Trust and privacy
Privacy at HOL
Hashgraph Online DAO LLC operates hol.org, the HOL Points program, the Universal Agentic Registry experience, HOL Guard, and related software and developer services. This page gives people and software agents a clear summary of how privacy is handled and points to the complete legal policy. The complete Privacy Policy was last updated on June 29, 2026 and remains the controlling description of data practices, rights, service providers, retention, security, and contact procedures.
Data HOL may process
Depending on the service used, HOL may process account identifiers, contact information, authentication records, workspace and device metadata, product events, support messages, subscription records, security telemetry, agent or registry metadata, and information needed to operate connected integrations. Some HOL products interact with public blockchain networks. Information written to a public blockchain can be visible to third parties and may be permanent even when an off-chain account is changed or deleted. Users should not submit secrets, credentials, regulated data, or other highly sensitive information unless a product expressly supports that use and the appropriate controls are configured.
Why information is used
Information is used to provide and secure services, authenticate users, operate workspaces and integrations, process payments, respond to support requests, prevent abuse, measure product performance, improve reliability, comply with legal obligations, and communicate service or policy changes. HOL uses service providers for infrastructure, analytics, email, authentication, payments, and related operations. The complete policy names categories of providers and explains the safeguards and legal bases that apply.
Choices and rights
Depending on location and applicable law, users may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information. Users may also be able to manage consent, communication choices, cookies, and connected services through account or privacy settings. Requests can be submitted to [email protected]. The complete policy explains identity verification, authorized agents, appeals, response periods, and region-specific rights.
Security and agent access
Public crawlers and AI agents are permitted to read public pages and machine-readable resources, but permission to crawl does not grant access to private accounts, workspaces, protected APIs, personal data, or confidential content. Protected resources require authentication and are subject to authorization scopes, rate limits, audit controls, and product-specific terms. Security or privacy concerns should be reported through the contact channels in the complete policy so they can be investigated without exposing sensitive details publicly.