Opincur
OPINCUR TOKEN DISTRIBUTION & RESERVATION PORTAL — PRIVACY POLICY

Effective Date: 20 September 2026

Data Controller: MONOLITH LABS LTD, registered in England and Wales.

ICO Registration Number: ZC126753

Registered Address: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ

Contact: info@monolithlabs.uk

1. Introduction and How This Policy Fits the OPINCUR Ecosystem

MONOLITH LABS LTD (the "Company", "we", or "us") operates the OPINCUR Token Distribution & Reservation Portal at opincur.com/cio(the "Portal"). This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the Portal, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The Portal sits between two other products in the OPINCUR ecosystem, each governed by its own separate privacy policy: the OPINCUR HUB application (where your CIO Points balance is recorded) and the OPINDEX wallet application (which you connect to the Portal to reserve and claim $CIO). This Policy covers only the Portal itself. Where the Portal reads data from, or writes data to, OPINCUR HUB or OPINDEX, that data is additionally subject to the respective privacy policy of that product, both of which are available at their respective apps and at opincur.com/policy and opindex.io/wallet-privacy.

This Privacy Policy forms an inseparable part of the Portal's Terms of Use. By using the Portal, you accept both this Privacy Policy and the Terms of Use.

2. The Portal's Privacy Design Principle

The Portal is designed to be a thin, largely stateless bridge between your OPINCUR HUB loyalty balance and your on-chain $CIO allocation. In line with the OPINDEX "zero-knowledge" architecture it connects to, the Portal does not require you to create a separate account, and does not itself ask for your name, email address, or physical address. Consistent with the Portal's Terms of Use, the Company does not collect or verify identity documents ("KYC") as a condition of using the Portal.

3. Data We Do Not Collect

The Portal never collects, stores, or has access to:

4. Data We Collect and Why

4.1. Wallet Address. When you connect a Web3 wallet to the Portal, we process your public wallet address. This is necessary to look up your CIO Points balance from OPINCUR HUB, to display your reservation status, and to construct the on-chain claim transaction you sign. A public wallet address is a pseudonymous identifier, not directly your name or contact details, though it may become linkable to you through your own on-chain activity or elsewhere.

4.2. CIO Points Balance and Burn Record. To calculate your 1:1 $CIO allocation, the Portal reads your unredeemed CIO Points balance from the OPINCUR HUB database (see the OPINCUR HUB Privacy Policy for how that balance is generated and held) and, upon your action, triggers the one-way burn of that balance as described in the Terms of Use. A record of this burn event (wallet address, amount, timestamp) is kept for reconciliation and audit purposes.

4.3. Public Blockchain Data. When you reserve or claim $CIO, the resulting transaction — including your public wallet address, the token amount, and the smart contract interaction — is broadcast to the public Solana blockchain. Blockchain data is public, immutable, and visible to anyone in the world. We do not control this public data and cannot delete or alter it once confirmed on-chain.

4.4. Technical Data. We collect standard technical data when you use the Portal, including IP address (anonymised or hashed where possible), browser type, device type, and approximate timestamps, for security, fraud prevention, and sanctions-screening purposes as described in Clause 3 of the Terms of Use.

4.5. Usage and Analytics Data. We may collect anonymised data about how you interact with the Portal's interface (e.g. pages visited, button clicks, error logs) to help us fix bugs and improve performance.

4.6. Support Correspondence. If you contact info@monolithlabs.uk, we process the contents of that correspondence, and any email address or other contact detail you choose to include in it, solely to respond to your enquiry.

5. Legal Bases for Processing (UK GDPR)

Wallet address, CIO Points balance/burn records, and blockchain transaction data are processed on the basis of contractual necessity (Article 6(1)(b) UK GDPR) — this processing is required to operate the reservation and claim functionality you request.

Technical data used for sanctions screening and fraud prevention is processed on the basis of the Company's legal obligations (Article 6(1)(c) UK GDPR) and its legitimate interests in protecting the Portal and its users (Article 6(1)(f) UK GDPR).

Usage and analytics data is processed on the basis of the Company's legitimate interests in maintaining and improving the Portal (Article 6(1)(f) UK GDPR).

Support correspondence is processed on the basis of the Company's legitimate interest in responding to you, or, where applicable, to take steps prior to entering into a contract with you (Article 6(1)(b)/(f) UK GDPR).

6. Sharing Data With Third Parties

The Company does not sell your personal data. Data is shared only with the following categories of recipient:

7. International Data Transfers

Your data may be processed outside the United Kingdom, including by hosting infrastructure and sanctions-screening providers based elsewhere. Wherever data is transferred outside the UK, the Company ensures appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses, so that your data receives equivalent protection regardless of its physical location.

8. Data Retention

Wallet address and burn-record data associated with a completed reservation or claim is retained for six (6) years from the date of the transaction, to meet the Company's accounting, audit, and AML record-keeping obligations under applicable UK law. Technical data collected for security and sanctions-screening purposes is retained for a maximum of twelve (12) months. Anonymised usage/analytics data is retained for a maximum of twelve (12) months. Support correspondence is retained for as long as reasonably necessary to resolve your enquiry and for a reasonable period afterwards for record-keeping purposes.

Public blockchain data cannot be altered or deleted by us or anyone else, and is not subject to the retention periods above.

9. Your Legal Rights

Under UK GDPR, you have the right to: request access to your personal data; request correction of inaccurate personal data; request erasure of your personal data ("right to be forgotten"); object to processing or request restriction of processing; and withdraw consent, where processing is based on consent.

Important limitations: (a) where we hold only a pseudonymous wallet address and no other identifying information, we may not be able to verify that a request relates to your data, and may ask you to demonstrate control of the wallet address (for example, by signing a message) before actioning your request; and (b) we cannot erase, alter, or otherwise affect any transaction or public address already recorded on the Solana blockchain, as blockchain data is cryptographically immutable and outside the Company's control.

To exercise any of these rights, contact info@monolithlabs.uk.

10. Children's Privacy

The Portal is strictly intended for individuals aged 18 and over, in accordance with the Terms of Use. The Company does not knowingly collect personal data from anyone under 18. If the Company becomes aware that it has inadvertently collected data from a minor, it will take immediate steps to delete such data, to the extent it is able to do so (noting the limitation in Clause 9 above in respect of public blockchain data).

11. Security

The Company implements reasonable technical and organisational measures to protect the data described in this Policy against unauthorised access, disclosure, alteration, or destruction. No digital system is completely secure. You remain responsible for the security of your own device, wallet, and private keys, as set out in the Terms of Use.

12. The Information Commissioner's Office (ICO)

If you believe the Company has mishandled your personal data, you have the right to lodge a complaint at any time with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at www.ico.org.uk (ICO Registration Number: ZC126753). The Company welcomes the opportunity to address your concerns directly at info@monolithlabs.uk in the first instance.

13. Changes to This Privacy Policy

The Company may update this Privacy Policy from time to time to reflect changes in applicable law, regulatory guidance, or the Portal's features. Material changes will be indicated by updating the Effective Date at the top of this document and, where reasonably practicable, notified on the Portal. Continued use of the Portal after such an update constitutes your acknowledgment of the revised Policy.

© 2026 MONOLITH LABS LTD. All rights reserved. Company Number: 17154388. ICO Registration: ZC126753. Registered in England and Wales.

Contact: info@monolithlabs.uk