1. About this policy
This Privacy Policy explains how [Registered legal entity name] ("Dyma", "we", "us") processes personal data in connection with the Dyma platform, including the web application, our application programming interfaces, and related services (the "Platform"). It should be read together with the Terms of Service.
"Personal data" means any information relating to an identified or identifiable person. Where this policy uses terms defined in the Terms of Service, such as Quest, Campaign, Project, Submission, Linked Account and Wallet, they carry the same meaning here.
This policy does not apply to the practices of Projects, third-party identity providers, social platforms, wallet software or blockchain networks, each of which determines its own handling of data. Where a Project processes your data for its own purposes, it acts as an independent controller and its own privacy notice applies.
2. Who is responsible for your data
The controller of the personal data described in this policy is [Registered legal entity name], registered number [Company registration number], of [Registered office address].
- Privacy contact.
- privacy@dyma.io for any question, request or complaint about this policy.
- Data protection contact.
- [Data protection officer or EU/UK representative], for individuals in the European Economic Area and the United Kingdom.
Where we and a Project both determine the purposes of a processing operation, for example when a Campaign requires us to disclose to the Project which participants completed a Quest, we act as joint controllers for that operation. In those cases each party is responsible for the lawfulness of its own use, and you may exercise your rights against either of us.
3. Personal data we collect
We collect only what the Platform needs in order to work, to verify Quests honestly, and to comply with our obligations. The categories below reflect what we actually store.
Account and identity data
- a pseudonymous internal identifier and a public identifier used to reference your Account;
- the email address you verify, if you sign in with a one-time code or link an email for notifications, and the date it was verified;
- an optional display name, username and locale preference that you choose;
- the authentication methods active on your Account, and, where you enable two-factor authentication, the fact that it is enabled together with an encrypted secret;
- the status of your Account, the time of your last sign-in, and counts of failed sign-in attempts and any temporary lock applied as a result.
Wallet data
- each blockchain address you link, the network it belongs to, whether it is your primary address, and when it was linked;
- the signature and the one-time challenge used to prove you control that address. We do not receive, request or store private keys or seed phrases.
Linked Account data
- for each third-party account you connect, such as X, YouTube, Discord, GitHub, Telegram or Google: the provider, your identifier with that provider, and the limited profile fields the provider returns, which may include a handle, username, display name, email address and avatar;
- access and refresh tokens issued by the provider, held encrypted and used only to perform the verification the Quest requires;
- the specific verification signals a Quest depends on, for example whether a given account is followed, whether a post was reposted, or whether you are a member of a server or channel.
Quest and Submission data
- the Quests and Campaigns you view, start, submit and claim, and the status of each Submission over time;
- the wallet address recorded against a Submission for payout purposes;
- the content you supply to complete a Quest, including links, text, answers to assessments, redeemed codes, and any file, image or screenshot you upload as evidence;
- the outcome of verification, including any reason recorded for a rejection, and the reward amounts credited to you;
- your referral code, the code of anyone who referred you, and the referrals attributed to you.
Technical and security data
- IP address, recorded with security-relevant events in our audit log;
- request metadata generated by our servers, such as timestamps, endpoints called, response status and user agent;
- for each API key you create: a non-secret prefix, an irreversible hash of the key, its scopes, its expiry and when it was last used. We cannot recover the key itself;
- signals used to detect fraud and coordinated abuse, including patterns across Accounts, devices, networks, Submissions and on-chain activity.
Communications and preferences
- your notification preferences by channel and category;
- records of transactional messages we send you and whether delivery succeeded;
- the content of any message you send to our support or security addresses.
Data we do not want
We do not seek special category data, such as data revealing health, political opinions, religious beliefs, trade union membership, sexual orientation or biometric identifiers, and we do not ask for government identity documents unless a specific Campaign or legal obligation requires it and that requirement is disclosed to you. Please do not include such data in a Submission or support message. If you send it to us unsolicited we will delete it unless we are required to retain it.
4. Where the data comes from
- From you, when you create an Account, complete your profile, link a Wallet or Linked Account, participate in a Quest, create an API key or contact us.
- From your device, automatically, when your browser or client makes a request to the Platform.
- From third-party identity providers and platforms, when you authorise a connection, limited to the fields described in Section 3.
- From public blockchain networks and indexers, when we check on-chain activity a Quest depends on, such as a delegation, a transfer or a contract interaction associated with your linked address.
- From Projects, where a Project records the outcome of a manual review of your Submission.
- From service providers, such as infrastructure, storage, email and security providers acting on our instructions.
5. Why we use your data and our legal bases
Where the General Data Protection Regulation or the equivalent United Kingdom regime applies, we rely on the legal bases identified below. Where another law applies, we process the data for the purposes stated, on the basis that law permits.
- To provide the Platform.
- Creating and authenticating your Account, displaying Campaigns and Quests, recording Submissions, maintaining balances and history, and delivering the features you ask for. Basis: performance of a contract with you.
- To verify Quests and issue Rewards.
- Checking evidence, querying third-party platforms and blockchain networks, determining whether conditions are met, and recording eligibility and payouts. Basis: performance of a contract with you, and our legitimate interest in operating a reward system that is accurate and auditable.
- To prevent fraud and abuse.
- Detecting duplicate Accounts, automated participation, fabricated evidence, exploitation of defects and coordinated schemes, and enforcing the Terms of Service. Basis: our legitimate interest in protecting the Platform, Projects and honest participants, and compliance with legal obligations where applicable.
- To secure the Platform.
- Logging security events, investigating incidents, rate limiting, maintaining audit trails and protecting against unauthorised access. Basis: our legitimate interest in security, and our legal obligation to implement appropriate technical measures.
- To communicate with you.
- Sending one-time sign-in codes, transactional notices about Submissions and Rewards, security alerts, and responses to your enquiries. Basis: performance of a contract with you, and our legitimate interest in service communications. Marketing messages, if any, are sent only with your consent, which you may withdraw at any time.
- To display participation publicly.
- Showing leaderboards, ranks and Campaign progress using a public identifier or display name. Basis: performance of a contract with you where a Campaign is competitive, otherwise our legitimate interest in a functioning community feature. See Section 8.
- To improve the Platform.
- Diagnosing errors, understanding which features are used and in aggregate how Campaigns perform. Basis: our legitimate interest in maintaining and improving our service. We use aggregated or de-identified data for this wherever it is sufficient.
- To comply with law and defend claims.
- Meeting legal, regulatory, tax and sanctions obligations, responding to lawful requests, and establishing, exercising or defending legal claims. Basis: compliance with a legal obligation, and our legitimate interest in defending our rights.
Where we rely on legitimate interests we have assessed that our interest does not override your rights and freedoms. You may object to that processing as described in Section 13, and you may ask us for information about the assessment by writing to privacy@dyma.io.
6. Automated decision-making
Quest verification is substantially automated. Software evaluates evidence, queries blockchain networks and third-party platforms, applies rules configured by the Project, and sets the status of your Submission, which in turn determines whether a Reward becomes payable. Anti-fraud logic may also automatically flag, restrict or suspend an Account.
These decisions can affect you, because they determine whether you receive a Reward and whether your Account remains usable. We therefore apply safeguards: rules are configured in advance rather than inferred from profiling of your personal characteristics; automated rejections record a reason; and you have the right to obtain human intervention.
To contest an automated decision, express your point of view or request a human review, write to support@dyma.io within 30 days, identifying the Submission concerned. A person will review the decision and tell you the outcome.
We do not use your personal data to build advertising profiles, and we do not sell or share it for cross-context behavioural advertising.
8. Public information and data on blockchains
Some data is, by design, visible to others.
On the Platform
Leaderboards and Campaign progress display a public identifier and, if you set one, your display name, together with your rank and reward totals. Choose a display name that you are comfortable making public, and do not use your legal name if you prefer not to be identified. You can change or clear your display name in your profile.
On blockchain networks
Blockchains are public, append-only and outside our control. A wallet address, a transaction and any reward settled on chain are permanently visible to anyone, cannot be edited, and cannot be deleted by us or by you.
This has two consequences you should understand before linking a Wallet. First, a request to erase your personal data cannot extend to data recorded on a public blockchain, because neither we nor any Project has the technical ability to alter it. Second, because addresses are persistent identifiers, on-chain activity associated with your address may be linkable to you by third parties using public analysis tools, including activity unrelated to Dyma.
We keep the association between your Account and your linked addresses within our systems, and we disclose it only as described in Section 9. We do not publish that association ourselves.
10. International transfers
We and our service providers operate internationally, so your personal data may be processed in countries other than your own, including countries that have not been recognised as providing an equivalent level of protection.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on an appropriate safeguard, which will normally be an adequacy decision covering the destination, or the Standard Contractual Clauses approved by the European Commission together with the United Kingdom Addendum where relevant. We assess the circumstances of the transfer and apply supplementary technical and organisational measures, such as encryption in transit and at rest and access controls, where they are needed.
You may request a copy of the safeguard relied on for a particular transfer, with commercially confidential terms redacted, by writing to privacy@dyma.io.
11. How long we keep data
We keep personal data only as long as we need it for the purposes in Section 5, and then delete or de-identify it. In practice:
- Account data is kept while your Account is open. After you close it, we delete or anonymise your profile without undue delay, retaining only what a purpose below requires.
- Submissions and verification records are kept for the duration of the Campaign and then for as long as needed to audit reward distribution and resolve disputes, ordinarily up to 24 months after the Campaign closes.
- Uploaded evidence files are kept while the Submission may be reviewed or disputed and are then deleted, ordinarily within 12 months of the Campaign closing unless a dispute is open.
- Reward and payout records are kept for as long as required by accounting, tax and anti-money-laundering law, which is commonly between 5 and 10 years depending on jurisdiction.
- Security and audit logs, including IP addresses, are kept for a limited period appropriate to incident investigation, ordinarily up to 12 months, and longer where an investigation is open.
- Anti-fraud records relating to an Account we have restricted or terminated are kept for as long as necessary to prevent the same person from re-registering in breach of the Terms of Service.
- One-time codes and session state expire within minutes and are deleted automatically.
- Support correspondence is kept for up to 24 months after the matter is closed.
We may retain data for longer where we are subject to a legal hold, where proceedings are reasonably in prospect, or where a law requires it. Data recorded on a public blockchain cannot be deleted, as explained in Section 8.
12. How we protect data
We implement technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest for sensitive fields such as third-party tokens and two-factor secrets, irreversible hashing of API keys and passwords, http-only session cookies, scoped and least-privilege access for staff and for API keys, network isolation, rate limiting, audit logging of privileged actions, dependency and vulnerability management, and backup and recovery procedures.
No system is completely secure. You play an essential part: keep your private keys and seed phrases offline and to yourself, secure the email inbox used for one-time codes, enable two-factor authentication where offered, do not reuse credentials, restrict API key scopes and rotate keys, and be alert to phishing. Dyma will never ask you for a private key, a seed phrase or a one-time code.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals, without undue delay. To report a suspected vulnerability or incident, contact security@dyma.io.
13. Your rights
Subject to the conditions and exceptions of the law that applies to you, you may exercise the following rights.
- Access.
- Obtain confirmation of whether we process your personal data and a copy of it, together with information about the processing.
- Rectification.
- Have inaccurate data corrected and incomplete data completed. You can edit much of your profile directly on the Platform.
- Erasure.
- Have your data deleted where it is no longer necessary, where you withdraw consent that was the only basis for it, or where you successfully object. This right does not extend to data on a public blockchain, or to data we must keep to comply with law, to prevent fraud or re-registration in breach of the Terms of Service, or to defend legal claims.
- Restriction.
- Ask us to limit processing while a dispute about accuracy or our legitimate interests is resolved.
- Portability.
- Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection.
- Object at any time to processing based on our legitimate interests, and object at any time and without reason to processing for direct marketing.
- Withdraw consent.
- Withdraw consent where we rely on it, without affecting the lawfulness of processing carried out beforehand. You can disconnect a Linked Account and change notification preferences in your profile.
- Human review.
- Obtain human intervention in relation to an automated decision, express your point of view and contest the decision, as described in Section 6.
- Complain.
- Lodge a complaint with a supervisory authority, as described in Section 18.
How to exercise a right
Write to privacy@dyma.io from the email address on your Account, or from within your Account where a feature is provided. We will respond within one month, and may extend that period by two further months for complex requests, telling you if we do. We do not charge a fee unless a request is manifestly unfounded or excessive.
We may ask for information reasonably necessary to verify that the request is genuinely yours, for example a signature from a linked Wallet or confirmation from a verified email address. This protects you against someone else obtaining or deleting your data. We will not use verification data for any other purpose. An authorised agent may act for you on proof of authorisation.
14. Additional information for the EEA, UK and Switzerland
Providing the data described in Section 3 is generally necessary to enter into and perform our contract with you. If you do not provide it, we may be unable to create your Account, verify a Quest or pay a Reward. Where a field is optional, we say so at the point of collection.
You have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is [Lead supervisory authority]. We would welcome the chance to address your concern first, at privacy@dyma.io.
Where required, we maintain a representative for the purposes of Article 27 of the General Data Protection Regulation and the equivalent United Kingdom provision. Contact details are given in Section 2.
15. Additional information for California residents
This Section supplements the rest of this policy for residents of California and is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
In the 12 months preceding the date of this policy we collected the following categories of personal information: identifiers, including a public identifier, email address and blockchain address; internet or other electronic network activity information, including request metadata; commercial information, in the form of Quest participation and reward records; user-generated content, in the form of Submissions; and inferences limited to fraud and abuse signals. The sources, purposes and recipients of each category are described in Sections 3, 4, 5 and 9.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We have not sold or shared the personal information of consumers, including any consumer under 16, in the preceding 12 months.
You have the right to know what we collect and how we use and disclose it, to obtain a copy, to request correction, to request deletion, and to limit the use of sensitive personal information where we use it for purposes beyond those permitted by default. We do not use or disclose sensitive personal information for purposes that require an option to limit.
We will not discriminate against you for exercising these rights. To submit a request, write to privacy@dyma.io. We will verify your identity as described in Section 13, and will respond within the statutory timeframes. You may use an authorised agent, and we may require proof of their authority and verification of your identity.
16. Additional information for other regions
- Brazil.
- Under the Lei Geral de Proteção de Dados you may request confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, and review of automated decisions, and you may withdraw consent.
- Canada.
- Under federal and provincial private-sector privacy law you may request access to and correction of your personal information, and may withdraw consent subject to legal and contractual restrictions. Complaints may be directed to the applicable privacy commissioner.
- Australia.
- Under the Privacy Act you may request access and correction, and may complain to us and then to the Office of the Australian Information Commissioner.
- Other jurisdictions.
- If the law of your jurisdiction grants you rights not listed in this policy, we will honour them to the extent it requires. Write to privacy@dyma.io and tell us which law you are relying on.
17. Children
The Platform is not directed to children and may not be used by anyone under 18, or under the age of majority in their jurisdiction if higher. We do not knowingly collect personal data from children.
If you believe a child has provided us with personal data, contact privacy@dyma.io and we will investigate, delete the data and close any Account we find to belong to a child, unless we are required to retain something by law.
18. Changes to this policy
We may update this policy to reflect changes in the Platform, our providers or the law. The version in force is always published on this page with its effective date and version number.
Where a change materially affects how we use personal data about you, we will give notice by a prominent notice on the Platform or, where we hold a verified email address for you, by email, before the change takes effect. Where the change requires your consent, we will obtain it.
19. How to contact us
- Controller.
- [Registered legal entity name], [Registered office address].
- Privacy enquiries and rights requests.
- privacy@dyma.io.
- Data protection contact.
- [Data protection officer or EU/UK representative].
- Security reports.
- security@dyma.io.
- General and legal notices.
- legal@dyma.io.
If you are not satisfied with our response, you may escalate to the supervisory authority identified in Section 14 or to the authority competent in your jurisdiction.