Legal

Privacy Policy

1. Who is responsible for your data

The controller of personal data collected through this site, under Article 4(7) GDPR, is:

This policy is written to the standard of the EU General Data Protection Regulation. Where other privacy laws apply to you, they apply in addition to what is described here.

2. What we collect, and why

Visiting the site

You can browse perme.io without giving us anything. Our hosting provider records standard server logs — IP address, timestamp, requested page, referrer, browser and operating system — to serve the site, keep it available, and detect abuse. The legal basis is our legitimate interest in operating a secure website, Article 6(1)(f) GDPR.

This site loads typefaces from Google Fonts. When a page loads, your IP address is transmitted to Google’s servers to fetch them.

Inquiries by email

If you write to us from our contact page, we process the name, email address, and any details you choose to include, so that we can answer you. The legal basis is your consent, Article 6(1)(a) GDPR, given by sending the message; you can withdraw it at any time by writing to the address above.

Do not put sensitive personal data, credentials, or confidential third-party information into your message.

Legal claims

Where we need to establish, exercise, or defend a legal claim, we may process names, contact details, and information about the matter, and pass them to our legal advisers or a court. The legal bases are Articles 6(1)(f) and, for special categories of data, 9(2)(f) GDPR.

3. Who else sees it

We do not sell personal data and we do not share it for advertising. We use a small number of providers who process data on our instructions:

Beyond these, we disclose personal data only where the law requires it, or to our legal advisers and competent authorities in connection with a legal claim.

4. Transfers outside the EEA

We are established in Singapore and our providers operate internationally, so your data is processed outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, as applicable to each provider.

5. How long we keep it

6. On-chain data

The Perme protocol writes consent and access records to a public blockchain. Anything written to a blockchain is, by design, permanent: it cannot be edited or deleted by us or by anyone else, so the right to erasure cannot be exercised against it. Personal data is not written on-chain — raw data stays encrypted in the user’s personal data store (PDS) off-chain, and only records that prove integrity and consent are anchored on-chain. Please take this into account before using any product built on the protocol.

This policy covers the perme.io marketing site. Use of the Perme app, wallet, or SDK is covered separately by the terms and notices presented in those products.

7. Cookies and analytics

This site sets no advertising or tracking cookies and runs no analytics or profiling scripts. Only cookies strictly necessary to serve the site may be set by our host.

8. Your rights

Under the GDPR you have the right to:

To exercise any of these, write to info@perme.io. We answer within one month.

You also have the right to lodge a complaint with a data protection supervisory authority in the country where you live or work, or where you believe a breach occurred (Art. 77 GDPR).

9. Children

This site is not directed at people under 18, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

10. Automated decision-making

We do not make decisions about you by automated means alone, and we do not carry out profiling within the meaning of Article 22 GDPR.

11. External links

Our pages link to sites we do not control, including our documentation and social accounts. We are not responsible for their privacy practices; please read their policies.

12. Changes to this policy

We update this page when our practices change. The date at the top shows the current version.