1. Introduction
This Privacy Policy explains how personal data are processed when you visit the website http://arxium.network (the "Website") and when you contact us by email. The Website is an informational, multi-page marketing website for the Arxium Network project, containing a project overview, roadmap, tokenomics, team information, documents, blog content and links to community channels.
The Website has no user accounts, no login or registration, no wallet-connection functionality, no payment processing, no token purchase functionality, no web forms and no newsletter signup. Nevertheless, visiting the Website and contacting us by email involve the processing of certain personal data, in particular technical data that are automatically processed to deliver and protect the Website. This Policy describes that processing transparently.
This Policy is drafted primarily in accordance with the Swiss Federal Act on Data Protection ("FADP") and the Swiss Data Protection Ordinance ("DPO").
2. Identity and Contact Details of the Controller
The controller responsible for the processing described in this Policy is:
ARXIUM PROTOCOL AG
Aktiengesellschaft (AG)
Registered office: Cham, Switzerland
c/o Zuger BusinessHub GmbH, Alte Steinhauserstrasse 10, 6330 Cham
Swiss commercial register / UID: CHE-___.___.___
Privacy contact: contact@arxium.network
3. Scope of this Privacy Policy
This Policy applies to (i) the processing of personal data of visitors to the Website and (ii) the processing of personal data of persons who contact us at contact@arxium.network. It does not apply to third-party websites, community channels or social media platforms that are linked from the Website; those are operated by third parties under their own privacy policies (see Section 24).
4. Categories of Personal Data Processed
We do not ask you to provide any personal data to use the Website. The categories of personal data processed are limited to:
- automatic technical and security data generated when you access the Website (Sections 5–7);
- data contained in strictly necessary cookies or similar technologies, if and to the extent such technologies are active (Section 8); and
- data you provide when contacting us by email (Section 9).
5. Automatic Technical and Security Data
When you access the Website, technical data are automatically processed in order to deliver the requested content to your device and to keep the Website secure and available. Depending on the configuration, this may include:
- IP address
- date and time of access
- requested URL and page
- HTTP request information (method, status code, transferred data volume)
- browser type and version and device information
- operating system
- language and locale settings
- referring URL
- traffic routing information
- security and bot-detection information
- Cloudflare request identifiers (e.g. Ray ID)
- information contained in server or security logs
This processing is technically necessary: without it, the Website cannot be delivered to your device or protected against attacks and abuse.
6. Website and Server Logs
Access and security events may be recorded in server and security logs operated by our hosting and security provider (Section 7) and, where applicable, in logs accessible to us. Logs are used exclusively for the purposes stated in Section 10 (delivery, availability, security, abuse prevention, troubleshooting) and, where necessary, to establish, exercise or defend legal claims. Log retention is described in Section 18.
7. Cloudflare Pages, CDN and Security Services
The Website is hosted and delivered through Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and its affiliates (including Cloudflare Germany GmbH for certain EEA/Swiss arrangements, to be confirmed) ("Cloudflare"). Cloudflare provides hosting, content delivery network (CDN), DNS and security services (such as protection against distributed denial-of-service attacks and malicious bots) and, for this purpose, processes the technical data described in Sections 5 and 6.
For hosting and content delivery, Cloudflare generally acts as our processor on the basis of a data processing agreement. For certain network security, threat intelligence and abuse-prevention activities, Cloudflare may act as an independent controller.
Cloudflare operates a global network of data centres; see Section 17 on international data processing. Further information is available in Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.
9. Communications by Email
If you contact us at contact@arxium.network, we process the personal data contained in your inquiry, including:
- your name (as provided)
- your email address
- the contents of your message
- any attachments
- date and time of the message
- related technical metadata (e.g. mail headers, sending server information)
- subsequent correspondence with you
Our email service is provided by e-mail hosting provider, which processes email data on our behalf as a service provider. Providing personal data by email is voluntary; however, without your email address and message we cannot respond to your inquiry.
10. Purposes of Processing
We process personal data exclusively for the following purposes:
- technically delivering the content of the Website to your device
- maintaining the availability, stability and performance of the Website
- preventing and detecting fraud, bots, abuse, and cyberattacks, and protecting the Website and its infrastructure
- troubleshooting technical issues and maintaining security
- responding to inquiries sent to us by email and managing the related correspondence
- establishing, exercising or defending legal claims
- complying with legal obligations to which we are subject
We do not process personal data for marketing, analytics, newsletters or customer-account purposes, because such functions do not exist on the Website. Should such functions be introduced, this Policy will be updated beforehand.
11. Legal Grounds and Justification under Swiss Law
Under the FADP, processing of personal data by private controllers does not require a legal basis in every case; it must comply with the processing principles (Art. 6 FADP) and must not unlawfully breach the personality rights of the data subjects (Art. 30–31 FADP). Where a justification is required, we rely on:
- our overriding private interests (Art. 31(1) FADP), in particular in securely and reliably operating the Website, defending it against attacks and abuse, and responding to inquiries addressed to us;
- performance of steps at your request, where you contact us in connection with a potential contract or business relationship;
- compliance with legal obligations under Swiss law; and
- your consent, where we exceptionally ask for it for a specific processing activity (which is currently not the case).
12. Data Recipients and Service Providers
We share personal data only with the following categories of recipients, and only to the extent necessary:
- Cloudflare, Inc. and its affiliates – hosting, content delivery and security provider (Section 7);
- professional advisers (e.g. lawyers, auditors) where necessary for legal or compliance purposes; and
- courts and public authorities, where we are legally required to disclose data or where disclosure is necessary to establish, exercise or defend legal claims.
Service providers that process personal data on our behalf are bound by data processing agreements in accordance with Art. 9 FADP.
13. No Analytics, Advertising, Behavioural Tracking or Profiling
Based on the current configuration, the Website does not use analytics tools, advertising technologies, behavioural tracking, cross-site tracking or profiling. Security-related evaluation of technical data by Cloudflare (e.g. bot detection) serves exclusively to protect the Website and does not constitute profiling for marketing purposes.
14. GDPR
If you are located in the European Economic Area (EEA) and the GDPR applies to our processing of your personal data, the following additional information applies.
Legal Bases under Art. 6(1) GDPR
- Art. 6(1)(f) GDPR (legitimate interests): delivering and securing the Website, preventing fraud, bots and cyberattacks, maintaining logs, responding to inquiries, and establishing, exercising or defending legal claims. Our legitimate interests are the secure and reliable operation of the Website and communication with interested parties.
- Art. 6(1)(b) GDPR: where your inquiry relates to steps prior to entering into a contract at your request.
- Art. 6(1)(c) GDPR: compliance with legal obligations to which we are subject.
- Art. 6(1)(a) GDPR: consent, where we ask for it for a specific activity (currently not the case).
Subject to the statutory conditions, you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21) GDPR, as well as the right to withdraw consent at any time (Art. 7(3) GDPR) and the right not to be subject to solely automated decision-making within the meaning of Art. 22 GDPR (which we do not carry out).
You have the right to lodge a complaint with a supervisory authority in the EEA member state of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR).
15. No Sale of Personal Data
We do not sell personal data and do not disclose personal data to third parties in exchange for remuneration or other consideration.
16. No Automated Decision-Making
We do not make automated individual decisions within the meaning of Art. 21 FADP that produce legal effects for you or significantly affect you. Automated security mechanisms (such as blocking malicious traffic) serve exclusively to protect the Website.
17. International Data Processing and Transfers
Cloudflare operates a global network of data centres. As a result, the technical data described in Sections 5–7 may be processed on servers outside Switzerland, including in countries whose data protection laws are not recognised as providing an adequate level of protection.
You may contact us at contact@arxium.network to request further information about the countries involved and the safeguards applied, including, where applicable, a copy of the relevant contractual safeguards.
18. Data Retention
We retain personal data only as long as necessary for the purposes stated in this Policy or as required by law. Where exact periods are stated as placeholders, they must be confirmed before publication. When retention is no longer necessary, data are deleted or anonymised.
19. Data Security
We and our service providers apply appropriate technical and organisational measures under Art. 8 FADP and Art. 1–6 DPO to protect personal data against unauthorised access, loss, misuse and alteration, including transport encryption (TLS), access controls and the security services described in Section 7. No internet transmission or storage system can be described as absolutely secure; we maintain measures appropriate to the risk.
20. Your Rights under Swiss Law
Under the FADP you have, subject to the statutory conditions and exceptions, the right to:
- request information about whether and which personal data concerning you are processed (Art. 25 FADP);
- request the correction of inaccurate personal data (Art. 32(1) FADP);
- request the deletion or destruction of personal data;
- request that a specific processing activity be restricted or prohibited, or that disclosure to third parties be prohibited (Art. 32(2) FADP);
- receive certain personal data that you have disclosed to us in a commonly used electronic format, or have them transferred to another controller, where the statutory requirements for data portability are met (Art. 28 FADP);
- withdraw consent at any time with effect for the future, where processing is based on consent (currently no processing is based on consent); and
- object to processing and pursue legal remedies before the competent civil courts (Art. 32(2) FADP in conjunction with Art. 28 ff. of the Civil Code).
21. How to Exercise Your Rights
You may exercise your rights at any time by contacting us at contact@arxium.network. We may need to verify your identity by appropriate and proportionate means before responding. We respond within the statutory time limits (as a rule, within 30 days under Swiss law for access requests). Exercising your rights is in principle free of charge.
22. Right to Contact the FDPIC
You may lodge a report or complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (https://www.edoeb.admin.ch). This is without prejudice to any other administrative or judicial remedy.
23. External Links and Social Media Channels
The Website contains links to external websites, documents and community channels (e.g. social media and messaging platforms). Based on the current configuration, such content is linked, not embedded, meaning no data are transmitted to those third parties merely by loading our pages.
24. Children and Minimum Age
The Website is informational and not directed at children. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data by email, please contact us at contact@arxium.network so that we can delete such data.
25. Changes to this Privacy Policy
We may amend this Policy at any time, in particular if the functionality of the Website changes (for example, if a newsletter, forms, analytics, wallet connection, token sale or KYC process is introduced) or if the legal framework changes. The version published on the Website is the current version; the "Last updated" date indicates the latest revision. Material changes will be highlighted on the Website where reasonably possible.
26. Contact Information
For all privacy-related matters:
ARXIUM PROTOCOL AG
c/o Zuger BusinessHub GmbH, Alte Steinhauserstrasse 10, 6330 Cham, Switzerland
Email: contact@arxium.network