Data Privacy Policy

IOU Wallet — Version 1.0 — Last updated: 19.01.2026

1. Introduction

This Data Privacy Policy explains how IOU Wallet ("IOU Wallet", "we", "us") collects, processes, and protects personal data in accordance with the General Data Protection Regulation (GDPR).

IOU Wallet is designed to minimise data collection and to process only what is necessary to provide its core functionality.

2. Data Controller

IOU Wallet is the data controller responsible for personal data processed through the platform.

Contact: info@iou-wallet.com

3. Categories of Data Collected

Depending on usage, IOU Wallet may process:

a) Account and Identification Data: Email address, user ID, authentication metadata (e.g. verification timestamps)

b) IOU-Related Data (User-Provided): IOU descriptions, values or reference amounts (if entered), item/service references, timestamps, counterparty identifiers (limited to platform users)

c) Technical and Usage Data: IP address, device/browser type, logs for security/reliability, error/performance metrics

d) Settlement References (If Used): third-party transaction identifiers, settlement timestamps

IOU Wallet does not receive or store payment credentials, private keys, or bank details.

4. Data Visibility and Access

a) User Visibility: IOU data is visible only to users explicitly involved in that IOU. No IOU content is publicly visible by default.

b) Internal Access: Staff access is restricted to what is necessary for maintenance, support, and security. IOU content is not reviewed, analysed, or used for profiling.

5. Purpose of Processing

Data is processed to provide IOU recording and acknowledgment functionality, enable optional settlement redirection, ensure platform security and integrity, and comply with legal obligations. IOU Wallet does not process personal data for advertising or resale.

6. Legal Basis (GDPR Art. 6)

Processing is based on performance of a contract (service provision), legitimate interest (security and abuse prevention), and user consent where applicable (e.g. optional analytics).

7. Data Sharing and Third Parties

Unless explicitly stated or required for a specific feature, IOU Wallet does not share personal data with third parties during the beta phase.

Where sharing occurs, it is limited to infrastructure providers (hosting/security), settlement providers only when a user initiates settlement, and authorities where legally required. IOU Wallet does not sell personal data.

8. Data Retention

Data is retained only as long as necessary to provide the service, meet legal obligations, and resolve security or integrity issues. Users may request deletion, subject to applicable legal requirements.

9. User Rights

Users have rights to access, rectify, erase, restrict/object, and portability, and to lodge a complaint with a supervisory authority. Requests: info@iou-wallet.com

10. Security Measures

IOU Wallet implements appropriate technical and organisational safeguards, including access controls, encryption in transit, secure hosting, and monitoring. No system can guarantee absolute security.

11. Changes to This Policy

We may update this policy to reflect product or regulatory changes. Material changes will be communicated appropriately.