// LEGAL

Privacy Policy

entity: Haycar Global Pty Ltd (ABN pending) - Animalis aRK dApp
domain: animalisark.app
effective: 2026-05-02
updated: 2026-05-02
contact: [email protected]

Table of Contents

  1. About This Policy and the dApp
  2. A Note on Blockchain Architecture
  3. Data We Collect Off-Chain
  4. On-Chain Data - Wallets, DIDs, Tokens, Governance
  5. Animal DID and TWIN NFT Data
  6. How We Use Off-Chain Data
  7. Legal Basis for Processing
  8. Third-Party Infrastructure
  9. Data Retention
  10. International Data Transfers
  11. Your Rights
  12. Wallet Security
  13. Children's Privacy
  14. Data Breaches
  15. Contact and Complaints

1. About This Policy and the dApp

This Privacy Policy governs the handling of personal data by Haycar Global Pty Ltd (ABN pending) ("we", "us") in connection with the Animalis aRK dApp at animalisark.app - a decentralised application for animal digital identity, AARK token operations, DePIN node staking, and conservation DAO governance on the Cardano blockchain.

We are committed to compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For users in the European Economic Area or United Kingdom, we also comply with the General Data Protection Regulation (GDPR) and UK GDPR.

The dApp operates across two distinct environments: (1) the off-chain web application at animalisark.app, and (2) the Cardano public blockchain. These environments have fundamentally different privacy characteristics. Please read Section 2 carefully before connecting your wallet.

2. A Note on Blockchain Architecture

Critical Notice: The Cardano blockchain is a public, decentralised, immutable ledger. Data written to the Cardano blockchain - including wallet addresses, transaction hashes, DID registrations, AARK token balances, and DAO governance votes - is publicly visible, permanently stored, and cannot be deleted or modified by anyone, including Animalis aRK or Haycar Global Pty Ltd.

Before connecting your wallet or interacting with any on-chain feature of this dApp, please understand:

// Example on-chain record - permanent and public
did:haycar:device:aic-A1B2C3D4E5F6 {
  registered_at: <block_hash>,
  issuer_wallet: addr1q...<public>,
  credential_hash: <sha256>
}

If you are not comfortable with public, permanent records of your wallet activities, do not connect your wallet to this dApp.

3. Data We Collect Off-Chain

The off-chain components of the Animalis aRK dApp (the web application at animalisark.app) may collect the following:

3.1 Connection and session data

3.2 Technical data

3.3 Voluntarily submitted data

3.4 What we do NOT collect off-chain

4. On-Chain Data - Wallets, DIDs, Tokens, Governance

The following categories of data are recorded on the Cardano blockchain by your actions within the dApp. All such data is public and permanent:

5. Animal DID and TWIN NFT Data

Animalis-IC device DIDs are anchored to Cardano via Atala PRISM. The DID document contains:

Raw veterinary health records and clinical data are stored off-chain in our secure platform (animalisark.io) and are subject to the 7-year health records retention policy. Only cryptographic hashes are written on-chain.

TWIN NFT metadata is stored on IPFS and anchored to Cardano. IPFS content is content-addressed and globally replicated. While IPFS content can theoretically be unpinned (ceasing propagation), any copies already replicated across the IPFS network will persist independently. Treat TWIN NFT metadata as effectively permanent once minted.

The animal's owner details (human name, contact info) are not written to the blockchain. The DID is pseudonymous. However, the association between a wallet address and an animal may be determinable by a sophisticated observer through external means.

6. How We Use Off-Chain Data

We use off-chain data collected by the dApp to:

We do not sell off-chain data. We do not use your wallet address or dApp activity for third-party advertising.

7. Legal Basis for Processing

Under the Australian Privacy Act 1988, we process personal information where reasonably necessary for delivering the dApp services in the context of the user's voluntary use.

For EEA/UK users under GDPR:

On-chain data (once written) is outside the scope of privacy law erasure rights due to blockchain immutability - this is an inherent technical characteristic of public blockchain infrastructure, not a choice we make.

8. Third-Party Infrastructure

9. Data Retention

10. International Data Transfers

Cardano blockchain data is replicated globally by the decentralised node network - this is inherent to the technology. Off-chain application data may be hosted on servers in Australia and/or Singapore. We apply appropriate safeguards for cross-border transfers of off-chain personal data.

The animalisark.app web application is accessible globally via Cloudflare's CDN. Cloudflare may process request metadata at edge nodes worldwide; this is governed by Cloudflare's privacy policy and data processing agreements.

11. Your Rights

Under the Australian Privacy Act 1988 and GDPR, you have the following rights over your off-chain personal data:

Limitation: Rights of erasure and rectification cannot extend to on-chain data. Once recorded on the Cardano blockchain, data is immutable and beyond our ability to alter or delete. This applies to all parties including governments and courts.

To exercise rights over off-chain data, contact [email protected]. We respond within 30 days.

12. Wallet Security

Your wallet security is solely your responsibility. We will never ask for your seed phrase, private key, or wallet password. Any communication claiming to be from Animalis aRK that asks for these credentials is a scam - do not respond.

We recommend using hardware wallets for significant AARK holdings. We are not liable for losses arising from compromised wallet credentials, phishing attacks, or unauthorised wallet access.

13. Children's Privacy

The Animalis aRK dApp involves cryptocurrency and blockchain operations and is not suitable for or directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has connected a wallet or created an account, contact [email protected].

14. Data Breaches

In the event of an eligible data breach affecting off-chain personal data:

On-chain data cannot be subject to a "breach" in the conventional sense, as it is already public by design. We implement technical security measures for all off-chain application data including encrypted storage, access controls, and audit logging.

15. Contact and Complaints

Privacy Officer - Animalis aRK dApp
Haycar Global Pty Ltd
Brisbane, Queensland, Australia
Email: [email protected]

Complaints unresolved by us may be lodged with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. EEA/UK users may contact their local data protection authority.

This Privacy Policy may be updated. Material changes will be communicated via the dApp interface and via our foundation communications. The current version and effective date are shown at the top of this page.