Privacy and cookies policy for Donation Stream – updated 8th March 2021

At Donation Stream, we’re working hard to deliver a better alternative to donation revenue streams, privacy is a hugely important part of this. We want you to be confident that your data is safe and secure with us, and that you understand how we use it.

What this policy covers:

The data controller (who determines the purpose and manner in which your personal data is used) is Nascent Blockchain Limited (referred to in this policy as “we” or “us”).

We are committed to doing the right thing when it comes to how we collect, use and protect your personal data. That’s why we’ve developed this privacy and cookies policy (“Policy”), which:

Sets out the different ways you interact with us and the types of personal data that we collect and explains the reasons why we use the data we collect, explains when and why we will share personal data within the platform and with other users on the platform; and explains the rights and choices you have when it comes to your personal data We offer a platform to bring together donors and donees, so we want you to be clear about what this Policy covers. This Policy applies to you if you use our services (referred to in this Policy as “our Services”).

Using our Services means:

Using the websites (“our Website”) where this Policy is posted;

This Policy also applies if you contact us or we contact you about our Services

Our Website may contain links to other websites operated by other organisations that have their own privacy policies. Please make sure you read the terms and conditions and privacy policy carefully before providing any personal data on a website as we do not accept any responsibility or liability for websites of other organisations.

Online media channels include websites, social media sites, pay TV providers and any other channels that become available to us.

Donation Stream – Privacy Policy

Personal data we collect when we interact with you

This section tells you what personal data we may collect from you when you use our Services and what other personal data we may receive from other sources.

Types of data

Aggregated data We try and remove personal data we do not need. If we remove enough personal data it becomes anonymous. This means that you cannot be identified.

We might also take data we hold and remove certain information and replace it with other non-identifying information such as ID number or reference number. This is an extra technique we use to protect data.

We have no intention of using this data beyond our platform.

Identity data This is information that helps us and others using the platform identify who you are, so your display name, XRP wallet public address etc

Contact data This is information that details how we can contact you e.g email address. This may be used for verification purposes or password changes for example.

Financial data This may include information about your XRP wallet that is publicly available on the blockchain or other similar examples. This may also include verification of your Coil account or usage of coil for web monetisation purposes on our site.

Location data In some cases(google analytics – although not currently implemented on the platform but may be in the future) we may receive your location data.

Transaction data This is information about your streaming data which includes when, where, what and how you conducted that stream.

Technical data This is information about your device used to access our sites and apps. This could be information that identifies your device, its operating system, internet address, your login data; browser and plug-ins; location; where you came to our site from and where you leave to as well as how often you visit(this may be implemented in the future with google analytics).

User data This is information collected about you as a user of our website and services(compared to other types of data that relate to you directly for us to deliver our specific service to you). This may include where you engage with Nascent Blockchain Limited in a survey, provide feedback on your stream experience etc.

We will also collect information about you that allows us to create an analysis of you as a stream user to better judge what services to offer.

Interaction data This is information about how you interact with our services, namely what you click on and interact with on our site.

Marketing and communications data This is your marketing preferences and also your interaction with online marketing to be able to judge its effectiveness. Although we do not currently conduct marketing contact on the website.

When you register for our Services You may provide us with: Your personal details, including your XRP wallet public address, email addresses, display name, Twitter account, gmail account or github account.

Your account login details, such as your username and the password that you have chosen.
We may collect:
Identity data
Contact data
Financial data
Technical data
User data
Marketing and communications data

When you browse our Websites

We may collect: Information about your streams(for example, what you have bought, when and where you bought it and how you paid for it). Information about your online browsing behaviour. Information about any devices you have used to access our Services (including the make, model and operating system, IP address, browser type and mobile device identifiers)

What type of data might be collected: Identity data Contact data Financial data Transaction data Technical data User data Interaction data Marketing and communications data

When you contact us or we contact you or you take part in promotions, competitions, surveys or reviews about our Services

We may collect: Personal data you provide about yourself anytime you contact us about our Services (for example, your name, username and contact details), including by phone, email or post or when you speak with us through social media Details of the emails and other digital communications we send to you that you open, including any links in them that you click on. Your feedback and contributions to customer surveys or reviews.

What type of data might be collected: Identity data Contact data User data

What personal data has the Government given Nascent Blockchain Ltd? The Government has not given us any data or information about you or your household.

‘Our legitimate interests in using your personal data’). The rest of this Policy explains how and why we process data because you are a user of our services.

How will Nascent Blockchain Ltd keep this personal data safe?

For more information on how we keep your personal data safe, see the section in this Policy called “How we protect your personal data”.

More information and your data privacy rights For more information about your data privacy rights, please see the sections in this Policy called “Subject Access Rights” and “Other Data Protection Rights”.

Why we collect the data we collect and why we are allowed to use that personal data This section explains in detail how and why we use personal data. We use personal data to:

Make our Services available to you This means that processing your personal data allows us to: Manage the accounts you hold with us.

Why do we process your personal data in this way? We need to process your personal data so that we can manage your user accounts, provide you with the goods and services you want to buy and help you with any issue regarding our services you may ask about.

Why we are using this data (Legal Basis):

Contractual Necessity – at the time we collect it: Purchase & transaction data; Contact details; Profile details; We will not be able to provide you with your services if you do not provide us with this data.

Legitimate Interests - following fulfilment of your stream.

Manage and improve our day-to-day operations Manage and improve our Website

Why do we process your personal data in this way?

We use cookies and similar technologies on our Websites to improve your customer experience.

You can disable other cookies but this may affect your customer experience. For more information about cookies and how you can disable them, see the cookies and similar technologies section.

Help to develop and improve our product range, services, information technology systems, know-how and the way we communicate with you

Why do we process your personal data in this way?

We rely on the use of personal data to carry out market research and internal research and development, and to improve our information technology systems (including security) and our services. This allows us to serve you better as a customer.

Detect and prevent fraud or other crime Why do we process your personal data in this way? It is important for us to monitor how our Services are used to detect and prevent fraud, other crimes and the misuse of services. This helps us to make sure that you can safely use our Services.

Why we are using this data (Legal Basis): Contractual Necessity – at the time we collect it: Purchase & transaction data; Contact details; Profile details;

We will not be able to provide you with your services if you do not provide us with this data. Legitimate Interests - following fulfilment of your stream for the other personal data in that section. Why we are using this data (Legal Basis): Legitimate Interests

Personalise your Donation Stream experience Use your online browsing behaviour to help us better understand you as a customer and provide you with personalised service.

Why do we process your personal data in this way? Looking at your browsing behaviour allows us to personalise services for you. This helps us meet your needs as a customer. Provide you with relevant marketing communications (including by email), relating to our services.

Contact and interact with you Contact you about our Services, for example by email or by responding to social media posts that you have directed at us.

Why do we process your personal data in this way? We want to serve you better as a customer so we use personal data to provide clarification or assistance in response to your communications

Manage promotions and competitions you take part in.

Why do we process your personal data in this way?

We need to process your personal data so that we can manage the promotions and competitions you choose to enter. Invite you to take part in and manage customer surveys, reviews and other market research activities carried out by Nascent Blockchain Ltd and by other organisations on our behalf. We currently do not run promotions or competitions on the site.

Why do we process your personal data in this way?

We carry out market research to improve our Services. However, if we contact you about this, you do not have to take part in the activities. If you tell us that you do not want us to contact you for market research, we will respect this choice.

Why are we using this data? (Legal basis): Legitimate Interests.

Claims In order to resolve legal claims or disputes involving you or us. Why do we process your personal data in this way? For example if there is any issue with a stream.

Data access We only authorise access to employees and trusted partners who need it to carry out their responsibilities; We regularly monitor our systems for possible vulnerabilities and attacks, and we carry out penetration testing to identify ways to further strengthen security; We will ask for proof of identity before we share your personal data with you; Whilst we take appropriate technical and organisational measures to safeguard your personal data, it is important that you keep your login details and devices protected from unauthorised access.

How long we use personal data for We will not keep your personal data longer than we need to, and will only use your personal data for the purposes set out in this Policy. We will always keep your personal data in accordance with applicable legal and regulatory requirements. In most circumstances this means we will not keep your personal data for more than 7 years after the end of your relationship with us.

Where your personal data is needed because we are in serious dispute with you (such as litigation), your personal data will be deleted 7 years after closure of the matter.

Cookies and similar technologies We have a Cloudflare security cookie in the browser to help prevent illegitimate users on the website, also some other essential cookies in relation to firebase/firestore to help us conduct user authentication on the site. We may use other cookies in the future and will update accordingly. If we do use cookies and similar technologies, such as tags and pixels (“cookies”), to personalise and improve your customer experience in the future we will update this policy and you will always be given an opt-out on the website This section provides more information about cookies, including how we use them and how you can exercise your choices about our use of cookies.

How we use cookies Cookies are small textfiles containing a unique identifier, which are stored on your computer or mobile device so that your device can be recognised when you are using a particular website or mobile app. They can be used only for the duration of your visit or they can be used to measure how you interact with services and content over time. Cookies help to provide important features and functionality on our Website, and to improve your customer experience. Cookies can also be used help us to detect fraudulent activity or to prevent security breaches and so we may record information about your device within the cookie.

When you consent to cookies on our Services, these may be used to do the following:

Improve the way our Website works: Cookies allow us to improve the way our Website works so that we can personalise your experience and allow you to use many of their useful features. For example, we use cookies so we can remember your preferences and the contents of your stream when you return to our Website.

Improve the performance of our Websites and Mobile Apps

Cookies can help us to understand how our Website is being used, for example, by telling us if you get an error messages as you browse. These cookies collect data that is mostly aggregated and anonymous.

We may also use cookies to measure the effectiveness of our marketing communications, for example by telling us if you have opened a marketing email that we have sent -although we currently do not send emails.

Web browser cookies You can use your browser settings to accept or reject non essential cookies and to delete existing non-essential cookies. You can also set your browser to notify you each time new cookies are placed on your computer or other device. You can find more detailed information about how you can manage cookies through your browser’s help function.

If you choose to disable some or all cookies, you may not be able to make full use of our Website. For example, you may not be able to use any of our services that require you to sign in(although we regard this as an essential cookie).

Managing your cookie preferences We use cookies to improve your experience on our website. However, your consent is needed for certain cookies before they can be used. You can also choose which cookies you allow us to use, apart from essential cookies, which can’t be turned off .

How we protect your personal data: Please contact us for further information as to how we protect your personal information.

Subject access rights You have the right to see the personal data we hold about you. This is called a Subject Access Request. To comply with government guidance we provide an email for you to contact if you would like a copy of the personal data we hold about you, please email us at privacy@donationstream.co.uk.

Other data protection rights In relation to your personal data, you also have the right to: . have inaccurate information corrected:

Summary of the right:

if you believe we hold inaccurate or missing information, please let us know and we will correct it.

object to our use of it: Summary of the right: general objection - We will then consider your objection to our use of your personal data. If on balance, your rights outweigh our interests in using your personal data, then we will at your request either restrict our use of it or delete it.

objection in relation to direct marketing - If you make such an objection, we will stop using your personal data for direct marketing purposes.

restrict our use of it: Summary of the right: There are several situations when you can restrict our use of your personal data, this includes (but is not limited to): you have successfully made a general objection. you are challenging the accuracy of the personal data we hold. we have used your personal data unlawfully, but you do not want us to delete it.

have us delete it: Summary of the right: There are several situations when you can have us delete your personal data, this includes (but is not limited to): we no longer need to keep your personal data; you have successfully made a general objection;

you have withdrawn your consent to us using your personal data (and we do not have any other grounds to use it);

we have unlawfully processed your personal data.

complain to the data protection regulator: We’d like the chance to resolve any complaints you have, however you also have the right to complain to the UK data protection regulator (the “ICO“) about how we have used your personal data.

Their website is https://ico.org.uk/your-data-matters/raising-concerns/ (https://ico.org.uk/your-data-matters/raising-concerns/).

More Information on your Data Protection Rights The ICO website also contains more detail on the data protection rights mentioned above, or if you would like to speak to us about these rights in more detail, see the “how to contact us” section below.

How to contact us

privacy@donationstream.co.uk

We reserve the right to change the policy at any time, so please check back regularly to keep informed of updates to this Policy.