Legal

Privacy Policy

How World DePIN collects, uses, and protects your personal data โ€” including data processed via the WhatsApp Business API.

๐Ÿ“… Effective date: 31 August 2026 ๐Ÿข IT Solution Architecture Limited ยท Company No. 12066050 ๐ŸŒ worlddepin.io

Who we are: World DePIN is a trading name of IT Solution Architecture Limited, a company registered in England and Wales (Company No. 12066050, VAT No. 325 6309 11). We distribute Unetwork (Unity Node) licences for decentralised network infrastructure. Our contact email is hello@worlddepin.io.

1. Introduction

IT Solution Architecture Limited ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights in relation to it.

This policy applies to all services we provide under the World DePIN brand, including our website (worlddepin.io), our WhatsApp Business communications channel, and any related digital services.

We act as the data controller for the personal data described in this policy. UK GDPR and the Data Protection Act 2018 apply to our processing activities.

2. Data We Collect

We collect only the minimum data necessary to provide our services. The categories of personal data we may collect include:

2.1 Data You Provide Directly

  • Contact details: Name, email address, phone number
  • WhatsApp profile information: Display name and phone number when you message us via WhatsApp
  • Enquiry content: Messages, questions, or requests you send to us
  • License application details: Number of licenses requested, device type (Android/iOS), and any other information you choose to share in support of a license claim
  • Referral information: Referral codes or links, if provided

2.2 Data Collected Automatically

  • Technical data: IP address, browser type and version, device type, operating system, pages visited, and timestamps โ€” collected via standard web server logs and analytics
  • Cookies: We use essential cookies only (session management). We do not use tracking or advertising cookies. See our cookie notice below.

2.3 WhatsApp Business API โ€” Specific Data

We use the WhatsApp Business API (provided by Meta Platforms, Inc.) to communicate with users who contact us via WhatsApp. When you message us on WhatsApp, the following data is processed:

  • Your WhatsApp phone number โ€” used to identify and reply to you
  • Your WhatsApp display name โ€” used to address you personally
  • Message content โ€” the text or media you send to us, used solely to respond to your enquiry or support request
  • Message timestamps and delivery status โ€” used for operational record-keeping

WhatsApp messages are routed through Meta's infrastructure. Meta's own privacy policy applies to data held on WhatsApp's platform. We only retain message content on our own systems for as long as necessary to resolve your enquiry (see Section 6).

We do not use WhatsApp data for advertising, profiling, or any purpose other than directly responding to your communications with us.

3. How We Use Your Data

Purpose Data Used Legal Basis (UK GDPR)
Responding to enquiries and support requests (including via WhatsApp) Name, phone number, message content Legitimate interests (Art. 6(1)(f))
Processing Unity Node license applications Name, email, device type, license quantity Contractual necessity (Art. 6(1)(b))
Sending transactional updates about your license or account Email address / phone number Contractual necessity (Art. 6(1)(b))
Improving our services and website Anonymised usage data Legitimate interests (Art. 6(1)(f))
Licence-lifecycle emails โ€” issuing codes, activation reminders, offline warnings and expiry notices Email address, licence and device status Contractual necessity (Art. 6(1)(b))
Keeping a change log of licence, device and operator records so we can answer questions about what changed and when Operator reference, device identifiers, field-level changes Legitimate interests (Art. 6(1)(f))
Complying with legal or regulatory obligations As required by law Legal obligation (Art. 6(1)(c))

We do not sell your personal data. We do not use your data for unsolicited marketing without your prior consent.

4. WhatsApp Business API โ€” Compliance

Our use of the WhatsApp Business API is governed by Meta's WhatsApp Business Policy and Commerce Policy. We commit to the following:

  • We only send messages to users who have opted in to receive communications from us via WhatsApp, or who have initiated contact with us
  • We use WhatsApp only for legitimate business communications: responding to enquiries, providing license support, and sending transactional notifications
  • We do not send bulk unsolicited messages (spam) via WhatsApp
  • We do not share WhatsApp message content with third parties, except where required by law or with your explicit consent
  • Users may opt out of WhatsApp communications at any time by replying STOP or by emailing us at hello@worlddepin.io
  • We apply appropriate technical and organisational security measures to protect data processed via the API

5. Sharing Your Data

We share your personal data only in limited circumstances:

  • Meta Platforms, Inc. โ€” as the provider of the WhatsApp Business API, Meta processes message data in accordance with their platform policies and privacy policy
  • Netlify, Inc. โ€” our website hosting provider; processes web request logs and contact form submissions on our behalf
  • Email service providers โ€” used to send transactional email to you
  • Legal authorities โ€” where required by law, regulation, or court order

All third-party processors are contractually required to handle your data securely and only for the purposes we specify.

6. Data Retention

  • WhatsApp messages: Retained for up to 12 months from the date of last contact, or until your enquiry is resolved โ€” whichever is shorter โ€” then securely deleted
  • Contact form submissions: Retained for up to 12 months from submission
  • License records: Retained for the duration of the license and for 7 years thereafter (UK legal / accounting requirement)
  • Web server logs: Retained for up to 90 days
  • Change log entries (licence, device and operator record changes): Retained for 24 months

6a. Marketing

We publish general marketing on our own social channels (currently Facebook). Those posts are written by us and are not targeted using your personal data โ€” we do not upload enquiry, licence or contact records to any advertising platform, and we do not build audiences from them. Emails we send you are about your own licence, not marketing, and every one of them can be stopped by replying or writing to support@worlddepin.io.

7. Cookies

We use only essential cookies required for our website to function (e.g., session state). We do not use analytics, advertising, or social-media tracking cookies. No cookie consent banner is required for essential-only cookies under UK GDPR/PECR.

8. Security

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include HTTPS encryption for all web traffic, access controls on our systems, and secure handling of API credentials. No method of electronic transmission or storage is 100% secure; we work continuously to protect your data to a high standard.

9. International Transfers

Some of our third-party service providers (including Meta and Netlify) operate outside the UK. Where personal data is transferred internationally, we ensure that appropriate safeguards are in place in accordance with UK GDPR, including Standard Contractual Clauses or adequacy decisions where applicable.

10. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access โ€” to obtain a copy of your personal data
  • Right to rectification โ€” to correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") โ€” to request deletion of your data where we no longer have a legal basis to hold it
  • Right to restriction โ€” to limit how we process your data in certain circumstances
  • Right to data portability โ€” to receive your data in a structured, machine-readable format
  • Right to object โ€” to object to processing based on legitimate interests
  • Right to withdraw consent โ€” where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, please contact us at hello@worlddepin.io. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113.

11. Children's Privacy

Our services are not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "effective date" at the top of this page will reflect when it was last revised. We encourage you to review this page periodically. Continued use of our services after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy, how we handle your personal data, or wish to exercise your rights, please contact us:

IT Solution Architecture Limited (trading as World DePIN)
Registered in England and Wales ยท Company No. 12066050 ยท VAT No. 325 6309 11
๐Ÿ“ง hello@worlddepin.io
๐ŸŒ worlddepin.io