Privacy Policy

Last Updated: 8/22/2026

1. Introduction

Nebula Studio ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information.

2. Data Controller

Nebula Studio is the data controller for your personal data. For EU users, our EU representative is [EU Representative Details].

3. Information We Collect

3.1. Personal Information

  • Identity Data: Name, email address, government-issued ID (for KYC), proof of address
  • Contact Data: Email, phone number, mailing address
  • Financial Data: Wallet addresses, transaction history, source of funds information
  • Technical Data: IP address, browser type, device information, usage data
  • Compliance Data: KYC verification status, PEP screening results, sanctions checks

3.2. Blockchain Data

We collect on-chain data related to your deployed contracts, including contract addresses, transaction hashes, and network interactions. This data is publicly available on the blockchain.

4. How We Use Your Information

We use your personal data for:

  • Service Provision: To provide and maintain our services
  • KYC/AML Compliance: To verify your identity and comply with regulatory requirements
  • Transaction Monitoring: To detect and prevent fraud, money laundering, and other illegal activities
  • Regulatory Reporting: To fulfill our reporting obligations to regulatory authorities
  • Communication: To send you service updates, security alerts, and compliance notifications
  • Improvement: To analyze usage patterns and improve our services
  • Legal Compliance: To comply with legal obligations and respond to regulatory requests

5. Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract Performance: To fulfill our contract with you
  • Legal Obligation: To comply with KYC/AML and other regulatory requirements
  • Legitimate Interest: For fraud prevention, security, and service improvement
  • Consent: Where you have provided explicit consent (e.g., marketing communications)

6. Data Sharing and Disclosure

We may share your data with:

  • Regulatory Authorities: When required by law or for compliance purposes
  • KYC/AML Service Providers: Third-party identity verification and screening services
  • Blockchain Networks: Transaction data is recorded on public blockchains
  • Service Providers: Cloud hosting, analytics, and other infrastructure providers (under strict confidentiality agreements)
  • Law Enforcement: When required by court order or legal process

Cross-Border Transfers: Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for EU data transfers.

7. Data Retention

We retain your personal data for:

  • Transaction Records: Minimum 5 years (AML requirement) or as required by law
  • KYC Data: For the duration of your account plus 5 years after closure
  • Marketing Data: Until you withdraw consent or opt-out
  • Legal Holds: Extended retention when subject to legal proceedings or regulatory investigations

After the retention period, we securely delete or anonymize your data, except where legal obligations require continued retention.

8. Your Rights (GDPR & CCPA)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data (subject to legal retention requirements)
  • Restriction: Request limitation of processing in certain circumstances
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for processing where consent is the legal basis
  • Opt-Out (CCPA): Opt-out of the sale of personal information (we do not sell personal information)

To exercise these rights, contact us at privacy@nebulastudio.com. We will respond within 30 days (or as required by applicable law).

9. Data Security

We implement technical and organizational measures to protect your data:

  • Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.3+)
  • Access Controls: Role-based access control and multi-factor authentication
  • Security Monitoring: Continuous monitoring for security threats
  • Regular Audits: Security audits and penetration testing
  • Employee Training: Regular security and privacy training for staff

10. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours (GDPR requirement)
  • Notify affected users without undue delay
  • Provide details of the breach and mitigation measures

11. Cookies and Tracking

We use cookies and similar technologies to enhance your experience. See our Cookie Policy for details. You can manage cookie preferences through your browser settings or our cookie consent banner.

12. Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Continued use after changes constitutes acceptance.

14. Contact & Data Protection Officer

For privacy inquiries, contact:

  • Privacy Email: privacy@nebulastudio.com
  • Data Protection Officer (EU): dpo@nebulastudio.com
  • Address: [Company Address]