Legal · v1.0
Privacy & Data Protection
Effective date: at first public deployment of this version. Contact: privacy@telluris.xyz
Who we are & what we do with data
TELLURIS (the “issuer”) operates an investor portal for registered gold-backed share certificates in AurumX LLC. We process the minimum data required to verify investors, run the sale, pay distributions and keep AML/CTF records: wallet address, KYC documents and decisions via Sumsub, transaction hashes, and your consent/agreement logs.
Legal bases (UK GDPR Art. 6 / GDPR Art. 6)
Contract performance — operating the portal, minting certificates you buy, paying USDC distributions. Legal obligation — AML/KYC screening, sanctions checks, retention of records. Legitimate interests — security and abuse prevention (rate-limiting, hashed IPs). Consent — optional storage: invitation attribution across visits, Google web fonts, marketing contact if you opt in.
Cookies & local storage
We set no advertising or cross-site tracking cookies. Strictly necessary storage keeps your consent record, T&C acceptance proof, wallet session and KYC access state; it is legally exempt from prior consent. Optional items — invitation attribution (functional) and Google Fonts (third-party media) — activate only after you accept them, can be withdrawn at any time via the ⚙ Cookies control, and withdrawal never disables core services.
Consent evidence & logs
Every cookie and agreement decision is mirrored server-side with timestamp, document version, coarse device metadata and a daily-rotated hash of your IP address (never the raw IP). This is how we demonstrate consent under Art. 7(1) GDPR after you have left the site or cleared your browser.
Third parties
Sumsub (identity verification; documents held by Sumsub under its own regulated processing), blockchain networks and public RPC/indexer providers (wallet address + transactions are inherently public once minted), hosting provider (Netlify — request logs), Google Fonts (only after you consent to that category). We do not sell personal data and share it with authorities only when legally compelled.
Retention
KYC records: 5 years after the end of the business relationship (typical AML requirement) even where an account is closed or erased. Consent/agreement logs: 6 years (contract evidence). On-chain records: technically immutable once minted — see “Right to erasure” below for how this affects your request.
Your rights
Access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent at any time (withdrawal does not affect prior lawful processing). Exercise them at the portal’s Your Data & Rights page (/data) or by email to privacy@telluris.xyz. You may complain to your supervisory authority (UK: ICO; EU: your local DPA).
Right to erasure on a public ledger
Certificate ownership and distribution history live immutably on the blockchain — this is inherent to tokenised securities and applies where required by the offering’s legal structure. An erasure request removes our off-chain personal data (KYC files, contact details, consent logs) subject to statutory AML retention; the on-chain record becomes unlinkable from you once our off-chain identity links are deleted. We will confirm in writing exactly what was and could not be erased, and why.
Security
TLS everywhere, secrets server-side only, least-privilege access for staff, append-only consent evidence, and no raw IP logging beyond hashed abuse forensics. Report concerns to security@telluris.xyz.
Exercise your rights
View what we hold on this device, download a copy, or file an erasure request:
Your Data & Rights →