Overview

OpenWorld, Inc., a Nevada corporation whose registered office is at ____________________ (“OpenWorld”, “we”, “us”) operates the website at openworld.dev (the “Site”). This Privacy Policy describes the personal information we collect through the Site and in our communications with you, how we use and share it, and the choices you have.

For the purposes of the EU General Data Protection Regulation (“EU GDPR”), the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act (2021 Revision) of the Cayman Islands (the “Cayman DPA”), OpenWorld is the controller of the personal data described in this policy. You can reach us about any privacy matter at connect@openworld.dev or at the address above.

We have not appointed a data protection officer; privacy enquiries are handled by the contact above.

We have designated a representative in the European Union and a representative in the United Kingdom for the purposes of Article 27 of the EU GDPR and the UK GDPR respectively, whose details are set out below.

This policy applies to the Site and to enquiries you send us from it. It does not cover the practices of third parties whose websites or services we link to, including the U.S. Securities and Exchange Commission’s EDGAR system where our filings are published.

It also does not cover personal data we process on behalf of a client under a services agreement, where the client is the controller and its own privacy notice applies, or personal data recorded on a public blockchain, which by design is permanent, publicly visible and outside the control of any single party including us.

Information we collect

Information you give us

The contact forms on the Site open your own email application with a pre-filled message. Anything you send us arrives as an ordinary email, so we receive whatever you choose to include, typically your name, email address, company or publication, and the substance of your enquiry.

Information collected automatically

When you browse the Site our hosting infrastructure records standard server logs: the IP address of your connection, the pages requested, the time of each request, referring URLs, and browser and device characteristics.

The Site does not use analytics, advertising, cross-site tracking, session replay or heat-mapping technologies, and loads no third-party scripts. If that changes we will update this policy and our Cookie Policy, and obtain consent where the law requires it, before the change takes effect.

Information from other sources

If you interact with us on a third-party platform, or a business partner introduces you, we may receive your contact details and the context of the introduction. We may also collect business contact information from publicly available sources such as company websites, professional networking sites, public registers and regulatory filings.

Sensitive information

We do not seek to collect special category data within the meaning of Article 9 of the EU or UK GDPR, sensitive personal data within the meaning of the Cayman DPA, or sensitive personal information as defined under United States state privacy laws, and we ask that you do not send it to us unsolicited. We do not use or disclose sensitive personal information for any purpose that would require us to offer a right to limit that use.

How we use information

We use personal information to:

  • Respond to your enquiries and carry on the conversation you started.
  • Operate, secure, and improve the Site, including diagnosing technical problems.
  • Understand how the Site is used so we can make it clearer and more useful.
  • Send information you have asked for about OpenWorld and its activities.
  • Comply with legal obligations, including those that apply to a company whose filings are made with the U.S. Securities and Exchange Commission.
  • Conduct client onboarding, due diligence, and sanctions and anti-money-laundering screening.
  • Establish, exercise or defend legal claims, and evaluate or complete corporate transactions.

We do not use personal information collected through the Site to make automated decisions that produce legal or similarly significant effects.

How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only:

  • With service providers that host the Site, deliver email, or provide analytics on our behalf, under contracts that limit their use of the information to those services.
  • With professional advisers such as lawyers, accountants, and auditors where needed for their advice.
  • Where required by law, regulation, legal process, or a governmental request, or to protect the rights, property, or safety of OpenWorld, our users, or others.
  • In connection with a merger, acquisition, financing, or sale of all or part of our business, in which case the information may transfer to the successor entity subject to this policy.
  • With other companies in the OpenWorld group, for group administration, consolidated reporting, audit, insurance and shared services.
  • With our transfer agent and registrar, our investor relations and regulatory filing agents, and any proxy solicitor, tabulator or financial printer we engage, in connection with shareholder communications and securities-law compliance.

Each service provider acts on our documented instructions under a written contract, except where it determines its own purposes, in which case it acts as an independent controller and its own privacy notice applies in addition to this one.

Cookies and similar technologies

The Site uses a small number of cookies and similar technologies. Our Cookie Policy explains what they are, what they do, and how to control them through your browser. The Site sets only strictly necessary cookies, and we will ask for your consent before setting any non-essential cookie or equivalent technology.

Retention and security

We keep personal information for as long as needed for the purposes described above, and afterwards for as long as required by law or reasonably necessary to resolve disputes and enforce agreements. Server logs are retained for a limited period for security and diagnostics.

We determine retention by reference to the purpose and whether it can still be achieved, the volume and sensitivity of the data, the risk of harm from unauthorised use or disclosure, and any applicable statutory or limitation period.

We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold. No method of transmission or storage is completely secure, and email in particular travels through systems outside our control.

If a personal data breach occurs we will notify the relevant supervisory authority and, where required, affected individuals. Under the EU and UK GDPR we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms. Under the Cayman DPA we will notify the Office of the Ombudsman and affected individuals without undue delay and in any event no later than five days after we should, with the exercise of due diligence, have been aware of the breach.

Your rights and choices

Depending on where you live, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to object to or restrict certain processing, or to receive a copy in a portable format. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR.

You may withdraw your consent at any time where we rely on consent, and you may object at any time, without giving reasons, to the use of your personal data for direct marketing. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

Cayman Islands

Under the Cayman DPA you have the right to be informed of how we process your personal data, to access it, to have inaccurate data rectified, to require us to stop processing that is causing or is likely to cause unwarranted substantial damage or distress, to require us to stop processing for direct marketing, and to seek compensation for damage caused by a contravention of the Act. We will respond to a subject access request within 30 days.

United States

Residents of California have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Residents of Texas, Nebraska and the other states with comprehensive privacy laws in force have comparable rights under their own statutes. Subject to the law of your state, these are the rights to know and access, to delete, to correct, to obtain a portable copy, to opt out of the sale or sharing of personal information and of targeted advertising, to opt out of profiling in furtherance of decisions producing legal or similarly significant effects, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. We do not engage in profiling of that kind.

We will respond to a verifiable consumer request within 45 days, extendable once by a further 45 days where reasonably necessary, and we will tell you within the first 45 days if we need the extension. If we decline your request you may appeal by replying to our decision or writing to connect@openworld.dev with “Privacy appeal” in the subject line; if we deny the appeal we will tell you how to contact your state attorney general. An authorised agent may make a request on your behalf on production of written authority.

We recognise and honour the Global Privacy Control browser signal as a valid request to opt out of the sale and sharing of personal information and of targeted advertising for the browser and device on which it is sent.

Making a request

To make a request, email connect@openworld.dev from the address you want us to act on. We may ask for information to verify your identity before responding, and we will respond within the time required by applicable law.

You may also complain to a supervisory authority. In the Cayman Islands this is the Office of the Ombudsman, PO Box 2252, Grand Cayman KY1-1107. In the European Economic Area it is the authority of the Member State of your habitual residence, place of work or the place of the alleged infringement. In the United Kingdom it is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. In the United States you may contact your state attorney general.

Email from us includes a way to stop receiving it. Cookie choices are described in the Cookie Policy. Our position on the sale and sharing of personal information is set out on the Do Not Sell My Info page.

International transfers

OpenWorld, Inc. is incorporated in the State of Nevada and the Site is hosted in the United States. Personal information may also be accessed by group companies and service providers in other countries, including the Cayman Islands. If you access the Site from outside the United States, your information is transferred to and processed in countries whose privacy laws may differ from those of your own.

Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement or its Addendum to those Clauses, an applicable adequacy decision, or a derogation under Article 49 where one is available. Where the Cayman DPA applies, section 12 restricts transfers to countries that do not ensure an adequate level of protection, and we rely on a permitted ground where adequacy is not established. You may request a copy of the relevant safeguards, redacted for commercially confidential terms.

Children

The Site is directed at institutions, businesses, and professional audiences. It is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it. We do not knowingly sell or share the personal information of consumers under 16 years of age.

Shareholders and investor relations

OpenWorld, Inc. is a registrant with the U.S. Securities and Exchange Commission whose shares are listed on the Nasdaq Stock Market. Securities laws require the disclosure of information that includes personal data, such as the identity and holdings of directors, officers and significant shareholders. Once filed, that information is publicly available on EDGAR and cannot be withdrawn, corrected or erased by us, and rights of erasure, restriction and objection do not apply to it. The register of shareholders is maintained by our transfer agent and access to it is governed by corporate law rather than by this policy. Please do not send us material non-public information.

Changes to this policy

We may update this policy from time to time. The effective date at the top of the page shows when it was last revised, and material changes will be signposted on the Site. We keep prior versions and make them available on request.

Questions about this page can be sent to connect@openworld.dev.