1. Data Collected
- Solana wallet pubkey (public on-chain data)
- KYC data (collected and reviewed directly by the Foundation) — ID document, selfie, address, contact
- KYC hash (SHA-256) — stored on-chain
- Identity check (selfie match) + sanction screening result
- GA4 — pageviews and events (anonymized)
2. Purposes
- Sybil prevention
- OFAC/SDN/PEP sanction screening (AML)
- Class-differentiated policy
- Governance vote weight computation
- Legal compliance (quarterly sanction rescreening)
3. Retention
Foundation retention: 5 years post-transaction (AML obligation) — photos and ID details are stored encrypted on the Foundation's own servers. On-chain KYC hash: permanent (Solana blockchain). GA4: 14 months.
4. Third-Party Sharing
- KYC data — not shared with any third party (stored and reviewed by the Foundation)
- Sanction lists — compared against public, free lists (OFAC SDN · UN · EU); no external vendor
- Tatum — Solana RPC (wallet addresses)
- Google Analytics 4 — anonymous usage statistics
- Upon legal request — judicial authorities
5. User Rights
Users have rights to access, correct, and delete (off-chain data only) their KYC data. On-chain KYC hashes are technically immutable.
6. Contact
privacy@dcosmos.io