Privacy Policy

Last Updated: April 2026

Effective Date: April 2026

This Privacy Policy describes how Haetae Finance (“Haetae,” “we,” “us,” or “our”), a Georgia-registered entity, collects, uses, and handles information when you use the Haetae Finance protocol, website (https://haetae.finance), and associated services (collectively, the “Service”).

Haetae Finance is a decentralized, non-custodial yield optimization protocol. We are committed to a privacy-first, blockchain-native approach. We collect minimal data, we do not require personal identification, and we do not perform KYC (Know Your Customer) verification.

1. Introduction

Haetae Finance operates as a DeFi (decentralized finance) protocol. Unlike traditional financial services, we do not create user accounts, require email addresses, or collect personal identification documents. You interact with our protocol through your self-custodial cryptocurrency wallet.

This means our data collection is fundamentally different from conventional web services. This policy is designed to be transparent about what data we do and do not collect, and how any collected data is used.

2. Information We Collect

2.1 On-Chain Data (Publicly Available)

When you interact with Haetae Finance smart contracts, certain data is inherently recorded on public blockchain networks (GIWA Chain, Ethereum, Base, Arbitrum, Optimism). This includes:

  • Wallet addresses that interact with Haetae Finance contracts.
  • Transaction data: deposit amounts, withdrawal amounts, vault interactions, timestamps, gas fees paid.
  • Vault share token balances associated with your wallet address.

This data is publicly visible to anyone on the respective blockchain networks. Haetae Finance does not control, own, or have the ability to delete on-chain data. The collection of this data is an inherent function of blockchain technology, not a choice made by Haetae Finance.

We may index and aggregate publicly available on-chain data to display information on the Service interface (e.g., total value locked, vault performance metrics, your deposit history when your wallet is connected).

2.2 Technical Data (Collected by the Website)

When you visit the Haetae Finance website, we may automatically collect limited technical data, including:

  • IP address(may be anonymized or aggregated).
  • Browser type and version.
  • Operating system.
  • Device type (desktop, mobile, tablet).
  • Referring URL (the page that linked you to our site).
  • Pages visited and time spent on the Service.
  • General geographic region (derived from IP address, not precise location).

This data is collected for analytics and security purposes only and is not linked to your identity or wallet address.

2.3 Information We Do NOT Collect

To be clear, Haetae Finance does not collect:

  • Names, email addresses, phone numbers, or physical addresses.
  • Government-issued identification or KYC documents.
  • Social media accounts or profiles.
  • Bank account or credit card information.
  • Private keys, seed phrases, or wallet passwords.
  • Biometric data.

We do not create user accounts. We do not require registration. We do not send marketing emails because we do not have your email.

3. How We Use Information

3.1 On-Chain Data

  • To display your vault positions, balances, and transaction history when your wallet is connected to the Service interface.
  • To calculate and display aggregate protocol metrics (total value locked, vault APY, historical performance).
  • To monitor protocol health and detect potential security incidents.

3.2 Technical Data

  • To understand how users interact with the Service interface and identify areas for improvement.
  • To monitor and ensure the security and stability of the website.
  • To detect and prevent abuse, including bot attacks and denial-of-service attempts.
  • To generate aggregated, anonymized usage statistics.

3.3 Legal Basis for Processing

Where applicable (e.g., for users in jurisdictions subject to GDPR), we process data based on:

  • Legitimate interest: Website analytics, security monitoring, and protocol health.
  • Consent: Where cookies or tracking technologies require consent under applicable law.

4. Cookies and Tracking Technologies

4.1 What We Use

The Haetae Finance website may use:

  • Strictly necessary cookies: Required for the website to function (e.g., wallet connection state, user preferences such as selected chain).
  • Analytics cookies: Used to understand website usage patterns. We may use privacy-focused analytics tools that minimize data collection.

4.2 What We Do Not Use

  • We do not use advertising cookies or tracking pixels.
  • We do not participate in advertising networks.
  • We do not sell or share cookie data with advertisers.
  • We do not use cross-site tracking.

4.3 Managing Cookies

You can control cookies through your browser settings. Blocking strictly necessary cookies may impair the functionality of the Service interface, but will not affect your ability to interact with the smart contracts directly.

5. Third-Party Services

The Service interacts with or relies on the following categories of third-party services:

5.1 Blockchain Networks

Transactions are processed on public blockchain networks (GIWA Chain, Ethereum, Base, Arbitrum, Optimism). These networks are decentralized and operated by independent validators/miners. Your on-chain data is governed by the properties of these networks.

5.2 Wallet Providers

We integrate with third-party wallet providers (e.g., MetaMask, WalletConnect) to allow you to interact with the protocol. Your use of these wallet providers is governed by their respective privacy policies.

5.3 Beefy Finance API

We may use the Beefy Finance API to retrieve vault data, APY calculations, and TVL information. This interaction involves server-to-server requests and does not transmit your personal data to Beefy Finance.

5.4 Analytics Providers

We may use privacy-focused analytics services to understand website usage. These providers receive the technical data described in Section 2.2 and process it according to their own privacy policies.

5.5 Infrastructure Providers

The website is hosted on cloud infrastructure. Hosting providers may process server logs containing IP addresses and request metadata as part of standard operations.

We do not control the data practices of these third-party services. We encourage you to review their respective privacy policies.

6. Data Sharing

6.1 What We Share

We do not sell, rent, or trade any data to third parties for marketing or advertising purposes.

We may share data in the following limited circumstances:

  • Service providers: With infrastructure, analytics, and hosting providers strictly necessary to operate the Service, subject to appropriate data processing agreements.
  • Legal requirements: If required to do so by law, regulation, legal process, or enforceable governmental request.
  • Security: To investigate or address security incidents, fraud, or violations of our Terms of Service.
  • Aggregated data: We may share anonymized, aggregated protocol statistics (e.g., total value locked, number of transactions) publicly. This data cannot be used to identify individual users.

6.2 What We Do Not Share

  • We do not share wallet addresses with third parties for their own purposes.
  • We do not share technical data with advertisers.
  • We do not share data with data brokers.

7. Data Retention

7.1 On-Chain Data

On-chain data is permanent and immutable. It exists on the blockchain independently of Haetae Finance and cannot be deleted by us or anyone else.

7.2 Technical Data

  • Server logs (including IP addresses): Retained for a maximum of 90 days, then deleted or anonymized.
  • Analytics data: Retained in aggregated, anonymized form. Individual-level analytics data is retained for no more than 14 months.
  • Wallet connection state and preferences: Stored locally in your browser (localStorage/cookies) and under your control. We do not retain this data on our servers.

7.3 Deletion Requests

Because we do not maintain user accounts or link data to identities, there is generally no personal data on our servers to delete. If you believe we hold data about you that you would like deleted, please contact us (see Section 13), and we will make reasonable efforts to address your request.

8. International Data Transfers

Haetae Finance is a Georgia-registered entity. The Service is accessible globally, and technical data may be processed in jurisdictions outside your country of residence. By using the Service, you acknowledge that your technical data may be transferred to and processed in countries that may not provide the same level of data protection as your home country.

Where required by applicable law (e.g., transfers from the EEA), we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions.

9. Security Measures

We implement reasonable technical and organizational measures to protect the data we collect, including:

  • Encryption: Data in transit is encrypted using TLS/HTTPS.
  • Access controls: Access to server infrastructure and any data stores is restricted to authorized personnel on a need-to-know basis.
  • Monitoring: We monitor our systems for unauthorized access and security anomalies.
  • Minimization: We collect and retain only the minimum data necessary to operate the Service.
  • Smart contract security: Our vault smart contracts are based on Beefy Finance's audited architecture.

However, no system is completely secure. We cannot guarantee the absolute security of your data. Because the Service is non-custodial, the security of your crypto assets depends primarily on how you secure your own wallet and private keys.

10. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect data from children under 18. Because the Service does not require registration or age verification, we rely on users to comply with the age requirement stated in our Terms of Service.

If you believe a child under 18 has interacted with the Service, please contact us, and we will take appropriate steps to the extent any data is identifiable.

11. Your Rights

Regardless of your jurisdiction, we believe in giving users control over their data. To the extent applicable under your local laws, you may have the following rights:

11.1 Access

You may request information about what data, if any, we hold about you.

11.2 Correction

You may request correction of inaccurate data.

11.3 Deletion

You may request deletion of your data from our systems. Note that on-chain data cannot be deleted.

11.4 Restriction

You may request that we restrict processing of your data.

11.5 Portability

You may request a copy of your data in a portable format.

11.6 Objection

You may object to our processing of your data based on legitimate interest.

11.7 Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time.

To exercise any of these rights, please contact us using the information in Section 13. We will respond within 30 days (or the time period required by applicable law). Because we collect minimal data and do not maintain user accounts, we may need you to provide your wallet address to identify any data associated with your use of the Service.

11.8 GDPR (European Economic Area)

If you are located in the EEA, you have the rights described above under the General Data Protection Regulation. You also have the right to lodge a complaint with your local data protection authority.

11.9 Other Jurisdictions

Users in other jurisdictions may have additional rights under their local laws (e.g., CCPA for California residents, LGPD for Brazilian residents, PIPA for South Korean residents). We will comply with applicable data protection laws to the extent they apply to our processing activities.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the “Last Updated” date at the top of this document.
  • We will, where feasible, provide a notice through the Service interface.

Your continued use of the Service after any modification constitutes your acknowledgment of the updated Privacy Policy.

13. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can reach us through:

We will make reasonable efforts to respond to inquiries within 30 days.

This document is a reference draft. Review by a qualified legal professional is recommended before actual application.