Innovunode

Privacy Policy

Last updated: 2 August 2026

This Privacy Policy explains how InnovuNode collects, uses, stores and protects personal data when you visit https://www.innovunode.io/, contact us, use our website tools, or connect to public infrastructure operated by InnovuNode.

The first part of this policy applies to the InnovuNode website and its related website services. The separate section titled “COTI Mainnet Node and Public RPC Services” applies specifically to InnovuNode’s COTI mainnet node, JSON-RPC endpoint and WebSocket endpoint.

Who we are

InnovuNode is an independently operated infrastructure provider and community resource supporting the COTI network. InnovuNode operates blockchain infrastructure, monitoring tools, informational resources and community services.

For the purposes of applicable data protection law, InnovuNode is the controller of personal data processed through this website and through the public node infrastructure described in this policy.

Privacy questions, requests or complaints can be submitted through our contact page at https://www.innovunode.io/contact/.

Scope of this policy

This policy applies to:

  • Visitors to the InnovuNode website;
  • People who contact InnovuNode through a contact form or another published communication channel;
  • Users of website tools, dashboards and informational services operated by InnovuNode;
  • Users connecting to InnovuNode’s public COTI mainnet RPC and WebSocket endpoints; and
  • People whose personal data may appear in legitimate security, abuse-prevention or operational records.

Information you provide to us

When you contact InnovuNode, we may process information that you voluntarily provide, including:

  • Your name;
  • Your email address;
  • Your business or project name, where provided;
  • The category or subject of your request;
  • The contents of your message;
  • Any files, links or other information you choose to include; and
  • Subsequent correspondence relating to your request.

We use this information to respond to questions, review feedback, investigate reported problems, communicate about proposed collaborations and maintain appropriate records of correspondence.

Comments

If comments are enabled and you leave a comment, we may collect the information entered into the comments form, together with the submission time, IP address and browser information used for spam prevention, moderation and website security.

An anonymized value derived from your email address may be provided to the Gravatar service to determine whether you use that service. Gravatar is operated by Automattic. Its privacy policy is available at https://automattic.com/privacy/. If a comment is approved, a profile image associated with your Gravatar account may be visible publicly alongside the comment.

Media

If the website allows you to upload images or other media, you should remove embedded location information, including EXIF GPS data, before uploading it. Publicly accessible media may be downloaded by other visitors, who may be able to extract embedded metadata.

Website technical data

When you access the website, our web server, hosting provider or security services may process limited technical information necessary to deliver and protect the website. This may include:

  • Your IP address;
  • The date and time of the request;
  • The requested page or resource;
  • The HTTP request method and response status;
  • The amount of data transferred;
  • Basic browser or device information;
  • The referring page, where supplied by your browser; and
  • Information associated with errors, suspected attacks or abnormal traffic.

This information is processed to provide the website, maintain availability, diagnose technical errors, prevent abuse, enforce reasonable rate limits and protect the website and its users.

Cookies

The website may use cookies or similar local-storage technologies that are necessary for basic website functionality, security and administration.

If comments are enabled, you may be offered the option to store your name, email address and website in cookies so that you do not need to enter those details again when submitting another comment. These convenience cookies may remain for up to one year.

If you access a WordPress login or administration page, temporary and functional cookies may be used to determine whether your browser accepts cookies, maintain an authenticated session, remember display preferences and protect the login process. Login cookies generally expire when you log out or after a limited period. A “Remember Me” option may extend the login period.

Where non-essential analytics, embedded media or other optional technologies require consent under applicable law, they will only be activated after the required consent has been obtained. You can withdraw consent through any cookie controls made available on the website.

Embedded content and external links

Pages on this website may contain embedded content or links from other websites, including videos, images, social media content, dashboards and third-party tools. Embedded content may behave as though you visited the third-party website directly.

Those third parties may collect technical information, use cookies or similar technologies and monitor your interaction with their content. Their processing is governed by their own privacy policies, and InnovuNode does not control their independent processing activities.

How we use personal data

We may use personal data for the following purposes:

  • Providing, maintaining and securing the website;
  • Responding to messages, questions and support requests;
  • Investigating technical issues and bug reports;
  • Reviewing suggestions, feedback and collaboration proposals;
  • Preventing spam, fraud, denial-of-service attacks and other abuse;
  • Monitoring service availability and performance;
  • Maintaining appropriate administrative and security records;
  • Complying with legal obligations and valid legal requests; and
  • Establishing, exercising or defending legal claims.

Legal bases for processing

Where the General Data Protection Regulation or similar legislation applies, we rely on one or more of the following legal bases:

  • Legitimate interests: operating, securing, maintaining and improving the website and node infrastructure; responding to communications; preventing abuse; and protecting our services and users;
  • Consent: where you voluntarily provide information or where consent is required for optional cookies or similar technologies;
  • Contractual necessity: where processing is necessary to provide a service you specifically request or to take steps at your request before entering into an agreement;
  • Legal obligation: where processing is required by applicable law; and
  • Legal claims: where information is necessary to establish, exercise or defend a legal claim.

Who we share personal data with

We do not sell personal data.

Personal data may be disclosed only where reasonably necessary to:

  • Hosting, server, content-delivery, security, email or technical service providers supporting the website;
  • Spam-prevention or website-security providers;
  • Professional advisers where legal, accounting or security advice is required;
  • Government authorities, regulators, courts or law-enforcement bodies where disclosure is legally required; or
  • Other parties where necessary to investigate abuse, protect the service or defend legal rights.

Service providers are given access only to information reasonably necessary to perform their services and are expected to handle that information securely and in accordance with applicable law.

International data transfers

Some service providers or embedded third-party services may process information outside your country or outside the European Economic Area. Where required, appropriate safeguards will be used, such as an adequacy decision, contractual protections or another transfer mechanism permitted by applicable data protection law.

Website data retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.

  • Contact form messages and correspondence: normally retained for up to 12 months after the last meaningful communication, unless a longer period is necessary for an ongoing collaboration, dispute, security matter or legal obligation;
  • Published comments: retained while the comment remains published or while needed for moderation and continuity of the discussion;
  • Comment moderation and spam records: retained for as long as reasonably necessary to prevent repeated abuse;
  • Website access logs: normally retained for no longer than 14 days, unless an entry is required for investigating a security incident or abuse;
  • Website error logs: normally retained for no longer than 30 days; and
  • Security incident records: may be retained for up to 90 days after the incident is resolved, or longer where required for legal proceedings or compliance with law.

Information may be deleted earlier when it is no longer needed. Information may be retained longer where required by law, necessary to resolve a dispute or required to protect the security and integrity of our services.

Your data protection rights

Depending on where you live and the law that applies, you may have the right to:

  • Request access to personal data held about you;
  • Request correction of inaccurate or incomplete information;
  • Request deletion of personal data;
  • Request restriction of processing;
  • Object to processing based on legitimate interests;
  • Request a portable copy of information you provided, where applicable;
  • Withdraw consent at any time where processing is based on consent; and
  • Submit a complaint to the data protection authority responsible for your location.

These rights are not absolute. A request may be limited where retaining or processing information is necessary for security, legal compliance, the rights of others or the establishment, exercise or defence of legal claims.

To submit a privacy request, use the contact form at https://www.innovunode.io/contact/. We may request limited additional information where reasonably necessary to confirm your identity and prevent unauthorized disclosure.

Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss and misuse. These measures may include access controls, encrypted connections, software updates, network restrictions, rate limiting, monitoring and limited log retention.

No internet service can guarantee absolute security. You should avoid sending confidential information through public website forms unless it is necessary for your request.

Children’s privacy

The website and node services are not directed at children, and we do not knowingly collect personal data from children. If you believe that a child has provided personal data through our services, please contact us so that the information can be reviewed and, where appropriate, deleted.

Changes to this policy

We may update this Privacy Policy when our services, infrastructure, legal obligations or data-processing practices change. The date shown at the beginning of the policy indicates when it was most recently updated. Material changes may also be announced through the website where appropriate.


COTI Mainnet Node and Public RPC Services

This section applies specifically to InnovuNode’s COTI mainnet infrastructure, including its Geth node, JSON-RPC endpoint and WebSocket endpoint.

The public endpoints covered by this section are:

How the node service works

The node service receives JSON-RPC or WebSocket requests, forwards valid requests to a COTI-compatible Geth node and returns the resulting response. When you submit a signed blockchain transaction, the node may validate and propagate that transaction to other participants in the COTI network.

Requests are processed automatically. InnovuNode does not require blockchain users to create a website account merely to access the public RPC endpoints.

Minimal reverse-proxy logging

The public node is placed behind an Nginx reverse proxy for connection handling, TLS termination, rate limiting, abuse prevention and operational security.

Access logging for the RPC and WebSocket services is intentionally limited. The node access log may contain only:

  • The source IP address presented to the reverse proxy;
  • The date and time of the request or connection;
  • The HTTP method;
  • The endpoint path, such as /rpc or /ws;
  • The HTTP response status;
  • The number of response bytes transferred; and
  • The total request or connection-processing time.

The node-specific Nginx access log is configured not to intentionally store:

  • HTTP request bodies;
  • JSON-RPC request parameters;
  • Raw signed transaction contents;
  • Private keys, seed phrases or wallet credentials;
  • URL query strings;
  • Referrer headers;
  • Browser user-agent strings; or
  • Cookies.

IP addresses may also be processed temporarily in memory for connection management and per-IP rate limiting. Rate-limit counters are temporary operational values and are not used to create permanent user profiles.

WebSocket connections

For WebSocket connections, the reverse proxy may process the source IP address, connection time, disconnection time, endpoint, connection status and transferred data volume. WebSocket messages are processed transiently to provide the requested node service and are not intentionally stored in the Nginx access log.

Geth operational logs

The underlying Geth software produces operational logs required to run and troubleshoot the blockchain node. These logs may include synchronization status, block-processing information, peer connectivity, software warnings, performance information and error messages.

Geth operational logging is not intentionally used to create histories of individual RPC users. InnovuNode does not intentionally configure Geth to store JSON-RPC request bodies, private keys or seed phrases. In exceptional cases, an application error may include limited technical context necessary to diagnose the failure. Such information is subject to the retention limits described below.

Information processed by the node

Depending on the request you submit, the node may transiently process:

  • Your source IP address and connection metadata;
  • The JSON-RPC method requested;
  • Public wallet addresses;
  • Contract addresses;
  • Block numbers, transaction hashes and other public blockchain identifiers;
  • Read-only contract-call parameters;
  • Signed transaction data submitted for broadcast; and
  • WebSocket subscription requests and related network events.

This information is processed as necessary to execute the requested RPC operation, return a response, maintain the connection or propagate a submitted transaction. Except for the limited operational logs described in this policy, request data is not retained merely because it passed through the RPC service.

Public blockchain information

COTI is a blockchain network. Information included in a valid transaction and propagated to the network may be recorded by independent network participants and may become permanently available through the blockchain.

Depending on the transaction and protocol used, blockchain information may include wallet addresses, contract addresses, transaction hashes, transaction input data, timestamps, block information, fees and other transaction-related data. Privacy-enabled COTI applications may protect particular values or application data, but this depends on the relevant protocol and application.

InnovuNode does not control the COTI blockchain or the independent nodes that receive and store blockchain data. Once information has been included in the blockchain, InnovuNode may be unable to correct or erase it. Users should not include unnecessary personal information in public transaction data, contract input data or other blockchain fields.

Purposes of node data processing

Node-related technical information is processed only where reasonably necessary to:

  • Receive and respond to RPC and WebSocket requests;
  • Propagate signed transactions to the COTI network;
  • Maintain service availability and reliability;
  • Apply connection and request-rate limits;
  • Prevent denial-of-service attacks, scanning, exploitation and other abuse;
  • Diagnose errors, failed requests and performance problems;
  • Monitor capacity and node synchronization;
  • Protect the node, its operator and other users; and
  • Comply with applicable legal obligations.

Legal basis for node processing

Where applicable data protection law requires a legal basis, limited node logging and security processing are based on InnovuNode’s legitimate interests in operating secure, stable and abuse-resistant public blockchain infrastructure.

Processing of an RPC request is also necessary to provide the technical service actively requested by the user. Additional information may be retained where required by law or necessary for the establishment, exercise or defence of legal claims.

Node data retention policy

The following retention periods apply to InnovuNode’s COTI mainnet node services:

  • Raw Nginx RPC and WebSocket access logs: retained for a maximum of 7 days and then automatically rotated or deleted;
  • Nginx error logs: retained for a maximum of 14 days, unless required for investigation of a specific fault or attack;
  • Geth operational logs: retained for a maximum of 14 days under normal operation;
  • Temporary rate-limit and connection counters: retained only for the short period required to enforce the applicable limit and then automatically expire;
  • Security incident extracts: relevant entries may be isolated and retained for up to 90 days after an incident is resolved;
  • Legal or regulatory matters: relevant records may be retained longer where required by law, a valid legal request or an active legal dispute; and
  • Aggregated operational statistics: statistics that do not contain raw IP addresses or individual request contents may be retained for up to 12 months for capacity planning and reliability analysis.

Raw node logs are not retained indefinitely. They are deleted or overwritten through automatic log rotation unless a limited portion must be preserved for a documented security investigation or legal requirement.

No advertising profiles or sale of node data

InnovuNode does not sell RPC usage data and does not use RPC traffic to create advertising profiles.

InnovuNode does not intentionally correlate wallet addresses with IP addresses for marketing, user profiling or behavioural advertising. Limited technical correlation may occur temporarily where necessary to investigate an attack, prevent abuse or diagnose a specific service failure.

Sharing of node information

Limited node-related information may be processed by infrastructure providers that host, route, protect or monitor the node service. Access is limited to what is reasonably necessary to provide those infrastructure services.

Signed transactions submitted for broadcast may be shared automatically with COTI network peers. This propagation is an essential part of providing a blockchain RPC service and is separate from disclosure of reverse-proxy access logs.

Relevant log information may also be disclosed where required by law or where reasonably necessary to investigate abuse, respond to a security incident or defend legal rights.

Security and abuse prevention

The node may use TLS encryption, request-size limits, method restrictions, connection limits, per-IP rate limits, firewall rules and automated abuse detection. Requests that are malformed, excessive, unauthorized or harmful may be rejected or temporarily blocked.

These controls are intended to protect service availability and do not guarantee that every malicious request will be detected or prevented.

Your rights relating to node logs

You may contact InnovuNode to request access to, correction of, restriction of or deletion of personal data contained in identifiable node logs, subject to applicable law and the technical ability to identify the relevant records.

To help locate a relevant node log entry, you may need to provide the approximate date and time of the connection, the endpoint used and the source IP address involved. We may request reasonable proof that you were assigned that IP address at the relevant time.

Because raw access logs are retained for a maximum of 7 days, older identifiable access records may already have been automatically deleted before a request is received.

These rights do not generally allow InnovuNode to remove information independently recorded on the COTI blockchain or held by other network participants.

Contact regarding the node service

Questions about node logging, retention, security or privacy can be submitted through https://www.innovunode.io/contact/.