1. Who We Are
Medallion XLN ("Medallion XLN", "we", "our", "us") operates the open-beta creator platform at medallionxln.com (the "Service"). For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for personal data described in this policy.
Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY / REGISTRATION NUMBER].
Privacy contact: privacy@medallionxln.com
2. Scope
This policy applies to everyone who uses the Service, wherever they are located. Sections 9 and 10 describe rights available specifically to individuals in the European Economic Area, the United Kingdom, and Switzerland. Section 11 describes rights available to California residents.
3. Information We Collect
3.1 Information you give us
- Account information - email address, username, display name, profile details you choose to add.
- Authentication data - one-time login codes and the timestamps of their issue and use.
- Content you create - posts, comments, reactions, group and community activity, uploaded media.
- Messages - direct messages you send through the Service.
- AI prompts and conversations - anything you type into an AI agent, and the responses returned. See Section 5.
- Support communications - anything you send us by email or through in-product support.
3.2 Information generated by your use
- Usage data - pages viewed, features used, agent runs consumed, session timestamps.
- Device and connection data - IP address, browser type and version, operating system, referring page.
- Cookies and similar technologies - see Section 7.
3.3 Wallet and on-chain information
- Algorand address associated with your account.
- Wallet key material held by the Service: [DESCRIBE EXACTLY WHAT IS STORED AND HOW IT IS PROTECTED - see note below]
- On-chain transactions - mints, transfers, and claims recorded on the Algorand public ledger.
Transactions recorded on a public blockchain are permanent, publicly visible, and outside our control. Please read Section 10.2 before you mint or transact.
3.4 Payment information
Payments are processed by Stripe. We do not receive or store your full card number. We retain a customer identifier, subscription status, credit balance, and transaction history.
3.5 Third-party contact data
Certain AI agent features can retrieve business contact information about people who are not Medallion XLN users. Where we process such data we rely on legitimate interests, and the individuals concerned hold the rights described in Section 10. Requests may be sent to privacy@medallionxln.com.
4. Why We Process It, and Our Legal Basis
Under Article 6 GDPR we rely on the following bases:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account, deliver the Service | Account, authentication, content | Performance of a contract - Art. 6(1)(b) |
| Run AI agents you invoke | Prompts, conversation history, account identifiers | Performance of a contract - Art. 6(1)(b) |
| Process payments and subscriptions | Payment and billing data | Contract - Art. 6(1)(b); legal obligation for tax records - Art. 6(1)(c) |
| Wallet operations and on-chain actions you request | Wallet and transaction data | Performance of a contract - Art. 6(1)(b) |
| Security, abuse prevention, service integrity | Usage, device, IP, authentication logs | Legitimate interests - Art. 6(1)(f) |
| Product analytics and performance measurement | Usage and device data | Consent - Art. 6(1)(a) |
| Newsletters and marketing email | Email address | Consent - Art. 6(1)(a) |
| Responding to legal process and regulatory duties | As required | Legal obligation - Art. 6(1)(c) |
| Retrieving third-party business contact data | Name, role, business email | Legitimate interests - Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure and functional platform is not overridden by your rights. You may object at any time under Section 10. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
5. Artificial Intelligence
5.1 You are interacting with an AI system
Medallion XLN agents are artificial intelligence systems. When you use Agent Chat or any agent from the marketplace, you are interacting with software, not a human being. This is disclosed in the product interface as well as here.
5.2 What happens to your prompts
Your prompts, uploaded context, and conversation history are transmitted to our AI model provider in order to generate a response. Agents may additionally call external tools to search the web, look up Medallion XLN member records, or retrieve business contact information. The provider and tool vendors are listed in Section 8.
Model provider currently in use: [PROVIDER NAME AND PROCESSING LOCATION].
Training: [STATE WHETHER THE PROVIDER MAY TRAIN ON YOUR INPUTS - VERIFY AGAINST THE PROVIDER'S API TERMS BEFORE PUBLISHING]
5.3 Output is not reliable by default
AI output can be inaccurate, incomplete, or fabricated, including when it appears confident and specific. Do not rely on agent output for legal, financial, medical, or other consequential decisions without independent verification.
5.4 Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significant effects, based solely on automated processing within the meaning of Article 22 GDPR. Automated systems are used for abuse detection and rate limiting; where such a system restricts your account you may request human review at support@medallionxln.com.
5.5 Agents published by third parties
The marketplace hosts agents published by other users. When you use one, your prompts are processed under this policy, but the agent's configuration, instructions, and behaviour are set by its publisher. We do not review or endorse third-party agent behaviour.
6. Retention
We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it.
| Category | Retention period |
|---|---|
| Account data | For the life of the account, then [30 / 60 / 90] days after deletion request |
| One-time login codes | Minutes; deleted or expired after use |
| Posts, comments, community content | Until you delete it or your account is closed |
| Direct messages | Until deleted by either participant or account closure |
| AI prompts and conversation history | [CONFIRM - browser-side history is under your control; state server-side retention] |
| Security and access logs | [90 / 180] days |
| Billing and transaction records | Up to 7 years, to meet tax and accounting obligations |
| On-chain transactions | Permanent - see Section 10.2 |
Do not publish a period you do not actually enforce. Stated retention that is not honoured is itself a compliance failure.
7. Cookies and Similar Technologies
We use:
- Strictly necessary cookies - session, authentication, security, and load handling. These cannot be switched off and do not require consent.
- Analytics and performance cookies - only where you have consented.
Users in the EEA and UK are shown a consent banner on first visit and can change their choice at any time via [LINK OR CONTROL - a banner is required; browser settings alone are not valid consent under the ePrivacy Directive].
8. Who We Share Information With
We do not sell personal information and we do not share it for cross-context behavioural advertising. We use the following processors and sub-processors:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| [AI MODEL PROVIDER] | Generating agent responses | Prompts, conversation history | [LOCATION + TRANSFER MECHANISM] |
| [WEB SEARCH VENDOR] | Agent web search | Search queries | [LOCATION] |
| [CONTACT LOOKUP VENDOR] | Business contact retrieval | Names, domains, business emails | [LOCATION] |
| Stripe | Payments and subscriptions | Billing data, customer ID | US / EU - SCCs |
| [HOSTING PROVIDER] | Application and database hosting | All stored platform data | [LOCATION] |
| [EMAIL DELIVERY PROVIDER] | Transactional and newsletter email | Email address, message content | [LOCATION] |
| Algorand public network | On-chain transactions you initiate | Wallet address, transaction data | Public, global, permanent |
We may also disclose information:
- to legal or regulatory authorities where required by law;
- to protect the rights, safety, or property of Medallion XLN, our users, or the public;
- to a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.
9. International Transfers
Some of our processors are located outside the EEA and UK. Where we transfer personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses together with supplementary technical and organisational measures.
[EACH NON-EEA PROCESSOR MUST HAVE AN EXECUTED DPA AND SCCs BEFORE THIS SECTION IS ACCURATE. A PROCESSOR WITH NO SCCs CANNOT LAWFULLY RECEIVE EU PERSONAL DATA, WHATEVER THIS PAGE SAYS.]
You may request a copy of the safeguards in place by writing to privacy@medallionxln.com.
10. Your Rights (EEA, UK, Switzerland)
10.1 What you can ask for
- Access - a copy of the personal data we hold about you (Art. 15).
- Rectification - correction of inaccurate or incomplete data (Art. 16).
- Erasure - deletion of your data, subject to Section 10.2 (Art. 17).
- Restriction - limiting how we process your data (Art. 18).
- Portability - a machine-readable export of data you provided (Art. 20).
- Objection - to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
- Withdraw consent - at any time, without affecting prior processing.
Write to privacy@medallionxln.com. We respond within one month, extendable by two further months for complex requests, and will tell you if we extend. We do not charge for these requests.
You also have the right to lodge a complaint with your national supervisory authority. Our lead supervisory authority is [NAME OF AUTHORITY, IF ESTABLISHED IN THE EU].
10.2 The limits of erasure on a blockchain
We can delete your account, profile, posts, messages, and off-chain records. We cannot delete or alter data already written to the Algorand public ledger. Blockchain records are immutable by design, replicated across nodes we do not operate, and permanently public.
Before you mint or transact, understand that the wallet address and transaction details become a permanent public record that cannot be erased on request. If you erase your account, we will remove the link between your identity and your wallet address in our systems, but the on-chain record remains.
10.3 EU Representative
[IF YOU ARE NOT ESTABLISHED IN THE EU AND OFFER THE SERVICE TO EU USERS, ARTICLE 27 GDPR REQUIRES YOU TO APPOINT AN EU REPRESENTATIVE AND NAME THEM HERE.]
11. California Privacy Rights (CCPA / CPRA)
California residents may:
- know what personal information is collected, used, and disclosed;
- request deletion of personal information;
- correct inaccurate personal information;
- opt out of sale or sharing - note that we do not sell or share personal information;
- limit use of sensitive personal information;
- not be discriminated against for exercising these rights.
Requests: privacy@medallionxln.com. We verify requests by confirming control of the account email. Authorised agents may submit requests with written proof of authorisation.
12. Security
We apply technical and organisational measures including:
- encryption of data in transit using TLS;
- server-side encryption of direct message content using AES-256-GCM;
- passwordless authentication with short-lived, single-use login codes;
- access controls limiting who can reach production data;
- logging of authentication and administrative events.
Direct messages are encrypted at rest on our servers. They are not end-to-end encrypted: message content is decrypted server-side in order to be displayed, so we are technically capable of accessing it. Do not treat direct messages as a confidential channel.
No system is completely secure and we cannot guarantee absolute security.
13. Data Breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will notify you directly without undue delay.
To report a suspected vulnerability or breach, contact security@medallionxln.com.
14. Children
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has provided us data, contact privacy@medallionxln.com.
15. Changes to This Policy
We may update this policy. Every version carries a version number and an effective date. For material changes we will give notice by email or in-product at least 14 days before the change takes effect. Where a change requires your consent, we will ask for it rather than relying on continued use.
| Version | Effective | Summary |
|---|---|---|
| 2.0 | 23 July 2026 | Added GDPR disclosures, AI processing transparency, sub-processor list, retention schedule, breach notification, blockchain erasure limits |
| 1.0 | [ORIGINAL DATE] | Initial open-beta policy |
16. Contact
Medallion XLN
Privacy: privacy@medallionxln.com
Support: support@medallionxln.com
Security: security@medallionxln.com