VALT Foundation (“VALT,” “the Company,” “we,” “us,” or “our”) is a Singapore-incorporated entity that operates the website, token sale platform, and related wallet-linking and referral services (the “Services”) described in our Terms and Conditions. We take the protection of your personal data seriously and are committed to being transparent about how we collect, use, disclose, and safeguard it.
This Privacy Policy explains what personal data we collect from or about you, why we collect it, how we use and share it, and the choices and rights available to you. Our data processing activities are designed to comply with the Singapore Personal Data Protection Act 2012 (“PDPA”).
Because the Services involve issuing VALT Tokens on Vision Chain’s public blockchain, certain activities you undertake — such as receiving tokens into your wallet — are recorded on that public ledger. Section VI below explains what this means for your personal data and why blockchain records behave differently from the rest of the data we hold.
Unless stated otherwise, capitalized terms used in this Privacy Policy have the meanings given to them in our Terms and Conditions. This Privacy Policy applies to Users and prospective participants in the Token Sale. If you are an employee, contractor, or service provider of VALT, your personal data is instead governed by your employment or engagement agreement and our internal policies.
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
Account Data refers to information related to your VALT account, including your login credentials, account settings, and preferences.
Company (or “VALT,” “we,” “us,” or “our”) refers to VALT Foundation.
Contact Data refers to information used to communicate with you, such as your email address, telephone number, and mailing address.
Identity Data refers to information that identifies you personally, such as your full name, date of birth, and nationality.
KYC Data (Know-Your-Customer Data) refers to information and documentation collected to verify your identity and screen you against anti-money-laundering (“AML”), counter-terrorist-financing, and sanctions requirements, including a government-issued identification document or passport, a selfie photograph used to match against that document, and, where relevant, source-of-funds information.
Payment Data refers to information relating to your payment for participation in the Token Sale, such as the payment method used and payment confirmation details. VALT does not collect or store full payment-card or bank-account numbers, which are processed by our payment service providers.
Personal Data refers to any information relating to an identified or identifiable individual.
Referral Data refers to information relating to your participation in the Referral Program, including the referral relationship between you and other Users and any resulting referral benefits.
Technical Data refers to information about the devices and systems you use to access the Services, including IP address, cookie identifiers, browser type, operating system, and access timestamps.
Transaction & Vesting Data refers to information about your participation in the Token Sale, including the amount purchased, payment status, and the vesting and cliff schedule and unlock history applicable to your token allocation.
User (or “you” or “your”) refers to the individual or entity that accesses or uses the Services.
Wallet & Blockchain Data refers to information generated by or associated with the Digital Wallet address you register with the Services, including your public wallet address, transaction hashes, and on-chain token balances. Wallet & Blockchain Data does not include your private keys or seed phrase, which VALT does not collect, store, or have access to.
VALT Foundation is the controller responsible for the Personal Data you share with us when you register for an account or use any part of the Services. VALT Foundation is incorporated in Singapore.
We maintain administrative, technical, and organizational measures designed to protect your Personal Data, and we review these measures regularly. We only disclose your Personal Data with your consent, unless disclosure is required by law, necessary to verify your identity, or necessary to perform our contract with you, as further described in Section VIII below.
We may collect, use, store, and transfer the following categories of Personal Data about you:
We may also derive Aggregated Data — statistical or demographic data derived from your Personal Data — for purposes such as understanding how many Users use a given feature. Aggregated Data does not, on its own, identify you. Where we combine Aggregated Data with other data in a way that could identify you, we treat the combined data as Personal Data and handle it in accordance with this Privacy Policy.
If you do not provide the Personal Data we need — particularly Identity Data and KYC Data required by applicable AML and financial-services regulation — we may be unable to open your account, process your Token Sale participation, or continue providing part or all of the Services, and we will inform you if this is the case.
We do not collect Audio Data (call recordings or voice data). If this changes in the future — for example, if we introduce voice-based support — we will update this Privacy Policy accordingly before doing so.
Most of the Personal Data we collect comes directly from you, including when you:
As you use the Website, your device automatically transmits certain Technical Data to us, such as your IP address, device identifiers, browser type, operating system, and access timestamps. We use this information to operate, secure, and improve the Services, including to detect fraud, unauthorized access, and abuse of the Referral Program. We use cookies and similar technologies on the Website to recognize your device, remember your preferences, and understand how the Services are used. You can configure your browser to refuse or delete cookies, though this may limit some functionality of the Services.
We may receive Personal Data about you from third parties, including:
We process Personal Data on the following legal bases: (i) performance of our contract with you (our Terms and Conditions); (ii) compliance with our legal and regulatory obligations, including AML, KYC, and sanctions requirements applicable in Singapore; (iii) our legitimate interests, provided these do not override your interests or fundamental rights; and (iv) your consent, where required, such as for optional marketing communications.
The table below summarizes the principal purposes for which we process your data, the data types typically involved, and the corresponding legal basis. A given processing activity may rely on more than one legal basis.
| Purpose / Activity | Type of Data | Legal Basis |
|---|---|---|
| Account creation, onboarding, and KYC/AML identity verification | Identity, Contact, KYC Data | Performance of contract; compliance with legal obligations (AML, KYC, sanctions screening) |
| Processing your Token Sale participation, payment, and token allocation | Payment, Transaction & Vesting, Wallet & Blockchain Data | Performance of contract |
| Screening participants for anti-money-laundering and sanctions compliance | Identity, KYC Data | Compliance with legal obligations |
| Operating the Referral Program and calculating referral benefits | Referral, Identity, Contact Data | Performance of contract |
| Securing accounts, detecting and preventing fraud, unauthorized access, and referral abuse | Technical, Identity, Referral Data | Legitimate interests (platform and user security); compliance with legal obligations |
| Operating, maintaining, and improving the Website | Technical Data | Legitimate interests (service performance and improvement) |
| Communicating with you about your account, your Token Sale participation, or changes to our Terms or this Privacy Policy | Contact, Identity Data | Performance of contract; compliance with legal obligations |
| Sending optional marketing communications and community updates | Contact Data | Consent; legitimate interests |
The Services are intended for adult Users only. Because VALT requires Users to meet KYC and age-of-majority requirements under applicable law, we require your date of birth to verify eligibility. If we become aware that we have inadvertently collected Personal Data from a minor, we will delete it promptly. If you believe we have unintentionally collected data from a minor, please contact us using the details in Section XVI.
VALT Tokens are issued on Vision Chain’s public blockchain. When VALT allocates or distributes tokens to your Digital Wallet, certain information — including your public wallet address, the token amount, and a transaction hash — is recorded on Vision Chain’s public, distributed ledger.
Blockchain records are, by design, immutable and cannot be altered or deleted, including by VALT. This means that once a transaction is confirmed on-chain, VALT cannot erase, rectify, or restrict the on-chain record itself, even in response to a request under Section XI below. Where your public wallet address can be linked to your identity (for example, because you completed KYC verification with us), on-chain data connected to that address may function as Personal Data, even though it is also publicly viewable by anyone using a blockchain explorer.
We do not publish your KYC Data, Identity Data, or other off-chain Personal Data on the blockchain. VALT does not collect, store, or have access to your private keys or wallet seed phrase; these remain solely under your control, and you are responsible for safeguarding them. We are not able to recover funds, reverse transactions, or restore access to a wallet if you lose your private keys.
If you no longer wish to receive marketing newsletters or other optional promotional communications, you may contact us using the details in Section XVI, using the email address registered to your account. We will process opt-out requests within 7 business days. Please note that you cannot opt out of service-related communications, such as security alerts, KYC or Token Sale notices, or notices required by applicable law.
We may disclose your Personal Data to the following categories of recipients, where necessary for the purposes described in this Privacy Policy:
We disclose data under these circumstances only where: (i) required by law; (ii) requested by you for the processing of a transaction or other service; (iii) necessary for the performance of our contract with you; or (iv) necessary to safeguard our legitimate interests, in each case consistent with the PDPA.
We may use service providers (such as cloud hosting and KYC verification providers) located outside Singapore, in which case your Personal Data may be transferred to, stored, and processed in a country other than your country of residence, including a country that may not have data protection laws equivalent to those in your jurisdiction. Where we transfer Personal Data internationally, we take steps designed to ensure an adequate level of protection, consistent with the requirements of the PDPA.
We retain your Personal Data for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, tax, accounting, and AML record-keeping obligations. In particular, KYC Data and Transaction & Vesting Data are retained for the minimum period required under applicable Singapore law — generally at least 5 years following the end of your relationship with VALT or the completion of the relevant transaction, in line with Singapore’s AML record-keeping requirements — after which such data is securely destroyed or anonymized.
We determine appropriate retention periods considering the amount, nature, and sensitivity of the data, the risks of unauthorized access or disclosure, and applicable legal requirements. Please note that Wallet & Blockchain Data recorded on Vision Chain persists indefinitely on the public ledger and is not subject to our retention schedule, as explained in Section VI.
At the end of the applicable retention period, we securely delete or anonymize your data, and we instruct third parties to whom we transferred the data to do the same, where feasible.
Please keep your identification and contact details accurate and up to date, and notify us within 7 calendar days of any change. Subject to the PDPA, you have the following rights in relation to your Personal Data:
A. Right to Access: you may request confirmation of whether we process your data, and request a copy of the data we hold about you.
B. Right to Correction: if your data is inaccurate or incomplete, you may request that we correct or complete it.
C. Right to Erasure: you may ask us to delete your data where there is no valid ground for us to continue processing it, subject to our legal retention obligations described in Section X and the limitations on erasing on-chain data described in Section VI.
D. Right to Restrict Processing: you may request that we restrict processing of your data in certain circumstances, such as where you dispute its accuracy or object to our processing.
E. Right to Data Portability: where processing is based on your consent and carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
F. Right to Object: you may object to our processing of your data where it is based on our legitimate interests, although we may have overriding grounds to continue processing in some cases.
G. Right to Withdraw Consent: where processing is based on your consent, you may withdraw it at any time; this will not affect the lawfulness of processing carried out before withdrawal, and we may be unable to continue providing certain Services (such as Token Sale participation) if withdrawal affects data we need for KYC/AML compliance.
H. Right to Complain: you may lodge a complaint with the Personal Data Protection Commission of Singapore, in addition to contacting us directly.
To exercise any of these rights, please contact our Data Protection Officer using the details in Section XVI, providing your full name and the email address registered to your account so that we can verify your identity. We may request additional information to confirm your identity before actioning a request. We aim to respond to requests within one month; complex or multiple requests may take longer, in which case we will keep you informed. We may charge a reasonable administrative fee for manifestly unfounded, repetitive, or excessive requests.
We maintain administrative, technical, and organizational safeguards designed to protect your Personal Data against accidental loss, unauthorized access, alteration, or disclosure. Access to your Personal Data is restricted to personnel and third parties with a legitimate business need, who are bound by confidentiality obligations and act only on our instructions.
VALT will never ask you for your private keys or wallet seed phrase. You are solely responsible for safeguarding your account credentials, private keys, and seed phrase, and for any activity conducted through your wallet using them. If you suspect unauthorized access to your account or wallet, please contact us immediately using the details in Section XVI.
In the event of a suspected Personal Data breach, we have procedures in place to investigate, contain, and remediate the incident, and to notify affected Users and the relevant regulatory authorities in accordance with applicable law, including the PDPA’s mandatory data breach notification requirements.
The Services are not directed to, and are not intended for use by, individuals under the age of 18 or the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect Personal Data from minors. If we discover that we have inadvertently collected Personal Data from a minor, we will delete it as soon as reasonably practicable. If you believe a minor has provided us with Personal Data, please contact us using the details in Section XVI.
The Website may contain links to third-party websites or blockchain explorers that are not under our control. We are not responsible for the privacy practices or content of such third parties. Before providing any Personal Data on an external website, please review its own privacy policy and terms.
We may update this Privacy Policy from time to time to reflect changes in our data practices, the Services, or applicable law. The date at the top of this Privacy Policy indicates when it was last revised. Material changes will be notified to you by email or by a notice on our website, and will take effect upon posting unless otherwise required by law. This Privacy Policy should be read together with our Terms and Conditions.
Entity Responsible for Data Processing:
Data Protection Officer:
To help us process your request efficiently, please contact us using the email address registered to your account, and be prepared to provide identification to verify your identity.