Section 1Who we are
This policy explains how Bluemetal Services Pty Ltd (ACN 701 330 627), the Australian proprietary company that operates “Cobault” (“Cobault”, “we”, “us”, “our”), handles personal information.
| Legal entity | Bluemetal Services Pty Ltd |
|---|---|
| ACN | 701 330 627 |
| Registered office | Level 2, 179 St Georges Terrace, Perth WA 6000, Australia |
| Ultimate holding company | Chain Capital Technologies Ltd, registered in England and Wales, company number 16081911, Hop Fields, 4 Tongham Road, Runfold, Farnham, Surrey GU10 1PH, United Kingdom |
| Privacy contact | privacy@cobault.io |
We operate the Cobault platform: the websites at cobault.io and cobault.net, the web application at wrap.cobault.io, and the associated APIs and services (together, the Platform).
For the purposes of the Privacy Act 1988 (Cth) we act as an APP entity. Where the EU General Data Protection Regulation or the UK GDPR applies to our processing, we act as a data controller.
This policy applies worldwide. It does not apply to any third-party website, wallet, exchange or service you reach from the Platform, each of which has its own privacy practices.
Section 2Summary
This is a summary only. The detail follows, and prevails.
- Cobault lets you create shared multisignature Bitcoin vaults with people you choose. We collect the minimum needed to do that: an email address or social login identifier, Bitcoin public keys, vault records, and technical data such as IP address.
- We never collect, hold, or have any means of recovering your seed phrase or private keys. In a shared vault, Cobault holds no key at all.
- If someone wants you in their vault, they send you a claim link themselves, through a channel of their own. We hold nothing about you until you use it — see section 5.
- Vault activity is written to the Bitcoin blockchain, which is public, global and permanent. We cannot alter or delete it. Section 9 explains this and you should read it before depositing.
- We do not sell personal information and do not disclose it for third-party advertising. Our public marketing pages ask you first, then — only if you agree — use Google Analytics to measure visits in aggregate and set one first-party cookie that tells us which marketing link brought a mailing-list signup — see section 8; the signed-in Platform carries no analytics or advertising trackers.
- If you ask for company updates on one of our public websites, we use your email address for that and nothing else. It is optional, it is separate from any Cobault account, and you can unsubscribe at any time — see section 17.1.
- Our infrastructure is primarily in the United Kingdom; we are established in Australia. Section 11 covers cross-border transfers.
- You have rights over your information. Section 15 explains how to exercise them; section 9.4 explains the limits the blockchain imposes.
- Contact us at privacy@cobault.io.
Section 3What Cobault does, in privacy terms
A shared vault is a Bitcoin address controlled by an m-of-n multisignature script. The keys belong to the participants — you and the people you choose. Cobault provides the coordination layer: it helps you assemble the participant set, construct the script, collect signatures on proposed spends, and track the vault on-chain.
Cobault holds no key to any shared vault. Our role is coordination and record-keeping only. We cannot sign, and cannot move funds under any circumstances.
Section 4The information we collect
4.1 Information you give us
| Category | Examples | When |
|---|---|---|
| Account identifiers | Email address; where you use a social or passwordless login, the identifier and basic profile returned by that provider — typically email address, name where supplied, provider user ID, and login type | Registration |
| Bitcoin public key material | Extended public keys, per-vault public keys, your identity public key, and the addresses derived from them | Registration and vault creation |
| Vault configuration | Vault name, the quorum you choose (m of n), participant slots | Vault creation |
| Slot labels | Optional short labels you type to tell a vault’s invitation slots apart, visible to everyone in the vault | Vault creation |
| Withdrawal details | Destination addresses and amounts you propose | Each withdrawal |
| Communications | Support requests, correspondence, feedback | As you send them |
| Preferences | Notification and interface preferences | As you set them |
| Mailing-list subscription | The email address you type into the “Keep in touch” form, and the time you submitted it | When you ask for company updates on cobault.io or cobault.net — optional, and not connected to any account |
| Marketing-link click identifier | A random identifier that carries no name and no contact details, generated by our link-attribution provider when you follow one of our short marketing links | When you reach cobault.io or cobault.net through one of our short marketing links — see section 8 |
4.2 Information generated by your use of the Platform
| Category | Examples |
|---|---|
| Vault records | Vault identifiers and state history, participant records, quorum, multisignature descriptor, acceptance and sealing records |
| Transaction records | Proposed and partially signed Bitcoin transactions, collected signatures, broadcast records, timestamps |
| On-chain identifiers | Vault addresses, transaction identifiers, deposit and destination addresses (see section 9) |
| Authentication records | Sign-in events, signed authentication challenges, session records, claim-link and invitation-event records, key-fingerprint records used to restore access to your vaults |
| Technical data | IP address, approximate location derived from IP address, browser and device type, operating system, language, referring page, and your interactions with the Platform |
| Security data | Access logs, error and audit logs, rate-limit and abuse-detection records |
4.3 Information we receive from others
| Source | Information |
|---|---|
| Authentication provider (embedded wallet, social or passwordless login) | Your provider user identifier, email address where available, login type, authentication tokens |
| Email delivery provider | Delivery, bounce and complaint records for messages we send you |
| Marketing email platform | Delivery, bounce, complaint and unsubscribe records for company updates we send to our mailing list |
4.4 What we never collect
We do not collect, receive, store or have any means of recovering:
- your seed phrase or recovery phrase;
- your private keys, including your vault signing key, your identity key and your personal wallet key;
- your credentials for any third-party login provider.
These are generated and held in your own browser or device. If you lose them we cannot restore them and we cannot recover your Bitcoin.
4.5 Sensitive information
We do not seek sensitive information (as defined in the Privacy Act 1988 (Cth)) or special category data (Article 9 GDPR), and none is required to use shared vaults. Please do not send it to us.
4.6 Children
The Platform is not offered to, and must not be used by, anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Section 5If you were sent a claim link to join a vault
This section is the information required by Article 13 of the GDPR and UK GDPR, and by Australian Privacy Principle 5, where we collect your personal information directly from you.
- How you came to be here, and what we knew about you before. A participant in a shared vault created a claim link and sent it to you themselves — by message, email or any other channel of their own. The link is anonymous: it carries no name and no address, it is not addressed to anybody, and we are not told who it was sent to. Cobault does not send invitations and holds no information about you until you use the link. We did not obtain your details from the person who sent it, or from a public source, a data broker or a list.
- What the vault record holds before a link is used. Only the slot the link belongs to: a one-way hash of the link, the time it expires, and an optional short label the vault’s creator typed to tell their own slots apart. No email address, no name, nothing about the person the link was sent to.
- What we collect when you use the link. The email address or social login identifier of the Cobault account you sign in with, the public key your browser generates for the vault, the times you consent and sign, and the technical and security data in section 4.2. Your signing key itself never leaves your browser — see section 4.4.
- Why we collect it, and our lawful basis. To add you to the vault as a participant, record your public key, collect your signatures and notify you of vault events. Our lawful basis is performance of a contract with you (Article 6(1)(b)) from the point you join, together with our legitimate interests (Article 6(1)(f)) in securing the Platform against abuse. Section 6 sets out every purpose.
- Who else sees it. The other participants in the vault — they will see the email address on your account, your public key, and the fact and timing of your acknowledgements and signatures, and you will see theirs. A shared vault cannot be joined anonymously as against your co-participants. The person who created the vault is also emailed your account email address at the moment you claim the slot, so they can check that the link reached the person they meant it for. Before you join, the accept screen shows you the email address on the creator’s own account. Our cloud hosting and email delivery providers are listed with everyone else in section 10.
- Where it goes. Our infrastructure is in the United Kingdom and we are established in Australia, so your information is transferred internationally. Section 11 sets out the safeguards.
- Whether you have to provide anything. You do not. Joining a vault is entirely voluntary. If you do join, a Cobault account identifier and a public key become a contractual necessity — a vault cannot include a participant without them.
- If you decide not to join. Close the page. Nothing about you is recorded, there is nothing for you to delete, and the link simply goes unused until it expires — by default 7 days after it was created, and never more than 30 days. We cannot tell the person who sent it anything about you, only that the slot is still unclaimed. Ordinary security records of the request, such as an IP address and a timestamp, are kept for the period in section 12.
- Your rights. Once you have joined, every right in section 15 applies, and section 9.4 explains the limit the blockchain places on erasure. You may complain to a data protection supervisory authority at any time; section 17.2 lists them. Our identity is in section 1, and our representatives in the European Union and the United Kingdom under Article 27 are in section 20.
If you are the person creating a vault and sharing a link: a claim link is a bearer credential — whoever holds it can take that slot, once, until it is used or expires. Send it only through a channel you trust and only to the person you intend to have it. We cannot see where you sent it and cannot recall it, though you can regenerate a slot’s link, which cancels the previous one, or remove a slot that has not yet been claimed. Anyone who opens the link will see the email address on your account. Please do not type another person’s name, email address or other details into a slot label: labels are shown to every participant on the vault roster, and a label is the one place information about somebody who is not a participant could end up in a vault record that has no need for it.
Section 6Why we use your information, and our lawful basis
Where the GDPR or UK GDPR applies, we must have a lawful basis for each purpose. The table sets out both.
| Purpose | Information used | Lawful basis (EU / UK GDPR) |
|---|---|---|
| Create and administer your account; authenticate you | Account identifiers, authentication records, identity public key | Contract (Art 6(1)(b)) |
| Construct shared vaults; coordinate participants; assemble and relay signatures | Public key material, vault configuration, participant records, transaction records | Contract (Art 6(1)(b)) |
| Create and manage vault claim links; record invitation events | Slot records and labels, invitation-event records, claim timestamps | Contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) — securing an invitation mechanism against abuse |
| Track vaults on-chain and notify participants of deposits, proposed withdrawals, quorum status and broadcasts | Vault addresses, transaction records, email address | Contract (Art 6(1)(b)) |
| Provide customer support | Communications, account and vault records | Contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) |
| Secure the Platform; detect, investigate and prevent fraud, abuse and unauthorised access | Technical data, security data, authentication records | Legitimate interests (Art 6(1)(f)) — protecting the Platform and its users; legal obligation (Art 6(1)(c)) |
| Restrict access from jurisdictions we do not serve | IP address, derived location | Legitimate interests (Art 6(1)(f)) — regulatory compliance; legal obligation (Art 6(1)(c)) |
| Maintain records, accounts and audit trails | Account, vault and transaction records | Legal obligation (Art 6(1)(c)); legitimate interests (Art 6(1)(f)) — establishing and defending legal claims |
| Understand how the Platform is used and improve it | Technical data, security data | Legitimate interests (Art 6(1)(f)) |
| Send company updates to people who join our mailing list | Email address, subscription and unsubscribe records | Consent (Art 6(1)(a)) |
| Tell which marketing link a mailing-list subscription came from | Marketing-link click identifier, email address | Consent (Art 6(1)(a)) |
| Send you other marketing about Cobault, should we ever do so | Email address, marketing preferences | Consent (Art 6(1)(a)); legitimate interests (Art 6(1)(f)) for limited marketing to existing users, subject to objection |
| Comply with legal process; respond to regulators, law enforcement and courts | Any relevant information | Legal obligation (Art 6(1)(c)) |
| Group reporting and governance | Account and vault records, aggregated data | Legitimate interests (Art 6(1)(f)) |
Where we rely on legitimate interests we have assessed that our interest is not overridden by your interests, rights and freedoms. You may request a summary of that assessment.
Where we rely on consent you may withdraw it at any time; withdrawal does not affect the lawfulness of prior processing.
Australia. Under Australian Privacy Principle 6 we use and disclose personal information for the purpose of collection, for a directly related secondary purpose you would reasonably expect, with your consent, or as required or authorised by law.
Section 7Automated decision-making
Some decisions on the Platform are made, or substantially assisted, by automated systems using your personal information.
| Decision | How it is made | Information used | Effect |
|---|---|---|---|
| Jurisdictional access restriction | Automated, based on the location derived from your IP address | IP address, derived location | Access to some or all of the Platform is blocked |
| Security, fraud and abuse controls | Automated rules and rate limits | Technical data, security data, authentication records | Requests throttled; in serious cases access suspended pending human review |
We do not use automated processing to profile you for advertising, credit scoring or pricing.
Your rights. Where the GDPR or UK GDPR applies and a decision produces legal effects concerning you or similarly significantly affects you, you have the right under Article 22 to obtain human intervention, to express your point of view and to contest the decision. Contact us and a person, not a system, will review it.
Australia. This section is also provided to meet the automated decision-making transparency requirements introduced into Australian Privacy Principle 1 by the Privacy and Other Legislation Amendment Act 2024 (Cth), which take effect on 10 December 2026.
Section 8Cookies, local storage and similar technologies
We keep this simple, because there is little to disclose:
- Cobault sets no cookies of its own on the user-facing Platform. Your signed-in session is held in your browser’s memory for the life of the page, not in a cookie.
- Our authentication provider (the embedded wallet service that operates social and passwordless login) sets a cookie and browser-storage entries on wrap.cobault.io to keep its login session alive for up to 30 days. These are strictly necessary for the sign-in method you chose and are set without consent on that basis.
- Local storage on your device holds application state, such as the list of your vaults and interface preferences.
- Your encrypted key material is held in your browser’s storage. That is not a tracking technology; it is how self-custody works. Clearing your browser storage without having backed up your seed phrase may permanently cut you off from your Bitcoin.
- We use no advertising cookies, no cross-site tracking and no profiling technologies on any surface, and no analytics of any kind on the signed-in Platform.
- Our public marketing pages (the informational websites at cobault.io — including this page — and cobault.net) use Google Analytics 4 to measure visits in aggregate. Both sites report into a single analytics stream, so one visit that moves between them is counted once rather than twice. It sets first-party
_gaand_ga_*cookies (lifespan up to 24 months) and sends usage data — pages viewed, referrer, device and browser type, and an approximate location derived transiently from your IP address — to Google LLC, which processes it on our behalf. Google Analytics 4 does not record your IP address, and Google’s advertising features, remarketing and ads signals are disabled. You can block or delete these cookies in your browser, or install Google’s opt-out browser add-on; the pages work identically without them. - Our public marketing pages also set one first-party attribution cookie. If you reach cobault.io or cobault.net through one of our short marketing links — a link we place in an article or a social post, for example — that link passes a random click identifier in the web address. We keep it in a
dub_idcookie for up to 90 days, and if you go on to join the mailing list from that browser we send it with your email address to our link-attribution provider, so that we can tell which link brought you. The identifier is a random string: it carries no name, email address or account, we do not use it to build a profile or to follow you across other websites, and we do not advertise to you. Blocking or clearing the cookie costs us the attribution and nothing else — the pages and the signup form work identically without it.
We ask before setting any analytics or attribution cookie, in every jurisdiction — through the banner described in our Cookie Notice — and refusing is as easy as accepting.
Section 9Blockchain data — please read this carefully
Cobault operates on the Bitcoin blockchain. The privacy consequences are different from an ordinary online service, and they cannot be undone.
9.1 What goes on-chain
When a shared vault is funded, the following become part of the public Bitcoin blockchain:
- the vault address and the multisignature script that controls it — which reveals the quorum and the number of participants;
- the funding transaction, including the source addresses of the Bitcoin deposited;
- every transaction spending from the vault, including destination addresses, amounts, and which participants’ keys signed it;
- the timing of all of the above.
9.2 On-chain data is public, global and permanent
The Bitcoin blockchain is a public ledger replicated across tens of thousands of computers worldwide. Once data is confirmed on it:
- anyone in the world can read it, without asking us or you;
- it cannot be edited, deleted, redacted or recalled — not by us, not by you, and not by any court order directed at us;
- it will remain readable for as long as the Bitcoin network exists.
We read the blockchain through Bitcoin nodes we operate ourselves; we do not send your addresses to third-party blockchain data services.
9.3 On-chain data may identify you, and may reveal your co-participants
A Bitcoin address is not, on its face, a name. But an address or transaction becomes personal information — and, under the GDPR, personal data — where it can be linked to a person by means reasonably likely to be used. That linkage can arise from information we hold, from information an exchange holds, from blockchain analytics, or from something a participant discloses.
Shared vaults carry a specific additional exposure: a multisignature spend reveals which of the participant keys signed. Anyone analysing the chain can therefore observe patterns of who in a group acts, and when. If the membership of the group is known or guessable, this is meaningful information about identifiable people.
Assume that on-chain activity can be linked to you and to the people you share a vault with, and act accordingly.
9.4 What this means for your right to erasure
We follow the European Data Protection Board’s Guidelines 02/2025 on processing of personal data through blockchain technologies.
- We do not write personal data to the blockchain in plain text. What appears on-chain is limited to what the Bitcoin protocol requires: addresses, scripts, amounts and transaction structure.
- Identity information is held off-chain, not on the ledger.
- When you exercise a valid right to erasure, we delete or irreversibly destroy the off-chain records and identifiers that link you to on-chain data, so that on-chain data can no longer reasonably be attributed to you by us. That is how erasure is given effect against an immutable ledger.
- We cannot delete the on-chain data itself. No one can. We do not claim technical impossibility as a general excuse for non-compliance — we claim it only for the ledger, and we mitigate it by minimising what goes on-chain and destroying the off-chain linkage.
Two limits you should understand before you rely on this.
Retention. Some records — vault contracts, transaction records and account records — are retained for the periods in section 12 to meet record-keeping obligations and to establish, exercise or defend legal claims. Where a retention obligation applies, we restrict the record rather than delete it, and we destroy the linkage at the end of the retention period rather than on the date of your request. We will tell you which of your records this applies to and when the period ends.
Shared records. A shared vault’s record is also your co-participants’ record. While the vault subsists, your public key, the multisignature descriptor and your recorded signatures cannot be removed — they are the structure of the vault itself, and deleting them would destroy other people’s access to their Bitcoin. We rely on Article 17(3)(b) and (e) of the GDPR, and on the corresponding position in the other regimes we are subject to, in retaining them. We will remove your email address and contact details, and we will delete everything else, but we will not be able to sever the link between you and the vault entirely while it exists. If that matters to you, consider it before you join a vault.
Section 10Who we share your information with
We do not sell personal information and do not disclose it to third parties for their own marketing.
| Recipient | What they receive | Why |
|---|---|---|
| Other participants in a vault you join | Your account email address, any label the vault’s creator applied to your slot, your public key, your acceptance status, and the fact and timing of your signatures | Because a shared vault is a shared record — you cannot participate anonymously to your co-participants |
| Chain Capital Technologies Ltd and group companies | Account, vault and aggregated data on a need-to-know basis | Group management, governance, financial reporting, shared professional services |
| Cloud infrastructure and hosting providers | All Platform data, encrypted at rest and in transit | To run the Platform |
| Authentication and embedded wallet providers | Login identifiers, email address, authentication events, and the technical signals their sign-in flow’s bot-protection checks | To sign you in and support browser-held key generation |
| Email delivery provider | Email address, message content, delivery and bounce records | To send vault notifications |
| Marketing email platform | The email address you gave us for company updates, your subscription status, and the delivery, bounce and unsubscribe records for messages we send to the list | To operate the company-updates mailing list you asked to join |
| Workflow automation provider | The email address you submit through the “Keep in touch” form | To carry your subscription from the website form to the marketing email platform |
| Marketing-link attribution provider | The email address you submit through the “Keep in touch” form, and the click identifier of the marketing link that brought you, where there was one | To tell which marketing link a subscription came from, so we can judge which placements are worth repeating |
| Professional advisers — lawyers, auditors, accountants, insurers | Information relevant to the engagement | Advice, audit and insurance |
| Regulators, law enforcement, courts and government agencies | Information we are required or authorised to disclose | Legal compliance; establishing, exercising or defending legal claims |
| An acquirer or investor in a sale, merger, financing or restructure | Information relevant to the transaction, under confidentiality | To complete the transaction; you will be notified of any change of controller |
| The public Bitcoin network | On-chain transaction data — see section 9 | Because Bitcoin is a public network |
Service providers act on our documented instructions under written contracts requiring confidentiality, appropriate security and, where the GDPR applies, terms compliant with Article 28.
Section 11Where your information is held
Our primary infrastructure is hosted in the United Kingdom (London region). Certificate management and edge-security control services run in the United States, and website content is delivered through edge locations in North America, Europe and Israel. We are established in Australia. Our parent company is in the United Kingdom. Personal information is therefore transferred across borders as a matter of course.
11.1 Australia — cross-border disclosure
Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients do not breach the Australian Privacy Principles, by contract, by provider due diligence, and by technical controls.
The countries in which overseas recipients are likely to be located are: the United Kingdom, the United States, European Union member states, and Israel.
Where we disclose personal information overseas in reliance on Australian Privacy Principle 8.1, section 16C of the Privacy Act 1988 (Cth) makes us accountable to you for the acts and practices of the overseas recipient as if they were our own.
11.2 European Economic Area and United Kingdom — international transfers
Australia is not the subject of an adequacy decision by the European Commission or the UK Secretary of State. Where we transfer personal data from the EEA or the UK to a country without an adequacy decision, we rely on the following, supported in each case by a transfer impact assessment and, where indicated, supplementary technical and organisational measures including encryption in transit and at rest.
Transfers to service providers. Where the recipient is a service provider whose own processing is not itself subject to the GDPR, we rely on the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in the applicable module. For transfers from the United Kingdom we use the International Data Transfer Agreement or the UK Addendum to those clauses.
Our own access from Australia. Where we are directly subject to the GDPR and UK GDPR under Article 3(2) in respect of EU and UK users, the Standard Contractual Clauses are not available for personal data moving between our own systems in the United Kingdom and Australia — they are drafted for importers not themselves caught by the Regulation, and the European Commission has not yet adopted the additional module intended for importers who are. For those flows we have assessed our position under Chapter V of the GDPR, applied the same technical and organisational safeguards, and documented the assessment.
Where a recipient is in an adequate country, we rely on that adequacy decision. You may request a copy of the safeguards we rely on; we may redact commercially confidential terms.
Section 12How long we keep your information
| Information | Retention |
|---|---|
| Account and profile records | Life of your account, then 7 years from closure |
| Shared vault records, participant records and transaction records | 7 years from closure of the vault, or from your ceasing to be a participant, whichever is later |
| Unclaimed vault slots and used or expired claim links | Kept with the vault record they belong to, for the period in the row above. A slot nobody claims holds no personal information — only a one-way hash of the link, the time it expires, and any label the vault’s creator typed. See section 5 |
| Records of vault invitation events — a slot created, a link regenerated, a slot claimed, cancelled or declined | 7 years, matching the vault record. These entries identify the participant who acted by their public key; they never record the link, or anything about a person who has not joined |
| Support correspondence | 3 years from resolution |
| Security, access and audit logs | 12 months, except where retained for an active investigation |
| Email delivery, bounce and complaint records | 24 months |
| Website analytics (marketing pages only) | Event data is retained in Google Analytics for up to 14 months; the analytics cookies themselves expire after at most 24 months — see section 8 |
| Mailing-list subscription | Until you unsubscribe, or until we close the list |
| Marketing-link click identifier | The cookie expires after at most 90 days. Where a subscription was attributed to a link, that attribution record is kept with the mailing-list record for as long as the row above |
| Marketing preferences and suppression lists | Indefinitely, so we can honour your opt-out |
| On-chain data | Permanent and beyond our control — see section 9 |
Retention periods reflect limitation periods for legal claims and Australian record-keeping obligations, including under the Corporations Act 2001 (Cth) and taxation law.
Section 13How we protect your information
In summary:
- Self-custody by design. Your keys are generated and held in your browser or device. We hold no key to any shared vault and cannot move your Bitcoin under any circumstances.
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Access control. Least-privilege access, multi-factor authentication for personnel, logged and reviewed administrative actions.
- Independent review. An independent security firm, Halborn, assessed the Platform in mid-2026; its findings and their remediation are tracked internally.
No system is perfectly secure. You are responsible for protecting your seed phrase, your device and your login credentials. We will never ask you for your seed phrase or private keys, by any channel, for any reason. Any message that does is fraudulent.
Section 14Data breaches
If a data breach occurs that is likely to result in serious harm, we will:
- notify the Office of the Australian Information Commissioner and affected individuals as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth);
- notify the relevant supervisory authority within 72 hours where the GDPR or UK GDPR applies, and affected individuals where the breach is likely to result in a high risk to their rights and freedoms;
- notify the Personal Data Protection Commission of Singapore within 3 calendar days of assessing a breach as notifiable, and affected individuals as required;
- notify the Office of the Privacy Commissioner of Canada and affected individuals where a breach creates a real risk of significant harm;
- notify other regulators and individuals as required in any other affected jurisdiction.
Section 15Your rights
15.1 Rights we extend to everyone
- Access — a copy of the personal information we hold about you.
- Correction — to have inaccurate or incomplete information corrected.
- Deletion — subject to section 9.4 (blockchain), section 9.4’s shared-record limit, and records we must retain by law.
- Marketing opt-out — at any time.
- Complaint — to us, and to a regulator.
15.2 Additional rights under the EU and UK GDPR
- Restriction of processing in defined circumstances.
- Portability — to receive information you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection to processing based on legitimate interests; and an absolute right to object to direct marketing.
- Withdrawal of consent at any time.
- Human review of automated decisions — see section 7.
- Complaint to a supervisory authority — see section 17.
15.3 Additional rights in other jurisdictions
- Australia — access and correction under Australian Privacy Principles 12 and 13, and the right to deal with us anonymously or by pseudonym where lawful and practicable (Australian Privacy Principle 2). See section 16.
- Singapore — access, correction and withdrawal of consent under the Personal Data Protection Act 2012.
- Hong Kong — data access and correction requests under sections 18 and 22 of the Personal Data (Privacy) Ordinance. We may charge a fee that is not excessive.
- Canada — access, challenge to accuracy, and challenge to our compliance, under the Personal Information Protection and Electronic Documents Act.
15.4 How to exercise a right
Write to privacy@cobault.io. We will:
- acknowledge promptly;
- verify your identity — normally by asking you to sign a challenge with the key associated with your account, or by other reasonable means;
- respond within 30 days (Australia, Singapore, Canada), one month (EU and UK GDPR, extendable by two further months for complex requests, with notice), or 40 days (Hong Kong);
- tell you if we cannot comply, and why.
No charge for a first request. We may charge a reasonable, non-excessive fee for repetitive or manifestly unfounded requests where the law permits.
Section 16Anonymity and pseudonymity
You may browse the public Cobault websites without identifying yourself. To create an account we need an email address or a social login identifier, because vault coordination depends on being able to reach you — an unreachable participant can freeze a vault for everyone in it. Within a vault, the other participants will see the email address on your account, together with any label the vault’s creator typed for your slot. The Platform does not use separate display names. If you prefer not to be identified by your address, use an address that does not name you — the choice of account email is yours.
Whether you have to give us information. Providing an email address or social login identifier and a Bitcoin public key is a contractual requirement — we cannot create an account or include you in a vault without them, and if you do not provide them we will be unable to offer you the Platform. Everything else in section 4.1 is voluntary, and declining it affects only the feature concerned. There is no statutory requirement to provide any of it: the choice is whether to use the Platform.
Section 17Marketing and complaints
17.1 Marketing
Every email the Platform sends is transactional — it exists to operate your account or a vault you are part of. We have not yet sent a marketing email to anybody.
Our company-updates mailing list. Our public websites at cobault.io and cobault.net invite you to leave your email address to hear about what we build. That list is optional and consent-based, and it is separate from your Cobault account: we will not add your account email address to it because you registered, created a vault or were sent a claim link, and joining it is never a condition of using the Platform. Every message we send to the list carries a free, simple unsubscribe.
Marketing we send — to that list or otherwise — will only go where you have consented, or where you are an existing user and the law permits marketing on the basis of that relationship. Every marketing message will identify us, give current contact details, and contain a free, simple unsubscribe. We will action unsubscribes:
- within 5 business days (Australia, Spam Act 2003 (Cth));
- without undue delay (EU and UK);
- within 10 business days (Canada, CASL);
- promptly and free of charge (Singapore and Hong Kong).
Hong Kong. We will not use your personal data in direct marketing without first notifying you of the kinds of data to be used and the classes of goods, services and facilities to be marketed, and obtaining your consent. You may require us to cease at any time, at no charge.
Singapore. We do not collect telephone numbers and do not send marketing calls or text messages. If that changes, we will check the Do Not Call Registry before sending marketing messages to Singapore telephone numbers.
17.1a Claim links and vault notifications
Claim links are created and shared by vault participants themselves, not by us — Cobault does not send invitations. The only message we send about a claim link is the slot-claimed notice to the vault’s creator when someone uses their link, which is a vault notification like any other.
Vault notifications — slot claims, activation signatures, proposed and broadcast withdrawals, and security events — are sent while you hold a position in a live vault regardless of your preferences. They carry information you need in order to protect your Bitcoin, and you cannot opt out of them while your key is part of a funded vault. You can end them by leaving the vault.
Neither is marketing, and we do not treat either as a route to it.
17.2 Complaints
Start with us. Write to privacy@cobault.io. We will acknowledge within 5 business days and respond substantively within 30 days.
If you are not satisfied, you may complain to a regulator:
| Where you are | Regulator |
|---|---|
| Australia | Office of the Australian Information Commissioner — oaic.gov.au — 1300 363 992 |
| United Kingdom | Information Commissioner’s Office — ico.org.uk — 0303 123 1113. You may also raise the matter through our UK representative, GDPR Local Ltd, at bluemetalservicesptyltd.gdprlocal.com/uk (section 20) |
| European Economic Area | Your national supervisory authority, or the authority where you live, work, or where the alleged infringement occurred. You may also raise the matter through our EU representative, Instant EU GDPR Representative Limited, at bluemetalservicesptyltd.gdprlocal.com/eu (section 20) |
| Singapore | Personal Data Protection Commission — pdpc.gov.sg |
| Hong Kong | Office of the Privacy Commissioner for Personal Data — pcpd.org.hk |
| Canada | Office of the Privacy Commissioner of Canada — priv.gc.ca |
You need not complain to us first, but it is usually quicker.
Section 18Hong Kong Personal Information Collection Statement
Provided for the purposes of Data Protection Principle 1(3) of the Personal Data (Privacy) Ordinance (Cap. 486). It summarises information set out in full above.
- Purposes of collection: to create and administer your account; to create, coordinate and operate shared Bitcoin vaults, including the claim links used to join them; to notify you of vault events; to secure the Platform and prevent fraud; to comply with legal obligations; and, with your consent, to send marketing.
- Obligatory or voluntary: an email address or social login identifier, and the public key required to construct a vault, are obligatory — we cannot provide the Platform without them. Slot labels, vault names, preferences and joining our mailing list are voluntary.
- Classes of transferees: other participants in your vault; our ultimate holding company and its group; cloud infrastructure, authentication, email delivery, marketing email and workflow automation, and security providers; professional advisers; regulators, law enforcement and courts where legally required. Bitcoin transaction data is transferred to the public Bitcoin network and is thereafter available to anybody.
- Access and correction: write to the Privacy Contact in section 20.
- Direct marketing: we will not use your personal data in direct marketing without first notifying you of the kinds of data and classes of goods and services concerned and obtaining your consent — see section 17.1.
Section 19Links to other services
The Platform links to and interoperates with services we do not control, including wallet software, block explorers and authentication providers. Where the Platform shows a link to a public block explorer, following it is your choice, and that explorer’s own privacy practices apply — we do not send it anything on your behalf. We are not responsible for the practices of any third-party service.
Section 20How to contact us
| Privacy contact | The Privacy Officer, Bluemetal Services Pty Ltd |
|---|---|
| privacy@cobault.io | |
| Post | c/o Flinders Financial, Level 2, 179 St Georges Terrace, Perth WA 6000, Australia |
| Data Protection Officer | We have not appointed a data protection officer under the GDPR. For Singapore: the Privacy Officer is our data protection officer for the purposes of section 11 of the Personal Data Protection Act 2012 and can be contacted as above |
| EU representative (Article 27 GDPR) | Instant EU GDPR Representative Limited, Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland — bluemetalservicesptyltd.gdprlocal.com/eu — contact@gdprlocal.com — +353 (0)1 554 9700. Appointed in writing on 27 August 2026 as our representative in the European Union. You, or a supervisory authority, may contact them on any matter concerning our processing of your personal data, instead of or as well as contacting us |
| UK representative (Article 27 UK GDPR) | GDPR Local Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton BN1 1EB, United Kingdom — bluemetalservicesptyltd.gdprlocal.com/uk — contact@gdprlocal.com — +44 (0)1772 217800. Appointed in writing on 27 August 2026 as our representative in the United Kingdom. You, or the Information Commissioner’s Office, may contact them on any matter concerning our processing of your personal data, instead of or as well as contacting us |
Section 21Changes to this policy
Version 1.4 (31 August 2026) records that the Platform is now available in the United Kingdom and the Member States of the European Union, alongside Australia, Singapore and Hong Kong. The availability statement in the footer of our pages is updated to say so. Nothing about how we handle personal information changes with this version: no new collection, purpose, processor or retention period is added. This policy already provides for EU and UK users throughout — our representatives appointed under Article 27 of the GDPR and UK GDPR (section 20), your rights under the GDPR and UK GDPR (section 15), the EU and UK complaint routes (section 17.2) and our cross-border transfer safeguards (section 11) are all unchanged.
Version 1.3 (31 August 2026) names our representatives in the European Union and the United Kingdom, appointed under Article 27 of the GDPR and UK GDPR, in section 20; adds their reporting pages to the complaint routes in section 17.2; and points to them from the claim-link notice in section 5. It also tidies how we identify ourselves: we say plainly that Cobault is operated by Bluemetal Services Pty Ltd, and we show the registered office by its street address alone — the postal address for reaching us in section 20 is unchanged. And section 8 now describes the consent banner introduced alongside this version: our marketing pages ask before setting any analytics or attribution cookie, and the new Cookie Notice is linked there. Nothing else changes: no new collection, purpose, processor or retention period is added, and the countries in which the Platform is available are unchanged.
Version 1.2 (26 August 2026) records how we attribute a mailing-list signup to the marketing link that brought you: a new collection category in section 4.1, a purpose in section 6, a first-party dub_id cookie in section 8, one further processor in section 10, and a retention period in section 12. It adds no tracking to the signed-in Platform, which still carries none, and it changes nothing for anyone who already holds an account.
Version 1.1 (25 August 2026) records the company-updates mailing list now offered on our public websites: a new collection category in section 4.1, a consent purpose in section 6, two processors in section 10, a retention period in section 12, and a rewritten section 17.1. It changes nothing about how we handle the information of anyone who already holds an account: the list is separate, and nobody is added to it without asking. Version 1.0 took effect on 24 August 2026.
We may update this policy. For a material change we will notify you by email or by prominent notice on the Platform at least 14 days before it takes effect, unless it must take effect sooner to comply with law. The date at the top shows when it was last updated. Prior versions are available on request.