Privacy policy
How we use personal data across the marketplace, DreamForge and our connected services.
For privacy requests, write to contact@sentx.io. Company and contact details
This policy explains our processing; accepting the terms does not give blanket consent to tracking or other optional uses of your data.
1. What this policy covers
This policy covers personal data processed by SentX when you browse, connect a wallet, trade, use DreamForge creator and AI tools, use our APIs, or contact us. Some integrations have their own notices. Independent wallet, payment and blockchain providers are responsible for their own processing; that does not remove SentX's responsibilities for the processing we determine or commission.
Our services are intended for adults aged 18 or over. If you believe a child has provided personal data, contact us so we can investigate, restrict the account where appropriate and handle deletion subject to legal obligations.
2. Data we use and where it comes from
- Account and profile: wallet/account identifiers, authentication and session information, preferences, and names, avatars, email addresses or linked profiles you choose to provide. Optional profile information is not required simply to browse.
- Activity and transactions: holdings, listings, offers, bids, transfers, purchases, fees, rewards, creator operations and related records. We obtain these from your interactions, our systems, public blockchain/mirror data and connected services. A public wallet address can identify or be linked to a person; it is not necessarily anonymous.
- Creator and AI content: files, metadata, prompts, reference images, text or lyrics, generated outputs and operation history. Content can contain personal data about you or other people. Provide only material you are entitled to use and avoid unnecessary sensitive information.
- Permissions and credentials: API credentials and permission settings, and collection keys you import or configure for supported creator actions. These are distinct from your personal wallet recovery phrase. Never send your wallet recovery phrase or private key in a privacy or support request.
- Support and legal records: messages, attachments, moderation reports, billing information where relevant, consent choices and terms acceptance evidence, including the wallet, document version and acceptance time.
- Technical information: IP address, browser/device information, approximate location derived from the connection, request and error logs, and cookie or similar identifiers. Where optional analytics or replay is enabled, this can include page content and interactions. Diagnostics can be associated with a wallet account.
Public profile and blockchain information may come from sources other than you, including Hedera mirror services and HashPack profile lookup. Required account, transaction or security information is needed to provide the corresponding feature. If you do not supply it, that feature may be unavailable; optional consent is separate.
3. Why we use data and our legal bases
- Provide the features you request: contract, or steps you request before a contract
- Authenticate accounts, execute requested marketplace and creator operations, deliver AI results, manage API access and respond to service requests. This applies only to processing necessary for those purposes.
- Operate and protect SentX: legitimate interests
- Prevent abuse and fraud, investigate incidents, diagnose failures, maintain availability and manage support or disputes. Our interests are a reliable service, protection of users and enforcement or defence of legitimate claims. We must balance these interests against your rights. Public market and wallet information also supports discovery and market statistics; public availability does not remove data-protection duties.
- Meet legal duties: legal obligation
- Keep required accounting and tax information, answer lawful authority requests and handle statutory rights. We retain acceptance and transaction evidence where needed to establish the contract or defend claims, on the applicable contractual or legitimate-interest basis. We do not treat every user as subject to a universal identity-checking obligation.
- Optional tracking and communications: consent where required
- Use non-essential cookies, behavioral analytics, session replay and marketing according to the choices and legal requirements that apply. We request any necessary consent separately. You can withdraw it without affecting earlier lawful processing or necessary service functions.
6. International transfers and public networks
Providers and network participants may process data outside the European Economic Area, including in the United States. Transfers arranged by SentX require an applicable legal basis for the transfer, such as an adequacy decision covering the recipient, or standard contractual clauses and any necessary additional safeguards. A provider being based in the US does not itself establish that a transfer is covered by an adequacy decision. Contact us for the safeguards and how to obtain a copy for a particular transfer.
Blockchain transactions and content published to decentralized networks can be copied worldwide and retained independently of SentX. Wallets, amounts, metadata and links can reveal personal information. SentX cannot promise to erase those independent copies. We remain responsible for assessing our own disclosures and handling rights concerning the data and systems we control.
7. How long we keep data
Retention depends on the purpose and the category of information, not simply on whether your wallet remains connected:
- Account, content and operation data: for as long as needed to provide the requested features, maintain your account or content, and resolve unfinished operations or disputes.
- Support, contract and acceptance records: for the request or contractual relationship and the applicable period for establishing, exercising or defending claims.
- Accounting and tax records: for applicable statutory periods, generally six years for commercial accounting records and four years for tax obligations, subject to longer requirements or interruption of limitation periods.
- Security and identifiable usage data: only as long as necessary for the documented purpose, with a maximum of 48 months, unless a specific legal duty or active claim requires restricted retention. Survey or user-test responses, where collected, have a maximum of 24 months.
- Optional consent: withdrawal stops future consent-based use; limited evidence of the choice may remain where needed to demonstrate compliance.
Where applicable, data must be restricted or blocked for legal responsibilities before final deletion. Backups and provider copies require their own retention handling; disconnecting a wallet is not an account-deletion request. Contact us to request deletion or the criteria applicable to a particular record. Public blockchain and independently stored decentralized copies have the limits described above.
8. Automated safeguards and review
Automated rules can use request patterns, IP or network signals and account activity to detect abuse, rate-limit requests or restrict access. Content and reports may also be reviewed by administrators. Not every technical block is preceded by human review.
If a restriction affects you, contact us to request review, explain your circumstances and challenge an error. Where a decision based solely on automated processing has legal or similarly significant effects, the protections and restrictions in Article 22 GDPR apply, including any required human intervention and opportunity to contest it. This notice does not create an exception to those protections.
9. Your rights and how to use them
Depending on the applicable conditions, you can request access and a copy, correction, deletion or restriction of your data. You can request portability of data you provided when processing is automated and based on consent or a contract.
You may object to processing based on legitimate interests because of your particular situation. You may object to direct marketing at any time. You can withdraw consent as easily as giving it; this does not affect processing that was lawful before withdrawal.
Write to contact@sentx.io or the postal address below. Requests are normally free. We may ask for proportionate verification if we reasonably need to confirm that the data is yours, rather than routinely requiring identity documents. Never send wallet recovery phrases or private keys.
We normally respond within one month of receiving a request. If its complexity or number requires up to two additional months, we will explain the extension within the first month. If we cannot act on a request, we will explain why and your complaint options.
You can complain directly to the Spanish Data Protection Agency (AEPD) or the supervisory authority in your place of habitual residence, work or the alleged infringement. You do not have to contact us first.
10. Security
We use technical and organizational safeguards appropriate to the processing, such as access controls and measures to protect service credentials and communications. No service can guarantee absolute security. Tell us promptly if you suspect unauthorized use; we assess incidents and notify affected people or authorities when the law requires it.
11. Changes to this policy
We publish updates with a revised date and give additional notice of material changes where required. Before using data for a new purpose, we must provide the required information and establish an appropriate legal basis. A policy update or acceptance of marketplace terms does not replace any new consent that is required.
12. Company and privacy contact
The controller is SENTX LABS, SL, trading as SentX. NIF (VAT) B16403198.
C/ Ortega y Gasset 9, 6th & 7th floor30009 Murcia, Spain
contact@sentx.io
Registro Mercantil de Murcia: sheet MU-113640, entry 1, IRUS 1000422115959. We handle privacy enquiries in English and Spanish.


