Legal
Privacy Policy
What we collect to run the rail, and what we do not.
Effective 14 September 2026
1. Controller
The Operator of this site (see Terms) is the controller of personal data processed to run the rail. Until published: legal name, Ecuadorian ID, and RUC are [pending RUC]. Contact: legal@sluzen.network.
We follow applicable data-protection law. For people in Ecuador that includes the Ley Orgánica de Protección de Datos Personales (LOPDP) and the Superintendencia de Protección de Datos Personales (SPDP). This policy is not a substitute for a contract with an issuer who is a separate controller of their own users.
2. What we collect
- Rail telemetry — route identifiers, challenge and settlement outcomes, amounts in drops, timestamps, latency, and transaction hashes. The public live feed is aggregated and may redact routes.
- Issuer configuration — source route, upstream URL, price, classic receive address, and API-key metadata (keys are hashed at rest on the proxy).
- Access logs — IP address, user agent, and request metadata on the site and proxy, for security and abuse control.
- Browser session — the product app opens an HttpOnly cookie on the API host after you unlock. The token is not kept in
sessionStorage. On local HTTP the cookie may not stick; the token stays in page memory until you close the tab. - Issuer customer file — collected out-of-band before a key is issued: legal name, tax ID, country, and authorized funding XRPL address.
- Terms acceptance — contract versions, content hashes, timestamp, IP, and user-agent.
- Credit-grant records — source transaction hash, source XRPL address, and drops.
- Sanctions screening — issuer identity and funding address checked against international lists (OFAC/UN).
- Invoicing FX — USD/XRP rate captured at the 0.8% debit.
XRPL addresses and IP addresses are treated as personal data under Ecuadorian law when they can identify a person, even if pseudonymised. Combined with an issuer identity they are personal data.
3. What we do not collect
Wallet seeds, signing keys, or passwords for agent wallets. Do not paste them into sluzen.network. We do not run a hosted wallet. We do not collect identity through a public KYC upload. We do not sell personal data.
4. Purposes and bases
Operate and secure the rail; settle and meter according to the published fee policy; show public proof counts; comply with law (including AML requests if they apply). Bases: performance of the terms, legitimate interest in securing a public proxy, and legal obligation where it exists.
5. Processors and transfers
Hosting and delivery may use Oracle Cloud (proxy) and Cloudflare (this site). That is an international transfer. We use processors only to run the service. We do not use the live feed as an advertising graph.
6. Retention
Settlement events and logs are kept as long as needed to operate, debug, and meet legal retention. Public live rows are short-window telemetry, not a credit file.
7. Rights
Subject to LOPDP and other applicable law, you may request access, rectification, deletion, opposition, or portability, and you may complain to the SPDP. Some rail records (ledger hashes, settlements) cannot be rewritten; we can restrict our copies where the law requires.
Security incidents that meet the legal threshold will be notified to the authority and, where required, to affected persons, in the statutory terms.