Privacy Policy
Preamble
This Privacy Policy (this "Policy") sets forth how ATH Labs Ltd., a free-zone company registered in the Abu Dhabi Global Market ("ADGM"), with its registered office at Office 3602, Floor 36, Sky Tower, Shams Abu Dhabi, Al Reem Island, Abu Dhabi, UAE (the "Company"), handles the personal data of users (each, a "User") in connection with the RWA (Real World Asset) trading card platform "DeadStock" (the "Service") operated by the Company on its website (https://deadstock.gg/; the "Website"). As an ADGM company, the Company protects and handles the personal data of Users in accordance with the ADGM Data Protection Regulations 2021. This Policy is a separate document from the Terms of Service of the Service (the "Terms of Service"), but together with the Terms of Service governs the relationship between the Company and the User in connection with the Service. In the event of any inconsistency between this Policy and the Terms of Service with respect to the handling of personal data, this Policy shall prevail. A User shall be deemed to have expressly agreed to all provisions of this Policy by clicking the consent button displayed on the registration screen of the Website. Users who do not agree to this Policy may not use the Service. This Policy has been prepared in English as the original. Where a Japanese-language version or any other language version is also made available, the English version shall prevail in the event of any inconsistency in interpretation between the language versions.
01
Personal Data Collected
The Company collects the following personal data in connection with the provision of the Service.
1. Information Provided by the User
1.1 Account Information
Email address
Account information obtained via third-party authentication services (such as Google Account), including profile information such as email address and display name
Username (optional)
Social media handles and profile links (optional)
1.2 Contact and Delivery Information (only at the time of Redemption)
Name
Delivery address
Telephone number
Country and region
1.3 KYC Information (only where the Company reasonably determines it to be necessary)
Pursuant to Article 10, paragraph 2 of the Terms of Service, the Company may request a User to undergo KYC (Know Your Customer) procedures only where the Company reasonably determines that such procedures are necessary for compliance with applicable law, prevention of misuse, anti-money laundering measures, or other reasonable circumstances. In such procedures, the Company may collect the following information:
Images of government-issued identification documents (such as passports or driver's licenses)
Images of proof-of-address documents (such as utility bills or bank statements)
Photographs (selfies for identity verification)
Date of birth
Other information required for KYC procedures
1.4 Transaction and Service Usage Information
Information related to Invite Codes (acquisition, use, and distribution history)
Pack Purchase history (types and quantities of Packs purchased, opening information)
Information related to Asset Management Services (information on Cards held under the Company's custody)
Buyback history
Redemption history (request history, delivery address, shipping tracking information)
Points/Login Bonus history (balance, grant and use history)
1.5 Communication Information
Content of inquiries to the Company (via email or forms)
Communications with customer support
Communications via optional social media channels
2. Information Collected Automatically
2.1 Wallet-Related Information
Wallet address (automatically generated upon Account registration)
Balances of Digital Twins and cryptoassets in the Wallet
On-chain transaction information via the Wallet
Due to the nature of blockchain technology, Wallet addresses, the holding and transfer history of Digital Twins, and other transaction information are publicly available on the blockchain and viewable by anyone. Such information cannot be technically deleted and shall be retained on the blockchain on a semi-permanent basis.
2.2 Device and Technical Information
IP address
Device information (OS, browser, screen resolution, device type, unique identifiers)
Access logs
General location information inferred from the IP address (at the country and region level)
Browser time zone
2.3 Usage Information
Pages visited, time spent, navigation paths
Feature usage information (Pack opening, Buyback use, Redemption requests, etc.)
Date, time, and frequency of access
2.4 Cookie and Tracking Technology Information
Strictly necessary cookies (session management, authentication, CSRF tokens, etc.)
For details, see Article 9 (Cookies and Tracking Technologies) of this Policy.
3. Information Obtained from Third-Party Sources
3.1 Information from Third-Party Authentication Services
Profile information obtained via Google authentication (such as email address and display name)
3.2 Information from Payment Processors
Transaction information confirmed by payment processors (such as credit card payment, cryptoasset payment, etc.)
3.3 Public Information (only where necessary)
Public information on the blockchain (transaction history, information associated with Wallet addresses)
Public information necessary for sanctions list screening
4. Handling of Special Categories of Personal Data
The Company does not, in principle, intend to collect personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation (collectively, "Special Categories of Personal Data"). However, identification documents submitted in the course of KYC procedures (paragraph 1.3 of this Article) may contain such information, and the Company shall process such information only for the purposes of the KYC procedures.
5. Information Sharing Functions on the Service
The Service may provide functions that allow Users to share Pack opening results and similar content on third-party platforms such as social media. The images and URLs generated for such sharing contain information about Cards (such as Card name, rarity, and Fair Market Value), but do not contain information that personally identifies the User (such as name, username, Wallet address, or email address). Where the User shares such images or URLs on third-party platforms such as social media, the terms of service and privacy policies of such platforms shall apply, and the Company shall not be liable for the handling of information on such platforms.
02
Purposes of Use of Personal Data
The Company uses the personal data collected for the following purposes.
1. Service Provision
Account registration and authentication (including authentication via third-party authentication services)
Automatic generation and management of the Wallet
Issuance and activation of Invite Codes
Processing of Pack Purchases
Asset Management Services (storage and management of physical Cards)
Processing of Buybacks
Processing of Redemptions (including the shipment of physical Cards and KYC procedures)
Grant and management of Points/Login Bonus
Payment processing (via payment processors)
2. Security and Prevention of Misuse
Prevention of unauthorized access to Accounts
Prevention and detection of fraud, money laundering, terrorist financing, and other criminal acts
Prevention of Sybil attacks, bot use, multiple Account acquisition, and other forms of misuse
Prevention of misuse of the blockchain
Detection of forged Digital Twins and Cards
3. Legal Compliance
Compliance with applicable law
Response to legitimate requests from law enforcement authorities, governmental authorities, and courts
Response to requests from regulatory authorities
Response to disputes and litigation
Retention of tax and accounting records
4. Customer Support
Response to inquiries from Users
Resolution of technical issues
Confirmation and handling of Account-related matters
Tracking and handling of Redemption-related matters
5. Service Improvement and Analysis
Analysis of Service usage (at an aggregated level)
Improvement of Service quality
Development of new features
Optimization of user experience
6. Notices from the Company
The Company shall send the following notices to Users in connection with the provision of the Service:
One-Time Password (OTP) for Account Login
For login authentication to the Account, the Company shall send a one-time password to the registered email address.
Other Notices Necessary for the Operation of the Service
The Company may send notices necessary in connection with the provision of the Service (such as transaction confirmations, important notices regarding the Service, and notices in the event of a personal data breach) by means of posting on the Website, sending to the email address provided at the time of registration, display via the dashboard or notification function on the Service, or any other method that the Company reasonably determines.
The above notices are essential for the continued use of the Service and compliance with applicable law, and Users may not, in principle, refuse to receive them.
7. Marketing (upon Future Introduction)
The Company does not currently process personal data for marketing purposes (such as the distribution of email newsletters, the conduct of Promotions and Campaigns, or targeted advertising). If the Company introduces processing for marketing purposes in the future, the Company shall update this Policy and notify Users. Processing for marketing purposes shall, in principle, be based on the User's express consent (opt-in). With respect to communications for marketing purposes (upon future introduction), the User may, at any time, opt out of receiving such communications via the opt-out link in the email, the settings on the Website, or the Contact Information set forth in Article 11 of this Policy. However, the operational notices set forth in paragraph 6 of this Article shall continue to be sent during the User's continued use of the Service.
03
Retention Period of Personal Data
The Company shall retain Users' personal data for the period necessary to achieve the purposes of processing set forth in this Policy, or for the period during which retention is required by applicable law, whichever is longer. In determining the retention period of personal data, the Company shall consider the following factors:
01
The volume, nature, and sensitivity of the personal data;
02
The potential risk of harm from unauthorized use or disclosure;
03
The purposes for which the Company processes the personal data and whether such purposes can be achieved by other means;
04
Requirements under applicable law (such as tax records, AML-related records, and dispute response).
After the achievement of the processing purposes or the termination of the retention obligation under applicable law, the Company shall delete or anonymize the personal data within a reasonable period. However, information recorded on the blockchain (such as Wallet addresses, transaction history, and the holding and transfer history of Digital Twins) cannot be technically deleted due to the nature of blockchain technology and shall be retained on the blockchain on a semi-permanent basis.
04
Disclosure and Sharing of Personal Data with Third Parties
The Company shall disclose or share Users' personal data with third parties only in the following cases.
1. Provision to Service Providers
In connection with the provision of the Service, the Company may engage third-party service providers (collectively, "Service Providers") to process personal data on the Company's instructions for the purposes of operations, development, customer support, payment processing, the storage and shipment of physical Cards, the provision of cloud infrastructure, and similar purposes. The Company has entered into data processing agreements with such Service Providers in compliance with applicable law, and imposes appropriate data protection obligations on such Service Providers. The categories of Service Providers are as follows:
Wallet service providers
Payment processors
Cloud infrastructure providers
Storage and shipment providers for physical Cards
Customer support providers
Development and operations service providers
Professional advisors such as law firms and accounting firms
Marketing and public relations service providers (upon future introduction)
Analytics tool providers (upon future introduction)
Users who wish to obtain information about specific Service Providers may contact the Company using the contact information set forth in Article 11 of this Policy. The Company shall provide information within a reasonable scope and to the extent permitted by applicable law.
2. Provision to Law Enforcement Authorities, Governmental Authorities, and Courts
The Company may, to the extent permitted by applicable law, provide personal data in the following cases:
Where required by legal obligations (such as warrants, orders, or subpoenas);
In response to legitimate requests from law enforcement authorities, governmental authorities, or courts;
Where necessary to protect the rights, property, or personal safety of the Company, the User, or any third party;
Where necessary for the investigation or prevention of fraud, money laundering, or other illegal acts.
3. Business Transfers
In the event of a merger, acquisition, corporate split, business transfer, corporate reorganization, bankruptcy, or liquidation, personal data may be transferred to the successor entity.
4. Sharing Based on the User's Consent
Where the User has expressly consented, the Company may share personal data with third parties within the scope of such consent.
5. Public Information on the Blockchain
As set forth in Article 1, paragraph 2.1 of this Policy, Wallet addresses, transaction history, and the holding and transfer history of Digital Twins are made publicly available on the blockchain. Although this is, rather than "third-party provision," the publication of information as a characteristic of blockchain technology, this is also referenced in this Article for the purpose of ensuring transparency to Users.
6. Voluntary Sharing by the User
As set forth in Article 1, paragraph 5 of this Policy, Users may voluntarily share information through functions such as social media sharing of Pack opening results. Such sharing constitutes the User's voluntary act and does not constitute third-party provision by the Company; however, this is also referenced in this Article for the purpose of ensuring transparency.
05
Cross-Border Transfer of Personal Data
The Company is a free-zone company registered in the Abu Dhabi Global Market (ADGM), and in connection with the provision of the Service, may transfer Users' personal data to the following regions outside the ADGM:
The locations of Service Providers (including the locations of the Service Providers in each category set forth in Article 4, paragraph 1 of this Policy);
The locations of cloud infrastructure (which may be distributed across multiple regions);
The locations of payment processors;
The locations of storage and shipment providers for physical Cards.
In transferring personal data outside the ADGM, the Company shall take appropriate safeguards in accordance with the ADGM Data Protection Regulations 2021 and other applicable laws. Specifically, the Company shall implement transfers based on one of the following mechanisms:
Where the destination region has been recognized as an Adequate Jurisdiction by the ADGM Office of Data Protection, transfers based on such recognition;
Transfers based on Standard Contractual Clauses approved by the ADGM Office of Data Protection or other appropriate contractual safeguards;
Transfers based on the User's express consent;
Other transfer mechanisms permitted by applicable law.
The personal data protection laws of the destination region may differ from those of the User's country of habitual residence. The Company shall take reasonable measures to ensure the level of protection of personal data in the destination region.
06
Rights of Data Subjects
The User has the following rights with respect to its personal data under applicable law.
01
Right of Access
The User may request disclosure of the personal data of the User held by the Company.
02
Right to Rectification
The User may request the rectification of inaccurate personal data or the completion of incomplete personal data.
03
Right to Erasure
The User may request the erasure of its personal data. However, this shall not apply where the Company is under a legal obligation to retain such data, or where the Company has a legitimate business interest in retaining such data. Information recorded on the blockchain (such as Wallet addresses and transaction history) cannot be technically deleted due to the nature of blockchain technology.
04
Right to Restriction of Processing
The User may, in certain circumstances, request the restriction of the processing of personal data.
05
Right to Data Portability
The User may request to receive the personal data the User has provided to the Company in a structured, commonly used, and machine-readable format, or to have such personal data transferred to another controller.
06
Right to Object
The User has the right to object to the processing of its personal data (including processing for direct marketing purposes).
07
Right to Withdraw Consent
Where the Company processes personal data based on consent, the User may withdraw such consent at any time. The withdrawal of consent shall not affect the lawfulness of processing carried out prior to the withdrawal.
08
Right Not to be Subject to Automated Decision-Making
The User has the right not to be subject to a significant decision based solely on automated decision-making. However, the Company does not generally make significant decisions based solely on automated decision-making.
09
Right to Lodge a Complaint with a Supervisory Authority
The User has the right to lodge a complaint with the personal data protection supervisory authority in the User's place of residence. Given that the Company is an ADGM company, the User may also lodge a complaint with the ADGM Office of Data Protection.
10
Right to Opt-Out of Sale or Sharing (for Residents of California, USA)
The Company does not "sell" or "share" Users' personal information (as defined under the California Consumer Privacy Act / California Privacy Rights Act). However, if the Company engages in any processing that is deemed a "sale" or "sharing" under such laws in the future, the User may request to opt out of such processing.
Method of Exercising Rights
The User may exercise the above rights by contacting the Company using the contact information set forth in Article 11 of this Policy. The Company shall, in principle, respond to a request to exercise rights within 30 days of receipt. However, the Company may extend such period in cases involving the complexity of the request, the volume of requests, or other circumstances requiring reasonable consideration by the Company. Where such period is extended, the Company shall notify the User accordingly. The Company may conduct identity verification procedures to confirm that a request to exercise rights is genuinely from the User. If the User does not cooperate in providing the information necessary for identity verification, the Company may refuse to respond to such request. The Company shall, in principle, respond to requests to exercise rights free of charge. However, with respect to requests that are manifestly unfounded, excessively repetitive, or that would cause unreasonable business burden, the Company may charge a reasonable fee or refuse to respond.
07
Security
The Company shall take appropriate technical and organizational measures to protect Users' personal data from unauthorized access, unauthorized use, alteration, leakage, loss, or destruction. These include:
Encryption of communications (such as SSL/TLS);
Access controls (authentication, authorization);
Conclusion of appropriate data processing agreements with Service Providers;
Education and training of employees on personal data protection;
Establishment of a security incident response system.
However, the Company cannot guarantee absolute security in communications via the internet or in the storage of electronic data. The Company shall use reasonable efforts to protect personal data, but shall not be liable for any data leakage caused by circumstances beyond the Company's reasonable control, except where caused by the Company's willful misconduct or gross negligence. In the event of a personal data breach, the Company shall promptly provide the necessary notifications in accordance with applicable law (including the ADGM Data Protection Regulations 2021).
08
Children's Privacy
The Service is intended for Users aged 18 or older, and is not intended for individuals under the age of 18. The Company does not knowingly collect personal data from individuals under the age of 18. Pursuant to Article 3, paragraph 1 of the Terms of Service, the User represents and warrants that the User is at least 18 years of age. If the Company becomes aware that personal data has been collected from an individual under the age of 18, the Company shall promptly take reasonable measures to delete such personal data. If a parent or guardian of an individual under the age of 18 becomes aware that the Company has collected personal data of such individual, please contact the Company using the contact information set forth in Article 11 of this Policy.
09
Cookies and Tracking Technologies
The Company uses cookies and similar tracking technologies (collectively, "Cookies") to the extent necessary for the provision of the Service.
1. Cookies Currently in Use
The Cookies currently used by the Company are limited to those that are strictly necessary for the provision of the basic functions of the Service ("Strictly Necessary Cookies"), as follows:
Session Management Cookies
Used to maintain login status, etc.
Authentication Cookies
Used for authentication via third-party authentication services (such as Google Account)
Security Cookies
Used to prevent CSRF (Cross-Site Request Forgery) attacks, etc.
Strictly Necessary Cookies are essential for the operation of the Service and are not subject to the User's consent. However, the User may refuse to accept Cookies through the User's browser settings. If the User refuses to accept Cookies, all or part of the Service may not function properly.
2. Future Introduction of Optional Cookies
The Company may, in the future, introduce analytics tools, marketing tools, advertising tools, or other optional cookies (collectively, "Optional Cookies") to the Service. Upon such introduction, the Company shall obtain the User's consent as required by applicable law. Upon the introduction of Optional Cookies, the Company shall update this Policy and notify Users. The Company may also separately establish a Cookie Policy for the use of Optional Cookies.
10
Withdrawal Procedures
1. Method of Requesting Withdrawal
The User may request withdrawal (deletion of the Account) using the contact information set forth in Article 11 of this Policy or by other methods designated by the Company (including the prescribed form on the Website).
2. Identity Verification
In connection with a withdrawal request, the Company shall conduct identity verification procedures to confirm that the request is genuinely from the User. If the User does not cooperate in providing the information necessary for identity verification, the Company may refuse to respond to the withdrawal request.
3. Matters to Confirm Before Withdrawal
Before withdrawal, the User is recommended to confirm and address the following matters:
Digital Twins Held
After withdrawal, the User's access to Digital Twins in the Wallet through the Service will be lost. Before withdrawal, please complete Redemption (exchange for physical Cards) or take other necessary actions as appropriate.
Physical Cards under Asset Management Services
After withdrawal, requests for Redemption of physical Cards under the Company's custody may become difficult. Before withdrawal, please complete Redemption as appropriate.
Points Held
Upon withdrawal, the Points held by the User shall expire (in accordance with Article 11, paragraph 4 of the Terms of Service).
4. Handling of Personal Data After Withdrawal
After a withdrawal request is approved, the Company shall handle the User's personal data in accordance with the following policy:
Information to be Deleted
Account information (email address, name, delivery address, etc.), authentication credentials, and Service usage history that are not subject to retention obligations shall be deleted or anonymized within a reasonable period.
Information to be Retained
A portion of the information may be retained based on retention obligations under applicable law or based on the legitimate business interests of the Company, to the extent necessary. This includes tax records, AML-related records, dispute response records, and transaction records of Pack Purchase, Buyback, and Redemption. The retention period shall be in accordance with Article 3 of this Policy.
Information on the Blockchain
Information recorded on the blockchain (such as Wallet addresses, transaction history, and the holding and transfer history of Digital Twins) cannot be technically deleted due to the nature of blockchain technology and shall be retained on the blockchain even after withdrawal.
5. Irreversibility of Withdrawal
After the withdrawal procedure is completed, the Account cannot be restored. The availability of re-registration with the same email address shall be determined based on the Company's operational policies and technical constraints.
11
Contact Information
For inquiries regarding the handling of personal data, requests for the exercise of data subject rights, and other matters relating to this Policy, please contact the Company at the following:
| Operating Entity | ATH Labs Ltd. |
| Registered Office | Office 3602, Floor 36, Sky Tower, Shams Abu Dhabi, Al Reem Island, Abu Dhabi, UAE |
| Contact | contact@deadstock.gg |
| Website | https://deadstock.gg/ |
| Terms of Service | https://deadstock.gg/terms-service |
The Company shall, in principle, respond to inquiries within 30 days of receipt. However, the Company may extend such period in cases involving the complexity of the request, the volume of requests, or other circumstances requiring reasonable consideration by the Company.
12
Modifications to This Policy
01
The Company may, at its sole discretion, modify the content of this Policy from time to time.
02
Where the Company modifies this Policy, the Company shall notify Users of the content of the modified Policy and the effective date by means of posting on the Website, sending to the email address provided at the time of registration, or any other method that the Company reasonably determines.
03
Modifications to this Policy shall adopt the same three-tier classification as Article 27 of the Terms of Service, with the following notification system applied:
Material Modifications (material changes to personal data handling policies, material changes to the scope of third-party provision, or other modifications that materially restrict rights already held by Users): the Company shall notify Users at least 30 days prior to the effective date of the modification.
Modifications Related to New Features or Services (addition of marketplace functionality, addition of new Pack product lines, introduction of analytics tools, addition of new Service Providers, or other modifications that do not materially restrict rights already held by Users): the Company shall notify Users on the effective date of the modification or within a reasonable period thereafter.
Minor Modifications (correction of typographical errors, clarification of expressions, updates to contact information, or other modifications that do not materially restrict rights already held by Users): the Company shall notify Users on the effective date of the modification or within a reasonable period thereafter.
04
Where the User continues to use the Service after the effective date of the modified Policy, the User shall be deemed to have agreed to the modified Policy.
05
Where the User does not agree to the modified Policy, the User may discontinue use of the Service and withdraw in accordance with Article 10 of this Policy.
13
Effective Date
This Policy shall take effect on May 1, 2026. This Policy is the DeadStock Service Privacy Policy v1. Effective Date: May 1, 2026.