[✓] ARCHITECTURAL PRIVACY BY DESIGN
At Vellum Cash ("Vellum," "we," "us," or "our"), we operate under a foundational cryptographic doctrine: data that is never collected cannot be leaked, compromised, or subpoenaed. Our protocol interfaces with the Arc Blockchain and EVM networks utilizing client-side Groth16 zero-knowledge proofs.
This Privacy Policy details how we handle the minimal telemetry necessary to operate the web interface (https://vellum.cash), how client storage functions, and your legal rights under international regulations including the General Data Protection Regulation (GDPR) and UK Data Protection Act.
§ 1. Information We Collect
[INGRESS TELEMETRY]We categorize incoming telemetry into two strictly delineated tiers: information voluntarily submitted by you, and ephemeral technical data collected automatically by network edges.
1.1 Information You Provide Voluntarily
- Direct Communications: Email addresses, contact handles, or transaction hashes provided when submitting developer feedback, security bug reports, or support tickets.
- Partner API Applications: Business entity information and technical contact details provided when requesting upgraded programmatic relayer access.
1.2 Information Collected Automatically
- Ephemeral Edge Logs: Temporary caching of IP addresses strictly for DDoS prevention, rate limiting, and geoblocking enforcement. Edge logs are purged within a rolling 24-hour cycle.
- Client Environment: Browser user-agent strings, device viewport dimensions, and WebAssembly (WASM) capability flags required to load the Circom SnarkJS cryptographic prover.
- Public Ledger Data: Public cryptographic commitments, deposit hashes, and nullifier proofs broadcast onto public blockchains (Ethereum, Arc, Base, Arbitrum).
[EXCLUSION: ABSOLUTE PRIVACY GUARANTEE]
Vellum NEVER collects, requests, or stores: (1) Private Keys, (2) Seed Phrases, (3) Unblinded Secret Witness Nullifiers, or (4) User Banking Information. All cryptographic witnesses remain strictly within your local device’s memory.
§ 2. Purposes & Legal Bases for Processing
[PROCESSING RATIONALE]In accordance with GDPR Article 6, we process minimal technical data under the following legitimate legal bases:
[LEGITIMATE INTERESTS]Maintaining network infrastructure resilience, preventing malicious sybil attacks, and optimizing WASM circuit execution speeds.
[CONTRACTUAL NECESSITY]Executing requested cross-chain circuit routing and providing technical support to inquiries initiated by you.
[LEGAL OBLIGATIONS]Enforcing automated geoblocking for sanctioned jurisdictions and preventing access by designated terror or exploit addresses.
§ 3. Information Sharing & Relayer Disclosures
[DISCLOSURES]We do not sell, rent, monetize, or trade user data. Disclosures are strictly limited to the following architectural necessities:
- Independent Relayer Nodes: Relayers receive the zero-knowledge Groth16 proof, public nullifier, and calldata necessary to dispatch destination settlements on-chain. Relayers receive zero personally identifiable information (PII).
- Edge & Routing Infrastructure: Content delivery and edge caching providers (e.g. Cloudflare, Vercel) process incoming HTTP packets to protect against volumetric DDoS attacks.
- Compelled Legal Disclosure: We may disclose information if required to do so by a binding court order, subpoena, or enforceable decree from a competent jurisdiction.
§ 4. Data Retention & Ephemeral Purging
[RETENTION CYCLES]We maintain rigorous data minimization schedules:
DATA TYPERETENTION LIFESPAN
Edge IP CachingRolling 24 Hours [AUTO-PURGE]
Active Ephemeral Conduit Session30 Minutes (Browser Memory)
Support CommunicationsUp to 180 Days (Unless legally required)
On-Chain Cryptographic CommitmentsImmutable Blockchain Permanence
§ 5. Cryptographic Security Posture
[SECURITY PROTOCOLS]Vellum enforces enterprise-grade security protocols across all software distributions:
TLS 1.3 ENCRYPTIONAll transport traffic is encrypted via TLS 1.3 with strict HTTP Strict Transport Security (HSTS).
CLIENT-SIDE SNARK PROVERWitness calculations occur locally in WebAssembly. Zero secret knowledge is transmitted over networks.
NO TRACKING PIXELSZero invasive third-party behavioral advertising scripts or cross-site tracking beacons.
FORMAL AUDITSCircuit constraints and smart contract settlement routers undergo rigorous formal security audits.
§ 6. Children & Minor Restrictions
[AGE REQUIREMENT]Our Services are strictly engineered for adults and are not directed to children under 18 years of age. We do not knowingly collect personal information from minors. If you discover that a minor has provided us with personal data, notify us immediately at privacy@vellum.cash for immediate deletion.
§ 7. User Consent & Architectural Boundary
[CONSENT]By utilizing Vellum, you provide explicit consent to the minimal data processing practices set forth in this Codex. If you do not consent to ephemeral logging or on-chain settlement, you must discontinue use of the interface.
§ 8. Your Global Privacy Rights (GDPR & International)
[DATA RIGHTS]Under the General Data Protection Regulation (GDPR), UK GDPR, and comparable privacy frameworks, you possess the following statutory rights regarding your personal information:
8.1 Right of Access (Art. 15 GDPR)You have the right to obtain confirmation as to whether personal data concerning you is processed and request a copy of such data.
8.2 Right to Rectification (Art. 16 GDPR)You have the right to request correction of inaccurate personal data maintained by our off-chain systems.
8.3 Right to Erasure / "Right to Be Forgotten" (Art. 17 GDPR)You may request deletion of your personal data held off-chain. Note: Data recorded immutably on decentralized blockchain ledgers cannot be altered or removed by Vellum.
8.4 Right to Object (Art. 21 GDPR)You may object to the processing of your personal data where such processing relies upon legitimate interest grounds.
8.5 Right to Restriction (Art. 18 GDPR) & Portability (Art. 20 GDPR)You have the right to request restriction of processing and receive your data in a structured, machine-readable format.
8.6 Right to Lodge a Supervisory Complaint (Art. 77 GDPR)You have the right to file a complaint with a competent Data Protection Authority in your European Union or EEA member state.
To exercise any of these statutory rights, transmit your request to privacy@vellum.cash. We respond within thirty (30) days without undue delay.
§ 9. Cross-Border Data Transfers
[INTERNATIONAL TRANSFERS]Because Vellum operates as a globally distributed cryptographic protocol, minimal edge telemetry may be processed on secure servers located outside your home jurisdiction. Where international transfers occur, we implement Standard Contractual Clauses (SCCs) and rigorous technical safeguards to ensure parity with European data protection benchmarks.
§ 10. Modifications & DPO Contact
[GOVERNANCE]We may update this Privacy Policy to reflect technical advances in our zero-knowledge circuits or evolving legal precedents. All modifications will be posted with an updated ratification date.
DATA PROTECTION INQUIRIES: privacy@vellum.cash[ZERO-KNOWLEDGE ARCHITECTURE: ACTIVE]