Legal & access

Privacy Policy

This Policy describes what personal data the Xity platform collects, how it is stored and protected, and the rights you hold over it.

Version 1.1 · Canonical domain: xity.city · This Policy is issued by the Operator of the Platform and applies to all processing of personal data described herein. The Operator is the founding authority that maintains the Platform pending the constitution of formal government institutions; its contact address is published on the website. Where applicable data protection law requires a named data controller, the Operator is the controller for all processing described in this Policy.

1. Scope and application

This Policy applies to the Xity platform, including the public website, the XityChain ledger, the XityConnect identity system, the XityCoin currency system, and the SpaceNFT asset system. It covers all personal data processed in connection with those services. It does not cover services operated by third parties that link to or build on the platform; those services have their own policies.

Development phase. The Platform is in active development. The fiat-currency interface (deposit and redemption) is not open to the public during this phase, and access to some services may be restricted. Processing during this phase is limited to what is described in this Policy and necessary for operating, testing, and securing the Platform.

A distinctive feature of this platform is the separation between data recorded on the public ledger and data held on access-controlled systems. This Policy distinguishes the two throughout, because the distinction determines what can be modified or deleted and what cannot.

2. Definitions

  • “On-chain data” means data recorded as transactions on XityChain, which is immutable and publicly readable;
  • “Off-chain data” means data held on access-controlled systems operated by the Operator, including identity evidence and platform records;
  • “Identity evidence” means documents and materials submitted to verify a claim about you, including identity documents and photographs;
  • “Device-stored data” means data stored only on your device, including your Private Key and its PIN-encrypted container;
  • “Relying party” means any person or service that verifies a claim about your identity through the platform.

3. What the platform does not collect

The following is stated first because it defines the architecture. The platform does not collect, store, transmit, or process:

  • Your Private Key. It is generated on your device, encrypted with a PIN you choose, stored only on that device, and never transmitted anywhere. The Operator cannot recover, read, or reset it;
  • Your PIN. It exists only in your memory and, in derived form, on your device;
  • Biometric data. The platform does not collect fingerprints, facial scans, or voiceprints;
  • Contacts, location history, or device contents. The platform does not access your files, camera roll, or contact list;
  • Behavioural profiles for advertising. The platform runs no advertising and builds no advertising profile.

4. On-chain data (public and immutable)

When you transact on the platform, the following is recorded on XityChain and becomes publicly readable by anyone, forever:

  • Your wallet address (the string beginning xity1);
  • The public key associated with your wallet;
  • The existence, timestamps, and amounts of your transactions;
  • The counterparties of your transactions, by wallet address;
  • The registration status of your identity and credentials, without underlying evidence;
  • Governance actions, if any, that you take.

Immutability and your rights. On-chain data cannot be edited or deleted by the Operator or by anyone else. Requests to correct or erase on-chain data therefore cannot be fulfilled as to the historical record. What can be done: a current state can be superseded (for example, a credential can be revoked, changing its current status to invalid), and off-chain references to an address can be removed. The historical transaction record remains. You should assume that anything recorded on-chain is permanent and public before you transact, and you should weigh this when deciding what to do on the platform.

Pseudonymity. A wallet address is a pseudonym. It does not contain your name, and the public interfaces of the platform do not disclose the linkage between an address and an identity. The linkage is held off-chain under access controls described in Section 5.

5. Off-chain data (access-controlled)

The following data is held on access-controlled systems operated by the Operator. It is not returned over any public interface. Access is restricted by role, and every access path is separated from the public role:

  • Identity evidence. Documents and materials you submit for verification, held only for as long as necessary to support the verification status recorded on-chain;
  • Address-to-identity linkage. The mapping between your wallet address and your identity record;
  • Platform records. Session metadata for services you use, notification records, and preferences;
  • Communications. Messages you send through the contact form or to published contact addresses;
  • Newsletter subscriptions. Your email address, if you subscribe, held only for the purpose of sending public-notice alerts.

The public role of the platform’s interfaces returns only wallet balance, transaction nonce, and existence. It never returns public keys, identity names, or address-to-identity linkages. Service roles can read verification status but never identity evidence. Administrative roles are confined to systems that are not exposed on the public internet.

6. Device-stored data

Your Private Key is stored on your device in an encrypted container. The container is encrypted with an AES-256 key derived from your PIN using PBKDF2 with one hundred thousand iterations. The Operator has no access to this container, no ability to decrypt it, and no copy of its contents. If you clear your browser storage, the container is destroyed and, unless you have configured recovery, access to your wallet is permanently lost.

7. Purposes and lawful bases of processing

Off-chain personal data is processed only for the following purposes, each with its lawful basis under applicable data protection law (including the GDPR, where it applies):

  • Operating the identity and verification system you asked to use.Basis: performance of a contract (the Terms of Use) to which you are party, and your consent where the service is optional;
  • Maintaining the security and integrity of the platform.Basis: legitimate interests in preventing abuse, fraud, and unauthorized access, balanced against your rights;
  • Complying with legal obligations applicable to the Operator.Basis: legal obligation (including any AML, sanctions, or tax obligations that may apply);
  • Communicating with you about matters you have raised or subscribed to.Basis: your consent (newsletter) or legitimate interests (service communications you have initiated);
  • Keeping an audit record of state actions.Basis: legitimate interests in transparency and accountability, and legal obligation where applicable.

Data is not processed for advertising, profiling, automated decision-making about you, or sale to any third party. The platform does not sell personal data, ever.

8. Retention

  • Identity evidence: retained only as long as necessary to support the verification status recorded on-chain, then deleted;
  • Address-to-identity linkage: retained while the identity is active; deleted when the identity is revoked or dissolved;
  • Communications: retained for the period needed to handle the matter;
  • Newsletter subscriptions: retained until you unsubscribe;
  • Audit records of state actions: recorded on-chain and therefore permanent by design;
  • On-chain data: permanent by design, as described in Section 4.

9. Sharing and disclosure

The Operator does not sell, rent, or trade personal data. Off-chain data is disclosed only:

  • To a relying party, as a yes or no claim answer with a cryptographic proof, never as underlying evidence;
  • To service providers engaged to operate infrastructure, bound by confidentiality and processing only on instruction;
  • Where required by law, court order, or valid legal process, limited to what is compelled;
  • In an emergency involving a credible threat to the safety of a person, where disclosure is necessary and proportionate.

10. Security

The platform is designed on a principle of least exposure. Technical measures include: Ed25519 cryptography for all signing; role-based access control with the public role returning the minimum viable fields; server-side scrubbing of personal identifiers from public transaction views; encryption of the private key container on your device; and time-locked recovery with a twenty-four hour delay. Organisational measures include restricted administrative access and audit logging of state actions on the chain, where they cannot be quietly altered.

No system is perfectly secure. If a breach of off-chain personal data occurs that is likely to result in a risk to your rights and freedoms, the Operator will notify the competent supervisory authority without undue delay and, where required by applicable law, within seventy-two hours of becoming aware of the breach, and will notify affected persons directly where the risk to you is high. The fact and the response will also be recorded on the platform’s public record.

11. Your rights

To the extent applicable law grants you rights over your personal data, the platform honours them as follows:

  • Access. You may request a copy of off-chain personal data held about you. On-chain data is already publicly readable by you at all times;
  • Rectification. You may correct inaccurate off-chain data. On-chain records cannot be edited; superseding state can be recorded;
  • Erasure. You may request deletion of off-chain data not needed for a legal purpose or an active service. On-chain data cannot be deleted; revocation can change current status;
  • Portability. Your wallet, keys, and the public chain record are already yours and portable by design;
  • Objection and restriction. You may object to processing based on legitimate interests; the platform will cease that processing unless a compelling reason prevails;
  • Complaint. You may lodge a complaint through the contact address published on the website.

Requests are made through the contact address. The Operator responds within a reasonable period and does not charge for the first reasonable request in any twelve-month span.

12. Children

The platform is not directed at persons under 18. Wallet and identity creation is restricted to adults. If the Operator learns that off-chain personal data of a child has been collected through the platform without verified parental consent, it will delete that data.

13. Cookies and tracking

The public website sets no advertising or tracking cookies and runs no analytics. Application services may set a strictly necessary session token for the duration of your sign-in. There is no cross-site tracking of any kind.

14. International transfers

The Operator’s infrastructure and its service providers may be located in more than one jurisdiction. Where off-chain personal data is transferred to a jurisdiction that has not been recognised as providing an adequate level of data protection, the Operator will ensure that appropriate safeguards are in place, including: standard contractual clauses approved by the European Commission or an equivalent supervisory authority; binding corporate rules where the recipient is part of the same group; or another legally recognised transfer mechanism. A copy of the applicable safeguards is available on request through the contact address.

15. Changes to this Policy

The Operator may update this Policy by publishing a new version at the canonical domain. Material changes will be highlighted on the website. The current version is always the one published at the canonical domain. Updates do not apply retroactively to data already recorded on the chain, which is immutable.

16. Contact

Privacy questions, access requests, and complaints may be directed to the contact address published on the website. The Operator aims to acknowledge all privacy correspondence promptly.


Read together with the Terms of Use, which govern your use of the platform as a whole.