1. General Provisions

This Personal Data Processing Policy regulates the collection, storage, use, and protection of user information of the exchange service, including the website and Telegram bot.

The Service respects users’ right to privacy and takes reasonable measures to protect personal data.

By using the website, the user confirms their agreement with the terms of this Policy.

2. Data That May Be Collected

The Service may collect and process the following data:

  • email address;
  • IP address;
  • browser, device, and technical connection data;
  • details provided by the user for exchange operations (wallets, accounts, and other payment data);
  • when using the Telegram bot, data transmitted by Telegram (username, user_id, user messages);
  • other information necessary for processing requests and ensuring service security.

The Service does not request user documents directly, unless required by law or necessary for the technical execution of a request.

3. AML / KYC Data

If AML / KYC / SoF verification is required:

  • personal data is processed by the payment provider;
  • the payment provider acts as an independent data controller;
  • the Service does not receive or store user documents directly;
  • the user provides data directly to the payment provider in accordance with its rules and procedures.

4. Purposes of Data Processing

The collected data is used for:

  • processing exchange requests;
  • identifying requests and communicating with the user;
  • preventing fraud and abuse;
  • ensuring the security of the website and service;
  • complying with AML and other applicable legal requirements;
  • handling user inquiries and claims.

5. Data Storage

Data is stored on secure servers with restricted access.

The data retention period is determined by the Service’s internal policies, legal requirements, and the need to fulfill obligations to the user and protect the Service’s legitimate interests.

6. Transfer of Data to Third Parties

The Service may transfer data to third parties only to the extent necessary to fulfill its obligations, ensure security, and comply with legal requirements, including:

  • the payment provider;
  • banks and payment systems;
  • authorized government authorities — in cases предусмотренных законодательством.

7. Data Protection

The Service takes reasonable organizational and technical measures to protect information from unauthorized access, modification, disclosure, or destruction, including:

  • use of secure HTTPS connection;
  • restricted access to data;
  • implementation of server and software protection measures.

8. User Rights

The user has the right to:

  • request information about processed data, if not prohibited by law;
  • request correction or deletion of data, if permitted by law and does not interfere with the Service’s obligations;
  • contact the Service regarding personal data processing using the contact details provided on the website.

9. Use of Cookies

The website may use cookies and other technical tools to ensure proper operation, analyze user activity, improve usability, and maintain security.

10. Policy Changes

The Service reserves the right to make changes to this Personal Data Processing Policy at any time. The current version is published on the website and comes into force upon publication.