Orego →
Privacy Policy
Last updated: 07 September 2026
This Privacy Policy explains how ArsOrigo srl (“ArsOrigo”, “AO”, “we”) processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws.
ArsOrigo is a digital working environment and technical tool designed for artists, artisans, creators, studios, and professionals who wish to build, manage, and preserve their digital identity and digital assets, including through blockchain-based technologies and the creation and management of NFT-related assets.
1) Data Controller
ArsOrigo srl – Via Miraglia, 1 – 30170 Mestre (VE) – Italy
VAT / Tax ID: 05429843021 – Website: www.arsorigo.com
Support & privacy contact: support@arsorigo.com
2) Categories of Personal Data Processed
- Account data: email address, username, name (if provided), OAuth identifiers (Google/Discord/Facebook/Instagram), Web3 wallet address (e.g. Phantom), and guest profile identifiers.
- Content and User-Generated Content (UGC): profile images, account name, country flag, chat messages, and content uploaded or generated by the user within the platform in connection with digital asset and NFT creation.
- Technical data: minimal logs, IP address, user agent, session identifiers, device settings, security and anti-fraud events, cookie preferences.
- Payment and billing data: transaction outcomes, payment identifiers, credit balances, invoicing metadata. Payment card data is processed directly by Stripe and never stored by ArsOrigo.
- Blockchain / NFT data: wallet addresses, mint addresses, NFT metadata (on-chain and off-chain), donation and minting history, collection contract references, and blockchain transaction records.
- Cookies and similar technologies: strictly necessary cookies and, with consent, functional, analytics, and marketing cookies.
3) Purposes of Processing and Legal Bases
| Purpose | Legal Basis (Art. 6 GDPR) | Data |
|---|---|---|
| Account authentication and platform functionality (login, session, chat, user environment access) | Performance of a contract | Account data, UGC, technical data |
| Content moderation, abuse prevention, fraud detection, platform security | Legitimate interest; legal obligations where applicable | UGC, logs, technical data |
| Payments, billing, credit management | Performance of a contract; legal obligations | Transaction and billing data |
| NFT metadata generation, TokenURI creation, ERC-721 contract support; minting support | Performance of a contract; legal obligations | Wallet addresses, NFT metadata, blockchain records |
| Statistical analysis and platform improvement | Consent; legitimate interest if anonymized | Usage and technical data |
| Marketing, remarketing, social SDKs | Consent | Online identifiers, events |
| Customer support and assistance | Performance of a contract | Account and communication data |
4) Nature of Data Provision
Data required to provide the service (authentication, security, payments, blockchain operations support) is mandatory. Failure to provide such data may prevent access to the platform. Analytics/marketing cookies and optional features are voluntary and require explicit consent.
5) Methods of Processing
Data is processed using electronic tools and appropriate organizational and technical safeguards. Automated systems may be used for moderation, fraud prevention, and security purposes. Users are responsible for ensuring that uploaded or submitted content is lawful and does not infringe third-party rights.
6) Data Retention
- Active accounts: retained for the duration of the contractual relationship.
- Security logs: typically 6–24 months.
- UGC and platform content: retained as long as necessary to provide the service or until deleted by the user, subject to technical backups.
- Billing and accounting data: retained according to legal obligations (e.g. up to 10 years in Italy).
- Cookies: retained according to the durations shown in the Cookie Preferences panel (consent record up to 6 months unless renewed).
7) Data Sharing and Recipients
We do not sell personal data. Data may be shared with service providers acting as Data Processors (e.g. hosting, CDN, email services, monitoring, payments via Stripe, security, Web3 infrastructure providers), under contracts compliant with Art. 28 GDPR. Data may also be disclosed to public authorities where required by law.
8) International Data Transfers
Some providers may be located outside the EEA. Transfers are carried out in compliance with Chapter V GDPR, using adequacy decisions, Standard Contractual Clauses (SCCs), and supplementary measures where necessary. Further information can be requested at support@arsorigo.com.
9) Cookies and Similar Technologies
We use strictly necessary cookies (always active) and, with your consent, functional, analytics, and marketing cookies. You can change your choices at any time via the “Cookie Preferences” link.
| Category | Examples | Typical Retention | Legal Basis |
|---|---|---|---|
| Necessary | Session, security, load balancing | Session / short term | Contract necessity |
| Functional | Preferences, external embeds | Up to 6 months (renewable) | Consent |
| Analytics | Aggregated usage measurement (e.g. GA4 with anonymized IP) | Up to 6 months (renewable) | Consent / legitimate interest if anonymized |
| Marketing | Remarketing, third-party pixels/SDKs | Up to 6 months (renewable) | Consent |
You can change your choices at any time via the “Cookie Preferences” link.
Settings: •
10) Social Login and Third-Party Integrations
Users may authenticate via Google, Discord, Facebook, Instagram, or Web3 wallets (e.g. Phantom). These providers act as independent data controllers for authentication processes. Please refer to their respective privacy policies.
11) ArsOrigo, AO, and Digital Passports (NFTs)
ArsOrigo (AO) is a technical tool and working environment that enables artists, artisans, creators, and professionals to:
- create digital passports for works or assets;
- generate NFT-compliant metadata (
metadata.json); - produce ready-to-use TokenURIs;
- support on-chain minting on public blockchains;
- create and register a personal ERC-721 collection contract associated with the user account, and support minting via technical infrastructure and relayers.
Fundamental clarification on ownership
ArsOrigo is not, and cannot be, the owner, co-owner, author, or rights holder of any digital passport, NFT, or underlying asset. This is not merely a policy choice — it is a structural property of blockchain technology.
- Ownership and authorship are cryptographically linked to the user’s wallet address.
- Smart contracts and blockchain records are public, immutable, and independent of ArsOrigo.
- ArsOrigo has no technical ability to transfer, alter, revoke, or claim ownership of digital passports or NFTs.
ArsOrigo acts exclusively as a tool provider, a technical facilitator, and an interface between users and decentralized infrastructure. All rights, responsibilities, and ownership remain entirely with the user.
Once executed, on-chain operations cannot be modified, undone, or deleted.
12) IPFS, Pinning, and Gateways
Digital content and metadata generated through the platform may be stored on IPFS (InterPlanetary File System), a decentralized storage network.
ArsOrigo uses pinning services and a dedicated gateway to make content accessible via HTTP and ensure technical availability during the service period. Due to the decentralized nature of IPFS, long-term availability may depend on external nodes and infrastructure. Users remain responsible for preserving TokenURIs and IPFS references.
13) Data Subject Rights
Users may exercise rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection) by contacting support@arsorigo.com. Users also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
14) Minors
The service is intended for users aged 14 or older (or the applicable minimum age for digital consent in the user’s jurisdiction). If we become aware that personal data of a minor has been collected without proper authorization, we will take steps to delete it where possible.
15) Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, or service-related changes. The date at the top indicates the most recent revision.