For the complete documentation index, see llms.txt. This page is also available as Markdown.

Privacy & Cookie Policy

Last updated: 26 June 2026

This Privacy and Cookie Policy (the “Policy”) for DeriW Foundation Ltd (the “Company”, “we”, “our”, or “us”) describes the basis on which we may process personal data we may collect from users of the Company’s website, www.deriw.com, including any of its subdomains (the “Website”), in accordance with applicable law. For purposes of applicable data protection laws, the Company is the controller. For the purposes of this Policy, “you” and “your” refers to you as the user of the Website.

Read this Policy carefully so that you understand your rights in relation to your personal data and how we might collect, use, and process it. If you do not agree to this Policy, do not use, access, connect to or interact with the Website, or otherwise provide your information to us.

When you access, use, connect to, or interact with the Website, we may collect certain categories of information about you, including personal data, from a variety of sources.

1.1 Information You Provide to Us

Data may include: (i) any digital-asset, smart-contract, or protocol address (“Wallet”) information; and (ii) geolocation data. You provide this data to us when you connect your Wallet to the Website. Other data may include transaction data or history, such as your public blockchain transaction history and other information associated with a linked address or Wallet and any token holdings. Should you contact us, we will collect the content of the communications we have with you and any personal data contained within, including the email address you used to contact us.

1.2 Information We Collect Automatically

When you visit certain pages on our Website, our servers save each access in a log file. The following data may be collected: (i) the date and time of access; (ii) the country from which the Website is accessed; (iii) any API endpoints being accessed; (iv) user agent details; (v) the operating system of your computer and the browser you are using (provider, version, and language); and (vi) the transmission protocol used (e.g., HTTP/1.1).

We may also use web beacons, clear gifs, geolocation and tracking technologies, and other applications when you visit the Website, including technologies that collect certain information about your access to, use of, connection to, or interaction with the Website (“Usage Data”) that may be integrated with third-party service providers. In our legitimate interests in providing effective services to you, we may also use this data to create aggregated, anonymised, or de-identified data.

1.3 Third-Party Wallet Connections and Disclaimer

Certain features of the Website may require you to connect a compatible third-party digital Wallet. By using such a Wallet, you agree that your access to, use of, connection to, and interactions with such third-party Wallets are governed by the policy applicable to the relevant Wallet, and you agree that you are using the Wallet in accordance with the terms and conditions of the applicable third-party provider. Wallets are not maintained or supported by, or associated or affiliated with, the Company. We expressly disclaim any and all liability for actions arising from your use of third-party Wallets, including without limitation actions relating to the use or disclosure of personal information by such third-party Wallets.

1.4 Blockchain Data

Certain data relating to your activity on the Website may be recorded on a public blockchain. Given the technological design of public blockchains, this data is publicly accessible, may be retained indefinitely, and cannot be deleted, amended or made anonymous by us. You acknowledge and accept this characteristic of public blockchains before interacting with the Website.

We generally process the information we collect when we need to do so to perform our contract with you. For example, the processing of this data is carried out for the purpose of enabling your access to, use of, connection to, and interaction with the Website, including: (i) to facilitate your connection to the Website; and (ii) to identify if you are likely to be a Restricted Person, as defined in our Terms and Conditions. Each case with respect to any of (i) or (ii) is in order for us to perform our contract with you and in our legitimate interests to provide access to the Website to you.

With your consent, we may use any data collected, including Usage Data, to tailor features and content to you and to ensure content is presented in the most effective manner for you and your device. We may also use and run analytics to better understand your user experience with respect to the Website.

We may also process this data in our legitimate interests to assist system security and stability for provision of the Website, to conduct troubleshooting, data analytics, testing, and research, to enable optimisation and internal statistical analysis with respect to the Website, and to maintain the safety and security of our users, the Website, and to improve and develop the Website. In addition to the foregoing, we may use any of your information to comply with any applicable legal obligations, to enforce any applicable terms of use, and to protect or defend the Website, our rights, and the rights of our users or others.

We use cookies to enhance your experience when accessing and using the Website. The cookies we use are strictly necessary cookies, which help ensure compliance with our Terms and Conditions, and are otherwise integral to our ability to provide the best user experience and to help us understand general usage patterns. These cookies are not used for marketing purposes. By continuing to use the Website, you consent to the placement of these cookies.

You can configure your browser to refuse some or all cookies, or to alert you when cookies are being set. If you disable strictly necessary cookies, some parts of the Website may not function properly.

2. Your Rights

Under applicable data protection laws, you may have certain rights in relation to your personal data. These rights may include the following:

  • Access to your personal data that we hold, information on how we use it, and who we share it with;

  • Request the correction of inaccurate or incomplete personal data we hold about you, which we may verify as necessary before making changes;

  • Deletion or removal of your personal data, in certain circumstances;

  • Objection to the processing of your personal data, in certain circumstances;

  • Restriction of the processing of your personal data, to stop us from processing the personal data we hold about you other than for storage purposes, in certain circumstances;

  • Portability of your personal data; we will endeavour to provide you, or a third party, with a copy of the personal data that we hold about you and transfer it to a third party in a structured, commonly used, machine-readable format;

  • Withdrawal of consent, where we rely on consent to process personal data. This will not affect the processing of personal data carried out before consent is withdrawn or on legal bases other than consent.

You may submit a written request concerning the processing of your personal data to us at our registered office at Citrus Grove, Ground Floor 106 Goring Avenue, Suite #647, 10 Market Street Camana Bay George Town, Grand Cayman, KY1-9006, Cayman Islands. Prior to any response to such request, we will require you to verify your identity. We may have valid legal reasons to refuse your request and will inform you if that is the case. These rights apply only in certain circumstances and all of these rights may be limited by law. Such limitations may apply, for example, where fulfilling your request would adversely affect other individuals or our trade secrets or intellectual property, where there are overriding public interests, or where we are required by law to retain your personal data. To the extent required under applicable data protection laws, we will be responsive to your request without undue delay and, where required, at least within one month (though this may be extended by a further two months in certain circumstances).

3. Sharing of Personal Data

In certain circumstances, we may share your information with third parties with your consent, as necessary, or as otherwise required or permitted by law, including but not limited to:

  • Service providers and vendors: we may share your personal data with third parties to process on our behalf. Such third parties could include blockchain analysis service providers, sanctions-screening service providers, developers, content-delivery service providers, geo-blocking service providers, and data-analytics service providers. Such service providers may assist us with many different functions and tasks, including geo-blocking based on IP address and collecting anonymised device information for analytics purposes.

  • Professional advisors, in our legitimate interests or as required by law.

  • For legal and security reasons and to protect our Website, in our legitimate interests or as required by law.

Your personal information may be transferred to and stored or processed in countries outside the jurisdiction in which you live and reside, including outside the European Economic Area (“EEA”) and the United Kingdom (“UK”), in order to provide the Website. Your personal information may also be processed by staff operating outside the UK and EEA who work for us or for third-party service providers or partners. We will take steps reasonably necessary to ensure that your personal information is treated securely and in accordance with this Policy.

Where we transfer your personal information to third parties located outside the EEA or the UK, we will seek to put in place appropriate safeguards to ensure that this transfer occurs in accordance with applicable laws. These measures include seeking entry into the standard contractual clauses (“SCCs”) approved by the European Commission (for transfers outside the EEA) and an international data transfer agreement or addendum to the SCCs approved by the UK Information Commissioner’s Office (“ICO”) (for transfers outside the UK), unless the data transfer is to a country that has been determined by the European Commission or the relevant UK authorities, as applicable, to provide an adequate level of protection for individuals’ rights and freedoms with respect to their personal data.

4. Retention

We will retain your personal data only for so long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements, or as otherwise required by law. The length of time we retain your data will depend on the nature of the data and the purpose for which it was processed.

5. Children’s Privacy and Data Protection

The Website is not intended for or directed at any person under eighteen (18) years of age. If we become aware that we have unknowingly collected information about any person under eighteen (18) years of age, we will make commercially reasonable efforts to delete such personal data and other information from our records.

6. Security Measures Taken to Protect Personal Data

Be aware that despite our efforts to protect your personal data and other information, we cannot guarantee perfect security of your information transmitted through the Website. In addition, any information you send to us electronically may not be secure while in transit. Any transmission is at your own risk.

7. Usage Data Collection

When you access, use, connect to, or interact with the Website, the Company and any of its third-party service providers may receive and record personal data that you may have provided and your digital signature.

We may provide links on the Website to other websites or online platforms operated by third parties, including social media or content platforms operated by third parties, such as X (formerly Twitter), Telegram, Discord or Medium (such platforms generally, “Social Media Platforms”). We may also provide links to websites or online platforms operated by third-party contributors to the DeriW Protocol and ecosystem (“Contributors”). We do not own, operate, or control such third-party websites.

If you follow links to sites not owned or operated by us, you should review their available privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy, security, or content of these sites, including the accuracy, completeness, or reliability of information and services found on these sites.

Third parties and Contributors may provide services, information, dashboards, websites, tools, functionalities, and applications, and these may be linked from time to time through the Website or through Social Media Platforms. Such third parties and Contributors are independent and, as such, we do not own, operate, or control their services, information, dashboards, websites, tools, functionalities, and applications and cannot guarantee, and are not responsible for, the privacy, security, or content of these sites or the accuracy, completeness, or reliability of any services, information, dashboards, websites, tools, functionalities, and applications found on these sites. Our inclusion of links, including through Social Media Platforms, does not, by itself, imply any endorsement of such services, information, dashboards, websites, tools, functionalities, and applications, or of their owners, operators, or publishers, except as disclosed on the Website.

When you open a link to any Social Media Platform from the Website, a direct connection may be established between your browser and the server of the Social Media Platform. This provides the Social Media Platform with information that you visited the Website and accessed the link. If you access a link to a Social Media Platform while logged into your account on the Social Media Platform concerned, the content of the Website may be linked to your profile on the platform (the Social Media Platform may link your visit to the Website directly to your user account). If you want to prevent this, you should log out before clicking on the relevant links. In any case, an association takes place when you log in to the relevant Social Media Platform after clicking on the link.

9. Periodic Reviews and Updates to Policy

This Policy takes into account the requirements of applicable data protection laws in Cayman Islands and general privacy principles. Individuals located in the European Union (“EU”) and the United Kingdom may have rights under the EU General Data Protection Regulation 2016/679 and the UK General Data Protection Regulation, respectively (collectively, the “GDPR”). You can file a claim with the data protection supervisory authority in the EEA country in which you live or work or where you think we have infringed data protection laws, or with the UK Information Commissioner’s Office, as applicable to you. Other applicable global privacy and data-protection laws may provide you with rights with respect to your personal data and other information.

We may review and update this Policy from time to time. Updates to this Policy will apply only to information collected after the date of the change. If we make material changes, we will update the “Last updated” date at the top of this Policy.

10. Contact

If you have any questions about this Policy or our processing of your personal data, please write to us at our registered office at Citrus Grove, Ground Floor 106 Goring Avenue, Suite #647, 10 Market Street Camana Bay George Town, Grand Cayman, KY1-9006, Cayman Islands.

Last updated