1. Who is responsible
Chainvara (the company is being registered; its legal name, address and registration number will appear here once registered) is the controller of the personal data described here. For personal data a customer puts into the Service about its own customers or counterparties, the customer is the controller and we process it on its behalf under the Data Processing Addendum.
Contact for any privacy question or request: support@chainvara.com.
2. What we collect
Account data: your email, your name if you give it, your organization, role and team; your sign-in method (password held by our authentication provider, Google or single sign-on), two-factor and passkey settings.
Security and activity data: the audit trail of what you do in the console and the API, with time, network address and browser, and failed sign-in attempts.
Organization data: wallets, transfers, policies, address book entries, Travel Rule and compliance data you enter, invoices and payments.
Support data: the messages you write in the chat and the email you give us there.
Website visitors: we use no advertising or analytics trackers. If you write in the chat without an account, we keep your email and messages to answer you.
3. Why, and on what legal basis
To provide the Service you or your organization signed up for (performance of the contract).
To secure accounts and funds, detect fraud and abuse, and keep evidence of who did what (our legitimate interest in a secure service, and your organization's).
To keep the records anti-money-laundering, tax and accounting laws require (legal obligation).
To answer your support requests and send service emails such as sign-in links, alerts and invoices (contract and legitimate interest). We send product news only to people who did not opt out, with an unsubscribe link in each email.
4. How long we keep it
Account data: as long as the account exists; deleted when you delete your account (Settings → Your data).
Audit trail entries and transfer approvals: five years after the business relationship ends, as anti-money-laundering record keeping requires.
Support conversations: deleted with the account; conversations of website visitors without an account are deleted 24 months after their last message.
Organization data: as long as the organization uses the Service; deleted on request when it leaves, except records the law requires us to keep.
5. Who receives it
Our subprocessors (listed on the subprocessors page) process data for us under written agreements. Blockchain networks receive the public addresses and transactions you send; blockchain transactions are public by nature. Providers you connect yourself (exchanges, risk-scoring providers) receive what that connection needs, under your own agreement with them.
We disclose data to authorities only when the law requires it. We do not sell personal data.
6. Transfers outside the European Economic Area
Some subprocessors are outside the EEA. Transfers rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, with additional measures where needed.
7. Security
Data is encrypted in transit and at rest; signing material and secrets are sealed with keys specific to each organization, under a master key held in a key management service. Access is limited to those who need it, protected by two-factor authentication and recorded. The security page describes the measures in detail.
8. Your rights
You can access, export and delete your own data at any time in the console under Settings → Your data. You can also ask us to correct your data, restrict or object to a processing, or receive your data in a portable format, by writing to us.
You may lodge a complaint with your data protection authority; in France, the CNIL (www.cnil.fr).
9. Cookies and local storage
We use only what the Service needs to work: the sign-in session, the organization and environment you selected, and, if you use the chat without an account, a random token that keeps your conversation. Your theme and similar preferences stay in your browser's local storage. No advertising or analytics cookies are used, so no consent banner is needed.
10. Changes
We update this policy when our processing changes and show the date of the last update at the top of this page. Material changes are announced by email or in the console.