PROVIDERS 139 0 NEW CATEGORIES 28 28 ACTIVE SERVICES 305 0 NEW ODD 2 1.4% USERS 580 6 NEW AVG:RATING 3.7 0 RECENT VIEWS:TODAY 49 1 LAST HR INTROS 4 0 7D TOP:CATEGORY OTC DESK 66 ACTIVE:NOW 0 USERS

Privacy Policy

Last Updated: July 11, 2026

This policy explains how Digital Opportunities Group Enterprises, Inc. ("DigOpp," "we," "us"), operator of Counterparty Catalogue (www.counterpartycatalogue.com, the "Site"), collects, uses, shares, and protects personal information, and the rights you have. It covers Site visitors, account holders, people who submit claims, disputes, reviews, or contact requests, and individuals who appear in our published datasets. For visitors in the EEA/UK, we are the data controller. It does not govern third-party websites or services linked from the Site.

1. Information We Collect

1.1 From you directly

  • Account data — name, email address, password (stored hashed, never in plain text), organization/role information, and email-confirmation status.
  • Content you submit — reviews, RFPs and comments, profile-claim requests (submitter name, email, role, message), incident disputes (your identity and the reasons and evidence you provide), profile information you supply for a company, and contact-form messages.
  • Billing data — for paid listings we collect billing contact and invoicing details. We do not collect or store payment-card numbers; if we add an online payment processor, the processor will collect card details directly and we will name it here first.
  • Correspondence — emails you exchange with us, including introduction requests, which we process to deliver the feature.

1.2 Automatically

  • Usage and device data — we log page views and interactions (such as profile views and link, email, or phone-reveal clicks) together with IP address, browser user-agent, and referrer, in our own systems. We use this for site analytics, security, abuse and bot detection, enforcing view limits, and — for provider profiles — producing aggregate interaction statistics visible to us and to the profile's owner.
  • Cookies — see Section 6.

1.3 From third-party public sources (our published datasets)

We compile publicly available records about security incidents, exploits, and audits in the digital-asset industry from sources including De.Fi Rekt, SlowMist, DefiLlama, and audit reports published by audit firms. These records are primarily about companies and protocols, but they may include personal data about identifiable individuals where the public source includes it (for example, named principals of a firm or persons publicly identified in incident reports). Section 4 explains how we handle that data and your rights regarding it.

We do not knowingly collect data from anyone under 18, and the Site is not directed at them. We do not seek special-category (sensitive) data and ask that you not submit any.

2. How We Use Information, and Our Legal Bases

  • Provide the Site (accounts, reviews, claims, disputes, RFPs, introductions) — account data and content you submit. Legal basis: contract performance.
  • Publish research datasets and computed metrics — publicly sourced data (Section 4). Legal basis: legitimate interests in publishing accurate public-interest research about a professional industry; freedom of expression and information.
  • Display reviews and profile content with attribution — your account name and content. Contract performance; legitimate interests.
  • Share your details when you request an introduction or respond to an RFP — name, organization, contact details. Contract performance, at your request.
  • Site analytics and product improvement — usage/device data from our own first-party logs. Legitimate interests.
  • Security, anti-abuse, bot detection, rate limiting — IP, user agent, usage logs. Legitimate interests.
  • Billing and account administration — billing data. Contract performance; legal obligation (tax/accounting).
  • Service emails (confirmations, password resets, dispute and review notifications) — email address. Contract performance.
  • Marketing emails — email address. Consent, or the soft opt-in where the law allows; every message includes unsubscribe.
  • Legal compliance and defending legal claims — as needed. Legal obligation; legitimate interests.

We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you. Published firm-level metrics are computed about companies, not about individual users.

3. How We Share Information

  • Service providers (processors) acting on our instructions: hosting and infrastructure, email delivery, and payment processing if added. Some page assets (for example, charting libraries) load from third-party CDNs, which receive your IP address as a technical necessity of serving the file.
  • Other users, at your direction: when you request an introduction or respond to an RFP, we share your name, organization, and contact details with that counterparty. Your reviews are published under your account name. The fact and outcome of a dispute may be referenced on the relevant public record.
  • The public: content you choose to publish (reviews, RFPs, claimed-profile content) is public, and public display may make it available to search engines and archives. Our published datasets are public (Section 4).
  • Legal: we may disclose information to comply with law, enforce our Terms, or protect rights, safety, and security, and in connection with a merger, acquisition, or asset sale (with notice of any resulting policy change).

We do not sell personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act). We have no advertising trackers on the Site. We honor Global Privacy Control signals where legally required. If any of this changes, this policy and our disclosures will change first.

4. Personal Data in Our Published Research Datasets

Our incident and audit datasets are compiled from public sources and concern companies and protocols. Where an identifiable individual appears in them, we process that data under legitimate interests in publishing research on matters of public concern in a professional industry, balanced against the individual's rights — the data originates from public reporting, relates to professional (not private) life, and is attributed to its source. We do not intend to publish private contact details, identity documents, or unrelated personal information.

If you are an individual named in our datasets and believe a record about you is inaccurate, outdated, or should not be published, contact [email protected]. You may request correction, object to processing, or request erasure; we will respond within 30 days. We may decline erasure where the processing remains necessary for freedom of expression and information or for legal claims; where we do, we will tell you why, and you may complain to your supervisory authority. Companies (as opposed to individuals) are not data subjects — disputes about firm-level records follow the correction process in our Terms of Service.

5. Data Retention

  • Account data: for the life of the account and up to 12 months after deletion (backup cycles), except data we must keep for legal or tax reasons.
  • Published content (reviews, disputes' public outcomes): while published; if you delete your account we will, at your choice, delete your reviews or retain them de-identified.
  • Interaction and security logs: IP address, user agent, and referrer are removed after 13 months by an automated daily job. The remaining event records (which page or profile, the interaction type, the timestamp, and — for signed-in users — the link to your account) are retained for aggregate statistics and account features; records linked to your account are deleted with the account (see "Account data" above).
  • Claim-verification evidence (the message and supporting details you submit with a profile claim): purged by the same automated job 90 days after the claim is resolved, unless an active dispute or law requires longer. The fact and outcome of the claim are retained (see next item).
  • Claim and dispute records: retained while the related public record exists, as part of the audit trail supporting our published research, and as needed for legal claims.
  • Billing records: as required by tax and accounting law (typically 6–7 years).

6. Cookies

We use strictly necessary cookies only: session and authentication cookies (including "remember me") and security/CSRF cookies. These require no consent. We do not use advertising cookies, and we do not run third-party analytics trackers; our analytics come from our own first-party server logs (Section 1.2). You can control cookies through your browser settings, but disabling essential cookies will break sign-in.

7. International Transfers

We operate globally and our infrastructure providers may process data in the European Union and the United States. Where personal data moves from the EEA/UK to countries without an adequacy decision, we rely on appropriate safeguards such as standard contractual clauses. You may contact us for information about the safeguards that apply.

8. Security

We use reasonable technical and organizational measures: TLS in transit, hashed passwords, role-restricted admin access, audit logging of administrative changes, and routine verified backups. No system is perfectly secure; we cannot guarantee absolute security. If a breach affects your personal data and the law requires notice, we will notify you and the relevant authority within the required timeframes.

9. Your Rights

Everyone: you may access, correct, or delete your account data, and unsubscribe from marketing at any time (link in every email). Account holders can edit most data in-account; for anything else, email us.

EEA/UK (GDPR/UK GDPR): rights of access, rectification, erasure, restriction, portability, and objection (including to legitimate-interests processing and to direct marketing), and the right to withdraw consent at any time without affecting prior processing. We respond within one month (extendable by two for complex requests). You may lodge a complaint with your supervisory authority; UK residents may complain to the Information Commissioner's Office.

California (CCPA/CPRA): rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information, so there is no opt-out to exercise. We verify identity and respond within 45 days (extendable once); you may use an authorized agent and may appeal our response.

Other jurisdictions (other U.S. state privacy laws, Canada's PIPEDA, and similar): we honor analogous rights on request.

To exercise any right: email [email protected] with "Privacy Request" in the subject.

10. Children

The Site is for professionals and is not intended for anyone under 18. We do not knowingly collect their data; if we learn we have, we will delete it.

11. Changes to This Policy

We will post changes here and update the date above; for material changes we will give account holders notice by email or prominent Site notice before they take effect.

12. Contact

Digital Opportunities Group Enterprises, Inc.
Privacy requests: [email protected]
General: [email protected]