Real World Asset
TTOKNIFYRWA

PRIVACY AND DATA

Privacy Policy

How TOKNIFY collects, uses, publishes, retains and protects information across RWA creation, local-wallet activity, payments, AI generation, NFT minting and redemption.

Effective 2026-08-10Version 1.0.0
Important blockchain notice

Wallet addresses, transactions, NFT ownership and published metadata may be permanently visible on public blockchains. Do not submit private keys, seed phrases, passwords, sensitive personal information or confidential material.

01

Scope and controller

This Policy applies to the TOKNIFY website, WordPress account, RWA creation interface, local non-custodial wallet integration, server APIs, NFT metadata workflow and related support. The data controller is TOKNIFY, Local jurisdiction.. Separate asset issuers, custodians, blockchains, token providers and other services may act as independent controllers under their own policies.

By using TOKNIFY, you acknowledge this Policy and the Terms and Conditions. Where consent is the legal basis, you may withdraw it for future processing, but withdrawal does not invalidate earlier lawful processing or reverse public blockchain activity.

02

Information we collect

  • Account information: WordPress user ID, username, email, authentication records and account preferences.
  • Wallet and blockchain information: public wallet addresses, network, token balances requested by the interface, transaction hashes, token IDs, NFT ownership, contract events and redemption records.
  • Order and financial records: design ID, payment reference, asset quantity, quote, fees, deposit address, detected payment, settlement, refund and transaction status. We do not collect conventional card details through the active crypto-payment flow.
  • Creation content: engraving message, prompt description, uploaded reference artwork, generated image, validation output, metadata, hashes and publication choices.
  • Technical and security data: IP address, browser and device information, timestamps, request logs, error records, nonce and signature-validation data, fraud or abuse indicators and service diagnostics.
  • Communications: support requests, legal notices, feedback and administrative correspondence.
03

Local non-custodial wallet boundaries

The TOKNIFY RWA wallet is designed to create or import an encrypted keystore in your browser. The encrypted keystore remains in local browser storage. When unlocked, sensitive signing material is held only for the browser session. Your wallet password, plaintext private key and seed phrase are not intentionally transmitted to TOKNIFY servers. Public addresses and signed transactions are transmitted or published as necessary to display balances, make payments, transfer assets or redeem NFTs.

You control deletion of local wallet storage through your browser or wallet controls. Clearing browser data without a secure backup may permanently remove access. Never send recovery credentials to support.

04

How information is collected

We collect information directly from forms, uploads, wallet actions and communications; automatically from the website and server; from public BNB Smart Chain records and explorers; and from providers involved in generation, pricing, swaps, validation, custody, compliance or settlement. Public-chain information may be combined with account records to verify payment, ownership and redemption.

05

Purposes and legal bases

Provide the contracted service

Create orders, generate designs, detect payment, acquire backing, mint NFTs, show assets, process refunds and verify redemption.

Contract necessity
Security and integrity

Authenticate requests, prevent replay and fraud, validate content, reconcile blockchain activity, investigate failures and protect users.

Legitimate interests and legal obligations
Legal and financial records

Maintain accounting, tax, dispute, sanctions, asset-liability and compliance records.

Legal obligations and legitimate interests
Publication

Publish approved images, messages, metadata, hashes and token records after the required customer confirmation and payment.

Contract necessity and consent where required
Service improvement

Analyze aggregated performance, reliability, errors and feature usage without using wallet secrets.

Legitimate interests
Communications

Send transactional notices, respond to support and provide legally required updates.

Contract necessity, legal obligations or consent
06

Artificial-intelligence processing

Design instructions, reference images and related technical context may be sent to OpenAI through its API to generate and validate a personalized asset visualization. Do not include unnecessary personal or sensitive information. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Provider retention, safety monitoring and processing remain subject to the applicable account configuration and provider terms. See OpenAI business data privacy.

Generated outputs and validation results may be reviewed automatically and, where support or safety requires, by authorized personnel. Source artwork stays private during the generation workflow unless publication is necessary and approved; the final validated image and NFT metadata become public when the paid asset is finalized.

07

Public blockchain and NFT information

BNB Smart Chain is a public decentralized network. Wallet addresses, transaction amounts, contract interactions, NFT ownership, burns and redemption events may be visible indefinitely and copied by third parties. Final NFT images, messages, attributes, token URIs, metadata and cryptographic commitments may also be publicly accessible. Blockchain publication is not confidential, and TOKNIFY generally cannot erase or alter data confirmed on-chain or copied by independent services.

08

How information is shared

We disclose only what is reasonably necessary to:

  • hosting, infrastructure, security, email, WordPress and support providers;
  • OpenAI for generation and validation;
  • BNB Smart Chain nodes, RPC providers, explorers and smart contracts;
  • token issuers, decentralized exchanges, liquidity providers, custodians, valuation sources and asset-module partners;
  • auditors, lawyers, accountants, insurers and compliance providers under appropriate duties;
  • authorities, courts or affected parties where required by law or necessary to protect rights and safety;
  • a buyer, investor or successor in a merger, financing, restructuring or transfer, subject to applicable safeguards.

Public NFT publication and user-initiated blockchain transactions are disclosures to the public, not private processor transfers.

09

International transfers

Providers and blockchain infrastructure may process information outside your country. Where applicable law requires it, we use recognized transfer mechanisms such as adequacy decisions, contractual safeguards or other lawful measures. Public blockchain information is globally available and cannot be geographically restricted after publication.

10

Retention

We retain information only as long as reasonably necessary for service delivery, security, legal obligations and disputes. Account and active-order records remain while the relationship continues. Financial, settlement, backing, refund and compliance records may be retained for up to 7 years after completion or longer where law or a dispute requires. Support and operational correspondence may be retained for up to 3 years. Private source files may be removed earlier when no longer needed. Backups expire on their normal rotation.

Encrypted local wallet data remains on your device until you remove it. Public blockchain records, decentralized storage, published NFT metadata and copies held by third parties may remain indefinitely.

11

Cookies, browser storage and similar technologies

WordPress may use essential cookies for login, security, preferences and sessions. The local wallet uses browser storage for the encrypted keystore and session storage for temporary unlocked state. Transaction-resume markers may prevent loss of progress after interruption. Essential technologies are required for requested functionality. Any analytics, advertising or non-essential cookies added by the site must be disclosed and consented to separately where required.

12

Security

We use measures intended to protect information, including HTTPS, access controls, signed server requests, nonce and replay protection, isolated services, encrypted wallet storage, integrity hashes and restricted private-file access. No internet, blockchain, wallet or storage system is completely secure. You are responsible for device security, strong unique passwords, backups and checking transaction details. Notify us promptly of suspected account compromise without disclosing wallet secrets.

13

Your privacy rights

Depending on location, you may have rights to be informed; request access, correction or deletion; restrict or object to processing; receive portable data; withdraw consent; and complain to a competent authority. You may also have rights relating to direct marketing and qualifying automated decisions. These rights are not absolute and may be limited by identity verification, legal retention, protection of others, fraud prevention, legal claims and technical impossibility.

Submit a request to info@toknify.com. State the right requested and enough account or order information to locate the record, but never provide a password, private key or seed phrase. We may verify identity and wallet control before responding.

14

Deletion and correction limitations

We can remove eligible off-chain account, design or support data when no overriding obligation applies. We cannot reliably delete public blockchain transactions, smart-contract events, NFT ownership history, token metadata already cached or copied, or information independently controlled by another provider. Correcting an off-chain display does not rewrite blockchain history. Cancelling an unpaid request removes it from the customer interface while a limited server audit record may remain to detect late payment and prevent loss.

15

Automated processing

Automation is used for quote calculation, payment detection, confirmations, AI generation, render validation, swap routing, settlement, minting, refunds, gas recovery, ownership discovery and redemption verification. These processes execute user-requested service rules and security controls. Where applicable law gives you rights regarding a solely automated decision with legal or similarly significant effect, contact us to request information or eligible human review.

16

Children

TOKNIFY is not directed to anyone under 18. We do not knowingly provide RWA or digital-asset services to children. If you believe a child submitted personal data, contact us so eligible off-chain information can be investigated and removed.

17

Sale of data and marketing

We do not sell or rent private keys, wallet passwords, customer prompts or personal information. We use contact details primarily for transactional, support, security and legal communications. Optional marketing requires the choice or lawful basis applicable in your location, and you may unsubscribe from marketing without disabling essential service notices.

18

Third-party sites and independent services

Links to explorers, token issuers, blockchains, wallets, exchanges, AI providers or other sites are governed by their own policies. TOKNIFY is not responsible for independent processing. Review third-party terms before connecting a wallet, sending data or executing a transaction.

19

Changes to this Policy

We may update this Policy when modules, providers, laws or practices change. The effective date will be revised and material changes may be announced on the site or through account contact information. Review the current Policy before submitting a new order or enabling a new asset module.

20

Contact and complaints

Controller: TOKNIFY
Local jurisdiction.
Privacy email: info@toknify.com

You may also complain to the data-protection authority competent for your location where that right applies.