Privacy Notice
Effective October 1, 2025
World Foundation Privacy Notice
1. Introduction
1.1 This Privacy Notice describes how World Foundation and its affiliates (“we”, “us”, “our”, or “World”), process personal data in relation to the world.org, developer.world.org and docs.world.org websites (“Websites”), features, where applicable, provided by World Foundation according to the User Terms and Conditions (“Features”) and applications for grant programs (“Grants”).
1.2 World Foundation is a nonprofit organization that serves as the steward of the World ID protocol. The interface to securely create, store, verify, and use World ID to prove that you are a real and unique human without revealing who you are is provided by companies building Orbs - please see their respective privacy notices (available here) for information on their personal data processing practices.
2. What data do we collect?
2.1 We collect the following information directly from you when you use our website and the Features that you provide to us:
- Digital wallet address and blockchain transaction data: When you initiate a transaction on World Chain using our sequencer or when you use our other blockchain-based Features, we collect information about digital wallet address, timestamp and other transaction details.
- Grants application data: When you apply for a grant, we may collect such information as your name, email address, location, digital wallet address, as well as data needed for KYC purposes such as information from government documents.
- Customer support enquiries and other communications: When you contact us for customer support or otherwise communicate with us, we may collect information related to such communication, including your name, email address and other information that you provide us in relation to your query.
- Information related to events: When we enable your attendance in events that we organize, depending on the nature of the event, we may collect your name, email, other contact details, affiliation and position.
- Newsletter and updates contact details: When you want to be notified about updates to the World project may collect your name, email or other contact details.
- Developer portal account data: When you set up a developer account, we collect your email address, your username, information about teams and project you are engaged in.
2.2 We collected the following information that we automatically collect through your visits to our websites and/or use of Features:
- Usage information: We collect information about your activity on our Website, like frequency of use, areas and features that you access, visit, or use, and engagement with particular features.
- Device-related information: We may collect a limited amount of device-related information such as IP address and browser information, operating system, language and time zone.
- Cookies: When you use our Websites, we may place cookies or similar technologies on your device and collect information through such technologies. Please see more information in our Cookie Policy for more information about our use of cookies and tracking technologies.
2.3 We may receive the following information from third parties:
- Rewards data: When using the Invite Rewards feature, we receive information from app providers (such as Tools for Humanity) that is necessary for payouts supported by this feature, such as digital wallet address.
- Safety and public blockchain data: We may use service providers to provide us with fraud-prevention services and to analyze blockchain transactions, where we receive such data as information about wallets linked to potential fraud and or illicit activity and information about suspicious transactions.
3. Why do we use your data? Legal Bases for Processing
3.1 The table below outlines the purposes for which we use personal data together with legal bases that we may apply.
Why we process your data | What personal data we process | What is the legal basis for processing |
Executing transactions and payouts supported by Worldcoin Interface and the Invite Rewards | Digital Wallet address and Blockchain transaction data Rewards data Device-related information | Performance of contract |
Executing transactions on World Chain using our sequencer | Digital Wallet address and Blockchain transaction data | Performance of contract |
Ensuring proper functioning of our Websites and using Cookies as described in Cookie Policy | Cookies Device-related information | Legitimate interest to have our Website work properly Consent |
Analyzing the performance of our Websites and improving it as well as maintaining its security | Usage Information Device-related information Cookies | Legitimate Interest to ensure quality and security of the Website Consent |
Analyzing the performance of the blockchain-based features and maintaining their security | Digital Wallet address and Blockchain transaction data Device-related information | Legitimate Interest to ensure quality and security of the blockchain-based features |
Fraud prevention and compliance with applicable laws such as anti-money laundering law, and sanctions | Digital Wallet address and Blockchain transaction data Rewards data Safety and public blockchain data Device-related information | Legitimate interest to prevent certain types of fraud Legal obligation |
Customer service requests, complaints and inquiries handling | Customer support enquiries and other communications Device-related information | Performance of contract |
Organization of events and other engagements with you | Information related to events Newsletter and updates contact details: | Consent Legitimate Interest to organize events and engagements with interested parties |
Provide the developer portal functionality | Developer portal account data Usage information Device-related information Cookies | Performance of contract Legitimate interest to ensure quality and security of the developer portal |
Applying for Grants and performing KYC procedures | Grants application data | Consent Performance of contract |
Defending or asserting our rights in courts and other authorities | All types of personal data listed in this policy | Legitimate interest to defend or assert our rights |
4. Who do we share your personal data with?
4.1 The data we collect may be shared with team members across our organization (including Foundation’s affiliates) when they need access to such data for the purposes set out in this Privacy Notice.
4.2 We also share your data with vendors and service providers under contract when this is needed for provision of services to us. Such third parties that may have access to your personal data include: Tools for Humanity Corp., (which provide us, among others, with software development and maintenance services) its subsidiaries and subprocessors, KYC services providers, IT services and cloud solutions providers, blockchain-related services providers, auditors, consultants and law firms.
4.3 We may share your personal data if it is required by applicable law, legal process or a binding governmental request.
4.4 We may share your personal information in connection with, or during negotiations concerning, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
4.5 In principle, we process your personal data within the European Union and in the United States subject to appropriate security measures. If your personal data needs to be transferred internationally to a recipient in a country that does not provide an adequate level of protection for personal data under the terms of the European Union General Data Protection Regulation (GDPR) or other data protection legislation, Foundation takes appropriate measures to ensure that your personal data remains adequately protected, in particular through entering into the European Commission Standard Contractual Clauses (SCCs) (see more information about the SCCs here). Please contact us should you like to request a copy of the SCCs.
4.6 Transaction information related to your use of our features, in particular World Chain, Worldcoin Interface or Invite Rewards, is recorded on a public blockchain. Blockchains are public ledgers of transactions that are maintained on decentralized networks operated by third parties that are not controlled or operated by us.
5. How long do we retain your personal data?
5.1 We typically retain your data for as long as is reasonably necessary to fulfill the purposes outlined in this Privacy Notice. Subsequently, we will delete the data or render it anonymous unless we are required by law or order to retain your personal data as necessary to comply with our legal and regulatory obligations.
6. What rights do you have with respect to your personal data?
6.1 Under applicable data protection laws, you may have rights to:
- Access and get a copy of your personal data: You have the right to obtain from us upon request information about the personal data we process concerning you (such as the categories of personal data we have collected about you and their sources, the purposes for which the we use personal data and information whom personal data we disclose). You may also request a copy of personal data concerning you as well as request the receipt or transmission to another provider, in a machine readable form, the personal data that you have provided to us.
- Correct and erase your data: You may request us to correct any inaccurate personal data we process about you. Also, you may ask us to erase the personal data that relate to you.
- Object to data processing: You may object to our processing of your personal data, in particular when it’s based on a legitimate interest or used for marketing purposes. You may also request suspension of processing of your personal data.
- Withdraw your consent: You may also withdraw your consent to data processing when it is based on consent. Note that withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- File a complaint with the competent supervisory authority: You may file a complaint with your local data protection authority. If you live in the EU, you may also file a complaint with our lead Supervisory Authority in the EU - the Bavarian Data Protection Authority.
6.2 You may control the personal data that we have collected and exercise any of the rights by contacting us at our Request Portal.
6.3 We do not sell personal data we collect. Please note that we may use third-party cookies for advertising purposes which in some jurisdictions can be considered as a “sale” or “share” of data. Please refer to our Cookie Policy for further information about our use of cookies and information on how to manage your cookie choices.
7. Security of data
7.1 We implement legal, technical, and organizational safeguards to protect your personal data's confidentiality and security. The protection framework includes developing robust policies, implementing access restrictions, conducting regular employee training sessions, and monitoring personal data handling practices. Additionally, we maintain consistent oversight of all personnel and service providers who have access to personal information.
8. Protection of minors
8.1 You must be at least the age of majority in your country (and a minimum of 18 years old) to use our Features. We take the protection of minors seriously – if you believe someone under 18 years of age is using our Features, please contact us immediately via our Request Portal or other channels set out in this Privacy Notice.
9. Update of this Privacy Notice
9.1 We can update this Privacy Notice any time. When we do, we will publish an updated version and effective date on this page, unless another type of notice is required by applicable law.
9.2 If you wish to access previous versions of this Privacy Notice, please contact us via our Request Portal or other channels set out in this Privacy Notice.
10. Data controller and Contact information
10.1 If you have questions or concerns regarding this Privacy Notice, wish to exercise your rights, or to contact our Data Protection Officer, Marcin Czarnecki, please submit your request through our Request Portal, send us an email to [email protected] or send us a letter to the relevant address indicated below.
10.2 Unless otherwise stated in this Privacy Notice,the data controller for responsible for processingpersonal data used depends on your location:
10.2.1 If you live in the European Union, one of the EFTA States or in the United Kingdom - World Network (Europe) GmbH, MIes-van-der-Rohe-Str. 6, 80807 Munich, Germany
10.2.2 If you live outside of the European Union, the EFTA States and the United Kingdom - World Foundation, Suite 3119, 9 Forum Lane, Camana Bay, PO Box 144, George Town, Grand Cayman KY1-9006, Cayman Island.
10.3 The data controller for personal data used in the context of the Worldcoin Interface Feature, the Invite Rewards or Grantsis World Foundation, Suite 3119, 9 Forum Lane, Camana Bay, PO Box 144, George Town, Grand Cayman KY1-9006, Cayman Island, regardless of your location.
WFPS20250801