1. Scope and controller
The controller of your personal data is [BitHz legal entity name], registered in [jurisdiction] under registration number [registration number]. We are the entity that decides why and how your data is used.
Questions about this policy, and requests to exercise your rights, go to [privacy email].
2. Data we collect
We collect the data we need to open and run your account, to keep it secure and to meet our legal duties. This includes:
- identity data — name, date of birth, nationality, gender, photograph or liveness image, identity document numbers and copies
- contact data — email address, phone number, residential address
- verification data — the results of identity checks, sanctions and adverse media screening, source of funds and source of wealth information, and politically exposed person status
- transaction data — orders, trades, deposits, withdrawals, wallet addresses you send to or receive from, and balances
- account and technical data — device and browser details, IP address, login history, and the settings you choose
- security and support data — two-factor authentication status, correspondence with support, complaints and their outcomes
- marketing and usage data — how you reached us and how you use the platform, where you have not opted out
3. Where the data comes from
Most of the data comes from you, from what you type into the platform, and from how you use it. Some of it comes from the identity verification provider that runs our checks, from the venue that executes your trades, from your payment or blockchain transactions, and from public registers and blockchain records.
If you do not provide the data we need for verification, we cannot open or maintain your account.
4. Why we use your data
We use your data for the following purposes, each with the basis the law requires:
- to open, operate, secure and close your account, and to execute and settle your orders — because we need it to perform our agreement with you
- to verify your identity, screen you and your transactions, monitor activity, keep records and report where required — because the law requires it, including the rules on anti-money laundering and counter-terrorist financing
- to prevent fraud, abuse and unauthorised access, and to protect the platform and other users — because we have a legitimate interest in doing so
- to improve the platform, measure how it is used and provide support — because we have a legitimate interest in running the service well
- to send you product and market communications — where you have consented, or where the law allows us to contact existing customers, and you can opt out at any time
5. Identity checks, screening and reporting
As a regulated platform we must know who our customers are. We verify identity against official documents and third-party databases, screen you and your transactions against sanctions, politically exposed person and adverse media lists, and monitor transactions for unusual activity.
When we identify activity that may be suspicious, we report it to the Financial Intelligence Unit through the channels the law requires. We are not allowed to tell you that a report has been made.
We are under a legal duty to keep the records that document these checks.
7. Transfers outside your country
Some of the providers above are outside the country you live in, including in the United Arab Emirates. Where we transfer your data abroad we rely on the transfer mechanisms the law provides, such as contractual protections, and we require the recipient to protect it to the standard of this policy.
8. How long we keep data
We keep the records that document your identity checks and your transactions for at least 8 years after the end of the relationship, which is the period the rules in the United Arab Emirates require for virtual asset platforms. Records that may relate to national security may be kept longer.
Other data is kept only as long as there is a reason to keep it — while your account is open, while a dispute or investigation is open, and for the period the law or a regulator requires. When the period ends, we delete or anonymise the data.
10. Your rights
Depending on where you live, you may have the right to:
- see the personal data we hold about you, and receive a copy of it
- have inaccurate data corrected
- ask us to delete data, or to stop using it, where the law allows and where we do not have to keep it for a legal reason such as an AML record
- object to processing based on our legitimate interests, and withdraw consent you have given
- ask us to transfer data you gave us to another provider
- complain to the data protection regulator in your country, or to the regulator that licenses BitHz
Write to [privacy email] to make a request. We answer within the period the law allows, and we may need to confirm your identity before we act on it.
11. How we protect data
We encrypt data in transit and at rest, restrict access to the staff who need it, log access to sensitive systems, and test our systems against intrusion. Our staff are trained on data protection and confidentiality.
No system is completely secure. If a breach affects your data and creates a risk to you, we tell you and the regulator as the law requires.
12. Children
The platform is only for people aged 18 and over. We do not knowingly collect data from children. If we learn that we have, we close the account and delete the data, unless the law requires us to keep it.
13. Changes to this policy
When this policy changes we publish the new version on this page and update the date at the top. Where the change is significant we tell you in the platform or by email before it takes effect.
14. Contact
For anything about your personal data, write to [privacy email]. For account and trading questions, use [support email].