โขProtection of legitimate interests
Please note that wallet addresses, transactions, and other data already recorded on public blockchains cannot be deleted as blockchain data is immutable by design.
9. Your Rights (GDPR)
As a data subject you have the following rights:
Right of Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Request deletion of your account and personal data
Right to Portability
Export your data in a machine-readable format (JSON)
Right to Object
Object to processing based on legitimate interests
Right to Restrict
Restrict processing of your personal data
To exercise any of these rights, contact us at mr.pobienski@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), Republic of Bulgaria, at cpdp.bg.
10. Withdrawing Consent
Where processing is based on your consent (such as marketing communications), you may withdraw consent at any time by contacting us at mr.pobienski@gmail.com or through your account settings. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
11. Automated Processing
Certain rewards, rankings, eligibility determinations, and anti-abuse measures are processed automatically based on platform activity and blockchain data. This includes CeR rank calculation, airdrop point scoring, and referral qualification checks.
No decisions producing legal or similarly significant effects are made solely by automated means without the possibility of human review.
13. Blockchain Data
When you connect a wallet or perform on-chain transactions, certain data becomes permanently public on the Ethereum blockchain:
- โ ๏ธYour wallet address is publicly visible on-chain
- โ ๏ธAll token transactions are permanently recorded
- โ ๏ธStaking activity and rewards are publicly visible
- โ ๏ธThis data cannot be deleted โ it is immutable by blockchain design
While we can delete wallet addresses stored in our systems upon request, we cannot remove wallet addresses, transactions, or other information already recorded on public blockchains.
14. Wallet Verification
Wallet ownership is verified through a cryptographic signature request. This proves you control the wallet address without revealing your private key. No private keys are ever collected or stored by the platform.
15. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will comply with applicable GDPR notification obligations, including notifying the relevant supervisory authority within 72 hours where required, and notifying affected users where appropriate.
16. Children's Privacy
The TRITO Token platform is not directed at children under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at mr.pobienski@gmail.com and we will take steps to delete such information.
17. Changes to Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes by email. The "Last updated" date at the top of this page will always reflect the most recent version.
18. Contact
Privacy Contact
Jordan Pobienski (Data Controller)
Sofia, Bulgaria
Email: mr.pobienski@gmail.com
Website: tritotoken.eu
Supervisory Authority: Commission for Personal Data Protection (CPDP), Republic of Bulgaria โ cpdp.bg