Scope and controller
This Policy applies to the TOKNIFY website, WordPress account, RWA creation interface, local non-custodial wallet integration, server APIs, NFT metadata workflow and related support. The data controller is TOKNIFY, Local jurisdiction.. Separate asset issuers, custodians, blockchains, token providers and other services may act as independent controllers under their own policies.
By using TOKNIFY, you acknowledge this Policy and the Terms and Conditions. Where consent is the legal basis, you may withdraw it for future processing, but withdrawal does not invalidate earlier lawful processing or reverse public blockchain activity.
Information we collect
- Account information: WordPress user ID, username, email, authentication records and account preferences.
- Wallet and blockchain information: public wallet addresses, network, token balances requested by the interface, transaction hashes, token IDs, NFT ownership, contract events and redemption records.
- Order and financial records: design ID, payment reference, asset quantity, quote, fees, deposit address, detected payment, settlement, refund and transaction status. We do not collect conventional card details through the active crypto-payment flow.
- Creation content: engraving message, prompt description, uploaded reference artwork, generated image, validation output, metadata, hashes and publication choices.
- Technical and security data: IP address, browser and device information, timestamps, request logs, error records, nonce and signature-validation data, fraud or abuse indicators and service diagnostics.
- Communications: support requests, legal notices, feedback and administrative correspondence.
Local non-custodial wallet boundaries
The TOKNIFY RWA wallet is designed to create or import an encrypted keystore in your browser. The encrypted keystore remains in local browser storage. When unlocked, sensitive signing material is held only for the browser session. Your wallet password, plaintext private key and seed phrase are not intentionally transmitted to TOKNIFY servers. Public addresses and signed transactions are transmitted or published as necessary to display balances, make payments, transfer assets or redeem NFTs.
You control deletion of local wallet storage through your browser or wallet controls. Clearing browser data without a secure backup may permanently remove access. Never send recovery credentials to support.
How information is collected
We collect information directly from forms, uploads, wallet actions and communications; automatically from the website and server; from public BNB Smart Chain records and explorers; and from providers involved in generation, pricing, swaps, validation, custody, compliance or settlement. Public-chain information may be combined with account records to verify payment, ownership and redemption.
Purposes and legal bases
Create orders, generate designs, detect payment, acquire backing, mint NFTs, show assets, process refunds and verify redemption.
Contract necessityAuthenticate requests, prevent replay and fraud, validate content, reconcile blockchain activity, investigate failures and protect users.
Legitimate interests and legal obligationsMaintain accounting, tax, dispute, sanctions, asset-liability and compliance records.
Legal obligations and legitimate interestsPublish approved images, messages, metadata, hashes and token records after the required customer confirmation and payment.
Contract necessity and consent where requiredAnalyze aggregated performance, reliability, errors and feature usage without using wallet secrets.
Legitimate interestsSend transactional notices, respond to support and provide legally required updates.
Contract necessity, legal obligations or consentArtificial-intelligence processing
Design instructions, reference images and related technical context may be sent to OpenAI through its API to generate and validate a personalized asset visualization. Do not include unnecessary personal or sensitive information. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Provider retention, safety monitoring and processing remain subject to the applicable account configuration and provider terms. See OpenAI business data privacy.
Generated outputs and validation results may be reviewed automatically and, where support or safety requires, by authorized personnel. Source artwork stays private during the generation workflow unless publication is necessary and approved; the final validated image and NFT metadata become public when the paid asset is finalized.
Public blockchain and NFT information
BNB Smart Chain is a public decentralized network. Wallet addresses, transaction amounts, contract interactions, NFT ownership, burns and redemption events may be visible indefinitely and copied by third parties. Final NFT images, messages, attributes, token URIs, metadata and cryptographic commitments may also be publicly accessible. Blockchain publication is not confidential, and TOKNIFY generally cannot erase or alter data confirmed on-chain or copied by independent services.
How information is shared
We disclose only what is reasonably necessary to:
- hosting, infrastructure, security, email, WordPress and support providers;
- OpenAI for generation and validation;
- BNB Smart Chain nodes, RPC providers, explorers and smart contracts;
- token issuers, decentralized exchanges, liquidity providers, custodians, valuation sources and asset-module partners;
- auditors, lawyers, accountants, insurers and compliance providers under appropriate duties;
- authorities, courts or affected parties where required by law or necessary to protect rights and safety;
- a buyer, investor or successor in a merger, financing, restructuring or transfer, subject to applicable safeguards.
Public NFT publication and user-initiated blockchain transactions are disclosures to the public, not private processor transfers.
International transfers
Providers and blockchain infrastructure may process information outside your country. Where applicable law requires it, we use recognized transfer mechanisms such as adequacy decisions, contractual safeguards or other lawful measures. Public blockchain information is globally available and cannot be geographically restricted after publication.
Retention
We retain information only as long as reasonably necessary for service delivery, security, legal obligations and disputes. Account and active-order records remain while the relationship continues. Financial, settlement, backing, refund and compliance records may be retained for up to 7 years after completion or longer where law or a dispute requires. Support and operational correspondence may be retained for up to 3 years. Private source files may be removed earlier when no longer needed. Backups expire on their normal rotation.
Encrypted local wallet data remains on your device until you remove it. Public blockchain records, decentralized storage, published NFT metadata and copies held by third parties may remain indefinitely.
Cookies, browser storage and similar technologies
WordPress may use essential cookies for login, security, preferences and sessions. The local wallet uses browser storage for the encrypted keystore and session storage for temporary unlocked state. Transaction-resume markers may prevent loss of progress after interruption. Essential technologies are required for requested functionality. Any analytics, advertising or non-essential cookies added by the site must be disclosed and consented to separately where required.
Security
We use measures intended to protect information, including HTTPS, access controls, signed server requests, nonce and replay protection, isolated services, encrypted wallet storage, integrity hashes and restricted private-file access. No internet, blockchain, wallet or storage system is completely secure. You are responsible for device security, strong unique passwords, backups and checking transaction details. Notify us promptly of suspected account compromise without disclosing wallet secrets.
Your privacy rights
Depending on location, you may have rights to be informed; request access, correction or deletion; restrict or object to processing; receive portable data; withdraw consent; and complain to a competent authority. You may also have rights relating to direct marketing and qualifying automated decisions. These rights are not absolute and may be limited by identity verification, legal retention, protection of others, fraud prevention, legal claims and technical impossibility.
Submit a request to info@toknify.com. State the right requested and enough account or order information to locate the record, but never provide a password, private key or seed phrase. We may verify identity and wallet control before responding.
Deletion and correction limitations
We can remove eligible off-chain account, design or support data when no overriding obligation applies. We cannot reliably delete public blockchain transactions, smart-contract events, NFT ownership history, token metadata already cached or copied, or information independently controlled by another provider. Correcting an off-chain display does not rewrite blockchain history. Cancelling an unpaid request removes it from the customer interface while a limited server audit record may remain to detect late payment and prevent loss.
Automated processing
Automation is used for quote calculation, payment detection, confirmations, AI generation, render validation, swap routing, settlement, minting, refunds, gas recovery, ownership discovery and redemption verification. These processes execute user-requested service rules and security controls. Where applicable law gives you rights regarding a solely automated decision with legal or similarly significant effect, contact us to request information or eligible human review.
Children
TOKNIFY is not directed to anyone under 18. We do not knowingly provide RWA or digital-asset services to children. If you believe a child submitted personal data, contact us so eligible off-chain information can be investigated and removed.
Sale of data and marketing
We do not sell or rent private keys, wallet passwords, customer prompts or personal information. We use contact details primarily for transactional, support, security and legal communications. Optional marketing requires the choice or lawful basis applicable in your location, and you may unsubscribe from marketing without disabling essential service notices.
Third-party sites and independent services
Links to explorers, token issuers, blockchains, wallets, exchanges, AI providers or other sites are governed by their own policies. TOKNIFY is not responsible for independent processing. Review third-party terms before connecting a wallet, sending data or executing a transaction.
Changes to this Policy
We may update this Policy when modules, providers, laws or practices change. The effective date will be revised and material changes may be announced on the site or through account contact information. Review the current Policy before submitting a new order or enabling a new asset module.
Contact and complaints
Controller: TOKNIFY
Local jurisdiction.
Privacy email: info@toknify.com
You may also complain to the data-protection authority competent for your location where that right applies.
Real World Asset