Legal · Document 1 of 5

PrivacyPolicy.

How CryptoMize, the operator of the Sovereignty Infinium Intelligence Platform, collects, uses, discloses, and protects personal information.

Effective: 2026-06-13Version 1.013 sections · 5 contact channels

Template — Not Legal Advice

This is a template legal document. The Sovereignty Infinium platform is operated by CryptoMize. The final version of this document, including any jurisdiction-specific adaptations, is provided in your engagement documentation. Use of the website is governed by your engagement terms.

Table of Contents

  1. 1.Introduction and Scope
  2. 2.Data Controller and Contact Information
  3. 3.Information We Collect
  4. 4.How We Use Information
  5. 5.Lawful Bases for Processing
  6. 6.Data Sharing and Disclosure
  7. 7.International Data Transfers
  8. 8.Data Retention
  9. 9.Your Rights
  10. 10.Security Measures
  11. 11.Children's Privacy
  12. 12.Changes to This Policy
  13. 13.Contact Information
01

Introduction and Scope

This Privacy Policy describes how CryptoMize ("CryptoMize", "we", "us", or "our"), the operator of the Sovereignty Infinium Intelligence Platform (also referred to as Sovereignty Infinium or XS1) accessible at sovereignty.co.in (the "Platform"), collects, uses, discloses, and protects personal information in connection with:

  • The public-facing marketing website at sovereignty.co.in
  • The Sovereignty Infinium platform, products, and services (the "Services")
  • Sales, marketing, and customer-support interactions
  • Any other interaction you have with us that links to this Policy

This Policy applies to information collected through any means, including online, offline, by email, through APIs, or through any other channel. It does not apply to information collected by third parties, including any third-party websites, applications, or services that you may access through links on the Platform.

02

Data Controller and Contact Information

For the purposes of applicable data-protection laws (including, where relevant, the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and analogous frameworks), the data controller for personal information collected through the Platform is CryptoMize, with its registered office identified in your engagement documentation.

We have appointed a Data Protection Officer (DPO) who can be contacted at:

Data Protection Officer

privacy@sovereignty.co.in

For any privacy-related request, including the rights described in Section 9, please contact our DPO using the channels above.

03

Information We Collect

We collect personal information from and about you in the following categories:

3.1 Information You Provide Voluntarily

  • Account and Contact Information: name, email address, phone number, organization, role/title, country, and similar identifiers when you register, request a demo, sign in, or otherwise interact with us.
  • Engagement Information: information necessary to evaluate, contract, deliver, and support the Services, including billing information, technical requirements, and stakeholder contacts.
  • Communications: information you provide when you contact us, including the content of emails, support tickets, feedback, and survey responses.
  • User Content: files, documents, datasets, prompts, queries, configurations, and other content you submit, upload, or transmit through the Services ("User Content").

3.2 Information Collected Automatically

  • Device and Technical Information: IP address, browser type and version, operating system, device identifiers, language settings, screen resolution, and referring URLs.
  • Usage Information: pages viewed, features used, time spent, click patterns, navigation paths, and timestamps.
  • Security and Diagnostics: event logs, error reports, and security telemetry required to operate, secure, and improve the Platform.
  • Cookies and Similar Technologies: please see our Cookie Policy for details.

3.3 Information from Third Parties

  • Identity-verification, fraud-prevention, and credit-check providers (where contractually required).
  • Publicly available sources, including professional networking platforms and corporate registries.
  • Partners, resellers, and integration partners who help us deliver the Services.
04

How We Use Information

We use the information we collect for the following purposes:

  • To Provide and Operate the Services: authenticate users, configure and deliver the Services, process transactions, and provide customer support.
  • To Improve and Develop: understand how users interact with the Platform; develop new features, products, and services; and conduct research and analytics.
  • To Communicate: respond to inquiries, send administrative notices, deliver product updates, and (where permitted) send marketing communications.
  • To Secure: detect, prevent, and address fraud, abuse, security incidents, and other harmful activity; verify identity; and enforce our terms.
  • To Comply: comply with legal obligations, regulatory requirements, and lawful governmental requests.
  • To Protect Rights: establish, exercise, or defend legal claims.
  • Aggregated and De-Identified Use: create aggregated, statistical, or de-identified data that we may use and disclose for any lawful purpose.
05

Lawful Bases for Processing

Where applicable data-protection law requires a lawful basis, we rely on one or more of the following:

Purpose
Lawful Basis
Provide the Services and respond to your requests
Performance of a contract; steps taken at your request prior to entering a contract
Communicate with you about the Services and your account
Performance of a contract; legitimate interests
Send marketing communications (where permitted)
Consent (which you may withdraw at any time)
Improve the Platform, develop new features, and analytics
Legitimate interests (where applicable law permits); consent for non-essential cookies
Secure the Platform, prevent fraud, and enforce terms
Legitimate interests; legal obligation
Comply with legal, tax, accounting, and regulatory obligations
Legal obligation
Establish, exercise, or defend legal claims
Legitimate interests; legal obligation

If you have questions about the legal basis on which we process your personal information, contact our DPO at privacy@sovereignty.co.in.

06

Data Sharing and Disclosure

We do not sell personal information. We disclose personal information only as follows:

  • Service Providers and Sub-Processors: with vendors, consultants, and other service providers that perform services on our behalf (such as cloud hosting, data storage, security, customer support, billing, and analytics), bound by confidentiality and data-protection obligations.
  • Affiliates and Subsidiaries: with entities within the CryptoMize corporate group for the purposes described in this Policy.
  • Business Transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business.
  • Legal and Safety: when we believe in good faith that disclosure is necessary to comply with applicable law, a valid subpoena, court order, or governmental request, or to protect the rights, property, or safety of CryptoMize, our users, or others.
  • With Your Consent: otherwise with your consent or at your direction.
07

International Data Transfers

CryptoMize operates globally. Your information may be transferred to, stored, and processed in a country other than your country of residence. Where required by applicable law, we implement appropriate safeguards for international transfers, which may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission or other relevant authorities
  • Adequacy decisions recognized by the relevant authority
  • Binding Corporate Rules, where applicable
  • Supplementary technical, organizational, and contractual measures (such as encryption in transit and at rest with AES-256-GCM, and access controls)
08

Data Retention

We retain personal information for as long as reasonably necessary to:

  • Provide the Services and maintain your account
  • Comply with our legal, tax, accounting, and reporting obligations
  • Resolve disputes and enforce our agreements
  • Meet other legitimate operational, security, and business needs

When personal information is no longer needed, we will securely delete, anonymize, or aggregate it in accordance with our retention schedules.

09

Your Rights

Subject to applicable law, you may have some or all of the following rights:

  • Right of Access: request a copy of the personal information we hold about you.
  • Right of Rectification: correct inaccurate or incomplete personal information.
  • Right of Erasure (Right to be Forgotten): request deletion of your personal information in certain circumstances.
  • Right to Restriction of Processing: request that we limit how we process your personal information.
  • Right to Data Portability: receive your personal information in a structured, machine-readable format.
  • Right to Object: object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent: withdraw consent at any time, where processing is based on consent.
  • Right to Opt Out of Sale or Sharing (where applicable, e.g., CCPA/CPRA).
  • Right Not to Be Subject to Automated Decision-Making with legal or similarly significant effects.
  • Right to Lodge a Complaint with a supervisory authority in your jurisdiction.

To exercise any of these rights, contact privacy@sovereignty.co.in. We may need to verify your identity before fulfilling the request.

10

Security Measures

We implement technical and organizational measures designed to protect personal information, including:

  • Encryption in Transit: TLS 1.3 and mutual TLS (mTLS).
  • Encryption at Rest: AES-256-GCM (or equivalent).
  • Access Controls: role-based access control, least-privilege, and MFA for administrative access.
  • Network Security: segmented networks, WAFs, and intrusion detection / prevention systems.
  • Logging and Monitoring: centralized logging, anomaly detection, and continuous security monitoring.
  • Vulnerability Management: regular scanning, patch management, and periodic third-party penetration testing.
  • Cryptographic Standards: FIPS 140-3 validated cryptographic modules where operationally feasible.
  • Organizational Measures: information security policies, confidentiality obligations, security awareness training, and an incident response program.
  • Compliance Certifications: we maintain alignment with ISO 27001, SOC 2 Type II, and applicable industry standards.

No system is perfectly secure. We cannot guarantee absolute security.

11

Children's Privacy

The Platform and Services are not directed to children under the age of 16 (or such other age as may be required by applicable law). We do not knowingly collect personal information from children. If you believe that we have collected personal information from a child in violation of this Policy, please contact us at privacy@sovereignty.co.in and we will take appropriate steps to delete the information.

12

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you through the Platform or by other means.

13

Contact Information

For any questions, comments, or requests regarding this Policy or our privacy practices, please contact:

Data Protection Officer

privacy@sovereignty.co.in

Mailing Address: As identified in your engagement documentation.

Sovereignty Infinium is built for sovereign clients · All engagements operate under mutual non-disclosure · Some capabilities subject to national export controls

SOC 2 Type IIISO 27001GDPRFedRAMPFIPS 140-3Common Criteria EAL5+