Privacy Policy

How information is collected, used, stored, and protected.

This Privacy Policy (this "Privacy Policy") applies to your use of the Purps mobile application (the "App"), a mobile interface to the Nado protocol. The App is provided, owned, and operated by Spira Arc Inc. ("Purps," "we," "our," or "us"), a corporation organized and existing under the laws of the Republic of Panama, with its registered office at PH The Century Tower, Office 317, Betania, Vía Ricardo J. Alfaro, 07095 Panama City, Panama. For the purposes of applicable data protection laws, Spira Arc Inc. is the data controller.

Purps is a mobile front-end that allows you to access and interact with the Nado protocol, which is also available through Nado’s websites and web applications. Your use of the App and the underlying protocol is also governed by the Purps Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use.

Purps values your privacy and the privacy of its other users (collectively, the "Users") and wants you to be familiar with how Purps collects, uses, stores, and protects personal information from and about you. 

By accessing or using the App and disclosing personal information, you accept the practices described in this Privacy Policy, to the extent permitted by law. If you do not agree to this Privacy Policy, do not use the App.

Purps is aware of its responsibilities to handle your personal information with care, to keep it secure, and to comply with applicable privacy and data protection laws, including Panama's Law No. 81 of March 26, 2019 on the Protection of Personal Data and its Regulations, and Executive Decree 285 of May 28, 2021 (together, the "Data Protection Law"). 

Individuals located in the European Economic Area ("EEA") and the United Kingdom ("UK") may have additional rights under the EU General Data Protection Regulation 2016/679 and the UK General Data Protection Regulation, respectively (collectively, the "GDPR"). See the section titled "Your Rights and Choices" below.

Information We Collect

Purps has designed the App to be data-minimizing. As a non-custodial interface, the App does not require you to create an account with a username and password, and Purps does not take control of your Digital Assets or private keys at any time. The categories of information described below are the only categories Purps collects in connection with the App.

Information we do NOT collect

To be clear about the limits of our data practices, Purps does not:

(a) collect your full legal name, postal address, date of birth, or government-issued identification;

(b) collect or have access to your private keys, seed phrases, Wallet passwords, or recovery phrases;

(c) collect your contacts, photos, files, or other personal media;

(d) collect your bank account, credit card, or other traditional financial-account information; or

(e) knowingly collect special categories of sensitive data such as health, biometric, or data revealing political or religious beliefs.

Information you provide to us

Wallet information. When you connect a compatible third-party digital-asset wallet ("Wallet") to the App, we process the public blockchain address associated with that Wallet in order to enable your interaction with the Nado protocol. Your public blockchain transaction history and associated on-chain activity are recorded on public blockchains, which are outside Purps's control.

Support communications. If you contact us for support or otherwise, we collect the content of your communications with us and any personal information contained within them, including the email address you use to contact us.

Information collected automatically

IP address and location data (geographic screening). When you access or use the App, we collect your IP address and derive approximate location information from it. We use this information to screen for and restrict access by users located in, or accessing from, Restricted Territories, and to detect and prevent circumvention of those restrictions (including through the use of VPNs or other anonymization tools), as required under the Terms of Use. We use your IP address and derived location for this purpose at the point of access. We retain a record of this information for a limited period as described in the "Data Retention and Deletion" section below.

Device and diagnostic data. We may collect technical information about the device you use to access the App, which may include your device type and model, operating system and version, unique device identifiers, app version, and application crash and diagnostic data. This information is used to operate, secure, troubleshoot, and improve the App. 

Push notification tokens. If you enable push notifications, we process a push notification token associated with your device so that we can deliver notifications to you. You can disable push notifications at any time through your device settings.

How We Use Personal Information

Purps uses the information it collects to:

(a) enable your connection to, and interaction with, the App and the Nado protocol;

(b) deliver push notifications you have enabled;

(c) respond to your support communications and manage our relationship with you;

(d) provide, maintain, secure, and improve the App, including troubleshooting, testing, and ensuring system stability and security;

(e) screen for and restrict access by users in Restricted Territories, detect and prevent circumvention of geographic restrictions, and otherwise enforce eligibility requirements under the Terms of Use;

(f) prevent, detect, and address fraud, abuse, money laundering, terrorist financing, other financial crime, or other harmful or unlawful activity; and

(g) comply with applicable legal obligations, enforce the Terms of Use, and protect or defend the App and the rights, property, and safety of Purps, its Users, and others.

Legal basis for processing (EEA/UK Users)

Where the GDPR applies, Purps processes personal information on the following bases:

  • Performance of a contract: to provide the App and enable your interaction with the Nado protocol under the Terms of Use.

  • Consent: where you have given consent, such as enabling push notifications; you may withdraw consent at any time, which will not affect processing carried out before withdrawal.

  • Legitimate interests: to secure and improve the App, prevent abuse and fraud, enforce geographic and eligibility restrictions under the Terms of Use, and maintain the safety and security of our Users and the App, provided such processing does not override your fundamental rights and freedoms.

  • Legal obligation: to comply with applicable laws (including anti-money laundering, counter-terrorist-financing, and sanctions requirements) and to respond to lawful requests from public or law enforcement authorities.

Sharing of Personal Information

Purps does not sell your personal information. Purps may share the limited information it collects in the following circumstances:

Service providers and vendors. We may share personal information with third parties that process it on our behalf, solely for the purposes described in this Privacy Policy and under obligations of confidentiality. These currently include:

  • Email address or social account identifier. If you sign in with an email address, Google, or Apple through Privy, we receive that identifier from Privy.

  • Referral code. If you sign up using a referral link, we link your wallet address to the referral code and to the wallet address that referred you through Fuul.

Purps ensures that such service providers process personal information only in accordance with Purps's instructions and this Privacy Policy, and are not permitted to use it for their own purposes.

Legal, security, and protective disclosures. We may disclose personal information where we believe in good faith that doing so is necessary to comply with applicable law or a lawful request from a competent authority; to enforce the Terms of Use; to protect against fraud, abuse, or unlawful use; or to protect the rights, property, or safety of Purps, its Users, or others, in each case only to the extent permitted by applicable law.

Business transfers. If Purps, or substantially all of its assets, is acquired by, merged with, or transferred to a third party, or in connection with a contemplated investment or change-of-ownership transaction, personal information may be transferred or assigned as part of that transaction, including during any related diligence process.

Non-personal information. Purps may share aggregated or anonymized information that does not identify any individual User.

International Transfers

As Purps operates globally, personal information may be transferred to, stored, and processed in countries other than your own, including outside the EEA and UK. Some of these countries may have data protection laws that differ from those of your jurisdiction. Where required by applicable law, Purps will put in place appropriate safeguards for such transfers, which may include the standard contractual clauses approved by the European Commission (for transfers outside the EEA) and/or the international data transfer agreement or addendum approved by the UK Information Commissioner's Office (for transfers outside the UK), unless the transfer is to a jurisdiction recognized as providing an adequate level of protection.

Data Retention and Deletion

Purps retains personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or for the period required or permitted by applicable law (such as for compliance, dispute resolution, or enforcement of our agreements).

Because the App is non-custodial and account-light, the personal information Purps retains is limited. Specifically:

  • Support communications, including the email address you used to contact us, are retained for as long as necessary to handle your request and to keep records of our communications, and in any event no longer than 5 years after your last interaction with us, unless a longer period is required by applicable law. 

  • IP address and derived location data collected for geographic screening are retained for 5 years for security, fraud-prevention, and compliance-logging purposes, after which they are deleted or anonymized.

How to request deletion

You may request deletion of the personal information Purps holds about you at any time by contacting us at info@nado.xyz. You do not need to reinstall or reopen the App to make a request. Upon a verified request, Purps will delete or anonymize all personal information that it is not required or permitted to retain under applicable law. Where personal information has been transferred to backup storage and cannot be immediately deleted, Purps will continue to store it securely and will not use it for any purpose until it can be deleted.

Please note that transactions, wallet addresses, and other data recorded on public blockchains and distributed ledgers are outside Purps's control and, due to the technological nature of those networks, cannot be altered or deleted by Purps.

Your Rights and Choices

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:

  • Access to the personal information we hold about you and information about how we process it;

  • Correction of inaccurate or incomplete personal information;

  • Deletion of your personal information, in certain circumstances;

  • Objection to or restriction of certain processing, in certain circumstances;

  • Portability of your personal information, where applicable; and

  • Withdrawal of consent, where we rely on consent; this does not affect processing carried out before withdrawal.

To exercise these rights, contact us at info@nado.xyz. To protect your privacy and security, we may take steps to verify your identity before responding, and may use trusted third-party verification providers solely for that purpose. These rights may be limited by applicable law, and we may have valid legal grounds to decline a request, in which case we will inform you. Where required by applicable data protection law, we will respond without undue delay and, where required, within one month (extendable by a further two months in certain circumstances).

EEA/UK Users may lodge a complaint with their local data protection supervisory authority or, in the UK, the Information Commissioner's Office.

Users protected by Panama's Data Protection Law may exercise their rights and file complaints with the National Authority for Transparency and Access to Information (ANTAI) in accordance with that law.

Marketing communications. Purps does not currently send marketing communications through the App. Where such communications are sent, you may opt out at any time; we may still send you non-promotional service messages necessary to operate the App.

Children's Privacy

The App is intended only for individuals who have reached the age of legal majority in the jurisdiction in which they reside, and in any event is not directed to children. Purps does not knowingly collect personal information from any person under the age of eighteen (18). If Purps becomes aware that it has inadvertently collected personal information from such a person, Purps will take commercially reasonable steps to delete it in accordance with applicable law. If you believe we have collected such information, contact us at info@nado.xyz.

Data Security

Purps uses a range of technical and organizational measures to protect the integrity, confidentiality, and security of personal information, which may vary based on the sensitivity of the information and the risks involved in processing it. No method of transmission or storage is completely secure, however, and Purps cannot guarantee the absolute security of any information transmitted to or stored by it. Any transmission is at your own risk.

Third-Party Wallets, Services, and Links

Third-party Wallets. The App requires you to connect a compatible third-party Wallet. Wallets are not maintained, supported, or controlled by, or affiliated with, Purps. Your use of any Wallet is governed by the terms and privacy policy of the applicable third-party Wallet provider. Purps expressly disclaims any liability arising from your use of third-party Wallets, including the collection, use, or disclosure of personal information by such providers.

Third-party services and links. The App may reference or link to third-party websites, applications, protocols, or services (including projects built on the Nado protocol) that Purps does not own or control. This Privacy Policy does not govern the practices of those third parties, and Purps is not responsible for their content, security, or privacy practices. We encourage you to review their privacy policies.

Changes to This Privacy Policy

Purps may modify this Privacy Policy from time to time in its sole discretion. If Purps makes changes, it will provide notice by updating the "Last updated" date at the top of this Privacy Policy and, where appropriate, through the App. Unless stated otherwise, changes are effective immediately, and your continued use of the App after notice confirms your acceptance. If you do not agree to the revised Privacy Policy, you must stop using the App.

Contact

If you have any questions, comments, or complaints about this Privacy Policy or Purps's data practices, contact us at legal@nado.xyz.