Buy tokens
Buy tokens
Version 0.1, under review by external counsel. The final version will be published before Stage 1 opens. Items in [brackets] are fixed in the final version.
Controller: [OPERATING ENTITY], [address] (“Brydg”, “we”). Contact: hello@brydg.net. This policy explains how we process personal data when you use the Brydg pre-sale site, create an account, complete verification, purchase Token allocations, use the referral programme, contact support, or subscribe to updates. The Terms of Sale govern purchases; this policy governs data.
Account data: email, password hash, country, language, communication preferences. Verification data (tiered by purchase amount): name, date of birth, nationality, address, government identity document images, selfie, and at higher tiers source-of-funds or source-of-wealth documentation; outcomes of reviews. Wallet and transaction data: wallet addresses you link, signed ownership messages, transaction hashes, amounts, chains, deposit addresses, screening results. Note that blockchain transactions are public by design and permanently visible on-chain; we cannot erase on-chain data. Purchase and ledger data: allocations, stages, prices, terms versions, referral relationships, claims. Support and communications. Technical data: IP address, approximate location derived from it (used for jurisdiction enforcement), device and browser data, and cookie data per §8.
We never collect private keys, seed phrases or wallet PINs. Never provide them to anyone claiming to be us.
Providing the account, dashboard, purchases, delivery at TGE and distributions: contract. Identity verification, sanctions and wallet screening, AML/CTF compliance and jurisdiction restrictions: legal obligation, and legitimate interests where a check exceeds strict obligation. Fraud prevention, referral-abuse detection, security and access logging: legitimate interests. Support, notices and terms-version notifications: contract and legitimate interests. Newsletter and marketing updates: consent, withdrawable any time via unsubscribe. Regulatory and tax reporting and responding to lawful requests: legal obligation. Establishing or defending legal claims: legitimate interests.
We use identity documents for verification and compliance, not marketing. We do not sell personal data. We do not make automated decisions producing legal effects without human review: verification decisions at document tiers are made by humans, and automated screening flags route to human review.
Service providers under contract (hosting, cloud storage, email delivery, blockchain analytics and screening, and, if engaged, an identity-verification provider); our external legal counsel and accountants; auditors; payment and settlement infrastructure; regulators, tax authorities, law enforcement and courts where required; and a successor entity in any reorganisation, with notice. Providers act on our instructions; a current provider list is available on request.
We operate from [jurisdiction] and use providers in multiple countries. Where data leaves a jurisdiction with transfer restrictions (for example the EEA or UK), we rely on [adequacy decisions / standard contractual clauses / equivalent safeguards]; copies are available on request.
Identity documents are stored encrypted; access is only via short-lived signed links; every access is logged. Role-based access, a separated admin realm with two-factor authentication, least-privilege support roles, and monitored infrastructure. No system is perfectly secure; we will notify you and the relevant authority of a breach where the law requires.
Account and ledger data: for the life of your participation plus [5 to 10] years, per AML and audit obligations; ledger data also underpins your allocation and delivery rights, and deleting it would delete proof of what we owe you. Verification documents: [5] years after the relationship ends, or longer where law requires. Marketing data: until you unsubscribe. Technical logs: [12 to 24] months. On-chain data: permanent by nature and outside our control.
Subject to law, you may request access, correction, erasure, restriction, portability, and object to legitimate-interests processing. You may withdraw consent (marketing) at any time. Limits: we cannot erase data we must keep for AML, tax or ledger-integrity purposes, and we cannot alter blockchains. Requests: hello@brydg.net; we respond within [one month]. You may complain to your supervisory authority.
Strictly necessary cookies (session, security, jurisdiction enforcement) run without consent. Optional analytics run only with consent via the banner. We do not run advertising cookies. Full cookie table: [published at launch].
The services are for adults 18+. We do not knowingly process children's data; accounts found to belong to minors are closed and data deleted subject to legal holds.
We may update this policy; changes are published on Official Channels before taking effect, with material changes notified to account holders. The version and effective date appear at the top.