Privacy Policy

Last updated: Feb 21, 2026 Controller: Evolve (“Evolve”, “we”, “us”, “our”) Contact: [email protected]

This Privacy Policy explains how Evolve collects, uses, discloses, and protects personal data when you access Evolve’s websites, applications, dashboards, APIs, and related services (the “Services”) in connection with eUSD.

Evolve’s smart contracts and vault infrastructure are powered by YieldFi (the infrastructure provider). YieldFi may process certain technical and operational data on Evolve’s behalf as a service provider/subprocessor to deliver the Services.

This policy is provided for transparency and does not constitute legal advice.


1) Scope

This policy applies to:

  • Visitors to Evolve websites and apps

  • Users who connect wallets, mint, redeem, or otherwise interact with eUSD

  • Users who undergo eligibility checks, KYC/KYB, or AML screenings (where applicable)

  • Partners/integrators using Evolve’s integration surfaces (where applicable)

It does not apply to third-party websites, wallets, exchanges, DeFi protocols, or blockchains you use to interact with eUSD, each of which has its own policies.


2) What we collect

A) Data you provide

  • Contact details (e.g., email if you contact support)

  • Account/profile data (if we provide an optional account layer)

  • Support communications (messages, attachments, and metadata)

B) Identity and verification data (if KYC/KYB is required)

Where access is gated (Greenlist), we may collect or receive:

  • Identity information (name, date of birth, nationality)

  • Government ID and verification artifacts (ID images, selfie/liveness checks)

  • Entity/KYB information (company registration, beneficial ownership, proof of address, director/officer details)

  • Screening results (sanctions/PEP/adverse media flags, risk scores)

C) Wallet and blockchain data

  • Wallet addresses you connect

  • Transaction hashes and onchain activity linked to your wallet (public blockchain data)

  • Balances and positions as displayed in the app (derived from onchain data and product accounting)

D) Technical and usage data

  • IP address (and approximate geolocation derived from IP)

  • Device and browser information (user-agent, OS version, identifiers)

  • Log data (access logs, error logs, timestamps, pages/actions)

  • Security telemetry (signals used to detect fraud, abuse, or exploitation patterns)

We may use cookies or similar technologies for:

  • essential site functionality

  • security

  • analytics and performance

(You can manage cookies via browser settings; some controls may limit functionality.)


3) How we use data

We use personal data to:

Provide and operate the Services

  • enable wallet connections and user workflows (mint/redeem requests, dashboards)

  • deliver product pages, disclosures, and reporting views

  • administer eligibility gating where applicable

Compliance, safety, and risk management

  • enforce eligibility restrictions and restricted jurisdiction access blocks

  • perform KYC/KYB/AML checks where required

  • run wallet screening and detect illicit or sanctioned activity

  • investigate incidents, fraud, abuse, and security events

Improve and maintain the Services

  • debugging, monitoring, performance analytics

  • feature development and reliability

Communications

  • respond to support inquiries

  • send critical operational notices (e.g., policy changes, security incidents)


Depending on jurisdiction, our processing may rely on one or more of:

  • performance of a contract (to provide Services you request)

  • legal obligations (AML/CFT, sanctions compliance)

  • legitimate interests (security, fraud prevention, product improvement)

  • consent (where required, e.g., certain cookies/marketing)


5) How we share data

We may share data with:

A) Infrastructure provider (YieldFi)

Evolve uses YieldFi as the smart contract and vault infrastructure provider. YieldFi may process limited technical and operational data (e.g., logs, workflow events, security telemetry) as a service provider/subprocessor to help operate the Services.

B) Verification and screening providers

Where KYC/KYB or wallet screening is required, we share necessary data with vendors to:

  • verify identity/entity information

  • conduct sanctions/PEP screening and risk checks

C) Analytics, hosting, and security providers

We may use service providers for:

  • hosting and content delivery

  • application monitoring and security alerting

  • analytics and performance monitoring

We may disclose data if required to comply with law, respond to lawful requests, enforce our terms, or protect rights, safety, and integrity of the Services.

E) Business transfers

If Evolve undergoes a merger, acquisition, restructuring, or asset sale, data may be transferred as part of that transaction, subject to applicable law and confidentiality protections.

We do not sell your personal data to advertisers.


6) International transfers

Your data may be processed in multiple jurisdictions depending on where Evolve and its service providers operate. Where required, we use appropriate safeguards (e.g., contractual protections) for cross-border transfers.


7) Retention

We retain data only as long as necessary for:

  • providing the Services

  • compliance obligations (including AML/sanctions screening records where applicable)

  • security, auditability, and dispute resolution

Retention periods vary by data category and legal requirements. You may request deletion where applicable, subject to legal and operational constraints.


8) Security

We implement administrative, technical, and organizational measures designed to protect personal data. However, no system can be guaranteed 100% secure. You are responsible for maintaining the security of your wallet(s), keys, and devices.


9) Your rights

Depending on your jurisdiction, you may have rights to:

  • access, correct, or delete personal data

  • object to or restrict processing

  • request portability (where applicable)

  • withdraw consent (where processing relies on consent)

To exercise rights, contact [email protected]. We may request verification of identity to protect users from unauthorized requests.


10) Children

The Services are not intended for children. Do not use the Services if you are not of legal age in your jurisdiction.


11) Changes to this policy

We may update this policy from time to time. We will post the updated version and update the “Last updated” date. Material changes may be communicated via the app or other reasonable channels.


12) Contact

For privacy questions, requests, or complaints: [email protected]

Last updated