ANNEX - Legal bases/purposes for Tools for Humanity data processing activities
Version: 1.1Effective September 3, 2025
ANNEX – Legal bases/purposes for Tools for Humanity data processing activities
Why We Process the Data | What Personal Data is Processed | Legal Ground for the Processing | Retention Period |
To create your account in World App | Wallet address, metadata, username | Performance of contract | Duration of your use of our Services, or until you request the deletion of the data. |
To ensure you are of eligible age | Date of birth | Legal obligation | Your exact date of birth is never stored. We only store whether you are over the age of majority in your country. We store this information for the duration of your use of our Services or until you request the deletion of the data. |
To enable your contacts to easily communicate and transact with you, to help restore your backup and attribute referrals | Phone number | Consent | Duration of your use of the feature or until you request the deletion of the data. |
To enable you to easily communicate and transact with your contacts | Address book contacts | Consent | Duration of your use of our Services, or until you request the deletion of the data. |
To show you Orbs near you | Location information | Consent | Up to 24 months. |
To prevent fraud | Metadata, IP addresses, Device ID | Legitimate interest, namely to prevent certain types of fraud | Up to 24 months. |
To ensure our Service are permitted in your country or region | IP addresses, location information | Legal obligation | Up to 24 months. |
To display your self-custodial wallet and provide an interface for wallet transactions | Wallet address, transaction data | Performance of contract | No personal data is stored in this context. |
To display your self-custodial World ID and provide an interface for verifications | Verification level | Performance of contract | No personal data is stored in this context. |
To display your self-custodial Credentials and provide an interface for sharing the Credentials | Credential information, credential validity information | Performance of contract | No personal data is stored in this context. |
To analyze and improve our Services and to conduct data science research | Usage data and metadata, public transaction data | Consent | Up to 24 months. Please note that public transactions on a blockchain are immutable, meaning that they cannot be deleted. |
To comply with applicable laws such as anti-money laundering law, and sanctions | Public transaction data, wallet address | Legal obligation | Duration of your use of our Services. If We have reasonable suspicions of illicit behavior We store data for 5 years for sanctions compliance requirements. Please note that public transactions on a blockchain are immutable, meaning that they cannot be deleted. |
To comply with applicable laws, such as content regulations | Content you publish on Mini Apps | Legal obligation | Duration of the use of our Services. If We have reasonable suspicions of illicit behavior We store data for 3 years in case of any subsequent legal action. |
To enable communication and marketing | Email address, push notifications | Legitimate interest, namely to notify you about relevant events | Up to 24 months. |
Correspondence from you | Legitimate interest, namely to respond to communication | Up to 24 months. | |
Feedback from you | Legitimate interest, namely to learn from feedback | Up to 24 months. | |
To handle your customer service requests, complaints and inquiries | Communication information and email or social media profile name if you seek to communicate with us through such means | Performance of contract | Up to 24 months. |
To make sure the app is functioning well for you | Metadata, including device metadata, IP addresses and to the extent necessary, previous interactions. | Performance of contract | Duration of your use of our Services. |
To learn from your interactions with our Services and improve them | Metadata, previous interactions and events. | Consent | Up to 24 months. |
To verify your device | Device metadata | Performance of contract | Duration of your use of our Services. |
To prevent fraud | Device metadata, connection data like IP address | Legitimate interest, namely to prevent fraud | Up to 12 months; if potential fraud is detected We keep the data for 5 years. |
To resolve disputes, troubleshooting issues, and enforcing our agreements with you, including this Privacy Policy and our Terms and Conditions | Your interactions with World App and potential identifiers | Legitimate interests, namely the to enforce rights and resolve disputes | We only store this data if We have reasonable grounds to assume that a dispute will arise and store it for the duration of the dispute, or for 3 years if no dispute arises. |
TFHDPA20250801