Privacy Policy

Version: 2.0 Effective: 23 July 2026 We do not sell personal data

1. Who We Are

Medallion XLN ("Medallion XLN", "we", "our", "us") operates the open-beta creator platform at medallionxln.com (the "Service"). For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for personal data described in this policy.

Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY / REGISTRATION NUMBER].

Privacy contact: privacy@medallionxln.com

2. Scope

This policy applies to everyone who uses the Service, wherever they are located. Sections 9 and 10 describe rights available specifically to individuals in the European Economic Area, the United Kingdom, and Switzerland. Section 11 describes rights available to California residents.

3. Information We Collect

3.1 Information you give us

  • Account information - email address, username, display name, profile details you choose to add.
  • Authentication data - one-time login codes and the timestamps of their issue and use.
  • Content you create - posts, comments, reactions, group and community activity, uploaded media.
  • Messages - direct messages you send through the Service.
  • AI prompts and conversations - anything you type into an AI agent, and the responses returned. See Section 5.
  • Support communications - anything you send us by email or through in-product support.

3.2 Information generated by your use

  • Usage data - pages viewed, features used, agent runs consumed, session timestamps.
  • Device and connection data - IP address, browser type and version, operating system, referring page.
  • Cookies and similar technologies - see Section 7.

3.3 Wallet and on-chain information

  • Algorand address associated with your account.
  • Wallet key material held by the Service: [DESCRIBE EXACTLY WHAT IS STORED AND HOW IT IS PROTECTED - see note below]
  • On-chain transactions - mints, transfers, and claims recorded on the Algorand public ledger.

Transactions recorded on a public blockchain are permanent, publicly visible, and outside our control. Please read Section 10.2 before you mint or transact.

3.4 Payment information

Payments are processed by Stripe. We do not receive or store your full card number. We retain a customer identifier, subscription status, credit balance, and transaction history.

3.5 Third-party contact data

Certain AI agent features can retrieve business contact information about people who are not Medallion XLN users. Where we process such data we rely on legitimate interests, and the individuals concerned hold the rights described in Section 10. Requests may be sent to privacy@medallionxln.com.

4. Why We Process It, and Our Legal Basis

Under Article 6 GDPR we rely on the following bases:

PurposeData usedLegal basis
Create and operate your account, deliver the ServiceAccount, authentication, contentPerformance of a contract - Art. 6(1)(b)
Run AI agents you invokePrompts, conversation history, account identifiersPerformance of a contract - Art. 6(1)(b)
Process payments and subscriptionsPayment and billing dataContract - Art. 6(1)(b); legal obligation for tax records - Art. 6(1)(c)
Wallet operations and on-chain actions you requestWallet and transaction dataPerformance of a contract - Art. 6(1)(b)
Security, abuse prevention, service integrityUsage, device, IP, authentication logsLegitimate interests - Art. 6(1)(f)
Product analytics and performance measurementUsage and device dataConsent - Art. 6(1)(a)
Newsletters and marketing emailEmail addressConsent - Art. 6(1)(a)
Responding to legal process and regulatory dutiesAs requiredLegal obligation - Art. 6(1)(c)
Retrieving third-party business contact dataName, role, business emailLegitimate interests - Art. 6(1)(f)

Where we rely on legitimate interests, we have assessed that our interest in operating a secure and functional platform is not overridden by your rights. You may object at any time under Section 10. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

5. Artificial Intelligence

5.1 You are interacting with an AI system

Medallion XLN agents are artificial intelligence systems. When you use Agent Chat or any agent from the marketplace, you are interacting with software, not a human being. This is disclosed in the product interface as well as here.

5.2 What happens to your prompts

Your prompts, uploaded context, and conversation history are transmitted to our AI model provider in order to generate a response. Agents may additionally call external tools to search the web, look up Medallion XLN member records, or retrieve business contact information. The provider and tool vendors are listed in Section 8.

Model provider currently in use: [PROVIDER NAME AND PROCESSING LOCATION].

Training: [STATE WHETHER THE PROVIDER MAY TRAIN ON YOUR INPUTS - VERIFY AGAINST THE PROVIDER'S API TERMS BEFORE PUBLISHING]

5.3 Output is not reliable by default

AI output can be inaccurate, incomplete, or fabricated, including when it appears confident and specific. Do not rely on agent output for legal, financial, medical, or other consequential decisions without independent verification.

5.4 Automated decision-making

We do not make decisions producing legal effects concerning you, or similarly significant effects, based solely on automated processing within the meaning of Article 22 GDPR. Automated systems are used for abuse detection and rate limiting; where such a system restricts your account you may request human review at support@medallionxln.com.

5.5 Agents published by third parties

The marketplace hosts agents published by other users. When you use one, your prompts are processed under this policy, but the agent's configuration, instructions, and behaviour are set by its publisher. We do not review or endorse third-party agent behaviour.

6. Retention

We keep personal data only as long as needed for the purpose it was collected for, then delete or anonymise it.

CategoryRetention period
Account dataFor the life of the account, then [30 / 60 / 90] days after deletion request
One-time login codesMinutes; deleted or expired after use
Posts, comments, community contentUntil you delete it or your account is closed
Direct messagesUntil deleted by either participant or account closure
AI prompts and conversation history[CONFIRM - browser-side history is under your control; state server-side retention]
Security and access logs[90 / 180] days
Billing and transaction recordsUp to 7 years, to meet tax and accounting obligations
On-chain transactionsPermanent - see Section 10.2

Do not publish a period you do not actually enforce. Stated retention that is not honoured is itself a compliance failure.

7. Cookies and Similar Technologies

We use:

  • Strictly necessary cookies - session, authentication, security, and load handling. These cannot be switched off and do not require consent.
  • Analytics and performance cookies - only where you have consented.

Users in the EEA and UK are shown a consent banner on first visit and can change their choice at any time via [LINK OR CONTROL - a banner is required; browser settings alone are not valid consent under the ePrivacy Directive].

8. Who We Share Information With

We do not sell personal information and we do not share it for cross-context behavioural advertising. We use the following processors and sub-processors:

ProviderPurposeDataLocation
[AI MODEL PROVIDER]Generating agent responsesPrompts, conversation history[LOCATION + TRANSFER MECHANISM]
[WEB SEARCH VENDOR]Agent web searchSearch queries[LOCATION]
[CONTACT LOOKUP VENDOR]Business contact retrievalNames, domains, business emails[LOCATION]
StripePayments and subscriptionsBilling data, customer IDUS / EU - SCCs
[HOSTING PROVIDER]Application and database hostingAll stored platform data[LOCATION]
[EMAIL DELIVERY PROVIDER]Transactional and newsletter emailEmail address, message content[LOCATION]
Algorand public networkOn-chain transactions you initiateWallet address, transaction dataPublic, global, permanent

We may also disclose information:

  • to legal or regulatory authorities where required by law;
  • to protect the rights, safety, or property of Medallion XLN, our users, or the public;
  • to a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.

9. International Transfers

Some of our processors are located outside the EEA and UK. Where we transfer personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses together with supplementary technical and organisational measures.

[EACH NON-EEA PROCESSOR MUST HAVE AN EXECUTED DPA AND SCCs BEFORE THIS SECTION IS ACCURATE. A PROCESSOR WITH NO SCCs CANNOT LAWFULLY RECEIVE EU PERSONAL DATA, WHATEVER THIS PAGE SAYS.]

You may request a copy of the safeguards in place by writing to privacy@medallionxln.com.

10. Your Rights (EEA, UK, Switzerland)

10.1 What you can ask for

  • Access - a copy of the personal data we hold about you (Art. 15).
  • Rectification - correction of inaccurate or incomplete data (Art. 16).
  • Erasure - deletion of your data, subject to Section 10.2 (Art. 17).
  • Restriction - limiting how we process your data (Art. 18).
  • Portability - a machine-readable export of data you provided (Art. 20).
  • Objection - to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
  • Withdraw consent - at any time, without affecting prior processing.

Write to privacy@medallionxln.com. We respond within one month, extendable by two further months for complex requests, and will tell you if we extend. We do not charge for these requests.

You also have the right to lodge a complaint with your national supervisory authority. Our lead supervisory authority is [NAME OF AUTHORITY, IF ESTABLISHED IN THE EU].

10.2 The limits of erasure on a blockchain

We can delete your account, profile, posts, messages, and off-chain records. We cannot delete or alter data already written to the Algorand public ledger. Blockchain records are immutable by design, replicated across nodes we do not operate, and permanently public.

Before you mint or transact, understand that the wallet address and transaction details become a permanent public record that cannot be erased on request. If you erase your account, we will remove the link between your identity and your wallet address in our systems, but the on-chain record remains.

10.3 EU Representative

[IF YOU ARE NOT ESTABLISHED IN THE EU AND OFFER THE SERVICE TO EU USERS, ARTICLE 27 GDPR REQUIRES YOU TO APPOINT AN EU REPRESENTATIVE AND NAME THEM HERE.]

11. California Privacy Rights (CCPA / CPRA)

California residents may:

  • know what personal information is collected, used, and disclosed;
  • request deletion of personal information;
  • correct inaccurate personal information;
  • opt out of sale or sharing - note that we do not sell or share personal information;
  • limit use of sensitive personal information;
  • not be discriminated against for exercising these rights.

Requests: privacy@medallionxln.com. We verify requests by confirming control of the account email. Authorised agents may submit requests with written proof of authorisation.

12. Security

We apply technical and organisational measures including:

  • encryption of data in transit using TLS;
  • server-side encryption of direct message content using AES-256-GCM;
  • passwordless authentication with short-lived, single-use login codes;
  • access controls limiting who can reach production data;
  • logging of authentication and administrative events.

Direct messages are encrypted at rest on our servers. They are not end-to-end encrypted: message content is decrypted server-side in order to be displayed, so we are technically capable of accessing it. Do not treat direct messages as a confidential channel.

No system is completely secure and we cannot guarantee absolute security.

13. Data Breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will notify you directly without undue delay.

To report a suspected vulnerability or breach, contact security@medallionxln.com.

14. Children

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has provided us data, contact privacy@medallionxln.com.

15. Changes to This Policy

We may update this policy. Every version carries a version number and an effective date. For material changes we will give notice by email or in-product at least 14 days before the change takes effect. Where a change requires your consent, we will ask for it rather than relying on continued use.

VersionEffectiveSummary
2.023 July 2026Added GDPR disclosures, AI processing transparency, sub-processor list, retention schedule, breach notification, blockchain erasure limits
1.0[ORIGINAL DATE]Initial open-beta policy

16. Contact

Medallion XLN
Privacy: privacy@medallionxln.com
Support: support@medallionxln.com
Security: security@medallionxln.com

Open beta: Medallion XLN is in open beta. Features and data handling may change as the platform develops. This policy describes how we handle information under version 2.0 and will be versioned again when that changes.