Cookie Policy
1. Data Controller & Scope
This policy applies to all personal data processed by [Firm Name] (the ‘Data Controller’) in connection with our digital asset investment services. It covers data collection, processing, storage, and transfer in compliance with GDPR, CCPA, and relevant financial regulations.
2. Information We Collect
- Identity Data: Name, date of birth, nationality, passport/ID number, source of funds.
- Contact Data: Email, phone, residential address, verified wallet addresses.
- Financial Data: Bank account details, trading history, portfolio balances, risk tolerance, investment objectives.
- Technical Data: IP address, browser type, device identifiers, login timestamps, API logs, transaction hashes.
- Due Diligence Data: PEP status, sanctions screening results, adverse media findings, KYC documents.
3. Legal Basis for Processing
- Performance of contract (Art. 6(1)(b) GDPR) for account management.
- Legal obligation (Art. 6(1)(c)) for AML/KYC and record-keeping.
- Legitimate interests (Art. 6(1)(f)) for fraud prevention, IT security, and business operations.
- Consent (Art. 6(1)(a)) for marketing communications (withdrawn at any time).
4. Data Sharing & International Transfers
We share data with regulatory bodies (e.g., FCA, FINMA, MAS), auditors, custodians, liquidity providers, and cloud service providers (AWS, Azure). International transfers are governed by Standard Contractual Clauses (SCCs) or adequacy decisions (e.g., UK, Swiss, Singapore).
5. Data Retention
We retain personal data for the duration of the business relationship plus 5 years after account closure (per AML regulations). Trading records are kept for 6 years. Statutory retention periods may override.
6. Your Rights
Under GDPR: access, rectification, erasure (right to be forgotten), restriction, data portability, objection, automated individual decision-making. Under CCPA: right to know, delete, opt-out of sale (we do not sell data). Exercise rights via [email protected]. We respond within 30 days.
7. Security Measures
We implement encryption (AES-256 at rest, TLS 1.3 in transit), multi-factor authentication, role-based access controls, SIEM monitoring, and annual penetration tests. Custody of digital assets uses multi-sig with geographically distributed key shards.
8. Policy Updates
We review this policy annually. Material changes will be notified via email and a banner on our platform. Continued use implies acceptance.
9. Complaints & Contact
For complaints, contact our Data Protection Officer: [email protected]. If unresolved, you have the right to lodge a complaint with the lead supervisory authority (e.g., ICO, CNIL, FADP).
