Global Compliance & Data Protection Policy

Privacy Policy

Learn how VeriAgent Pay protects your personal data, cryptographic credentials, and transaction records across our web platform and messaging bot integrations.

[Effective Date: August 1, 2026][Last Updated: August 1, 2026]Version 2.4.0

A. Introduction & Overview

Welcome to VeriAgent Pay (operated by [Company Name / Veridex Protocol], referred to as "we", "us", or "our"). VeriAgent Pay is a cross-platform social payment, yield automation, and peer-to-peer liquidity protocol that allows users to send gasless cryptocurrency payments, split bills, deposit into yield vaults, and manage group credit lines.

Scope of This Policy: This Privacy Policy applies to all services, products, tools, and interfaces provided by VeriAgent Pay, including our official Web Application (https://veriagentpay.xyz), Telegram Mini App, Telegram Bot (@VeriAgentPayBot), WhatsApp Bot, Discord Bot, Slack Bot, and REST/WebSocket APIs (collectively, the "Service").

We are committed to maintaining the highest global standards of privacy, security, and transparency under applicable data protection laws, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the UK Data Protection Act 2018 (UK GDPR), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and Brazil’s Lei Geral de Proteção de Dados (LGPD).

B. Data We Collect

We collect personal and technical data to deliver secure, non-custodial social payment workflows. Below is an exhaustive list of the data categories we process:

1. Personal Identification Data

Social messaging handles and platform IDs: Telegram username & Telegram user ID, WhatsApp phone number, Discord user ID, Slack user ID, Google account email (if authenticating via OAuth), and counterfactual/deployed Smart Account wallet addresses.

2. Biometric Data Credentials

WebAuthn / Passkey public key credentials (P-256 curve cryptographic public key material). Crucial Notice: We NEVER collect, receive, or store your raw fingerprint scans, Face ID data, or local device biometric templates. All raw biometric processing occurs exclusively within your local device’s Secure Enclave / Trusted Execution Environment (TEE).

3. Financial & Transaction Data

On-chain transaction hashes, token transfer amounts, supported asset balances (BOT, USDC, USDT, ETH, SOL), counterparty wallet addresses, yield vault deposit/withdrawal records, peer credit pool loan proposals, voting activity, and red envelope claims.

4. Technical & Usage Data

Internet Protocol (IP) address, device type, operating system version, browser type, Telegram Mini App viewport telemetry, API request timestamps, error trace logs, and web analytics.

5. Communication & AI Query Data

Bot command text inputs (e.g. /pay 50 USDC @alice), natural language payment queries processed via Google Gemini AI via @veridex/agents, customer support tickets, and feedback form submissions.

6. Contact List Data

Frequent recipient social handles saved manually or automatically recorded following successful peer-to-peer transfers (accompanied by explicit in-chat notification during recipient auto-save).

C. How We Collect Data

We collect information through three primary channels:

  • Direct Interactions: When you initiate commands in Telegram, WhatsApp, Discord, or Slack; authenticate via WebAuthn Passkey; or submit forms inside the Web Dashboard or Telegram Mini App.
  • Automated System Collection: Through our NestJS backend infrastructure, Prisma ORM logging layer, PostgreSQL database engines, and privacy-preserving analytics scripts.
  • Third-Party Integrations & Blockchain RPCs: Via official OAuth/Webhook events provided by Telegram, WhatsApp Cloud API, Discord API, Slack API, and public blockchain RPC nodes (e.g. BOTChain RPC, Bohr RPC, Arbitrum, Base) when retrieving transaction confirmations.

D. How We Use Your Data & Legal Bases

Under GDPR and international privacy regulations, we process data based on defined legal grounds:

Processing PurposeCategories of DataLegal Basis (GDPR Art. 6)
Execute transactions & smart contractsWallet address, tx amount, token symbol, handlesContractual Necessity (Art. 6(1)(b))
Authenticate passkeys & session keysP-256 public key, short-lived session hashesContractual Necessity (Art. 6(1)(b))
Send bot notifications & receiptsPlatform ID, handle, transaction statusLegitimate Interest (Art. 6(1)(f))
Parse natural language intent via AIRaw text query (anonymized payload)Legitimate Interest (Art. 6(1)(f))
Fraud prevention & system debuggingIP address, request logs, device detailsLegitimate Interest (Art. 6(1)(f))
Legal & regulatory complianceOn-chain receipts, audit logsLegal Obligation (Art. 6(1)(c))

E. Biometric Passkey Data Guarantee

VeriAgent Pay utilizes modern WebAuthn / FIDO2 standards to enable biometric passkey authentication (Touch ID, Face ID, Windows Hello, Android Biometrics).

🔒 Technical Guarantee: When you register a biometric passkey with VeriAgent Pay, your device’s hardware security module generates an asymmetric key pair. Your raw biometric measurements never leave your physical device. VeriAgent Pay stores only the public key material used to verify WebAuthn assertion signatures during session key authorization.

It is mathematically impossible for VeriAgent Pay, third parties, or attackers to reconstruct your biometric data or access your device through stored passkey public keys.

F. How We Share Your Data

We strictly limit third-party data sharing:

  • Counterparties: When you send a payment, split a bill, or issue a request, your social handle and truncated wallet address (0x123...456) are shared with the recipient to complete the transaction.
  • AI Service Providers (@veridex/agents / Gemini AI): Natural language queries entered into bot chats are processed by AI models to infer payment parameters (e.g. amount, token, intent). We transmit only the text string entered; no personal profile identifiers are attached unless explicitly typed by the user in the prompt.
  • Blockchain Network Nodes: Signed transaction payloads are broadcast to public blockchain RPC nodes (BOTChain, Bohr, Arbitrum, Base) to execute smart account transfers.
  • Legal Requirements: We disclose user information only when compelled by valid, binding law enforcement requests, court orders, or subpoenas.
  • No Data Sales: We do NOT sell, rent, trade, or monetize your personal data or contact lists to advertising networks or data brokers.

G. Data Retention & Blockchain Storage

Data retention periods vary based on data category and technology constraints:

  • Blockchain Records (Immutable): Transactions broadcast to public blockchain networks (hashes, public wallet addresses, transfer amounts) are permanently recorded on-chain by network consensus and cannot be altered or deleted.
  • Account Profile & Passkey Data: Retained in PostgreSQL while your account remains active. Off-chain user profile data can be anonymized or deleted upon request (Section H).
  • Bot Interaction & Queue Logs: Retained in encrypted Redis/PostgreSQL storage for up to 12 months for service optimization and operational debugging, after which logs are scrubbed or anonymized.
  • Analytics Data: Retained for up to 26 months in aggregated, anonymized form.

H. Your Legal Rights & Regional Choices

Depending on your jurisdiction (GDPR, CCPA/CPRA, UK DPA, PIPEDA, LGPD), you enjoy the following privacy rights:

Right to Access

Request a complete copy of off-chain personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete social handles or profile links.

Right to Erasure (Forgotten)

Request deletion of off-chain profile data (excluding immutable blockchain records).

Right to Portability

Export transaction history and contact lists in machine-readable JSON format.

To exercise your rights, email your request to privacy@veriagent.pay or access Settings inside the Web Dashboard. We fulfill requests within 30 days without charge.

I. International Data Transfers

VeriAgent Pay operates globally. Your data may be processed on secure servers located in the United States, European Union, or other global jurisdictions.

When transferring personal data internationally from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, data processing agreements (DPAs), and strict technical encryption measures to ensure data protection equivalence.

J. Cookies & Tracking Technologies

Web Dashboard: We use essential HTTP cookies and local storage tokens strictly required for user authentication, session key authorization, and security. We may use privacy-respecting analytics to evaluate page load metrics.

Messaging Bots & Mini Apps: Telegram Mini Apps do not store browser cookies; user context is provided directly via Telegram’s secure initData HMAC signatures.

K. Children’s Privacy

VeriAgent Pay is not directed to or intended for children under the age of 16 (or 13 in certain US jurisdictions). We do not knowingly collect personal information from minors. If we discover that a minor under 16 has established an account, we will immediately delete their off-chain profile data.

L. Security Measures & Encryption

We deploy defense-in-depth security infrastructure to protect user assets and privacy:

  • End-to-End Transport Security: HTTPS/TLS 1.3 encryption for all Web API endpoints and Webhook payloads.
  • Session Key Vault Security: Active Smart Account Session Keys are encrypted at rest using AES-256-GCM authenticated encryption.
  • Strict Access Control & Rate Limiting: NestJS throttler guards, IP rate limits, and zero public exposure of sensitive database infrastructure.

M. Changes to This Policy

We may update this Privacy Policy from time to time to reflect protocol changes, regulatory updates, or new platform integrations. When material updates occur, we will notify users via in-chat bot broadcasts or prominent Web App notices. Your continued use of VeriAgent Pay following notice indicates acceptance of the updated policy.

N. Contact Us & Legal Disclaimers

If you have questions, concerns, or legal inquiries regarding this Privacy Policy or your personal data, contact our compliance team:

Entity: [Company Name / Veridex Protocol]

Email: privacy@veriagent.pay

Telegram: @VeriAgentPayBot

Address: [100 Blockchain Plaza, Suite 400, San Francisco, CA 94105, USA]

⚠️ Legal Notice & Disclaimer:

This privacy policy is provided for informational purposes and does not constitute formal legal advice. VeriAgent Pay makes no warranties regarding the completeness or accuracy of this document. Users should consult their own legal counsel for specific regulatory compliance concerns.

In the event of any inconsistency or discrepancy between this English version and any translated version of this Privacy Policy, the English version shall prevail.