Privacy Policy
1. Who we are
This website (www.reformdao.com) is operated by HoFiDa Limited, a company registered in Gibraltar under number 123286, with its registered office at Irish Town, GX11 1AA, Gibraltar ("Reform", "we", "us"). HoFiDa Limited acts on behalf of Reform DAO and is the controller of the personal data described in this policy.
For any privacy question or request, contact us at info@reformdao.com.
2. Scope
This policy explains how we handle personal data of visitors to our website, people who contact us or book a meeting, and representatives of (prospective) clients and business partners. We process personal data in accordance with the Gibraltar General Data Protection Regulation and the Data Protection Act 2004 and, where applicable, the EU General Data Protection Regulation (together, "data protection law").
3. What personal data we collect
- Contact details you give us when you email us or book a meeting: name, email address, company, job title and any information you include in your message.
- Meeting data when you schedule a call through our booking page: the date and time you choose and the details you enter in the booking form.
- Client and partner data when we consider or enter into an engagement: names and contact details of representatives, and information needed for know-your-customer (KYC/KYB) and anti-money-laundering checks, such as identity documents, ownership structure and beneficial owners, and sanctions-screening results.
- Technical data when you visit our website: IP address, browser type and pages requested, processed by our hosting provider to deliver and secure the website.
We receive most of this data directly from you. For KYC/KYB and sanctions screening we may also use public registers and screening services.
4. Why we use your data and on what legal basis
- Responding to your questions and scheduling meetings: our legitimate interest in handling enquiries and developing our business, or steps taken at your request before entering into a contract.
- Providing our services and managing the client relationship: performance of a contract.
- KYC/KYB, anti-money-laundering and sanctions checks: compliance with a legal obligation.
- Sending updates about our services to business contacts: our legitimate interest, or your consent where required. You can opt out at any time.
- Operating, securing and improving the website: our legitimate interest in a secure, functioning website.
- Establishing or defending legal claims: our legitimate interest.
5. Cookies
Our website uses only cookies and similar technologies that are strictly necessary for it to function and to be secure. We do not use analytics, advertising or tracking cookies, and we do not use third-party tracking pixels. These necessary cookies do not require your consent. If we introduce other cookies in the future, we will update this policy and ask for your consent before placing them.
Links on our website to third-party services (such as our booking page and social media channels) take you to websites with their own privacy and cookie policies.
6. Who we share your data with
We share personal data only where needed for the purposes above:
- Service providers acting on our behalf (processors), such as our website host (Webflow), our meeting-scheduling provider (Cal.eu), our email provider (Google Gmail), our CRM provider (Attio) and other IT providers. They may only use your data on our instructions and under a data processing agreement.
- Compliance and screening providers that support KYC/KYB and sanctions checks.
- Professional advisers, such as lawyers, auditors and accountants, under a duty of confidentiality.
- Authorities and regulators where we are legally required to do so.
We do not sell your personal data.
7. International transfers
Some of our service providers are located outside Gibraltar, the United Kingdom or the European Economic Area, for example in the United States. Where we transfer personal data to such countries, we rely on an adequacy decision or appropriate safeguards such as standard contractual clauses, as required by data protection law. You can contact us for more information on these safeguards.
8. How long we keep your data
- Enquiries and meeting requests that do not lead to an engagement: up to 2 years after our last contact.
- Client and partner data: for the duration of the relationship and up to 5 years afterwards, or longer where required by law (for example anti-money-laundering rules).
- Technical website data: for a limited period as set by our hosting provider, typically no longer than needed for security and operation.
After these periods we delete or anonymise the data.
9. How we protect your data
We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, such as access controls, encryption in transit and careful selection of service providers.
10. Your rights
Subject to data protection law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to our processing, including for direct marketing;
- receive your data in a portable format;
- withdraw your consent at any time, where processing is based on consent.
To exercise these rights, email info@reformdao.com. We may ask you to verify your identity and will respond within one month.
You also have the right to lodge a complaint with the Gibraltar Regulatory Authority (www.gra.gi) or, if you are in the EU, with the data protection authority in your country of residence. We would appreciate the chance to address your concern first.
11. Changes to this policy
We may update this policy from time to time. The latest version is always available on this page, with the date of the last update at the top.