Privacy Policy
Introduction
PrövenantX ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
Information We Collect
We collect information that you provide directly to us, including:
- Email address and name when you join our waitlist
- Communication preferences and consent records
- Technical information such as IP address, browser type, and device information
- Usage data and analytics through cookies and similar technologies
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Send you updates about PrövenantX and early access opportunities
- Respond to your inquiries and provide customer support
- Analyze usage patterns and optimize user experience
- Comply with legal obligations and protect our rights
Privacy in Our Blockchain Ecosystem
PrövenantX leverages Ethereum's ERC-1155 standard for immutable provenance wrappers, but we prioritize user privacy through advanced cryptographic tools:
Zero-Knowledge Proofs (ZKPs)
We integrate ZKPs (e.g., via libraries like zk-SNARKs) to enable verification of share ownership and transaction history without disclosing underlying personal data, such as wallet details or VIP identities. This ensures compliance with "data minimization" principles—you prove what you know without revealing how.
Hybrid Ledgers
For sensitive operations (e.g., custody syncing or accredited investor checks), we use permissioned or hybrid ledger models (public Ethereum for transparency + private sidechains for restricted access). This prevents full exposure on public blockchains while maintaining auditability.
On-chain data is pseudonymized (e.g., wallet addresses only), and we never store full KYC info on-chain. Off-chain, all data is encrypted (AES-256) and access-logged. For more on ZKPs in Web3 privacy, see resources from Hiro Systems.
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
Your Rights
You have the right to access, correct, or delete your personal information. You may also opt out of marketing communications at any time by contacting us at info@provenantx.com.
CCPA/CPRA Compliance (California Residents)
As a "business" under the California Consumer Privacy Act (CCPA) as amended by CPRA, we do not "sell" or "share" personal information (as defined) but may disclose it to service providers (e.g., Ethereum nodes, custodians). In the past 12 months, we collected: emails (for waitlists), IP addresses (analytics), and wallet hashes (pseudonymized). No sensitive data sales.
Your CCPA Rights:
| Right | Description | How to Exercise | Response Time |
|---|---|---|---|
| Know (Access) | Categories/sources of data | Verified request to info@provenantx.com | 45 days |
| Delete | Remove data (with on-chain exceptions via delinking) | Same; two requests/year | 45 days |
| Opt-Out of Sharing | For targeted ads (none currently) | Do Not Sell/Share link in footer | Immediate |
| Correct/Limit Use | Update inaccuracies; limit sensitive inferences | Same | 45 days |
| Non-Discrimination | No penalties for exercising rights | ||
GDPR Compliance (EU/EEA Users)
If you are in the European Economic Area (EEA), we act as a data controller under the General Data Protection Regulation (GDPR). We process data only for legitimate interests (e.g., waitlist management, provenance verification) with minimal retention (e.g., 6 months post-interaction).
Your GDPR Rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of your data | Email info@provenantx.com |
| Rectification | Correct inaccuracies | Same as above |
| Erasure ("Right to be Forgotten") | Delete data where possible; for on-chain elements, we unlink metadata via ZKPs | Same; note: core ledger immutability limits full erasure |
| Objection/Opt-Out | Stop processing for marketing | Unsubscribe link in emails |
| Portability | Receive data in machine-readable format (e.g., JSON) | Request form forthcoming |
| Automated Decisions | No solely automated profiling; human review for accreditation | |
International transfers (e.g., to US custodians) use Standard Contractual Clauses (SCCs).
Contact Us
If you have questions about this Privacy Policy, please contact us at info@provenantx.com
Last updated: October 28, 2025