Data Protection
How Prediity processes personal data as a processor on your behalf — covering roles, safeguards, sub-processors, cross-border transfers, retention, and breach notification.
Last updated: August 2026
We never sell personal data, and on-chain settlement records are address-keyed and pseudonymous — transparent markets don't require exposing who you are.
This Data Processing Agreement (DPA) forms part of Prediity's Terms of Service and Privacy Policy and applies whenever Prediity processes personal data on your behalf as a data processor. Where you use Prediity's prediction-market, gaming, or Broker Desk services, we act as an independent data controller of the data we collect directly from you. Where we process data on instructions you give us through the platform, you act as the controller and Prediity acts as the processor. This DPA documents those processing activities, the safeguards in place, and each party's obligations under applicable data-protection law (including the GDPR, UK GDPR, and CCPA).
We process personal data only to provide, maintain, and secure the platform: account registration data (name, email, username, and sign-in methods), identity-verification data where you choose KYC (government ID, proof of address, liveness selfie), transaction and ledger data (deposits, withdrawals, trades, bets, and settlements), device and usage data (IP address, browser, pages viewed), and support correspondence. We do not sell personal data. Processing is limited to what is necessary for the performance of the service, legal and regulatory compliance (including AML/KYC and sanctions screening), fraud and market-abuse prevention, and our legitimate interests in operating the platform.
You may exercise your rights over the data we hold about you at any time — access, rectification, erasure, restriction of processing, data portability, and objection. Requests can be made from Account Settings or by emailing privacy@prediity.com. We respond to verified requests within the timeframe required by applicable law. Where you are a controller and one of your end users raises a request, we will reasonably assist you in fulfilling it from the data we process as your processor.
We implement appropriate technical and organisational measures to protect personal data. These include encryption in transit (TLS 1.3) and at rest (AES-256), access controls with least-privilege principles, multi-factor authentication for administrative access, rate-limited and same-origin-checked API access, immutable ledger writes for all financial events, and continuous monitoring for fraud, abuse, and anomalous activity. On-chain settlement means financial events are also recorded immutably on public ledgers in address-keyed, pseudonymous form without personal information.
We engage a limited set of sub-processors that help us run the platform and may process personal data: cloud hosting and database providers, email delivery services, crypto payment-processing and on-chain infrastructure providers, image-storage providers for avatars and uploaded files, and translation or support tooling. Each sub-processor is bound by a contract that imposes data-protection obligations no less protective than those in this DPA. An up-to-date list of sub-processors is available on request from privacy@prediity.com.
Prediity operates globally and your data may be processed in countries other than your own, including where our hosting and database providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards — including standard contractual clauses and the adequacy decisions of applicable regulators — to ensure the level of protection required by law travels with the data.
We retain personal data only as long as needed for the purposes described in the Privacy Policy, and for the periods required by law — including the statutory retention windows for financial records and AML/KYC documentation. On your request, or when retention is no longer required, we delete or anonymise the data. On-chain records are an exception: settlement data that has been written to a public ledger cannot be removed, and persists in pseudonymous, address-keyed form.
We maintain procedures for detecting, investigating, and responding to personal-data breaches. Where a breach creates a risk to your rights and freedoms, we will notify you and, where required, the relevant supervisory authority without undue delay — and in any event within the timeframes required by applicable law. We will provide reasonable information about the nature of the breach, the categories of data involved, and the steps we have taken to mitigate it.
Prediity's prediction markets are resolved from objective, verifiable real-world outcomes using a strict source hierarchy — official government announcements, major news agencies, official sports bodies, verified on-chain data for crypto markets, and company filings. Games use provably-fair commitment schemes: the server publishes a SHA-256 hash of its seed before each round, then reveals the seed afterwards so every outcome can be independently recomputed. Every trade, bet, and settlement is recorded in our public Explorer. This DPA does not change any of that: transparency about outcomes never comes at the expense of your personal data.
We may update this DPA as the platform or applicable law evolves. Material changes will be reflected by the 'last updated' date on this page and, where appropriate, notified by email or platform notice. Continued use of the service after an update constitutes acceptance of the current version.
Questions about this DPA or data processing? Email privacy@prediity.com or write to Prediity Inc., 228 Park Ave S, New York, NY 10003.