Privacy Policy

Version 2.0 · Effective: 1 August 2026 · Last updated: 1 August 2026

1. Introduction and Scope

1.1 Overview

Jupiter Meta Labs Foundation (the “Foundation”, “we”, “us” or “our”) develops and maintains the JMDT Chain platform (the “Platform”) and the JMDT tokens (the “Tokens”). We are committed to protecting the privacy of everyone who interacts with the Platform and the Tokens, and to holding ourselves to the strictest reasonable standard of data minimisation.

This Privacy Policy explains how we approach the collection, use, storage, protection and disclosure of data in connection with the Platform, the Tokens, our related services and communications, and the operation of and participation in validator nodes. It should be read together with our Terms of Use and any product- or service-specific terms that apply to you.

1.2 Our Privacy-by-Design Philosophy

Privacy is not a feature we add after the fact; it is a design constraint we build around. In practice, this means four things:

1.3 Who This Policy Applies To

This Policy applies to all users of, and visitors to, the Platform, including general users who hold or transact JMDT Tokens, enterprise users building applications on the Platform, validator node operators participating in network consensus, and visitors to our websites and documentation.

2. The Data We Process

2.1 Our Data-Minimisation Commitment

We have deliberately designed the Platform so that the vast majority of interactions require no personal data at all. Where data must be processed to keep the network secure and functioning, we limit that processing to what is strictly necessary, retain it for as short a period as possible, and avoid linking it to your identity wherever we can.

2.2 Personal Data

You do not need to create an account, undergo identity verification, or supply personal information in order to hold or transact JMDT Tokens or to interact with the Platform’s core protocol. For those core interactions, we do not collect names, contact details, government-issued identifiers, biometric data, payment card details, or behavioural or demographic profiles.

There are, however, two narrow circumstances in which we process a limited amount of personal data, and we want to be transparent about them.

2.3 On-Chain (Blockchain) Data

We do not actively collect, aggregate, or profile wallet addresses, transaction histories, Token holdings, or smart-contract interaction data. It is important to understand, however, that transactions submitted to a public blockchain are recorded on that blockchain by its distributed network of nodes - not by us - and are, by design, publicly visible and permanent. This on-chain record exists independently of the Foundation and is a characteristic of the underlying technology rather than a collection practice of ours. Section 6 explains what this means for you in more detail.

2.4 Technical and Network Operations Data

To operate a secure and reliable network, we process a small volume of technical data. This includes basic connection and connectivity information, low-level blockchain protocol communications, and validator synchronisation data exchanged between nodes. We also process transaction broadcasts as they propagate across the network (without attributing them to identified individuals), anonymous validator performance metrics, and anonymised error logs used for maintenance and diagnostics.

2.5 Voluntary Communications

Any direct communication between you and the Foundation is user-initiated. We do not send unsolicited marketing, and we only process the personal data contained in a communication because you have chosen to send it to us for a specific purpose - support, enterprise engagement, community participation, or bug reporting.

3. Why We Process Data and Our Lawful Bases

3.1 Purposes and Legitimate Interests

Where we process the limited data described above, we do so because we have a legitimate interest in operating the Platform safely and effectively. Those legitimate interests include securing the network and preventing abuse, performing technical maintenance and monitoring performance, developing and improving the protocol, and managing our infrastructure. We balance these interests against your privacy and, given how little data is involved and how transiently we hold it, we consider that balance firmly in favour of the narrow processing we carry out.

3.2 Legal Compliance

We may also process data where we are required to do so in order to meet regulatory and security obligations, or to cooperate with lawful judicial or governmental process. Any such processing is limited to what the applicable obligation genuinely requires.

3.3 What We Do Not Do

We do not conduct targeted advertising, build user profiles, personalise experiences on the basis of tracking, sell or monetise data, or run commercial business analytics on our users. We also do not use Google Analytics or comparable third-party tracking services, advertising pixels, or third-party marketing platforms on our properties.

4. Data Sharing and Disclosure

4.1 No Commercial Sharing

We do not share data with advertisers, data brokers, analytics firms, or commercial partners for their own purposes. We do not treat data as a product.

4.2 Infrastructure and Service Providers

A limited amount of technical data may be processed on our behalf by trusted service providers — principally our cloud infrastructure provider ([e.g., Google Cloud Platform, United States]), together with network and security service providers. These providers act as our processors under written agreements that restrict them to processing data only on our instructions and for the purposes of delivering their services to us.

4.3 Legal and Regulatory Disclosure

We will disclose data only in response to valid legal process or where we are otherwise required by law. In every such case, we disclose the minimum data necessary, subject the request to legal review, and — where we are lawfully permitted to do so — notify the affected user. Where appropriate, we may publish transparency reporting on the volume and nature of such requests.

4.4 Emergency Situations

In rare cases involving an imminent threat to the safety of a person or the integrity of the network, we may share limited data to address that threat. Such disclosures remain subject to legal review and are confined to what the emergency genuinely requires.

5. Data Storage, Security and Retention

5.1 Storage Infrastructure

The limited data we hold is stored on redundant, resilient cloud infrastructure ([e.g., Google Cloud Platform, United States]). Our infrastructure and controls are aligned with recognised security standards, including SOC 2 and ISO/IEC 27001.

5.2 Security Measures

Encryption. Data at rest is protected using AES-256 encryption, data in transit is protected using TLS 1.3, and cryptographic keys are managed within hardware security modules.

Access control. Access to systems is governed by multi-factor authentication and role-based access control on a least-privilege basis, supported by comprehensive audit logging and access reviews conducted at least quarterly.

Minimised server-side knowledge. Wherever practicable we rely on client-side cryptography and zero-knowledge techniques so that our servers hold as little sensitive information as the architecture allows.

5.3 Security Monitoring

Our environment is monitored on a continuous basis. We conduct periodic penetration testing, maintain an active vulnerability-management programme, and operate a defined incident-response process so that any security event can be identified and addressed promptly.

5.4 Retention and Minimisation

We retain technical data only for as long as it is needed for the purpose for which it was processed. Operational logs are automatically purged after 30 days, data is anonymised wherever feasible, and our retention practices are reviewed as part of our periodic audits.

6. Blockchain Technology and Immutability

Because the Platform is built on public blockchain technology, certain characteristics of that technology directly affect how data behaves - in ways that differ fundamentally from a traditional, centrally controlled database. Transactions recorded on the blockchain are immutable and cannot be altered or deleted; they are publicly visible; and the ledger is stored in a distributed manner across the network rather than under any single party’s control.

A practical consequence of this design is that no one, including the Foundation, can edit or erase data once it has been written to the chain. You remain in control of your own participation: you decide which transactions to submit, and you are responsible for the security of your private keys and wallet. However, the usual right to have on-chain data deleted cannot technically be honoured, because the ledger is immutable and outside our control. Smart contracts on the Platform execute automatically according to their code, operate transparently, and are not designed to process personal data.

7. Your Rights and Their Practical Limits

We respect the data-protection rights available to you under applicable law, including rights of access, correction, deletion, restriction, objection and portability. The practical scope of these rights is shaped by how little personal data we hold. In most cases there is no identity-linked personal profile for us to access, on-chain data is public and immutable, and our technical logs are transient and quickly purged. Within those constraints, you retain full control over your wallet and transactions, you may cease using the Platform at any time, and you control whether and how you communicate with us.

If you wish to exercise a right, raise a concern, or make a complaint, please contact us using the details below. We aim to respond within 30 days.

Data Protection Officer: Yashaswini – <[email protected]>

Legal Team: [Legal Email Address][Foundation Legal Address]

Our complaint process moves from initial contact, to investigation, to resolution; where you remain dissatisfied, you may escalate to the competent supervisory authority in your jurisdiction.

8. International Data Transfers

Our infrastructure and validator network are global, and the limited data we process may therefore be handled in jurisdictions other than your own - including, in particular, [the United States, via our cloud provider]. Wherever data crosses borders, we protect it through encryption, appropriate contractual safeguards with our providers, and compliance with the transfer requirements of applicable data-protection law.

9. Children’s Privacy

The Platform is not directed at children, and we do not knowingly collect data from them. If we become aware that we have inadvertently processed data relating to a child, we will delete it. Our practices are designed to be consistent with applicable children’s privacy laws, including the U.S. Children’s Online Privacy Protection Act (COPPA).

10. Cookies and Similar Technologies

Our websites use only strictly necessary cookies - for example, to maintain a session, provide security, and balance load. We do not use third-party cookies, and we do not use cookies for advertising, cross-site tracking, or behavioural profiling.

11. Third-Party Links and Services

The Platform and our documentation may link to third-party services such as blockchain explorers, exchanges, community forums, and external documentation. These services are operated independently and are governed by their own privacy policies. We encourage you to review those policies, as we are not responsible for the practices of third parties.

12. Data Breach Notification

Should a data breach occur, we follow a structured process of assessment, containment, investigation and remediation. Where a breach is likely to affect your rights, we will notify affected users and the relevant regulatory authorities within the timeframes required by applicable law, and we will document the incident and our response.

13. Business Transfers and Corporate Changes

If the Foundation is involved in a merger, acquisition, restructuring, or transfer of assets, any data covered by this Policy may transfer as part of that transaction, and the privacy obligations set out here will continue to apply to it. We will provide notice of any change that materially affects how your data is handled.

14. Changes to This Privacy Policy

We review this Policy at least annually, and update it as needed to reflect changes in law, technology, or our practices. Where a change is material, we will provide appropriate notice; the “Last updated” date at the top of this Policy always reflects the most recent version.

15. Jurisdiction-Specific Rights

Depending on where you are located, you may have specific statutory rights. We recognise and give effect to these rights within the minimal-data context described in this Policy:

European Economic Area and United Kingdom (GDPR / UK GDPR). You have rights of access, rectification, erasure, restriction, objection and portability, and the right to lodge a complaint with a supervisory authority. Our lawful basis for the limited processing we carry out is our legitimate interest in operating a secure network, as described in Section 3.

California (CCPA / CPRA). You have the right to know what personal information is processed, to request its deletion, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined under California law.

India (Digital Personal Data Protection Act, 2023). Where the Act applies, you have the right to access and correct your personal data, to seek its erasure, to nominate a representative, and to a grievance-redressal mechanism. You may contact our Data Protection Officer using the details in Section 7.

#

16. Transparency and Accountability

Accountability underpins everything above. We embed privacy by design into how the Platform is built, subject our controls to independent audit, and treat privacy as a matter of continuous improvement rather than one-time compliance.

17. Contacting Us

If you have any questions about this Privacy Policy or how we handle data, please contact our Data Protection Officer or Legal Team using the details in Section 7. In short: we collect as little as we can, we secure what we must hold, we are transparent about our practices, we leave you in control of your participation, and we hold ourselves accountable to the law and to you.