GDPR Compliance
usmewe is committed to protecting user privacy and complying with the General Data Protection Regulation (GDPR).Overview
usmewe processes minimal personal data. Most protocol data is on-chain and pseudonymous.
Data We Collect
On-Chain Data (Public)
| Data | Purpose | Storage |
|---|---|---|
| Wallet addresses | Protocol operation | BASE blockchain |
| Transaction history | Protocol operation | BASE blockchain |
| Trust Score | Protocol operation | BASE blockchain |
| Loan records | Protocol operation | BASE blockchain |
On-chain data is pseudonymous. We don’t link wallet addresses to real identities unless you provide that information.
Off-Chain Data
| Data | Purpose | Storage | Retention |
|---|---|---|---|
| Email address | Notifications | Supabase | Until deletion |
| Profile name | Social features | Supabase | Until deletion |
| Device tokens | Push notifications | Supabase | Until deletion |
| IP address | Security, abuse prevention | Logs | 30 days |
| Usage analytics | Product improvement | Plausible | Anonymized |
Your Rights
Under GDPR, you have the following rights:Access
Request a copy of your personal data
Rectification
Correct inaccurate personal data
Erasure
Request deletion of your data
Portability
Export your data in a readable format
Restriction
Limit how we process your data
Objection
Object to certain processing
Exercising Your Rights
Data Export
Export your off-chain data:- Profile information
- Notification preferences
- Activity history (off-chain)
Account Deletion
Request account deletion:- Go to Settings > Privacy > Delete Account
- Confirm your decision
- We’ll process within 30 days
Data Correction
Update your information:Legal Basis for Processing
| Processing | Legal Basis |
|---|---|
| Protocol operation | Contract performance |
| Security measures | Legitimate interest |
| Email notifications | Consent |
| Analytics | Legitimate interest |
| Marketing | Consent |
Data Protection Measures
Encryption
Encryption
- TLS 1.3 for all connections
- AES-256 encryption at rest
- End-to-end encryption for sensitive data
Access Control
Access Control
- Role-based access control
- Principle of least privilege
- Regular access audits
Data Minimization
Data Minimization
- Collect only necessary data
- Automatic deletion after retention period
- Anonymization where possible
Security Testing
Security Testing
- Regular penetration testing
- Bug bounty program
- Continuous monitoring
International Transfers
Data may be transferred to:| Region | Safeguard |
|---|---|
| United States | Standard Contractual Clauses |
| EU | No transfer needed |
Data Processors
We use the following third-party processors:| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, auth | USA (EU available) |
| Railway | Hosting | USA |
| Plausible | Analytics | EU |
Cookies
usmewe uses minimal cookies:| Cookie | Purpose | Duration | Type |
|---|---|---|---|
session | Authentication | Session | Essential |
preferences | User settings | 1 year | Functional |
We don’t use tracking or advertising cookies.
Governance and Privacy
Governance proposals affecting user data must:- Include privacy impact assessment
- Pass with 60% majority (higher threshold)
- Allow 30-day opt-out period
Data Breach Notification
In case of a data breach:- We’ll notify affected users within 72 hours
- Report to relevant supervisory authorities
- Document the incident and remediation
Contact
For GDPR-related inquiries:- Email: [email protected]
- DPO: [email protected]
- Address: [Company Address]
Updates to This Policy
We may update this policy. Significant changes will be:- Announced via email
- Posted in-app
- Subject to 30-day notice period
Privacy Policy
Full privacy policy