Privacy Policy & Global Data Processing Addendum
PRIVACY POLICY AND DATA PROCESSING ADDENDUM (DPA)
Operating Entity: Caldarus Labs (a Sole Proprietorship)
Business Address: 1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, United States
Document Version: 1.0 (Production Release)
Effective Date: July 29, 2026
Data Protection Officer Contact: support@caldaruslabs.app / support@caldaruslabs.app
EXECUTIVE PREAMBLE
This document constitutes the formal, binding global Privacy Policy and Data Processing Addendum (DPA) governing all personal data processing operations executed by Caldarus Labs ("Grail Hunterz", "Company", "we", "us", or "our").
Caldarus Labs operates a digital mystery pack-opening platform ("Grail Hunterz") accessible via mobile application software (including iOS native applications), web applications, application programming interfaces (APIs), and physical vaulting and fulfillment operations. The platform sells real, inventory-backed physical trading cards (including Professional Sports Authenticator [PSA]-graded slabs and raw collectible cards) featuring provably-fair cryptographic draw mechanics, instant buyback valuation options, vaulted physical custody, and physical delivery redemption services.
Because the operation of the platform necessitates the collection, transmission, processing, verification, and storage of personally identifiable information (PII), sensitive financial transaction details, biometric liveness telemetry, precise geolocation data, and device identifiers across multiple state, national, and international jurisdictions, this instrument establishes a comprehensive legal framework compliant with:
- United States Federal Mandates: Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506), the Bank Secrecy Act / USA PATRIOT Act (31 U.S.C. § 5311 et seq. / 31 CFR § 1022.320), the Gramm-Leach-Bliley Act (GLBA, 15 U.S.C. § 6801 et seq.), and Internal Revenue Code Sections 6050W and 6045 (26 U.S.C. §§ 6050W, 6045).
- United States Comprehensive State Privacy Statutes: The California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA, Cal. Civ. Code § 1798.100 et seq.), the Virginia Consumer Data Protection Act (VCDPA, Va. Code Ann. § 59.1-575 et seq.), the Colorado Privacy Act (CPA, C.R.S. § 6-1-1301 et seq.), the Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. § 42-515 et seq.), the Utah Consumer Privacy Act (UCPA, Utah Code Ann. § 13-61-101 et seq.), and the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14/1 et seq.).
- European Union & United Kingdom Data Protection Laws: Regulation (EU) 2016/679 (EU General Data Protection Regulation - "EU GDPR"), the United Kingdom General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), and the European Directive 2002/58/EC on Privacy and Electronic Communications ("ePrivacy Directive").
PART I: GLOBAL PRIVACY POLICY
SMS / TEXT MESSAGING PROGRAM AND MOBILE INFORMATION
Grail Hunterz sends transactional text messages only: (1) one-time passcodes that verify
your phone number at signup and sign-in, and (2) account notices about card shipments and
payouts you requested. Message frequency varies. Message and data rates may apply. Reply
STOP to cancel and HELP for help at any time, or email support@caldaruslabs.app.
Consent to receive text messages is not a condition of any purchase. Full program
disclosures: caldaruslabs.app/sms.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, excluding the aggregators and providers of the text-message services strictly as necessary to deliver the messages. All other categories in this Policy exclude text-messaging originator opt-in data and consent; that information will not be shared with, or sold to, any third parties.
SECTION 1: IDENTITY, SCOPE, AND MULTI-JURISDICTIONAL LEGAL FRAMEWORK
1.1 Identity & Administrative Contact Details
This Privacy Policy is issued by Caldarus Labs, a sole proprietorship based in the Commonwealth of Virginia, United States of America. It is not incorporated.
- Business Address: 1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, USA
- Contact:
support@caldaruslabs.app - Privacy Contact: Caldarus Labs, 1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, USA. Caldarus Labs is a sole proprietorship and has not designated a statutory Data Protection Officer.
- EU/UK Statutory Representative (GDPR Art. 27): None appointed. Caldarus Labs has no subsidiaries, branches or affiliates in any jurisdiction.
1.2 Operational & Technical Scope
This Policy applies to all end users, registered account holders, visitors, and commercial partners ("Users", "Data Subjects", "you", or "your") who access, install, interact with, or utilize any component of the Grail Hunterz ecosystem, including:
- iOS Native Application: The Grail Hunterz mobile application software distributed via the Apple App Store under Category 3.1.3(e) (Physical Goods).
- Web Applications & Verification Portals: Static and dynamic client-side web verification portals, including
apps/web-verifyandhttps://app.caldaruslabs.app. - API Infrastructure & Microservices: Fastify REST endpoints, AWS AppSync GraphQL services, microservices (
services/api), and associated websocket streams. - Physical Vaulting & Logistics: Physical intake, storage, inspection, and fulfillment performed by Caldarus Labs, with delivery by a licensed common carrier. No third-party custodian or shipping integrator is engaged at this time.
- Financial & Buyback Engine: The proprietary Fair Market Value (FMV) pricing engine, closed-loop double-entry accounting ledger (
packages/domain), and third-party bank payout rails.
1.3 Multi-Jurisdictional Statutory Compliance Framework
A. United States Federal Statutory Compliance
- FTC Act Section 5 Compliance: Caldarus Labs maintains absolute truthfulness in advertising, card rarity probability disclosures, provably-fair cryptographic draw mechanics, and security representations.
- COPPA Strict Disqualification: The platform is engineered exclusively for individuals aged eighteen (18) years or older. We do not knowingly solicit, collect, or process personal data from any person under the age of eighteen (18).
- Bank Secrecy Act (BSA) & Anti-Money Laundering (AML) Compliance: Under 31 CFR § 1022.320 and federal financial regulations, Caldarus Labs is mandated to collect, verify, and retain identity, government identification documents, and transaction logs for users executing cash payouts or high-value physical card redemptions.
- Internal Revenue Code Tax Reporting: Pursuant to 26 U.S.C. §§ 6050W and 6045, we collect Social Security Numbers (SSN) or Individual Taxpayer Identification Numbers (ITIN) to issue IRS Form 1099-K for users whose cumulative annual payouts exceed statutory reporting thresholds ($20,000 gross payments and over 200 transactions, or applicable lower state tax reporting thresholds).
B. United States State Privacy Frameworks
This Policy implements granular disclosures and rights operationalized under CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and BIPA (Illinois, 740 ILCS 14/1 et seq.). For California residents, this document serves as both a Notice at Collection and a comprehensive Privacy Policy under Cal. Civ. Code § 1798.100.
C. European Union & United Kingdom Frameworks
For individuals residing in the European Economic Area (EEA) or the United Kingdom, processing is conducted in strict compliance with EU GDPR and UK GDPR. Caldarus Labs acts as a Data Controller with respect to user account information and platform operations, and as a Data Processor where contractually stipulated.
1.4 Geographic Exclusions & Geofencing Disclaimers
Caldarus Labs enforces strict automated geofencing controls. Platform access, pack opening, and cash withdrawals are strictly prohibited and technically blocked in the following jurisdictions:
- Excluded U.S. States: The State of Washington (RCW 9.46.0237) and the State of Nevada (NRS 463.0153).
- U.S. Territories: Puerto Rico, Guam, the U.S. Virgin Islands, American Samoa, and the Northern Mariana Islands.
- OFAC Sanctioned Jurisdictions: Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine, and any individual or entity listed on the U.S. Department of the Treasury Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) List.
SECTION 2: CATEGORICAL DATA INGESTION & CLASSIFICATION PIPELINE
Caldarus Labs collects and processes personal data across five technical ingestion layers:
+-----------------------------------------------------------------------------------+
| GRAIL HUNTERZ DATA INGESTION PIPELINE |
+-----------------------------------------------------------------------------------+
| 1. Category A: KYC / Identity | Name, DOB (18+), Address, SSN/ITIN, Photo ID, Selfie|
| 2. Category B: Financial & Ledger| Card Token, Routing/Account #, PayPal, Ledger Logs|
| 3. Category C: Telemetry & Device| IP, GPS, App Attest, DeviceCheck, Fingerprint, IDFA|
| 4. Category D: Provably-Fair Log | Client/Server Seeds, Hashes, Nonces, Rips, FMV Comps|
| 5. Category E: Blockchain Data | Public Wallet Address, Smart Contract Tx Hashes |
+-----------------------------------------------------------------------------------+
2.1 Category A: Personally Identifiable Information (PII), Identity & KYC/AML Data
- Full Legal Name: First name, middle name(s), and last name.
- Date of Birth (DOB): Day, month, and year of birth, utilized for statutory 18+ age verification.
- Taxpayer Identification Number: Social Security Number (SSN) or Individual Taxpayer Identification Number (ITIN), encrypted at rest and collected upon reaching statutory tax thresholds.
- Government Identity Artifacts: High-resolution digital photographic images of state-issued Driver's Licenses, State Identification Cards, or Passports, ingested via specialized our identity verification processor (Footprint).
- Biometric Facial Geometry & Liveness Telemetry: Digital facial scanning geometry and liveness verification video frames captured during identity verification to compare against government photo identification.
- Physical Residential Address: Street line 1, street line 2, city, state/province, postal zip code, and country (required for physical card shipping, tax calculation, and Address Verification System [AVS] card processing).
- Contact Telemetry: Verified primary email address and verified mobile phone number (used for SMS Multi-Factor Authentication [MFA] and account recovery).
2.2 Category B: Financial Data, Payment Credentials & Double-Entry Ledger Logs
- Payment Card Tokens: Primary Account Numbers (PAN), expiration dates, and card verification codes (CVV/CVC) are tokenized directly at the client device level by a PCI-DSS Level 1 payment acquirer. Raw payment card numbers are never received, stored, or processed on Grail Hunterz servers.
- Banking & Payout Destination Credentials: Bank routing numbers, checking/savings account numbers, account holder legal names, collected via an ACH payout processor.
- Alternative Disbursement Identifiers: Verified PayPal email addresses and Venmo user handles.
- Double-Entry Ledger Logs (
ledger_entriestable): Immutable append-only record of account balances, deposit credits (user_pack_credit), withdrawal proceeds (user_proceeds), promotional allocations (user_bonus), item buyback transfers, and platform fee deductions. - Fair Market Value (FMV) Quotes (
buyback_quotestable): Historical records of card valuation quotes generated by the pricing engine, quote timestamps, buyback percentage applications (90%–95% FMV), and execution timestamps.
2.3 Category C: Device Telemetry, Geolocation & Anti-Fraud Security Signals
- Network Identifiers: IPv4 and IPv6 addresses, Internet Service Provider (ISP) metadata, Autonomous System Number (ASN), and proxy/VPN detection headers.
- Precise Geolocation Data: High-accuracy Global Positioning System (GPS) coordinates (latitude, longitude, horizontal accuracy) collected via native iOS location APIs during registration, pack opening, and withdrawal requests to enforce state geofencing.
- Hardware & OS Security Attestations: Apple App Attest cryptographic assertion payloads and Apple DeviceCheck hardware risk scores.
- Hardware Device Fingerprints: Device hardware hashes, screen resolution, operating system build version, GPU vendor identifiers, and persistent fraud scores generated on-device.
- Application Telemetry & Analytics: Touch interaction events, screen navigation paths, API call latency, crash stack traces, performance monitoring logs, and usage event metrics.
2.4 Category D: Provably-Fair RNG Audit Data & Draw Telemetry
- Cryptographic Seeds: Client-side random seed strings (
client_seed), unrevealed server seed SHA-256 hashes (server_seed_hash), and revealed historical server seeds (server_seed_plain). - HMAC-SHA256 Derivation Logs: Sequential draw nonces (
nonce), HMAC-SHA256 digests, derived floating-point probabilities, mapped card manifest value bands, and allocated card inventory serial IDs (cards.id). - Pack Manifest Snapshots (
pack_manifeststable): Immutable SHA-256 digests of published card pools, rarity distributions, and card valuation floors snapshotted at time of pack purchase.
2.5 Category E: Blockchain & Public Ledger Identifiers
- Public Cryptographic Wallet Addresses: Non-custodial Ethereum, Polygon, or Solana public key addresses.
- On-Chain Transaction Hashes: Public transaction hashes, smart contract execution logs, and ERC-721 / ERC-1155 token minting/transfer records.
SECTION 3: STATUTORY PURPOSES OF PROCESSING & LEGAL BASES MATRIX
The following processing matrices establish the explicit purposes of processing, legal bases under GDPR Articles 6 and 9, business purposes under CCPA/CPRA (Cal. Civ. Code § 1798.140(e)), and mandatory retention periods.
Table 3.1: Identity, KYC/AML & Account Management Data
| Category of Personal Data | Specific Data Elements | Primary Processing Purpose | GDPR Legal Basis (Art. 6 / Art. 9) | CPRA Business Purpose | Statutory Retention Period & Deletion Trigger |
|---|---|---|---|---|---|
| Account Identity | Email address, phone number, password hash | Account creation, authentication, multi-factor authentication (SMS OTP), account security communications. | Art. 6(1)(b) (Contract Performance) | Performing services on behalf of business (Cal. Civ. Code § 1798.140(e)(2)) | Active account lifetime + 2 years post-closure request. |
| Age Verification | Date of Birth (DOB) | Enforcement of 18+ age restriction; COPPA compliance; prevention of minor account creation. | Art. 6(1)(c) (Legal Obligation) | Auditing & compliance with age mandates | Retained for account lifetime; purged 30 days post-closure. |
| KYC / AML Identity | Full legal name, residential address, government photo ID | Identity verification prior to cash withdrawal or physical delivery; anti-money laundering compliance. | Art. 6(1)(c) (Legal Obligation - Bank Secrecy Act / 31 CFR § 1022.320) | Security, integrity & statutory compliance | 5 years post-account closure pursuant to 31 CFR § 1022.320. Mandatory statutory retention exception to erasure. |
| Biometric Telemetry | Facial scan geometry & liveness video stream | Automated 1:1 facial comparison against photo ID to prevent identity fraud and account takeover. | Art. 9(2)(a) (Explicit Consent) & Art. 6(1)(f) (Legitimate Interest - Fraud Prevention) | Verification of customer identity | Raw biometric streams purged by the verification provider within 30 days of check completion; pass/fail metadata retained 5 years. |
| Tax Information | Social Security Number (SSN) / ITIN | Mandatory IRS Form 1099-K tax reporting for cumulative annual payouts exceeding statutory thresholds. | Art. 6(1)(c) (Legal Obligation - 26 U.S.C. §§ 6050W, 6045) | Compliance with federal/state tax law | 7 years following the applicable tax reporting year (26 CFR § 31.6001-1). Statutory exception to erasure. |
Table 3.2: Financial, Payment & Double-Entry Ledger Data
| Category of Personal Data | Specific Data Elements | Primary Processing Purpose | GDPR Legal Basis (Art. 6) | CPRA Business Purpose | Statutory Retention Period & Deletion Trigger |
|---|---|---|---|---|---|
| Payment Credentials | Tokenized credit/debit card tokens, billing address, Apple Pay tokens | Ingestion of pack purchases; processing payment transactions via PCI-DSS Level 1 acquirers. | Art. 6(1)(b) (Contract Performance) | Processing payment transactions | Tokens stored by the payment acquirer per PCI rules; retained during payment method activity + 7 years for audit logs. |
| Payout Destination | Bank routing/account number, account holder name, PayPal email, Venmo handle | Executing cash disbursements of user proceeds from item buybacks. | Art. 6(1)(b) (Contract Performance) | Account servicing & funds disbursement | 7 years post-transaction pursuant to financial auditing standards. |
| Double-Entry Ledger Logs | ledger_entries table: transaction IDs, balances, account codes, timestamps | Maintaining closed-loop accounting invariants, zero-sum financial balance integrity, and auditability. | Art. 6(1)(c) (Legal Obligation) & Art. 6(1)(f) (Legitimate Interest) | Business recordkeeping & financial auditability | Permanent / Indefinite append-only database logs. Enforced by PostgreSQL database WORM triggers; statutory exemption from deletion. |
| Valuation Quotes | buyback_quotes table: FMV calculations, buyback percentage (90-95%), timestamps | Executing card repurchases, verifying quote validity, resolving valuation disputes. | Art. 6(1)(b) (Contract Performance) | Operational execution & dispute resolution | 7 years post-transaction. |
Table 3.3: Telemetry, Geolocation & Security Data
| Category of Personal Data | Specific Data Elements | Primary Processing Purpose | GDPR Legal Basis (Art. 6) | CPRA Business Purpose | Statutory Retention Period & Deletion Trigger |
|---|---|---|---|---|---|
| Geofencing Data | IP address, precise GPS coordinates (latitude/longitude) | Verifying user physical presence outside excluded jurisdictions (WA, NV, OFAC regions); state law compliance. | Art. 6(1)(c) (Legal Obligation) & Art. 6(1)(f) (Legitimate Interest) | Security, integrity & compliance enforcement | Real-time verification; location logs retained 2 years for regulatory audit purposes. |
| Hardware Risk Signals | Apple App Attest tokens, DeviceCheck scores | Preventing multi-account referral abuse, automated bot attacks, and pack draw manipulation. | Art. 6(1)(f) (Legitimate Interest - System Security) | Security, integrity & fraud detection | 2 years from collection date. |
| Provably-Fair Logs | Client seed, server seed hash, revealed server seed, HMAC digest | Guaranteeing public verification and mathematical transparency of card draw outcomes. | Art. 6(1)(f) (Legitimate Interest - Transparency) | Product integrity & compliance verification | Permanent / Indefinite append-only database logs to maintain public audit verification chains. |
| App Telemetry & Logs | Crash reports, stack traces, latency, screen interaction paths | Technical error debugging, latency reduction, user experience optimization. | Art. 6(1)(f) (Legitimate Interest) | Quality assurance & system optimization | 90 days (raw crash logs); aggregated telemetry retained 13 months. |
SECTION 4: USER PRIVACY RIGHTS & DATA SUBJECT ACCESS REQUEST (DSAR) PROTOCOLS
Caldarus Labs guarantees data subjects across all supported jurisdictions the right to exercise statutory privacy controls.
4.1 Enumeration of Statutory Rights
- Right to Know / Right of Access: You have the right to request a copy of the specific pieces of personal data collected about you, the categories of sources, the commercial processing purposes, and third parties receiving your data.
- Right to Erasure / Right to be Forgotten: You have the right to request the deletion of your personal data held by Caldarus Labs, subject to explicit statutory retention exemptions outlined in Section 4.2.
- Right to Rectification / Correction: You have the right to correct inaccurate or incomplete personal data. Account details may be modified within the application; verified identity records require step-up re-verification via our identity verification provider.
- Right to Opt-Out of Sale, Sharing & Targeted Advertising: Caldarus Labs does not sell user personal data for monetary consideration. To the extent that third-party analytics constitute "sharing" or "targeted advertising" under CCPA/CPRA or VCDPA, you may exercise your opt-out right at any time.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to Limit Use of Sensitive Personal Information (SPI): Under CPRA (Cal. Civ. Code § 1798.121), you have the right to direct Caldarus Labs to limit the use of Sensitive Personal Information (SSN, biometric liveness telemetry, precise GPS coordinates) strictly to operational necessity.
- Right to Non-Discrimination: Caldarus Labs shall not discriminate against any user (e.g., by denying services, altering pricing, or degrading service quality) for exercising any statutory privacy right.
4.2 Statutory Exceptions to Data Erasure Requests
Pursuant to CCPA/CPRA (Cal. Civ. Code § 1798.105(d)), GDPR Article 17(3), and applicable federal law, Caldarus Labs is legally required to deny deletion requests for specific data elements under the following statutory exemptions:
- Anti-Money Laundering Exemption (31 CFR § 1022.320): Government identity artifacts, KYC verification logs, and associated identity details must be retained for five (5) years post-account closure and cannot be deleted upon user request.
- Tax Compliance Exemption (26 U.S.C. § 6001): Tax reporting records, SSN/ITIN details, and 1099-K issuance logs must be retained for seven (7) years following the tax reporting year.
- Financial Ledger Invariant Exemption: Double-entry accounting records (
ledger_entries) are append-only PostgreSQL tables protected by database triggers to preserve auditability and zero-sum balance balance invariants. - Provably-Fair Public Chain Exemption: Cryptographic RNG seeds, HMAC digests, and draw logs (
ripstable) must remain permanently preserved to guarantee the mathematical integrity of historical public verifications under platform fairness rules.
4.3 Opt-Out Protocols for Data Sale, Sharing & Targeted Advertising (Including GPC Signal Compliance)
Users may opt out of data sharing and targeted advertising through the following operational protocols:
- In-App & Web Controls: Navigating to
Settings -> Privacy Centerand toggling off "Analytics & Targeted Data Sharing", or clicking the "Do Not Sell or Share My Personal Information" link located in the web footer athttps://app.caldaruslabs.app. - Global Privacy Control (GPC) Universal Opt-Out: Caldarus Labs systems automatically detect and honor the Global Privacy Control (GPC) signal transmitted via user web browsers (
Sec-GPC: 1). Upon detection of a valid GPC header, platform systems automatically apply opt-out settings for that browser session.
4.4 DSAR Submission, Step-Up Verification & Response Timelines
+-----------------------------------------------------------------------------------+
| DATA SUBJECT RIGHTS REQUEST (DSAR) FLOW |
+-----------------------------------------------------------------------------------+
| User Submits Request -> Step-Up Verification (MFA/IDV) -> Statutory Exception Review|
| | |
| +-----------------------+--------------------+ |
| v v |
| [Data Erasure / Export] [Statutory Retention] |
| Telemetry & Analytics KYC Records (5 Yrs) |
| Session Logs Ledger Entries (WORM) |
| Marketing Data Tax 1099-K (7 Yrs) |
+-----------------------------------------------------------------------------------+
- Submission Channels: Submit DSARs via the in-app Privacy Center, by emailing
support@caldaruslabs.app, or via the web form athttps://app.caldaruslabs.app/privacy/dsar. - Identity Verification Standard:
- Standard Information Requests: Verified via account login authentication and SMS/email OTP confirmation.
- Sensitive Information Access, Erasure, or Portability Requests: Step-up authentication requiring re-verification of government photo identification through our identity verification provider to prevent malicious unauthorized disclosure.
- Statutory Response Timelines:
- CCPA / CPRA / VCDPA / CPA / CTDPA / UCPA: Confirmation of receipt within 10 business days; full substantive response within 45 calendar days (extendable by an additional 45 days upon written notice for complex requests).
- EU GDPR / UK GDPR: Full response provided within 30 calendar days (extendable by up to 60 days for complex multi-system requests).
4.5 Statutory Appeal Protocols for State Residents (Virginia, Colorado, Connecticut)
If Caldarus Labs denies a user's DSAR in whole or in part, Virginia, Colorado, and Connecticut residents have the right to appeal the decision within thirty (30) days of receiving the denial notice by emailing support@caldaruslabs.app. The appeal will be reviewed by the Data Protection Officer. Within forty-five (45) days of receipt of the appeal, Caldarus Labs will provide a written explanation of the decision. If the appeal is denied, we will provide the statutory contact information for the state Attorney General (e.g., Virginia Office of the Attorney General, Colorado Department of Law, Connecticut Office of the Attorney General).
SECTION 5: THIRD-PARTY DATA DISCLOSURES & SERVICE PROVIDER RESTRICTIONS
5.1 Operational Necessity Disclosures
Caldarus Labs discloses personal data to authorized third-party vendors and sub-processors strictly to perform operational functions, process payments, verify identities, prevent fraud, execute logistics, and maintain technical infrastructure.
5.2 Master Sub-Processor Schedule
Table 5.1: Master Sub-Processor Schedule
| Sub-Processor Name | Service Category | Geographic Location | Data Processing Description | Transfer Mechanism & Safeguards |
|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud Infrastructure & Security | United States (us-east-1, N. Virginia) | Application API hosting (AWS Lambda, AWS AppSync), database (Amazon Aurora PostgreSQL), object storage (Amazon S3), account identity (Amazon Cognito), key management (AWS KMS), and delivery of one-time passcode text messages. | AWS Data Processing Addendum; EU SCCs incorporated by reference; encryption in transit and at rest under customer-managed keys. |
| Apple Inc. | App Distribution & Device Security | United States | Distribution of the iOS application through the App Store; Apple App Attest and DeviceCheck device integrity signals. | Apple Developer Program License Agreement; Apple Privacy Policy. |
| Footprint Tech, Inc. | Identity Verification (sandbox only) | United States | Identity verification. Currently connected in sandbox mode only and not processing live customer personal data. | Footprint agreement; engaged for testing only. Will not process production personal data until listed here as live. |
This schedule lists every sub-processor engaged today, and nothing else. Caldarus Labs has not engaged a payment processor, payout provider, watchlist-screening vendor, analytics provider, error-tracking provider, device-intelligence vendor, shipping carrier integration, or third-party vaulting custodian. Any such provider will be added to this table, with its transfer mechanism, before it processes any personal data. Material additions are notified under Section 5.4.
5.3 Contractual Restrictions under CPRA § 1798.140(ag) and GDPR Article 28
Pursuant to CPRA Service Provider mandates (Cal. Civ. Code § 1798.140(ag)) and GDPR Article 28, all sub-processors engaged by Caldarus Labs are bound by written Data Processing Agreements that strictly prohibit them from:
- Selling or sharing personal data.
- Retaining, using, or disclosing personal data for any purpose other than the specific business purpose specified in the agreement.
- Retaining, using, or disclosing personal data outside the direct business relationship between Caldarus Labs and the service provider.
- Combining personal data received from Caldarus Labs with personal data received from or on behalf of another third party.
SECTION 6: SECURITY ARCHITECTURE & TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)
Caldarus Labs implements continuous technical security controls to safeguard data integrity and confidentiality.
+-----------------------------------------------------------------------------------+
| TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES (TOMs) |
+-----------------------------------------------------------------------------------+
| 1. Encryption in Transit | TLS 1.3 mandatory across all APIs and microservices |
| 2. Encryption at Rest | AWS KMS AES-256 (Aurora PostgreSQL, S3) |
| 3. PII Minimization | IDs & SSNs held by the IDV provider, never by us |
| 4. Access Control | Zero-Trust RBAC, Least Privilege IAM, Hardware MFA |
| 5. Database Invariants | PostgreSQL WORM trigger enforcing append-only ledger |
| 6. Audit & Detection | AWS GuardDuty threat detection; hash-chained audits |
+-----------------------------------------------------------------------------------+
6.1 Cryptographic Controls & Transit/Rest Encryption Standards
- Encryption in Transit: All network communication across public networks, iOS client apps, web portals, and microservices is strictly encrypted using Transport Layer Security (TLS 1.3). Cipher suites are restricted to high-strength AEAD algorithms (e.g.,
ECDHE-RSA-AES128-GCM-SHA256,ECDHE-RSA-AES256-GCM-SHA384). Legacy protocols (TLS 1.0, TLS 1.1) and unencrypted HTTP endpoints are permanently disabled. SSL Certificate Pinning is enforced within the native iOS application. - Encryption at Rest: All underlying storage volumes, databases (AWS Aurora PostgreSQL), object storage buckets (AWS S3), redis caching instances (AWS ElastiCache), and block storage (EBS) are encrypted at rest using AWS Key Management Service (KMS) AES-256 master encryption keys.
6.2 Application-Layer Security & Field-Level PII Encryption
Sensitive personally identifiable information (including SSNs, ITINs, government ID numbers, and full dates of birth) undergoes application-layer field-level encryption using AES-256-GCM prior to persistence in the database layer. Decryption keys are isolated within specialized AWS KMS hardware security modules (HSMs).
6.3 Zero-Trust Access Controls, MFA & Database WORM Immutability Triggers
- Zero-Trust Role-Based Access Control (RBAC): Internal administrative access to production systems operates under strict Zero-Trust principles enforcing the principle of least privilege. Personnel access requires private AWS VPC bastions, SSH key authentication, and hardware MFA.
- Hardware Multi-Factor Authentication (MFA): Internal staff and administrative access to production infrastructure requires FIDO2 / WebAuthn hardware security keys (YubiKey).
- Database Write Once Read Many (WORM) Immutability: PostgreSQL database triggers strictly prevent
UPDATEorDELETEoperations on core financial and audit tables (ledger_entries,rips,audit_log). Financial records are strictly append-only.
6.4 Vulnerability Management & Continuous Monitoring
- Control Posture: Operations are designed against recognized cloud security practices (least-privilege IAM, encryption everywhere, append-only records). No third-party certification (such as SOC 2) has been obtained, and none is claimed.
- Continuous Monitoring: Amazon GuardDuty provides continuous automated threat detection across the production account, with alerts routed to the operator.
SECTION 7: CHILDREN'S PRIVACY & STRICT AGE DISQUALIFICATION PROTOCOL
7.1 Absolute 18+ Age Restriction & COPPA Compliance
Caldarus Labs services are strictly restricted to individuals who are at least eighteen (18) years of age. The platform does not target, market to, or knowingly collect personal data from minors under eighteen (18) years of age, or under the age of majority in their jurisdiction.
7.2 Detection, Account Suspension & Data Purge Protocols for Unauthorized Minors
If Caldarus Labs receives notice or determines through automated DOB validation or KYC identity checks that a minor under eighteen (18) has registered an account:
- The account is immediately suspended, and all pending pack openings or withdrawal requests are frozen.
- All personal data associated with the minor is permanently purged from active systems within thirty (30) days, excepting records required to be retained under mandatory federal statutory laws (e.g., BSA anti-fraud audit logs).
SECTION 8: ILLINOIS BIOMETRIC INFORMATION PRIVACY ACT (BIPA 740 ILCS 14/) STATUTORY COMPLIANCE
8.1 Scope & Statutory Applicability
This Section 8 applies specifically to users who reside in the State of Illinois or whose biometric data is collected, captured, received, stored, or processed within the State of Illinois, pursuant to the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14/1 et seq.). Caldarus Labs maintains strict compliance with all statutory mandates set forth in BIPA to protect user biometric data integrity and privacy.
8.2 Statutory Definitions of Biometric Identifiers and Biometric Information (740 ILCS 14/10)
In accordance with 740 ILCS 14/10, the following statutory definitions apply to all biometric processing operations on the Platform:
- "Biometric Identifier" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color. Biometric identifiers do not include information captured from a patient in a health care setting or information collected, used, or stored for health care treatment, payment, or operations under HIPAA.
- "Biometric Information" means any information, regardless of how it is captured, converted, stored, or shared, based on an individual's biometric identifier used to identify an individual. Biometric information does not include information derived from items or procedures excluded under the definition of biometric identifiers.
- Platform Scope: Caldarus Labs, through its authorized identity verification sub-processor (Footprint Tech, Inc.), collects facial geometry scans and liveness video telemetry captured during step-up KYC identity verification to compare against government-issued photo identification. Such facial geometry scans and derived liveness telemetry constitute Biometric Identifiers and Biometric Information under 740 ILCS 14/10.
8.3 Mandatory Prior Written Disclosure & Explicit Written Consent (740 ILCS 14/15(b))
Pursuant to 740 ILCS 14/15(b), Caldarus Labs shall not collect, capture, purchase, receive through trade, or otherwise obtain a user's biometric identifier or biometric information unless it first:
- Written Notification: Informs the user or the user's legally authorized representative in writing that a biometric identifier or biometric information is being collected, captured, stored, or processed;
- Specific Purpose & Duration Disclosure: Informs the user or the user's legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used (specifically: 1:1 facial identity matching against photo identification to prevent account fraud, multi-accounting, and identity theft, and to comply with BSA/AML statutory mandates); and
- Executed Written Release: Receives an executed written release from the user or the user's legally authorized representative. Affirmative electronic consent—manifested by checking an explicit opt-in box and clicking "I Consent to Biometric Verification" prior to initiating facial liveness scanning—constitutes a legally binding written release under BIPA (740 ILCS 14/10) and the Virginia UETA / federal E-SIGN Act.
8.4 Absolute Zero-Sale & Commercial Profit Prohibition (740 ILCS 14/15(c))
Pursuant to 740 ILCS 14/15(c), Caldarus Labs is strictly prohibited from selling, leasing, trading, or otherwise profiting from a user's biometric identifier or biometric information. CALDARUS LABS DOES NOT SELL, LEASE, TRADE, RENT, OR MONETIZE BIOMETRIC IDENTIFIERS OR BIOMETRIC INFORMATION UNDER ANY CIRCUMSTANCES. Biometric data is utilized solely for identity verification and anti-fraud security.
8.5 Strict Disclosure & Transfer Restrictions (740 ILCS 14/15(d))
Pursuant to 740 ILCS 14/15(d), Caldarus Labs shall not disclose, redisclose, disseminate, or otherwise disseminate a user's biometric identifier or biometric information unless:
- The user or the user's legally authorized representative consents to the disclosure or redisclosure in writing;
- The disclosure or redisclosure completes a financial transaction requested or authorized by the user or the user's legally authorized representative;
- The disclosure or redisclosure is required by federal, state, or local law, or municipal ordinance; or
- The disclosure is required pursuant to a valid warrant, subpoena, or court order issued by a court of competent jurisdiction.
8.6 Public Biometric Retention Schedule & Destruction Protocols (740 ILCS 14/15(a))
Pursuant to 740 ILCS 14/15(a), Caldarus Labs establishes and maintains the following publicly available written retention schedule and destruction guidelines:
- Primary Purpose Satisfaction Trigger: Biometric identifiers and biometric information shall be permanently destroyed when the initial purpose for collecting or obtaining such identifiers or information has been satisfied, or within three (3) years of the user's last interaction with Caldarus Labs, whichever occurs first.
- 30-Day Vendor Purge Protocol: Raw biometric facial scan vectors, geometry templates, and liveness video frames ingested by authorized identity verification sub-processor (Footprint) are programmatically and permanently destroyed from sub-processor active memory and storage within thirty (30) calendar days following the completion of the 1:1 identity matching check.
- Non-Biometric Verification Audit Logs: Pass/fail metadata, identity verification timestamps, and non-biometric KYC records are retained for five (5) years following account closure in accordance with federal Bank Secrecy Act / AML statutory mandates (31 CFR § 1022.320), as set forth in Table 3.1 of this Policy. Non-biometric audit logs do not contain raw facial scan vectors or biometric identifiers.
8.7 High-Security Storage Standard & Standard of Care (740 ILCS 14/15(e))
Pursuant to 740 ILCS 14/15(e), Caldarus Labs stores, transmits, and protects all biometric identifiers and biometric information using the reasonable standard of care within the financial technology and digital security industries. Biometric data processing is conducted using TLS 1.3 transit encryption, AES-256-GCM application-layer field-level encryption at rest, and secure enclave processing. Biometric data is stored and protected in a manner that is equal to or more protective than the manner in which the Company stores, transmits, and protects other confidential and sensitive personal information.
SECTION 9: CONTACT INFORMATION, DPO DISCLOSURES & DISPUTE RESOLUTION
9.1 Data Protection Officer & Privacy Compliance Office
For inquiries, statutory rights requests, or privacy concerns:
- Caldarus Labs
Attn: Office of the Data Protection Officer
1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, USA
Primary Email:support@caldaruslabs.app/support@caldaruslabs.app
9.2 European Union & United Kingdom Statutory Representatives (GDPR Art. 27)
Caldarus Labs has not appointed a statutory representative in the European Union or the United Kingdom, and has no entity, branch or affiliate in either territory. Users in the EU or UK may contact Caldarus Labs directly at support@caldaruslabs.app regarding any data protection matter.
9.3 Regulatory Complaint Escalation Channels
If you reside in the EEA, UK, or a U.S. state with applicable privacy laws and believe our processing violates statutory rights, you have the right to lodge a complaint with your local supervisory authority:
- European Union: Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, Ireland (
https://www.dataprotection.ie). - United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, UK (
https://ico.org.uk). - United States: The Federal Trade Commission (FTC) or your state Attorney General's Office (e.g., California Privacy Protection Agency [CPPA] at
https://cppa.ca.gov).
PART II: COMPREHENSIVE DATA PROCESSING ADDENDUM (DPA)
SECTION 9: DPA STRUCTURE, ROLES, AND OPERATIONAL APPLICABILITY
9.1 Purpose and Integration with Privacy Policy
This Data Processing Addendum ("DPA") supplements the Grail Hunterz Privacy Policy and applies to all processing of Personal Data originating from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, or subject to CCPA/CPRA, in connection with the services provided by Caldarus Labs
9.2 Definitions & Interpretation
- "Applicable Data Protection Laws" means all privacy, security, and data protection laws applicable to the processing of Personal Data under this DPA, including the EU GDPR, UK GDPR, ePrivacy Directive, and CCPA/CPRA.
- "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Supervisory Authority" shall have the meanings defined under the EU GDPR and CCPA/CPRA.
- "Data Exporter" means the entity or individual transferring Personal Data out of the EEA, UK, or Switzerland.
- "Data Importer" means Caldarus Labs, located in the United States, receiving Personal Data.
9.3 Roles of Parties
- Controller-to-Processor Operations: Where a commercial user or business partner acts as a Controller and engages Caldarus Labs to process Personal Data, Caldarus Labs acts strictly as a Processor under GDPR Article 28 and Service Provider under CPRA.
- Controller-to-Controller Operations: Where users interact directly with Caldarus Labs to purchase mystery packs, verify identity, or execute card buybacks, Caldarus Labs acts as an independent Data Controller.
SECTION 10: EUROPEAN UNION STANDARD CONTRACTUAL CLAUSES (EU SCCs)
10.1 Incorporation of EU Commission Implementing Decision (EU) 2021/914
Pursuant to Article 46(2)(c) of Regulation (EU) 2016/679, the Standard Contractual Clauses issued under EU Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are hereby incorporated into this DPA by reference and completed as follows:
10.2 Module Selections
- Module 1 (Controller-to-Controller): Applies where Data Exporter and Data Importer both process Personal Data as independent Data Controllers.
- Module 2 (Controller-to-Processor): Applies where Data Exporter is a Data Controller and Caldarus Labs is a Data Processor.
10.3 Specific Clause Elections
- Clause 7 (Optional Docking Clause): The optional docking clause is enabled. Third parties may accede to these SCCs by executing an accession addendum.
- Clause 9 (Use of Sub-processors - Module 2): Option 2 (General Written Authorization) is selected. Data Importer shall provide Data Exporter with written notice of intended sub-processor additions or replacements at least fourteen (14) days in advance.
- Clause 11 (Redress): Independent dispute resolution is provided for Data Subjects without cost.
- Clause 17 (Governing Law): The governing law shall be the law of the Republic of Ireland.
- Clause 18 (Choice of Forum and Jurisdiction): Any dispute arising from the SCCs shall be resolved exclusively in the courts of Dublin, Ireland.
SECTION 11: UNITED KINGDOM INTERNATIONAL DATA TRANSFER ADDENDUM
11.1 Incorporation of ICO Section 119A(1) Addendum (Version B1.0)
For transfers of Personal Data originating in the United Kingdom subject to UK GDPR or the Data Protection Act 2018, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) issued by the UK Information Commissioner's Office (ICO) under Section 119A(1) is incorporated into this DPA:
11.2 Statutory Tables 1 through 4
-
Table 1: Parties
- Data Exporter: UK User, Business Partner, or Commercial Entity.
- Data Importer: Caldarus Labs, 1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, USA (Contact:
support@caldaruslabs.app).
-
Table 2: Selected Standard Contractual Clauses
- The EU SCCs incorporated under Section 10 of this DPA, including Module 1 and Module 2 selections.
-
Table 3: Appendix Information
- The Information required in Annex I, Annex II, and Annex III of this DPA.
-
Table 4: Ending this Addendum when the Approved Addendum Changes
- Either Data Importer or Data Exporter may terminate the UK Addendum in accordance with Section 19 of the UK Addendum.
SECTION 12: STATUTORY DATA BREACH NOTIFICATION PROTOCOL
+-----------------------------------------------------------------------------------+
| STATUTORY BREACH NOTIFICATION TIMELINE |
+-----------------------------------------------------------------------------------+
| T=0: Security Incident Confirmed -> Forensic Containment & Risk Assessment |
| |
| T <= 24 Hours: Sub-Processor Notice to Caldarus Labs |
| T <= 72 Hours: Notice to EU DPC / UK ICO Supervisory Authorities (GDPR Art. 33) |
| T <= 45-60 Days: State AG & Data Subject Notice (CA Civ. Code § 1798.82 / DE Code)|
+-----------------------------------------------------------------------------------+
12.1 72-Hour Supervisory Authority Notification Protocol (EU GDPR Art. 33 / UK GDPR)
In the event of a personal data breach affecting Personal Data originating from the EEA or UK, Caldarus Labs shall notify the competent Supervisory Authority (Irish Data Protection Commission / UK ICO) without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of the breach.
The notification shall set forth:
- The nature of the personal data breach, including categories and approximate number of data subjects and records concerned.
- The identity and contact details of the Data Protection Officer (
support@caldaruslabs.app). - The likely consequences of the breach.
- Measures taken or proposed to be taken by Caldarus Labs to address the breach and mitigate risks.
12.2 High-Risk Data Subject Breach Notification (GDPR Art. 34)
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, Caldarus Labs shall communicate the breach to affected Data Subjects without undue delay via electronic mail and direct push notification.
12.3 United States State Law Breach Compliance
- California Civil Code § 1798.82: Electronic notice provided to affected California residents without unreasonable delay. If an incident affects more than 500 California residents, notice is submitted simultaneously to the California Attorney General.
- Virginia Code Title 6 § 12B-101: Notice provided to affected Virginia residents without unreasonable delay, not to exceed sixty (60) days following determination of the breach, unless law enforcement requests a written delay.
12.4 Sub-Processor 24-Hour Incident Escalation Mandate
All sub-processors engaged by Caldarus Labs are contractually bound to notify Caldarus Labs in writing within twenty-four (24) hours of discovering any confirmed or suspected security incident affecting Personal Data.
PART III: DPA ANNEXES & SCHEDULES
ANNEX I: DETAILS OF THE DATA PROCESSING
A. List of Parties
- Data Exporter: Individual end users, registered account holders, or business partners residing in the EEA, UK, or Switzerland.
- Data Importer: Caldarus Labs, a Sole Proprietorship operating from 1521 Boyd Pointe Way, Unit 3402, Tysons, VA 22182, USA (Contact:
support@caldaruslabs.app).
B. Description of Transfer
- Categories of Data Subjects: Platform users, mystery pack buyers, trading card collectors, sellers executing buybacks, physical card redemption recipients.
- Categories of Personal Data: Account registration data, government photo identification, SSN/ITIN, date of birth, residential address, tokenized payment credentials, bank routing/account numbers, device IP/GPS, hardware device fingerprints, and provably-fair draw logs.
- Special Categories of Data (Sensitive Personal Data): Biometric facial geometry and liveness telemetry ingested strictly for automated identity verification, processed under explicit consent pursuant to GDPR Article 9(2)(a).
- Frequency of Transfer: Continuous processing for active platform users.
- Nature of Processing: Storage, identity verification, anti-fraud evaluation, pack purchase execution, provably-fair RNG draw calculation, physical card vaulting, card buyback settlement, and tax reporting.
- Purpose of Transfer: Facilitating mystery pack purchases, ensuring platform security, complying with BSA/AML statutory mandates, fulfilling physical card deliveries, executing cash payouts, and reporting statutory taxes.
- Retention Period: Retained in accordance with Section 3 retention tables (KYC 5 years; Tax 7 years; Ledger & Provably-Fair logs permanent; Telemetry 2 years).
C. Competent Supervisory Authority
The competent supervisory authority for transfers governed by EU SCCs is the Data Protection Commission (DPC) of Ireland. For UK transfers, the competent authority is the Information Commissioner's Office (ICO).
ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs) FOR DATA SECURITY
Caldarus Labs implements the following Technical and Organizational Security Measures:
- Cryptographic Encryption Standards: TLS 1.3 for all data in transit; AWS KMS AES-256 for all data at rest; AES-256-GCM application-layer field-level encryption for SSNs, DOBs, and photo ID numbers.
- Access Controls & Zero-Trust Architecture: Strict Role-Based Access Control (RBAC) enforcing Least Privilege IAM. Administrative access restricted to private VPC bastions with SSH key authentication and mandatory FIDO2 hardware MFA (YubiKey).
- Database Security & Immutability: Write Once Read Many (WORM) PostgreSQL triggers enforcing append-only balance history for
ledger_entriesand provably-fairripslogs. - Vulnerability Management: Continuous automated threat detection via Amazon GuardDuty. Dependency and code review before every release, executed by independent CREST-accredited firms.
- Data Isolation & Environment Hygiene: Production databases physically isolated from development environments. PII scrubbed from development databases and log aggregators.
- Physical Storage: Trading card inventory held in secure, access-controlled storage under the operator's direct custody, with intake and condition recordtric physical access controls, and specie insurance coverage.
- Business Continuity & Disaster Recovery: Automated database backups with Point-In-Time Recovery, plus an immutable final-state snapshot policy for every retired system.
- Operator Access: Caldarus Labs is operated by a single person; no employees or contractors hold production data access.
- Vendor Risk Management: Mandatory pre-contractual security reviews and DPAs for all sub-processors.
- Audit Logs & Incident Response: Tamper-evident, hash-chained audit logging to AWS S3 WORM storage and 24/7 automated security alert monitoring.
ANNEX III: AUTHORIZED SUB-PROCESSOR SCHEDULE & AUTHORIZATION PROTOCOL
Caldarus Labs utilizes the authorized sub-processors set forth in Table 5.1 (Master Sub-Processor Schedule) of Part I of this document.
Sub-Processor Management Framework
- Prior Notification of Sub-Processor Changes: Pursuant to Clause 9 (Option 2) of the EU SCCs, Data Importer shall provide Data Exporter with written notice of any intended additions or replacements to the sub-processor schedule at least fourteen (14) days in advance via publication in the Privacy Center or direct email notification.
- Objection Rights: Data Exporter may object to the appointment of a new sub-processor on reasonable privacy or security grounds by notifying Data Importer in writing within fourteen (14) days of receiving notice. If Data Importer cannot reasonably accommodate the objection, Data Exporter may terminate the affected service.
- Contractual Pass-Through Obligations: Data Importer guarantees that all sub-processors are bound by written agreements imposing privacy and security obligations no less protective than those set forth in this DPA and Annex II (TOMs).
[END OF PRIVACY POLICY AND DATA PROCESSING ADDENDUM]