Privacy Policy (EU)

Last updated: 13 July 2026

This Privacy Policy explains how WeAreLyra processes the personal data of users who visit the website wearelyra.net (the “Site”) or sign up for the informational services offered through it. This document is drafted in accordance with Regulation (EU) 2016/679 (the “GDPR”), which applies as the Site is directed at users located in the European Union.

1. Data controller

The data controller is WeAreLyra LLC, a limited liability company incorporated under the laws of Georgia, with its registered office in Tbilisi (Georgia), identification number 404789635 (the “Controller”).

For any request concerning the processing of personal data, you can contact the Controller at the email address: support@wearelyra.net.

2. Scope

This policy applies exclusively to the Site, including the main page, the Resources section and the related informational pages. The Site is purely informational and editorial in nature and also allows users to voluntarily sign up, through a dedicated form, to receive the free guide, the informational newsletter and updates on the project and on the future launch of Lyra.

The Site does not allow users to open accounts, carry out cryptocurrency transactions, hold or safeguard funds, execute payments or access financial services of any kind, and does not collect financial data, wallet-related data or cryptographic keys.

3. Personal data processed

a) Email address. This is the only personal data requested directly from the user through the sign-up form, in order to receive the free guide and the informational newsletter.

b) Technical browsing data. During normal browsing, technical data such as IP address, browser type and pages visited may be collected automatically. This data is used exclusively for the operation and security of the Site and is not associated with identified users. For the use of cookies, please refer to the Cookie Policy published on the Site.

Providing your email address is optional: if you do not provide it, you will simply be unable to receive the guide and the newsletter, without affecting your ability to browse the Site.

4. Purposes and legal basis of the processing

a) Sending the free guide requested by the user and the informational newsletter dedicated to the world of cryptocurrencies, including updates on the development and launch of the Lyra product. Legal basis: the data subject’s consent (Art. 6(1)(a) GDPR), expressed by voluntarily signing up through the form.

b) Technical operation, maintenance and security of the Site. Legal basis: the Controller’s legitimate interest (Art. 6(1)(f) GDPR) in ensuring the operation and security of the Site.

Personal data is not used for profiling purposes, is not subject to automated decision-making and is not transferred or sold to third parties for marketing purposes.

5. Processing methods and processors

Data is processed by electronic means, with technical and organizational measures appropriate to ensure the confidentiality and security of the data.

For the management of sign-ups and the sending of email communications, the Controller relies on the Brevo platform, provided by Brevo SAS, a company based in France (European Union), which acts as a data processor pursuant to Art. 28 GDPR, in accordance with the applicable Data Processing Agreement. According to Brevo’s documentation, subscribers’ data is stored on servers located within the European Union.

6. Transfers of data to third countries

Subscribers’ data is stored within the European Union. The Controller is based in Georgia and, for the processing described in this policy, is directly subject to the GDPR pursuant to Art. 3(2), as it offers services to users located in the European Union. Any access to the data by the Controller from Georgia takes place in a limited manner, solely for the purposes indicated in this policy and in compliance with the obligations that the GDPR places directly on the Controller. Data subjects may request further information by writing to the contact address indicated in Article 1.

7. Data retention

The email address is retained until consent is withdrawn, i.e. until the user unsubscribes. Following unsubscription, the data is removed from the mailing list and deleted within 30 days, unless legal obligations require further retention. Technical browsing data is retained for the time strictly necessary for operational and security purposes.

8. Rights of the data subject

Pursuant to Articles 15 to 22 of the GDPR, data subjects have the right to obtain access to their personal data, rectification, erasure, restriction of processing, data portability, as well as the right to object to the processing.

Data subjects may withdraw their consent at any time, without affecting the lawfulness of the processing carried out before such withdrawal: consent may be withdrawn via the unsubscribe link included in every email or by writing to support@wearelyra.net.

Data subjects also have the right to lodge a complaint with a supervisory authority; for users located in Italy, the competent authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority).

9. Minors

The Site and the informational services offered are not intended for persons under the age of 18. The Controller does not knowingly collect personal data from minors. Should it become aware of a sign-up made by a minor, the Controller will promptly delete the relevant data.

10. Changes to this policy

The Controller reserves the right to amend or update this Privacy Policy, including in relation to the evolution of the Site and of the services offered. The updated version is published on this page with an indication of the date of the last update. Substantial changes affecting the processing of subscribers’ data will be communicated by email.