1. Data controller
Data controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG):
SGA - Sovereign Global Alliance, Marcel Hermann Rappold, Bruder-Willram-Straße 7, 6300 Wörgl, Austria
E-mail (general): info@sga-connect.org
E-mail (technical support / platform): support@sga-connect.org
E-mail (data protection enquiries): info@sga-connect.org
Legal notice: https://app.sga-connect.org/legal/en/impressum
2. Scope
This privacy policy applies to SGA - Sovereign Global Alliance (SGA) and covers:
• the public information site https://sga-connect.org (foundations, practical examples, reference, downloads, contact form, seminar registration)
• the SGA Connect platform (member area, APIs, XRPL/Xaman login, optional modules such as e-mail, shop, payments, AI/usage, LiveKit)
• locale variants of the organisation website to be provided via the hub in future
Where individual purpose enterprises are separate controllers (e.g. their own shop or e-mail domain), their privacy notices may apply additionally.
For wallet providers (e.g. Xaman) and payment service providers, their own privacy information applies.
3. Website sga-connect.org — contact & seminars
On the public website https://sga-connect.org we process data that you voluntarily submit to us:
- Contact form: name, optional telephone, e-mail, message — purpose: handling your enquiry (Art. 6(1)(b) and (f) GDPR)
- Seminar registration: first name, surname, date/place/country of birth, domicile, e-mail, telephone, seminar selection, security check — purpose: organisation and confirmation of the GC IV foundation seminar (Art. 6(1)(b) GDPR)
- Consent in the registration form: processing for the purpose of seminar organisation; no disclosure to third parties outside the processors named in this notice
- Landing page & preview: technical access data on page load (IP truncated in statistics optionally, timestamp, browser) — Art. 6(1)(f) GDPR (operation and security)
Seminar cancellations: seminars@sga-connect.org. Seminar prices (as stated on the website): first attendance 250 EUR, repeat attendance 210 EUR.
Technical access data (IP, timestamp, browser) may be recorded in server logs when the website is accessed (Art. 6(1)(f) GDPR — operation and security).
4. Categories of personal data
Depending on use, role and activated modules, we process in particular the following categories of data:
- Master data: name, display name, contact (e-mail, telephone), language, address, membership and purpose-enterprise assignment
- Authentication and identity data: XRPL address, XID, session token, nonce/expiry, signature proofs, roles, permissions, login history
- Usage and log data: API calls, feature usage, AI token/cost usage, audit events, error and security logs
- Process performance telemetry (PPO): pseudonymised runtime measurements for defined platform flows (e.g. voice triage, DMS, Site Studio) — without plaintext member ID in raw data
- Communication data: e-mail content, subject, recipients/senders, attachment metadata (in the e-mail module)
- Payment and transaction data: amounts, currency, payment status, payment intent IDs, wallet balances and booking history (depending on module)
- Content data: website blocks, documents, seminar registrations, accounting/EÜR entries, uploaded files
- Technical data: IP address, timestamps, browser/user agent, device information, referrer, cookies and localStorage contents (where personal)
- Speech/media data: when using voice/AI or LiveKit, audio metadata and connection data may arise
5. Purposes and legal bases
We process personal data only where a legal basis exists. The main purposes and bases are:
- Provision of the platform, contract performance, member administration — Art. 6(1)(b) GDPR
- XRPL/Xaman login, identity binding, session management — Art. 6(1)(b) and (f) GDPR (legitimate interest in secure authentication and abuse prevention)
- Role, ABAC and permission checks, governance — Art. 6(1)(b), (c) and (f) GDPR
- E-mail, shop and payment processing — Art. 6(1)(b) GDPR
- AI/usage logging (costs, quotas, billing) — Art. 6(1)(b) and (f) GDPR
- IT security, error analysis, audit records — Art. 6(1)(f) GDPR
- Process performance optimisation (PPO): technical spans for load times and system stability — Art. 6(1)(f) GDPR; optional extended diagnostic spans only with opt-in in master data — Art. 6(1)(a) GDPR
- Compliance with legal obligations (e.g. retention, disclosure to authorities) — Art. 6(1)(c) GDPR
- Consent-based processing (e.g. optional newsletter, non-essential cookies) — Art. 6(1)(a) GDPR (revocable at any time)
6. Provision of data and consequences of non-provision
Certain information is required to use the member area (e.g. successful authentication, assignment to role/purpose enterprise). Without this data we cannot provide access.
Optional information (e.g. additional contact details) serves convenience; refusing it generally does not restrict core functions.
7. XRPL, Xaman (XUMM) and blockchain
When logging in via Xaman/XUMM we generate a sign-in payload. We process among other things XID, nonce, expiry, XRPL address and the result of cryptographic signature verification on our servers.
Xaman/XUMM (Xumm BV, Netherlands) is a separate provider of the wallet app. Its privacy policy and terms apply additionally: https://xumm.app/legal/privacy
We transmit to the XUMM API only the payload data technically required for sign-in. API keys are stored server-side and not exposed in the browser.
Transactions and balances on the XRP Ledger (XRPL) may be publicly visible. We additionally store associations (e.g. member ↔ XRPL address) in our systems in accordance with this notice.
8. Recipients and processors
Depending on configuration and environment, data may be transmitted to the following categories of recipients. Contracts pursuant to Art. 28 GDPR exist with processors where required:
- Hosting/frontend deployment (e.g. Vercel Inc., USA — server logs, IP)
- Database/auth (e.g. Supabase/PostgreSQL — storage of member and usage data)
- E-mail transport (e.g. Stalwart on own VPS or Brevo/Sendinblue — delivery)
- Payment service providers (e.g. Stripe, Inc. — payment processing, fraud prevention)
- AI/speech services (e.g. Aethera service, xAI/Grok for TTS — only when actively used)
- Real-time communication (e.g. LiveKit, Inc. — audio/video signalling and media relay)
- Xaman/XUMM API (Xumm BV, NL — sign-in payload creation and status)
- IT service providers in the context of maintenance and support (access on need-to-know basis only)
9. Transfers to third countries
Some service providers are based outside the European Economic Area (EEA), particularly in the USA (e.g. Vercel, Stripe, LiveKit).
Where required, we ensure appropriate safeguards, in particular EU Standard Contractual Clauses (SCC) pursuant to Art. 46 GDPR, supplementary technical and organisational measures and — where available — provider certifications.
Specific safeguards and sub-processors can be provided on request at info@sga-connect.org.
10. Storage period
We store personal data only as long as necessary for the stated purposes or where statutory retention periods apply. Principles:
- Session and login data: until logout or session expiry; refresh tokens per security configuration
- Audit and security logs: typically 6–24 months, longer for ongoing incidents or legal obligation
- AI/usage logs: for billing and quota generally up to 24 months, unless a longer legal obligation applies
- PPO raw spans: default 14 days; with opt-in "extended process telemetry" up to 90 days; hourly aggregates without personal reference up to 400 days
- Contract, accounting and payment records: up to 7 years under Austrian retention rules, where applicable
- E-mail content: per purpose-enterprise policy and technical architecture; deletion after purpose ceases, unless archiving duty applies
- Demo/test data (staging): may be labelled and deleted earlier after test purpose
11. Process performance telemetry (PPO)
To improve load times and stability we capture technical measurement points (spans) for defined user flows. The following applies:
- Pseudonymisation: raw data contains no plaintext member ID, but an HMAC hash
- Data minimisation: only catalog-defined technical attributes; no raw audio, no e-mail/notification text, no IP in PPO spans
- Default retention: raw spans 14 days; anonymised hourly rollups without personal reference longer
- Opt-in: in master data you can enable "extended process telemetry" — then additional technical detail attributes and up to 90 days raw retention
- Revocation: opt-in can be disabled at any time in master data; deletion on request to info@sga-connect.org
- No marketing tracking: PPO is not advertising analytics and does not require a separate marketing cookie banner
13. Automated decisions and profiling
Role and permission checks (ABAC) are automated to control access to functions. This does not result in legally binding decisions within the meaning of Art. 22 GDPR against consumers without human involvement.
We do not conduct advertising profiling beyond the core functions described. Should this change, we will inform you separately.
14. Your rights as a data subject
Under the GDPR you have in particular the following rights. To exercise them, a message to info@sga-connect.org is sufficient. We may require confirmation of your wallet/member identity for verification.
- Access to processed data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure ("right to be forgotten", Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR), where applicable
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given with effect for the future (Art. 7(3) GDPR)
Consent given can be withdrawn at any time with effect for the future without affecting the lawfulness of processing until then.
15. Response period and right to complain
We generally respond to data subject requests within one month (Art. 12(3) GDPR). In complex cases the period may be extended by up to two further months; we will inform you in advance.
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
Competent supervisory authority in Austria: Austrian Data Protection Authority (DSB), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at
16. Security of processing
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR, including role-based access control (ABAC), signature verification for Web3 login, encryption in transit (TLS), least privilege, logging of security-relevant events and separation of test/production environments.
Absolute security cannot be guaranteed. You share responsibility for your wallet, devices and credentials.
If you suspect a data breach, contact us immediately at info@sga-connect.org.
17. Minors
The platform is not directed at children under 14. If you are aware of processing of minors' data without required consent, contact us for review and deletion.
18. Changes to this notice
We update this privacy policy when the legal situation, technology or scope of services changes materially. The current version is available at https://app.sga-connect.org/legal/en/privacy (last updated: 2026-07-08).
Summary: SGA processes member data for platform operation, XRPL/Xaman login, roles, optional e-mail/shop/payments/AI. Processors may include Vercel, Supabase, Stripe, LiveKit, XUMM. GDPR requests: info@sga-connect.org. Technical support: support@sga-connect.org. The Austrian DSB is the supervisory authority.
This is an AI-assisted translation of the German original. In case of any discrepancy, only the German version is legally binding.