Privacy Policy
Last updated: 20 July 2026 (v2.1 — cookie section expanded, GDPR consent banner added) · Effective date: 29 June 2026
Operated by N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121)
NavScope (“we”, “us”, or “our”) is committed to protecting your privacy. This Policy is compliant with the Australian Privacy Act 1988 (Cth) — 13 Australian Privacy Principles (APPs) — and provides GDPR Article 6 / CCPA disclosures for EU, UK, and California residents.
Table of Contents
- About This Policy
- What Personal Information We Collect
- Webhook Delivery — Customer-Controlled URLs
- How We Use Personal Information
- How We Share Personal Information
- Fractional ID and Payment Attribution Data
- Data Retention
- Security of Personal Information
- Your Rights (APPs / GDPR / CCPA)
- Cookies and Local Storage
- International Data Transfers
- Complaints
- Policy Amendments
1. About This Policy
This Privacy Policy describes what personal information NavScope (N.S. IT SERVICES PTY LTD, ABN 75 122 740 121) collects about you, why we collect it, how we use and share it, how long we keep it, and your rights regarding it.
This Policy applies to all personal information collected through navscope.io, staff.navscope.io, NavScope’s APIs, webhook delivery services, and any interaction between you and NavScope.
This Policy does not apply to publicly available on-chain data, exchange market data, or public social media posts about cryptocurrency projects.
2. What Personal Information We Collect
Account Information
Email address; display name or username; hashed password; account creation timestamp; subscription tier and history.
Token Issuer Registration Data
Token name/symbol; contract address(es); project team name/entity; website URL; social media handles (X/Twitter, Telegram, Discord); contact email; DNS verification token; representations and warranties submitted.
Payment Data
Ethereum wallet address from which USDT payment was sent (recorded from blockchain); transaction hash; payment amount (USDT) and timestamp; Fractional ID; invoice ID and subscription period. NavScope does not collect credit card numbers, bank account details, or any fiat payment data.
Usage and Technical Data
IP address; browser type/version; operating system; referring URL; pages visited and timestamps; features accessed; API request logs.
Communications Data
Emails and support tickets; right-of-reply submissions (retained 7 years from publication per defamation limitation periods under the Limitation Act 1969 (NSW)).
Voluntary Wallet Tying
You may voluntarily associate an Ethereum wallet address with your NavScope account via the wallet-tying flow (POST /api/v1/public/checkout/wallets/tie and POST /api/v1/public/checkout/wallets/tie/verify). This involves signing a one-time challenge nonce with your Ethereum wallet (MetaMask or hardware wallet via personal-sign) and submitting the signed message to NavScope for verification. On successful verification, your Ethereum wallet address is stored in the customer_tied_wallets table, linked to your account. This collection is voluntary — it enables faster refund processing and simplified subscription renewal. The wallet address is retained for the duration of the account and 7 years after closure, consistent with payment record retention (see Data Retention table). You may untie a wallet at any time by contacting [email protected].
Webhook Configuration Data
Webhook endpoint URL(s); configuration settings (event types, filter criteria, authentication headers if provided); delivery logs (timestamps, HTTP response codes, retry counts, payload summaries) — retained for 30 days rolling, then auto-purged.
3. Webhook Delivery — Customer-Controlled URLs and Data-in-Transit
NavScope’s webhook service delivers NavScope market data events (token prices, gate statuses, narrative publication events) to HTTPS endpoints you configure. Webhook payloads do not contain personal information about NavScope customers or individuals.
Customer-Side Responsibility
You are the data controller for all NavScope market data received via webhooks and for any personal information you associate with that data on your own systems. You are solely responsible for: (a) the security of your webhook endpoint; (b) access controls to your endpoint server; (c) not embedding personal information in your registered endpoint URL.
Data-in-Transit Security
NavScope transmits webhook payloads using HTTPS with TLS encryption and optionally signs payloads with an HMAC-SHA256 signature (available to API subscribers) so you can verify authenticity. NavScope is not liable for security breaches at your endpoint or for misuse of NavScope data that you associate with personal information on your systems.
Delivery Log Retention
Delivery attempt logs (endpoint URL, HTTP status, retry count, payload summary) are retained for 30 days, then auto-purged. Customers may request a delivery log extract via [email protected] within the 30-day window.
4. How We Use Personal Information
- Account creation and maintenance
- USDT payment processing and attribution via Fractional ID
- Provisioning subscribed services and delivering webhook events
- Subscription invoicing, renewal reminders, and payment confirmations
- Token Issuer verification (DNS TXT verification) and critical-question outreach workflows
- Sanctions screening (OFAC / Australian DFAT) on incoming USDT transactions
- Fraud detection, abuse prevention, and security monitoring
- ATO tax compliance and potential AUSTRAC obligations
- Aggregated, de-identified usage analytics for product improvement
- Legal proceedings and regulatory compliance
5b. Legal Basis for Processing (EU/UK GDPR — Article 6)
| Processing Activity | Legal Basis |
|---|---|
| Account registration and authentication | Contract (Art. 6(1)(b)) — necessary to provide the Service |
| Transactional emails (OTP, invoices, renewal notices) | Contract (Art. 6(1)(b)) — essential service communications |
| USDT payment processing and attribution | Contract (Art. 6(1)(b)) — fulfilling the payment agreement |
| Webhook delivery to Customer-configured endpoints | Contract (Art. 6(1)(b)) — fulfilling the API subscription agreement |
| API access logging for rate-limiting and fair use | Legitimate interests (Art. 6(1)(f)) — protecting service integrity |
| Sanctions screening (OFAC / AU DFAT) | Legal obligation (Art. 6(1)(c)) — AML/CTF compliance |
| Anonymised usage analytics | Legitimate interests (Art. 6(1)(f)) — product improvement; opt-out available |
| Newsletter subscription | Consent (Art. 6(1)(a)) — withdrawable at any time by unsubscribe |
6. Fractional ID and Payment Attribution Data
When you make your first payment to NavScope, our system assigns you a permanent 6-decimal Fractional ID (e.g., .000123) embedded in every USDT invoice amount for the lifetime of your account.
The Fractional ID alone is not personally identifiable. However, when linked to your account in the customer_fractional_assignments table, it forms part of a personal information dataset. NavScope treats all associated records as personal information subject to APP protections.
Your Fractional ID is retained permanently for your account lifetime and for at least 7 years after account closure per ATO and potential AUSTRAC record-keeping obligations. For deletion requests, NavScope may retain the Fractional ID in pseudonymised form to comply with AML record-keeping obligations.
7. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information (email, name, tier) | Account duration + 7 years | ATO + AU civil limitation |
| Payment records (TX hash, wallet, amount, Fractional ID) | 7 years from transaction | ATO + potential AUSTRAC |
| Fractional ID assignment | Permanent (pseudonymised after 7 years if closed) | AML/CTF record integrity |
| OFAC/sanctions screening records | 7 years | Compliance best practice |
| Token Issuer registration data | Registration duration + 7 years | AU civil limitation |
| Right-of-reply submissions | 7 years from article publication | Defamation limitation (NSW) |
| IP address and usage logs | 12 months rolling | Security; abuse detection |
| Email and support records | 3 years from last communication | Contract records |
| Webhook configuration (endpoint URLs, settings) | Webhook subscription duration + 2 years | Service audit |
| Webhook delivery logs | 30 days rolling → auto-purge | Troubleshooting |
| Newsletter subscriber email | Until unsubscription + 30 days | Consent-based |
8. Security of Personal Information
- All data in transit: HTTPS / TLS 1.3 encryption on all public-facing services.
- Data at rest: AES-256 encryption for sensitive fields (including customer_fractional_assignments).
- Passwords: one-way bcrypt hash — NavScope cannot read your plain-text password.
- Hardware wallet custody: NavScope USDT treasury held in a Ledger hardware wallet under physical PM custody.
- Webhook payload authentication: optional HMAC-SHA256 signature (API subscribers) for payload origin verification.
- Access controls: personal data accessible only to NavScope staff requiring it for their role.
- Data Breach Response (NDB scheme / GDPR Article 33): NavScope will notify the OAIC and affected individuals of eligible breaches as soon as practicable, and within 72 hours consistent with GDPR Article 33 obligations where applicable.
9. Your Rights (APPs / GDPR / CCPA)
How to exercise your rights
Email [email protected] with your request. NavScope will verify your identity and respond within 30 calendar days. Complex or numerous requests may be extended by a further 60 days with notification within the first 30 days.
11. International Data Transfers
NavScope is an Australian company. Primary infrastructure is hosted with Hetzner Online GmbH in Germany (EU). By using the Platform, you acknowledge that your personal information may be transferred to and processed in Germany.
NavScope will execute a DPA with Hetzner Online GmbH prior to processing first paying customer’s personal data, governing Hetzner’s handling in accordance with APP 8 (Cross-Border Disclosure of Personal Information).
Where NavScope transfers personal data outside the EU/EEA (for example, to Cloudflare in the USA), NavScope relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms recognised under GDPR.
Supervisory Authority Contact Points
- Australia: OAIC — www.oaic.gov.au / 1300 363 992
- Germany: BfDI — bfdi.bund.de
- UK: ICO — ico.org.uk
- Other EU: edpb.europa.eu
12. Complaints
Privacy Officer. NavScope has designated a Privacy Officer as the first point of contact for all privacy inquiries, access requests, and complaints.
Contact: [email protected]
NavScope will acknowledge your complaint within 5 Working Days and provide a substantive response within 30 days.
If you are not satisfied, you may lodge a complaint with the OAIC (www.oaic.gov.au) for Australian residents, or the relevant supervisory authority in your jurisdiction for EU/UK residents.
13. Policy Amendments
NavScope may amend this Privacy Policy at any time. Material amendments will be notified to registered Customers via email at least 14 days before they take effect. The current version of this Policy is always available at navscope.io/legal/privacy.
Privacy Contact
For all privacy enquiries, data requests, or to report a concern, contact our Privacy Officer at [email protected].
N.S. IT SERVICES PTY LTD · ABN 75 122 740 121 · ACN 122 740 121 · Australia