Working document prepared for review by the CoC-Legal node. The Spanish version is the controlling text; this English translation is a courtesy. This draft has not been reviewed by an attorney; it requires a Mexican legal opinion and verification against current law before publication. The controller's identification details (full legal name and address) must be completed before publication.
1 — CONTROLLER
1.1 The controller of your personal data is the Cocentrica foundation, domiciled in Mexico ("Cocentrica", "the controller"). Privacy contact: [privacy email to be defined], operated from the cocentrica.org platform.
1.2 This notice is issued under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties and its secondary regulations. Additionally, for users in the European Union and the European Economic Area, we apply the General Data Protection Regulation (GDPR) guarantees described in section 8.
2 — DATA WE COLLECT
2.1 Account and identity data: email, phone, name, display name, public alias, password (stored only as a hash), photo or avatar, email-verification status, and who invited you to the platform.
2.2 Presence profile data: full name, nickname, date of birth, country, and — encrypted at rest with AES-256-GCM — address, phone and personal identification number. You decide, field by field, which of these are shown publicly (granular publication consent).
2.3 Platform operational data: node memberships and levels, per-day node attendance, missions and evidence (including photographs with notes), token movements in the internal ledger, XP points, signature PIN (stored only as a hash), and the identifier of a physical NFC tag if you choose to bind one to your Presence.
2.4 Payment and donation data: bank transaction records imported by nodes (amount, date, counterparty, reference), PayPal receipts (payer email and identifier), payment-processor risk flags, bank details (CLABE or account) you voluntarily provide when requesting a discretionary token buy-back, photographic evidence of cash deposits, and — if you use USDT deposits — the public address and transaction hash you provide.
2.5 AI assistant content: the text of your conversations with the platform's assistants and associated usage records.
2.6 What we do NOT collect: the platform uses no advertising trackers, pixels or third-party analytics. We employ only strictly necessary functional cookies: authentication session, interface preference and active node.
3 — PURPOSES OF PROCESSING
3.1 Primary purposes (necessary for the legal relationship): creating and operating your account and Presence; authenticating and protecting your account; operating node, mission, token and governance mechanics; recording donations and their token visualization for transparency purposes; maintaining the auditable, tamper-evident internal ledger; meeting legal, accounting and fraud-prevention obligations; and sending you operational notices and verification codes.
3.2 Secondary purposes: none. We do not use your data for advertising, commercial profiling or paid disclosure to third parties.
4 — PROCESSORS AND TRANSFERS
4.1 To operate the platform we use the following processors, who process data on the controller's behalf: Resend (email and verification codes), Google (Gemini models for AI assistants; other configurable model providers: OpenAI, DeepSeek, Kimi), Supabase (file storage), Vercel (application hosting and file storage), PayPal (payment processing), and the Etherscan/Polygonscan block explorer (read-only verification of USDT transactions you report).
4.2 Cocentrica's central Kernel service (kernel.cocentrica.org) receives aggregate token counters, node license data and node operating signals.
4.3 We do not sell your personal data or transfer it to third parties for their own purposes. Transfers to the processors above are necessary to provide you the service.
4.4 Processors may be located outside Mexico, mainly in the United States. By using the platform you consent to these transfers, which are carried out with the contractual and technical safeguards described in this notice.
5 — RETENTION
5.1 We retain your data while your account exists and, afterwards, only as needed to meet legal obligations, resolve disputes and preserve ledger integrity. The internal ledger's records are, by design, a tamper-evident chained history: entries documenting donation and token flows are retained in pseudonymized form even after account deletion, being necessary for the Foundation's transparency purpose and the ecosystem's accounting integrity.
6 — SECURITY
6.1 We apply administrative, technical and physical security measures, including: passwords and PINs stored only as cryptographic hashes; AES-256-GCM encryption at rest of address, phone and personal identification number; node payment credentials encrypted at rest; account lockout on failed PIN attempts; a hash-chained ledger; and level-restricted access.
7 — YOUR RIGHTS (ARCO AND RELATED)
7.1 You may at any time exercise your rights of Access, Rectification, Cancellation and Objection (ARCO), as well as revoke your consent and limit the use or disclosure of your data, by request to the privacy contact in section 1. We will verify your identity, respond within the legal deadlines and inform you of the remedies available before the Mexican data-protection authority.
7.2 Cancellation of data does not reach records the law obliges us to retain, nor the pseudonymized ledger records described in section 5.
8 — ADDITIONAL GUARANTEES FOR EUROPEAN UNION USERS (GDPR)
8.1 If you reside in the European Union or the European Economic Area, we additionally recognize your GDPR rights: access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated decisions with legal effects. The platform performs no such automated decision-making and no commercial profiling.
8.2 Legal bases for processing: performance of the contract (Terms and Conditions) to operate your account and the platform's mechanics; compliance with legal obligations; the Foundation's legitimate interest in transparency, fraud prevention and ledger integrity; and your consent for the publication of profile fields and for international transfers.
8.3 International transfers: Mexico has no adequacy decision from the European Commission. Transfers of your data to Mexico and to the listed processors rely on your explicit consent (Article 49(1)(a) GDPR) and on the transfer's necessity for the performance of the contract with you (Article 49(1)(b) GDPR), and you are hereby expressly informed of this.
8.4 You may lodge complaints with your local supervisory authority. The Foundation will evaluate the designation of a representative in the Union under Article 27 GDPR; the representative's details, once designated, will be published in this notice.
9 — MINORS
9.1 The platform is not directed at persons under 18. If we detect a minor's data, we will suspend the account and delete the data we are not obliged to retain.
10 — CHANGES TO THIS NOTICE
10.1 We will publish any change to this notice on the platform, identifying each version with a number and date. Substantial changes will be communicated prominently and, where the law requires, your consent will be obtained anew.