Privacy Policy
Date of Issuance: November 6, 2024
Preamble
OpenTheta AG, a Swiss company established in Baar, Zug, with Enterprise Identification Number (UID) CHE-232.576.191 (“OpenTheta”, “we”, “us”, or “our”), is committed to protecting your privacy. This Privacy Policy describes our practices regarding the Personal Data (as defined below) we collect, use, and share in connection with your visit to and/or access and use of ThetaSwap, including any content, functionality, and service offered on or through ThetaSwap (collectively, the “Service”) located at https://thetaswap.org.
BY ACCESSING THE SERVICE, YOU UNDERSTAND AND AGREE THAT YOUR PERSONAL DATA IS COLLECTED AND PROCESSED BY OPENTHETA.
PLEASE READ THIS POLICY CAREFULLY TO UNDERSTAND OUR POLICIES AND PRACTICES REGARDING YOUR PERSONAL DATA.
OpenTheta employs privacy by default standards and is committed to storing Personal Data securely and processing it with appropriate care and attention in accordance with the Data Protection Laws.
Capitalized terms defined in the Terms of Use apply to this Privacy Policy.
Definitions
In these Terms of Service, the following capitalized terms have the following meanings:
-
“Anonymous Data”
Data, including aggregated and de-identified data, that is not associated with or linked to any Personal Data and therefore does not, by itself, permit the identification of individual persons. -
“Consent”
Any freely given, specific, informed, and unambiguous indication of which the Data Subject, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to them. -
“Cookie(s)”
A piece of information that is placed automatically on your electronic device’s hard drive when you access the Service. Cookies uniquely identify your browser to the server, allowing OpenTheta to store information such as language preferences, technical information, click or path information, etc., to enhance your web experience and conduct website analysis and performance reviews. Most web browsers accept cookies by default, but you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Note that some parts of the website may not function properly if you refuse cookies. -
“Data Controller(s)”
The natural or legal person, alone or jointly with others, who determines the purposes and means of the Processing of Personal Data. For this Privacy Policy, the Data Controller is OpenTheta. -
“Data Protection Laws”
The Swiss Federal Act on Data Protection of 19 June 1992 (RS 235.1), the Swiss Ordinance to the Federal Act on Data Protection of 14 June 1993 (RS 235.11), and, where applicable, the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with regard to the Processing of Personal Data (General Data Protection Regulation; GDPR). -
“Data Portability”
The right of the Data Subject to receive their Personal Data in a structured, commonly used, and machine-readable format and the right to transmit those Personal Data to another controller without hindrance from the Data Controller. -
“Data Processor”
A natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller. -
“Data Subject(s)”
The natural or legal persons whose data is processed, i.e., the User of the ThetaSwap Platform. -
“Disclosure”
Making Personal Data accessible, for example, by permitting access, transmission, or publication. -
“EEA”
The European Economic Area. -
“TNT20 Token”
A token standard implemented on the Theta Blockchain, compatible with the Ethereum Virtual Machine (EVM), allowing for the creation, transfer, and management of fungible tokens on the Theta Network. -
“ThetaSwap”
This website and its media channels (including all sub-websites and sub-media channels). -
“Personal Data”
Any type of data and information relating to a person who is either identified or identifiable. -
“Processing”
Any operation with Personal Data, including collection, storage, use, revision, disclosure, archiving, or destruction of Personal Data. -
“Standard Contractual Clauses”
The Standard Contractual Clauses as attached to the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on Standard Contractual Clauses for the Transfer of Personal Data to Third Countries pursuant to Regulation (EU) 2016/679 (GDPR). -
“Theta”
The native, Ethereum Virtual Machine (EVM) compatible blockchain with an open-source protocol that allows developers and partners to build decentralized applications. The Theta Network aims to provide decentralized video streaming infrastructure, offering various content types, including e-sports, movies, TV series, and music. -
“Third-party(-ies)”
Any natural and/or legal person who is not OpenTheta or a User. -
“User”
Both the Visitor and the User of the Theta Swap Platform.
Scope
This Privacy Policy explains how OpenTheta collects, uses, and shares Personal Data in connection with your visit to and/or access and use of the ThetaSwap Exchange Platform. It outlines the conditions under which we may collect, store, use, and share information about you, as well as your choices regarding the collection, use, and disclosure of your Personal Data.
Acceptance
By visiting, accessing, and/or using the ThetaSwap Platform, you acknowledge that:
- OpenTheta may collect and process certain Personal Data about you.
- OpenTheta is free to use such Personal Data within the limits provided by law, especially Data Protection Laws and this Privacy Policy.
- You have read and understood this Privacy Policy.
- You agree to be bound by this Privacy Policy.
- You agree to comply with all applicable laws and regulations regarding matters covered by this Privacy Policy.
IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY POLICY, PLEASE REFRAIN FROM VISITING AND/OR ACCESSING AND USING THE THETASWAP PLATFORM.
Principles for Processing Personal Data
While Processing Personal Data, OpenTheta will always adhere to the following general principles:
Transparency
The Data Subject must be informed about how their Personal Data is processed. When Personal Data is collected, the Data Subject must be informed of:
- The existence of this Privacy Policy.
- The identity of the Data Controller.
- The purpose of Personal Data Processing.
- Third-parties to whom the data might be transmitted.
Restriction to a Specific Purpose
Personal Data processed by OpenTheta should be adequate and relevant to the purpose for which it was collected, ensuring that the types of Personal Data collected are not excessive but proportionate to the purposes.
Fairness and Lawfulness
When Processing Personal Data, the individual rights of the Data Subjects must be protected. Personal Data shall be processed lawfully, fairly, and in good faith.
Consent of the Data Subject
Personal Data shall be collected directly from the concerned Data Subject, and Consent shall be required before such collection and further Processing. Consent must be obtained in writing or electronically and is valid only if given voluntarily. If Consent was not obtained before collection and/or Processing, it shall be obtained in writing as soon as possible after the beginning of such Processing.
THE CONSENT FOR THE PROCESSING OF PERSONAL DATA IS GIVEN OR REITERATED:
- When you freely submit Personal Data to access and use the Service.
- Personal Data can be processed without Consent if it is necessary to enforce a legitimate interest of OpenTheta, such as legal or financial purposes.
- The processing of Personal Data is also permitted if national legislation requests, requires, or allows this.
Accuracy
Personal Data must be correct and kept up to date. Inaccurate or incomplete Personal Data shall not be kept on file and will be deleted.
Collected Data
We collect both Personal Data and Anonymous Data during your visit to and/or access and use of the ThetaSwap Platform as described below:
Information You Provide Us
-
Account Information:
When you access and use the Service, update your account profile, or contact us, we may collect Personal Data such as email address, first and last name, username, profile picture, biography, social media information, and other information you provide. We also collect your blockchain address, which may be associated with Personal Data when you use and access the Service. -
Feedback and Inquiries:
If you provide feedback or contact us, we will collect your name and contact information, as well as any other content included in the message. -
Voluntary Information:
We may collect Personal Data at other points in the Service where you voluntarily provide it or where we state that Personal Data is being collected.
Information Collected via Technology
As you visit, navigate through, and interact with the Service, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
-
Information Collected by Our Servers:
To provide the Service and make it more useful to you, we (or a third-party service provider) collect information including, but not limited to, your browser type, operating system, Internet Protocol (“IP”) address, mobile device ID, blockchain address, wallet type, and date/time stamps. -
Log Files:
We gather information automatically and store it in log files, such as IP addresses, browser type, Internet service provider (“ISP”), referring/exit pages, operating system, date/time stamps, and clickstream data. This information is used to analyze trends, administer the Service, track Users’ movements around the Service, and better tailor our Services to our Users’ needs. -
Cookies:
We use Cookies to collect information. Cookies allow us to store information on the server to help make the Web experience better for you and to conduct website analysis and performance reviews. Most web browsers accept Cookies by default, but you can reset your browser to refuse all Cookies or to indicate when a Cookie is being sent. Note that some parts of the website may not function properly if you refuse Cookies. -
Pixel Tags:
We use “Pixel Tags” (also referred to as clear Gifs, Web beacons, or Web bugs) to analyze how Users find our Service, make the Service more useful to you, and tailor your experience with us to meet your particular interests and needs. -
Not Track Signals:
Our systems do not currently recognize “Do Not Track” signals or other mechanisms that might enable Users to opt out of tracking on our site. -
Google Analytics:
We use Google Analytics to collect information about how Users use the Service. Google uses Cookies to help analyze how Users use the Service. The data generated by the Cookies concerning your use of the Service will be forwarded to and stored by Google on servers located outside of Switzerland. Google will use this information to evaluate your use of the Service, compile reports on site activity, and provide other services relating to site activity and Internet usage. Google may release these data to third parties if required by law or when third parties process these data for Google's account. Google will not cross-reference your IP address with any other data held by Google.You may deactivate the use of Cookies by selecting appropriate parameters on your browser. However, deactivation may prevent the use of certain functions of the Service. By accessing and using the Service, you consent to the Processing of your Personal Data by Google as described above.
Information Collected from Third-Party Companies
We may receive Personal Data and/or Anonymous Data about you from companies that offer their products and/or services for use in conjunction with the Service or whose products and/or services may be linked from the Service. For example, third-party wallet providers supply us with your blockchain address and certain other information you choose to share with those wallet providers. We may add this to the data we have already collected from or about you through the Service.
Public Information Observed from Blockchains
We collect data from activity that is publicly visible and/or accessible on the Theta Blockchain. This may include blockchain addresses and information regarding purchases, sales, or transfers of TNT20 Tokens, which may then be associated with other data you have provided to us.
Use of Your Data
Please note that not all the uses described below will be relevant to every User.
Personal Data
We process your Personal Data to run our business, provide the Service, personalize your experience on the Service, and improve the Service. Specifically, we use your Personal Data to:
- Facilitate the creation and security of your account.
- Identify you as a user in our system.
- Provide you with the Service, including viewing, exploring, and managing TNT20 Tokens using our tools, and connecting directly with others to purchase, sell, or transfer TNT20 Tokens on the Theta Blockchain.
- Improve the administration of the Service and the quality of experience when you interact with the Service, including analyzing how you and other Users find and interact with the Service.
- Provide customer support and respond to your requests and inquiries.
- Investigate and address conduct that may violate our Terms of Service.
- Detect, prevent, and address fraud, violations of our terms or policies, and/or other harmful or unlawful activity.
- Display your username next to the TNT20 Tokens currently or previously accessible in your third-party wallet and next to TNT20 Tokens on which you have interacted.
- Send you a welcome email to verify ownership of the email address provided when your account was created.
- Send you administrative notifications, such as security, support, and maintenance advisories.
- Send you newsletters, promotional materials, and other notices related to the Service or third parties' goods and services.
- Respond to your inquiries related to employment opportunities or other requests.
- Comply with applicable laws, cooperate with investigations by law enforcement or other authorities of suspected violations of law, and/or pursue or defend against legal threats and/or claims.
- Act in any other way we may describe when you provide the Personal Data.
Anonymous Data
We may create Anonymous Data records from Personal Data and use this Anonymous Data to analyze request and usage patterns to improve the Service and enhance Service navigation. We reserve the right to use Anonymous Data for any purpose and to disclose Anonymous Data to third parties without restriction.
Disclosure of Your Personal Data
We disclose your Personal Data as described below and elsewhere in this Privacy Policy.
Cross-Border Data Transfers
Unless otherwise stated, any cross-border transfer of Personal Data ensures adequate protection by applying the Standard Contractual Clauses as approved by the Swiss Data Protection Authority and the European Commission. These clauses ensure an adequate level of protection for Personal Data transferred outside of Switzerland and the EEA.
Third Party Service Providers
We may share your Personal Data with third-party service providers to:
- Provide technical infrastructure services.
- Conduct quality assurance testing.
- Analyze how the Service is used.
- Prevent, detect, and respond to unauthorized activities.
- Provide technical and customer support.
- Provide other support to us and the Service.
Affiliates
We may share some or all of your Personal Data with any subsidiaries, joint ventures, or other companies under our common control (“Affiliates”). We require our Affiliates to honor this Privacy Policy.
Corporate Restructuring
We may share some or all of your Personal Data in connection with or during negotiation of any merger, financing, acquisition, or dissolution transaction or proceeding involving the sale, transfer, divestiture, or disclosure of all or a portion of our business or assets. In the event of insolvency, bankruptcy, or receivership, Personal Data may also be transferred as a business asset.
Other Disclosures
We may also disclose your Personal Data to:
- Fulfill the purpose for which you provide it.
- For any other purpose disclosed by us when you provide it.
- With your consent.
Third-Party Websites
The Service may contain links to third-party websites. When you click on a link to another website, you will leave the Service and go to another website, and another entity may collect Personal Data from you. We have no control over, do not review, and cannot be responsible for these third-party websites or their content. Please be aware that the terms of this Privacy Policy do not apply to these third-party websites or their content, or to any collection of your Personal Data after you click on links to such third-party websites. We encourage you to read the privacy policies of every website you visit. Any links to third-party websites or locations are for your convenience and do not signify our endorsement of such third parties or their products, content, or websites.
Third-Party Wallets
To access and use the Service, you must use a third-party wallet (e.g., MetaMask) that allows you to engage in transactions on the Theta Blockchain. Your interactions with any third-party wallet provider are governed by the applicable terms of service and privacy policy of that third party. Under no circumstances shall OpenTheta be liable for the utilization of these third-party wallet applications, especially regarding data protection rules.
Storage of Your Personal Data
Your Personal Data will be stored in Europe. You agree that we may store your Personal Data in any country of the EEA, including Switzerland. Accordingly, your Personal Data may be stored at a destination outside of your country of residence. You also agree that Processing may lead to your Personal Data being transferred and stored in countries offering a lower level of protection than your country of residence. In any such case, OpenTheta ensures that adequate protection is guaranteed for Personal Data transferred outside of Switzerland and the EEA by applying the Standard Contractual Clauses.
Retention of Your Personal Data
In accordance with applicable laws, we will use your Personal Data for as long as necessary to satisfy the purposes for which your Personal Data was collected or to comply with applicable legal requirements.
Security of Your Personal Data
OpenTheta applies high industry standards and will always apply adequate technical and organizational measures, in accordance with applicable laws, to ensure that your data is kept secure.
In the event of a Personal Data breach, we shall, without undue delay and, where feasible, no later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to your rights and freedoms. If the breach is likely to result in a high risk to your rights and freedoms, we shall communicate this breach to you, if feasible, without undue delay.
Access to Your Data and Information Rights
You have the right to request access to or information about the Personal Data relating to you which are processed by us.
Where provided by law, you, your successors, representatives, and/or proxies may:
- Request deletion, correction, or revision of your Personal Data.
- Oppose the data Processing.
- Limit the use and disclosure of your Personal Data.
- Revoke Consent to any of our data Processing activities, if OpenTheta is relying on your Consent and does not have another legal basis to continue Processing your data.
These rights can be exercised by contacting us through our contact form or writing to us at dpo@opentheta.io with an attached copy of your ID. If the request is submitted by a person other than you, without providing evidence that the request is legitimately made on your behalf, the request will be rejected.
The request is free of charge unless your request is unfounded or excessive (e.g., if you have already requested such Personal Data multiple times in the last twelve months or if the request generates an extremely high workload). In such cases, we may charge you a reasonable request fee according to applicable laws.
We may refuse, restrict, or defer the provision of Personal Data where we have the right to do so, for example, if fulfilling the request will adversely affect the rights and freedoms of others.
Portability of Your Data
You have the right to receive your Personal Data, which you have provided to us, in a structured, commonly used, and machine-readable format. Furthermore, you have the right to transmit those data to another controller without hindrance from OpenTheta.
This right can be exercised by contacting us through our contact form or writing to us at dpo@opentheta.io with an attached copy of your ID. If the request is submitted by a person other than you, without providing evidence that the request is legitimately made on your behalf, the request will be rejected.
The request is free of charge unless your request is unfounded or excessive (e.g., if you have already requested such Personal Data multiple times in the last twelve months or if the request generates an extremely high workload). In such cases, we may charge you a reasonable request fee according to applicable laws.
We may refuse, restrict, or defer the provision of Personal Data where we have the right to do so, for example, if fulfilling the request will adversely affect the rights and freedoms of others.
Privacy by Design and by Default
We will, both at the time of determining the means for Processing and at the time of Processing itself, implement appropriate technical and organizational measures, such as pseudonymization, designed to implement data-protection principles, such as data minimization, in an effective manner. These measures ensure that by default, only Personal Data necessary for each specific purpose of Processing is processed. This includes the amount of Personal Data we collect, the extent of their Processing, the period of storage, and their accessibility.
Data Controller
The Data Controller is:
OpenTheta AG
Sihlbruggstrasse 140
6340 Baar
Switzerland
Concerns and Complaints
We will address any questions or concerns you may have about your Personal Data. You can contact us through:
- Our contact form on the ThetaSwap Exchange.
- Our email address: contact@opentheta.io.
- Our postal address: Sihlbruggstrasse 140, 6340 Baar, Switzerland.
OpenTheta’s representative in the EU for the purposes of the General Data Protection Regulation is Dr. iur. Andreas Gmuender, ChFP, who can be contacted at dpo@opentheta.io. Additionally, you have the right to make a complaint if you believe your Personal Data has been mishandled or if we have failed to meet your expectations. You are encouraged to contact us about any concerns or complaints, but you are also entitled to complain directly to the relevant supervisory authority.
Changes to this Privacy Policy
The most current version of this Privacy Policy will be made available on the ThetaSwap Exchange Platform located at https://opentheta.io/privacy.
We may modify this Privacy Policy from time to time. If a modification reduces your rights, a pop-up window will inform you immediately upon your visit to and/or access and use of the Service, and you will have to accept such changes before further use.
Jurisdiction and Governing Law
This Privacy Policy and any questions relating thereto shall be governed by the laws of Switzerland, excluding any rules of conflict resulting from private international law.
Any dispute relating to this Privacy Policy must exclusively be brought before the courts of Zug, subject to an appeal to the Swiss Federal Court.
Contact
To ask questions or make comments on this Privacy Policy or to make a complaint about our compliance with applicable privacy laws, please contact us through:
- Our contact form on the ThetaSwap Exchange Platform.
- Our email address: contact@opentheta.io.
- Our postal address: Sihlbruggstrasse 140, 6340 Baar, Switzerland.
We will acknowledge and investigate any complaint pursuant to this Privacy Policy.