Privacy Policy
Working draft for legal and business review. Fields marked [PLACEHOLDER] require confirmation. Applications and funding remain closed until the launch requirements are complete.
This notice describes personal information used by The Table, the Happimeal investor portal at [PLACEHOLDER: PORTAL URL]. The responsible organization is [PLACEHOLDER: COMPANY LEGAL NAME], [PLACEHOLDER: REGISTERED ADDRESS]. Privacy contact: [PLACEHOLDER: PRIVACY CONTACT]. Any required representative or data protection officer: [PLACEHOLDER: PRIVACY REPRESENTATIVE OR NOT APPLICABLE].
1. Information we process
Application information: the name or entity name, email, jurisdiction category, investor classification, optional experience, requested seat count, wallet address, submitted declarations and application status.
Agreement and financial records: wallet-control proofs, signed acceptance messages, document versions and digests, timestamps, operator eligibility references, seat records, public funding and payout transactions, daily entitlements, refunds and wallet-change proofs.
Access and security records: session identifiers stored in hashed form on the server, login challenges, operator identifiers and authentication information, audit events, request and job outcomes, rate-limit records and service logs. The application uses a keyed representation of the client IP for rate limiting when trusted ingress supplies it; the hosting proxy can separately log the connecting IP.
Support and additional verification: information you provide through the designated support or verification channel. Any additional identity provider, evidence collected and secure submission process are [PLACEHOLDER: ADDITIONAL VERIFICATION DATA AND PROVIDER]. Do not send wallet private keys or recovery phrases.
Sources include you, your connected wallet, public blockchain records, authorized operators, the programme’s revenue accounting service and the operator login provider. Public wallet and transaction records can become identifiable when linked to application information.
2. Purposes and legal grounds
We use this information to review applications, verify control of wallets, record consent, administer seats and accounting, verify transfers, review refunds and wallet changes, provide support, secure the service and meet applicable recordkeeping obligations.
The legal ground for each purpose, any relevant legitimate interests and which information is required by contract or law are [PLACEHOLDER: PURPOSE BY PURPOSE LEGAL BASIS AND REQUIRED DATA]. Without information needed for application review, wallet verification or accounting, the corresponding service may be unavailable. Reading or acknowledging this notice does not by itself establish consent as the legal ground for every use.
3. Cookies and browser storage
The portal uses essential cookies for investor sessions, operator sessions and short-lived authentication flows. Production session cookies are restricted to this site and cannot be read by page scripts. Investor login lasts at most 24 hours with a two-hour inactivity limit; operator login lasts at most one hour with a fifteen-minute inactivity limit. Login challenges last five minutes. Signing out revokes the current session.
A browser preference stores the selected visual theme. The supplied portal does not include advertising or marketing analytics scripts. The deployed hosting, login and wallet providers’ actual cookies and additional processing must be disclosed at [PLACEHOLDER: DEPLOYED PROVIDER COOKIE AND STORAGE DETAILS] before launch. New optional tracking requires separate review and any applicable choice mechanism.
4. Recipients and service providers
Authorized programme personnel receive information needed for their responsibilities. Hosting, database, backup, monitoring, blockchain access, operator identity and any verification providers may process relevant information. The actual providers, purposes and locations are [PLACEHOLDER: SERVICE PROVIDERS AND PROCESSING LOCATIONS]. Legal or professional disclosures and their conditions are [PLACEHOLDER: LEGAL AND PROFESSIONAL DISCLOSURE POLICY].
Public blockchain transactions disclose wallet addresses, amounts and transaction details to network participants and public explorers. The portal does not put names, email addresses or agreement text into USDC transfers. Your chosen wallet and services you open independently may process information under their own notices.
5. International transfers
The countries in which information is processed, applicable transfer safeguards and how to obtain details are [PLACEHOLDER: INTERNATIONAL DATA TRANSFER ARRANGEMENTS]. Do not assume that a blockchain or an overseas service provider stores information only in the Company’s home country.
6. Retention and correction
The retention periods or criteria for rejected and expired applications, active and former holders, financial and consent records, security logs, support material and backups are [PLACEHOLDER: DATA RETENTION SCHEDULE]. Authentication expiry prevents reuse but does not itself mean that every associated audit or ledger record has been deleted.
Financial and signed-consent records are protected against ordinary edits. Corrections and lawful deletion or restriction requests require review of the affected records, supporting evidence, retention duties and backups. The approved procedure is [PLACEHOLDER: DATA RIGHTS AND DELETION PROCEDURE]. Public blockchain history cannot be erased by this portal.
7. Your requests and rights
Depending on the law that applies, you may have rights to obtain information and access, correct inaccurate information, request erasure or restriction, object to certain processing, receive portable information, withdraw consent where relied upon, and complain to a supervisory authority. Contact [PLACEHOLDER: PRIVACY CONTACT]. We verify requests without asking for wallet keys. The applicable authority and request process are [PLACEHOLDER: PRIVACY AUTHORITY AND REQUEST PROCESS].
Any required exceptions, response periods and escalation route must be confirmed for the actual Company and affected users. A privacy request does not authorize a wallet change, financial transfer or deletion of another person’s records.
8. Automated processing and human review
Software verifies signatures and transfers, applies recorded eligibility states, calculates entitlements and enforces security controls. An authorized operator reviews eligibility and payout instructions; Safe owners separately sign transfers. The supplied portal does not use AI to decide applicant eligibility. Requests to review an outcome go to [PLACEHOLDER: SUPPORT EMAIL]. Any additional automated screening by a provider must be explained in the approved verification procedure.
9. Security, children and changes
The release includes restricted access, secure sessions, encrypted transport, audit records and backup tooling. Actual hosting and provider arrangements must be configured and verified. No system can promise that information will never be lost or accessed unlawfully. Report a suspected incident to [PLACEHOLDER: SECURITY CONTACT].
The service’s minimum age and eligibility restrictions are [PLACEHOLDER: MINIMUM AGE AND CAPACITY REQUIREMENTS]. If information was provided by an ineligible child, contact the privacy team for review under the applicable retention and deletion procedure.
The process for notifying material changes to this notice is [PLACEHOLDER: PRIVACY NOTICE CHANGE PROCEDURE]. The page identifies its version and update date. A later notice does not silently change a previously signed seat agreement.
