Privacy Policy

Last updated · May 30, 2026

Overview

This Privacy Policy explains how POOLARIS AI ("Poolaris", "we", "us") collects, uses, shares, and protects personal data when you use our website, applications, APIs, and related services (the "Service"). We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR), the Spanish LOPDGDD, the California Consumer Privacy Act (CCPA/CPRA) where applicable, and other applicable laws.

1. Data controller and contact

The data controller is POOLARIS AI.

Privacy contact: privacy@poolaris.ai

Data Protection Officer (if appointed): [DPO CONTACT]

EU/EEA representative (if the controller is outside the EU, Art. 27 GDPR): [EU REPRESENTATIVE]

2. Scope

This Policy applies to personal data we process as a controller. It does not cover Third-Party Protocols, wallet providers, or external sites, which have their own policies.

3. Personal data we collect

Blockchain data: wallet addresses you connect and associated on-chain activity (transactions, balances, LP positions). This data is public on the blockchain; when linked to you it may constitute personal data.

Account data (if you register): username, email address, timezone, language, marketing preferences.

KYC/identity data (only if and where required): name, date of birth, identification documents, and verification results. [Include only if KYC is performed.]

Technical and usage data: IP address, device and browser identifiers, approximate location derived from IP, log data, interactions with the Service, and security/diagnostic data.

Communications: messages you send to support or in-product chat, and related metadata.

Cookies and similar technologies: see Section 12.

We do not intentionally collect special categories of data and ask that you not provide them.

4. Sources

We collect data directly from you, automatically through your use of the Service, from public blockchains, and from service providers (e.g. analytics, RPC, KYC, anti-fraud vendors).

6. Automated decision-making and AI (GDPR Art. 22)

The Service uses automated systems, including AI/LLM components, to screen pools and—if you enable Automatic Mode—to make and execute operational decisions (e.g. selecting, deploying, rebalancing, or exiting positions) within parameters you set. Where such processing produces legal or similarly significant effects on you, it is carried out on the basis of your explicit instruction and consent when enabling Automatic Mode and subject to the safeguards described here. You may disable Automatic Mode, request human intervention, express your point of view, and contest a decision by contacting privacy@poolaris.ai. These systems can be wrong; see the Terms for related risk disclosures.

7. Sharing and recipients

We share personal data with:

• Processors / infrastructure providers: hosting, cloud, RPC and node providers, analytics, email, customer support, security, and AI/data vendors, each under a data-processing agreement with appropriate safeguards.

• KYC, anti-fraud, and compliance providers (where applicable).

• Professional advisers, auditors, and insurers.

• Authorities, regulators, or law enforcement where required by law or to protect rights, safety, and security.

• Successors in a merger, acquisition, or restructuring, subject to this Policy.

We do not sell your personal data for money. Under laws such as the CCPA/CPRA that define "sale"/"sharing" broadly (e.g. certain analytics/advertising), you may exercise opt-out rights via privacy@poolaris.ai.

8. International transfers

Your data may be processed outside your country, including outside the EU/EEA. Where we transfer EEA personal data internationally, we rely on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses, with supplementary measures where needed. You may request a copy of the relevant safeguards.

9. Retention

We retain personal data only as long as necessary for the purposes described:

• Account data: for the duration of your account and up to [X] months after closure.

• KYC/AML records: for the period required by law (typically [5] years after the relationship ends). [Adjust per applicable AML law.]

• Technical/security logs: typically [6–24] months.

• Communications: typically [X] months.

• Data needed for legal claims: until the relevant limitation periods expire.

On-chain data cannot be deleted (Section 11). Specific periods will be finalized with counsel.

10. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including for the Funding Wallet's key-management environment. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify you and/or the relevant supervisory authority of personal-data breaches where required by law.

11. Public blockchains

Transactions recorded on public blockchains are permanent, public, and immutable. We cannot modify or delete on-chain data, and erasure or rectification rights do not extend to information already recorded on a blockchain.

12. Cookies and similar technologies

We use strictly necessary cookies and, subject to your consent where required (EU ePrivacy/LOPDGDD), analytics and preference cookies. You can manage non-essential cookies through our cookie banner/settings. [Link to Cookie Policy if separate.]

13. Your rights

Subject to applicable law, you have the right to: access; rectification; erasure; restriction; data portability; object (including to processing based on legitimate interests and to direct marketing); and to withdraw consent at any time without affecting prior processing. To exercise these rights, contact privacy@poolaris.ai. We will respond within the legally required timeframe (under GDPR, generally one month, extendable). We may need to verify your identity. Exercising your rights is free unless requests are manifestly unfounded or excessive.

For California residents: rights to know, delete, correct, and opt out of "sale"/"sharing", and not to be discriminated against for exercising rights.

14. Children

The Service is not directed to, and we do not knowingly collect data from, individuals under 18. If you believe a minor has provided data, contact privacy@poolaris.ai and we will delete it.

15. Marketing

We send marketing communications only with your consent (or as otherwise permitted by law). You can opt out at any time via the unsubscribe link or by contacting us.

16. Complaints

If you are in the EU/EEA, you may lodge a complaint with your supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), https://www.aepd.es. We encourage you to contact us first so we can try to resolve your concern.

17. Changes

We may update this Policy. The "Last updated" date reflects revisions; we will provide additional notice where required.

18. Contact

Privacy inquiries: privacy@poolaris.ai

POOLARIS AI.

This document is a template/draft and does not constitute legal advice. It must be reviewed and adapted by qualified data-protection counsel, in particular regarding the legal bases, automated decision-making (Art. 22), KYC/AML data, international transfers, and retention periods.

Questions? Contact legal@poolaris.ai or privacy@poolaris.ai.