Privacy policy

Your trust is sacred to us. Read how we protect and respect your personal information.

YOUR PRIVACY,
our responsibility.

This Privacy Policy explains how Meritus Projects Inc. (“we”, “us”, “our”, or the “Company”) collects, uses, shares, and protects personal data when you use the DIMASH platform, website, and related services (the “Platform”). It should be read together with our Terms & Conditions.

We are the data controller for personal data processed through the Platform. Our custodial wallet provider, payment processors, and identity-verification providers act as separate controllers or processors for the data they handle; their own privacy notices also apply to you.

Meritus Projects Inc. is the operator of the Platform. Meritus Projects Inc registered office address is Office A, RAK DAO Business Centre Al Riffa, Sheikh Muhammad Bin Zayed Road, RAK 1234, Ras al Khaimah, UAE. All privacy queries can be sent to .

The Platform launches in the UK, Latin America (including Mexico), Kazakhstan, Hong Kong, and Singapore. Depending on where you are, your data may be protected by the UK GDPR and Data Protection Act 2018, the EU GDPR, Mexico’s Federal Law on Protection of Personal Data Held by Private Parties, Kazakhstan’s Law on Personal Data and its Protection, Hong Kong’s Personal Data (Privacy) Ordinance, Singapore’s Personal Data Protection Act, and other applicable laws. Where laws differ, we apply the standard that gives you the greater protection for the relevant processing.

CategoryExamplesSource
Account dataEmail address, hashed password, preferred language, country/region.You, at registration.
Wallet dataCustodial wallet address linked to your account; any self-custody address you connect.Custodian / you.
Transaction dataPurchases, sends, spends, claim-code redemptions, NFT activity, on-chain transaction IDs.Platform and blockchain.
Participation dataCohort, badges, voting activity, fan-activity signals, referrals, ambassador / moderator / translator roles.Platform and your activity.
Technical dataIP address, approximate location (for geo-blocking), device and browser data, cookies and analytics identifiers.Automatically, via your device.
Support dataMessages and information you provide to support.You.

Where the UK/EU GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Create and operate your account and custodial wallet; provide the Platform and process your transactions.Performance of a contract with you.
Security, debugging, abuse and bot prevention, and protecting the Platform and users.Legitimate interests.
Analytics and product improvement (e.g., GA4, Microsoft Clarity).Consent (where required) or legitimate interests.
Marketing communications and newsletters.Consent, which you can withdraw at any time.
Cookies and similar technologies.Consent for non-essential cookies; legitimate interests / necessity for essential cookies.
Complying with court orders, regulators, and law enforcement.Legal obligation.

Where local laws other than the GDPR apply, we process your data on the equivalent lawful grounds available under those laws, including your consent where required.

We use essential cookies to operate the Platform and keep it secure, and non-essential cookies for analytics and performance.

We use Google Analytics 4 and Microsoft Clarity to understand how the Platform is used. These tools may set cookies and collect technical and usage data.

In regions that require it, we ask for your consent before setting non-essential cookies and you can change your choices at any time through the cookie banner or settings.

We process your IP address and approximate location to enforce geographic restrictions and to block access from Restricted Jurisdictions, as described in our Terms. We compare IP-based location against your declared country of residence and may flag discrepancies for review. We use IP geolocation rather than language or browser settings for this purpose, so your choice of language does not affect geo-restriction.

The Solana blockchain is public, permanent, and outside our control. On-chain transactions, wallet addresses, token transfers, and NFT activity are recorded publicly and cannot be changed, erased, or hidden by us. Data rights such as erasure cannot be applied to data already written to the blockchain.

We do not publish your name or email on-chain. However, anyone may be able to view on-chain activity associated with a wallet address. You should consider this before transacting.

We share personal data only as needed, with:

  • the Custodian and KYC/AML providers, who verify identity and hold and operate custodial wallets;
  • payment processors and on-ramp providers, to process payments;
  • analytics, hosting, communications, and security providers acting as our processors;
  • the Artist and Artist Management, in aggregated or limited form where necessary to deliver experiences you have requested or to operate the project;
  • regulators, law enforcement, and authorities where required by law; and
  • a successor entity in the event of a reorganisation, merger, or sale, subject to this Policy.

We do not sell your personal data.

We operate across multiple jurisdictions, and your data may be transferred to and processed in countries other than your own, including outside the UK/EU. Where we transfer personal data internationally, we use appropriate safeguards required by applicable law, such as the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or transfers to jurisdictions recognised as providing adequate protection.

  • Account and transaction data: for as long as your account is active and for a reasonable period afterwards to meet legal, accounting, and dispute-resolution needs.
  • Backups: deleted or overwritten on a rolling schedule (we operate automated daily backups with a 30-day retention window for operational data).
  • On-chain data: remains on the blockchain permanently and cannot be deleted.

Subject to your local law, you may have the right to: access your data; correct inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent at any time. Where the GDPR applies, you also have the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner’s Office). To exercise your rights, contact us using the details in Section 1. We may need to verify your identity before responding, and some rights are limited where data is held by the Custodian or recorded on-chain.

We use technical and organisational measures to protect personal data, including hashing of passwords, access controls, encryption in transit, and monitoring. Private keys to custodial wallets are held and secured by the Custodian. No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.

The Platform is not intended for anyone under 18 (or the age of majority where higher). We do not knowingly collect data from children. If we learn that we have collected data from a child, we will delete it.

Where you have opted in, we may send you updates about the Platform and the project. You can unsubscribe at any time using the link in our messages or by contacting us. Essential service messages (such as security and transaction notifications) are not marketing and will continue.

We may update this Policy from time to time. We will post the updated version on the Platform with a new effective date and, for material changes, notify you through the Platform or by email.

For privacy questions, requests, or complaints, contact us at .