Transparency
Data, by design.
What we collect, why, who can see it, and where it goes. This testnet product document is not legal advice or a claim of legal compliance.
!
Implementation status Some privacy controls are not built yet. We mark those gaps below. Have this policy reviewed by counsel before processing real personal data.
Data inventory
| Data | Purpose | Access | Sent to AI? | Storage |
|---|---|---|---|---|
| Submitted venue photos and attributed demo illustrations Optional | Show the submitted venue. Demo reference images are labeled and are not venue evidence. | Public | No | Product/review gallery; private storage with signed photo links lasting one hour |
| Venue profile: name, city, province, sports, courts, dimensions, surface, rates, hours, use of proceeds | Help investors assess venue capacity and revenue context. | Public | No | Product page; profile hash is bound to ACQUISITION_CLOSED attestation |
| Monthly financial summary: gross revenue, distributable net profit (D), digital payment share | D12 is used in valuation; inputs and outputs are disclosed to investors (PRD §4.1). | Public | No | Product page |
| Valuation: reviewer-entered asset value, D12, r, V, implied yield, X, token supply, reference price | Explain how the reference price is calculated. | Public | No | Product page + contract (valuation, supply, and reference price) |
| Land status: self-owned, title type, and whether pledged · no certificate number | Only self-owned land qualifies; disclose encumbrance risk. | Public | No | Product page |
| Exact venue address | Help confirm the venue exists without disclosing its precise address publicly. | KYC-verified investors & staff | No | Product page · KYC-verified investors |
| Monthly waterfall: gross revenue, refunds, expenses, tax, fees, reserves, D, per-token distribution Optional | Investors can inspect figures signed by the platform and owner; the contract recalculates them. | Public | No | Product page + contract (waterfall figures and evidence hash) |
| Venue PoS ledger entries: time, type, amount, payment settlement status Optional | Period revenue source, reconcilable to on-chain evidence hashes. | Verification staff only | No | pos.ledger_entries; customer identities are not stored, only hashes |
| KYB documents: company deed, NIB, NPWP, land title, permits, statements, financials, tax, debt, insurance | Evidence for human reviewers and advisory AI extraction/cross-checks. | Verification staff only | Yes · redacted text only | Private storage; signed links expire after five minutes; venue photos may be public |
| Company identity: legal name, NIB, NPWP, deed, KBLI, directors, commissioners, signatory, contacts | KYB checks the business and authorized representatives. | Verification staff only | No | platform.organizations · server access only |
| Beneficial owners at 25% or more: name, ownership share, national ID · masked to last four digits | KYB/AML identifies who controls the business. | Verification staff only | No | platform.beneficial_owners |
| Land title details: number, holder, title type, mortgage status, building permits | Verify self-owned land and assess encumbrance risk. | Verification staff only | Yes · redacted text only | platform.venue_land |
| Financial and debt details: monthly waterfall inputs, bank credits, outstanding debt, lender, covenants | Calculate D12 and assess claims on venue profit. | Verification staff only | No | platform.venue_financials, platform.organizations.debt |
| Owner payout account: bank, account holder, account number · masked and hashed | Receive acquisition funds and daily payment splits; holder name must match the business. | Verification staff only | No | platform.owner_bank_accounts |
| Investor account: email, Privy wallet address, KYC status | Link tokens to one investor account and wallet. Only allowlist status reaches chain. | Verification staff only | No | platform.users, platform.kyc_records |
| Investor full name from KYC | Match the bank account holder with the verified investor before the first purchase. | Verification staff only | No | platform.kyc_records |
| Investor bank account: bank, holder, masked/hashed number, name match, replacement hold | Withdrawals go only to an account held by the investor. | Verification staff only | No | platform.investor_bank_accounts |
| Investor balance and activity: distributions, withdrawals, reinvestments, buybacks | Track the investor’s simulated distribution-account balance. | Verification staff only | No | platform.investor_ledger · append-only; investors see their own entries |
| Investor identity documents · national ID and selfie | Identity verification is performed by Didit. Open Grounds does not store these documents. | Not stored by Open Grounds | No | KYC provider only; platform receives status and name |
| Venue PoS customer data Optional | PoS stores only a hashed reference and short label to prevent fictitious bookings. | Owner & their PoS team | No | PoS · isolated by company |
| On-chain data: wallet addresses, allowlist/freeze status, token lots, waterfall figures, evidence hashes | The chain enforces rules. Names, IDs, bank accounts, and documents never go on-chain. | Public | No | Sepolia · public and permanent |
What the system does today
- Documents use private storage. Staff download links expire after five minutes; venue photos may be public.
- Company identity, bank accounts, contacts, and financial details are server-only; they are not accessible from the browser.
- Before document text reaches an AI model, national IDs, bank numbers, phone numbers, and email addresses are redacted. Images are not sent. Models have no tools or network access; outputs are validated.
- AI cannot approve applications, issue tokens, change bank accounts, or move funds. Humans review every finding. Token issuance requires platform and owner signatures.
- Didit processes investor identity documents. Open Grounds receives status and name for bank-name matching. Without Didit, the KYC path is a labeled sandbox mock.
- Bank-account and national-ID numbers are masked to their last four digits and stored with hashes.
- No personal data is written on-chain. Wallet addresses, figures, and evidence hashes are public and permanent.
- Important actions are recorded in an audit log.
What is not built yet
- Automatic retention and deletion. No retention schedule exists. Before production, define deletion after appeal periods and legally required retention for active series.
- Data-subject requests for access, correction, deletion, or withdrawal of consent. Requests are manual; legal recordkeeping may limit deletion.
- Official NIB, NPWP, and deed checks against AHU/OSS are not integrated. Current checks validate formats and compare submitted evidence.
- Incident notification. No automated process exists yet.
- Formal privacy impact assessment. Not completed.