1. General Provisions
1.1. Purpose
This Personal Data Processing Policy (“Policy”) defines the procedures for collecting, using, storing, and protecting personal data of users of the cryptocurrency exchange (“Service”) and the security measures applied.
1.2. Data Controller
The Service acts as the personal-data operator and processes data in compliance with applicable data-protection laws.
1.3. User Consent
By using the Service, the user agrees to this Policy and authorizes processing of personal data under its terms.
2. Definitions
2.1. Personal Data
Any information relating to an identified or identifiable natural person (data subject).
2.2. Processing
Any operation or set of operations performed on personal data, including collection, recording, systematization, accumulation, storage, updating, use, transfer, depersonalization, blocking, deletion, or destruction.
2.3. Operator
The entity that determines the purposes and means of personal-data processing, alone or jointly with others.
3. Processing Principles
Lawfulness and fairness
Purpose limitation
Data minimization
Accuracy
Storage limitation
Confidentiality and security
4. Categories of Personal Data Processed
4.1. Data provided by the user
Full name
Date of birth|
E-mail address
Phone number
Payment details
Identity documents
4.2. Data collected automatically
IP address
Browser type and version
Operating systеm
Information about visits and on-site behavior
5. Purposes of Processing
Service provision: Registration, exchanges, payment processing, and other Service functions.
Identification and authentication: Verifying the user’s identity and securing the account.
Service improvement: Analyzing user behavior to enhance functionality and user experience.
Marketing (with consent): Informing users about new products, promotions, and offers.
Legal compliance: Meeting AML/CFT and other statutory requirements.
6. User Rights
Access: Obtain information about personal data processed.
Rectification: Request correction of inaccurate or incomplete data.
Erasure: Request deletion of data in certain cases.
Restriction: Request limitation of processing in certain cases.
Portability: Receive data in a structured, commonly used format and transmit it to another controller.
Withdraw consent: Revoke consent at any time when processing is based on consent.
7. Data-Protection Measures
7.1. Technical Measures
The Service employs modern security technologies, including encryption, protection against unauthorized access, and security monitoring.