Back to Mithqal

Privacy Policy

Last updated: 2026-09-15

MITHQAL is currently operated by JOZOUR LLC during the institutional development phase. The constitutional architecture described throughout this documentation represents the intended institutional destination of the project. Planned entities do not yet exist and are not currently operating.

1. Controller

The data controller is JOZOUR LLC, a New Jersey Limited Liability Company (NJ filing 0600463904, EIN 84-3470275), sole member Mohamed S. Eltonsy. For privacy enquiries contact operator@mithqal.org.

2. Data We Collect

  • Formation Committee intake: name, email, organisation, role, and any message you submit via the public intake form.
  • Testnet simulator activity: the wallet address you connect (read-only), simulator mint/redeem amounts, and timestamps. These are stored in our operational database.
  • Server logs: IP address, user agent, request path, and timestamp for every HTTP request. Retained for 30 days for security and abuse prevention.
  • Public on-chain data: any read of Monad Testnet is public and outside our control.

3. Sub-processors

We use the following sub-processors. PII you submit may be processed by them. We do not sell personal data.

  • Vercel Inc. (USA) — web hosting and edge functions.
  • Turso / LibSQL (USA, us-east-1) — operational database for testnet ledger and intake records.
  • Google Cloud / Gemini API — LLM inference for the optional "Mithqal Brain" compliance / risk panels (only invoked when you explicitly submit a compliance inquiry).
  • Groq Inc. — LLM inference (same scope as above).
  • Hugging Face Inc. — LLM inference (same scope as above).
  • Apple iCloud Mail — outbound transactional email (intake acknowledgements, operator alerts).
  • Monad Labs — public testnet RPC node provider; on-chain reads are public.

Note: the three LLM sub-processors receive only the free-text compliance inquiry you explicitly submit; they do not receive your wallet, your testnet ledger, or your server logs.

4. Lawful Basis (GDPR)

  • Consent (Art. 6(1)(a)) — when you submit the intake form or a Brain inquiry.
  • Legitimate interest (Art. 6(1)(f)) — server logs for security, fraud prevention, and rate-limiting.
  • Legal obligation — where future regulatory frameworks require record retention.

5. Retention

  • Formation Committee intake records: retained until you request deletion.
  • Testnet simulator ledger: retained for the lifetime of the testnet.
  • Server logs: 30 days.

6. Your Rights

EU/UK/California residents may request access, rectification, erasure, restriction, portability, or objection. Email operator@mithqal.org. We respond within 30 days.

7. International Transfers

Data may be transferred to the United States (where our sub-processors operate). Where required, transfers rely on Standard Contractual Clauses or the recipient's participation in an approved certification framework.

8. Security

Authentication uses scrypt-hashed credentials. Rate-limiting is applied to public endpoints. Database access is scoped to a single operator credential. We have not yet completed SOC 2 Type II or ISO 27001 certification; see our Risk Disclosure.

9. Changes

We will update this policy as our sub-processors or practices change. Material changes will be announced at the top of this page.