The Protocol
  • Home
  • Technical Architecture
  • Attestation Network
  • Governance
  • Join Beta

Privacy Policy

The Protocol - Sovereign Agent Infrastructure

📅 Effective: January 2025
📋 Version: 1.0
🔒 GDPR Compliant

Table of Contents

  • 1. Data Controller
  • 2. Data Protection Officer
  • 3. Collection and Storage of Personal Data
  • 4. Data Processing for Specific Purposes
  • 5. Data Sharing
  • 6. Your Rights as Data Subject
  • 7. Data Security
  • 8. Cookies and Tracking
  • 9. Special Categories of Data
  • 10. Automated Decision-Making
  • 11. Protection of Minors
  • 12. Changes to Privacy Policy
  • 13. Contact for Privacy Inquiries
§ 1

Data Controller

Responsible for data processing under the General Data Protection Regulation (GDPR):

Raphael Jeziorny
The Protocol
Richard-Strauss-Straße 6
83395 Freilassing
Germany

Email: r.jeziorny@theprotocol.cloud
Phone: +49 157 33924375

§ 2

Data Protection Officer

Data Protection Officer

Raphael Jeziorny

The Protocol

Email: privacy@theprotocol.cloud

Email: datenschutz@theprotocol.cloud

Phone: +49 157 33924375

§ 3

Collection and Storage of Personal Data

3.1 When Visiting the Website

When accessing our website, your browser automatically sends information to our server, temporarily stored in a log file:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of retrieved file
  • Referring website (Referrer URL)
  • Browser used and operating system
  • Name of your access provider

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in data security and functionality)

Storage Duration: 7 days, then automatic deletion

3.2 Registration and Platform Use

During registration we collect:

  • Name
  • Email address
  • Company information
  • Payment information (for paid services)
  • Technical identifiers (DIDs, API keys)

Legal Basis: Art. 6(1)(b) GDPR (contract fulfillment)

Storage Duration: During contract term + legal retention periods

3.3 Agent-Related Data

For agent infrastructure operation, we process:

  • Agent identifiers (DIDs)
  • Transaction data (timestamps, amounts, parties)
  • Performance metrics
  • Security events
  • Federation connection data

Legal Basis: Art. 6(1)(b) GDPR (contract fulfillment)

Storage Duration:

  • Transaction data: 10 years (tax law requirements)
  • Technical logs: 90 days
  • Security events: 1 year
§ 4

Data Processing for Specific Purposes

4.1 Token Transactions (TEG Layer)

Processed data:

  • Wallet addresses
  • Transaction amounts
  • Timestamps
  • Smart contract interactions

Purpose: Token economy operations, compliance, fraud prevention

Legal Basis: Art. 6(1)(b) GDPR (contract fulfillment), Art. 6(1)(c) GDPR (legal obligation - anti-money laundering)

4.2 Zero-Knowledge Proofs

Privacy by Design:

  • No storage of data being proven
  • Only storage of proof hashes
  • Metadata about proof creation

Purpose: Trust building without data disclosure

Legal Basis: Art. 6(1)(b) GDPR (contract fulfillment)

4.3 Federation Services

For registry federation:

  • Registry identifiers
  • Connection metadata
  • Routing information
  • Performance statistics

Purpose: Enabling federated network

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)

§ 5

Data Sharing

5.1 No Sharing with Third Parties

We do not share your personal data with third parties, except:

  • You have explicitly consented (Art. 6(1)(a) GDPR)
  • To fulfill legal obligations (Art. 6(1)(c) GDPR)
  • To protect legitimate interests (Art. 6(1)(f) GDPR)

5.2 Data Processors

We use the following service providers:

  • Hosting: Hetzner Online GmbH (Server location: Germany)
  • Email: Google Workspace (GDPR compliant)
  • Monitoring: Uptime Robot (EU servers)

Data processing agreements per Art. 28 GDPR exist with all processors.

5.3 Third Country Transfers

Federation partners may be located worldwide. Transfers only with:

  • EU Commission adequacy decision
  • Appropriate safeguards (e.g., standard contractual clauses)
  • Explicit user consent
§ 6

Your Rights as Data Subject

Under the GDPR, you have the following rights:

Right of Access

Art. 15 GDPR

Obtain information about your processed data

Right to Rectification

Art. 16 GDPR

Request correction of inaccurate data

Right to Erasure

Art. 17 GDPR

Request deletion ("right to be forgotten")

Right to Restriction

Art. 18 GDPR

Request restriction of processing

Data Portability

Art. 20 GDPR

Receive data in machine-readable format

Right to Object

Art. 21 GDPR

Object to processing based on legitimate interest

Withdrawal of Consent

Art. 7(3) GDPR

Withdraw consent at any time

Right to Complain

Art. 77 GDPR

Lodge complaint with supervisory authority

Supervisory Authority:

Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18
91522 Ansbach
Germany

§ 7

Data Security

7.1 Technical and Organizational Measures

  • Encryption: TLS 1.3+ for all connections
  • Access control: Multi-factor authentication
  • Encryption at rest: AES-256
  • Regular security audits
  • Incident response plan
  • Regular encrypted backups

7.2 SPIFFE/SPIRE Integration

  • Short-lived cryptographic identities
  • Zero-trust architecture
  • Continuous authentication
§ 8

Cookies and Tracking

8.1 Necessary Cookies

  • Session cookies for authentication
  • Security cookies (CSRF protection)

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest)

8.2 No Analytics Cookies

Privacy First: We do not use tracking or analytics cookies.

§ 9

Special Categories of Data

We generally do not process special categories of personal data per Art. 9 GDPR (e.g., health data, religious beliefs, political opinions).

§ 10

Automated Decision-Making

10.1 Agent Activities

The platform uses automated systems for:

  • Fraud detection
  • Risk assessment
  • Performance optimization

Your Right: You have the right to human review of automated decisions that significantly affect you.

§ 11

Protection of Minors

Our services are not directed at persons under 18 years. We do not knowingly collect data from minors.

§ 12

Changes to Privacy Policy

Changes will be published on this page. For material changes, we will inform registered users by email.

§ 13

Contact for Privacy Inquiries

Privacy Inquiries

Email: privacy@theprotocol.cloud

Email: datenschutz@theprotocol.cloud

Or by mail to the address above

Terms of Service Privacy Policy Data Processing Agreement Cookie Policy Risk Notice Enterprise SLA

© 2025 The Protocol | Architected by Raphael Jeziorny

Impressum | Datenschutzerklärung