Política de Privacidade
Vigência: 2026-09-19
O texto jurídico abaixo é o original em inglês. Não há documento jurídico traduzido para este idioma. English
Scope and controller
This policy covers the hosts catalystdesk.ai, watchlist.catalystdesk.ai, subscribers.catalystdesk.ai and unsubscribe.catalystdesk.ai, and the brief e-mails we send. Data controller: BANFF MANAGEMENT DATA ANALYSIS LIMITED (班夫管理數據分析有限公司), Flat/Rm 1911, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong.
What we collect
Your e-mail address (subscription and sign-in), request IP and time (rate limiting and security audit), sign-in code issuance and use, subscription confirmation and unsubscribe records; audit-log entries also record the e-mail address the action concerns. Each confirmed subscription also writes one statistics row with no e-mail address or IP (the date, the language and which subscribe link on the site you used), read only in aggregate to compare page wordings. If you use the on-chain unlock, we keep the public wallet address you link yourself and the result of the one-time signature check, and read that address's public approval and fill facts on the decentralised exchange; if you arrived from a community's alert card and then unlock, we keep that community's identifier on the address's unlock record so the community owner's share of the builder fee can be settled. To decide whether the optional on-chain channel may be offered to you we read the country the network edge reports for your request (derived from your IP), use it for that decision only and do not otherwise store it. If you interact with the messenger bot we keep your messenger user id, language and the community you came from; when a community owner binds a group we also keep the group id and title, the referral code or payout address they supply, and the rebate ledger held against that community. We never touch a private key or seed phrase and store no card number. Desk Alpha – Personal is paid on the payment provider's checkout page: you enter your card details there and we never see card numbers; the payment provider and Link receive what they need to process the transaction, and we keep only the subscription's status, its billing periods, the amounts paid or refunded, the provider's reference identifiers, linked to your e-mail address, and the source token cd_src held when you started the checkout (which page or e-mail link brought you to a plan page), to grant access, answer support requests and count checkouts by source; of the notifications the payment provider sends us we keep only their identifier and type, and we do not store your name, billing address, phone number or card details.
How we use it
To send the two briefs and sign-in codes, verify access, administer Desk Alpha subscriptions, prevent abuse and honour unsubscribe and data requests. We do not sell personal information or use it for third-party advertising.
E-mail metrics
Brief e-mails carry no open- or click-tracking pixels; the upgrade link carries a source token with nothing personal in it (the same for every recipient of the issue), see cd_src below; a click on the unsubscribe link is recorded so that sending stops immediately.
Cookies
The live page uses one session cookie to keep you signed in; this site sets no third-party or advertising tracking cookies. The site may also set two first-party measurement cookies: cd_exp keeps the version of a page you were shown the same on your next visit and lets us compare page wordings in aggregate by version; cd_src remembers which page or e-mail link brought you to a plan page, and if you then start a checkout that source token is stored with the checkout on your subscription record (see above). Neither cookie holds your e-mail address or IP, neither is shared with anyone, and there is no third-party tracking.
Security logs
Rate-limit and access-audit entries (IP, time, action, the e-mail address concerned) are kept for 90 days to prevent abuse and diagnose faults, never for profiling.
Retention and deletion
Network traffic and access logs are kept for 90 days on a rolling basis; sign-in codes and session tokens themselves, with their validation state, for 30 days (the access-audit entry that one was issued or used follows the 90-day rolling rule above); financial, tax and subscription payment records for 7 years as required by accounting law. After unsubscribing, the address stays on a suppression list so we never send again; write to us to delete the other account records, except the minimum the suppression list and statutory retention require.
Service providers and security
E-mails are delivered through an e-mail provider and the pages run on cloud hosting. Desk Alpha – Personal payments are processed by the payment provider, with Link as the seller of record. The on-chain view involves no fiat payment: approval and signing happen in your own wallet and go straight to the decentralised exchange; the Service is not a merchant of record and touches neither your keys nor your funds. Apart from any subscriber-category (professional / non-professional) reporting the data agreements require, market-data providers receive none of your personal information. All transport is TLS-encrypted and access is controlled by account, sign-in code or on-chain address approval. The service is not offered to anyone under 18.
Your rights
You may write at any time to access, correct or delete the records we hold about you, or unsubscribe at any time; we answer within a reasonable period.
Contact
Send privacy requests to alerts@catalystdesk.ai.