Last updated · October 2, 2026

Privacy Policy

This policy explains what personal data BitHz collects, why it is collected, who it is shared with and how long it is kept. It covers the website, the applications and the accounts and services offered through them.

This document is published ahead of the final legal sign-off. Text in square brackets marks BitHz entity details that are filled in by BitHz before the document is certified.

This document is published in English and in translation. If a translation differs from the English text, the English text prevails.

1. Scope and controller

The controller of your personal data is [BitHz legal entity name], registered in [jurisdiction] under registration number [registration number]. We are the entity that decides why and how your data is used.

Questions about this policy, and requests to exercise your rights, go to [privacy email].

2. Data we collect

We collect the data we need to open and run your account, to keep it secure and to meet our legal duties. This includes:

  • identity data — name, date of birth, nationality, gender, photograph or liveness image, identity document numbers and copies
  • contact data — email address, phone number, residential address
  • verification data — the results of identity checks, sanctions and adverse media screening, source of funds and source of wealth information, and politically exposed person status
  • transaction data — orders, trades, deposits, withdrawals, wallet addresses you send to or receive from, and balances
  • account and technical data — device and browser details, IP address, login history, and the settings you choose
  • security and support data — two-factor authentication status, correspondence with support, complaints and their outcomes
  • marketing and usage data — how you reached us and how you use the platform, where you have not opted out

3. Where the data comes from

Most of the data comes from you, from what you type into the platform, and from how you use it. Some of it comes from the identity verification provider that runs our checks, from the venue that executes your trades, from your payment or blockchain transactions, and from public registers and blockchain records.

If you do not provide the data we need for verification, we cannot open or maintain your account.

4. Why we use your data

We use your data for the following purposes, each with the basis the law requires:

  • to open, operate, secure and close your account, and to execute and settle your orders — because we need it to perform our agreement with you
  • to verify your identity, screen you and your transactions, monitor activity, keep records and report where required — because the law requires it, including the rules on anti-money laundering and counter-terrorist financing
  • to prevent fraud, abuse and unauthorised access, and to protect the platform and other users — because we have a legitimate interest in doing so
  • to improve the platform, measure how it is used and provide support — because we have a legitimate interest in running the service well
  • to send you product and market communications — where you have consented, or where the law allows us to contact existing customers, and you can opt out at any time

5. Identity checks, screening and reporting

As a regulated platform we must know who our customers are. We verify identity against official documents and third-party databases, screen you and your transactions against sanctions, politically exposed person and adverse media lists, and monitor transactions for unusual activity.

When we identify activity that may be suspicious, we report it to the Financial Intelligence Unit through the channels the law requires. We are not allowed to tell you that a report has been made.

We are under a legal duty to keep the records that document these checks.

6. Who we share data with

We do not sell your personal data. We share it only where we must, and only as far as needed:

  • WEEX, the venue that executes trades and holds the assets of the platform, and its custodian, so that your orders and balances can be processed
  • identity verification and screening providers, and the payment and blockchain analytics services that support deposits and withdrawals
  • cloud hosting, security and analytics providers that run and protect the platform
  • professional advisers, auditors and insurers, under duties of confidentiality
  • regulators, the Financial Intelligence Unit, law enforcement and the courts, where the law requires or permits it
  • a buyer or successor, if the business is reorganised, sold or merged, with the same protections applied to your data

7. Transfers outside your country

Some of the providers above are outside the country you live in, including in the United Arab Emirates. Where we transfer your data abroad we rely on the transfer mechanisms the law provides, such as contractual protections, and we require the recipient to protect it to the standard of this policy.

8. How long we keep data

We keep the records that document your identity checks and your transactions for at least 8 years after the end of the relationship, which is the period the rules in the United Arab Emirates require for virtual asset platforms. Records that may relate to national security may be kept longer.

Other data is kept only as long as there is a reason to keep it — while your account is open, while a dispute or investigation is open, and for the period the law or a regulator requires. When the period ends, we delete or anonymise the data.

9. Cookies and similar technologies

We use cookies and similar storage to run the platform and to understand how it is used. You can manage them through your browser, and through the consent choices we show you where the law requires them.

Essential cookies keep you signed in, remember your language and theme, and protect the platform against abuse — the platform cannot work without them. Preference cookies remember your settings. Analytics cookies, where you agree to them, tell us which pages are used so we can improve them. Turning off non-essential cookies does not stop you from trading.

Section 9 is a summary. The Cookies Policy is the full document and is published next to this one.

10. Your rights

Depending on where you live, you may have the right to:

  • see the personal data we hold about you, and receive a copy of it
  • have inaccurate data corrected
  • ask us to delete data, or to stop using it, where the law allows and where we do not have to keep it for a legal reason such as an AML record
  • object to processing based on our legitimate interests, and withdraw consent you have given
  • ask us to transfer data you gave us to another provider
  • complain to the data protection regulator in your country, or to the regulator that licenses BitHz

Write to [privacy email] to make a request. We answer within the period the law allows, and we may need to confirm your identity before we act on it.

11. How we protect data

We encrypt data in transit and at rest, restrict access to the staff who need it, log access to sensitive systems, and test our systems against intrusion. Our staff are trained on data protection and confidentiality.

No system is completely secure. If a breach affects your data and creates a risk to you, we tell you and the regulator as the law requires.

12. Children

The platform is only for people aged 18 and over. We do not knowingly collect data from children. If we learn that we have, we close the account and delete the data, unless the law requires us to keep it.

13. Changes to this policy

When this policy changes we publish the new version on this page and update the date at the top. Where the change is significant we tell you in the platform or by email before it takes effect.

14. Contact

For anything about your personal data, write to [privacy email]. For account and trading questions, use [support email].