FIN-TECHAI ← Back to registration
Legal

Privacy policy

How FIN-TECHAI collects, uses and protects personal data across this website, the $FTAI token sale and the risk API. It sits alongside the terms of service, whose clause 11 contains the risk disclosure.

Last updated: 30 July 2026 Version: v2.0 Controller: Fin-techAI Foundation
Contents
01

Who we are

The controller of your personal data is Fin-techAI Foundation, a non-stock foundation organised under the laws of the State of Delaware, United States ("FIN-TECHAI", "we", "us").

Our data protection contact is privacy@fin-techai.com. Because we offer the services to residents of the European Union and the United Kingdom, we have appointed Prighter Group as our representative under Article 27 of the EU GDPR and of the UK GDPR. Our EU representative is Maetzler Rechtsanwalts GmbH & Co KG, Schellinggasse 3/10, 1010 Vienna, Austria; our UK representative is Prighter’s United Kingdom entity. Both are reachable through prighter.com or at office@prighter.com, and EU and UK residents may use either channel to exercise their rights.

02

Scope

This policy covers this website, the presale and claim interfaces, our documentation, and the FIN-TECHAI risk API. It does not cover the blockchain networks themselves, your wallet provider, or any third-party site we link to — each has its own policy and we do not control them.

03

Data we collect

CategoryExamplesSource
Wallet and transactionPublic wallet addresses, contribution amounts, transaction hashes, chain, claim recordsYou, and public blockchains
TechnicalIP address, approximate country, device and browser type, referring page, timestampsCollected automatically
UsagePages viewed, interface actions, API endpoints called, request volumes and errorsCollected automatically
Account and contactName, email, company, role — where you register for API access or contact usYou
VerificationIdentity documents, proof of address, source-of-funds evidence, sanctions and PEP screening resultsYou, and screening providers — only where we are required to verify
CommunicationsSupport messages, emails, and records of consents and noticesYou

We do not ask for and never need your seed phrase or private keys. Any message asking you for them is not from us.

04

Wallet and on-chain data

Connecting a wallet discloses its public address to us. Contributing writes your address and amount to a public blockchain, permanently and publicly, by design and outside our control.

A wallet address is treated as personal data where it can be linked to you. We run blockchain analytics on contributing addresses to screen for sanctions exposure and illicit-source indicators, as described in the terms of service. This may associate your address with counterparty risk signals derived from public chain history.

05

Why we use your data

  • To operate the presale: recording contributions, calculating entitlements, and delivering claims.
  • To maintain the founding registry and the holder benefits attached to a wallet.
  • To meet legal obligations: sanctions screening, anti-money-laundering checks, record keeping, and responding to lawful requests.
  • To enforce jurisdiction restrictions, which is why we process approximate location from your IP address.
  • To secure the services: detecting fraud, abuse, phishing infrastructure, bot traffic and rate-limit evasion.
  • To provide and support API access, including authentication, billing and usage limits.
  • To improve the services and the accuracy of the risk models, using aggregated and de-identified data.
  • To communicate with you about the sale, security matters, and material changes to these documents.

We do not sell personal data, and we do not use it for third-party advertising.

06

Legal bases

Where the EU GDPR or the UK GDPR applies, we rely on: performance of a contract, for operating the sale, claims and API access; legal obligation, for AML, sanctions and record-keeping; legitimate interests, for security, fraud prevention, service improvement and enforcing eligibility, balanced against your rights; and consent, for optional analytics and marketing, which you may withdraw at any time.

07

Data processed for API customers

When a customer submits data to the risk API — for example an address, a transaction, or a counterparty identifier — that customer is the controller of it and we act as their processor under a data processing agreement. We process it to return a score or signal, to bill for usage, and to maintain security logs.

If you are an end user of one of our customers, contact that customer to exercise your rights. We will refer such requests to them.

08

Automated processing and scoring

The risk layer produces automated scores and signals about addresses and transactions. Where we apply automated screening to your own contribution and it results in a block, a delay or a withheld claim, we will tell you on request, and you may ask for the decision to be reviewed by a person. Contact privacy@fin-techai.com.

A score is a risk signal, not a determination of wrongdoing, and neither we nor our customers may present it as one.

09

Cookies and similar technologies

We use strictly necessary cookies and local storage to keep the interface working — for example remembering your selected chain and session state. These do not require consent.

Our analytics are cookieless. We use Plausible Analytics, which measures aggregate traffic without setting cookies, without cross-site tracking and without building a profile of you, so we set no advertising or profiling cookies and there is nothing to consent to or withdraw. Browser controls can block cookies, though blocking strictly necessary ones may break the interface. We honour Global Privacy Control signals where your browser sends them.

10

Who we share data with

  • Infrastructure and hosting providers, and content delivery networks.
  • Blockchain analytics, sanctions screening and identity verification providers.
  • Market data providers whose price feeds the interface displays.
  • Professional advisers, auditors and insurers, under confidentiality.
  • Regulators, law enforcement and courts, where legally required.
  • An acquirer or successor, in a merger, acquisition or reorganisation.

Processors act only on our instructions under a written contract. A current list of categories and named processors is available on request at privacy@fin-techai.com.

11

International transfers

We and our providers operate in more than one country, so your data may be transferred outside your country and will normally be processed in the United States. For data moving out of the European Union or the United Kingdom we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or our certification under the EU–US Data Privacy Framework and its UK extension, together with a transfer risk assessment. A copy of the safeguards is available on request.

12

How long we keep it

DataRetention
Contribution, entitlement and claim recordsFive years after the relationship ends, to meet record-keeping duties under the US Bank Secrecy Act and equivalent EU and UK rules
Verification and screening recordsFive years from the date of the check
Security and access logs12 months
API request logs12 months, or as agreed with the customer
Support correspondence24 months from the last message
Aggregated, de-identified analyticsIndefinitely, as it no longer identifies you

On-chain records cannot be deleted by us or by anyone, and remain public permanently.

13

Security

We apply encryption in transit and at rest, least-privilege access controls, multi-factor authentication for administrative systems, network segregation, logging and monitoring, and periodic penetration testing and review. Treasury funds are held under multi-signature control.

No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, notify affected US residents as required by applicable state breach-notification law, and inform affected users without undue delay.

14

Your rights

Subject to your local law, you may request access to your data, correction of inaccurate data, deletion, restriction of processing, portability, and objection to processing based on legitimate interests, including profiling. You may withdraw consent at any time, and you may ask for a human review of an automated decision that affects you.

To exercise a right, contact privacy@fin-techai.com. We may ask you to prove control of a wallet address, by signing a message, before acting on a request about it. We respond within 30 days, or within 45 days where a US state privacy law applies, and may extend once where a request is complex. If you are unsatisfied you may complain to your national data protection authority in the European Union, to the UK Information Commissioner’s Office, or to the California Privacy Protection Agency or your state attorney general in the United States.

15

US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Texas, Utah, Oregon or another state with a comprehensive privacy law in force, you have the right to know what personal data we hold about you and to receive a copy of it, to correct it, to delete it, to opt out of targeted advertising, profiling for decisions with a legal or similarly significant effect, and any sale of personal data, and to be free from discrimination for exercising these rights.

We do not sell your personal data and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, and we do not knowingly sell or share the data of anyone under 16.

Identity documents, government identifiers and source-of-funds evidence are sensitive personal information under California law. We collect them only where sanctions and anti-money-laundering rules require verification, we use them only for that purpose and for the security of the services, and we do not use or disclose them to infer characteristics about you.

To exercise a right, email privacy@fin-techai.com. You may use an authorised agent, in which case we will ask for written proof of their authority. We verify requests before acting on them, and we may ask you to sign a message from a wallet address where the request concerns that address. If we refuse a request you may appeal by replying to our decision, and we will respond to an appeal within 45 days.

16

Limits imposed by blockchains

Some rights cannot be fulfilled against data written to a public blockchain. Transactions, addresses and amounts are immutable, replicated across independent nodes worldwide, and outside the control of any party, so we cannot erase, rectify or restrict them. Where you exercise a right, we act on data in our own systems, and we will tell you where a request cannot extend to on-chain records.

17

Children

The services are not available to anyone under 18 and we do not knowingly collect their data. If we learn that we hold data about a person under 18, we will delete it from our systems.

18

Changes to this policy

We may update this policy. The version in force is the one on this page, identified by the version and date above. Where a change materially affects how we use your data, we will give notice through an official channel before it takes effect.

19

Contact

Questions, requests or complaints about privacy: privacy@fin-techai.com, Fin-techAI Foundation. EU and UK residents may also contact our Article 27 representative, Prighter Group, at office@prighter.com or through prighter.com.

See also the terms of service.