1. Introduction
This EAPES Privacy Policy (the “Privacy Policy”) explains how personal information is collected, used, disclosed, retained, and protected when you interact with EAPES.COM, APP.EAPES.COM, EAPES Island, EAPES Validator interfaces, community features, customer support, and other EAPES-operated Services that link to this Privacy Policy.
This Privacy Policy applies only to personal information handled by an EAPES entity.
Independent services, including self-custodied wallets, public blockchains, marketplaces, OneDex, social networks, payment providers, and other third-party websites, maintain their own privacy practices.
2. Organization Responsible for Personal Information
The organization responsible for personal information processed through the principal EAPES Services is:
EAPES, a company registered in Québec, Canada, with its business and mailing address at 1055 Rue Lucien-L'Allier, Unit #886, Montreal, QC H3G 3C4, Canada.
Privacy Officer: EAPES Privacy Officer. Privacy Email: [email protected]. Mailing Address: 1055 Rue Lucien-L'Allier, Unit #886, Montreal, QC H3G 3C4, Canada.
EAPES L.L.C. may receive limited personal information where necessary to manage intellectual property, licences, brand protection, creator programs, or related contractual matters.
Where another EAPES entity is responsible for a particular product or Service, the applicable notice or product-specific terms will identify that entity and its role.
3. Scope
This Privacy Policy applies to personal information processed through:
- EAPES.COM;
- APP.EAPES.COM;
- EAPES-operated community tools;
- EAPES Island interfaces;
- EAPES Validator interfaces;
- customer support;
- creator and licensing programs;
- EAPES-operated marketplace functionality;
- archived EAPES interfaces, where personal information remains displayed or retained; and
- other Services that link to this Privacy Policy.
It does not apply to information independently controlled by a third party.
4. Information We Collect
4.1 Information You Provide
Depending on the Service, you may provide:
- name;
- email address;
- username or Herotag;
- preferred language;
- profile image;
- country, city, or approximate region;
- social-media links;
- support communications;
- licensing or creator-program information;
- business or organization information;
- purchase or service-request information;
- transaction-related information;
- consent choices;
- marketing preferences; and
- information contained in forms, correspondence, or applications.
4.2 Account and Profile Information
If you create an EAPES account or profile, EAPES may process:
- account identifier;
- username;
- email address;
- authentication data;
- profile settings;
- public-display settings;
- linked public wallet address;
- language and region preferences;
- applicable terms and policy versions accepted;
- acceptance date and method; and
- account-status information.
4.3 Wallet and Blockchain Information
When you connect or use a digital wallet, EAPES may process:
- your public wallet address;
- blockchain network;
- public token or NFT holdings relevant to a requested feature;
- public transaction history;
- transaction hashes;
- public smart-contract interactions;
- signatures used to authenticate wallet ownership;
- delegation information relevant to EAPES Validator; and
- technical information needed to provide the requested feature.
EAPES does not collect and will never ask you to provide your private key or recovery phrase.
Information recorded on a public blockchain may be visible permanently and may not be capable of being changed or deleted by EAPES.
4.4 Transaction and Service Information
When you use an eligible Service, EAPES may process:
- product or feature used;
- date and time;
- transaction status;
- blockchain network;
- public transaction identifier;
- wallet address;
- price and fee information displayed by the interface;
- product-specific terms;
- accepted terms version;
- delivery or activation status;
- error information; and
- related support records.
4.5 EAPES Validator Information
Where you use EAPES Validator interfaces, EAPES may process:
- public EGLD wallet address;
- delegation status;
- public transaction information;
- validator-related requests;
- technical logs;
- reward or fee information available from public network data; and
- information needed to provide support.
EAPES does not control information independently recorded by the MultiversX network.
4.6 Community and Map Information
If you voluntarily participate in a community profile, map, directory, leaderboard, or public-facing feature, EAPES may process the information you choose to display, such as:
- username;
- profile image;
- country;
- city or approximate location;
- social links;
- collection membership;
- public wallet identifier; and
- community description.
Public display should be optional and disabled by default unless you choose otherwise.
Do not submit a precise residential address to a public community feature.
4.7 Technical and Usage Information
EAPES may automatically collect:
- IP address;
- browser type;
- device type;
- operating system;
- language;
- approximate region;
- referring page;
- pages and features visited;
- session identifiers;
- timestamps;
- diagnostic and error logs;
- security events;
- cookie and privacy preferences; and
- interaction information.
Non-essential analytics information is collected only in accordance with your consent choices where consent is required.
4.8 Communications
When you contact EAPES, EAPES may collect:
- your contact information;
- the content of your message;
- attachments;
- support history;
- transaction or wallet details you choose to provide; and
- information necessary to respond.
Do not send private keys, recovery phrases, passwords, or unnecessary identity documents.
4.9 Identity and Eligibility Verification
A specific product, transaction, jurisdiction, service provider, or documented risk control may require identity or eligibility verification.
Before collecting verification information, EAPES will provide a specific notice identifying:
- the information required;
- the purpose;
- whether submission is mandatory;
- the verification provider;
- whether the provider stores the information;
- the countries where processing may occur;
- the expected retention period; and
- the consequences of refusing.
EAPES will not collect biometric information unless it is necessary for a specific disclosed process and all required consents, assessments, contracts, and safeguards have been completed.
5. How We Collect Information
EAPES may collect information:
- directly from you;
- when you create or update an account or profile;
- when you connect a wallet;
- when you sign an authentication message;
- when you use a product or Service;
- from public blockchain records;
- through customer support;
- through cookies and similar technologies;
- from providers acting on EAPES’s behalf;
- from an EAPES entity involved in the same Service; and
- from publicly available information where permitted by law.
6. Why We Use Personal Information
EAPES may use personal information to:
- operate and secure the Services;
- authenticate users and wallets;
- provide requested features;
- process eligible purchases or service requests;
- display user-selected public profile information;
- provide customer support;
- respond to technical issues;
- maintain transaction, delivery, and acceptance records;
- operate EAPES Validator interfaces;
- manage intellectual property and licensing requests;
- protect EAPES L.L.C.’s intellectual property;
- detect fraud, abuse, and security threats;
- comply with legal obligations;
- enforce contracts and policies;
- maintain limited historical records for archived Services;
- communicate security, transaction, product, or policy updates;
- measure and improve the Services after obtaining consent where required; and
- establish, exercise, or defend legal rights.
EAPES does not use personal information to operate:
- an active DAO;
- an active holder-governance system;
- an active EAPES NFT staking program;
- an internal EAPES-operated $EAPES Pool; or
- a Banana or Banana Point conversion service into $EAPES.
7. Legal Grounds for Processing
Where applicable law requires a legal ground, EAPES processes personal information based on one or more of the following:
- your consent;
- performance of a contract or steps requested before entering into a contract;
- compliance with a legal obligation;
- protection against fraud, abuse, or security threats;
- legitimate interests that do not override your rights;
- establishment, exercise, or defence of legal rights; or
- another lawful basis recognized in the applicable jurisdiction.
Where processing is based on consent, you may withdraw consent, subject to legal or contractual restrictions and reasonable notice.
8. Public Blockchain Information
A blockchain may permanently display:
- wallet addresses;
- token balances;
- NFT ownership;
- transaction amounts;
- smart-contract interactions;
- delegation activity; and
- timestamps.
EAPES cannot normally delete, correct, conceal, or reverse information confirmed on a public blockchain.
Where appropriate, EAPES may remove a wallet address from an EAPES profile or stop displaying information through an EAPES interface, but the underlying blockchain record may remain public.
You should avoid publicly linking a wallet to personal information unless you understand the consequences.
9. Automated Processing and Profiling
EAPES does not make a decision producing legal or similarly significant effects solely through automated processing unless:
- the process is necessary for a permitted purpose;
- applicable law allows it;
- appropriate notice is provided; and
- any required rights or safeguards are available.
Security, fraud-prevention, spam, sanctions, or eligibility tools may flag activity for review. A flag does not necessarily constitute a final automated decision.
10. How We Disclose Information
10.1 Service Providers
EAPES may disclose information to providers supporting:
- hosting and cloud infrastructure;
- cybersecurity;
- analytics;
- email and communications;
- customer support;
- wallet connectivity;
- identity or eligibility verification;
- payment processing;
- transaction monitoring;
- professional services;
- legal compliance; or
- technical development and maintenance.
Providers may process information only for authorized purposes and subject to applicable contractual and legal obligations.
10.2 EAPES Entities
Information may be shared between EAPES entities where reasonably necessary to:
- operate a Service;
- provide support;
- manage intellectual property;
- administer licences;
- protect security;
- maintain records; or
- comply with law.
10.3 Legal and Regulatory Requirements
EAPES may disclose information where reasonably necessary to:
- comply with law;
- respond to a lawful order;
- protect users or the public;
- investigate fraud or security incidents;
- enforce agreements;
- protect intellectual property; or
- establish or defend legal claims.
10.4 Business Transactions
Information may be transferred as part of a merger, financing, restructuring, acquisition, insolvency process, or sale of assets, subject to applicable confidentiality, notice, and legal requirements.
10.5 With Your Direction
EAPES may disclose information when you request or authorize the disclosure.
11. Third-Party Services
Third-party services may collect information directly from you and are responsible for their own privacy practices.
EAPES is not the privacy controller for information independently collected by:
- OneDex;
- a self-custodied wallet provider;
- a marketplace;
- a blockchain explorer;
- a social network;
- an external payment provider; or
- another independently operated website or application.
Review the third party’s privacy policy before using its services.
12. OneDex
OneDex is an independent third-party service and is not operated by EAPES.
If you leave an EAPES-operated website to use OneDex, OneDex may independently collect or process information according to its own policies and technologies.
EAPES is not responsible for OneDex’s privacy, security, smart contracts, fees, transactions, or data practices.
13. International Processing
Personal information may be processed outside your province, state, or country.
Where required, EAPES will assess relevant privacy risks and implement contractual, organizational, or technical safeguards appropriate to the circumstances.
Information processed in another jurisdiction may be accessible to courts, law-enforcement bodies, or governmental authorities under that jurisdiction’s laws.
A current description of material provider locations may be requested from the Privacy Officer, subject to security, legal, and confidentiality restrictions.
14. Retention
EAPES retains personal information only for as long as reasonably necessary for the purpose for which it was collected, including:
- providing the Services;
- maintaining security records;
- responding to disputes;
- meeting tax, accounting, contractual, or legal obligations;
- managing intellectual property rights;
- maintaining required consent and transaction records; and
- preserving necessary historical information relating to archived Services.
Retention periods vary by data category and system.
EAPES will maintain an internal retention schedule identifying the responsible system, purpose, retention period, and deletion or anonymization method.
When information is no longer required, EAPES will delete, destroy, anonymize, or securely archive it, subject to legal, technical, backup, and blockchain-related limitations.
Public blockchain information may remain available indefinitely and is not controlled by EAPES.
15. Security
EAPES uses administrative, technical, and organizational measures appropriate to the sensitivity of the information and the risks associated with processing.
Measures may include:
- access restrictions;
- authentication controls;
- encrypted communications;
- secure development practices;
- monitoring;
- backups;
- incident-response procedures;
- provider controls; and
- employee or contractor confidentiality obligations.
No system is completely secure. EAPES cannot guarantee that unauthorized access, loss, misuse, alteration, or disclosure will never occur.
You are responsible for securing your wallet, device, passwords, private keys, and recovery phrase.
16. Privacy and Security Incidents
EAPES maintains procedures to assess and respond to suspected privacy and security incidents.
Where required by applicable law, EAPES will notify affected individuals and the appropriate authority.
If you believe your information or account has been compromised, contact [email protected].
17. Cookies and Similar Technologies
EAPES uses cookies, local storage, session storage, scripts, and similar technologies.
Strictly necessary technologies may operate without optional consent where permitted by law.
Analytics, functional, social, or advertising technologies will be activated only in accordance with your consent choices where consent is required.
More information is available in the EAPES Cookie and Similar Technologies Policy.
18. Marketing Communications
EAPES may send marketing communications only where permitted by law.
You may unsubscribe using the link included in the communication or by contacting EAPES.
EAPES may still send necessary operational communications concerning:
- security;
- transactions;
- account changes;
- policy changes;
- service interruptions; or
- support requests.
19. Community Features and Public Information
Information you choose to publish in a profile, map, directory, leaderboard, post, or community feature may be visible to others and may be copied or shared outside EAPES.
EAPES will provide settings or clear notices appropriate to the feature.
You may request removal of information from an EAPES-controlled public display, subject to legal, contractual, security, and blockchain limitations.
20. Children and Minors
The Services are not intended for individuals below the age permitted to use the applicable Service in their jurisdiction.
EAPES does not knowingly collect personal information from a child without the authorization required by law.
If you believe a child has improperly provided personal information, contact the Privacy Officer.
21. Archived Services
Archived EAPES pages may display limited historical blockchain or participation information.
Archived Services are not used to operate:
- new NFT staking;
- new $EAPES Pool positions;
- new Banana swaps;
- new DAO votes;
- new governance proposals; or
- new Banana or Banana Point conversions into $EAPES.
Historical records will be retained only where reasonably necessary for transparency, user support, asset recovery, contractual records, security, or legal obligations.
22. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
- request access to personal information;
- request correction;
- withdraw consent;
- request deletion where applicable;
- request restriction of certain processing;
- receive certain information in a structured and commonly used format;
- request information about disclosures;
- object to certain uses;
- request de-indexing or cessation of dissemination where applicable; and
- make a complaint to EAPES or a privacy authority.
To exercise a right, contact [email protected].
EAPES may need to verify your identity before responding.
Rights may be subject to lawful exceptions. EAPES cannot delete or alter a public blockchain record that it does not control.
23. Privacy Choices
You may be able to:
- update account or profile information;
- control public-display settings;
- disconnect a linked wallet from an EAPES profile;
- manage cookie preferences;
- unsubscribe from marketing;
- withdraw optional consent; and
- request account closure.
Account closure may not remove information that EAPES must retain or information recorded on a public blockchain.
24. Changes to This Privacy Policy
EAPES may update this Privacy Policy to reflect changes in products, data practices, providers, entity roles, security practices, or applicable law.
The current version will display its version number and effective date.
Material changes may be communicated through the Services, by email, or by another reasonable method.
Previous versions may remain available in the EAPES Legal Centre.
25. Language
A French version of this Privacy Policy is available.
Where applicable law requires a French version to be provided first, EAPES will make the French version available before a user expressly chooses the English version.
26. Contact and Complaints
Privacy Officer: EAPES Privacy Officer. Privacy Email: [email protected]. Mailing Address: 1055 Rue Lucien-L'Allier, Unit #886, Montreal, QC H3G 3C4, Canada.
You may also contact the privacy authority responsible for your jurisdiction.