Privacy policy
Privacy policy
Effective: TO CONFIRM: effective date
1. Who we are
The controller of personal data processed through the counterfeit stablecoin register on this website is TO CONFIRM: data controller entity ("we", "us"), which operates Artemis-Tracing. You can contact us about privacy at TO CONFIRM: privacy contact email or by post at TO CONFIRM: physical business address.
UK representative under Article 27 of the UK GDPR: TO CONFIRM: UK representative, or "not required" with reason. EU representative under Article 27 of the GDPR: TO CONFIRM: EU representative, or "not required" with reason.
This policy is written to meet the requirements of the UK GDPR and the Data Protection Act 2018, the EU General Data Protection Regulation (GDPR) where it applies, and the Israeli Privacy Protection Law, 5741-1981.
2. Whom this policy covers
The rest of this website has its own privacy notice, which applies to the free support service.
This policy applies to people who visit the counterfeit stablecoin register pages, use the wallet check, send us a message through the contact form, or submit a dispute. It also applies to people who control blockchain addresses that appear in our published listings.
3. What we collect, why, and on what legal basis
3.1 Contact form
Data: your name; your preferred contact method and contact details; your country of residence; a wallet address, if you choose to give one; your description of what happened and anything else you include; the page from which you sent the form; and a record of your consent (its date and the version of the consent wording).
Purpose: to respond to your enquiry and, if you ask, to consider whether and how we can help.
Legal basis: your consent (Article 6(1)(a)). Where you ask about our services, processing is also necessary to take steps at your request before entering into a contract (Article 6(1)(b)). You can withdraw your consent at any time by writing to TO CONFIRM: privacy contact email. Withdrawal does not affect processing that took place before it.
Information about a crime: your description may include information about a crime committed against you. Data protection law may treat this as information relating to criminal offences, or as special category data if it reveals, for example, information about your health. We use it only to respond to your enquiry, and we rely on your explicit consent and on the other conditions permitted by applicable law.
Retention: one year from the date we receive your message, after which it is deleted automatically. If you become a client of any practice with your consent, the records needed for that engagement are held under that practice's own terms.
3.2 Wallet check
Data: the wallet address you enter.
How it is used: the address is held in memory only for as long as needed to query public blockchain data providers and return your result. It is not written to our database or our application logs, it is not published, and the result is shown only to you. Result pages are excluded from search engines.
Rate limiting: to prevent abuse, we keep a temporary one-way hash of your IP address, combined with a secret value, in memory for up to one hour. It cannot be used to identify you and is not stored.
Legal basis: our legitimate interests in providing the check you request and in protecting the service from abuse (Article 6(1)(f)).
3.3 Dispute form
Data: your name; your organisation, if any; your email address; the listing concerned; your grounds; and any evidence you provide.
Purpose: to review the listing, to correct or remove information where appropriate, and to keep a record of how each request was handled.
Legal basis: our legitimate interests in keeping the register accurate and in respecting the rights of others (Article 6(1)(f)), and compliance with our legal obligations where your request is a data protection request (Article 6(1)(c)).
Retention: 3 years from the date we receive your request, after which it is deleted automatically.
3.4 Information published in listings
Data: public blockchain data about counterfeit token contracts: the contract address; the addresses that deployed, own, funded or distributed the token; transaction identifiers; timestamps; and the total number of wallets that received the token.
Source: public blockchains, read through block explorers and node providers. We did not obtain this information from you.
Personal data: a blockchain address is a string of characters, not a name. Where an address can be linked to an identifiable person, it may be personal data.
Purpose: to warn the public about counterfeit tokens, to help people recognise them and protect themselves, and to support reporting to the authorities.
Legal basis: our legitimate interests, and those of the public, in preventing fraud (Article 6(1)(f)). In balancing those interests against the interests of people who control listed addresses, we publish only facts recorded on the public blockchain, we name no person, we exclude known service addresses, a human reviews every listing, and anyone can object through our dispute process.
What we never publish: the addresses of wallets that received a counterfeit token.
Your right to object: if you control an address that appears in a listing, you can object under Article 21 by using our dispute form or by writing to TO CONFIRM: privacy contact email.
3.5 Technical data
Our hosting provider processes technical data such as IP addresses, browser type, the page requested and the time of the request, in order to deliver and secure the website. The register pages do not use analytics or advertising tools.
4. Cookies
The register pages use only storage that is strictly necessary:
- a record of your cookie choice, kept in your own browser until you clear it; and
- for authorised staff only, a sign-in session in the private administration area.
The register pages do not use analytics, advertising or tracking cookies. If we propose to use any non-essential cookie or similar technology on these pages in future, we will ask for your consent first.
5. Who we share personal data with
- Service providers that host and operate the website and its database, under written data processing terms.
- Blockchain data providers, which receive the wallet address you enter in the wallet check as part of the query needed to answer it.
- A law practice, only if you ask us to pass your details on or give your express consent.
- Authorities, where the law requires it or where you ask us to.
We do not sell personal data.
6. International transfers
Our service providers may process personal data outside the United Kingdom, the European Economic Area and Israel, including in the United States. Where they do, we rely on an adequacy decision or adequacy regulations, or on appropriate safeguards such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses. Transfers of data from Israel are made in accordance with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001. You can ask us for details of the safeguards used.
7. Retention
| Data | Retention |
|---|---|
| Contact form submissions | one year from receipt |
| Dispute submissions | 3 years from receipt |
| Wallet check addresses | Not stored |
| Rate limiting hashes | Up to one hour, in memory only |
| Cookie choice | Kept in your browser until you clear it |
8. Your rights
Depending on where you live, you have the right to access the personal data we hold about you; to have it corrected; to have it erased; to restrict its processing; to receive it in a portable format; to object to processing based on legitimate interests; and to withdraw consent at any time. Under Israeli law, you have the right to review information about you held in a database and to ask for it to be corrected or deleted.
To exercise any right, write to TO CONFIRM: privacy contact email. We may ask you to confirm your identity. We reply within one month, which may be extended where the law allows.
9. Complaints
If you are not satisfied with our response, you can complain to a supervisory authority: in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the European Union, the authority in your country of residence; and in Israel, the Privacy Protection Authority.
10. Security
We protect personal data with encryption in transit, access controls limited to authorised staff, authentication for the administration area, and encryption at rest provided by our infrastructure providers. Contact form submissions and disputes are never shown on any public page.
11. Children
This website is not directed at people under 18. If you are under 18, ask a parent or guardian to contact us for you.
12. Changes to this policy
We will publish any change on this page with a new effective date. Where a change materially affects how we use personal data that you have already given us, we will tell you before it takes effect.