Privacy Policy
Information we collect from you
Identity information: first name, last name, username or similar identifier, title, date of birth and gender.
Contact information: postal address, email address and telephone number.
Profile information: username and password, interests, preferences, feedback and survey responses.
Feedback and correspondence: information you provide in your responses to surveys, when you participate in market research activities, report a problem with Service, receive customer support or otherwise correspond with us.
Financial information: credit card or other payment card details.
Transaction information: details about purchases you make through the Service and billing details.
Usage information: information about how you use the Service and interact with us.
Marketing information: preferences for receiving marketing communications and details about how you engage with them.
Financial information: bank account number and bank routing number; financial assets holdings.
Technical Information: Ethereum wallet address, application programming interface (API)-key and network information regarding transactions.
We process your personal information to create and manage your user account, communicate with you about your orders, provide customer support, and ensure the proper functioning of our service. This processing is necessary for the performance of our contract with you, including account creation and order management (GDPR Article 6 (1) (b)). Additionally, where you have given consent, we process your data for marketing purposes and to respect your communication preferences (GDPR Article 6 (1) (a)). We also rely on our legitimate interests to maintain effective communication, respond to inquiries, resolve issues or complaints, and improve our services (GDPR Article 6 (1) (f)).
Information You Give Us In Relation to the Watt2TradeSite and Watt2Trade Services
Further information we collect from you in relation to https://wallet.watt2trade.com/ may include:
Identity information: country of birth, nationality, social security number, place of birth, employer and occupation.
Identity verification information: passport and/or photo ID for identity verification purposes.
Compliance information: information required to comply with anti-money laundering (AML) laws and know-your-customer (KYC) requirements (such as nationality and place of birth).
Financial information: source of funds for participating in token launches.
Transaction information: information that you give us in relation to your purchased token holdings, such as earnings received from staking, trading, and the number of tokens in your wallet.
We process the additional information you provide in connection with https://wallet.watt2trade.com to manage and fulfill your orders, process payments, provide customer support, and ensure billing accuracy. Processing this information is necessary to perform our contractual obligations with you, including handling orders and payments (GDPR Article 6 (1) (b)). We also process certain data to comply with applicable legal obligations, such as anti-money laundering (AML), know-your-customer (KYC) requirements, accounting, and tax reporting (GDPR Article 6 (1) (c)). Furthermore, we rely on our legitimate interests to resolve issues related to transactions, prevent fraud, and maintain the security and integrity of our services (GDPR Article 6 (1) (f)).
Blockchain and Wallet-Related Data
Because Watt2Trade operates on decentralized blockchain networks, we may process public on-chain data associated with your use of the Platform, including: wallet addresses, smart contract interactions, transaction hashes, public balances, governance participation (votes, proposals, delegation), token purchase confirmations (WTTO) & staking or liquidity operations
All blockchain data is public, immutable, and permanently stored on decentralized networks. Watt2Trade does not control, modify, delete, or influence blockchain records in any way.
On-Custodial Wallets and User Responsibility
Watt2Trade is a non-custodial platform. We do not store, hold, manage, or recover private keys, seed phrases, or digital assets.
You are solely responsible for the custody of your wallet, safeguarding your private keys and seed phrases, ensuring correct interaction with smart contracts & preventing unauthorized access to your wallet
Loss of private keys, mis-transactions, or errors are irreversible and cannot be remediated by Watt2Trade.
Personal Data Processed for the WATTOIN Token Sale
If you participate in any WTTO token sale event (private sale, presale, public sale or whitelist allocation), we may process:
wallet address used for purchase
KYC/AML data (if legally required)
jurisdiction and residency verification
transaction confirmation details
communication data regarding the offering
vesting schedule-related record.
We do not store payment card information or centralized financial credentials.
Processing of DAO Governance Data
We may process certain data necessary for governance operations, including: proposal creation, voting activity, off-chain snapshots, delegation of voting power (if applicable) & governance wallet identification.
On-chain governance activity is public and cannot be modified or deleted by Watt2Trade.
Public and Immutable Nature of Blockchain Data
Data recorded on public blockchains is stored across a decentralized network of nodes and may be accessed from any jurisdiction worldwide.
Such data cannot be altered, cannot be deleted, may not be compatible with "right to be forgotten" & is outside the control of Watt2Trade
We do not determine the location or jurisdiction of blockchain nodes.
Third-Party Wallets, RPC Providers, and Node Operators
When interacting with Watt2Trade, your data may be processed by third-party providers such as: Wallet integrations (MetaMask, WalletConnect, etc.), RPC/node providers (Infura, Alchemy, Ankr, QuickNode, etc.), Oracles (Chainlink or other data providers), Third-party dApps
These entities process data under their own privacy policies. Watt2Trade does not control how they process your data.
Log Files
We may automatically record certain information about how you use our Platform (we refer to this information as "Log Data"). Log Data may include information such as a user's Internet Protocol (IP) address, device and browser type, Internet Service Provider (ISP), operating system, the pages or features of our Platform to which a user browsed and the time spent on those pages or features, the frequency with which the Platform is used by a user, search terms, the links on our Sites that a user clicked on or used, and other statistics.
We process device and technical information based on our legitimate interest in improving our services and ensuring the security of our platform (GDPR Art. 6 (1) (f)). Additionally, we process this information as necessary for the performance of our services and contractual obligations to you (GDPR Art. 6 (1) (b)).
We may use cookies, local storage or similar technologies to analyze trends, administer the Platform, track users' movements around the Platform, and to gather demographic information about our user base as a whole. Users can control the use of cookies and local storage at the individual browser level.
We process location data based on your consent to collect and process real-time GPS or geolocation data (GDPR Art. 6.1(a)). It is also processed to fulfill our contract with you to provide location-based services as part of our service delivery (GDPR Art. 6.1(b)).
Cookies and Web Beacons
Like any other website, Watt2Trade uses "cookies". These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information.
We process this data to improve our website and tailor content to enhance your user experience, based on our legitimate interest in optimizing website functionality and marketing efforts (GDPR Art. 6 (1) (f)).
If you want to know more about how we use cookies and what other information we may collect, please visit our Cookie Notice https://www.watt2trade.com/privacy-policy.
Information we will never collect
We will never ask you to share your private keys or wallet seed. Never trust anyone or any site that asks you to enter your private keys or wallet seed.
Sharing of personal data
Below are the circumstances under which personal data may be shared:
Affiliates:
we may share your personal data with our subsidiaries and affiliated companies (i.e., entities under common ownership or control) only where necessary for legitimate business purposes, such as providing and improving our services, and in accordance with this Privacy Policy and applicable data protection laws.
Corporate transaction:
In the event of a potential or actual corporate transaction (e.g., a merger, acquisition, reorganization, sale of assets, or insolvency proceeding), we may transfer your personal data to relevant parties involved in the transaction. Such transfers will occur only to the extent necessary and subject to appropriate confidentiality and data protection safeguards, in compliance with Article 6 (1) (f) GDPR (legitimate interests) or other applicable lawful bases.
Compliance with the laws:
we may disclose your personal data to third parties where necessary to comply with legal obligations under Article 6 (1) (c) GDPR, including to:
comply with applicable laws and regulatory requirements (e.g., anti-money laundering (AML) and know-your-customer (KYC) obligations).
respond to valid legal requests, such as court orders, subpoenas, or lawful requests from public authorities.
Protection and Safety:
we may disclose your personal data to third parties where necessary to protect vital interests or our legitimate interests, including to:
protect the rights, property, and safety of our company, our users, our employees, or others (including enforcing our contracts, policies, or terms of use).
act in emergency situations to safeguard life or physical integrity under Article 6(1)(d) GDPR (vital interests).
Service Providers and Professional Advisors:
we may share your personal data with carefully selected providers and professional advisors, such as:
IT and cloud service providers;
Payment processors;
Customer support and communication platforms;
Legal, financial, audit, or insurance advisors.
These parties process personal data strictly on our behalf, under written data processing agreements (DPAs), and in accordance with Article 28 GDPR. They are contractually obligated to handle your data securely and only for the purposes we specify.
With your consent:
where you explicitly consent (Article 6 (1) (a) GDPR), we may share your personal data with third parties or entities of your choosing.
Aggregated or Anonymized Data:
we may share aggregated and anonymized data - which cannot reasonably be used to identify you - with third parties for statistical, research, marketing, or business purposes. This type of data does not qualify as personal data under the GDPR.
International data transfers
The Company has offices outside of the EU and has affiliates and service providers in the United States and in other countries. Your personal information may be transferred to or from the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.
EU users should read the important information provided below about transfer of personal information outside of the European Economic Area (EEA).
In case your personal data is provided to third parties outside the EEA, we will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses as adopted by the European Commission. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Retention of your information
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including providing the Services, administering token sale participation and any related claims/distribution processes, complying with legal obligations, resolving disputes, enforcing our agreements, and maintaining the security and integrity of the Platform.
When retention periods expire, we securely delete or anonymize personal data so it can no longer reasonably be used to identify you. We may retain anonymized and aggregated data for longer periods, including indefinitely, where lawful and appropriate.
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Please, see the table below:
1. Provision of Services and Platform Operations - 2 years
2. Legal compliance (fraud prevention, tax obligations etc.) - 2 years
3. Account management - 2 years
4. Customer support - 2 years
5. Marketing activities - 2 years
6. Service procurement - 2 years
7. Analytics & development - 2 years
8. Security and fraud prevention - 2 years
However, we may need to retain some of your personal data for longer if there is a need for it, for example, in order to comply with our tax, accounting and legal requirements. In this case, the applied legal basis for the processing of your information will be the necessity to comply with a legal obligation.
In some circumstances we may anonymize your personal information (so that it can no longer be associated with you) in which case we may use this information indefinitely without further notice to you.
Important - blockchain data: Information recorded on public blockchains (e.g., wallet addresses, transaction hashes, smart contract interactions) is public and generally cannot be deleted or modified by us. Our retention and deletion practices apply to off-chain data we control, not to immutable blockchain records.
Information Security
We employ industry standard security measures designed to protect the security of all information submitted through the Services.
We implement a comprehensive set of technical and organisational security measures to ensure the confidentiality, integrity, and availability of personal data, in accordance with the General Data Protection Regulation (GDPR). These measures include, but are not limited to, access controls, role-based permissions, regular security audits, data encryption in transit and at rest, secure coding practices, endpoint protection, intrusion detection systems, and regular vulnerability assessments.
All personal data of users is encrypted when in transit and at rest. Only system administrators have access to client data. No login credentials of users are stored, as users are their own custodians of their wallet secrets, private keys, and login credentials. User-based authentication guards all endpoints that access personal data. All third-party dependencies are regularly checked for vulnerabilities and updated.
All access to personal data is governed by the principle of least privilege, and we enforce strong password policies, session timeouts, and multi-factor authentication where applicable. Additionally, we conduct regular employee training on data protection and cybersecurity, maintain an incident response plan, and ensure all subprocessors meet equivalent security standards.
While we take reasonable steps to protect your personal data, no system can be completely secure. Therefore, we encourage users to take precautions to protect their own information, including maintaining the confidentiality of login credentials.
In order to protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected.
Automated decisions
According to the Article 22 of the GDPR, the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The Company does NOT make any decisions based solely on automated processing, including profiling, which produces legal effects concerning data subjects.
Updating personal data
If any of the personal data that you have provided to us changes, for example if you change your email address or if you wish to cancel any request you have made of us, or if you become aware we have any inaccurate personal data about you, please let us know by sending an email to notices@watt2trade.com. We will not be responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.
Children's Privacy
Watt2Trade does not knowingly collect any Personal Data from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.
Our priority is adding protection for children while using the Internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.
If you are under the age of majority in your jurisdiction of residence, you may use the Services only with the consent of or under the supervision of your parent or legal guardian. Consistent with the requirements of the GDPR and Children's Online Privacy Protection Act (COPPA), if we learn that we have received any information directly from a child under age 13 without first receiving his or her parent's verified consent, we will use that information only to respond directly to that child (his or her parent or legal guardian) to inform the child that he or she cannot use the Sites and subsequently we will delete that information.
Your rights and choices
Under the General Data Protection Regulation (GDPR), you have certain rights concerning your personal information. You may request that we take the following actions in relation to the personal data we hold about you:
Opt-out: stop sending you direct marketing communications you previously consented to receive. Please note that we may still send you service-related and other non-marketing messages.
Access: provide details about how we process your personal information and give you access to it.
Request: You have the right to receive your personal data in a structured, commonly used, and machine-readable format. If you wish, you can also request that we transfer this data directly to another data controller, where technically feasible.
Correct: update or correct any inaccuracies in your personal data.
Delete: remove your personal information from our records. In certain circumstances, you have the right to request the deletion of your personal data. This may apply if:
your data is no longer necessary for the purposes for which it was collected.
you object to the processing, and there are no overriding legitimate grounds for the processing.
your data has been unlawfully processed.
Please note that this right is not absolute and may be subject to exceptions, such as compliance with legal obligations or the establishment, exercise, or defense of legal claims.
Transfer: send you or a third party a machine-readable copy of your personal data.
Restrict: You have the right to request the restriction of processing of your personal data in certain situations, such as:
when you contest the accuracy of the data, for a period enabling us to verify its accuracy.
when you object to the processing, pending verification of whether our legitimate grounds override your rights.
when the processing is unlawful, and you request restriction instead of erasure.
While the processing is restricted, we will only store your personal data and will not process it further unless specific conditions apply.
Object: You have the right to object to the processing of your personal data based on our legitimate interests (Art. 6(1)(f) of the GDPR), unless we can demonstrate compelling legitimate grounds for the processing that override your rights and freedoms.
To exercise any of these rights, you may contact us at notices@watt2trade.com.
We may need to request specific information from you to verify your identity and process your request. In some cases, applicable laws may require or allow us to decline your request. If we are unable to comply, we will explain the reason, subject to any legal restrictions.
If you have concerns about how we handle your personal information or our response to your requests, you may contact us at notices@watt2trade.com or file a complaint with the data protection authority in your jurisdiction.
Changes to this Policy
We reserve the right to update and change this Policy in order to reflect any changes to the way in which we process your personal data or changing legal requirements.
We regularly update our Privacy Policy. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
CONTACT US
We welcome your comments or questions about this Policy, and you may contact us at the following address: notices@watt2trade.com.
Notice for California residents
If you are a California resident and would like to inquire about your privacy rights, please contact notices@watt2trade.com.
Users from Restricted Jurisdictions
Watt2Trade does not intentionally collect personal data from individuals located in the United States or any other restricted jurisdiction.
Access to the Watt2Trade Platform, including the DEX, Wallet, and any token-related services, is geoblocked and prohibited for users located in the United States.
If any personal data is inadvertently collected from a restricted jurisdiction, it will be promptly deleted once identified.
Sanctioned Jurisdictions & AML Screening
We may process geolocation or residency information to determine whether users reside in jurisdictions where access to certain services is restricted, including:
United States
Canada
Japan
OFAC-sanctioned countries
Other high-risk jurisdictions
This information is processed to comply with anti-money laundering, counter-terrorism financing, and international sanctions regulations.