Last Updated: September 8, 2026
At MineFarm (operated by NuCompute Exchange LTD, London, UK), we are committed to upholding the highest global standards of privacy, data protection, and cryptographic security. This Privacy Policy describes how we collect, process, secure, and retain your personal data under the UK General Data Protection Regulation (UK GDPR), the EU GDPR, the Data Protection Act 2018, and emerging international privacy frameworks.
1. Information We Collect
In accordance with the principle of data minimization (UK GDPR Art. 5(1)(c)), we collect strictly the operational metadata necessary to deliver distributed computing:
- Account Credentials: Usernames, email addresses, and cryptographic salted password hashes (bcrypt).
- Hardware Fingerprints: Node identifiers, operating system strings, CPU/GPU controller model descriptors, and computed 128-bit hardware hash digests.
- Network & Routing Telemetry: Public IP addresses, heartbeat ping logs, reverse SSH gateway port allocations (`50001+`), and private VPN tunnel mesh IPs (`10.205.0.0/16` or `10.8.0.0/16`).
- Activity & Security Logs: Read-only records of platform events (logins, rig status changes, rate updates, API calls) alongside requesting IP addresses for security audit logging.
- Zero Personal Bank Credential Storage: MineFarm does NOT collect, process, or store personal banking credentials (bank account numbers, sort codes, IBANs, SWIFT codes) or credit/debit card numbers on its servers. All payment processing, bank verification, and provider payouts are managed exclusively off-premise via PCI-DSS Level 1 certified Stripe Connect Express.
- Zero Tax Data Storage: We explicitly do NOT collect, request, or store Social Security Numbers (SSNs), Employer Identification Numbers (EINs), VAT numbers, or personal tax forms (Form W-9, Form W-8BEN) on our servers. All tax identity collection, TIN matching, and filings are processed off-premise via Stripe Connect Express.
2. Lawful Bases for Processing (UK/EU GDPR Article 6)
We process personal data strictly where a recognized statutory legal basis exists:
- Contractual Necessity (Art. 6(1)(b)): To register your account, provision GPU/CPU compute instances, establish zero-port reverse SSH tunnels, meter real-time usage, and disburse provider earnings.
- Legitimate Interests (Art. 6(1)(f)): To maintain platform security, prevent Sybil hardware spoofing via Proof-of-Work verification, mitigate abuse, and optimize cluster routing performance.
- Legal Obligation (Art. 6(1)(c)): To satisfy statutory accounting and tax reporting obligations, enforce international trade sanctions (UK, US, EU), and comply with mandatory cybersecurity incident disclosures under the EU NIS2 Directive.
- Consent (Art. 6(1)(a)): For optional marketing communications, non-essential cookies, and participation in voluntary research/beta programs. Consent may be revoked at any time.
3. International Data Transfers & Cross-Border Mechanisms
When personal data or compute telemetry is transferred across international borders, MineFarm enforces strict statutory transfer safeguards:
- UK International Data Transfer Addendum (IDTA): Used for transfers originating within the United Kingdom to third-country sub-processors.
- EU Standard Contractual Clauses (SCCs): Module 3 (Processor-to-Processor) and Module 2 (Controller-to-Processor) clauses implemented for European Economic Area transfers.
- UK-U.S. Data Bridge & Data Privacy Framework (DPF): Transatlantic transfers to certified U.S. infrastructure providers (such as Stripe, Inc.) rely on the UK Extension to the EU-U.S. Data Privacy Framework.
- Geographic Workload Pinning: Enterprise clients can enforce geographic isolation flags, ensuring that compute containers and private storage volumes remain pinned strictly to selected sovereign jurisdictions (UK, EU, US).
4. Statutory Data Retention Schedule
Personal data and system telemetry are retained only as long as necessary to fulfill operational, contractual, and legal obligations:
- Financial, Billing & Invoicing Records: Retained for seven (7) years following transaction completion in accordance with UK HMRC and statutory tax audit laws.
- Customer Support Tickets & Dispute Files: Retained for three (3) years from ticket closure to ensure dispute resolution and service quality assurance.
- Network Connection & Telemetry Logs: Retained in active storage for ninety (90) days before automated rotation and permanent deletion.
- Ephemeral Agentic AI Context & WASI Memory: Pure zero-retention memory purge. Task trajectories, intermediate prompts, and WebAssembly linear memory are zeroized immediately upon task completion.
5. U.S. Multi-State Privacy Rights (CCPA/CPRA, VCDPA, CPA, CTDPA)
For residents of California, Virginia, Colorado, Connecticut, and other qualifying U.S. states, the following rights apply under state privacy statutes:
- Right to Know & Access: You have the right to request disclosure of the categories and specific pieces of personal information collected.
- Right to Deletion: You may request deletion of personal information subject to legal record-keeping exceptions.
- No Sale or Sharing of Personal Information: MineFarm does NOT sell personal data or compute outputs to third parties for monetary or commercial consideration.
- Global Privacy Control (GPC): Our web platform honors Global Privacy Control (GPC) universal opt-out signals transmitted by client browsers.
- Non-Discrimination: We do not discriminate against any user for exercising statutory privacy rights.
6. GDPR Compliance & Self-Service Right to Erasure (Right to Forget)
Under UK GDPR and EU GDPR Article 17, all users and node operators possess the statutory Right to Erasure (the "Right to be Forgotten"):
- Self-Service Account Wiping: You can permanently delete your account, credentials, API keys, OpenVPN configs, farms, rigs, and transaction logs at any time directly through the Self-Deletion feature in your Settings.
- Irreversible Sanitization: Once authenticated, deletion takes effect immediately. Associated server files, database rows, and authentication tokens are purged permanently.
7. Hardware-Level Confidential Computing & Memory Isolation
For workloads deployed to nodes with verified "CC" (Confidential Compute) attestation:
- Silicon-Level Cryptographic Isolation: Data in memory is encrypted in hardware via NVIDIA Hopper/Blackwell CC or AMD SEV-SNP. The host operating system, hypervisor, and provider have zero visibility into plaintext memory.
- Zero-Copy Register Scrubbing: Upon job completion, hardware registers and VRAM memory blocks are zeroized immediately (NIST SP 800-88 Rev 2).
- Immutable Merkle Audit Logging: Attestation quotes and cryptographic execution receipts are anchored in tamper-proof Merkle ledgers for SOC 2 Type II and HIPAA compliance.
8. Schedule I: Campaign Attribution (UTM Data) & Cookies
We collect standard campaign attribution parameters (utm_source, utm_medium, utm_campaign) to measure advertising effectiveness and prevent referral fraud. UTM data is retained for twelve (12) months before automated aggregation or deletion. Essential session cookies (PHP_SESSION_ID) are used strictly for authentication.
NuCompute Exchange LTD
• Company No. 15892410 • Registered in England & Wales
Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
VAT Registration Number: GB 452 8192 34
© 2026 MineFarm. All rights reserved.