Privacy Policy

We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Decentralized Identity Wallet (the “Wallet”), which enables you to create Decentralized Identifiers (DIDs) and manage Verifiable Credentials (VCs).

The Personal Data Protection Act 2010 (“Act”) of Malaysia, as amended from time to time, applies to our processing of Personal Data under this policy.

1. Types of Data We Collect

We may collect two categories of data:

  • Personal Data (as defined under the Act).
  • Anonymous Data, including aggregated or de-identified data not linked to any individual, used to improve our services.

a. Information You Provide to Us

  • We do not collect your private keys, credentials, or seed phrases.
  • If you voluntarily contact us (e.g., for support or feedback), we may collect your name, email, and other information you provide.
  • Device information such as operating system version or app version may also be collected when submitted in support requests.

b. Information Collected via Technology

  • The Wallet operates primarily locally. We do not store your DID, VC, or private key data on servers.
  • If you access Wallet-related web services (e.g., DID resolution or credential schema fetching), our servers may log your IP address, browser type, domain, and timestamp.
  • These logs are used to improve service performance and troubleshoot issues.

c. Information from Third Parties

  • We may receive anonymized data from service providers (e.g., analytics). This data is not linked to your identity, DID, or credentials.

2. Use of Your Data

We may use data collected for the following purposes:

  • To provide Wallet functionality such as DID creation, credential issuance, storage, and verification.
  • To respond to support inquiries or requests.
  • To ensure interoperability with blockchain-based registries and revocation lists.
  • To improve service reliability, troubleshoot technical issues, and enhance performance.
  • To communicate with you regarding updates, new features, or compliance obligations (if you provide contact details).

3. Disclosure of Your Data

a. Third-Party Service Providers

We may engage service providers to support Wallet operations (e.g., hosting DID registries, credential schema repositories). These providers only receive limited, non-personal metadata where necessary.

b. Affiliates & Corporate Changes

We may share Personal Data collected (e.g., support inquiries) with affiliates or transfer it in connection with a business transition such as a merger or acquisition.

c. Legal & Safety Requirements

We may disclose Personal Data where required by law, regulation, or to investigate fraudulent or harmful activities.

d. User-Initiated Disclosures

When you choose to share a Verifiable Credential or Presentation with a third party, only the attributes you select will be disclosed. This happens solely under your explicit consent.

4. Third-Party Sites

The Wallet may link to or interact with third-party websites and services (e.g., DID resolvers, credential registries). Your use of those services is subject to their own privacy policies.

5. Your Choices Regarding Information

a. Communications

If you receive promotional communications, you may opt out by following unsubscribe instructions. However, we may still send important service or legal notices.

b. Cookies & Tracking

The Wallet itself does not rely on cookies. If you use a web-based interface, you may manage cookies in your browser settings.

6. Data Access and Control

  • You retain full control over your DIDs, credentials, and cryptographic keys. These remain encrypted and stored only on your device.
  • You may request access, correction, or deletion of Personal Data collected (e.g., support records).

7. Data Retention

  • Local Data: All credentials, DIDs, and keys remain on your device until you delete them.
  • Server Logs: Any server-side logs are retained only as long as necessary to provide services and maintain security.
  • Blockchain Records: Information written to a blockchain (e.g., DID registration) is permanent and cannot be altered or deleted.

8. Data Protection

We implement technical, administrative, and organizational measures to protect your data. However, no system is completely secure, and we cannot guarantee absolute protection against unauthorized access.

9. Consent

  • If you are under 18, you should obtain consent from a parent or guardian before using the Wallet.
  • If you provide data on behalf of others, you confirm you have obtained their consent.

10. International Users

Because blockchain networks and supporting services are global, some data may be processed outside your home jurisdiction. By using the Wallet, you consent to such international transfers.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The most current version will be made available, and continued use of the Wallet constitutes acceptance of any changes.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our practices, please contact us at: info@zetrix.com