top of page

Privacy Policy

Effective date: 2 June 2026  

1. Who we are and how to contact us

This Privacy Policy explains how personal data is collected and used in connection with the website at www.houseoflegends.art and any related services, content, or digital assets (collectively, the “Website”).

The data controller is Tiger Holdings LLC, a limited liability company organised under the laws of Saint Vincent and the Grenadines, with registered office at First Floor, First St Vincent Bank Ltd Building, James Street, Kingstown, Saint Vincent and the Grenadines (the “Company”, “we”, “us” or “our”). The Company decides why and how your personal data is processed.

For any privacy question, or to exercise your rights, contact us at tigerholdingsmedia@gmail.com.

2. Scope of this Policy and the standard we apply

Our digital assets are offered to a global audience, and because buyers transact on public blockchains and third-party marketplaces, we often cannot identify who holds our assets or determine where they are located. As we cannot exclude the possibility that some users are located in the European Union or the United Kingdom, we apply the EU General Data Protection Regulation (“EU GDPR”) and the UK GDPR (together, the “GDPR”) as the governing standard for this Policy, regardless of where you are located.

This Policy reflects only the processing activities we actually carry out and the obligations that apply to us. It does not grant rights or make commitments beyond those required by applicable law.

3. Blockchain and Web3 data — important limitations

Our digital assets exist on public blockchains (such as Ethereum) and are traded through third-party marketplaces that we do not operate. This has specific consequences you should understand:

  • A public wallet address is pseudonymous and may constitute personal data where it can be linked to an identifiable individual. We may process wallet addresses and on-chain transaction data when you interact with our assets.

  • Public blockchain records are maintained by decentralised networks outside our control. We cannot alter, correct or erase data recorded on a public blockchain. Rights of rectification and erasure (section 8) cannot be exercised against on-chain data, because it is technically impossible for us to do so.

  • Transactions on third-party marketplaces (for example, OpenSea or Coinbase) are governed by those platforms’ own privacy policies, for which we are not responsible.
     

4. What we collect, why, and for how long

We keep data collection to the minimum necessary. The table below sets out each purpose for which we process personal data, the data involved, our lawful basis, and how long we keep it. Retention periods are maximums; we delete or anonymise data sooner where it is no longer needed.

Purpose

Data used

Lawful basis (GDPR Art. 6)

Retention

Responding to enquiries

Name, email address, message contents, and any details you choose to provide

Legitimate interests, Art. 6(1)(f) (responding to people who contact us)

Up to 24 months after the matter is resolved

Fulfilling store orders (where the store is active)

Name, delivery address, email address, order details

Performance of a contract, Art. 6(1)(b)

Duration of the order plus the period required by tax/accounting law (typically up to 7 years)

Operating, securing and improving the Website

IP address, browser and device data, referring website, aggregate usage statistics (via Wix)

 

Legitimate interests, Art. 6(1)(f)

Server logs up to 90 days; aggregate analytics up to 14 months

Blockchain interactions

Public wallet address, on-chain transaction data

Legitimate interests, Art. 6(1)(f) (operating a Web3 project)

On-chain data persists on the public blockchain and cannot be deleted by us

Complying with legal obligations

Any of the above, as required

Legal obligation, Art. 6(1)(c)

As required by the relevant law

Where you give consent (e.g. non-essential cookies)

As described at the point of consent

Consent, Art. 6(1)(a) — withdrawable at any time

Until consent is withdrawn or expires

We do not intentionally collect special categories of personal data (such as data revealing health, ethnicity, religion or political opinions), and we ask that you do not send such data to us.

5. Where we obtain your personal data

We obtain personal data directly from you when you contact us or place an order, and automatically when you use the Website (as described above). Where you interact with our assets through a public blockchain or a third-party marketplace, we may receive the associated wallet address and transaction data from those public or third-party sources. If you follow us on a social-media platform, we may receive limited profile information from that platform in accordance with your settings there.

6. Cookies and similar technologies

The Website is built on the Wix platform. Wix may use cookies and similar technologies that fall into the following categories:

  • Strictly necessary cookies — required for the Website to function and to keep it secure. These do not require consent.

  • Functional and analytics cookies — used to remember preferences and to understand general usage trends. Where required by law, these are set only with your consent.

You can manage or disable cookies at any time through your browser settings, although some features of the Website may not function properly if you do so. Where applicable law requires consent for non-essential cookies, we obtain that consent before they are set.

7. Who we share personal data with

We do not sell your personal data. We share it only with the following categories of recipient, and only as necessary:

  • Service providers that operate the Website and fulfil our requests, including our website host and platform (Wix), our domain registrar (GoDaddy), and any provider that fulfils store orders. These providers act on our instructions under appropriate contractual terms.

  • Third-party platforms you choose to interact with (such as OpenSea, Instagram, or any community channel), which process your data under their own privacy policies.

  • Public authorities, where we are required to disclose data by law or valid legal process.

  • A successor entity, if the Company is involved in a merger, acquisition or sale of assets, subject to this Policy.
     

8. International data transfers

The Company is established in Saint Vincent and the Grenadines, and our service providers may operate in other countries. As a result, your personal data may be processed outside the European Economic Area and the United Kingdom, where data-protection laws may differ from those in your country.

Where we transfer personal data out of the EEA or the UK to a country that has not been recognised as providing adequate protection, we rely on appropriate safeguards where these are required, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement for UK transfers). You may request information about these safeguards using the contact details in section 1.


9. Your rights

Subject to applicable law and the limitations below, you have the right to: request access to your personal data; have inaccurate data corrected; have your data erased; restrict or object to certain processing; and receive your data in a portable format. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

These rights are not absolute. We may decline or limit a request where the law permits — for example, where we need to verify your identity first, where we are required to retain data to comply with a legal obligation, where the data was not provided by you, or where we do not process the data on the basis of consent or a contract. As explained in section 3, we cannot rectify or erase data recorded on a public blockchain, because that is technically impossible for us.

To exercise your rights, contact us using the details in section 1. You also have the right to lodge a complaint with a data-protection authority — in the EU, your local supervisory authority; in the UK, the Information Commissioner’s Office (ICO).
 

10. Security and data breaches

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. No system can be guaranteed to be completely secure. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and you, to the extent and within the timeframes required by applicable law.
 

11. Children

The Website and our digital assets are not directed to children, and we do not knowingly collect personal data from anyone under the age of 18 (or the age of majority in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
 

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind.
 

13. Notice for California residents

This section is provided as a courtesy for residents of California and does not create obligations beyond those that apply to us under California law. Based on its size and activities, the Company does not believe it meets the thresholds that would make the California Consumer Privacy Act (CCPA/CPRA) mandatory. We do not sell or share personal information for cross-context behavioural advertising. To the extent California law applies, California residents may have rights to know, delete, and correct personal information, and the right not to be discriminated against for exercising those rights; you may contact us using the details in section 1 to make such a request.


14. Changes to this Policy and previous versions

We may update this Policy from time to time. When we do, we will post the updated version on the Website, change the version number and effective date shown at the top, and — where the changes are material — take reasonable steps to bring them to your attention before they take effect.

We keep records of previous versions of this Policy. If you would like to see the version that applied at a particular time, or compare an earlier version with the current one, you can request a copy by contacting us at the email address in section 1, and we will provide it.

TOMO  Instagram Feed.png
bottom of page