Data Processing Addendum
Version 1.0 · Effective 18 September 2026
Overview
This Data Processing Addendum (DPA) describes how CollaFi processes user data and the third party services involved in data processing. It supplements the Privacy Policy with detail on processing activities and data flows.
Categories of Data Processed
Account Data
- Wallet address (Hedera Account ID)
- Display name (chosen by user)
- Email address (provided by user)
Transaction Data
- Offer creations, acceptances, and cancellations
- Loan funding and repayment events
- Default and claim events
- Points earned and redeemed
Communication Data
- AI chatbot interactions on the platform
- Email notifications sent
- Discord ticket communications
Technical Data
- Anonymized analytics on platform usage
- Cookies and session data
- Wallet connection metadata
Purposes of Processing
Data is processed for the following purposes only:
- Platform Operations: Enabling lending and borrowing functionality, escrow operations, notifications.
- User Communications: Sending transactional emails about offers, loans, and platform updates.
- Customer Support: Responding to inquiries via AI chatbot, Discord, and email.
- Platform Improvement: Analyzing usage patterns to identify issues and improve features.
- Anti Abuse: Monitoring for fraudulent activity or manipulation of the points system.
Data Transfers and Third Parties
CollaFi engages third party service providers to support platform operations. All providers are selected with consideration for their privacy and security practices. See the Third Party Service Provider List for details.
On Chain Data
Some user data, including wallet addresses and transaction history, is recorded on the Hedera network and is publicly visible. This is inherent to blockchain technology and cannot be modified or deleted by CollaFi.
Security Measures
- Industry standard encryption for data in transit and at rest.
- Access controls limiting team member access to user data.
- Monitoring for unauthorized access or unusual activity.
- Regular review of security practices and third party providers.
- Never storing private keys or seed phrases.
- Notifying affected users and any relevant authority without undue delay after a data breach.
CollaFi Reserves the Right
CollaFi reserves the right to update data processing practices as needed to protect users and maintain platform security. Material changes will be communicated through official channels.