Legal information
Terms of Service, privacy, cookies, donations, and related notices for the zbelthas.com website.
Last updated: April 22, 2026
Terms of Service
These Terms of Service (“Terms”) govern your access to and use of the public website and related web pages made available at zbelthas.com and our official subdomains (the “Site”), excluding any terms that a separate product, app store, or platform may require when you use downloadable software. By using the Site, you agree to these Terms. If you do not agree, do not use the Site.
1. Eligibility and acceptable use
You must have authority to accept these Terms. You agree to use the Site only for lawful purposes and in accordance with these Terms, applicable law, and any applicable third-party terms (for example, Patreon, Stripe, social platforms, and blockchain networks you interact with through links on the Site).
2. The Site does not provide financial, legal, or tax advice
Information on the Site is provided for general information only. It is not legal, tax, financial, or investment advice. We may describe cryptographic, wallet, and donation-related topics; that does not create a broker-dealer, advisory, or fiduciary relationship.
3. Software and non-custodial design
Zbelthas is designed to be non-custodial where that applies: you are responsible for safeguarding your own keys, recovery material, and devices. We do not have access to your keys or to decrypting your content on your behalf, except as explicitly described in product documentation. If you lose keys or send assets to a wrong address, we may be unable to recover them.
4. Third-party services and links
The Site may link to payment processors, community platforms, documentation, and blockchain services. When you leave the Site, their terms, fees, and privacy practices apply. We are not responsible for third-party services or for network conditions (including fees, reorgs, or delays) when you use public blockchains.
5. Donations, contributions, and payments
Voluntary contributions, donations, and subscriptions are subject to the separate Donations & contributions section on this page and to the rules of the relevant payment platform. Unless expressly stated in writing and governed by a separate contract, the Site is not a fundraising campaign or donation platform; we simply link to or describe ways you may support our work.
6. Disclaimers
THE SITE AND ITS CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE FULLEST EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SITE WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF HARMFUL COMPONENTS.
7. Limitation of liability
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ZBELTHAS AND ITS CONTRIBUTORS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, DATA, GOODWILL, OR OTHER INTANGIBLE LOSSES, ARISING OUT OF OR RELATED TO YOUR USE OF THE SITE, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. IN NO EVENT SHALL OUR AGGREGATE LIABILITY FOR ALL CLAIMS RELATING TO THE SITE EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US FOR USE OF THE SITE DURING THE TWELVE (12) MONTHS BEFORE THE CLAIM, OR (B) FIFTY EUROS (€50) IF (A) DOES NOT APPLY. SOME JURISDICTIONS DO NOT ALLOW CERTAIN LIMITATIONS; IN THOSE JURISDICTIONS, OUR LIABILITY IS LIMITED TO THE MAXIMUM PERMITTED BY LAW.
8. Indemnity
You will defend, indemnify, and hold harmless Zbelthas and its contributors from and against any claims, damages, losses, and expenses (including reasonable attorneys’ fees) arising out of your use of the Site, your violation of these Terms, or your violation of any rights of a third party, except to the extent caused by our willful misconduct.
9. Governing law and disputes
If you are a consumer, mandatory consumer protection rules in your country of residence may apply. Otherwise, you agree that substantive law and venue will be as determined in future updates once we publish a specific legal entity, registered office, and jurisdiction. Until then, you should treat these Terms as governed by general principles and seek independent legal advice for disputes. Nothing in these Terms limits non-waivable rights.
10. Contact
For questions about these Terms, contact: legal@zbelthas.com. For support unrelated to legal terms: support@zbelthas.com.
Privacy Policy
This policy describes how we handle information in connection with the public Site. Our products are architected to minimize data, but the Site is still a website and can involve basic technical data and, when you email us, the content you choose to send.
What we do not do
- We do not use third-party advertising or marketing trackers on the Site in order to build profiles of visitors.
- We do not sell your personal data.
- We do not use the Site to run behavioral analytics in the way typical ad-supported sites do.
What may be processed
- Server and network metadata: When you request pages, infrastructure providers (e.g. hosting, CDN) may process technical data such as IP addresses and logs needed to operate a website and to protect against abuse, depending on how you deploy the Site.
- Email: If you contact us, we process the information you include (for example, your address and your message) to respond and to maintain our relationship with you.
- Payment providers: If you use links to Stripe, Patreon, or similar, those providers process payment data on their own systems under their terms.
Legal bases (EEA/UK, where applicable)
Where GDPR-style rules apply, we rely on appropriate bases such as: (1) our legitimate interest in operating and securing the Site and communicating with you; (2) performance of a contract, where applicable; and (3) your consent, where we ask for it in a specific manner.
Your rights
Depending on your location, you may have rights to access, rectify, delete, object, or port personal data, and to complain to a supervisory authority. You may contact us at legal@zbelthas.com and we will respond in line with applicable law.
Children
The Site is not directed at children under 16 (or a higher age required locally). We do not knowingly collect personal information from children for marketing purposes.
AI policy (Z∅ neural interface)
The assistant accessible from the floating orb on this Site is a retrieval-augmented large-language model (Cloudflare Workers AI, Llama 3.3 Instruct class) operating on public Zbelthas content. It is intended solely to help you navigate the Site and understand the project.
What we do not do: we do not store your
prompts, responses, or conversation history beyond the ephemeral request lifetime; we do not build user
profiles; we do not use your queries to train any model. Responses are marked noindex.
Rate limiting: to protect the service, a lightweight per-IP rate limit is applied at the edge. It uses a daily-rotating SHA-256 bucket key (IP + date + salt) — the raw IP is never stored.
EU AI Act alignment: the assistant is a low-risk, informational tool with human oversight (you press send, you can ignore the answer). It is not used for any legal, biometric, employment, or other high-risk decision. It cannot execute actions on your behalf.
Limits: model output may be wrong, incomplete, or out of date. Nothing the assistant says is legal, financial, or security advice. For binding information, refer to this page and to the official documentation.
EU law references (EUR-Lex)
The table below lists principal European Union acts that are often relevant to websites, data protection, digital services, financial/crypto markets, and product cybersecurity. It is a non-exhaustive pointer to official sources on EUR-Lex (the authentic texts are those published in the Official Journal of the EU). This is not legal advice; applicability depends on your role, services, and facts.
| Common name | Instrument (short title) | Official text (EUR-Lex, EN) |
|---|---|---|
| GDPR | Regulation (EU) 2016/679 — General Data Protection Regulation | 2016/679 (GDPR) |
| ePrivacy | Directive 2002/58/EC — privacy in electronic communications (as amended) | 2002/58/EC |
| NIS2 | Directive (EU) 2022/2555 — measures for a high common level of cybersecurity (NIS 2) | 2022/2555 (NIS2) |
| DORA | Regulation (EU) 2022/2554 — digital operational resilience for the financial sector | 2022/2554 (DORA) |
| DSA | Regulation (EU) 2022/2065 — Digital Services Act | 2022/2065 (DSA) |
| DMA | Regulation (EU) 2022/1925 — Digital Markets Act | 2022/1925 (DMA) |
| MiCA | Regulation (EU) 2023/1114 — markets in crypto-assets | 2023/1114 (MiCA) |
| eIDAS | Regulation (EU) No 910/2014 — eID and trust services (as amended) | 910/2014 (eIDAS) |
| EUDI / eIDAS2 | Regulation (EU) 2024/1183 — European Digital Identity Framework (amends 910/2014) | 2024/1183 (EUDI) |
| CRA | Regulation (EU) 2024/2847 — Cyber Resilience Act (products with digital elements) | 2024/2847 (CRA) |
| EU AI Act | Regulation (EU) 2024/1689 — artificial intelligence (AI Act) | 2024/1689 (AI Act) |
Member State laws implement or complement many EU instruments (for example, national ePrivacy implementation, NIS2 transposition, and sector rules). The European Data Protection Board publishes GDPR guidance; ESMA, EBA, and national authorities publish MiCA, DORA, and financial-services materials. Always verify consolidated versions and in-force dates on EUR-Lex.
Donations & contributions
Also summarized on the Donate page.
General. The information here is provided for convenience only. It is not legal, tax, accounting, or investment advice. Laws differ by country, region, and over time. You are responsible for understanding and complying with the laws and regulations that apply to you, including (where relevant) financial promotion rules, consumer protection, sanctions and export controls, anti-money-laundering and counter-terrorist financing requirements, data protection, e-money or payment services rules, charity and fundraising laws, and rules applicable to virtual assets, securities, and taxes. If you are unsure, seek professional advice before contributing.
Voluntary support; not an investment. Unless a separate platform clearly states otherwise at the point of payment, contributions you make through direct cryptocurrency transfers, optional Web3 or on-chain transactions linked from the Site, or card and bank payments processed by Stripe, are intended as voluntary support for Zbelthas’s work. They are not investments, do not entitle you to any ownership, equity, interest, or profit, and are not a secondary-market instrument. Past or future use of the Zbelthas name, software, or services by others does not change the non-investment, voluntary character of a contribution described as a donation.
No quid pro quo for simple donations. For one-time and direct “donation” flows (including typical crypto, Web3, and Stripe checkout paths we describe on the Donate page), you should not expect goods, services, or exclusive rights in return; any incidental acknowledgments are gratuitous. Patreon is different: recurring Patreon support is a subscription managed by Patreon; tier descriptions and benefits are set on Patreon and are subject to Patreon’s terms, creator policies, and any stated perks—not the short summary on the Donate page.
Third-party processors and networks. Payment links to Stripe, Patreon, and blockchain interactions run on those providers’ or networks’ systems. Their terms, privacy notices, and fees apply. We do not control network fees, confirmation times, or reversals. Use only addresses, contracts, and links we publish; verify everything before you send value.
Taxes, receipts, and deductibility. Tax treatment (including whether a payment is a gift, a membership fee, or a potentially deductible contribution) depends on your facts, the recipient’s status, and local law. We do not represent that any payment is tax-deductible, VAT-exempt, or eligible for a receipt unless we explicitly state so in writing for your jurisdiction. You are responsible for your own reporting and for consulting a qualified professional.
Refunds, chargebacks, and errors. Digital asset transfers to wallet addresses and many on-chain transactions are generally irreversible. For card and wallet payments, refund and dispute rules follow Stripe’s policies and the rules of your card or bank. Do not use our donation options to evade lawfully owed amounts or to manipulate payment networks.
Eligibility; prohibited use. You must have legal capacity to contribute and you must not use our donation options for illegal purposes, including to violate sanctions, launder money, or defraud any person. We may decline or return support where we are required or permitted to do so by law or policy.
No professional relationship; updates. Nothing here creates an attorney–client, advisory, or fiduciary relationship. This section may be updated. Where mandatory consumer or other non-waivable rights exist in your country, they remain unaffected.
Security & responsible disclosure
To report a security vulnerability, email security@zbelthas.com. Our machine-readable policy is published at /.well-known/security.txt (RFC 9116).
Scope
In scope: zbelthas.com, all *.zbelthas.com subdomains, and signed Zbelthas release artifacts.
Out of scope: third-party services we do not operate (Stripe, Patreon, GitHub, RPC providers, block explorers); social-engineering of staff; physical attacks; recently disclosed CVEs (<30 days) in upstream dependencies; theoretical issues without a working proof of concept.
Rules of engagement
- Report privately first — do not publish details before we have responded and a fix is available.
- Do not exfiltrate user data. Stop at proof of concept.
- Do not degrade the service (no stress / DoS / spam of third parties).
- If you need to probe live systems, use accounts and data that you own.
Our commitments
- Acknowledgement within 72 hours.
- Triage and preliminary severity within 7 days.
- Transparent status updates on the fix schedule.
- Safe-harbor: security researchers acting in good faith under this policy will not be pursued legally.
- Credit in the fix announcement (opt-in) unless you prefer to remain anonymous.
A coordinated bug-bounty programme is not yet public. When it is, scope, rewards, and platform will be announced here and on the Trust Center. The bounty will complement — not replace — independent third-party audits.
Intellectual property
The Zbelthas name, logo, and related materials are protected; unauthorized use may infringe our rights. For trademark information, see the About page. Unless otherwise stated, content on the Site is licensed or reserved as we specify in repositories or documentation—do not copy or modify without permission.
Changes to these documents
We may update these terms and policies. The “Last updated” date at the top of this page will change when we do. Material changes may, where required by law, be communicated in additional ways. Your continued use of the Site after updates constitutes acceptance of the updated documents, to the extent permitted by law.
RegulatoryCompliance
Enterprise-ready from day one. Built to satisfy EU regulatory frameworks without architectural compromise or privacy trade-offs. Our zero-data architecture provides structural exemptions rather than requiring additional compliance measures.
Why is compliance automatic? Most companies struggle with GDPR because they collect data. Zbelthas collects nothing — no personal data, no metadata, no logs. You can't breach what doesn't exist. Compliance by architecture, not policy.
NIS2 Directive
- Risk management framework
- Incident response procedures
- Business continuity planning
- Supply chain security
- Cryptographic controls
DORA Regulation
- ICT risk management
- Incident reporting
- Resilience testing
- Third-party risk management
GDPR Compliance
- Data minimization: zero personal data collected
- Privacy by design & default — architectural, not policy
- No data subject requests needed (no data exists)
- No retention = no liability = no breach risk
eIDAS 2.0
- Digital identity support
- Electronic signatures (ML-DSA)
- Trust service interoperability
- Cross-border recognition
MiCA Regulation
- Non-custodial exemption
- No licensing required
- Transparency provisions
- Security standard compliance
Cyber Resilience Act
- Secure by design
- Secure by default
- Vulnerability handling policy
- Security documentation
EU AI Act
- No high-risk AI components
- Full transparency disclosures
- Human oversight maintained
- Risk assessment completed
Zbelthas' non-custodial architecture and zero-data-collection design result in structural regulatory exemptions — not through clever legal arguments, but through architectural choices that make compliance automatic:
- Non-custodial: No MiCA licensing required
- Zero data: No KYC/AML obligation
- No retention: GDPR compliance automatic
- No intermediary: No DORA full scope