We are committed to protecting your privacy and complying with GDPR, CCPA, and other applicable data protection laws.
1. Introduction
Nebula Studio ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information.
2. Data Controller
Nebula Studio is the data controller for your personal data. For EU users, our EU representative is [EU Representative Details].
3. Information We Collect
3.1. Personal Information
Identity Data: Name, email address, government-issued ID (for KYC), proof of address
Financial Data: Wallet addresses, transaction history, source of funds information
Technical Data: IP address, browser type, device information, usage data
Compliance Data: KYC verification status, PEP screening results, sanctions checks
3.2. Blockchain Data
We collect on-chain data related to your deployed contracts, including contract addresses, transaction hashes, and network interactions. This data is publicly available on the blockchain.
4. How We Use Your Information
We use your personal data for:
Service Provision: To provide and maintain our services
KYC/AML Compliance: To verify your identity and comply with regulatory requirements
Transaction Monitoring: To detect and prevent fraud, money laundering, and other illegal activities
Regulatory Reporting: To fulfill our reporting obligations to regulatory authorities
Communication: To send you service updates, security alerts, and compliance notifications
Improvement: To analyze usage patterns and improve our services
Legal Compliance: To comply with legal obligations and respond to regulatory requests
5. Legal Basis for Processing (GDPR)
We process your personal data based on:
Contract Performance: To fulfill our contract with you
Legal Obligation: To comply with KYC/AML and other regulatory requirements
Legitimate Interest: For fraud prevention, security, and service improvement
Consent: Where you have provided explicit consent (e.g., marketing communications)
6. Data Sharing and Disclosure
We may share your data with:
Regulatory Authorities: When required by law or for compliance purposes
KYC/AML Service Providers: Third-party identity verification and screening services
Blockchain Networks: Transaction data is recorded on public blockchains
Service Providers: Cloud hosting, analytics, and other infrastructure providers (under strict confidentiality agreements)
Law Enforcement: When required by court order or legal process
Cross-Border Transfers: Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for EU data transfers.
7. Data Retention
We retain your personal data for:
Transaction Records: Minimum 5 years (AML requirement) or as required by law
KYC Data: For the duration of your account plus 5 years after closure
Marketing Data: Until you withdraw consent or opt-out
Legal Holds: Extended retention when subject to legal proceedings or regulatory investigations
After the retention period, we securely delete or anonymize your data, except where legal obligations require continued retention.
8. Your Rights (GDPR & CCPA)
You have the right to:
Access: Request a copy of your personal data
Rectification: Correct inaccurate or incomplete data
Erasure: Request deletion of your data (subject to legal retention requirements)
Restriction: Request limitation of processing in certain circumstances
Portability: Receive your data in a structured, machine-readable format
Objection: Object to processing based on legitimate interests
Withdraw Consent: Withdraw consent for processing where consent is the legal basis
Opt-Out (CCPA): Opt-out of the sale of personal information (we do not sell personal information)
To exercise these rights, contact us at privacy@nebulastudio.com. We will respond within 30 days (or as required by applicable law).
9. Data Security
We implement technical and organizational measures to protect your data:
Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.3+)
Access Controls: Role-based access control and multi-factor authentication
Security Monitoring: Continuous monitoring for security threats
Regular Audits: Security audits and penetration testing
Employee Training: Regular security and privacy training for staff
10. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
Notify the relevant supervisory authority within 72 hours (GDPR requirement)
Notify affected users without undue delay
Provide details of the breach and mitigation measures
11. Cookies and Tracking
We use cookies and similar technologies to enhance your experience. See our Cookie Policy for details. You can manage cookie preferences through your browser settings or our cookie consent banner.
12. Children's Privacy
Our Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Continued use after changes constitutes acceptance.
14. Contact & Data Protection Officer
For privacy inquiries, contact:
Privacy Email: privacy@nebulastudio.com
Data Protection Officer (EU): dpo@nebulastudio.com