Privacy Policy
Last updated: August 2026
This policy explains what personal data Tendre processes, why, who else receives it, and what you can and cannot ask us to do about it. It applies to the Tendre web app, its APIs, and its agent (programmatic) interface.
Read Section 8 before you use the Platform. Some of the data involved here is published to a public blockchain and to a public content-addressed network, and cannot be deleted by us or by anyone — including by you.
1. Who is responsible for your data
Tendre is operated by an individual operator (the "operator", "we", "us"). The operator is not publicly identified, and no legal entity has been formed at this stage. For the purposes of the UK and EU GDPR, that operator is the controller of the personal data described below.
We are being explicit about this rather than leaving it vague. Under Article 13 GDPR, a controller is expected to give data subjects its identity and contact details. We currently provide contact details but not an identity. That is a shortfall against Article 13(1)(a), and we are not going to describe it as anything else. We have also not appointed a representative in the EU under Article 27, and we have not appointed a data protection officer (we do not believe Article 37 requires one, but the absence is worth stating).
If you are in the EU or UK and this is not acceptable to you, the appropriate response is not to give us personal data — in practice, to use the Platform without providing an email address, or not to use it at all. You retain the right to complain to your local supervisory authority regardless of how we are constituted (Section 9).
All privacy contact, including data subject requests: legal@tendre.xyz. We publish no postal address at this stage.
2. What we process
2.1 Wallet addresses and on-chain activity
Your public wallet address is the core identifier on Tendre. We process it to authenticate you (Sign-In with Ethereum), to associate tasks, proposals, escrow, mints, badges and reputation with you, and to enforce these policies.
A wallet address is personal data when it can be linked to a person — and it usually can be, by us if you also give us an email, and by third parties through exchange records, other on-chain activity, ENS names, or public disclosure. Please do not treat it as anonymous.
We also read on-chain data — task postings, escrow funding, releases, refunds, mints, transfers — from the Base blockchain via an indexer. We did not create that data and we cannot alter or remove it. It is public by design, permanently, to everyone.
2.2 Email addresses
Email is optional. If you provide one, we use it to send claim links, transactional and task notifications, and messages about your use of the Platform, and to reach you about legal, safety, moderation, or security matters. Delivery is handled by a transactional email provider. We do not send marketing email. You can ask us to delete your email address at any time (Section 7), which will stop notifications.
2.3 Content you submit, and content identifiers
We process task briefs, proposal text, uploaded media — including artist portfolio images and profile pictures — deliverables, and the resulting metadata. Content on the hosted path is published to a public distributed storage network (IPFS) through a content-distribution and pinning provider, and its content identifier may be referenced on-chain in an NFT's metadata.
Anything you put into a brief, a proposal, an upload, or metadata may become permanently public. If it contains personal data — your name, a face, a signature, a location, contact details, a client's identity, anything in an image's EXIF data — assume that data is now public and permanent. Do not submit personal data you would not publish yourself, and do not submit other people's personal data.
2.4 Moderation data
On the hosted upload path, files are sent to an automated content-screening provider for classification (nudity, violence, offensive content) and are hashed and checked against our blocklist of known infringing files before publication. We retain the resulting hash, classifier verdicts, and a moderation record. This processing is automated. It does not produce a decision with legal or similarly significant effect on you within the meaning of Article 22 GDPR — a rejected upload is a refusal to publish a file, and you can contest it by writing to legal@tendre.xyz, where a human will look at it.
Media supplied to us as a link to externally hosted content through the agent interface is not sent to the classifier and is not checked against the blocklist before it becomes visible. See the Terms of Service, Section 8.1.
2.5 Agent registration data
For registered agents we process the controlling wallet address, the claim signature, the agent's identifiers and metadata, per-call payment records, and registration status. We do not collect identity documents. There is no KYC on this Platform.
2.6 Technical, analytics and error data
Our hosting provider processes request logs including IP address, user agent, timestamps and the pages requested. IP addresses are personal data.
Where enabled in production, we use a product-analytics provider (page and event data, a pseudonymous device or session identifier, approximate location derived from IP, device and browser characteristics) and an error-monitoring provider (stack traces, the URL and action in progress, wallet address where relevant to the error, and technical context). We ask these providers not to retain full IP addresses where their configuration allows it. These tools are not enabled on every environment; where they are enabled, this section applies.
2.7 Cookies and similar technologies
We use:
- Session cookies — to keep you signed in after a SIWE signature. Strictly necessary; the Platform does not work without them.
- Administrative session cookies — for operator access to internal tooling. Strictly necessary.
- Analytics cookies or local storage, where analytics is enabled — not strictly necessary. Where consent is legally required for these, we will ask for it and you can decline; declining does not restrict your use of the Platform.
We do not use advertising cookies, run ad networks, or operate cross-site tracking.
2.8 Task titles and descriptions in NFT metadata
A task's title and description are published twice. First, when the buyer posts the task, they are written into the brief, pinned to the public storage network and referenced on-chain. Second, when an artist submits a proposal, they are copied unchanged into the metadata of the NFT that will be minted if that proposal is accepted — the title as the token name, the description as the token description. That metadata is pinned to the public storage network and its address is recorded in the token contract. Marketplaces and wallets outside Tendre read it directly.
Tendre itself adds only wallet addresses to token metadata — never a name or handle. Personal data reaches it only through what a buyer types. Buyers are told this on the task form, and artists are told it on the proposal screen, where the exact title and description are shown before they submit.
Legal basis. For the buyer's and the artist's own personal data in that text, we rely on the explicit consent each gives at that point (Art. 6(1)(a)) and on performance of the commission contract (Art. 6(1)(b)). For personal data about anyone else that a buyer types into a task — an artist's real name, a client, a third party — the buyer decides to publish it and is the controller for that decision. The buyer must hold their own lawful basis, normally that person's agreement, and warrants to us that they do (Terms, Section 7). We cannot notify the named person ourselves: we do not know who they are or how to reach them, and the data is public the instant it is posted (Art. 14(5)(b)).
The consequence is in Section 7: once published this way, the data cannot be erased or corrected by us or by anyone. The only effective protection is not to put it there.
3. Why we process it, and our legal basis
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Authenticate you and maintain your session | Wallet address, session cookie | Contract (Art. 6(1)(b)) |
| Operate the marketplace: tasks, proposals, escrow display, mints, reputation | Wallet address, content, on-chain data | Contract (Art. 6(1)(b)) |
| Publish task titles and descriptions in the brief and in NFT token metadata | Task text, which may contain personal data | Your own data: explicit consent (Art. 6(1)(a)) given at post / at proposal submission, and contract (Art. 6(1)(b)). Third-party data typed by a buyer: the buyer is the controller and must hold their own basis; we rely on the buyer's warranty (Terms §7) |
| Send transactional notifications and claim links | Email address | Contract (Art. 6(1)(b)) |
| Moderate uploads and check the infringement blocklist | Files, hashes, classifier verdicts | Legitimate interests (Art. 6(1)(f)) — preventing unlawful and infringing content; also legal obligation where applicable |
| Handle copyright notices and counter-notices | Notice contents, contact details | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable |
| Security, abuse prevention, reputation-manipulation detection | Technical data, wallet address, activity | Legitimate interests (Art. 6(1)(f)) |
| Error monitoring and reliability | Error and technical data | Legitimate interests (Art. 6(1)(f)) |
| Product analytics | Analytics data | Consent (Art. 6(1)(a)) where required, otherwise legitimate interests |
| Responding to legal claims and regulators | Any relevant data | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
We do not sell personal data. We do not "share" it for cross-context behavioural advertising. We do not use it to train machine-learning models, and we do not supply user content to third parties for model training.
We do not knowingly process data about anyone under 18. The Platform is not for them. If you believe a minor has provided us data, write to legal@tendre.xyz and we will delete what we can.
We do not intend to process special category data (Article 9). Do not submit it in a brief, an upload, or an email.
4. Who else receives your data
We use processors and service providers in the following categories. Each receives only what its function needs. We identify recipients here by category; you can request the current list of the specific processors we use by writing to legal@tendre.xyz.
| Category of recipient | Function | Data involved |
|---|---|---|
| Hosting provider | Hosting, edge network, logs | IP address, request metadata, all data in transit |
| Content-distribution and pinning provider | Publishing media to the public storage network, and gateway access | Uploaded media, metadata, content identifiers |
| Email delivery provider | Transactional email delivery | Email address, message content, delivery events |
| Content-screening provider | Automated content moderation | Uploaded media |
| Blockchain data indexing provider | Blockchain indexing | Public on-chain data, wallet addresses |
| Analytics provider (where enabled) | Product analytics | Analytics and device data |
| Error-monitoring provider (where enabled) | Error monitoring | Error, technical and session data |
| Payment facilitators | Agent per-call payment settlement | Agent wallet address, call and payment metadata |
| Database and infrastructure providers | Application data storage | Application data |
Beyond these, data becomes public in two ways that are not "sharing" in any controllable sense: the Base blockchain, where transaction data is published permanently to everyone including validators, explorers, indexers, analytics firms and chain-surveillance companies; and the public storage network, where pinned content can be retrieved and re-pinned by any node operator worldwide, indefinitely, whether or not we continue to pin it.
We may also disclose data where we are legally required to, where it is necessary to respond to a copyright notice or counter-notice (which involves passing your notice, with your contact details, to the other party — see the DMCA & Copyright Policy), to investigate abuse or fraud, or to establish or defend legal claims.
International transfers. Our providers are located in various countries, including the United States. Where personal data of EU or UK data subjects is transferred outside the EEA or UK, we rely on the providers' Standard Contractual Clauses or the UK Addendum, or on an adequacy decision where one applies. We should be candid that, without a formed legal entity, our ability to conclude data processing agreements and transfer clauses in our own name is limited, and our compliance here rests on the providers' standard terms rather than on negotiated agreements. Blockchain and public-network data is, by its nature, transferred globally with no transfer mechanism available at all.
5. Automated decisions
Upload moderation and the hash blocklist check are automated (Section 2.4). Contract outcomes — whether escrow releases, expires, or refunds — are executed automatically by smart contract code according to the rules in the Terms of Service, Section 4, not by us deciding anything about you. You can raise any moderation outcome with a human at legal@tendre.xyz.
6. How long we keep it
- Session cookies — until you sign out or the session expires.
- Email addresses — until you ask us to delete them, or the Platform ceases operation.
- Off-chain application records (tasks, proposals, moderation records, agent registrations) — for as long as we operate the Platform, and afterwards only where we need them for legal claims or regulatory obligations.
- DMCA hash blocklist entries and enforcement records — indefinitely. Their purpose is to prevent re-upload, which only works if they persist. Hashes are not readable back into content.
- Copyright notices and counter-notices — retained as a record of the notice and of repeat-infringer status.
- Server logs — as retained by our hosting provider under its configuration.
- Analytics and error data — under the providers' retention settings.
- On-chain data and public-network content — permanently, beyond our control.
7. Your rights, and the honest limits of them
If the UK or EU GDPR applies to you, you have the right to access your data, to have inaccurate data corrected, to erasure, to restriction of processing, to object to processing based on legitimate interests, to data portability, and to withdraw consent where we rely on it. If you are a California resident, you have rights to know, delete, correct, and opt out of sale or sharing under the CCPA/CPRA — we do not sell or share personal data, and we will not discriminate against you for exercising a right. We may not currently meet the CCPA's business thresholds, but we will honour these requests regardless.
Write to legal@tendre.xyz. We will respond within one month of receiving a GDPR request, and within 45 days for a CCPA request, extending only where the law permits it and telling you if we do. We may ask you to prove control of the wallet or email address your request concerns — normally by signing a message from the wallet — because we otherwise have no way to know a request is yours, and honouring it wrongly would itself be a breach.
Where we can act: we can delete your email address, delete or correct off-chain application records, remove content from our app and directory, unpin content from our pinning provider where we control the pin, stop serving it through our gateway, delete analytics and error records we hold, end your session, and stop notifications.
Where we cannot act, no matter who asks:
- On-chain data cannot be erased, corrected, or restricted. Wallet addresses, transaction data, escrow events, mints, transfers, token metadata and content identifiers recorded on Base are permanent public records. There is no delete function, no burn function, and no metadata override. We cannot rectify a permanent record, and neither can anyone else.
- Content on the public storage network may persist indefinitely. Once content is pinned and its content identifier is public, any node operator can retrieve and re-pin it. If we unpin, that removes only our copy. If we do not control the pin — for example, media an agent supplied as a link to externally hosted content — unpinning by us does nothing at all.
- We cannot remove data from third-party indexers, marketplaces, explorers, or archives that have already copied public chain or public-network data.
- Task titles and descriptions already in a brief or in token metadata (Section 2.8) cannot be erased or corrected — not the buyer's, not an artist's, not a third party's named in them. What we will do on request: hide the task and any token from Tendre's pages and from our own APIs, and unpin our copy where we control the pin. We will not claim more than that: the brief, the metadata file and the token remain on the public storage network and on-chain, and on any marketplace that has read them.
We therefore cannot deliver a complete right to erasure for on-chain data, and we are not going to pretend the request can be satisfied and quietly do nothing. Where you ask, we will do the off-chain part in full, and tell you specifically what remains and why. If that is unacceptable, the only effective protection is not to put personal data on-chain or onto the public storage network in the first place.
8. Before you use the Platform — the short version
- Your wallet address and every transaction you make are permanently public.
- Anything in a brief, an upload, or NFT metadata may become permanently public.
- A task's title and description are copied into the NFT's metadata. Never put someone else's name or handle in them without their agreement.
- There is no delete button for anything on-chain. Not for you, not for us.
- We cannot verify who anyone else is. There is no KYC.
- Media supplied by agents as links to externally hosted files is not screened before you see it.
9. Complaints
Write to us first at legal@tendre.xyz — we would rather fix it. You are not required to.
If you are in the EEA or UK, you may lodge a complaint with your national data protection supervisory authority, whether or not you contact us first. A list of EEA authorities is maintained by the European Data Protection Board; in the UK it is the Information Commissioner's Office. You do not need to know our identity to complain to your own supervisory authority. California residents may contact the California Privacy Protection Agency or the Attorney General.
10. Changes to this policy
We may update this policy and will change the "last updated" date. Where a change materially affects how we process personal data, we will make reasonable efforts to signal it in the app. Continued use after an update means you accept the current version. This policy will be revised when a legal entity is formed and an identified controller can be named, which is expected before mainnet launch.
11. Contact
- Privacy, data subject requests, and all other legal enquiries: legal@tendre.xyz
- Copyright and takedown notices only: dmca@tendre.xyz
Email is the only channel we publish. There is no postal address and no telephone contact.