This Privacy Policy describes how Worldwide AIS Network ApS, a company registered in Denmark under CVR number 45911748 with its registered office in Copenhagen ("MastChain", "we", "us", or "our"), collects, uses, discloses, and otherwise processes personal data in connection with the MastChain website, the MastChain network, and any related services (together, the "Services"). It also explains the rights available to you under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR") and the Danish Data Protection Act.
We act as the data controller for the personal data processed under this Policy. Please read this Policy carefully. By using the Services, you acknowledge that you have read and understood it. If you do not agree with it, you should not use the Services.
1. Scope of this Policy
This Policy applies to personal data we process about visitors to our website, recipients of our communications, operators who run a MastNode, and other individuals who interact with us. It does not apply to third-party websites, products, or services that we do not control, even where we link to them. Where the Services are made available to you by an organisation, such as your employer, that organisation may also process your personal data under its own privacy notice, for which it is responsible.
2. Personal data we collect
We collect personal data in the following ways and categories.
2.1 Information you provide to us
- Contact and subscription data, such as your name and email address when you subscribe to updates, complete a form, or contact us.
- Account and authentication data, such as login identifiers and credentials where you hold an account.
- Correspondence, including the content of messages, support requests, and any information you choose to share with us.
2.2 Operator and station data
If you operate a MastNode, we process information necessary to attribute coverage to your station and to maintain the integrity of the network. This may include station identifiers, hardware and configuration details, declared or approximate location, reception metadata, signal quality measurements, and uptime and performance information. Where any of this information relates to an identifiable individual, it constitutes personal data.
2.3 Information we collect automatically
- Device and connection data, such as your IP address, device type, operating system, and browser type.
- Usage data, such as the pages you view, the links you click, the dates and times of access, and the pages that referred you.
- Cookies and similar technologies, as described in our Cookies Policy.
2.4 Information from third parties
We may receive personal data from third parties such as analytics providers, infrastructure and security providers, and partners who help us operate and promote the Services, in each case in accordance with their own terms and applicable law. Where we ask you to provide personal data to comply with a legal requirement or to enter into a contract, and you do not provide it, we may be unable to provide the relevant part of the Services.
3. How we use personal data and the legal bases
We process personal data only where we have a lawful basis to do so under Article 6 of the GDPR. The table below sets out our principal purposes and the corresponding legal bases.
| Purpose | Legal basis |
|---|---|
| Providing, operating, and maintaining the Services | Performance of a contract; our legitimate interests in running the Services |
| Attributing coverage and rewards to the correct station | Performance of a contract; legitimate interests in operating the network fairly |
| Sending updates and communications you have requested | Consent |
| Responding to enquiries and providing support | Legitimate interests; performance of a contract |
| Securing the Services and preventing fraud and abuse | Legitimate interests; legal obligation |
| Measuring and improving the Services | Consent, where required for analytics cookies; otherwise legitimate interests |
| Complying with legal, regulatory, and accounting obligations | Legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms, and you may ask us for more information about that assessment. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Marketing communications
Where you have subscribed to our updates, we send them on the basis of your consent. Every marketing message includes a means to unsubscribe, and you can opt out at any time by following the link in the message or by contacting us. Opting out of marketing does not stop service-related communications that are necessary to operate the Services.
5. Disclosure of personal data
We do not sell your personal data. We disclose it only as described below:
- Service providers and processors who process personal data on our behalf and on our instructions, for example hosting, content delivery, email delivery, analytics, and security providers, subject to appropriate contractual safeguards.
- Professional advisers such as lawyers, auditors, and insurers, where necessary.
- Authorities and other third parties where required to comply with a legal obligation, to enforce our terms, or to protect the rights, property, or safety of any person.
- Acquirers in connection with any merger, reorganisation, financing, or transfer of all or part of our business.
Coverage data contributed to the network may be published, shared, or made available in aggregated, anonymised, or cryptographically signed form. This does not identify you personally.
6. International transfers
We are based in Denmark and seek to process personal data within the European Economic Area (the "EEA"). Where we transfer personal data to recipients outside the EEA, we ensure that an appropriate transfer mechanism is in place, such as an adequacy decision of the European Commission or the European Commission's standard contractual clauses, together with any supplementary measures required. You may request a copy of the relevant safeguards using the contact details in section 13.
7. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, regulatory, or reporting requirements, and to establish, exercise, or defend legal claims. The criteria we use to determine retention periods include the nature and sensitivity of the data, the purposes of processing, and applicable legal requirements. When personal data is no longer required, we delete it or anonymise it so that it can no longer be associated with you.
8. Data security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures may include encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping any credentials confidential.
9. Your rights
Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data:
- Access to a copy of the personal data we hold about you, and related information.
- Rectification of inaccurate or incomplete personal data.
- Erasure of personal data in certain circumstances.
- Restriction of processing in certain circumstances.
- Objection to processing based on our legitimate interests, and to direct marketing at any time.
- Portability, to receive certain personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Withdrawal of consent at any time, where processing is based on consent.
You may exercise these rights by contacting us using the details in section 13. We may need to verify your identity before responding. We will respond within the time limits set by the GDPR, ordinarily within one month, which may be extended for complex or numerous requests. There is normally no charge, although we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive.
10. Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. The network applies automated checks to assess the integrity of contributed data, but these do not constitute solely automated decisions about individuals within the meaning of Article 22 of the GDPR.
11. Children's privacy
The Services are not directed at children under the age of 16, and we do not knowingly collect personal data from them. If you believe that a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post the updated Policy on this page and revise the date shown at the top. Where required by law, we will provide additional notice of material changes or seek your consent.
13. How to contact us and complaints
If you have any question about this Policy, or wish to exercise your rights, please contact us at privacy@mastchain.io, or write to Worldwide AIS Network ApS, Copenhagen, Denmark.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, or with the supervisory authority in your country of residence or place of work.