borglife.ai — privacy notice

how we process personal data under the Swiss FADP and the EU GDPR

Version 1.0 · Effective 7 May 2026


> TL;DR (human-readable, not legally binding)


> 01 Scope & controller

Data minimization by design. Borglife is a non-custodial protocol. We are never a custodian of your assets and do not operate a financial account in your name. To participate in the on-chain protocol, you connect a self-custodial wallet (e.g., Talisman) — and that is all the protocol requires.

Most of your interaction with Borglife does not pass through our off-chain infrastructure. Your wallet talks directly to the public blockchain via your own client and your chosen RPC endpoint; signing, broadcasting, and reading on-chain state happen between you and the chain. We are not in that data-transmission path, and once a transaction is recorded on-chain, we cannot delete or modify it. We process personal data through our own infrastructure only at specific, opt-in touchpoints described in this Notice — for example, when you visit borglife.ai, use a frontend or indexer that we operate, email us, or run the borglife plugin with telemetry enabled.

For clarity on controller status: where we operate an off-chain touchpoint that receives or holds personal data, we are a controller for that processing (or, for Bounty content, a processor for the Sponsor — see §13). To the extent our design of the Borglife protocol (including the structure of on-chain data schemas such as Borg attributes, lineage records, badge fields, and Bounty metadata) determines what personal data is captured by protocol activity, we acknowledge that those design choices may engage controller-style responsibilities under data-protection law, while emphasising that we cannot delete or alter on-chain records once made (see §5).

We do not require, and from your wallet alone we cannot derive, your name, address, email, government-issued identity documents, identity-verification data, payment-card data, or any other personally identifying information. The categories of personal data described in this Notice apply only when you actively choose to interact with a touchpoint we operate.

This Privacy Notice describes how Swiss Choice GmbH, a Swiss limited liability company with its registered seat at Feusisberg (Höfe district, Canton Schwyz, Switzerland) ("Swiss Choice", "we", "our", "us"), processes personal data in connection with the borglife.ai website, the borglife plugin, the off-chain Borglife infrastructure (matching, indexing, oracle/verifier services), and our communications with you (collectively, the "Service").

This Notice forms part of, and is to be read together with, the Borglife Terms & Conditions. Defined terms used here have the meaning given to them in the Terms unless otherwise stated.

We are the data controller only for personal data that we actually collect, store, or otherwise handle, as described in this Notice and where we determine the purposes and means of that processing. Where another controller is identified (see §13 for the controller / processor allocation between us and Sponsors), that allocation prevails. Where we do not collect or store personal data about you — for example, where you interact with the Borglife protocol via Talisman and a public RPC endpoint without using a touchpoint we operate — there is no controller relationship between you and us in respect of that interaction. Our data-protection contact is info@borglife.ai.

This Notice applies to processing governed by the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR) in respect of EEA-resident data subjects to whom we direct the Service.

GDPR Article 27 — operational assessment. Where GDPR applies to our processing of personal data of EEA-resident data subjects, we have assessed the Article 27(2)(a) exemption as currently applicable, on the following operational grounds (each tied to the data-minimization architecture described in this Notice and in §16 of the Terms): (i) participation in the on-chain Borglife protocol requires only a self-custodial wallet connection, not personal data, and most user interaction does not pass through our off-chain infrastructure at all (see §1 above and §13.3); (ii) the processing of EEA-resident personal data through our own infrastructure is currently narrow, opt-in, and low-volume (voluntarily emailing us, joining a mailing list, requesting the whitepaper, contacting support, or visiting borglife.ai), within the EDPB's notion of "occasional" processing under Guidelines 3/2018; (iii) special-category data is an absolute exclusion under §2.1; and (iv) the resulting processing is unlikely to result in a risk to the rights and freedoms of natural persons, both because of (i)-(iii) and because data subjects can unsubscribe or request deletion at any time, after which we retain nothing about them beyond the narrow retention windows in §8.

We will actively monitor whether EEA-directed processing through our infrastructure remains within the Article 27(2)(a) scope. If EEA-directed processing becomes regular or systematic in the EDPB sense — for example, through sustained, non-trivial EEA-targeted website / frontend / indexer / oracle / plugin processing or through the materialisation of risks to data subjects above the low-risk threshold — we will, before continuing such processing (other than during a short good-faith transition period), either (a) appoint an Article 27 representative, or (b) restrict EEA-facing access at the off-chain access layer to keep processing within the structural exemption. In either case, this Notice will be updated under §17.

What this Notice does NOT cover. The Borglife smart contracts and the public blockchains they live on (Polkadot, Asset Hub, etc.) are operated by their respective decentralised networks, not by us. We do not control on-chain data, and we cannot delete, modify, or restrict it. See §5.

> 02 Categories of personal data we process

2.1 What we never collect

The following are absolute exclusions: we do not request them, we do not retain them, and we do not use them. If you nonetheless transmit any such category to us (for example, by attaching it to an email), we will delete or reject it without further use as soon as we identify it; brief incidental receipt during inbox triage does not constitute use or retention. We will not change this exclusion without amending this Notice and notifying you under §17.

2.2 What we do not require (you may voluntarily provide)

For participation in the on-chain Borglife protocol, we require only a wallet connection. We do not require — and from your wallet alone we cannot derive — any of the following. You may, however, voluntarily provide them in a separate, optional interaction (for example, by emailing us, joining the mailing list, requesting the whitepaper, or contacting support):

From a wallet address alone, we cannot in the ordinary course identify you personally. Wallet pseudonymity is, however, not anonymity — please see §5.

2.3 What we may process when you interact with the Service or voluntarily provide data

The categories below are processed by us only at specific, opt-in touchpoints. Where you do not engage with a given touchpoint, the corresponding category is not processed by us at all and we are not a controller of any data about you in that respect.

> 03 Sources of personal data

Where we process personal data, the sources are:

The default Borglife user path does not pass through our off-chain infrastructure. If you operate Talisman, sign transactions locally, broadcast via a public RPC endpoint, and never interact with a frontend, indexer, oracle, relayer, or communication channel we operate, we do not collect or store personal data about you through our own infrastructure. (Our design of the Borglife protocol may still engage controller-style responsibilities under data-protection law for the schema-level design choices that determine what data is recorded on-chain — see §1.)

> 04 Purposes & legal bases

Where we process personal data, we do so for the following purposes, on the following legal bases under FADP Art. 31 and GDPR Art. 6.

The table shows, for each purpose, the categories of data that may be used if and to the extent we actually hold them. Most categories are collected only when you voluntarily provide them (see §2); where we do not hold a category, the corresponding processing does not occur.

Purpose Categories used Legal basis (GDPR / FADP)
Providing the Service: serving the website, operating frontends, indexers, matching, oracle and verifier infrastructure, and processing your requests Wallet, technical, bounty/matching, Borg config, telemetry Performance of the Terms with you (GDPR Art. 6(1)(b) / FADP Art. 31(1)); legitimate interests (Art. 6(1)(f)) for visitors who have not yet accepted the Terms
Eligibility, sanctions & jurisdictional screening: verifying §3 of the Terms (no sanctioned jurisdictions, no U.S. Persons under Reg S, 18+) and recording your acceptance Wallet, technical, eligibility/sanctions/jurisdictional-screening data, acceptance record For sanctions screening: compliance with legal obligations (Art. 6(1)(c)) under Swiss SECO and applicable EU sanctions law. For Reg S U.S.-person and age screening: legitimate interests in operating a lawful Service and avoiding regulatory exposure (Art. 6(1)(f)). For recording your acceptance: performance of pre-contractual / contractual measures (Art. 6(1)(b))
Security, fraud prevention & abuse mitigation: detecting attacks, abuse, sybil behaviour, and protocol manipulation Wallet, technical, telemetry Legitimate interests (Art. 6(1)(f))
Communications: replying to your messages, sending operational notices about the Service, sending a mailing-list message you have subscribed to Contact, communication For replies to messages you initiate: legitimate interests (Art. 6(1)(f)). For operational notices to users who have accepted the Terms: performance of contract (Art. 6(1)(b)). For mailing-list and similar non-essential communications: your consent (Art. 6(1)(a))
Improvement & reliability: aggregate usage analysis, error and crash diagnostics, iterative improvement based on aggregate signals Technical, telemetry Legitimate interests (Art. 6(1)(f)); your consent (Art. 6(1)(a)) for any non-essential cookies
Computing, auditing, and defending Proof-of-Participation (ProP) allocations: calculating ProP entitlements at each crystallization event, anchoring contribution proofs on-chain, resolving disputes, and auditing allocations under §6.4 of the Terms Wallet and on-chain identifiers, ProP eligibility and allocation metadata Performance of the Terms with you (Art. 6(1)(b) / FADP Art. 31(1)) where you participate in a ProP-eligible role; legitimate interests in operating, auditing, and defending the protocol's reward mechanism (Art. 6(1)(f))
Compliance, legal claims, dispute resolution & defence Any category we already hold, only to the extent required for the specific compliance, claim, or defence purpose Compliance with legal obligations (Art. 6(1)(c)); legitimate interests in establishing, exercising, or defending legal claims (Art. 6(1)(f))

Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing is based on legitimate interests, you have the right to object on grounds relating to your particular situation (see §9).

> 05 Blockchain data & the right to erasure

Public blockchains such as Polkadot and Asset Hub are by design distributed, public, pseudonymous, and effectively immutable. Once a transaction is confirmed, neither we nor any other single party can delete or rewrite it. Wallet addresses, transaction history, Borg lineage, badges, and Bounty interactions are part of the chain's permanent record.

This has practical consequences for your data-protection rights:

By choosing to use a public blockchain, you accept these structural limits on data-protection rights as against the chain itself. This is a property of the technology, not a choice we make.

> 06 Recipients & sub-processors

To the extent we share personal data, we share it only with parties that have a need to receive it and that are bound by adequate contractual and technical safeguards. The current scope of recipients is deliberately narrow:

Communication platforms you choose to contact us through (e.g., Discord, GitHub) are not our sub-processors; they are independent controllers governed by their own privacy notices for the relationship between you and that platform. Off-chain matching, indexing, oracle, verifier, relayer, and ProP operator / allocation roles are operated by us directly during the bootstrap phase and are not third-party recipients.

Any new category of recipient (for example, a dedicated email-delivery provider, a third-party sanctions-screening API, or analytics tooling) will be added to this list by amendment to this Notice before deployment, in line with §17.

We do not sell personal data, and we do not share personal data with advertisers or data brokers.

> 07 International transfers

Switzerland and the EEA benefit from mutual adequacy. Where practicable, we prefer recipients and sub-processors located within Switzerland or the EEA.

If and when a recipient or sub-processor is located in a country that does not benefit from a Swiss FDPIC adequacy decision or a European Commission adequacy decision, we rely on appropriate safeguards including, as relevant:

You may request a copy of the relevant safeguards by contacting us at info@borglife.ai, subject to redactions necessary to protect commercial confidentiality and the rights of others.

> 08 Retention

Where we hold personal data, we retain it only as long as necessary for the purposes for which it was collected and any subsequent compatible purposes, plus any retention period required by law.

The periods below apply only to data we actually hold. If we never received a category from you, no retention applies for it.

Indicative periods:

When the retention period ends, we delete or anonymise the data, unless legal obligations require continued retention.

> 09 Your rights as a data subject

Subject to applicable law, you have the following rights in respect of personal data we process about you:

> 10 How to exercise your rights

To exercise any of the rights in §9, contact us at info@borglife.ai. We may need to verify your identity before responding — typically by asking you to send the request from the email address we already have on file, or to sign a verification message with the wallet whose data is the subject of the request.

We will respond within 30 days of receiving a verifiable request, unless the request is complex or numerous, in which case we may extend by up to 60 additional days and inform you of the extension and the reasons.

Exercising your rights is free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, and we will explain our reasoning.

> 11 Right to lodge a complaint

You have the right to lodge a complaint with a competent supervisory authority. In particular:

We would appreciate the opportunity to address your concerns directly first; please consider contacting us at info@borglife.ai before lodging a formal complaint.

> 12 Automated decision-making & profiling

We do not currently make decisions producing legal or similarly significant effects on you that are based solely on automated processing in the sense of GDPR Art. 22.

We use automated processing for limited operational purposes only — for example, sanctions-screening, basic anti-abuse heuristics, and rate-limiting. Where any such processing materially affects your access to the Service, a human review is available on request.

Note that the Borglife smart contracts execute deterministically on-chain. The contracts are not profiling within the meaning of GDPR; they are software executing rules on data you choose to submit. The economic, social, and reputational consequences of on-chain activity follow from those rules, not from any opaque decision by us about you personally.

> 13 Sponsors, Bounties & controller roles

13.1 Controller-role allocation

Different processing of personal data in connection with Bounties involves different controller roles. Each role is allocated as follows:

To the extent we process operational metadata derived from Bounty processing for our own purposes — including infrastructure operation, abuse detection, fraud prevention, security, and aggregate analytics — that processing falls under (a), and we act as a separate controller for those purposes (not as a joint controller with the Sponsor).

13.2 Exercising your rights

You may exercise the rights described in §9:

Where we act as a processor under (b), data-subject requests are most effectively directed to the relevant Sponsor as controller; we will assist the Sponsor in responding to the extent required by GDPR Art. 28(3)(e). If you are unsure who to contact, write to info@borglife.ai and we will route your request appropriately.

13.3 Paths that do not use our infrastructure

Where you participate in Bounties without using matching, indexing, oracle, verifier, or relayer infrastructure that we operate (for example, peer-to-peer discovery via libp2p with on-chain settlement), we have no visibility of and no operational role in the relevant Bounty processing, and no processing relationship — controller or processor — arises between you and us through our own infrastructure for that processing. (Our protocol-design choices may still engage controller-style responsibilities for the schema-level design — see §1.)

> 14 Children

The Service is not directed to children and the Terms restrict participation to persons aged 18 or older. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact info@borglife.ai and we will delete it without undue delay.

> 15 Security

Data minimization is our primary security control. What we do not collect cannot be lost, leaked, subpoenaed, or compelled. The non-custodial, no-account, real-time-screen-only architecture described in §1, §2, and §3 substantially reduces the personal-data attack surface relative to a typical web service.

For the limited categories of personal data we do hold (see §2.3), we implement appropriate technical and organisational measures to protect them against unauthorised access, alteration, disclosure, or destruction, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

No method of transmission over the internet or storage is fully secure. Your seed phrase and private keys are your responsibility alone — we never request, store, or have access to them. Please see §5 of the Terms.

If we become aware of a personal-data breach, we will assess the risk to your rights and freedoms and, where required by law, notify the competent supervisory authority — under GDPR Art. 33, without undue delay and where feasible within 72 hours of becoming aware of the breach, and under FADP Art. 24, as soon as possible. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (GDPR Art. 34 / FADP Art. 24 para. 4).

> 16 Cookies, analytics & local storage

The borglife.ai website does not currently deploy analytics, advertising, profiling, or cross-site tracking cookies, and does not use third-party tracking SDKs.

Where the Service uses cookies or browser local-storage mechanisms, they are strictly necessary to deliver the functionality you requested (for example, to record that you have accepted the Terms during a click-wrap acceptance flow). Strictly necessary cookies do not require consent under the Swiss FADP, and are exempt from the consent requirement of Article 5(3) of the ePrivacy Directive 2002/58/EC (as transposed in EEA Member States) for EEA users.

If that changes — for example, if we later deploy analytics, performance, or advertising cookies — we will request your consent in advance via a cookie banner, identify the categories and purposes, and allow you to refuse or selectively accept.

You can manage cookies through your browser settings.

> 17 Changes to this notice

We may amend this Notice from time to time. The "Effective" date at the top will be updated for any amendment, and where reasonably practicable we will also give notice on the website or by email where you have previously provided one.

Material changes (privacy posture) — including any change to the categories of personal data we process, the legal bases we rely on, the controller / processor allocation in §13, the international-transfers position in §7, the retention windows in §8, the §2.1 absolute exclusions, or the Article 27(2)(a) framing in §1 — will be treated as material privacy-posture changes for the purpose of §22 of the Terms & Conditions. Consistent with that section, continued access to touchpoints we operate after the effective date of a material privacy-posture change will be gated on a fresh affirmative click-wrap acceptance of the amended Notice; the amended Notice will not be applied to your processing on the basis of mere continued use.

Non-material changes — clarifications, formatting fixes, contact-information updates, cross-reference corrections, sub-processor-name changes that do not alter the underlying allocation, and similar — take effect on the new Effective date and continued use of the Service constitutes acceptance of those non-material amendments.

> 18 Contact

For any data-protection question or to exercise your rights, please contact us at info@borglife.ai.