HashKey Global Privacy Policy
Updated on 28 August 2026
HashKey Holdings Limited and its affiliates (collectively, “HashKey”, “we”, “us” or “our”) are a comprehensive digital asset group. HashKey operates globally and provides a range of services, including virtual asset trading, exchange, brokerage, custody and other related services. HashKey is committed to respecting and protecting your privacy and personal data. This Global Privacy Policy (this “Privacy Policy”) explains how the relevant HashKey entity collects, uses, stores, transfers, shares, discloses or otherwise processes your Personal Data when you access or use HashKey websites, mobile applications, account interfaces, online platforms and other related products or services (collectively, the “Services”).
For the purposes of this Privacy Policy, the HashKey entity that provides the relevant Services to you is generally responsible for the processing of your Personal Data in connection with those Services. “Personal Data” means any information relating to an identified or identifiable living individual, or any other similar term under applicable data protection laws, excluding the information processed anonymously. For the avoidance of doubt, this Privacy Policy is not a contract and does not itself create legal rights or obligations beyond those required by applicable law.
Our Services are designed exclusively for individuals who are 18 years of age or older. You must not access or use the Services if you are under 18 years old, do not meet the minimum age requirement applicable to the relevant Service or jurisdiction, or are otherwise legally restricted from using the Services. We do not knowingly collect Personal Data from children or minors. If you believe that a child or minor has provided Personal Data to us, please contact us so that we may take appropriate steps in accordance with applicable law.
Please read this Privacy Policy carefully before using or continuing to use the Services. If you do not provide certain Personal Data, we may be unable to provide the Services to you, process your account registration, complete identity verification, comply with legal or regulatory obligations, or make certain functions of the Services available.
This Privacy Policy is intended to operate as a global baseline. If you are located in, receive Services from, or interact with a HashKey entity established in Hong Kong, Singapore, Japan, the United Arab Emirates or Bermuda, please also review the jurisdiction-specific addendum applicable to you. If there is any inconsistency between the main body of this Privacy Policy and an applicable addendum, the addendum will prevail to the extent of that inconsistency.
This Privacy Policy is prepared and provided in English. In the event of any conflict between the English version and any other available translation, the English version shall prevail.
1. How We Collect and Use Your Personal Data
We collect Personal Data that you provide to us, Personal Data generated when you use the Services, and Personal Data obtained from third parties or public sources where permitted by applicable law.
1.1 Personal Data You Provide to Us
When you register for, apply for, subscribe to, or use the Services, we may collect Personal Data including:
1.1.1 Account registration and account administration. When you register for, apply for, subscribe to or use the Services, we may collect information associated with your account, including your name, username, email address, mobile phone number, account credentials, referral code, verification codes, preferred language, account settings and other information required to create, authenticate, administer and maintain your account.
1.1.2 Identity verification and due diligence. As a regulated virtual asset service provider, we may collect information required for identity verification, KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability and other compliance checks. This may include your date of birth, nationality, residential address, government-issued identification documents and numbers, photographs, selfie or liveness-check information, biometric verification information where required and permitted, tax information, source of funds or source of wealth information, occupation, employer information, beneficial ownership information, politically exposed person status, sanctions screening results, risk assessment results and other due diligence materials.
1.1.3 Financial, trading and transaction information. When you use the Services, we may collect information relating to your account and transactions, including bank account details, payment information, wallet addresses, transaction records, order history, trading activity, trading parameters and instructions, asset balances, deposit and withdrawal information, settlement details, risk profile, investor classification, suitability information and other information required for account administration, transaction processing, reporting or regulatory compliance.
1.1.4 Communications, support and complaints. When you contact us, submit feedback, make enquiries, lodge complaints, request support, appeal a decision or otherwise communicate with us, we may collect your contact details, account information, communication channel information, description of the issue, supporting materials, attachments, communications with us, call recordings or scripts, chat records, complaint and dispute records, and other information needed to verify your identity, understand your request, investigate the matter, provide support, resolve disputes and improve our Services.
1.1.5 Other information you choose to provide. We may also collect information that you submit through links, forms, surveys, events, promotions, campaigns, applications, onboarding questionnaires, due diligence requests or other interactions with us.
If you are an institutional or corporate customer, or act on behalf of such a customer, we may collect and process information relating to the relevant entity and its representatives, including corporate registration documents, incorporation details, business information, authorised representatives, directors, officers, employees, beneficial owners, controllers, traders, account administrators and other authorised persons. We may also collect information relating to account mandates, trading authorisations, API users, API credentials or identifiers, wallet addresses, transaction instructions, settlement details, access permissions, security settings and audit logs. We use this information to onboard and administer institutional or corporate accounts, verify authority and ownership structures, provide relevant Services, maintain account security, monitor account activities, and comply with legal and regulatory obligations.
If you provide Personal Data relating to another individual, you are responsible for ensuring that you have obtained all necessary authority, consent or other lawful basis to provide that information to us.
1.2 Personal Data Generated Through Your Use of the Services
To ensure the secure, stable and efficient operation of the Services, and to maintain account and transaction security, we may automatically collect or generate technical, usage, security and risk information when you access or use the Services. This may include:
1.2.1 We may collect device and technical information, such as your device model, device identifiers, operating system, browser type and version, IP address, language settings, time zone, network information, app version, crash logs and diagnostic information, in order to operate the Services, maintain technical compatibility, troubleshoot issues, improve performance and protect the security of our systems.
1.2.2 We may collect usage information, such as your login records, pages viewed, functions used, search and clickstream information, access dates and times, session duration, referral information, error reports and interaction records, in order to understand how the Services are used, support account administration, improve user experience, monitor service performance and develop or enhance our products and services.
1.2.3 We may collect security and risk information, such as account activity, authentication records, fraud indicators, suspicious activity reports, risk alerts, cybersecurity logs and information used to detect unauthorised, unlawful or non-compliant activities, in order to authenticate users, maintain account and transaction security, detect and prevent fraud, respond to security incidents and comply with legal and regulatory obligations.
1.2.4 We may collect approximate location information derived from IP address or similar technical data. We will collect precise location information only where the relevant function requires it, you have enabled the applicable device permission, and the collection is permitted by applicable law, for example to support security verification, fraud prevention, regulatory compliance or other location-based functionality notified to you where applicable.
Depending on the functions you use, we may request access to certain device permissions, such as camera, photo album or storage, push notification, file upload, biometric or liveness check, and, where applicable, microphone or location permissions. For example, camera or photo permissions may be required for identity verification, document upload, selfie or liveness checks; file upload permissions may be required when you submit onboarding, due diligence, source-of-funds, complaint or support materials; push notification permissions may be used for account, security, transaction or service alerts; and microphone or location permissions may be used only where the relevant function requires them and such use is notified to you.
We will request such permissions only where relevant to the function you use. If you decline a permission, the relevant function may not be available or may not operate properly, but this will not affect your use of other functions that do not require that permission. You may manage device permissions through your device or browser settings, subject to the functionality of the relevant device, operating system or browser.
1.3 Personal Data from Third Parties and Public Sources
Where permitted by applicable law, we may obtain Personal Data from HashKey group entities, service providers, business partners, banks, payment service providers, custodians, virtual asset service providers, blockchain analytics providers, identity verification vendors, credit reference or risk information providers, sanctions and politically exposed person databases, fraud prevention databases, government or regulatory sources, public registers, publicly available websites and other lawful sources. We use such information to verify your identity, conduct due diligence, assess account, wallet, transaction and counterparty risks, comply with legal and regulatory obligations, prevent fraud and unlawful activities, and provide, secure and improve the Services.
Certain virtual asset transactions are recorded on public or permissioned blockchains. Depending on the relevant network, wallet addresses, transaction hashes, timestamps, transferred amounts, digital signatures, smart contract identifiers and other on-chain information may be publicly visible, immutable or independently processed by third parties. We may collect, analyse and use on-chain information, including through blockchain analytics tools, and may combine it with other information we hold about you where permitted by applicable law, to provide the Services, verify transactions, assess wallet, transaction and counterparty risks, detect suspicious activity, comply with legal and regulatory obligations and respond to lawful requests from regulators, law enforcement agencies or other competent authorities.
1.4 How We Use Personal Data
We may use Personal Data for the following purposes:
1.4.1 We use Personal Data to process your application, registration, subscription and onboarding for the Services, create and administer your account, verify your identity, determine your eligibility to access the relevant Services, and perform KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability, creditworthiness, financial standing, solvency and other compliance checks.
1.4.2 We use Personal Data to provide, administer, operate, maintain and improve the Services, including processing transactions, safeguarding assets, maintaining accounts, facilitating settlements, maintaining records, providing customer support and enabling the functionality of the Services. We also use Personal Data to authenticate your identity, maintain account and transaction security, detect anomalous transaction patterns, monitor account activity, protect users and assets, and preserve the integrity and security of the Services.
1.4.3 We use Personal Data to comply with legal, regulatory, tax, accounting, court, law enforcement, self-regulatory organization, industry body or governmental requirements, including requirements relating to virtual asset transfers, AML/CTF, sanctions, fraud prevention, market integrity, regulatory reporting, audits, investigations and lawful requests from competent authorities.
1.4.4 We use Personal Data to communicate with you regarding your account, transactions, security alerts, service updates, changes to terms or policies, customer support, dispute resolution and other operational matters. We may also use Personal Data to respond to and process enquiries, complaints, appeals, privacy-related requests and other communications from you.
1.4.5 We use Personal Data for internal administration, audit, record-keeping, risk management, legal claim management, business continuity, corporate governance and general business management. We may also use Personal Data to improve user experience, monitor service performance, troubleshoot technical issues, conduct data analytics, develop or enhance products and services, compile aggregated or anonymised statistics, conduct research, surveys, market analysis, events, campaigns and direct marketing where permitted by applicable law and, where required, with your consent.
1.4.6 We may use Personal Data for due diligence, restructuring, merger, acquisition, financing, asset sale, transfer of business or similar corporate transactions, and for other purposes that are directly related to the above, notified to you at the time of collection, authorised by you, or otherwise permitted by applicable law.
We will only process Personal Data where we have a lawful basis or are otherwise permitted to do so under applicable law. Depending on the jurisdiction and the nature of the processing, our lawful basis may include your consent, performance of a contract with you, compliance with legal or regulatory obligations, establishment, exercise or defence of legal claims, protection of vital interests, public interest grounds, or our legitimate business interests where recognised by applicable law. Where applicable law does not recognise legitimate interests as a lawful basis (for example, under the UAE PDPL), we will rely on your consent or another statutory basis recognised under that law, and any reference to legitimate interests in this Privacy Policy will not apply to you. If we intend to process your Personal Data for any other purpose not covered by this Privacy Policy, we will notify you beforehand and ensure that such processing fully complies with applicable data protection laws.
We may use automated systems, rules engines, artificial intelligence, machine learning models or analytics tools to support identity verification, fraud detection, sanctions screening, transaction monitoring, account security, customer risk rating and other compliance, security or risk management activities. Such technologies may process information to identify patterns, detect anomalies, assess risks, prioritise reviews, generate alerts or support operational decisions. These technologies are used as support tools and are not intended to replace human oversight where such oversight is required under applicable law, regulatory requirements or our internal procedures. Where an automated output may materially affect your access to the Services, account status or transaction permissions, we will apply human review where required by applicable law, regulatory requirements or our internal compliance procedures.
We may aggregate, de-identify or anonymise Personal Data so that it no longer identifies you, and use such information for analytics, service improvement, product development, security, risk management, research, statistical and other legitimate business purposes. Where information has been anonymised, we will keep and use it in anonymised form and will not attempt to re-identify it except where required or permitted by applicable law.
2. How We Use Cookies and Similar Technologies
We use cookies, software development kits, pixels, local storage and similar technologies to operate the Services, remember your preferences, support account login, maintain security, analyse usage, improve performance and, where permitted, measure or deliver marketing.
You may configure your browser or device settings to block or delete cookies and similar technologies. If you do so, certain functions of the Services may not work properly, and you may need to log in again or reset your preferences. Where required by applicable law, we will obtain your consent before using non-essential cookies or similar technologies.
For more information on our use of cookies and similar technologies, please refer to the applicable HashKey Cookie Policy.
3. How We Share, Transfer or Disclose Your Personal Data
We may share, transfer or disclose Personal Data as described below, subject to applicable law and appropriate safeguards.
3.1 HashKey Group Entities
We may share Personal Data within the HashKey group where necessary for the purposes described in this Privacy Policy, including account administration, group-wide compliance, risk management, customer support, technology operations, audit, legal and business management.
Cross-platform account integration. HashKey operates through affiliated entities in different jurisdictions and provides Services through multiple platforms and channels. Where you register for an account with one HashKey group entity, we may share relevant Personal Data with other HashKey group entities to facilitate an integrated account experience across HashKey platforms. Such sharing may enable us to recognise your existing HashKey account, create or maintain corresponding account profiles, provide access to Services offered by other HashKey entities, administer your account relationship, and apply consistent security, compliance and risk management controls across our platforms.
Cross-Entity Onboarding and Due Diligence Reliance. Where permitted by applicable law and where necessary for the provision of the relevant Services, we may also share and rely on certain information relating to your identity verification and due diligence processes, including KYC, AML/CFT and sanctions screening information, to facilitate onboarding, avoid unnecessary duplication of verification procedures, maintain consistent compliance standards and support regulatory obligations across HashKey entities. Where required by applicable law, we will obtain your consent or implement another lawful basis before such information is shared or relied upon.
Intra-Group AML/CFT Data Sharing. Where you hold accounts with, or are identified across, more than one HashKey group entity, authorised compliance personnel (including Money Laundering Reporting Officers or their equivalents) may share Personal Data about you between HashKey group entities for anti-money laundering, counter-terrorist financing and sanctions compliance purposes. Such sharing may include identity and verification data, customer risk ratings, politically exposed person and sanctions screening results, transaction monitoring alerts, and related compliance information. This sharing is subject to strict purpose limitation: it may be used only for AML/CFT, sanctions compliance and related regulatory purposes and not for commercial, marketing or other unrelated purposes. Where one HashKey entity is legally required to freeze or restrict your account under applicable sanctions legislation or regulatory direction, it may notify other HashKey group entities, which will independently assess whether a corresponding restriction is required under their own applicable law.
3.2 Service Providers, Agents and Contractors
We may disclose Personal Data to service providers, agents, contractors and professional advisers who support our business and operations, including providers of identity verification, compliance, fraud prevention and security services, blockchain analytics, technology infrastructure, cloud hosting, data storage, cybersecurity, communications, customer relationship management, marketing, analytics, artificial intelligence, payment processing, banking, custody, audit, legal, tax and other professional, administrative or operational services.
These third parties are authorised to access, process or store Personal Data only to the extent necessary to perform services for us or as otherwise permitted by applicable law. We take appropriate contractual, technical or organisational measures to require them to protect Personal Data, process it in accordance with our instructions where applicable, and retain it only as necessary for the relevant purposes.
3.3 Regulators, Government Authorities and Other Required Recipients
We may disclose Personal Data to courts, regulators, supervisory bodies, law enforcement agencies, tax authorities, government authorities, self-regulatory organisations, industry bodies, financial institutions or other third parties where required or permitted by law, regulation, court order, legal process, regulatory request, applicable rulebook, travel rule requirement or other compliance obligation. We may also disclose Personal Data where we reasonably consider disclosure necessary to protect our rights, property, users, employees, systems or the integrity of the Services; to detect, prevent or address fraud, security incidents, unlawful activity or violations of our terms or policies; or to manage legal, regulatory, operational or security risks.
3.4 Travel Rule and Virtual Asset Transfers.
As a regulated virtual asset service provider, we are required by FATF Recommendation 16 and applicable anti-money laundering laws to obtain, hold and transmit certain originator and beneficiary information in connection with virtual asset transfers that meet the applicable threshold. When you send or receive a virtual asset transfer that meets the applicable threshold, we will collect and transmit information about you (such as your name, account or wallet identifier, and in some cases your address, national identity number or date of birth) to, or receive such information from, the counterparty virtual asset service provider. This disclosure is a mandatory legal obligation that may take precedence over the data minimisation principle, and you will not be able to exercise your right to restrict or object to such processing to the extent it is required by applicable law.
3.5 Business Partners and Third Parties Involved in Your Transactions
Where necessary to provide the Services, facilitate transactions, support joint products or services, administer partnership, referral, rebate or other commercial programs, or otherwise fulfil your requests, we may share relevant Personal Data with banks, payment service providers, custodians, brokers, liquidity providers, virtual asset service providers, referral partners, joint marketing partners and other business partners involved in the relevant products, services or transactions. We will share only the Personal Data that is reasonably necessary for the relevant purpose and will do so in accordance with applicable law. Where required by applicable law, we will obtain your consent or rely on another lawful basis before sharing such Personal Data.
3.6 Corporate Transactions
If HashKey is involved in an actual or proposed merger, acquisition, restructuring, financing, asset sale, transfer of business, insolvency, joint venture or similar transaction, we may disclose or transfer Personal Data to counterparties, advisers and other participants in the transaction, subject to appropriate confidentiality and data protection arrangements where required.
3.7 With Your Consent or at Your Direction
We may share Personal Data with third parties where you have consented to, requested or authorised the sharing, or where the sharing is otherwise notified to you and permitted by applicable law.
4. Cross-Border Transfer of Personal Data
HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or otherwise processed in jurisdictions outside the jurisdiction in which it was originally collected or outside the jurisdiction where the relevant HashKey entity is established, including Hong Kong, Singapore, Japan, the United Arab Emirates, Bermuda and other jurisdictions where HashKey group entities, service providers or business partners operate.
Where we transfer Personal Data across borders, we will do so in accordance with applicable data protection laws. Depending on the applicable jurisdiction, this may include implementing contractual safeguards, conducting transfer impact assessments, ensuring a comparable or adequate level of protection, relying on your consent, relying on recognised certifications or other lawful transfer mechanisms, or applying other measures required or permitted by law.
Where the EU GDPR or UK GDPR applies, and your Personal Data is transferred from the European Economic Area or the United Kingdom to a jurisdiction that has not been recognised as providing an adequate level of protection, we will implement an appropriate transfer mechanism where required. Such mechanisms may include, as applicable, an adequacy decision or adequacy regulation, binding corporate rules for intra-group transfers, the European Commission’s standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or another transfer mechanism recognised under applicable law.
For individuals located in other jurisdictions, your Personal Data may be transferred to jurisdictions that provide an adequate or comparable level of protection, or to jurisdictions that may not provide the same level of protection as your home jurisdiction. In such cases, HashKey will take steps required by applicable law, which may include implementing appropriate technical, organisational, contractual or other safeguards to protect your Personal Data.
The specific safeguards we apply may vary depending on the jurisdictions involved and the applicable legal requirements. You may contact us using the details in Section 9 if you would like to request further information about the safeguards used for cross-border transfers, subject to applicable law and confidentiality restrictions.
5. How We Store and Protect Your Personal Data
We retain Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected, provide the Services, comply with legal and regulatory obligations, maintain records, resolve disputes, manage risks, enforce agreements, protect our rights and interests, and meet legitimate business needs where permitted by law.
When determining retention periods, we may consider the purpose for which the Personal Data is processed, whether retention is necessary to continue providing the Services, the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, applicable legal, regulatory, tax, accounting, AML/CTF, sanctions, audit and reporting requirements, and whether the Personal Data may be relevant to disputes, investigations or legal claims.
When Personal Data is no longer required for the purposes for which it was collected, and we are no longer required or permitted to retain it under applicable law, we will securely delete, destroy, anonymise or de-identify it in accordance with our internal retention policies and applicable legal requirements.
Mandatory Retention Under Financial Regulations. As a regulated virtual asset service provider, we are required by applicable anti-money laundering, counter-terrorist financing and financial regulatory laws to retain certain identity verification records, transaction records and related information for minimum statutory periods. Such statutory retention periods vary depending on the applicable jurisdiction and regulatory requirements. These retention obligations override your right to request deletion or erasure to the extent required by law. If you request deletion of Personal Data that we are legally required to retain, we will explain the basis for retention and retain the data only for the period and purposes required by law.
Biometric Information. Where we collect biometric verification information (such as selfie or liveness-check data) for identity verification, we retain it only for as long as necessary to complete the verification, comply with applicable financial regulatory or AML/KYC requirements, or as otherwise required or permitted by applicable law. We do not use, disclose or retain biometric information for any other commercial purpose. Where we use third-party identity verification providers, such providers will retain biometric information in accordance with their applicable privacy notices.
We take reasonable and practicable technical, administrative, physical and organisational measures to protect Personal Data against unauthorised or accidental access, processing, erasure, loss, use, disclosure, alteration or destruction. These measures may include access controls, authentication mechanisms, encryption, secure transmission, monitoring, internal policies, employee training, vendor due diligence and incident response procedures.
No method of transmission over the internet or method of electronic storage is completely secure. We therefore cannot guarantee absolute security. If you suspect misuse or loss of your Personal Data or account, or unauthorised access to your Personal Data or account, please contact us immediately.
In the event of a personal data breach, we will take reasonable steps to contain and investigate the incident and to notify affected individuals and the relevant data protection authority where required by applicable law. The timing, content and recipients of any such notification will comply with the requirements of the applicable jurisdiction, as further described in the relevant jurisdiction-specific addendum.
6. Direct Marketing
Where permitted by applicable law and, where required, with your consent, we may use your name, contact details, account or service preferences and related information to send you direct marketing or promotional communications by email, SMS, telephone, push notification, in-app message or other communication channels about HashKey products, services, features, market insights, campaigns, events, promotions or other information that we think may be of interest to you.
You may opt out of receiving direct marketing communications by using the unsubscribe mechanism included in the relevant communication, adjusting your account or communication preferences, or contacting us using the details in Section 9.
Even if you opt out of direct marketing communications, we may continue to send you communications that are necessary to provide the Services or comply with applicable law. These may include communications relating to identity verification, security verification, account administration, transactions, customer support, legal or regulatory notices, policy changes, service updates, dispute resolution, fraud prevention or other operational matters. These communications are not marketing communications, and you may not be able to opt out of receiving them where they are necessary for the provision of the Services or compliance with legal or regulatory obligations.
7. Third-Party Websites and Services
The Services may contain links to, integrate with, or otherwise enable you to access third-party websites, applications, platforms, products or services. These third parties operate independently from HashKey and may have their own terms, privacy policies and security practices.
Where you choose to access or use a third-party website, application or service, your interactions with that third party and any Personal Data you provide to them will be governed by their own terms and privacy policies, unless otherwise stated. HashKey is not responsible for the availability, content, security or privacy practices of any third-party website, application or service. We encourage you to review the applicable terms and privacy policies before using such services or providing Personal Data to them.
8. How You Can Exercise Your Personal Data Rights
Depending on your jurisdiction and the applicable law, you may have rights in relation to your Personal Data, including the right to:
- request access to your Personal Data and information about how we process it;
- request correction or updating of inaccurate or incomplete Personal Data;
- request deletion, blocking, erasure, destruction, restriction or cessation of use of Personal Data in certain circumstances;
- withdraw consent where we rely on consent as the basis for processing;
- object to or opt out of direct marketing;
- request portability of certain Personal Data where applicable;
- request information about third parties to whom your Personal Data has been disclosed, where applicable; and
- lodge a complaint with the relevant data protection authority.
Automated Decision-Making and Your Rights. Where an automated decision or automated processing produces legal effects or similarly significantly affects you, you may have the rights available under applicable law to request human review, express your point of view, provide additional information, or contest the decision. We will consider such requests in accordance with applicable law, regulatory requirements and our internal procedures.
On-Chain Data Limitation. Certain transaction information is recorded on public or permissioned blockchains and is, by the nature of such networks, publicly visible, immutable and not subject to deletion, correction or restriction by us. Your rights to request deletion, correction or restriction of Personal Data do not extend to on-chain data that we cannot reasonably modify. We will, however, restrict or delete the off-chain association between your identity and on-chain data where required by applicable law and where retention is no longer necessary for legal, regulatory or security purposes.
Exercise Your Rights. To exercise your rights, please contact us using the details in Section 9. When submitting a request, please specify the right you wish to exercise and how we can assist you. To protect your account and Personal Data, we may ask you to provide information to verify your identity and authority to make the request. We may also contact you for further details to clarify your request and expedite our response. These rights may be subject to limitations, exemptions, identity verification, fees and procedural requirements under applicable law. We may refuse, limit or defer a request where permitted or required by law, including where we need to retain Personal Data for legal, regulatory, security, risk management, dispute resolution or record-keeping purposes.
Self-Service Privacy Tools. Where available, you may exercise certain rights (such as accessing, downloading, exporting or updating your Personal Data, or managing your marketing preferences) directly through your account settings or the privacy tools provided within the Services. Where a self-service tool is not available for your request, or where applicable law requires additional verification, please contact us using the details in Section 9.
9. How to Contact Us
If you have questions, concerns, complaints or requests regarding this Privacy Policy or the processing of your Personal Data, please contact HashKey’s Data Protection Officer or privacy contact at:
Email: dpo@hashkey.com
HashKey’s Data Protection Officer coordinates privacy matters across the HashKey group. Where required by applicable law, the relevant HashKey entity providing the Services to you remains responsible for complying with its obligations under applicable data protection laws.
Where your request relates to a specific HashKey Service, platform or local entity, you may also contact the relevant customer support channel or local privacy contact listed in the applicable jurisdiction-specific addendum.
10. How We Update This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, business operations, legal requirements or privacy practices. We will publish the updated version on our website or through other appropriate communication channels. If we make material changes to this Privacy Policy, particularly changes that materially affect your rights or how we process your Personal Data, we may provide additional or more prominent notice where required or appropriate, such as by email, in-app notice, website announcement, special alert displayed through the Services or other appropriate means.
If applicable law requires us to obtain your consent to a change in how we process your Personal Data, we will do so before the relevant change takes effect.
If you do not agree with the updated Privacy Policy, you should stop using the Services. Your continued use of the Services after the updated Privacy Policy becomes effective will be handled in accordance with applicable law.
Jurisdiction-Specific Addenda
Each addendum supplements and forms part of this Privacy Policy. It applies only where the relevant local law applies to our processing of your Personal Data. In the event of any inconsistency between an addendum and the main body of this Privacy Policy, the addendum will prevail to the extent of that inconsistency. Unless otherwise stated, terms used in each addendum have the meanings given under the applicable local law.
In these addenda, terms such as “data user”, “organisation”, “controller” and “business operator” are used to reflect the terminology under the applicable local data protection laws. Unless otherwise indicated, they refer to the HashKey entity that determines the purposes and means of processing, or is otherwise responsible for handling, your Personal Data in connection with the relevant Services.
A. Hong Kong Addendum
This Hong Kong Addendum applies where the Personal Data (Privacy) Ordinance (Cap. 486) (the “PDPO”) applies to the processing of your Personal Data.
A.1 Data User
For Hong Kong Services, the relevant data user is generally Hash Blockchain Limited or the HashKey entity that provides the relevant Services to you.
Hong Kong contact:
Address: 14th Floor, Three Exchange Square, 8 Connaught Place, Central, Hong Kong
Email: dpo@hashkey.com or support@customer.hashkey.com
A.2 Collection Notice
When we collect Personal Data directly from you, we will take reasonably practicable steps to inform you of the purposes for which the Personal Data will be used, whether provision of the Personal Data is obligatory or voluntary, the consequences if you do not provide obligatory information, the classes of persons to whom the Personal Data may be transferred, and your rights to request access to and correction of Personal Data.
A.3 Use and Direct Marketing
We will use Personal Data for the purposes notified to you, purposes directly related to those purposes, or other purposes permitted by the PDPO. If we intend to use your Personal Data for a new purpose that is not the original or a directly related purpose, we will obtain your prescribed consent unless an exemption applies.
We will not use your Personal Data, or provide your Personal Data to another person for that person’s use, for direct marketing unless we have notified you of the prescribed information and obtained your consent or indication of no objection where required by the PDPO. You may require us to cease using or providing your Personal Data for direct marketing at any time without charge. Where we intend to provide your Personal Data to another person for that person’s use in direct marketing, we will notify you of the prescribed information and obtain your consent or indication of no objection as required under the PDPO, and you may likewise require us to cease such provision.
A.4 Processors and Transfers
Where we engage data processors to process Personal Data on our behalf, we will adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use, and to prevent Personal Data from being kept longer than necessary for processing.
A.5 Access and Correction
You have the right to request access to and correction of your Personal Data in accordance with the PDPO. You may also request information regarding our policies and practices in relation to Personal Data and the kinds of Personal Data held by us, to the extent required under the PDPO. We may charge a fee for processing a data access request where permitted by law.
A.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong, or any other competent authority available under applicable Hong Kong law.
B. Singapore Addendum
This Singapore Addendum applies where the Personal Data Protection Act 2012 of Singapore (the “PDPA”) applies to the processing of your Personal Data.
B.1 Organisation
For Singapore Services, the relevant organisation is generally HashKey Technology Services Pte. Ltd. or the HashKey entity that provides the relevant Services to you.
Singapore contact:
Address: 3 Church Street, Samsung Hub #28-06, Singapore 049483
Email: dpo@hashkey.com or support@sg-cs.hashkey.com
B.2 Consent, Notification and Withdrawal
We will collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate in the circumstances and, where required, after notifying you of the relevant purposes and obtaining your consent or relying on another basis permitted under the PDPA.
You may withdraw your consent by contacting us. If you withdraw consent, we will inform you of the likely consequences of withdrawal, which may include our inability to continue providing certain Services, processing transactions, maintaining your account or complying with regulatory requirements. After a reasonable period, we will cease the relevant collection, use or disclosure unless it is required or authorised under applicable law. Withdrawal of consent will not affect processing that occurred before withdrawal or processing that is required or authorised under applicable law.
If we change a purpose for which we collect, use or disclose Personal Data, we will ensure that the changed purpose remains reasonably relevant to the original purpose and will notify you or publicly announce the changed purpose, where required by applicable law.
B.3 Access and Correction
Subject to the PDPA, you may request access to your Personal Data, information about how it has been used or disclosed, and correction of inaccurate Personal Data. We may charge a reasonable fee for processing an access request where permitted by law.
We will respond to access or correction requests as soon as reasonably possible and, where required under the PDPA, within 30 days after receiving the request or inform you in writing within that period of the time by which we will be able to respond. Where we correct Personal Data, we may send the corrected Personal Data to organisations to which the Personal Data was disclosed within the period required by the PDPA, unless an exception applies.
If we determine, after reasonable investigation, that a requested correction is not required, we may annotate the relevant record to indicate that a correction request was made.
B.4 Transfer Outside Singapore
Where the PDPA applies, we will not transfer Personal Data outside Singapore unless we have taken appropriate steps to ensure that the recipient is bound by legally enforceable obligations or otherwise provides a standard of protection that is comparable to that required under the PDPA.
B.5 Data Breach
Where a data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after we assess that the breach is notifiable, and will notify affected individuals in accordance with the PDPA.
B.6 Direct Marketing
Where you have given consent and have not subsequently opted out, we may from time to time use your Personal Data, including your name and contact details, to send you direct marketing or promotional communications, such as emails, messages or other communications containing news, promotions, events and marketing offers. The dispatch of such direct marketing communications may be undertaken by third-party service providers acting on our behalf.
If you do not wish to receive further direct marketing or promotional materials from us, you may opt out by using the unsubscribe mechanism in the relevant communication, adjusting your account or communication preferences, or contacting us through one of the channels set out in Section B.1. Where we send marketing or promotional messages to Singapore telephone numbers, we will comply with the Do Not Call provisions under the PDPA, including checking the relevant Do Not Call Registers where required, unless we have obtained the subscriber’s or user’s clear and unambiguous consent, evidenced in written or other accessible form, to receive such messages at that number. We will also honour any withdrawal of consent or opt-out request in accordance with applicable law.
B.7 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Data Protection Commission of Singapore or any other competent authority available under applicable Singapore law.
C. Japan Addendum
This Japan Addendum applies where the Act on the Protection of Personal Information of Japan (the “APPI”) applies to the processing of your Personal Data. In this Japan Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the APPI, unless the context otherwise requires.
C.1 Business Operator
For Japan Services, the relevant business operator handling personal information is generally HashKey Japan 株式会社 (HashKey Japan Co., Ltd.) or the HashKey entity that provides the relevant Services to you.
Japan contact:
Address: 2-3-2 Marunouchi, Chiyoda-ku, Tokyo 100-0005
Email: dpo@hashkey.com or support@jp-cs.hashkey.com
Telephone: 050-3204-4855
Representative Director: Deng Chao
We will make available information required under the APPI regarding the business operator handling Personal Data, the purposes of use, procedures for requests concerning retained personal data, security control measures and contact point for complaints and enquiries, through this Privacy Policy or other appropriate notices.
For Japan Services, we will also handle Personal Data in accordance with applicable laws, regulations and the self-regulatory rules of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), where applicable.
C.2 Purpose of Use
We will specify the purpose of use of Personal Data as specifically as possible and will not use Personal Data beyond the scope necessary to achieve the specified purpose of use unless permitted by the APPI or other applicable law. If we directly acquire Personal Data from you in writing or by electronic means, we will expressly indicate the purpose of use in advance unless an exception applies.
For Japan Services, the purposes of use include those described in Section 1.4 and such additional purposes as may be notified in connection with Japan Services.
We may record telephone communications with customers where necessary to accurately understand the content of transactions, enquiries, complaints or requests.
C.3 Sensitive Personal Information
For Japan Services, “special care-required personal information” includes information requiring special care to avoid unfair discrimination, prejudice or other disadvantage, such as information relating to race, creed, social status, medical history, criminal record, victimisation by crime and other information specified under applicable Japanese laws and regulations. Other sensitive information includes information relating to labour union membership, family origin, registered domicile, healthcare and sex life, except where such information is publicly available or otherwise excluded under applicable rules.
We will not acquire, use or provide special care-required personal information or sensitive information to third parties except in the cases described in this Privacy Policy, including where such handling is permitted by laws or regulations, is necessary to protect life, body or property, is necessary for public health or child welfare, is necessary to cooperate with public authorities, is necessary for inheritance, withholding tax or similar procedures, is necessary for the proper operation of crypto asset services with the individual’s consent, or involves the use of biometric authentication information for identity verification with the individual’s consent.
C.4 Third-Party Provision and Outsourcing
For Japan Services, we will not provide Personal Data to third parties except with your consent or where otherwise permitted under the APPI.
Where we outsource all or part of the handling of Personal Data, we select service providers in accordance with our standards and exercises necessary and appropriate supervision, including by entering into contracts concerning the handling of Personal Data where appropriate.
C.5 Handling in Foreign Countries
HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or processed in jurisdictions outside Japan, including by other HashKey group entities, cloud hosting providers, SaaS providers, KYC/AML and blockchain analytics vendors, and other service providers located in Hong Kong and other jurisdictions.
Where we transfer your Personal Data to a third party located in a foreign country, we will take necessary measures in accordance with the APPI and other applicable laws and regulations.
Specifically, unless permitted under the APPI, we will obtain your prior consent to the transfer of your Personal Data to a third party located in a foreign country. When obtaining such consent, we will provide you in advance with information concerning the personal information protection system in the foreign country where the third party is located, the measures implemented by the third party for the protection of personal information, and other information that serves as a reference to you, pursuant to the APPI.
Notwithstanding the above, we may transfer Personal Data without obtaining your consent in cases permitted under the APPI, including where the recipient is located in a foreign country recognized as having a personal information protection system at a level equivalent to Japan for protecting individual rights and interests (such as EU member states and the United Kingdom), or where the recipient has established a system necessary to continuously take measures equivalent to those required to be taken by the business operator handling personal information under the APPI.
Where we transfer your Personal Data to a third party located in a foreign country on the basis that the recipient has established a system necessary to continuously take the equivalent measures referred to above, we will take necessary measures to ensure the continuous implementation of such measures by the third party and, upon your request, will provide information regarding such necessary measures in accordance with the APPI.
For inquiries or requests for information regarding these matters, please contact our Japan contact indicated in Section C.1.
C.6 Joint Use
As described in Section 3.1 of this Privacy Policy, Personal Data may be jointly used among HashKey group entities for the purposes described in this Privacy Policy. Where such sharing constitutes “joint use” under the APPI, we will comply with the applicable requirements of the APPI, including identifying the HashKey entity responsible for the management of the jointly used Personal Data where required.
C.7 Security Control Measures
We implement the following security control measures to ensure the proper handling of retained Personal Data:
- organizational security control measures
- human security control measures
- physical security control measures
- technical security control measures
- understanding of external environments
For details regarding the security control measures implemented by us, please contact our Japan contact indicated in Section C.1.
C.8 Data Breach Notification
In the event of a breach involving Personal Data that is reportable under the APPI, we will, in accordance with the APPI and PPC guidelines, report the breach to the Personal Information Protection Commission and notify the affected individuals, unless an exception applies. We will take reasonable steps to contain the breach, investigate its cause and scope, and implement measures to prevent recurrence.
C.9 Enquiries and Complaints
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Information Protection Commission or any other competent authority available under applicable Japanese law.
D. United Arab Emirates Addendum
This United Arab Emirates Addendum applies where Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the “UAE PDPL”), applicable sectoral rules, or applicable virtual asset regulatory requirements apply to the processing of your Personal Data.
D.1 Controller
For UAE Services, the relevant controller is generally HashKey MENA FZE or the HashKey entity that provides the relevant Services to you.
UAE contact:
Address: Floor 5, Premises EPO-05-35 CVT Convention Tower Dubai World Trade Centre, Dubai, United Arab Emirates
Email: dpo@hashkey.com or support@mena-cs.hashkey.com
D.2 Lawful Basis
Where the UAE PDPL applies, we process Personal Data only where we have obtained your consent or another lawful basis recognised under the UAE PDPL or other applicable law. Such lawful bases may include, where applicable, processing necessary for the performance of a contract, compliance with legal obligations, protection of public interest or vital interests, establishment, exercise or defence of legal claims, scientific or statistical research, or other circumstances recognised under applicable law.
References in this Privacy Policy to lawful bases that are not recognised under the UAE PDPL do not apply where the UAE PDPL governs our processing.
D.3 Your Rights
Subject to the UAE PDPL and other applicable laws, you may have rights to request access to Personal Data, correction of inaccurate Personal Data, deletion of Personal Data, restriction or cessation of processing, transfer of Personal Data, withdrawal of consent, and objection to certain automated processing decisions, including where such decisions have legal effects or similarly significant effects on you.
D.4 Cross-Border Transfers
We will transfer Personal Data outside the UAE only where permitted under the UAE PDPL or other applicable rules, including where the destination jurisdiction provides an adequate level of protection, appropriate safeguards are implemented, you have provided consent where required, or another statutory exception applies.
D.5 VARA-Related Requirements
Where the relevant HashKey entity is subject to the Dubai Virtual Assets Regulatory Authority (“VARA”) Technology and Information Rulebook or other VARA requirements, we will comply with applicable personal data protection, data storage, transfer, privacy governance, breach reporting and record-keeping requirements.
Where required by VARA rules, HashKey will notify VARA as soon as possible and in any event within 24 hours following notification by us to a data regulator or data subject of any incident affecting or potentially affecting Personal Data, unless prohibited by applicable law.
D.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the UAE Data Office or any other competent authority available under applicable UAE law.
E. Bermuda Addendum
This Bermuda Addendum applies where the Personal Information Protection Act 2016 of Bermuda (the “PIPA”) applies to the processing of your Personal Data. In this Bermuda Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the PIPA, unless the context otherwise requires.
E.1 Organisation
For Bermuda Services, the relevant organisation is generally HashKey Bermuda Limited or the HashKey entity that provides the relevant Services to you.
Bermuda contact:
Address: c/o Carey Olsen Services Bermuda Limited, Rosebank Centre, 5th Floor, 11 Bermudiana Road, Pembroke, HM 08, Bermuda
Email: dpo@hashkey.com or support@global-cs.hashkey.com
E.2 Use of Personal Data
We may process Personal Data where we have your consent, where processing is necessary to perform a contract with you, where processing is necessary to comply with a legal obligation, or where processing is necessary for our legitimate interests, in each case subject to PIPA.
You may also contact us to ask about the purposes for which your Personal Data is used and the means available to control or limit our use of your Personal Data, subject to PIPA and applicable exemptions.
E.3 Overseas Transfers
As we operate globally, your Personal Data may be transferred to and stored in jurisdictions outside of Bermuda. When transferring your Personal Data overseas, we will take appropriate measures to ensure that the recipient provides a level of protection comparable to that required under PIPA, including through contractual, organisational or technical safeguards where appropriate.
E.4 Security Breach Notification
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your Personal Data, we will notify you and the Privacy Commissioner in accordance with our obligations under PIPA, where such breach is likely to result in a real risk of significant harm to individuals.
E.5 Your Rights
Subject to PIPA, you may request access to, correction of, blocking of, erasure of or destruction of your Personal Data. Your request should be made in writing and include sufficient information for us to identify the relevant Personal Data and respond to your request.
We will acknowledge receipt of your request promptly and in any event no more than 2 business days after receiving it where required by our applicable procedures. We will respond within a reasonable period, generally no more than 45 days depending on the nature and complexity of the request, subject to extensions permitted under PIPA.
Certain rights described elsewhere in this Privacy Policy, including data portability or restriction of processing, may not be available under PIPA and will apply only to the extent required by applicable law.
E.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Privacy Commissioner for Bermuda or any other competent authority available under applicable Bermuda law.
لا توجد تعليقات
المقال مغلق أمام التعليقات.