Legal

Privacy notice

Last updated 14 August 2026. TrustCBRC OÜ is the controller of the personal data described here.

1. Who we are

  • TrustCBRC OÜ, a company incorporated in Estonia, is the controller of the personal data described in this notice. TrustCBRC OÜ operates trustcbrc.com and is the campaign operator named in the campaign terms.
  • This notice covers trustcbrc.com: the public use case register, accounts, and the CBRC 2.0 Founding Contributor Campaign. Questions about it, or any request under the rights listed below, can be sent to the contact address in the final section.

2. What we collect

  • When you create an account: your name, email address, and optionally your organisation. Your password is never stored — only an Argon2 hash of it, from which the password cannot be recovered.
  • A destination tag, generated for your account. It is the number that identifies your contribution when it arrives on the XRP Ledger.
  • The XRP Ledger address you choose to declare, so a certificate and any SLT allocation can be delivered to it. Declaring one is your choice.
  • If you contribute: the sending address, the amount, the transaction hash, and the time the ledger closed it. These are read from the public XRP Ledger rather than collected from you.
  • A record that you accepted the campaign terms — which version, identified by a hash of its text, and when.
  • Ordinary server and security logs, and an internal audit record of administrative actions taken on your account or contribution.
  • We do not use analytics, advertising, tracking pixels, or any third-party script that profiles you. There are none on this site.

3. Why we process it, and on what basis

  • To give you an account and operate the campaign — creating your account, verifying your email address, allocating your destination tag, attributing your contribution, issuing your certificate and credits. Legal basis: performance of a contract with you.
  • To meet legal obligations, including any identity, source-of-funds or sanctions checks described in the campaign terms, and record-keeping we are required to maintain. Legal basis: compliance with a legal obligation.
  • To keep the service secure and to prevent and investigate fraud or abuse. Legal basis: our legitimate interests in operating a service that handles contributions of real value, balanced against your interests.
  • We do not make decisions producing legal effects about you by automated means. The CBRC score assesses a use case, not a person.

4. Who processes it for us

  • Railway Corp, our hosting provider. The application and its database run in Railway's europe-west4-drams3a region in Amsterdam, on Google Cloud infrastructure. Railway is a United States company, so although your data is stored in the European Union it is processed by a US-based processor. This is recorded as a deliberate decision in our architecture notes rather than an accident.
  • Scaleway SAS, for transactional email. Verification and account emails are sent through Scaleway Transactional Email in its fr-par region in Paris. Scaleway receives your name and email address. It was chosen specifically so that email processing stays inside the European Union.
  • Google Workspace, for CBRC's own correspondence, if you write to us.
  • We do not sell personal data, and we do not share it for anyone else's marketing.

5. The XRP Ledger, and what cannot be deleted

  • Read this section before contributing. It describes the one part of this service where your rights are limited by the technology rather than by our choices.
  • The XRP Ledger is a public, permanent, worldwide record that we do not control. Anyone can read it and nobody can alter or remove what it holds.
  • Your contribution — the sending address, the amount, the destination tag and the time — is on that ledger because you sent it there, not because we put it there. Your certificate, when issued, is a transaction on that same ledger.
  • This means we cannot erase, rectify or restrict processing of that data, and neither can anyone else. A request to delete your account will remove your account with us; it cannot remove anything from the ledger. If a wallet address is linked to your identity elsewhere, that link is outside our control.
  • If that is not acceptable to you, do not contribute. It is not a limitation we can waive.

6. The public contributors page

  • Contributors are listed on a public page on this site, with a link to the on-chain certificate. That listing is part of what the campaign offers rather than something incidental.
  • If you would prefer not to appear, tell us and we will remove the listing from this site. The underlying ledger record is covered by the section above and cannot be removed.

7. Cookies

  • We set cookies that are strictly necessary to sign you in and keep you signed in. There are no analytics cookies, no advertising cookies, and no third-party cookies.
  • Because we set nothing beyond what is strictly necessary, there is no consent banner to accept or reject. Blocking these cookies in your browser will prevent you signing in.

8. How long we keep it

  • Account data is kept while your account exists, and for as long afterwards as we are required to retain it for legal, accounting or compliance reasons.
  • Records of contributions, terms acceptances and administrative actions are kept for the life of the campaign and the retention period that applies to financial and compliance records afterwards. These are the records that let us show what happened to somebody's money, so they outlive the account.

9. How we protect it

  • Passwords are hashed with Argon2 and never stored in a recoverable form. Access to production systems is limited to the people who operate them, and administrative actions are recorded in an audit log.
  • No system that accepts payments over the internet is without risk. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.

10. Your rights

  • You have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable form. Where processing rests on consent, you may withdraw it at any time.
  • Section 5 explains the one place these rights meet a hard limit: data written to the XRP Ledger cannot be changed or removed by anyone, including us.
  • You may complain to a supervisory authority. For TrustCBRC OÜ that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), and you may also complain to the authority where you live or work.

11. Transfers outside the European Union

  • Your data is stored in the European Union. Our hosting provider is a United States company, so processing may involve access from outside the EU under the safeguards in its data processing terms.
  • Where a transfer outside the EU or an adequate country occurs, it is made under Standard Contractual Clauses or another lawful transfer mechanism.

12. Children

  • This service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this notice

  • If we change this notice we will publish the new version on this page and update the date shown at the top. Material changes affecting how we use your data will be notified to account holders.

14. How to contact us

  • Write to TrustCBRC OÜ at privacy@trustcbrc.com for any question about this notice or to exercise any of the rights described above.