PRIVACY NOTICE — DRAFT

Before final publication, this privacy notice must be reconciled with the actual production providers, logging settings, subprocessors, and technically implemented deletion/retention paths.

1. Controller

[PENDING OPERATOR / LEGAL CONFIRMATION] is intended to be the controller for personal data processed directly for the WAKE402 service, except where a third party is itself a controller for its own purposes. Legal name, business address, and privacy email remain open.

2. Data processed

Depending on the request and production configuration, WAKE402 may process: Wake ID; callback URL and hostname; requested and actual scheduling/delivery times; delivery status and error class; x402 Payment Identifier; Request Fingerprint; public payer wallet address; public blockchain transaction hash; payment network; public settlement metadata; and technical request/security metadata processed by the application or infrastructure providers.

Business-verification/attestation data and evidence of Terms version/acceptance are intended for the recommended future B2B model, but business verification and Terms acceptance are not currently implemented. WAKE402 does not require the seller’s or customer’s private key.

3. Purposes

Data may be processed to provide and secure the service; validate and reconcile payments; create, recover, and deliver Wakes; prevent abuse; diagnose incidents; later demonstrate contract acceptance; respond to legal requests; and meet tax, accounting, or other legal obligations.

4. Legal bases

Depending on the processing, performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR), legal obligations (point (c)), and legitimate interests in service security, abuse prevention, and legal defense (point (f)) are considered in particular as working assumptions. Where another legal basis is required, it must be determined before the relevant processing begins. Legal confirmation remains pending.

5. Recipients and infrastructure

Data may be processed by infrastructure and service providers required to deliver the service, such as cloud/hosting providers, blockchain/payment/facilitation infrastructure, and the configured RPC provider. Public blockchain data is inherently visible to third parties. The customer-selected callback endpoint receives the fixed callback body. The final list of processors/subprocessors and transfer mechanisms must match the actual production configuration and has not yet been finalized.

6. Blockchain transparency and permanence

Public wallet addresses and transaction data on Base form part of a public blockchain system. WAKE402 cannot delete information already published and independently replicated on the public Base blockchain. This does not remove WAKE402’s obligations for copies or metadata in systems under its control.

7. Retention

The legal-pack draft proposes limited retention classes, including 30–90 days for callback/delivery diagnostics and security logs, and longer periods for legally required contract, tax, or accounting records. This retention scheme is not currently fully technically implemented or finalized. No technical deletion is therefore claimed unless supported by the current source code. Before LEGAL_READY, the actual D1/provider/logging and deletion paths must be reconciled with the published scheme.

8. International transfers

Some service providers may process data outside the EEA. Where such transfers occur, the transfer mechanisms and contractual safeguards required by applicable data-protection law must be used. The final statement must name the actual production-provider configuration.

9. Rights

Where the GDPR applies, data subjects may have rights of access, rectification, erasure, restriction, objection, and data portability under the applicable statutory conditions. Privacy contact and responsible operator details remain open: [PENDING OPERATOR / LEGAL CONFIRMATION]. WAKE402 cannot promise deletion of publicly replicated blockchain data.

10. Security

The draft contemplates technical and organizational measures such as data minimization, secret separation, access controls, callback-target validation, and security testing. A final retention/deletion process is not yet fully implemented/finalized. No internet service can guarantee absolute security.

11. Cookies and analytics

No marketing cookies, advertising trackers, or third-party advertising analytics are currently intended for the initial WAKE402 service. If tracking technologies are introduced later, this notice and any required consent mechanism must be updated before use.

12. Changes

Material changes to a final privacy notice should be published with an updated effective date. Historical contract acceptances should continue to be assessed under the Terms version accepted for the relevant Wake; technical Terms acceptance is not currently implemented.