This Privacy Policy explains how Dot Vision Ltd ("Dot Vision", "we", "us") collects and uses personal data when you use www.onlyfarts.io and mint or interact with OnlyFarts NFTs.
Our registered office is:
VALLETTA BUILDINGS 2ND FLOOR SUITE 7TRIQ NOFS IN-NHAR
VALLETTA
VLT 1103
Malta
Dot Vision is the data controller. We comply with the EU General Data Protection Regulation (GDPR) and Malta's Data Protection Act (Cap. 586).
Contact for privacy matters: info@dotvision.io
1. The short version
- We collect as little as possible. You don't need to give us your name or email to mint.
- Your wallet address and transactions are recorded on the public Ethereum blockchain. That record is permanent and we cannot delete it.
- We don't sell your data and don't use it for targeted advertising.
- You have rights over your data and can complain to Malta's data protection authority (IDPC).
2. Blockchain data — please read
When you mint or transfer an NFT, your wallet address, the transaction details and timestamp are written to the Ethereum blockchain. This happens by the design of the network, not because we choose to publish it. Blockchain data is:
- public — anyone can view it on block explorers such as Etherscan;
- permanent — neither we nor anyone else can edit or delete it; and
- decentralised — it is stored by thousands of independent nodes worldwide.
A wallet address on its own doesn't reveal your identity, but it may be linked to you if you connect it to other information (e.g. an exchange account, ENS name or social profile). Please think about this before minting. We do not control the blockchain, so we are not the controller of data stored on it by the network. See section 7 for how this affects your rights.
3. What we collect and why
| Data | Source | Purpose | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|---|
| Wallet address, network, transaction hashes | Your wallet when you connect / mint | Enable minting, check eligibility and per-wallet limits, show your NFTs | Performance of a contract (6(1)(b)) | Off-chain copies: up to 24 months after mint closes. On-chain: permanent (outside our control) |
| IP address, browser/device type, timestamps, pages requested | Automatically by our hosting provider | Site security, preventing bots and attacks, fixing errors | Legitimate interests (6(1)(f)) | [30] days |
| Approximate location from IP (country) | Derived from IP | Blocking sanctioned jurisdictions | Legal obligation (6(1)(c)) and legitimate interests | Not stored beyond the request / [30] days in logs |
| Wallet sanctions/risk screening result | [SCREENING PROVIDER] | Complying with sanctions laws and preventing fraud | Legal obligation (6(1)(c)) and legitimate interests | [5] years where a match is found; otherwise not stored |
| Messages you send us | You | Replying to you, handling requests and complaints | Legitimate interests; legal obligation for rights requests | [24] months after last contact |
| Analytics data | Not collected on this Site | No analytics service is enabled | Not applicable | Not applicable |
We do not collect special category data (e.g. health, religion) and do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Automated bot detection or sanctions screening may block a mint attempt; you can contact us to have a person review it.
4. Where we share data
We share personal data only with:
- Service providers who process it on our behalf under contract: website hosting ([e.g. Vercel Inc.]), blockchain node/RPC provider ([e.g. Alchemy / Infura]), wallet connection service ([e.g. WalletConnect / Reown]), [sanctions screening provider], [email provider]. They may only use it on our instructions.
- Professional advisers (lawyers, accountants) where necessary.
- Authorities where required by law, e.g. in response to a lawful request or to comply with sanctions obligations.
- A buyer or successor if Dot Vision's business is reorganised or sold, subject to this Policy.
Third-party marketplaces, wallets, Discord and X are independent controllers; their own privacy policies apply when you use them.
5. International transfers
Some of our service providers are located outside the European Economic Area (e.g. the United States). Where data is transferred outside the EEA, we rely on an EU adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
6. Security
We use appropriate technical and organisational measures, including encrypted connections (HTTPS), access controls and limited data collection. We never ask for your seed phrase or private keys — anyone who does is a scammer.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict processing;
- data portability;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, without affecting earlier processing; and
- complain to a supervisory authority.
Blockchain limits. We will delete or restrict off-chain data we hold (e.g. our logs, database copies, email lists) when you exercise these rights. We cannot alter or delete data recorded on the Ethereum blockchain, because we do not control it and it is technically impossible. If you want to stop your wallet being associated with an NFT, you can transfer the NFT to another wallet, but past transactions remain visible. On request, we will stop displaying your wallet address on our Site where technically possible.
How to exercise your rights. Email info@dotvision.io. We may ask you to prove control of a wallet (e.g. by signing a message — never by sharing keys). We respond within one month, extendable by two months for complex requests. It's free unless requests are manifestly unfounded or excessive.
Complaints. You can complain to the Information and Data Protection Commissioner (IDPC), Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, Malta — idpc.org.mt — or to the authority in your EU country of residence. We'd appreciate the chance to resolve it first.
8. Children
The Services are not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
9. Cookies
See our Cookie Notice.
10. Changes
We may update this Policy. The "Last updated" date shows when; material changes will be announced on the Site.