> For the complete documentation index, see [llms.txt](https://opensci.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://opensci.gitbook.io/docs/agreement/privacy-policy.md).

# Privacy Policy

1. **INTRODUCTION**

1.1 About This Policy

1.1.1 This Privacy Policy describes how OPENSCI Ltd including its operating subsidiaries and affiliates (collectively, "OPENSCI", "we", "us" or "our") collects, uses, shares, and protects personal information when you use the OPENSCI platform ("Platform") and any associated services (the “Services”).

1.1.2 This Policy applies to:

(a) Our Platform and Services;

(b) Our smart contracts and blockchain interactions;

(c) Communications with us;

(d) Related services and features.

1.1.3 By accessing or using the Services, you (a) acknowledge that you have the right, capacity and authority to accept this Policy; (b) confirm that you have read and understood this Policy and (c) agree to the policies and practices described in this Policy. Accordingly, please read it carefully to understand what we do.

1.2 Key Terms

| Term           | Definition                                                                                |
| -------------- | ----------------------------------------------------------------------------------------- |
| Personal Data  | Information that identifies or can identify you directly or indirectly.                   |
| Processing     | Any operation performed on personal data (collecting, recording, storing, sharing, etc.). |
| Controller     | Entity determining purposes of and means of processing personal data.                     |
| CCPA           | California Consumer Privacy Act of 2018 (Cal. Civ. Code §1798.100 et seq.).               |
| CPRA           | California Privacy Rights Act of 2020, amending and supplementing the CCPA.               |
| GDPR           | Regulation (EU) 2016/679 (General Data Protection Regulation)                             |
| On-Chain Data  | Data recorded immutably on a public blockchain ledger.                                    |
| Off-Chain Data | Data stored in traditional systems                                                        |
| UAE PDPL       | The UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.             |

2. **DATA CONTROLLER**

2.1 The Controller for personal information processed through the Platform is: \[OPENSCI Ltd]; Registered Office/Business Address: \[*]; Email: \[*].

3. **INFORMATION WE COLLECT**

3.1 Information You Provide:

3.1.1 Account Information

| Data Type             | Purpose                                                                                                                                                                                   |
| --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Email address         | Account management, communications, security verification.                                                                                                                                |
| Username/Display name | Platform identification, community interaction.                                                                                                                                           |
| Profile information   | Community engagement, researcher identity.                                                                                                                                                |
| KYC documents         | Local regulatory compliance (AML/CTF), identity verification for certain features and special KYC information (including but not limited ORCID and LinkedIn)for researchers and academics |

3.1.2 Research Content

| Data Type        | Purpose                                                   |
| ---------------- | --------------------------------------------------------- |
| IDA descriptions | Platform functionality, asset tokenization.               |
| Research data    | Scientific collaboration, peer review, data monetization. |
| Publications     | Knowledge sharing, , proof of concept.                    |

3.1.3 Communications

| Data Type             | Purpose                                      |
| --------------------- | -------------------------------------------- |
| Support requests      | Customer service, issue resolution.          |
| Forum posts/proposals | Community engagement, governance discussion. |
| Feedback              | Product improvement, , user research.        |

3.2 Information Collected Automatically

3.2.1 Technical Data

| Data Type           | Purpose                                          |
| ------------------- | ------------------------------------------------ |
| IP address          | Security, fraud prevention, regional compliance. |
| Device information  | Compatibility, security optimization.            |
| Browser type        | Platform optimization, debugging.                |
| Cookies/Identifiers | Functionality, session management, analytics     |

3.2.2 Usage Data

| Data Type           | Purpose                                             |
| ------------------- | --------------------------------------------------- |
| Pages visited       | Analytics, user experience improvement.             |
| Features used       | Product improvement prioritization.                 |
| Transaction history | Platform functionality, customer support, auditing. |
| Voting history      | Governance transparency                             |

We will not collect sensitive information about you without your explicit consent, unless an exemption or exception applies. These exemptions or exceptions include where the collection is required or authorized by law, or is necessary to take appropriate action in response to suspected illegal activity or serious misconduct.

3.3 Blockchain Data

3.3.1 On-Chain Data (Permanent and Public)

By using the Platform's blockchain features, you acknowledge that the following data is recorded on a public blockchain. This data is permanent, immutable, and publicly accessible:

(a) Wallet addresses;

(b) Transaction hashes and timestamps;

(c) Token balances;

(d) IDA NFT ownership history;

(e) GRSA (Grant Result Sharing Agreement) allocations and flows;

(f) Governance voting records;

(g) Smart contract interactions.

3.3.2 Pseudonymity

(a) Blockchain data is linked to wallet addresses, not necessarily your legal name;

(b) Crucially, if you publicly link your real-world identity to your wallet address (e.g., in your Platform profile or external social media), all associated on-chain data becomes personally identifiable to you;

(c) Once published on-chain, OPENSCI cannot modify, delete, or restrict access to this data, even upon request.

3.4 Information from Third Parties

3.4.1 We may receive information from:

(a) Blockchain networks (public transaction data);

(b) Identity verification providers (KYC data);

(c) Analytics providers (aggregated usage data);

(d) Research institutions (collaboration data).

4. **HOW WE USE YOUR INFORMATION**

4.1 Legal Bases for Processing

| Purpose                       | Legal Basis                   | Details                                                                                                   |
| ----------------------------- | ----------------------------- | --------------------------------------------------------------------------------------------------------- |
| Platform operation            | Contract performance          | Necessary to fulfill the Terms of Service and provide the requested functionality (e.g., minting an IDA). |
| Security and Fraud Prevention | Legitimate interest           | Essential for protecting users, the platform, and the integrity of the ecosystem.                         |
| Compliance                    | Legal obligation              | Complying with applicable laws applicable to us in the UAE and other jurisdictions (e.g., AML/CTF, tax).  |
| Analytics                     | Legitimate interest           | Improving services, understanding user trends (usually based on aggregated/anonymized data).              |
| Marketing                     | Consent                       | Sending promotional materials only with your permission.                                                  |
| Research                      | Legitimate interest / Consent | Enabling the core scientific mission of the platform.                                                     |

4.2 Specific Uses

4.2.1 Platform Operation

(a) Creating and managing your account;

(b) Processing transactions;

(c) Enabling IDA creation and management;

(d) Facilitating governance participation;

(e) Distributing revenues to stakeholders.

4.2.2 Security and Fraud Prevention

(a) Detecting and preventing fraud;

(b) Enforcing terms of service;

(c) Protecting platform integrity;

(d) Responding to security incidents.

4.2.3 Compliance

(a) KYC/AML verification;

(b) Regulatory reporting;

(c) Responding to legal requests;

(d) Tax reporting (where required).

4.2.4 Communication

(a) Service announcements;

(b) Security alerts;

(c) Governance updates;

(d) Marketing (with consent).

5. **LEGAL BASIS FOR PROCESSING**

5.1 Our processing of Personal Data is based on:

5.1.1 Consent: where you have given us clear and affirmative consent to process your data for a specific purpose. Such as your consent to provide direct marketing communications to notify you of upcoming promotions, benefits, or membership updates via website or email notifications (if applicable);

5.1.2 Contractual necessity: to perform our obligations under agreements we have with you. Such as providing you with our Services: (i) to process and record your purchases of tokens; (ii) to manage and record your rights and privileges; (iii) to verify your eligibility for benefits and prevent fraud; (iv) by email, chat message and other measures to deliver customer support to address your requests and inquiries; (v) to promote the safety, security and integrity of our Services, find and address violations of our Terms of Use , investigate suspicious activity, detect and prevent harmful, unlawful or fraudulent behavior;

5.1.3 Legal compliance: to comply with legal and regulatory requirements. For example, we may require you to provide or otherwise collect necessary information and materials as per relevant laws or government orders to verify the legality of the sources and use of your funds; and

5.1.4 Legitimate interests: where processing is necessary for our business interests, provided it does not override your rights. For example, we may preserve and process your Personal Data under legal issues.

6. **HOW WE SHARE YOUR INFORMATION**

6.1 Categories of Recipients

We may share your Personal Data with:

6.1.1 Companies, Services and employees affiliated with us as a normal part of conducting business and offering our Services to you;

6.1.2 Service providers who assist us in operating our Services or with fulfilling requests;

6.1.3 Professional advisors, industry partners, authorities and regulators to promote the safety, security and integrity of our Services, find and address fraud and other illegal activity or security and technical issues; and

6.1.4 Law enforcement or government agencies when required by law or to protect our interests.

Please note that when affiliate Services and third-party services which are not governed by this Policy are provided to you, you will be governed by their own terms and privacy policies.

6.2 Public Information

6.2.1 The following information is publicly visible:

(a) IDA details and ownership (on-chain);

(b) GRSA allocations (on-chain);

(c) Governance votes (on-chain);

(d) Public profile information;

(e) Published research content.

6.3 Business Transfers

6.3.1 In the event of a merger, acquisition, or asset sale, your information may be transferred. We will notify you before any transfer and give you options regarding your data.

7. **INTERNATIONAL DATA TRANSFERS**

7.1 Global Operations and Server Locations

7.1.1 OPENSCI operates globally. You acknowledge that your Personal Data will be transferred to, stored, and processed on our servers and those of our service providers located primarily in Dubai and other jurisdictions where our service providers operate.

7.1.2 We may transfer Personal Data to jurisdictions outside your own, where we have taken appropriate measures to ensure the protection of your data as required by law. It may also be processed by persons working for us or our service providers outside your country of residence. Before such international flow/process of your Personal Data, we will request your explicit consent to this transfer, storage or processing, unless certain exemptions provided for under data protection law for our international transfers applies.

7.2 Transfer Mechanisms

Some of these jurisdictions may have data protection laws that are different from the laws of your country of residence.

7.2.1 For transfers from the UAE: We ensure compliance with the UAE PDPL regarding cross-border transfers, relying on mechanisms such as adequacy decisions (if applicable to the recipient country) or ensuring appropriate safeguards are in place.

7.2.2 For transfers from the EEA/UK: Where we transfer Personal Data to countries not deemed to provide an adequate level of protection by European authorities, we rely on (i) Standard Contractual Clauses adopted by the European Commission (SCCs) (with any required UK Addendum for UK transfers); (ii) other appropriate safeguards or derogations permitted by law (e.g., Transfer Impact Assessments (TIAs)).

7.2.3 For transfers from California: For transfers involving California residents' personal information, we adhere to CCPA/CPRA requirements.

7.2.4 For transfers from Hong Kong and Singapore: Both jurisdictions have robust data protection frameworks; transfers from/to these jurisdictions are carried out under contractual safeguards and technical measures to ensure security.

7.2.5 Where local law permits, or where necessary, we will seek your explicit consent to transfer and process Personal Data abroad. By using the Platform you consent to such transfers as described.

7.3 Blockchain Nature

By using the Platform, you acknowledge that On-Chain Data is replicated across a decentralized network of nodes globally and cannot be geographically restricted.

8. **HOW WE STORE ​** **AND RETAIN** **YOUR PERSONAL DATA**

8.1 Retention Periods

We recognize the importance of protecting the Personal Data of our users. We take steps to ensure that your Personal Data is protected against misuse, interference or loss, as well as unauthorized access, modification or disclosure. Your Personal Data is generally stored in our or our affiliates' computer databases and/or with third party storage providers. For information held on our computer databases, we have implemented data security guidelines to ensure that your Personal Data is managed securely. For shipping information, such data shall be retained only as long as needed to complete delivery and meet legal obligations. For the purpose of compliance, fraud prevention and auditing, Personal Data such as membership information and purchase histories may be retained longer, we undertake to retain relevant data only for the minimum period necessary.

8.2 Deletion Requests

8.2.1 Upon account deletion:

(a) Off-chain personal data will be deleted or anonymized;

(b) On-chain data CANNOT be deleted;

(c) Some data may be retained for legal compliance.

9. **YOUR RIGHTS**

9.1 General Rights

9.1.1 Subject to applicable law and certain limitations (especially regarding On-Chain Data), you have the right to:

| Right            | Description                                                                                                                          |
| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| Access           | Request confirmation of whether we process your data and a copy of that data.                                                        |
| Rectification    | Correct inaccurate or incomplete off-chain                                                                                           |
| Erasure          | Request deletion of your off-chain data when it is no longer necessary for the purposes collected.                                   |
| Portability      | Receive data in portable format                                                                                                      |
| Objection        | Object to processing based on legitimate interests or for direct marketing.                                                          |
| Restriction      | Request that we limit the processing of your data under certain conditions                                                           |
| Withdraw Consent | Where processing is based on consent, withdraw it at any time (this does not affect the lawfulness of processing prior to withdrawal |

9.2 Region Specific Rights

9.2.1 United Arab Emirates (under UAE PDPL)

Data subjects in the UAE may exercise rights to access, rectify, erase, restrict processing, stop processing, object and portability as provided under UAE PDPL. Complaints may be made to the UAE Data Office where available.

9.2.2 EU/UK (under GDPR/UK-GDPR)

Data subjects have rights set out in GDPR (access, rectification, erasure, restrict, data portability, object, and not to be subject to automated decision-making, right to lodge complaint with supervisory authority). We will respond to verified requests without undue delay and, where required, within 30 days (extendable as permitted by law).

9.2.3 California (under CCPA/CPRA)

California residents have rights to know, delete, correct, opt-out of sale, or sharing, limit use of sensitive personal information, and non-discrimination. To the extent CCPA applies, we will comply with lawfully submitted requests in the required timeframe.

9.3 Exercising Your Rights

9.3.1 To exercise your rights, contact us at: Email: \[\*] Response Time: Within 30 days (or as required by applicable laws)

9.4 Blockchain Data Limitations

You explicitly understand and agree that due to the immutable nature of blockchain technology, OPENSCI CANNOT fulfill requests for erasure, rectification, restriction, or objection regarding data that has already been published On-Chain. Your rights under privacy laws effectively apply only to Off-Chain Data held on our centralized servers.

10. **DATA SECURITY**

10.1 Security Measures

We implement appropriate security measures including:

10.1.1 Technical Measures

(a) Encryption in transit (TLS) and at rest

(b) Access controls and authentication

(c) Regular security audits

(d) Smart contract audits

10.1.2 Organizational Measures

(a) Staff training on data protection

(b) Access limited to authorized personnel

(c) Incident response procedures

(d) Data protection impact assessments

10.2 Incident Response

10.2.1 In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons:

(a) We will notify affected data subjects without undue delay where required by applicable law and provide information on the nature of the breach, likely consequences, measures taken, and contact information;

(b) We will notify supervisory authorities as required;

(c) We will take steps to mitigate the impact.

11. **COOKIES AND TRACKING**

11.1 Types of Cookies

| Type       | Purpose                |
| ---------- | ---------------------- |
| Essential  | Platform functionality |
| Functional | User preferences       |
| Analytics  | Usage analysis         |
| Marketing  | Targeted content       |

11.2 Cookie Choices

11.2.1 We use cookies and similar technologies to enhance your experience and for analytics purposes.

11.2.2 “Essential Cookies” are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services. You can set your browser to block or alert you about these cookies, but that will cause some parts of our Services to not work. These cookies do not store any personally identifiable information.

11.2.3 You can adjust your cookie preferences through your browser settings. To disable cookies through your browser, follow the instructions usually located within the “Help,” “Tools” or “Edit” menus in your browser. Please note that disabling a cookie or category of cookies does not delete the cookie from your browser unless manually completed through your browser function.

11.2.4 Collection of your data from our analytics cookies can be deleted. If cookies are deleted, the information collected prior to the preference change may still be used. However, we will stop using the disabled cookie to collect any further information from your user experience.

12. **CHILDREN'S PRIVACY**

12.1 The Platform is not intended for users under 18 years of age. We do not knowingly collect personal information from children.

12.2 If we become aware of data collected from a child, we will delete it promptly. If you become aware that any child is accessing or using the Services, please notify us so that we can take prompt action to prevent them from accessing or using the Services.

13. **RESEARCH DATA**AND ETHICS

13.1 Special Categories of Data in Research

13.1.1 Scientific research data uploaded to the Platform may sometimes contain "special categories" of personal data (e.g., health data, genetic data, biometric data of research subjects).

13.2 User Responsibilities

13.2.1 If you upload research data to the Platform, You are solely responsible for ensuring that:

(a) You have obtained all necessary explicit consents from research subjects, or have another valid legal basis (e.g., approved ethics committee waiver) to collect and share their data.

(b) The data has been appropriately de-identified or pseudonymized before uploading, whenever possible.

(c) Your actions comply with all applicable laws and ethical guidelines governing human subject research.

13.3 Platform Role

13.3.1 The Platform acts merely as technical infrastructure (a data processor or conduit) for research data uploaded by users. OPENSCI does not review, verify, or assume responsibility for the ethical compliance or legal basis of research data uploaded by users.

14. **UPDATES TO THIS POLICY**

14.1 Changes

14.1.1 We may update this Policy from time to time. Material changes will be communicated via:

(a) Notice on the Platform;

(b) Email to registered users;

(c) Updated effective date.

14.2 Review

14.2.1 We encourage you to review this Policy periodically.

15. **CONTACT US**

15.1 General Inquiries & Complaints

In compliance with the data privacy obligations, we commit to resolve all related complaints about our collection and use of your Personal Data. For any questions regarding this Policy, to exercise your rights or with inquiries or complaints regarding our handling of Personal Data, please contact us at: \[\*].
