Privacy Policy

Last Updated: November 25, 2025

TABLE OF CONTENTS

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing (GDPR)
  5. How We Share Your Information
  6. Third-Party Privacy Practices
  7. Data Retention
  8. Data Security
  9. Cookies and Tracking Technologies
  10. International Data Transfers
  11. Your Privacy Rights
  12. GDPR Rights for EEA Users
  13. California Privacy Rights (CCPA/CPRA)
  14. Children's Privacy
  15. Changes to This Privacy Policy
  16. Contact Information
  17. EU Representative
  18. Supervisory Authority

1. INTRODUCTION

BonkX, Inc. ("BonkX," "we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website bonkx.io (the "Website") and participate in our waitlist program with gamified quests.

Important: BonkX products are currently in development. This Privacy Policy applies only to our pre-launch waitlist program. When we launch our products, a separate privacy policy will govern those services.

Please read this Privacy Policy carefully. By accessing or using the Website, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Website.

Data Controller: BonkX, Inc., a Delaware corporation

2. INFORMATION WE COLLECT

2.1 Personal Information You Provide

Email Address: When you join our waitlist, you provide your email address. This is the only personal information we directly collect from you at this time.

2.2 Information Collected Through Third-Party Services

Domino.run Quest Platform: We use Domino.run, a third-party service provider, to manage our gamified quest system. When you participate in quests, Domino.run may collect and process:

Important: Domino.run's collection and use of your information is governed by their own privacy policy, which we encourage you to review.

2.3 Automatically Collected Information

When you visit the Website, we automatically collect certain information about your device and browsing actions:

2.4 Quest Activity Data

Information about your quest participation, including:

This information is collected and processed by Domino.run and shared with us to manage your waitlist position.

2.5 Third-Party Platform Data

When you complete quests, you may authorize Domino.run to access information from third-party platforms such as:

You control what information these platforms share through their authorization flows.

3. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

3.1 Waitlist Management

3.2 Communication

3.3 Website Operations and Improvement

You may opt out of marketing communications at any time (see Section 11).

3.6 Analytics and Research

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under GDPR Article 6:

Data Type Processing Activity Legal Basis
Email address Waitlist registration Consent (Art. 6(1)(a))
Email address Service communications Legitimate interest (Art. 6(1)(f))
Email address Marketing communications Consent (Art. 6(1)(a))
Quest activity data Waitlist management, points tracking Consent / Contract performance (Art. 6(1)(a)(b))
Usage/log data Website security, fraud prevention Legitimate interest (Art. 6(1)(f))
Usage/log data Website improvement, analytics Legitimate interest (Art. 6(1)(f))
Cookie data (non-essential) Analytics, preferences Consent (Art. 6(1)(a))
Cookie data (essential) Website operation Legitimate interest (Art. 6(1)(f))

Legitimate Interest Assessment: Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests include:

Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. See Section 12 for details.

5. HOW WE SHARE YOUR INFORMATION

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following circumstances:

5.1 Third-Party Service Providers

Domino.run (Quest Platform): We share your email address with Domino.run to enable quest participation and track your progress. Domino.run independently collects additional information when you interact with their platform. Domino.run acts as both a data processor (for email addresses we share) and an independent data controller (for quest activity data they collect directly from you). Their privacy practices are governed by their own privacy policy.

Other Service Providers: We may share your information with service providers who perform services on our behalf:

These service providers are contractually obligated to:

5.2 Third-Party Platforms

When you complete quests involving third-party platforms (X/Twitter, Discord, Telegram, blockchain networks, etc.), you authorize those platforms to share information with Domino.run according to their respective privacy policies and authorization flows. We do not control these platforms' data practices.

5.3 Business Transfers

If BonkX is involved in a merger, acquisition, financing, reorganization, bankruptcy, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will provide notice via email and/or a prominent notice on our Website before your information becomes subject to a different privacy policy.

We may disclose your information when required by law or when we believe in good faith that disclosure is necessary to:

5.5 Aggregated or De-Identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, including:

This information is not considered personal data under GDPR or other privacy laws.

We may share your information for any other purpose with your explicit, informed consent.

6. THIRD-PARTY PRIVACY PRACTICES

6.1 Domino.run

Domino.run is an independent third-party service provider. Their collection, use, storage, and sharing of your information is governed by their own privacy policy, not this Privacy Policy.

What Domino.run Does:

Our Relationship: We have contractual agreements with Domino.run requiring them to protect your data, but we have limited control over their day-to-day privacy practices.

Your Responsibility: We encourage you to review Domino.run's privacy policy to understand how they handle your information.

6.2 Social Media and Web3 Platforms

When you connect your social media accounts or blockchain wallets to complete quests, those platforms' privacy policies govern their collection and use of your information. We do not control and are not responsible for the privacy practices of:

Important: Blockchain transactions are public and permanent. Once information is recorded on a blockchain, it cannot be deleted or made private.

6.3 Your Responsibilities

You are responsible for:

The Website may contain links to third-party websites or services not owned or controlled by BonkX. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. Visiting third-party websites is at your own risk.

7. DATA RETENTION

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

7.1 Retention Periods

Data Category Retention Period Reason
Email address (active waitlist) Until you request deletion or unsubscribe Waitlist management
Email address (inactive) 24 months of inactivity, then deleted Legitimate interest
Quest activity data Duration of waitlist + 12 months Analytics, dispute resolution
Marketing consent records 3 years after consent withdrawn Legal obligation (proof of consent)
Log files and IP addresses 12-24 months Security, fraud prevention
Cookie data Duration specified in cookie banner Varies by cookie type
Support communications 3 years after case closed Customer service, legal protection
Legal/accounting records 7 years or as required by law Legal obligation
Aggregated/anonymized data Indefinitely Not personal data

7.2 Deletion After Retention Period

After the retention period expires, we will:

Exception: Blockchain data cannot be deleted due to the immutable nature of distributed ledger technology. This is a technical limitation, not a policy choice.

7.3 Third-Party Retention

Domino.run and other service providers maintain their own data retention policies, which may differ from ours. We require our service providers to delete or return data when no longer needed, but we cannot guarantee their compliance.

8. DATA SECURITY

We implement appropriate technical and organizational security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

8.1 Security Measures

Technical Safeguards:

Organizational Safeguards:

8.2 Limitations of Security

Important: No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

Risks include:

Third-Party Security: We cannot guarantee the security of information processed by third-party services like Domino.run, social media platforms, or blockchain networks. You acknowledge that sharing information with third parties involves inherent security risks.

Blockchain Risks: Blockchain transactions are public and permanent. Wallet addresses and transaction data:

8.3 Your Security Responsibilities

You are responsible for:

8.4 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

To Supervisory Authorities: We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33).

To You: We will notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms (as required by GDPR Article 34). Our notification will include:

9. COOKIES AND TRACKING TECHNOLOGIES

9.1 What Are Cookies

Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit a website. We use cookies and similar technologies such as:

9.2 Types of Cookies We Use

Strictly Necessary Cookies (Essential):

Analytics Cookies (Non-Essential):

Functional Cookies (Non-Essential):

Marketing/Advertising Cookies (Non-Essential):

Third-Party Cookies:

Cookie Banner: When you first visit our Website (if you're in the EU/EEA), you will see a cookie consent banner that:

Browser Controls: Most web browsers allow you to control cookies through settings. You can:

Browser-Specific Instructions:

Important: Disabling cookies may affect Website functionality and prevent you from participating in quests or accessing certain features.

9.4 Analytics Services

Google Analytics: We use Google Analytics to collect information about Website usage. Google Analytics uses cookies to collect information such as:

Opt-Out: You can opt out of Google Analytics by:

Data Processing: Google Analytics data is processed in accordance with Google's privacy policy: https://policies.google.com/privacy

9.5 Do Not Track Signals

Some web browsers have a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. Our Website does not currently respond to DNT signals or similar mechanisms. However, you can control tracking through:

10. INTERNATIONAL DATA TRANSFERS

10.1 Location of Data Processing

BonkX Operations: BonkX, Inc. is based in the United States. Your information will be transferred to, stored, and processed in the United States.

Service Providers: Our service providers (Domino.run, hosting providers, email services, etc.) may operate servers in various locations globally, including:

Data Transfer: If you are accessing the Website from outside the United States, particularly from the EEA, UK, or Switzerland, your information will be transferred to countries that may have different data protection laws than your country of residence.

10.2 Safeguards for International Transfers (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we ensure appropriate safeguards are in place for international data transfers as required by GDPR Chapter V:

Standard Contractual Clauses (SCCs):

Service Providers Using SCCs:

Supplementary Measures: In addition to SCCs, we implement technical and organizational measures such as:

Adequacy Decisions: Where available, we rely on European Commission adequacy decisions for certain countries that provide adequate data protection (e.g., UK under the UK GDPR, Switzerland under FADP).

10.3 Your Rights Regarding Transfers

You have the right to:

To request information about our transfer mechanisms or copies of SCCs, contact: gdpr@bonkx.io

10.4 Consequences of Transfer

By using the Website and providing your information, you acknowledge and consent to:

If you do not agree to international transfers, please do not use the Website or provide your information.

11. YOUR PRIVACY RIGHTS

All users, regardless of location, have certain basic privacy rights. Additional rights apply to users in specific jurisdictions (see Sections 12 and 13).

11.1 Universal Rights (All Users)

Right to Access: You may request a copy of the personal information we hold about you.

Right to Correction: You may request correction of inaccurate or incomplete information.

Right to Deletion: You may request deletion of your personal information, subject to certain exceptions (legal obligations, ongoing disputes, etc.).

Right to Opt-Out of Marketing: You may unsubscribe from marketing emails at any time by:

Right to Revoke Authorizations: You may revoke access to third-party platforms (social media accounts, wallets) through those platforms' settings.

11.2 How to Exercise Your Rights

Email: privacy@bonkx.io Subject Line: "Privacy Rights Request - [Your Request Type]"

Include in Your Request:

Response Timeline: We will respond to your request within 30 days (or as otherwise required by applicable law). We may extend this period by an additional 60 days for complex requests, in which case we will inform you of the extension and reasons.

Verification: To protect your privacy, we may need to verify your identity before fulfilling your request. We may request additional information such as:

Free of Charge: Generally, exercising your privacy rights is free. However, we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.

11.3 Limitations on Rights

We may decline requests in certain circumstances:

If we decline your request, we will explain the reasons and inform you of your right to complain to a supervisory authority (for EEA users).

12. GDPR RIGHTS FOR EEA USERS

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent laws.

12.1 Right of Access (Article 15)

You have the right to obtain:

How to Exercise: Contact gdpr@bonkx.io with subject "GDPR Access Request"

Timeline: Within 1 month (extendable by 2 months for complex requests)

Format: We will provide data in a commonly used electronic format (e.g., PDF, CSV)

12.2 Right to Rectification (Article 16)

You have the right to:

Examples:

How to Exercise: Contact gdpr@bonkx.io with subject "GDPR Rectification Request"

Timeline: Within 1 month

Notification: We will notify third parties (e.g., Domino.run) of corrections where feasible

12.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to request deletion of your personal data when:

Exceptions - We May Refuse Deletion When Data is Needed For:

Important Limitation: We cannot erase blockchain transaction data due to the immutable nature of distributed ledgers. This is a technical limitation inherent to blockchain technology.

How to Exercise: Contact gdpr@bonkx.io with subject "GDPR Erasure Request"

Timeline: Within 1 month

Notification: We will notify third parties of erasure where feasible, but cannot control their independent processing

12.4 Right to Restriction of Processing (Article 18)

You can request we restrict (but not delete) your data when:

What "Restriction" Means: We will store your data but not use it (except with your consent, for legal claims, to protect others' rights, or for public interest).

How to Exercise: Contact gdpr@bonkx.io with subject "GDPR Restriction Request"

Timeline: Within 1 month

Notification: We will inform you before lifting any restriction

12.5 Right to Data Portability (Article 20)

You can request your data in a structured, commonly-used, machine-readable format (e.g., CSV, JSON) when:

What You Can Receive:

Format Options: CSV, JSON, XML, or other commonly-used formats

Direct Transfer: You may request we transmit your data directly to another service provider where technically feasible.

How to Exercise: Contact gdpr@bonkx.io with subject "GDPR Portability Request"

Timeline: Within 1 month

Limitation: This right applies only to data you provided to us, not data generated by our systems (e.g., analytics)

12.6 Right to Object (Article 21)

Object to Processing Based on Legitimate Interests:

Object to Direct Marketing:

How to Exercise:

Timeline: We will stop processing immediately upon receiving objection to direct marketing; within 1 month for other objections

12.7 Right to Withdraw Consent (Article 7(3))

Where processing is based on consent (e.g., waitlist registration, marketing emails, non-essential cookies), you can withdraw consent at any time by:

Important: Withdrawal doesn't affect the lawfulness of processing before withdrawal. We may continue processing on a different legal basis (e.g., legal obligation, legitimate interest).

12.8 Right Not to be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.

Current Status: We do not currently engage in automated decision-making or profiling that produces legal or similarly significant effects.

Waitlist Ranking: Our points-based waitlist ranking is not considered automated decision-making under Article 22 because:

If we implement automated decision-making in the future, we will:

12.9 Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated GDPR or your rights.

Find Your Supervisory Authority:

Preferred Resolution: We encourage you to contact us first at gdpr@bonkx.io so we can address your concerns directly. However, this does not affect your right to lodge a complaint with a supervisory authority.

12.10 How to Exercise Your GDPR Rights

Contact: gdpr@bonkx.io Subject Line: "GDPR Rights Request - [Access/Erasure/Rectification/etc.]"

Include:

Response Timeline: Within 1 month of receiving your request. We may extend by an additional 2 months for complex or numerous requests, in which case we will inform you within the first month.

Free of Charge: Generally free. We may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests.

Verification: We may request additional information to verify your identity before fulfilling requests, particularly for access, deletion, or portability requests.

Third-Party Data: For data held by Domino.run (quest activity, social media connections), you must exercise your rights directly with them according to their privacy policy.

13. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

13.1 Categories of Personal Information We Collect

Under CCPA, we collect the following categories of personal information:

Category Examples Collected? Business Purpose
Identifiers Email address, IP address, device ID YES Waitlist management, communication
Internet Activity Browsing history, quest activity, clicks YES Website improvement, analytics
Geolocation Data Approximate location from IP YES Analytics, fraud prevention
Inferences Preferences, interests derived from activity Limited User experience improvement

Categories We Do NOT Collect:

13.2 Sources of Personal Information

We collect personal information from:

13.3 Business Purposes for Collection

We collect and use personal information for the following business purposes:

13.4 Your California Privacy Rights

Right to Know / Access (CCPA § 1798.100, 1798.110): You have the right to request disclosure of:

Right to Delete (CCPA § 1798.105): You have the right to request deletion of your personal information, subject to certain exceptions (legal obligations, fraud prevention, internal uses, etc.).

Right to Correct (CPRA § 1798.106): You have the right to request correction of inaccurate personal information.

Right to Opt-Out of Sale or Sharing (CCPA § 1798.120): Current Status: We do NOT sell your personal information to third parties. We share information with service providers (like Domino.run) for business purposes, which is not considered a "sale" under CCPA.

Right to Limit Use of Sensitive Personal Information (CPRA § 1798.121): Current Status: We do not collect or use "sensitive personal information" as defined by CPRA (e.g., precise geolocation, racial/ethnic origin, health data, biometric data).

Right to Non-Discrimination (CCPA § 1798.125): We will not discriminate against you for exercising your CCPA rights. You will not be:

13.5 How to Exercise Your California Rights

Methods:

Information to Include:

Verification: To protect your privacy, we will verify your identity by:

Authorized Agents: You may designate an authorized agent to make requests on your behalf. The agent must:

Response Timeline:

Right to Appeal (CPRA): If we deny your request, you have the right to appeal. We will provide appeal instructions in our response.

13.6 Disclosure of Personal Information

Past 12 Months: We have disclosed the following categories of personal information for business purposes:

No Sale: We have NOT sold personal information in the past 12 months and do not sell personal information.

No Sharing for Cross-Context Behavioral Advertising: We do not share personal information for cross-context behavioral advertising.

13.7 Retention Periods

See Section 7 for detailed retention periods. Generally:

13.8 Contact for California Privacy Questions

Email: privacy@bonkx.io Subject: "California Privacy Rights"

14. CHILDREN'S PRIVACY

14.1 Age Restriction

The Website is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18.

Why Age 18?:

14.2 If We Discover Child Data

If you are a parent or guardian and believe your child under 18 has provided us with personal information:

Our Response: If we become aware that we have collected personal information from a child under 18 without parental consent, we will:

14.3 Parental Rights (COPPA - if applicable)

While we do not target children, if a child under 13 (U.S.) or 16 (EEA) has provided information, parents have the right to:

14.4 Age Verification

We do not actively verify the age of users joining our waitlist, but we:

15. CHANGES TO THIS PRIVACY POLICY

15.1 Right to Modify

We may update this Privacy Policy from time to time to reflect changes in:

15.2 Notification of Material Changes

We will notify you of material changes by:

What Constitutes "Material" Changes:

15.3 Non-Material Changes

For minor, non-material changes (typos, clarifications, updated contact information), we will:

15.4 Your Acceptance

Continued Use = Acceptance: Your continued use of the Website after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

If You Disagree: If you do not agree with the updated Privacy Policy:

15.5 Review Regularly

We encourage you to review this Privacy Policy periodically to stay informed about:

16. CONTACT INFORMATION

16.1 General Privacy Inquiries

For general questions, concerns, or requests regarding this Privacy Policy or our privacy practices:

Email: privacy@bonkx.io Website: bonkx.io

Mailing Address: BonkX, Inc. [Your US Mailing Address] [City, State, ZIP Code] United States

16.2 GDPR-Specific Inquiries

For GDPR-related inquiries, data subject rights requests, or supervisory authority communications:

Email: gdpr@bonkx.io Subject Line: "GDPR - [Your Request Type]"

Data Protection Officer: While we are not legally required to appoint a Data Protection Officer, you may direct GDPR inquiries to the email above, and they will be handled by our privacy team.

16.3 California Privacy Rights

For California-specific privacy requests under CCPA/CPRA:

Email: privacy@bonkx.io Subject Line: "CCPA Request - [Your Right]"

16.4 Security Incidents

To report a security incident or suspected data breach:

Email: security@bonkx.io Subject Line: "URGENT: Security Incident"

Include:

16.5 Response Time

We strive to respond to all privacy inquiries within:

17. EU REPRESENTATIVE

17.1 Article 27 GDPR Requirement

As a company established outside the European Union that offers services to EU data subjects, we have appointed an EU Representative pursuant to Article 27 of the GDPR.

17.2 EU Representative Contact Information

Name: Adam-Noaf Grigore Address: Strada Emanoil Porumbaru 82-84, ap. 3 Sector 1 Bucharest Romania

Email: gdpr@bonkx.io

17.3 Purpose of EU Representative

Our EU Representative serves as the contact point in the European Union for:

What Our EU Representative Does:

What Our EU Representative Does NOT Do:

17.4 When to Contact Our EU Representative

Contact our EU Representative if:

Contact us directly if:

18. SUPERVISORY AUTHORITY

18.1 Right to Complain

If you are located in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated GDPR or your privacy rights.

18.2 Contact Information for Supervisory Authorities

European Economic Area (EEA): Find your country's supervisory authority: https://edpb.europa.eu/about-edpb/board/members_en

United Kingdom: Information Commissioner's Office (ICO) Website: https://ico.org.uk/ Phone: 0303 123 1113 Report a concern: https://ico.org.uk/make-a-complaint/

Switzerland: Federal Data Protection and Information Commissioner (FDPIC) Website: https://www.edoeb.admin.ch/ Email: info@edoeb.admin.ch

18.3 Lead Supervisory Authority

Under GDPR Article 56, our lead supervisory authority (for cross-border processing issues) is:

Romanian Supervisory Authority: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Website: https://www.dataprotection.ro/ Email: anspdcp@dataprotection.ro

18.4 We Encourage Direct Contact First

While you have the right to lodge a complaint with a supervisory authority at any time, we encourage you to contact us first at gdpr@bonkx.io so we can address your concerns directly and attempt to resolve the issue.

However, this does not affect your right to lodge a complaint with a supervisory authority.

SUMMARY OF KEY POINTS

This summary provides a quick overview. Please read the full Privacy Policy for complete details.

What information do we collect?

How do we use your information?

Do we share your information?

How long do we keep your information?

What are your rights?

How do we protect your information?

International data transfers?

Third-party services?

EU Representative?

Questions?

Last Updated: November 25, 2025

BonkX, Inc. - Delaware Corporation This Privacy Policy complies with GDPR (EU/EEA), UK GDPR, Swiss FADP, CCPA/CPRA (California), and other applicable privacy laws.

By using the Website, you acknowledge that you have read, understood, and agree to this Privacy Policy.