---
title: "Privacy Policy"
description: "How Overlayer Labs Ltd collects, uses, retains and transfers personal data across its websites, interfaces and off-chain infrastructure. Version 1.0."
canonical_url: https://docs.overlayer.fi/legal/privacy_policy
md_url: https://docs.overlayer.fi/legal/privacy_policy.md
last_updated: 2026-05-05T15:42:56.000Z
---

# Privacy Policy

> How Overlayer Labs Ltd collects, uses, retains and transfers personal data across its websites, interfaces and off-chain infrastructure. Version 1.0.

**Version:** 1.0

**Last Revised:** April 2026

---

## Important Notice — Please Read Carefully

This Privacy Policy (the "**Privacy Policy**") explains how Overlayer Labs Ltd, a business company incorporated under the laws of the British Virgin Islands (the "**Controller**", "**Overlayer Labs**", "**we**", "**us**" or "**our**"), collects, uses, discloses, retains, transfers and otherwise processes information, including personal data, in connection with its websites, interfaces, applications and related off-chain infrastructure (together, the "**Services**", as further defined below and in the Terms of Use).

This Privacy Policy is intended to comply, as applicable, with the EU General Data Protection Regulation 2016/679 ("**GDPR**"), the UK GDPR and Data Protection Act 2018 ("**UK GDPR**"), the Swiss Federal Act on Data Protection ("**FADP**"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("**CCPA/CPRA**"), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, "**LGPD**"), Canada's Personal Information Protection and Electronic Documents Act ("**PIPEDA**") and analogous data-protection Laws in other jurisdictions, in each case to the extent they apply to our processing of your personal data.

It must be read together with the **Terms of Use**, the **Cookie Policy**, the **Protocol Risk Disclosure**, the **Legal Disclaimers** and the **Regulatory Overview**. Capitalized terms used but not defined in this Privacy Policy have the meaning given to them in the Terms of Use.

**By accessing, browsing or using the Services in any manner — including by clicking "I agree", "Connect wallet", or any similar button — you acknowledge that you have read and understood this Privacy Policy.** If you do not understand or do not accept the practices described here, you must not access or use the Services.

This Privacy Policy does **not** apply to the Overlayer Protocol, any smart contract, any blockchain, any third-party wallet, any third-party website, any Third-Party Protocol, or any Third-Party Service, each of which is independent of the Controller and, where applicable, subject to its own privacy notices and practices.

---

## 1. Controller, Contact and Legal Framework

### 1.1 Data Controller

For purposes of GDPR, UK GDPR, FADP, LGPD, CCPA/CPRA and similar Laws, the "controller" (or "business", as applicable) responsible for the processing of your personal data in connection with the Services is:

**Overlayer Labs Ltd**
A business company incorporated in the British Virgin Islands
Registered office: as disclosed on the Website
Email: **privacy@overlayer.fi** (or, if not operational, **business@overlayer.fi**)

### 1.2 Role of the Overlayer Foundation and Other Ecosystem Entities

The Overlayer ecosystem may include the Overlayer Foundation, a foundation company incorporated in the Cayman Islands (the "**Foundation**"), and may in future include other Ecosystem Entities (such as SPVs, associations, DAOs, wrapper structures or similar vehicles). Unless expressly stated otherwise in a separate written agreement with you or in a specific privacy notice issued by such entity:

(a) the Foundation and the other Ecosystem Entities are **not** the data controller in respect of the processing described in this Privacy Policy;

(b) the Foundation and the other Ecosystem Entities do **not** assume any data-protection obligations towards you by virtue of your use of the Services; and

(c) nothing in this Privacy Policy shall be construed as creating a contractual, custodial, fiduciary or advisory relationship between you and the Foundation or any other Ecosystem Entity.

Where, from time to time, an Ecosystem Entity does act as a controller for specific processing activities (for example, in connection with grant programmes, institutional partnerships or governance activities), that entity will publish its own privacy notice covering the relevant processing.

### 1.3 EU/UK Representative (if applicable)

Where required under Article 27 of GDPR or UK GDPR, the Controller may designate an EU and/or UK representative, whose identity and contact details will be published on the Website. Individuals in the EU or UK may contact the designated representative directly on all issues related to the processing of their personal data.

### 1.4 Relationship with Other Policies

This Privacy Policy incorporates by reference, and must be read together with, the Cookie Policy (which describes in detail our use of cookies and similar technologies) and the Terms of Use (which govern your broader relationship with the Controller). In the event of any conflict between this Privacy Policy and the Cookie Policy on cookie-related matters, the Cookie Policy shall prevail. In the event of any conflict between this Privacy Policy and the Terms of Use on non-privacy matters, the Terms of Use shall prevail.

---

## 2. Definitions

For purposes of this Privacy Policy:

**"Personal Data"** has the meaning given to "personal data" under GDPR and UK GDPR, "personal information" under CCPA/CPRA, "personal data" under LGPD, or any equivalent term under any other applicable data-protection Law. In general, it means any information relating to an identified or identifiable natural person.

**"Processing"** means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure or destruction.

**"Processor"** means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.

**"Services"** has the meaning given in the Terms of Use, and includes, without limitation, the Website (overlayer.fi, dapp.overlayer.fi, docs.overlayer.fi and any related domain), the App, the Documentation, dashboards, analytics, APIs, SDKs and Official Channels operated by or on behalf of the Controller.

**"User"**, "**you**" or "**your**" means any visitor, user or recipient of the Services, whether or not registered.

**"Wallet"**, "**Digital Asset**", "**Protocol**", "**Overlaid Assets**", "**OVER**", "**Third-Party Protocols**", "**Third-Party Services**", "**Prohibited Person**" and "**Prohibited Jurisdiction**" have the meanings given to them in the Terms of Use.

---

## 3. Scope and Minimization Principle

### 3.1 Minimization as a Design Principle

The Services are designed to minimize the collection and processing of Personal Data. Consistent with our non-custodial architecture, the Controller:

(a) does **not** require you to create an account, register, submit government-issued identification, or provide your name, address, date of birth or financial statements to access the Services in their default configuration;

(b) does **not** operate internal ledgers or balance accounts for you;

(c) does **not** hold custody of your Digital Assets, private keys, seed phrases or signing credentials; and

(d) does **not** perform individualized profiling for advertising or behavioural marketing purposes.

### 3.2 What We Nevertheless Process

Notwithstanding the minimization principle, the mere operation of the Services necessarily involves the processing of certain technical, usage and wallet-related information, as described in Section 4. Such information may, alone or in combination with other data (including on-chain data), constitute Personal Data under applicable data-protection Laws, and we therefore describe our practices in this Privacy Policy accordingly.

### 3.3 When This Privacy Policy Applies

This Privacy Policy applies to:

(a) information we process when you access or use the Website, App, dashboards, APIs, SDKs, Documentation or Official Channels operated by or on behalf of the Controller;

(b) information we process when you communicate with us by email or through support tools;

(c) information we process for security, anti-abuse, fraud-prevention, compliance, AML/CFT, sanctions-screening and analytics purposes; and

(d) information we process in connection with any business transaction, corporate reorganization, investor relations or legal proceedings to which the Controller is a party.

It does **not** apply to: (i) the Protocol and on-chain interactions conducted directly on public blockchains; (ii) third-party wallets (such as MetaMask), exchanges, custodians, bridges, oracles, RPC providers, indexers or other Third-Party Services; (iii) Third-Party Protocols (such as Aave V3); (iv) social networks (such as X (Twitter), Telegram or Discord); or (v) any independent front-end, SDK, tool or integration operated by persons other than the Controller, even if such tools are presented as interacting with the Protocol.

---

## 4. Categories of Personal Data We Process

The categories of information we may process in connection with the Services include the following.

### 4.1 Technical and Usage Data

Collected automatically when you interact with the Services, this may include:

(a) IP address (processed, where possible, in truncated or otherwise pseudonymized form for security, routing and analytics purposes);

(b) device identifiers, device type, operating system, browser type and version, language settings, approximate (coarse-grained) geolocation inferred from IP address;

(c) referrer URLs, pages visited, features used, clicks, navigation paths, session duration, time and dates of access, error logs and performance metrics;

(d) network requests, HTTP headers and similar technical signals; and

(e) security-relevant information (such as indicators of bot activity, denial-of-service attempts, credential-stuffing attempts or other abuse).

### 4.2 Wallet and Interaction Data (Pseudonymous)

This may include:

(a) public blockchain addresses that you connect to the Interface;

(b) transaction hashes, transaction parameters and on-chain interactions that the Interface surfaces to, or constructs for, you;

(c) historical on-chain activity associated with the public addresses you connect (which is available to any third party and not private by nature);

(d) protocol parameters, strategy selections and configuration choices made in the Interface, to the extent processed off-chain; and

(e) signatures, signed messages and similar artefacts voluntarily produced by you to authenticate to specific features.

We treat Wallet and interaction data as pseudonymous. However, depending on circumstances, such data may constitute Personal Data under applicable Laws when combined with other information that, directly or indirectly, identifies you.

### 4.3 Communication Data

When you contact us by email, support tool, Official Channel or otherwise, we may process:

(a) your name, email address, handle or alias;

(b) the subject and content of your communication, including any voluntarily submitted information, screenshots, transaction hashes, logs, feedback, bug reports, complaints or inquiries; and

(c) any attachments you choose to send.

### 4.4 Cookie and Analytics Data

Collected via cookies, pixels, SDKs, tags, local storage, server logs and similar technologies. Our use of cookies is described in detail in the Cookie Policy. In general, these technologies enable us to operate the Services, support security, measure and improve usage, and, where applicable, remember your preferences.

### 4.5 Compliance, Sanctions and Anti-Abuse Data

To comply with applicable Laws and to protect the integrity of the Services, we may process:

(a) screening results associated with public blockchain addresses (for example, sanctions hits, OFAC matches, or high-risk exposure classifications generated by reputable compliance providers such as TRM Labs, Chainalysis, Elliptic or similar);

(b) IP-based geolocation for the purposes of geo-blocking or IP-blocking access from Prohibited Jurisdictions;

(c) records of enforcement measures we have taken (for example, blocklists, deny-lists, access restrictions) and related justifications; and

(d) logs reflecting attempted or actual breaches of the Terms of Use.

### 4.6 Business and Professional Contacts

If you interact with us as a counterparty, vendor, partner, investor, grant recipient, ecosystem participant, contributor or service provider, we may process your business contact information, corporate details, transaction and payment details, compliance documentation (including KYC/KYB information where required), and records of our interactions.

### 4.7 Data We Do Not Intentionally Collect

The Controller does **not** intentionally collect:

(a) "special category" data under Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, or data concerning sexual orientation or sexual life);

(b) criminal-offence data under Article 10 GDPR (except to the extent incidentally processed in sanctions-screening or as part of fulfilling legal obligations, as permitted by Law);

(c) Personal Data of children under the age of 18 (see Section 14); or

(d) Personal Data beyond what is reasonably necessary for the purposes described in this Privacy Policy.

If you voluntarily provide any of the foregoing without our request, you do so at your own risk, and the Controller may delete or anonymize it.

---

## 5. Sources of Personal Data

We obtain Personal Data from the following sources:

(a) **Directly from you**, when you access or use the Services, connect a Wallet, submit support requests, subscribe to updates or communicate with us;

(b) **Automatically**, through cookies, tags, log files, pixels, SDKs and similar technologies when you interact with the Services;

(c) **From the public blockchain**, including public Wallet addresses, transaction history and protocol-level data that is by nature publicly accessible; and

(d) **From third parties**, such as: (i) analytics and infrastructure providers (for example, hosting, CDN, security, monitoring and error-tracking vendors); (ii) blockchain-analytics and compliance providers (such as TRM Labs, Chainalysis, Elliptic or similar, where applicable); (iii) public sanctions, AML/CFT or restricted-party registries; (iv) our professional advisers; (v) our affiliates, service providers or partners; and (vi) any person who lawfully submits information about you to us (for example, a complainant).

---

## 6. Purposes and Legal Bases for Processing

Where GDPR, UK GDPR or an analogous framework applies, we process Personal Data for the following purposes and on the following legal bases. Where more than one legal basis may apply, we rely on the one that is most appropriate in the relevant context.

### 6.1 Providing, Operating and Maintaining the Services

To operate, maintain, secure and make available the Website, App, Documentation, dashboards, APIs, SDKs, Official Channels and related Services; to enable you to view information about the Protocol, Overlaid Assets, the OVER token, pools, strategies and Third-Party Protocols; to construct transactions at your request; and to respond to your technical actions.

Legal bases: **performance of a contract** (Article 6(1)(b) GDPR — the Terms of Use) and/or **legitimate interests** (Article 6(1)(f) GDPR) in operating a non-custodial technical interface.

### 6.2 Security, Abuse Prevention and Integrity of the Services

To monitor, detect, investigate, prevent, mitigate and respond to fraud, abuse, bots, credential-stuffing, denial-of-service attacks, malware, exploitation, phishing, impersonation, market manipulation, sybil attacks, unauthorized access and other security, technical or integrity incidents; to maintain logs; to enforce the Terms of Use and prohibited-use provisions; and to defend against, or investigate, actual or potential misuse of the Services.

Legal bases: **legitimate interests** (Article 6(1)(f) GDPR) in protecting the Services, the Controller, other Users and third parties; and, where applicable, **compliance with legal obligations** (Article 6(1)(c) GDPR).

### 6.3 Compliance with Laws, Sanctions and AML/CFT Requirements

To comply with, and to demonstrate compliance with, applicable Laws, including anti-money-laundering, counter-terrorist-financing, sanctions, tax, consumer-protection and securities Laws; to conduct sanctions, PEP, OFAC, EU, UK, UN and restricted-party screening on public Wallet addresses and, where applicable, on counterparties; to maintain compliance records; to respond to lawful requests from Governmental Authorities; and to cooperate with law-enforcement and regulatory investigations.

Legal bases: **compliance with legal obligations** (Article 6(1)(c) GDPR); **legitimate interests** (Article 6(1)(f) GDPR) in maintaining a lawful and compliant posture; and, where applicable, **substantial public interest** (Article 9(2)(g) GDPR) for any incidental processing of criminal-offence or sensitive data.

### 6.4 Analytics, Research and Improvement of the Services

To analyse aggregated usage, to measure the performance of the Services, to understand how Users interact with features, to identify bugs and friction points, to test improvements, and to develop, design and improve existing and new features. Wherever technically feasible, we rely on aggregated or anonymized data for these purposes.

Legal bases: **legitimate interests** (Article 6(1)(f) GDPR) in understanding and improving our Services; and, where required by applicable Laws (in particular for non-essential cookies), your **consent** (Article 6(1)(a) GDPR).

### 6.5 Communications, Support and Ecosystem Engagement

To respond to inquiries, support requests and bug reports; to provide technical assistance; to send service-related communications (such as security alerts, material updates to these legal documents, downtime or incident notifications); to notify you of material changes to the Services; and to manage any subscriptions to updates or newsletters to which you have affirmatively opted in.

Legal bases: **performance of a contract** (Article 6(1)(b) GDPR); **legitimate interests** (Article 6(1)(f) GDPR) in communicating with Users; and, for opt-in marketing communications, **consent** (Article 6(1)(a) GDPR).

### 6.6 Corporate, Legal and Administrative Purposes

To establish, exercise or defend legal claims; to respond to or cooperate with regulators, auditors, or law-enforcement authorities; to evaluate, plan, negotiate and effect mergers, acquisitions, reorganizations, financings, insolvencies or other business transactions; and to manage our accounting, audit, tax, insurance and record-keeping obligations.

Legal bases: **legitimate interests** (Article 6(1)(f) GDPR) in protecting our business and rights; and **compliance with legal obligations** (Article 6(1)(c) GDPR).

### 6.7 No Automated Decision-Making with Legal Effects

We do not conduct automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Sanctions and abuse-screening tools may flag Wallet addresses for human review and enforcement, but decisions to restrict access are based on the human or organizational application of our policies, not a solely automated process.

### 6.8 No Sale or "Sharing" of Personal Information in the CCPA/CPRA Sense

The Controller does not "sell" Personal Data for monetary consideration in the ordinary sense of that term, and does not "share" Personal Data for cross-context behavioural advertising as defined under CCPA/CPRA. To the extent any activity could nevertheless be deemed a "sale" or "sharing" under applicable Laws, we describe those activities and your rights in Section 12.

---

## 7. Cookies and Similar Technologies

We use cookies and similar technologies (including pixels, tags, SDKs, local storage and server logs) in connection with the Services. A detailed description of our use of such technologies, including their categories (strictly necessary, performance and analytics, functionality, and targeting), their sources, their retention, and how you can manage or disable them, is set out in the **Cookie Policy**, which is incorporated by reference into this Privacy Policy.

Where consent is required under the EU ePrivacy Directive, UK PECR or analogous Laws for the placement or reading of non-essential cookies, we will obtain such consent through the cookie banner or settings tool before deploying such cookies. You may withdraw your consent at any time through the same mechanism, without affecting the lawfulness of any processing carried out on the basis of consent before withdrawal.

---

## 8. Disclosures and Recipients of Personal Data

We may disclose Personal Data to the following categories of recipients, in each case subject to appropriate contractual, technical and organizational safeguards where required.

### 8.1 Service Providers and Processors

We engage Processors who process Personal Data on our behalf and under our documented instructions, including:

(a) **hosting, cloud and CDN providers** (such as Cloudflare or equivalents);

(b) **analytics providers** (such as Google Analytics or equivalents) for aggregated performance and usage metrics;

(c) **security, anti-bot, anti-abuse and error-monitoring providers**;

(d) **blockchain-analytics and compliance providers** (such as TRM Labs, Chainalysis or Elliptic or equivalents) for AML/CFT, sanctions, fraud and risk screening;

(e) **email, communications and customer-support providers**;

(f) **RPC, indexing, node and data-infrastructure providers** to the extent we process any identifiable data through them; and

(g) **enterprise resource, accounting, billing, document-management and operational tools**.

Each such Processor is bound by written contractual obligations consistent with Article 28 GDPR (or equivalent), including obligations of confidentiality, security, subprocessor management and, where applicable, international-transfer safeguards.

### 8.2 Professional Advisers

We may disclose Personal Data to our legal counsel, auditors, tax advisers, insurers and other professional advisers, where reasonably necessary for the purposes described in this Privacy Policy.

### 8.3 Affiliates and Ecosystem Entities

We may share Personal Data with our affiliates and, where relevant, with Ecosystem Entities (such as the Foundation), subject to appropriate safeguards and solely to the extent necessary to operate, maintain, secure or improve the Services, to coordinate ecosystem activities, or to respond to legal and regulatory obligations.

### 8.4 Governmental Authorities and Third Parties for Legal Purposes

We may disclose Personal Data to Governmental Authorities, courts, regulators, law-enforcement agencies and similar bodies, as well as to third parties, where we determine in good faith that such disclosure is required or permitted by Law, or is reasonably necessary to:

(a) comply with applicable Laws, court orders, subpoenas, warrants, lawful requests, sanctions measures, or similar legal process;

(b) respond to a regulatory inquiry, investigation or supervisory action;

(c) establish, exercise or defend legal claims;

(d) protect the rights, property, interests, integrity or safety of the Controller, its affiliates, its Users, the ecosystem or third parties;

(e) detect, prevent, investigate or address fraud, security, technical or AML/sanctions issues; or

(f) enforce the Terms of Use, the Protocol Risk Disclosure, this Privacy Policy or the Cookie Policy.

### 8.5 Business Transactions

If the Controller is involved (directly or indirectly) in a merger, acquisition, reorganization, restructuring, sale of all or substantially all of its assets, financing, joint venture, insolvency, bankruptcy or similar transaction, Personal Data may be transferred or disclosed as part of such transaction, subject to appropriate confidentiality safeguards. We will provide notice where required by Law.

### 8.6 Third Parties at Your Direction

Where you direct us to share Personal Data with a third party (for example, a third-party integrator or partner), we may do so. The third party's processing is governed by its own policies and terms, and we are not responsible for it.

### 8.7 No Sale of Personal Data

The Controller does not sell Personal Data for monetary consideration in the ordinary sense of that term and, to the best of its knowledge, has not done so in the preceding twelve (12) months.

---

## 9. International Transfers of Personal Data

### 9.1 Global Processing

Because the Controller is incorporated in the British Virgin Islands and relies on global infrastructure providers, your Personal Data may be transferred to, stored in, accessed from and otherwise processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.

### 9.2 Safeguards for Transfers Outside the EEA/UK/Switzerland

Where GDPR, UK GDPR or FADP applies, and where we transfer Personal Data outside the European Economic Area, the United Kingdom or Switzerland (as applicable) to a country that has not been the subject of an adequacy decision, we rely on one or more of the following safeguards:

(a) an **adequacy decision** by the European Commission, the UK Government or the Swiss Federal Council for the destination country;

(b) **Standard Contractual Clauses** approved by the European Commission (2021/914/EU), the UK's International Data Transfer Agreement or Addendum, and/or the Swiss equivalent, supplemented as necessary by additional technical, contractual and organizational safeguards following a transfer impact assessment;

(c) **binding corporate rules**, where applicable; or

(d) any **derogation** permitted under Article 49 GDPR (or equivalent), such as your explicit consent, necessity for contractual performance, or necessity for the establishment, exercise or defence of legal claims.

Copies or summaries of the relevant safeguards can be requested by contacting **privacy@overlayer.fi**, subject to appropriate redactions to protect commercially sensitive information and the rights of third parties.

### 9.3 Transfers in Connection with Blockchain Activity

Public blockchains are inherently global and decentralized. Any Personal Data recorded on, or inferable from, a public blockchain is by nature accessible from anywhere in the world. We do not control such data and cannot apply contractual or technical safeguards to it. By using the Services and interacting with the Protocol, you acknowledge this and accept the associated cross-border implications.

---

## 10. Data Retention

### 10.1 General Principle

We retain Personal Data only for as long as is reasonably necessary to fulfil the purposes described in this Privacy Policy, including to satisfy any legal, accounting, regulatory, compliance, tax, audit, reporting or record-keeping requirements, to enforce our agreements, to protect our rights and those of third parties, and to manage legal claims.

### 10.2 Retention Criteria

Retention periods vary depending on the category of data and the purposes of processing, taking into account factors such as:

(a) the duration of your use of the Services;

(b) the nature and sensitivity of the Personal Data;

(c) applicable statutory, regulatory or contractual retention obligations (for example, AML/CFT or tax retention periods that may extend to five to ten (5–10) years);

(d) the applicable statutes of limitation and periods during which legal claims may be made; and

(e) our legitimate interests in maintaining security, preventing abuse, detecting fraud and defending against legal claims.

### 10.3 Indicative Retention Periods

Without limiting Section 10.1, indicative retention periods include: (i) server logs and security telemetry — typically retained for up to twelve (12) months, and longer where necessary to investigate or respond to specific incidents; (ii) analytics data — retained in aggregated or pseudonymized form, consistent with the settings of the relevant analytics provider; (iii) cookie data — retained for the durations set out in the Cookie Policy; (iv) communications and support tickets — retained for the duration of our relationship with you and for a reasonable period thereafter to address follow-up or legal matters; (v) compliance records (sanctions screening, enforcement actions, Wallet blocklists) — retained for as long as necessary to meet applicable legal obligations and to defend against legal claims; and (vi) records relating to legal claims, disputes or regulatory investigations — retained until resolution and for the applicable limitation period thereafter.

### 10.4 Deletion or Anonymization

When Personal Data is no longer needed for the purposes for which it was collected or required to be retained, we will delete, destroy or irreversibly anonymize it in a secure manner, except to the extent that we are required or permitted by Law to retain it (for example, for backup integrity, legal hold, or demonstrable compliance purposes).

### 10.5 Blockchain Data Cannot Be Deleted

You acknowledge and agree that Personal Data, to the extent it is or becomes associated with a public blockchain (for example, a public Wallet address and its transaction history), is intrinsically immutable and publicly accessible. Neither the Controller nor any other person can edit, correct, restrict, erase or render unavailable such on-chain records. Any rights you may have to rectification, erasure, restriction or portability under applicable data-protection Laws cannot, by design, be exercised against blockchain records. This is an inherent feature of public blockchain technology.

---

## 11. Security

### 11.1 Technical and Organizational Measures

We implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks for individuals. Such measures may include, without limitation:

(a) access controls and the principle of least privilege;

(b) encryption in transit and, where appropriate, at rest;

(c) network segmentation, firewalls, bot and DDoS mitigation;

(d) logging, monitoring and anomaly detection;

(e) vulnerability management, patching and secure development practices;

(f) employee and contractor training, and confidentiality commitments; and

(g) documented incident-response procedures.

### 11.2 No Absolute Security

No method of transmission over the internet, and no method of electronic storage, is completely secure. The Controller cannot and does not guarantee absolute security. **You are solely responsible for the security of your Wallet, private keys, seed phrases, devices, credentials and authentication factors.** We strongly recommend that you use hardware wallets, multi-factor authentication, reputable anti-malware tools, up-to-date devices and browsers, and prudent operational-security practices.

### 11.3 Incident Notification

In the event of a personal-data breach that is reasonably likely to result in a risk to the rights and freedoms of affected individuals, the Controller will comply with applicable notification obligations, including, where required, notifying the competent supervisory authority and/or affected individuals within the time periods required by applicable Laws.

---

## 12. Your Rights

### 12.1 Rights under GDPR, UK GDPR and FADP

If GDPR, UK GDPR or FADP applies to you, you have, subject to the conditions and limitations set out in the relevant Laws, the following rights in respect of your Personal Data:

(a) **Right of access** — to obtain confirmation as to whether or not we process your Personal Data and, if so, to receive a copy of such data and information about the processing;

(b) **Right to rectification** — to request correction of inaccurate or incomplete Personal Data;

(c) **Right to erasure ("right to be forgotten")** — to request deletion of Personal Data in certain circumstances, subject to the limitations set out in Section 10.5 regarding blockchain data;

(d) **Right to restriction of processing** — to request restriction of processing in certain circumstances;

(e) **Right to data portability** — to receive Personal Data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible;

(f) **Right to object** — to object, on grounds relating to your particular situation, to processing based on legitimate interests (Article 6(1)(f) GDPR), and to object at any time to processing for direct-marketing purposes;

(g) **Right to withdraw consent** — where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

(h) **Right not to be subject to solely automated decisions** with legal or similarly significant effects; and

(i) **Right to lodge a complaint** with a supervisory authority, in particular in the EU/UK/Swiss country where you live, work or where the alleged infringement occurred.

### 12.2 Rights under CCPA/CPRA (California Residents)

If you are a resident of California, you may have, subject to applicable conditions and limitations, the following rights:

(a) **Right to know** — the categories and specific pieces of Personal Information we have collected, the sources, the purposes and the categories of third parties to whom we disclosed it;

(b) **Right to delete** — Personal Information we have collected from you, subject to exceptions (including, for example, retention obligations, security, fraud prevention and legal claims);

(c) **Right to correct** — inaccurate Personal Information;

(d) **Right to opt out** — of the "sale" or "sharing" of Personal Information (noting that we do not sell or share Personal Information in the sense defined by CCPA/CPRA, as described in Section 8.7);

(e) **Right to limit the use of sensitive personal information** — to the extent we process such data (we do not intentionally do so);

(f) **Right to non-discrimination** — we will not discriminate against you for exercising any of your CCPA/CPRA rights; and

(g) **Right to designate an authorized agent** to submit requests on your behalf, subject to verification.

You may submit a verifiable request by emailing **privacy@overlayer.fi** with sufficient information for us to verify your identity and the scope of your request.

### 12.3 Rights under LGPD (Brazilian Users)

If you are in Brazil, you have, subject to the conditions of the LGPD, the rights to: (i) confirm the existence of processing; (ii) access your data; (iii) correct incomplete, inaccurate or outdated data; (iv) anonymize, block or erase unnecessary or excessive data, or data processed in non-compliance with the LGPD; (v) data portability; (vi) delete Personal Data processed on the basis of consent; (vii) information about entities with which we have shared data; (viii) information about the possibility of not providing consent and the consequences of refusal; (ix) withdraw consent; and (x) oppose processing carried out on a basis other than consent where there is non-compliance.

### 12.4 Rights under PIPEDA and Other Regimes

If you are located in Canada or another jurisdiction with applicable data-protection Laws, you may have comparable rights to access, correction, withdrawal of consent and complaint mechanisms, subject to the conditions of those Laws.

### 12.5 Exercising Your Rights

To exercise any right, please contact us at **privacy@overlayer.fi**. We may need to:

(a) verify your identity before acting on a request, in particular where the request is made in respect of Personal Data associated with a specific public Wallet address (in which case we may require you to sign a message from that Wallet);

(b) decline or limit the scope of your request where an exemption, exception or limitation under applicable Law applies (for example, where compliance would reveal a third party's Personal Data or would prejudice an ongoing investigation); and

(c) charge a reasonable fee, or refuse to act on a manifestly unfounded or excessive request, to the extent permitted by Law.

We will generally respond to verified requests within the time limits required by applicable Laws (typically one (1) month under GDPR/UK GDPR, forty-five (45) days under CCPA/CPRA, or as otherwise required).

### 12.6 Blockchain and Third-Party Limitations

Certain rights cannot, by design, be exercised against on-chain data or against third parties (including Third-Party Protocols, Third-Party Services, Wallet providers, analytics platforms, or social networks). We will make commercially reasonable efforts to assist you in contacting the relevant third parties but cannot guarantee their response or cooperation.

---

## 13. Third-Party Wallets, Services, Protocols and Links

### 13.1 Third-Party Wallets

Certain transactions conducted via the Services require you to connect a self-custodial Wallet (such as MetaMask). By using such a Wallet, you agree that your interactions with the Wallet provider are governed by that provider's own terms and privacy policies. The Controller:

(a) has no access to your Wallet, private keys or seed phrases;

(b) does not receive, process or store those credentials; and

(c) expressly disclaims any liability for any action, omission or processing of personal information by any Wallet provider.

### 13.2 Third-Party Services and Protocols

The Services may link to, integrate with, or display information from Third-Party Services (including exchanges, custodians, bridges, oracles, RPC providers, analytics providers, social networks and messaging platforms) and Third-Party Protocols (such as Aave V3). Such third parties are independent controllers or processors and operate under their own privacy and security policies. You should review those policies before interacting with such third parties. The Controller is not responsible for any privacy or security practice of any third party.

### 13.3 Links to External Sites

The Services may contain links to websites or online platforms operated by third parties, including social networks (such as X (Twitter), Telegram or Discord) and Third-Party Protocols. Following such links is at your own risk. The inclusion of any link does not constitute an endorsement by the Controller.

---

## 14. Children's Privacy

The Services are not directed to, nor intended for, children under the age of 18 (or the age of majority in their jurisdiction, if higher). The Controller does not knowingly collect Personal Data from children under the age of 18. If we become aware that we have inadvertently collected Personal Data from a child under 18, we will take steps to delete such Personal Data as soon as reasonably practicable. If you believe we may have processed information about a child under 18, please contact us at **privacy@overlayer.fi**.

---

## 15. Public Blockchain Information

We collect, observe and may process data from activity that is publicly visible on, or inferable from, public blockchains. This may include Wallet addresses, balances, transaction hashes, transaction histories, token holdings and interactions with the Protocol, Overlaid Assets, the OVER token and Third-Party Protocols. Such data may, directly or indirectly, be associated with technical data we collect via the Services (such as IP addresses), for the purposes described in Section 6.

You acknowledge that:

(a) public blockchain data is inherently public and is accessible to any person in the world;

(b) the Controller does not have custody or control over any blockchain, and cannot modify, delete, redact or restrict access to blockchain records;

(c) on-chain analytics techniques (including cluster analysis, heuristic linking and chain analysis) may be used by the Controller, by Processors or by third parties to associate Wallet addresses with individuals or entities; and

(d) you should take independent steps to protect your on-chain privacy if that is a material concern for you (for example, by using privacy-preserving tools or by consulting qualified advisers).

---

## 16. Do-Not-Track Signals and Similar Mechanisms

Many browsers and mobile devices offer "Do Not Track" (DNT), Global Privacy Control (GPC) or similar signals. At this time, and except where otherwise required by applicable Law, the Services do not respond to DNT signals. Where required by applicable Law (for example, where GPC is treated as a valid opt-out of the "sale" or "sharing" of Personal Information under CCPA/CPRA), we will honour such signals to the extent technically feasible.

---

## 17. Marketing and Direct Communications

The Controller does not conduct extensive direct-marketing campaigns and does not engage in profiling for behavioural advertising purposes. Where you have actively opted in to receive newsletters, ecosystem updates or similar communications, you may unsubscribe at any time by following the opt-out link in any such communication or by contacting **privacy@overlayer.fi**. Your unsubscription will take effect within a reasonable period.

---

## 18. Sanctions, AML/CFT and Blockchain Analytics

You acknowledge and agree that, to comply with applicable Laws and to protect the integrity of the Services, the Controller may:

(a) use blockchain-analytics tools (including services provided by reputable providers such as TRM Labs, Chainalysis or Elliptic) to screen Wallet addresses for sanctions, AML/CFT, fraud, hacking or other high-risk indicators;

(b) implement IP-based geo-blocking, Wallet blocklists, front-end gating, consent modals and similar controls, which may prevent access by Prohibited Persons and persons in Prohibited Jurisdictions;

(c) share relevant Personal Data with Governmental Authorities and law-enforcement agencies, in accordance with applicable Law; and

(d) retain compliance records for the period required by applicable Laws and by prudent risk management, which may extend for several years after any interaction.

Such measures are not guarantees, are inherently imperfect and may be circumvented. Ultimate responsibility for compliance with applicable Laws remains with you.

---

## 19. Changes to This Privacy Policy

The Controller may modify this Privacy Policy from time to time, including to reflect changes in our data-processing practices, the Services, applicable Laws or our business. When we do so, we will update the "Last Revised" date at the top of this Privacy Policy and, where required by applicable Laws or where the changes are material, provide additional notice by reasonable means (such as posting a notice on the Website, displaying an in-product banner or sending an electronic notice).

**Your continued use of the Services after the effective date of any modified Privacy Policy constitutes your acknowledgement of, and agreement to, the modified Privacy Policy**, to the extent permitted by applicable Law. If you do not agree with the modified Privacy Policy, you must stop using the Services.

---

## 20. Complaints

### 20.1 Complaints to the Controller

You may lodge any complaint with the Controller directly by contacting **privacy@overlayer.fi**. We will investigate your complaint and respond within a reasonable period.

### 20.2 Complaints to Supervisory Authorities

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular:

(a) in the EU or EEA, with the data-protection authority of the Member State where you reside, work or where the alleged infringement occurred;

(b) in the UK, with the Information Commissioner's Office (ICO);

(c) in Switzerland, with the Federal Data Protection and Information Commissioner (FDPIC);

(d) in Brazil, with the Autoridade Nacional de Proteção de Dados (ANPD);

(e) in Canada, with the Office of the Privacy Commissioner of Canada or the relevant provincial regulator; or

(f) in any other jurisdiction, with the competent authority identified under the applicable data-protection Law.

---

## 21. Disclaimers and Limitations of Liability

To the maximum extent permitted by applicable Law, and without prejudice to the Controller's obligations under applicable data-protection Laws:

(a) the Controller provides this Privacy Policy on an informational basis, and compliance by the Controller with applicable data-protection Laws is subject to the practical constraints described herein (including the immutable nature of blockchain records);

(b) the Controller is not responsible or liable for the data-processing practices of any third party, including Wallet providers, Third-Party Services, Third-Party Protocols, social networks, public blockchains, validators, miners, node operators or independent front-ends;

(c) the Controller's aggregate liability to you for any matter arising out of or in connection with this Privacy Policy or our processing of Personal Data, to the extent not prohibited by applicable Law, shall be subject to the limitations set out in the Terms of Use (including the aggregate liability cap); and

(d) the Operator Parties (as defined in the Terms of Use) are intended third-party beneficiaries of this Privacy Policy to the extent relevant and may enforce its provisions directly.

This Section 21 does not limit or exclude any liability that cannot lawfully be limited or excluded under applicable data-protection Laws.

---

## 22. How to Contact Us

If you have any questions, concerns or requests regarding this Privacy Policy or our processing of Personal Data, you may contact us at:

**Email (primary):** privacy@overlayer.fi

**Email (secondary):** business@overlayer.fi

**Mailing Address:** Overlayer Labs Ltd, as disclosed on the Website.

Where required, we will make reasonable efforts to respond within the time limits set out in applicable data-protection Laws.

---

*This Privacy Policy is designed to operate in conjunction with the Terms of Use, the Cookie Policy, the Protocol Risk Disclosure, the Legal Disclaimers and the Regulatory Overview, each as made available through the Website and updated from time to time.*
