Effective: October 16, 2025
Version 1.0

This policy enters into force on October 16, 2025 and serves to protect the personal data of our users within the Colabonate ecosystem. Unlike centralized systems, data processing primarily occurs through cryptographic protocols and decentralized computing units.

Legal Basis: Art. 12, 13, 14, 25 GDPR (Duty to inform and Data Protection by Design), Swiss FADP.

Core Entities: Codex (DAO) as the governance structure and the Sovereign Identity Framework (SI) as the decentralized identity layer.

This policy applies to all interactions, services, web interfaces, and decentralized modules within the Colabonate network.

Legal Basis: Art. 4 Para. 1 and 2 GDPR — refers to all processing of personal data.

The policy specifically covers: the Colabonate Wallet, the Codex-based governance rules, the Audio/Video/Chat System, the Ticket System, and the Proximity Proof Mechanism.

Use of the Colabonate platform and its modules implies acceptance of this policy. As no central registration is required, consent is given by cryptographically signing user actions.

Legal Basis: Art. 6 Para. 1 lit. a and Art. 7 GDPR (Requirements for consent).

Consent to specific data processing operations is provided through digital signatures, generated via the SI Identity Layer (Wallet). Executing Proximity Proofs serves as a contextual consent mechanism for verifying presence, not central identification.

Colabonate adheres to the principle of minimal data collection. Personal data is only collected with the user's explicit cryptographically signed consent, or where strictly necessary to perform core decentralized functions.

Legal Basis: Art. 5 Para. 1 lit. c GDPR (Data Minimisation).

We collect and process the following types of metadata:

  • Identity Proofs — cryptographic hashes, Public Keys of the SI Framework
  • Proximity Proof Metadata — timestamp, geographical proximity (never exact coordinates)
  • Communication Data — end-to-end encrypted Nostr Events without content storage
  • Wallet & Payment Metadata — hash references from Bitcoin Lightning Network transactions
  • Governance Data — pseudonymous DAO Votes

Processed data is used exclusively for the functionality, security, and governance of the decentralized network.

Legal Basis: Art. 6 Para. 1 lit. b and f GDPR (Contract performance and legitimate interest: network security and functionality).

  • Verification of SI Identities — Zero-Knowledge hash matches
  • Interaction within the Codex System — transparent logging of governance actions
  • Processing Peer-to-Peer Payments — routing via Lightning Network without storage of sensitive payment info
  • Ensuring Communication Integrity — authentication of Nostr events
  • DAO Governance Audits — traceability of voting processes

This policy differentiates between: (1) local, user-controlled storage for managing Sovereign Identity (SI) and (2) traditional cookies required for the functionality of centralized components (Website, Forum). We do not use third-party cookies for tracking purposes.

Legal Basis: Section 25 TTDSG (Consent regulation for cookies), Art. 6 Para. 1 lit. f GDPR (Legitimate interest in functional cookies).

  • SI Context Cache: Local storage for managing SI keys and context
  • Functional Cookies (Centralized Services): When commenting, you may opt-in to save your name, email, and website in cookies (validity: 1 year). On login, temporary cookies are set to save your login information (validity: 2 days, "Remember Me": 2 weeks) and screen options

The Colabonate ecosystem integrates various decentralized networks for computation, communication, and transaction handling.

Legal Basis: Art. 28 GDPR (Data processor), where the decentralized nature of these protocols redefines the role of the "processor".

  • Nostr Relays: Storage and routing of decentralized events. User data is persisted only in encrypted or hashed form
  • Nostr Protocol: Event-based peer-to-peer communication. Colabonate stores no central communication logs, only metadata for event routing
  • Bitcoin Lightning Network (LN): Transaction data is pseudonymous and is not linked with Colabonate SI identity data to maximize financial privacy

Colabonate fundamentally does not disclose personal data to third parties, as the architecture is designed for data sovereignty. The user is the primary sovereign of their data.

Legal Basis: Art. 20 GDPR (Right to data portability), Art. 5 Para. 2 GDPR (Accountability).

Disclosure is only possible if: legally required (while adhering to all cryptographic guarantees), legitimized by DAO Governance (transparent consensus process in the Codex), or explicitly signed by the user (via the SI Consent Layer for interaction with external services).

Due to the decentralized Nostr relay infrastructure, processing naturally occurs across global jurisdictions. Compliance with GDPR and Swiss FADP is ensured through technical mechanisms, regardless of physical location.

Legal Basis: Art. 44 ff. GDPR (Guarantees for third country transfers).

Every persistent data record is protected by strong cryptographic hashes. The architecture replaces trusted third parties with trustworthy cryptographic proofs, representing an internationally recognized standard of protection.

We store data based on the "Minimal Data by Design" principle and retain decentralized cryptographic data (hashes, proofs) only as long as necessary for Codex governance consensus or service functionality. Different retention periods apply to hybrid services.

Legal Basis: Art. 5 Para. 1 lit. e GDPR (Storage limitation), Art. 6 Para. 1 lit. f (Legitimate interest in comment history).

  • Decentralized Data (SI, Codex): We store practically exclusively encrypted hashes or Zero-Knowledge Proofs. Automatic deletion/fragmentation occurs once a governance audit is complete or the verification hash is no longer needed
  • Hybrid Data (Comments, Forum): If you leave a comment, the comment and its metadata are retained indefinitely so we can recognize and approve follow-up comments automatically. For registered forum users, personal profile data is stored until the user requests deletion

Users have comprehensive rights according to GDPR (access, rectification, erasure, restriction, data portability) and FADP. The implementation of these rights differs depending on the use of the decentralized SI framework or hybrid services.

Legal Basis: Art. 15–22 GDPR (Rights of the data subject).

Decentralized Services (SI/Codex): Through the Self-managed Identity Layer (Wallet interface), the user has the technical tools to erase data (by destroying associated keys) and transfer data. Anonymous or pseudonymous use of the modules is possible without mandatory central account creation.

Hybrid Services (Forum/Comments): Users with a central account or commenters can request an exported file of the personal data we hold (right of access) and the erasure of all stored personal data (right to erasure), unless Colabonate is obligated to retain this data for administrative, legal, or security purposes.

Colabonate does not conduct centralized user profiling. Decisions affecting user experience (e.g., participation in governance) are based on transparent, algorithmic rules of the Codex.

Legal Basis: Art. 22 GDPR (Automated individual decision-making).

Reputation Scores and Governance Weightings are calculated exclusively contextually and decentrally via DAO Mechanisms. The algorithm is transparently documented in the Codex, ensuring no black-box decisions are made.

Our security strategy is based on cryptographic integrity and decentralization to protect data from unauthorized access, loss, or destruction.

Legal Basis: Art. 32 GDPR (Security of processing).

  • End-to-End Encryption (E2EE) across all communication channels (Nostr, Audio/Video)
  • Multi-layer Hash Verification by the Codex to secure the authenticity of processed data
  • Zero-Knowledge Proofs for identity confirmation, eliminating the need to disclose identity details
  • Audit Trails optionally anchored via Nostr event references to allow for immutable verification

Colabonate is exclusively for adults. Use of the platform by persons under 18 years of age is prohibited.

Legal Basis: Art. 8 Para. 1 GDPR (Conditions applicable to child's consent).

Wallet creation requires confirmation of legal age. If Colabonate becomes aware of use by minors, it reserves the right to suspend the corresponding pseudonymous SI hashes in accordance with Codex rules.

Changes to this Privacy Policy may only be made through a consensus process by the Colabonate DAO. Transparency and immutability of every revision are guaranteed.

Legal Basis: Art. 5 Para. 1 lit. a and Para. 2 GDPR (Transparency and accountability).

Policy changes are submitted as a proposal in the Codex Governance System and approved by vote. Every approved version receives a version number and a cryptographic Hash Identifier (CID), guaranteeing the policy's immutability and verifiability.

Since no central "Controller" exists, inquiries are primarily addressed through digital and decentralized channels.

Legal Basis: Art. 37 ff. GDPR (Data Protection Officer, contact point).

Data processing inquiries can be submitted via the Colabonate Ticket System, which forwards them pseudonymously to the responsible Governance Nodes.

Legal inquiries or formal notices should be addressed to the official address of the DAO Legal Node, as documented in the Colabonate Codex's current legal notice.

This section describes data processing that occurs outside the decentralized SI/Codex architecture on centrally operated components (e.g., the presentation website, the forum, or the newsletter tool). In these cases, the Colabonate DAO, through its Legal Node, acts as the data controller in the traditional sense.

Legal Basis: Art. 6 Para. 1 lit. a, b, f GDPR. Processing occurs in traditional server environments under separate security measures.

17.1 Comments

When visitors leave comments on our site, we collect the data shown in the comments form, and also the visitor's IP address and browser user agent string to help spam detection. An anonymized hash of your email address may be used for the Gravatar service.

17.2 Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS). Visitors to the website can download and extract any location data from these images.

17.3 Embedded Content

Articles on this site may include embedded content (e.g., videos, images, articles) from other websites. Embedded content behaves in the exact same way as if the visitor has visited the other website. These external websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content.

17.4 Forum Registration

For users who register on our website, we store the personal information they provide in their user profile (username, email, password hash). All registered users can see, edit, or delete their personal information at any time (except they cannot change their username).

17.5 Password Reset

If you request a password reset, your IP address will be included in the reset email. The storage of the IP address serves as a necessary security audit trail.

17.6 Data Transmission

Visitor comments are checked through an automated spam detection service, involving the transmission of comment content and metadata.