Terms&Policies

banner banner

HashKey Global Team

HashKey Global Privacy Policy
HashKey Global Privacy Policy
 
Updated on 28 August 2026
 
HashKey Holdings Limited and its affiliates (collectively, “HashKey”, “we”, “us” or “our”) are a comprehensive digital asset group. HashKey operates globally and provides a range of services, including virtual asset trading, exchange, brokerage, custody and other related services. HashKey is committed to respecting and protecting your privacy and personal data. This Global Privacy Policy (this “Privacy Policy”) explains how the relevant HashKey entity collects, uses, stores, transfers, shares, discloses or otherwise processes your Personal Data when you access or use HashKey websites, mobile applications, account interfaces, online platforms and other related products or services (collectively, the “Services”).
For the purposes of this Privacy Policy, the HashKey entity that provides the relevant Services to you is generally responsible for the processing of your Personal Data in connection with those Services. “Personal Data” means any information relating to an identified or identifiable living individual, or any other similar term under applicable data protection laws, excluding the information processed anonymously. For the avoidance of doubt, this Privacy Policy is not a contract and does not itself create legal rights or obligations beyond those required by applicable law.
Our Services are designed exclusively for individuals who are 18 years of age or older. You must not access or use the Services if you are under 18 years old, do not meet the minimum age requirement applicable to the relevant Service or jurisdiction, or are otherwise legally restricted from using the Services. We do not knowingly collect Personal Data from children or minors. If you believe that a child or minor has provided Personal Data to us, please contact us so that we may take appropriate steps in accordance with applicable law.
Please read this Privacy Policy carefully before using or continuing to use the Services. If you do not provide certain Personal Data, we may be unable to provide the Services to you, process your account registration, complete identity verification, comply with legal or regulatory obligations, or make certain functions of the Services available.
This Privacy Policy is intended to operate as a global baseline. If you are located in, receive Services from, or interact with a HashKey entity established in Hong Kong, Singapore, Japan, the United Arab Emirates or Bermuda, please also review the jurisdiction-specific addendum applicable to you. If there is any inconsistency between the main body of this Privacy Policy and an applicable addendum, the addendum will prevail to the extent of that inconsistency.
This Privacy Policy is prepared and provided in English. In the event of any conflict between the English version and any other available translation, the English version shall prevail.
 

1. How We Collect and Use Your Personal Data

We collect Personal Data that you provide to us, Personal Data generated when you use the Services, and Personal Data obtained from third parties or public sources where permitted by applicable law.
 
1.1 Personal Data You Provide to Us
When you register for, apply for, subscribe to, or use the Services, we may collect Personal Data including:
 
1.1.1 Account registration and account administration. When you register for, apply for, subscribe to or use the Services, we may collect information associated with your account, including your name, username, email address, mobile phone number, account credentials, referral code, verification codes, preferred language, account settings and other information required to create, authenticate, administer and maintain your account.
 
1.1.2 Identity verification and due diligence. As a regulated virtual asset service provider, we may collect information required for identity verification, KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability and other compliance checks. This may include your date of birth, nationality, residential address, government-issued identification documents and numbers, photographs, selfie or liveness-check information, biometric verification information where required and permitted, tax information, source of funds or source of wealth information, occupation, employer information, beneficial ownership information, politically exposed person status, sanctions screening results, risk assessment results and other due diligence materials.
 
1.1.3 Financial, trading and transaction information. When you use the Services, we may collect information relating to your account and transactions, including bank account details, payment information, wallet addresses, transaction records, order history, trading activity, trading parameters and instructions, asset balances, deposit and withdrawal information, settlement details, risk profile, investor classification, suitability information and other information required for account administration, transaction processing, reporting or regulatory compliance.
 
1.1.4 Communications, support and complaints. When you contact us, submit feedback, make enquiries, lodge complaints, request support, appeal a decision or otherwise communicate with us, we may collect your contact details, account information, communication channel information, description of the issue, supporting materials, attachments, communications with us, call recordings or scripts, chat records, complaint and dispute records, and other information needed to verify your identity, understand your request, investigate the matter, provide support, resolve disputes and improve our Services.
 
1.1.5 Other information you choose to provide. We may also collect information that you submit through links, forms, surveys, events, promotions, campaigns, applications, onboarding questionnaires, due diligence requests or other interactions with us.
 
If you are an institutional or corporate customer, or act on behalf of such a customer, we may collect and process information relating to the relevant entity and its representatives, including corporate registration documents, incorporation details, business information, authorised representatives, directors, officers, employees, beneficial owners, controllers, traders, account administrators and other authorised persons. We may also collect information relating to account mandates, trading authorisations, API users, API credentials or identifiers, wallet addresses, transaction instructions, settlement details, access permissions, security settings and audit logs. We use this information to onboard and administer institutional or corporate accounts, verify authority and ownership structures, provide relevant Services, maintain account security, monitor account activities, and comply with legal and regulatory obligations.
 
If you provide Personal Data relating to another individual, you are responsible for ensuring that you have obtained all necessary authority, consent or other lawful basis to provide that information to us.
 
1.2 Personal Data Generated Through Your Use of the Services
 
To ensure the secure, stable and efficient operation of the Services, and to maintain account and transaction security, we may automatically collect or generate technical, usage, security and risk information when you access or use the Services. This may include:
 
1.2.1 We may collect device and technical information, such as your device model, device identifiers, operating system, browser type and version, IP address, language settings, time zone, network information, app version, crash logs and diagnostic information, in order to operate the Services, maintain technical compatibility, troubleshoot issues, improve performance and protect the security of our systems.
 
1.2.2 We may collect usage information, such as your login records, pages viewed, functions used, search and clickstream information, access dates and times, session duration, referral information, error reports and interaction records, in order to understand how the Services are used, support account administration, improve user experience, monitor service performance and develop or enhance our products and services.
 
1.2.3 We may collect security and risk information, such as account activity, authentication records, fraud indicators, suspicious activity reports, risk alerts, cybersecurity logs and information used to detect unauthorised, unlawful or non-compliant activities, in order to authenticate users, maintain account and transaction security, detect and prevent fraud, respond to security incidents and comply with legal and regulatory obligations.
 
1.2.4 We may collect approximate location information derived from IP address or similar technical data. We will collect precise location information only where the relevant function requires it, you have enabled the applicable device permission, and the collection is permitted by applicable law, for example to support security verification, fraud prevention, regulatory compliance or other location-based functionality notified to you where applicable.
 
Depending on the functions you use, we may request access to certain device permissions, such as camera, photo album or storage, push notification, file upload, biometric or liveness check, and, where applicable, microphone or location permissions. For example, camera or photo permissions may be required for identity verification, document upload, selfie or liveness checks; file upload permissions may be required when you submit onboarding, due diligence, source-of-funds, complaint or support materials; push notification permissions may be used for account, security, transaction or service alerts; and microphone or location permissions may be used only where the relevant function requires them and such use is notified to you.
 
We will request such permissions only where relevant to the function you use. If you decline a permission, the relevant function may not be available or may not operate properly, but this will not affect your use of other functions that do not require that permission. You may manage device permissions through your device or browser settings, subject to the functionality of the relevant device, operating system or browser.
 
1.3 Personal Data from Third Parties and Public Sources
 
Where permitted by applicable law, we may obtain Personal Data from HashKey group entities, service providers, business partners, banks, payment service providers, custodians, virtual asset service providers, blockchain analytics providers, identity verification vendors, credit reference or risk information providers, sanctions and politically exposed person databases, fraud prevention databases, government or regulatory sources, public registers, publicly available websites and other lawful sources. We use such information to verify your identity, conduct due diligence, assess account, wallet, transaction and counterparty risks, comply with legal and regulatory obligations, prevent fraud and unlawful activities, and provide, secure and improve the Services.
 
Certain virtual asset transactions are recorded on public or permissioned blockchains. Depending on the relevant network, wallet addresses, transaction hashes, timestamps, transferred amounts, digital signatures, smart contract identifiers and other on-chain information may be publicly visible, immutable or independently processed by third parties. We may collect, analyse and use on-chain information, including through blockchain analytics tools, and may combine it with other information we hold about you where permitted by applicable law, to provide the Services, verify transactions, assess wallet, transaction and counterparty risks, detect suspicious activity, comply with legal and regulatory obligations and respond to lawful requests from regulators, law enforcement agencies or other competent authorities.
 
1.4 How We Use Personal Data
 
We may use Personal Data for the following purposes:
 
1.4.1 We use Personal Data to process your application, registration, subscription and onboarding for the Services, create and administer your account, verify your identity, determine your eligibility to access the relevant Services, and perform KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability, creditworthiness, financial standing, solvency and other compliance checks.
 
1.4.2 We use Personal Data to provide, administer, operate, maintain and improve the Services, including processing transactions, safeguarding assets, maintaining accounts, facilitating settlements, maintaining records, providing customer support and enabling the functionality of the Services. We also use Personal Data to authenticate your identity, maintain account and transaction security, detect anomalous transaction patterns, monitor account activity, protect users and assets, and preserve the integrity and security of the Services.
 
1.4.3 We use Personal Data to comply with legal, regulatory, tax, accounting, court, law enforcement, self-regulatory organization, industry body or governmental requirements, including requirements relating to virtual asset transfers, AML/CTF, sanctions, fraud prevention, market integrity, regulatory reporting, audits, investigations and lawful requests from competent authorities.
 
1.4.4 We use Personal Data to communicate with you regarding your account, transactions, security alerts, service updates, changes to terms or policies, customer support, dispute resolution and other operational matters. We may also use Personal Data to respond to and process enquiries, complaints, appeals, privacy-related requests and other communications from you.
 
1.4.5 We use Personal Data for internal administration, audit, record-keeping, risk management, legal claim management, business continuity, corporate governance and general business management. We may also use Personal Data to improve user experience, monitor service performance, troubleshoot technical issues, conduct data analytics, develop or enhance products and services, compile aggregated or anonymised statistics, conduct research, surveys, market analysis, events, campaigns and direct marketing where permitted by applicable law and, where required, with your consent.
 
1.4.6 We may use Personal Data for due diligence, restructuring, merger, acquisition, financing, asset sale, transfer of business or similar corporate transactions, and for other purposes that are directly related to the above, notified to you at the time of collection, authorised by you, or otherwise permitted by applicable law.
 
We will only process Personal Data where we have a lawful basis or are otherwise permitted to do so under applicable law. Depending on the jurisdiction and the nature of the processing, our lawful basis may include your consent, performance of a contract with you, compliance with legal or regulatory obligations, establishment, exercise or defence of legal claims, protection of vital interests, public interest grounds, or our legitimate business interests where recognised by applicable law. Where applicable law does not recognise legitimate interests as a lawful basis (for example, under the UAE PDPL), we will rely on your consent or another statutory basis recognised under that law, and any reference to legitimate interests in this Privacy Policy will not apply to you. If we intend to process your Personal Data for any other purpose not covered by this Privacy Policy, we will notify you beforehand and ensure that such processing fully complies with applicable data protection laws.
 
We may use automated systems, rules engines, artificial intelligence, machine learning models or analytics tools to support identity verification, fraud detection, sanctions screening, transaction monitoring, account security, customer risk rating and other compliance, security or risk management activities. Such technologies may process information to identify patterns, detect anomalies, assess risks, prioritise reviews, generate alerts or support operational decisions. These technologies are used as support tools and are not intended to replace human oversight where such oversight is required under applicable law, regulatory requirements or our internal procedures. Where an automated output may materially affect your access to the Services, account status or transaction permissions, we will apply human review where required by applicable law, regulatory requirements or our internal compliance procedures.
 
We may aggregate, de-identify or anonymise Personal Data so that it no longer identifies you, and use such information for analytics, service improvement, product development, security, risk management, research, statistical and other legitimate business purposes. Where information has been anonymised, we will keep and use it in anonymised form and will not attempt to re-identify it except where required or permitted by applicable law.
 

2. How We Use Cookies and Similar Technologies

We use cookies, software development kits, pixels, local storage and similar technologies to operate the Services, remember your preferences, support account login, maintain security, analyse usage, improve performance and, where permitted, measure or deliver marketing.
 
You may configure your browser or device settings to block or delete cookies and similar technologies. If you do so, certain functions of the Services may not work properly, and you may need to log in again or reset your preferences. Where required by applicable law, we will obtain your consent before using non-essential cookies or similar technologies.
 
For more information on our use of cookies and similar technologies, please refer to the applicable HashKey Cookie Policy.
 

3. How We Share, Transfer or Disclose Your Personal Data

We may share, transfer or disclose Personal Data as described below, subject to applicable law and appropriate safeguards.
 
3.1 HashKey Group Entities
 
We may share Personal Data within the HashKey group where necessary for the purposes described in this Privacy Policy, including account administration, group-wide compliance, risk management, customer support, technology operations, audit, legal and business management.
 
Cross-platform account integration. HashKey operates through affiliated entities in different jurisdictions and provides Services through multiple platforms and channels. Where you register for an account with one HashKey group entity, we may share relevant Personal Data with other HashKey group entities to facilitate an integrated account experience across HashKey platforms. Such sharing may enable us to recognise your existing HashKey account, create or maintain corresponding account profiles, provide access to Services offered by other HashKey entities, administer your account relationship, and apply consistent security, compliance and risk management controls across our platforms.
 
Cross-Entity Onboarding and Due Diligence Reliance. Where permitted by applicable law and where necessary for the provision of the relevant Services, we may also share and rely on certain information relating to your identity verification and due diligence processes, including KYC, AML/CFT and sanctions screening information, to facilitate onboarding, avoid unnecessary duplication of verification procedures, maintain consistent compliance standards and support regulatory obligations across HashKey entities. Where required by applicable law, we will obtain your consent or implement another lawful basis before such information is shared or relied upon.
 
Intra-Group AML/CFT Data Sharing. Where you hold accounts with, or are identified across, more than one HashKey group entity, authorised compliance personnel (including Money Laundering Reporting Officers or their equivalents) may share Personal Data about you between HashKey group entities for anti-money laundering, counter-terrorist financing and sanctions compliance purposes. Such sharing may include identity and verification data, customer risk ratings, politically exposed person and sanctions screening results, transaction monitoring alerts, and related compliance information. This sharing is subject to strict purpose limitation: it may be used only for AML/CFT, sanctions compliance and related regulatory purposes and not for commercial, marketing or other unrelated purposes. Where one HashKey entity is legally required to freeze or restrict your account under applicable sanctions legislation or regulatory direction, it may notify other HashKey group entities, which will independently assess whether a corresponding restriction is required under their own applicable law.
 
3.2 Service Providers, Agents and Contractors
 
We may disclose Personal Data to service providers, agents, contractors and professional advisers who support our business and operations, including providers of identity verification, compliance, fraud prevention and security services, blockchain analytics, technology infrastructure, cloud hosting, data storage, cybersecurity, communications, customer relationship management, marketing, analytics, artificial intelligence, payment processing, banking, custody, audit, legal, tax and other professional, administrative or operational services.
 
These third parties are authorised to access, process or store Personal Data only to the extent necessary to perform services for us or as otherwise permitted by applicable law. We take appropriate contractual, technical or organisational measures to require them to protect Personal Data, process it in accordance with our instructions where applicable, and retain it only as necessary for the relevant purposes.
 
3.3 Regulators, Government Authorities and Other Required Recipients
 
We may disclose Personal Data to courts, regulators, supervisory bodies, law enforcement agencies, tax authorities, government authorities, self-regulatory organisations, industry bodies, financial institutions or other third parties where required or permitted by law, regulation, court order, legal process, regulatory request, applicable rulebook, travel rule requirement or other compliance obligation. We may also disclose Personal Data where we reasonably consider disclosure necessary to protect our rights, property, users, employees, systems or the integrity of the Services; to detect, prevent or address fraud, security incidents, unlawful activity or violations of our terms or policies; or to manage legal, regulatory, operational or security risks.
 
3.4 Travel Rule and Virtual Asset Transfers.
 
As a regulated virtual asset service provider, we are required by FATF Recommendation 16 and applicable anti-money laundering laws to obtain, hold and transmit certain originator and beneficiary information in connection with virtual asset transfers that meet the applicable threshold. When you send or receive a virtual asset transfer that meets the applicable threshold, we will collect and transmit information about you (such as your name, account or wallet identifier, and in some cases your address, national identity number or date of birth) to, or receive such information from, the counterparty virtual asset service provider. This disclosure is a mandatory legal obligation that may take precedence over the data minimisation principle, and you will not be able to exercise your right to restrict or object to such processing to the extent it is required by applicable law.
 
3.5 Business Partners and Third Parties Involved in Your Transactions
 
Where necessary to provide the Services, facilitate transactions, support joint products or services, administer partnership, referral, rebate or other commercial programs, or otherwise fulfil your requests, we may share relevant Personal Data with banks, payment service providers, custodians, brokers, liquidity providers, virtual asset service providers, referral partners, joint marketing partners and other business partners involved in the relevant products, services or transactions. We will share only the Personal Data that is reasonably necessary for the relevant purpose and will do so in accordance with applicable law. Where required by applicable law, we will obtain your consent or rely on another lawful basis before sharing such Personal Data.
 
3.6 Corporate Transactions
 
If HashKey is involved in an actual or proposed merger, acquisition, restructuring, financing, asset sale, transfer of business, insolvency, joint venture or similar transaction, we may disclose or transfer Personal Data to counterparties, advisers and other participants in the transaction, subject to appropriate confidentiality and data protection arrangements where required.
 
3.7 With Your Consent or at Your Direction
 
We may share Personal Data with third parties where you have consented to, requested or authorised the sharing, or where the sharing is otherwise notified to you and permitted by applicable law.
 

4. Cross-Border Transfer of Personal Data

HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or otherwise processed in jurisdictions outside the jurisdiction in which it was originally collected or outside the jurisdiction where the relevant HashKey entity is established, including Hong Kong, Singapore, Japan, the United Arab Emirates, Bermuda and other jurisdictions where HashKey group entities, service providers or business partners operate.
 
Where we transfer Personal Data across borders, we will do so in accordance with applicable data protection laws. Depending on the applicable jurisdiction, this may include implementing contractual safeguards, conducting transfer impact assessments, ensuring a comparable or adequate level of protection, relying on your consent, relying on recognised certifications or other lawful transfer mechanisms, or applying other measures required or permitted by law.
 
Where the EU GDPR or UK GDPR applies, and your Personal Data is transferred from the European Economic Area or the United Kingdom to a jurisdiction that has not been recognised as providing an adequate level of protection, we will implement an appropriate transfer mechanism where required. Such mechanisms may include, as applicable, an adequacy decision or adequacy regulation, binding corporate rules for intra-group transfers, the European Commission’s standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or another transfer mechanism recognised under applicable law.
 
For individuals located in other jurisdictions, your Personal Data may be transferred to jurisdictions that provide an adequate or comparable level of protection, or to jurisdictions that may not provide the same level of protection as your home jurisdiction. In such cases, HashKey will take steps required by applicable law, which may include implementing appropriate technical, organisational, contractual or other safeguards to protect your Personal Data.
 
The specific safeguards we apply may vary depending on the jurisdictions involved and the applicable legal requirements. You may contact us using the details in Section 9 if you would like to request further information about the safeguards used for cross-border transfers, subject to applicable law and confidentiality restrictions.
 

5. How We Store and Protect Your Personal Data

We retain Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected, provide the Services, comply with legal and regulatory obligations, maintain records, resolve disputes, manage risks, enforce agreements, protect our rights and interests, and meet legitimate business needs where permitted by law.
 
When determining retention periods, we may consider the purpose for which the Personal Data is processed, whether retention is necessary to continue providing the Services, the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, applicable legal, regulatory, tax, accounting, AML/CTF, sanctions, audit and reporting requirements, and whether the Personal Data may be relevant to disputes, investigations or legal claims.
 
When Personal Data is no longer required for the purposes for which it was collected, and we are no longer required or permitted to retain it under applicable law, we will securely delete, destroy, anonymise or de-identify it in accordance with our internal retention policies and applicable legal requirements.
 
Mandatory Retention Under Financial Regulations. As a regulated virtual asset service provider, we are required by applicable anti-money laundering, counter-terrorist financing and financial regulatory laws to retain certain identity verification records, transaction records and related information for minimum statutory periods. Such statutory retention periods vary depending on the applicable jurisdiction and regulatory requirements. These retention obligations override your right to request deletion or erasure to the extent required by law. If you request deletion of Personal Data that we are legally required to retain, we will explain the basis for retention and retain the data only for the period and purposes required by law.
 
Biometric Information. Where we collect biometric verification information (such as selfie or liveness-check data) for identity verification, we retain it only for as long as necessary to complete the verification, comply with applicable financial regulatory or AML/KYC requirements, or as otherwise required or permitted by applicable law. We do not use, disclose or retain biometric information for any other commercial purpose. Where we use third-party identity verification providers, such providers will retain biometric information in accordance with their applicable privacy notices.
 
We take reasonable and practicable technical, administrative, physical and organisational measures to protect Personal Data against unauthorised or accidental access, processing, erasure, loss, use, disclosure, alteration or destruction. These measures may include access controls, authentication mechanisms, encryption, secure transmission, monitoring, internal policies, employee training, vendor due diligence and incident response procedures.
 
No method of transmission over the internet or method of electronic storage is completely secure. We therefore cannot guarantee absolute security. If you suspect misuse or loss of your Personal Data or account, or unauthorised access to your Personal Data or account, please contact us immediately.
 
In the event of a personal data breach, we will take reasonable steps to contain and investigate the incident and to notify affected individuals and the relevant data protection authority where required by applicable law. The timing, content and recipients of any such notification will comply with the requirements of the applicable jurisdiction, as further described in the relevant jurisdiction-specific addendum.
 

6. Direct Marketing

Where permitted by applicable law and, where required, with your consent, we may use your name, contact details, account or service preferences and related information to send you direct marketing or promotional communications by email, SMS, telephone, push notification, in-app message or other communication channels about HashKey products, services, features, market insights, campaigns, events, promotions or other information that we think may be of interest to you.
 
You may opt out of receiving direct marketing communications by using the unsubscribe mechanism included in the relevant communication, adjusting your account or communication preferences, or contacting us using the details in Section 9.
 
Even if you opt out of direct marketing communications, we may continue to send you communications that are necessary to provide the Services or comply with applicable law. These may include communications relating to identity verification, security verification, account administration, transactions, customer support, legal or regulatory notices, policy changes, service updates, dispute resolution, fraud prevention or other operational matters. These communications are not marketing communications, and you may not be able to opt out of receiving them where they are necessary for the provision of the Services or compliance with legal or regulatory obligations.
 

7. Third-Party Websites and Services

The Services may contain links to, integrate with, or otherwise enable you to access third-party websites, applications, platforms, products or services. These third parties operate independently from HashKey and may have their own terms, privacy policies and security practices.
 
Where you choose to access or use a third-party website, application or service, your interactions with that third party and any Personal Data you provide to them will be governed by their own terms and privacy policies, unless otherwise stated. HashKey is not responsible for the availability, content, security or privacy practices of any third-party website, application or service. We encourage you to review the applicable terms and privacy policies before using such services or providing Personal Data to them.
 

8. How You Can Exercise Your Personal Data Rights

Depending on your jurisdiction and the applicable law, you may have rights in relation to your Personal Data, including the right to:
  • request access to your Personal Data and information about how we process it;
  • request correction or updating of inaccurate or incomplete Personal Data;
  • request deletion, blocking, erasure, destruction, restriction or cessation of use of Personal Data in certain circumstances;
  • withdraw consent where we rely on consent as the basis for processing;
  • object to or opt out of direct marketing;
  • request portability of certain Personal Data where applicable;
  • request information about third parties to whom your Personal Data has been disclosed, where applicable; and
  • lodge a complaint with the relevant data protection authority.
Automated Decision-Making and Your Rights. Where an automated decision or automated processing produces legal effects or similarly significantly affects you, you may have the rights available under applicable law to request human review, express your point of view, provide additional information, or contest the decision. We will consider such requests in accordance with applicable law, regulatory requirements and our internal procedures.
 
On-Chain Data Limitation. Certain transaction information is recorded on public or permissioned blockchains and is, by the nature of such networks, publicly visible, immutable and not subject to deletion, correction or restriction by us. Your rights to request deletion, correction or restriction of Personal Data do not extend to on-chain data that we cannot reasonably modify. We will, however, restrict or delete the off-chain association between your identity and on-chain data where required by applicable law and where retention is no longer necessary for legal, regulatory or security purposes.
 
Exercise Your Rights. To exercise your rights, please contact us using the details in Section 9. When submitting a request, please specify the right you wish to exercise and how we can assist you. To protect your account and Personal Data, we may ask you to provide information to verify your identity and authority to make the request. We may also contact you for further details to clarify your request and expedite our response. These rights may be subject to limitations, exemptions, identity verification, fees and procedural requirements under applicable law. We may refuse, limit or defer a request where permitted or required by law, including where we need to retain Personal Data for legal, regulatory, security, risk management, dispute resolution or record-keeping purposes.
 
Self-Service Privacy Tools. Where available, you may exercise certain rights (such as accessing, downloading, exporting or updating your Personal Data, or managing your marketing preferences) directly through your account settings or the privacy tools provided within the Services. Where a self-service tool is not available for your request, or where applicable law requires additional verification, please contact us using the details in Section 9.
 

9. How to Contact Us

If you have questions, concerns, complaints or requests regarding this Privacy Policy or the processing of your Personal Data, please contact HashKey’s Data Protection Officer or privacy contact at:
 
HashKey’s Data Protection Officer coordinates privacy matters across the HashKey group. Where required by applicable law, the relevant HashKey entity providing the Services to you remains responsible for complying with its obligations under applicable data protection laws.
 
Where your request relates to a specific HashKey Service, platform or local entity, you may also contact the relevant customer support channel or local privacy contact listed in the applicable jurisdiction-specific addendum.
 

10. How We Update This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, business operations, legal requirements or privacy practices. We will publish the updated version on our website or through other appropriate communication channels. If we make material changes to this Privacy Policy, particularly changes that materially affect your rights or how we process your Personal Data, we may provide additional or more prominent notice where required or appropriate, such as by email, in-app notice, website announcement, special alert displayed through the Services or other appropriate means.
 
If applicable law requires us to obtain your consent to a change in how we process your Personal Data, we will do so before the relevant change takes effect.
 
If you do not agree with the updated Privacy Policy, you should stop using the Services. Your continued use of the Services after the updated Privacy Policy becomes effective will be handled in accordance with applicable law.
 
Jurisdiction-Specific Addenda
Each addendum supplements and forms part of this Privacy Policy. It applies only where the relevant local law applies to our processing of your Personal Data. In the event of any inconsistency between an addendum and the main body of this Privacy Policy, the addendum will prevail to the extent of that inconsistency. Unless otherwise stated, terms used in each addendum have the meanings given under the applicable local law.
In these addenda, terms such as “data user”, “organisation”, “controller” and “business operator” are used to reflect the terminology under the applicable local data protection laws. Unless otherwise indicated, they refer to the HashKey entity that determines the purposes and means of processing, or is otherwise responsible for handling, your Personal Data in connection with the relevant Services.
 

A. Hong Kong Addendum

This Hong Kong Addendum applies where the Personal Data (Privacy) Ordinance (Cap. 486) (the “PDPO”) applies to the processing of your Personal Data.
 
A.1 Data User
For Hong Kong Services, the relevant data user is generally Hash Blockchain Limited or the HashKey entity that provides the relevant Services to you.
Hong Kong contact:
Address: 14th Floor, Three Exchange Square, 8 Connaught Place, Central, Hong Kong
Email: dpo@hashkey.com or support@customer.hashkey.com
 
A.2 Collection Notice
When we collect Personal Data directly from you, we will take reasonably practicable steps to inform you of the purposes for which the Personal Data will be used, whether provision of the Personal Data is obligatory or voluntary, the consequences if you do not provide obligatory information, the classes of persons to whom the Personal Data may be transferred, and your rights to request access to and correction of Personal Data.
 
A.3 Use and Direct Marketing
We will use Personal Data for the purposes notified to you, purposes directly related to those purposes, or other purposes permitted by the PDPO. If we intend to use your Personal Data for a new purpose that is not the original or a directly related purpose, we will obtain your prescribed consent unless an exemption applies.
We will not use your Personal Data, or provide your Personal Data to another person for that person’s use, for direct marketing unless we have notified you of the prescribed information and obtained your consent or indication of no objection where required by the PDPO. You may require us to cease using or providing your Personal Data for direct marketing at any time without charge. Where we intend to provide your Personal Data to another person for that person’s use in direct marketing, we will notify you of the prescribed information and obtain your consent or indication of no objection as required under the PDPO, and you may likewise require us to cease such provision.
 
A.4 Processors and Transfers
Where we engage data processors to process Personal Data on our behalf, we will adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use, and to prevent Personal Data from being kept longer than necessary for processing.
 
A.5 Access and Correction
You have the right to request access to and correction of your Personal Data in accordance with the PDPO. You may also request information regarding our policies and practices in relation to Personal Data and the kinds of Personal Data held by us, to the extent required under the PDPO. We may charge a fee for processing a data access request where permitted by law.
 
A.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong, or any other competent authority available under applicable Hong Kong law.
 

B. Singapore Addendum

This Singapore Addendum applies where the Personal Data Protection Act 2012 of Singapore (the “PDPA”) applies to the processing of your Personal Data.
 
B.1 Organisation
For Singapore Services, the relevant organisation is generally HashKey Technology Services Pte. Ltd. or the HashKey entity that provides the relevant Services to you.
Singapore contact:
Address: 3 Church Street, Samsung Hub #28-06, Singapore 049483
Email: dpo@hashkey.com or support@sg-cs.hashkey.com
 
B.2 Consent, Notification and Withdrawal
We will collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate in the circumstances and, where required, after notifying you of the relevant purposes and obtaining your consent or relying on another basis permitted under the PDPA.
 
You may withdraw your consent by contacting us. If you withdraw consent, we will inform you of the likely consequences of withdrawal, which may include our inability to continue providing certain Services, processing transactions, maintaining your account or complying with regulatory requirements. After a reasonable period, we will cease the relevant collection, use or disclosure unless it is required or authorised under applicable law. Withdrawal of consent will not affect processing that occurred before withdrawal or processing that is required or authorised under applicable law.
 
If we change a purpose for which we collect, use or disclose Personal Data, we will ensure that the changed purpose remains reasonably relevant to the original purpose and will notify you or publicly announce the changed purpose, where required by applicable law.
 
B.3 Access and Correction
Subject to the PDPA, you may request access to your Personal Data, information about how it has been used or disclosed, and correction of inaccurate Personal Data. We may charge a reasonable fee for processing an access request where permitted by law.
 
We will respond to access or correction requests as soon as reasonably possible and, where required under the PDPA, within 30 days after receiving the request or inform you in writing within that period of the time by which we will be able to respond. Where we correct Personal Data, we may send the corrected Personal Data to organisations to which the Personal Data was disclosed within the period required by the PDPA, unless an exception applies.
 
If we determine, after reasonable investigation, that a requested correction is not required, we may annotate the relevant record to indicate that a correction request was made.
 
B.4 Transfer Outside Singapore
Where the PDPA applies, we will not transfer Personal Data outside Singapore unless we have taken appropriate steps to ensure that the recipient is bound by legally enforceable obligations or otherwise provides a standard of protection that is comparable to that required under the PDPA.
 
B.5 Data Breach
Where a data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after we assess that the breach is notifiable, and will notify affected individuals in accordance with the PDPA.
 
B.6 Direct Marketing
Where you have given consent and have not subsequently opted out, we may from time to time use your Personal Data, including your name and contact details, to send you direct marketing or promotional communications, such as emails, messages or other communications containing news, promotions, events and marketing offers. The dispatch of such direct marketing communications may be undertaken by third-party service providers acting on our behalf.
 
If you do not wish to receive further direct marketing or promotional materials from us, you may opt out by using the unsubscribe mechanism in the relevant communication, adjusting your account or communication preferences, or contacting us through one of the channels set out in Section B.1. Where we send marketing or promotional messages to Singapore telephone numbers, we will comply with the Do Not Call provisions under the PDPA, including checking the relevant Do Not Call Registers where required, unless we have obtained the subscriber’s or user’s clear and unambiguous consent, evidenced in written or other accessible form, to receive such messages at that number. We will also honour any withdrawal of consent or opt-out request in accordance with applicable law.
 
B.7 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Data Protection Commission of Singapore or any other competent authority available under applicable Singapore law.
 

C. Japan Addendum

This Japan Addendum applies where the Act on the Protection of Personal Information of Japan (the “APPI”) applies to the processing of your Personal Data. In this Japan Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the APPI, unless the context otherwise requires.
 
C.1 Business Operator
For Japan Services, the relevant business operator handling personal information is generally HashKey Japan 株式会社 (HashKey Japan Co., Ltd.) or the HashKey entity that provides the relevant Services to you.
Japan contact:
Address: 2-3-2 Marunouchi, Chiyoda-ku, Tokyo 100-0005
Email: dpo@hashkey.com or support@jp-cs.hashkey.com
Telephone: 050-3204-4855
 
We will make available information required under the APPI regarding the business operator handling Personal Data, the purposes of use, procedures for requests concerning retained personal data, security control measures and contact point for complaints and enquiries, through this Privacy Policy or other appropriate notices.
For Japan Services, we will also handle Personal Data in accordance with applicable laws, regulations and the self-regulatory rules of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), where applicable.
 
C.2 Purpose of Use
We will specify the purpose of use of Personal Data as specifically as possible and will not use Personal Data beyond the scope necessary to achieve the specified purpose of use unless permitted by the APPI or other applicable law. If we directly acquire Personal Data from you in writing or by electronic means, we will expressly indicate the purpose of use in advance unless an exception applies.
 
For Japan Services, the purposes of use include those described in Section 1.4 and such additional purposes as may be notified in connection with Japan Services.
 
We may record telephone communications with customers where necessary to accurately understand the content of transactions, enquiries, complaints or requests.
 
C.3 Sensitive Personal Information
For Japan Services, “special care-required personal information” includes information requiring special care to avoid unfair discrimination, prejudice or other disadvantage, such as information relating to race, creed, social status, medical history, criminal record, victimisation by crime and other information specified under applicable Japanese laws and regulations. Other sensitive information includes information relating to labour union membership, family origin, registered domicile, healthcare and sex life, except where such information is publicly available or otherwise excluded under applicable rules.
 
We will not acquire, use or provide special care-required personal information or sensitive information to third parties except in the cases described in this Privacy Policy, including where such handling is permitted by laws or regulations, is necessary to protect life, body or property, is necessary for public health or child welfare, is necessary to cooperate with public authorities, is necessary for inheritance, withholding tax or similar procedures, is necessary for the proper operation of crypto asset services with the individual’s consent, or involves the use of biometric authentication information for identity verification with the individual’s consent.
 
C.4 Third-Party Provision and Outsourcing
For Japan Services, we will not provide Personal Data to third parties except with your consent or where otherwise permitted under the APPI.
 
Where we outsource all or part of the handling of Personal Data, we select service providers in accordance with our standards and exercises necessary and appropriate supervision, including by entering into contracts concerning the handling of Personal Data where appropriate.
 
C.5 Handling in Foreign Countries
HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or processed in jurisdictions outside Japan, including by other HashKey group entities, cloud hosting providers, SaaS providers, KYC/AML and blockchain analytics vendors, and other service providers located in Hong Kong and other jurisdictions.
 
Where we transfer your Personal Data to a third party located in a foreign country, we will take necessary measures in accordance with the APPI and other applicable laws and regulations.
 
Specifically, unless permitted under the APPI, we will obtain your prior consent to the transfer of your Personal Data to a third party located in a foreign country. When obtaining such consent, we will provide you in advance with information concerning the personal information protection system in the foreign country where the third party is located, the measures implemented by the third party for the protection of personal information, and other information that serves as a reference to you, pursuant to the APPI.
 
Notwithstanding the above, we may transfer Personal Data without obtaining your consent in cases permitted under the APPI, including where the recipient is located in a foreign country recognized as having a personal information protection system at a level equivalent to Japan for protecting individual rights and interests (such as EU member states and the United Kingdom), or where the recipient has established a system necessary to continuously take measures equivalent to those required to be taken by the business operator handling personal information under the APPI.
 
Where we transfer your Personal Data to a third party located in a foreign country on the basis that the recipient has established a system necessary to continuously take the equivalent measures referred to above, we will take necessary measures to ensure the continuous implementation of such measures by the third party and, upon your request, will provide information regarding such necessary measures in accordance with the APPI.
 
For inquiries or requests for information regarding these matters, please contact our Japan contact indicated in Section C.1.
 
C.6 Joint Use
As described in Section 3.1 of this Privacy Policy, Personal Data may be jointly used among HashKey group entities for the purposes described in this Privacy Policy. Where such sharing constitutes “joint use” under the APPI, we will comply with the applicable requirements of the APPI, including identifying the HashKey entity responsible for the management of the jointly used Personal Data where required.
 
C.7 Security Control Measures
We implement the following security control measures to ensure the proper handling of retained Personal Data:
  • organizational security control measures
  • human security control measures
  • physical security control measures
  • technical security control measures
  • understanding of external environments
For details regarding the security control measures implemented by us, please contact our Japan contact indicated in Section C.1.
 
C.8 Data Breach Notification
In the event of a breach involving Personal Data that is reportable under the APPI, we will, in accordance with the APPI and PPC guidelines, report the breach to the Personal Information Protection Commission and notify the affected individuals, unless an exception applies. We will take reasonable steps to contain the breach, investigate its cause and scope, and implement measures to prevent recurrence.
 
C.9 Enquiries and Complaints
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Information Protection Commission or any other competent authority available under applicable Japanese law.
 

D. United Arab Emirates Addendum

This United Arab Emirates Addendum applies where Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the “UAE PDPL”), applicable sectoral rules, or applicable virtual asset regulatory requirements apply to the processing of your Personal Data.
 
D.1 Controller
For UAE Services, the relevant controller is generally HashKey MENA FZE or the HashKey entity that provides the relevant Services to you.
UAE contact:
Address: Floor 5, Premises EPO-05-35 CVT Convention Tower Dubai World Trade Centre, Dubai, United Arab Emirates
Email: dpo@hashkey.com or support@mena-cs.hashkey.com
 
D.2 Lawful Basis
Where the UAE PDPL applies, we process Personal Data only where we have obtained your consent or another lawful basis recognised under the UAE PDPL or other applicable law. Such lawful bases may include, where applicable, processing necessary for the performance of a contract, compliance with legal obligations, protection of public interest or vital interests, establishment, exercise or defence of legal claims, scientific or statistical research, or other circumstances recognised under applicable law.
References in this Privacy Policy to lawful bases that are not recognised under the UAE PDPL do not apply where the UAE PDPL governs our processing.
 
D.3 Your Rights
Subject to the UAE PDPL and other applicable laws, you may have rights to request access to Personal Data, correction of inaccurate Personal Data, deletion of Personal Data, restriction or cessation of processing, transfer of Personal Data, withdrawal of consent, and objection to certain automated processing decisions, including where such decisions have legal effects or similarly significant effects on you.
 
D.4 Cross-Border Transfers
We will transfer Personal Data outside the UAE only where permitted under the UAE PDPL or other applicable rules, including where the destination jurisdiction provides an adequate level of protection, appropriate safeguards are implemented, you have provided consent where required, or another statutory exception applies.
 
D.5 VARA-Related Requirements
Where the relevant HashKey entity is subject to the Dubai Virtual Assets Regulatory Authority (“VARA”) Technology and Information Rulebook or other VARA requirements, we will comply with applicable personal data protection, data storage, transfer, privacy governance, breach reporting and record-keeping requirements.
Where required by VARA rules, HashKey will notify VARA as soon as possible and in any event within 24 hours following notification by us to a data regulator or data subject of any incident affecting or potentially affecting Personal Data, unless prohibited by applicable law.
 
D.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the UAE Data Office or any other competent authority available under applicable UAE law.
 

E. Bermuda Addendum

This Bermuda Addendum applies where the Personal Information Protection Act 2016 of Bermuda (the “PIPA”) applies to the processing of your Personal Data. In this Bermuda Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the PIPA, unless the context otherwise requires.
 
E.1 Organisation
For Bermuda Services, the relevant organisation is generally HashKey Bermuda Limited or the HashKey entity that provides the relevant Services to you.
Bermuda contact:
Address: c/o Carey Olsen Services Bermuda Limited, Rosebank Centre, 5th Floor, 11 Bermudiana Road, Pembroke, HM 08, Bermuda
Email: dpo@hashkey.com or support@global-cs.hashkey.com
 
E.2 Use of Personal Data
We may process Personal Data where we have your consent, where processing is necessary to perform a contract with you, where processing is necessary to comply with a legal obligation, or where processing is necessary for our legitimate interests, in each case subject to PIPA.
You may also contact us to ask about the purposes for which your Personal Data is used and the means available to control or limit our use of your Personal Data, subject to PIPA and applicable exemptions.
 
E.3 Overseas Transfers
As we operate globally, your Personal Data may be transferred to and stored in jurisdictions outside of Bermuda. When transferring your Personal Data overseas, we will take appropriate measures to ensure that the recipient provides a level of protection comparable to that required under PIPA, including through contractual, organisational or technical safeguards where appropriate.
 
E.4 Security Breach Notification
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your Personal Data, we will notify you and the Privacy Commissioner in accordance with our obligations under PIPA, where such breach is likely to result in a real risk of significant harm to individuals.
 
E.5 Your Rights
Subject to PIPA, you may request access to, correction of, blocking of, erasure of or destruction of your Personal Data. Your request should be made in writing and include sufficient information for us to identify the relevant Personal Data and respond to your request.
We will acknowledge receipt of your request promptly and in any event no more than 2 business days after receiving it where required by our applicable procedures. We will respond within a reasonable period, generally no more than 45 days depending on the nature and complexity of the request, subject to extensions permitted under PIPA.
Certain rights described elsewhere in this Privacy Policy, including data portability or restriction of processing, may not be available under PIPA and will apply only to the extent required by applicable law.
 
E.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Privacy Commissioner for Bermuda or any other competent authority available under applicable Bermuda law.

عرض المزيد
icon

HashKey Global Team

Notice of Amendment to Investor Business Terms – Addition of Dormant Account Clause
Dear Valued Clients,
 
This notice is to inform you of an amendment to the Investor Business Terms (the “Terms”) between HashKey Bermuda Limited (“we” or “HBML”) and you. The amendment introduces a new clause regarding the management of dormant accounts.
 
Key Amendment Details
Clause 43.4 is updated to include a new subclause (a) as follows:
43.4 In addition to the above, HBML may suspend, restrict, or terminate the Account (and any accounts beneficially owned by related entities or affiliates of the Client), freeze, or lock the funds in all such Accounts, and suspend the Client's access to the HashKey Exchange where:
(a) the Client’s Account has been classified as a dormant account as reasonably determined by HBML;
(b) the Client acts in a manner that is abusive of the Account as reasonably determined by HBML;
(c) HBML decides not to provide any services in relation to the Account;
(d) where HBML detects unusual activity or suspects that the Account is being used to engage in illegal activities;
(e) if the Client fails to pay the fees and charges included or the Client fails to pay any amount owing to HBML or its Affiliates;
(f) the Account is subject to a government proceeding, criminal investigation, or other pending litigation;
(g) HBML is required to do so by a court order or command by a regulatory/government authority; or
(h) any other circumstance which requires HBML to do so.
 
The Terms incorporating this amendment will be available at: https://help.hashkey.com/hc/en-us/articles/13000983371036-Investor-Business-Terms
 
Effective Date
This amendment takes effect immediately upon the publication of this Amendment Notice.
 
Opt-Out Option
Clients who object to this amendment may exercise an opt-out right by terminating their Account under the Terms. To do so, you must submit written objections to HBML via email at support@global-cs.hashkey.com within fourteen (14) business days after the publication of this Amendment Notice on our Website. Failure to submit written objections within the specified period will result in your deemed acceptance of the amendment.
 
Continuity of Existing Terms
All other terms and conditions of the Terms remain unchanged and continue to be fully binding on you and HBML, except as expressly modified by this notice.
 
Should you have any questions about this amendment, please contact our CS team at support@global-cs.hashkey.com.
 
Thank you for your continued trust and cooperation.
 
Sincerely,
HashKey Global
عرض المزيد
icon

HashKey Global Team

Third Party Data Consent

By filling in/using a referral code or otherwise signing up to HashKey Global through a referred person, 
you agree and consent that your transaction data and other client-identifiable data may be shared to 
your referrer for purposes of referral rewards verification. You may withdraw this consent at any time 
and we will promptly cease to share the data for the aforementioned purpose.

عرض المزيد
icon

HashKey Global Team

Hashkey Global Complaints Handling Procedure

Customers may file a complaint if they are not satisfied with the services/ products provided or failed to be provided by HashKey Global (the “Company”). Once the Company has received customer complaint, the Company will deal with the matter as soon as practicable.

 

If you have a complaint with HashKey Global, you agree to first contact our customer support team where available to attempt to resolve such complaint. If we cannot resolve the complaint through our customer support team where available, you agree to use the complaints process set out in this document.

 

How can a complaint be made?

Customers can file customer complaint to the Company by email (global-complaints-hbel@hashkey.com), setting out the complaint in full details including but not limited to circumstances of the alleged incident.

 

What do customers need to provide when a complaint is lodged?

 

When a customer lodges a complaint, the Company requires certain information to verify the customer's membership. To help us resolve your complaint as quickly as possible, please provide the following details:

· Customer’s full name, address and other relevant personal details such as account;

· Number or account details to the extent that is necessary;

· A clear and honest outline of customer’s complaint;

· Copies of any supporting documents concerning the customer’s complaint; and

· Details of what customer would like the Company to do to rectify the situation.

 

Any personal information collected shall be subject to the applicable Privacy Policy.

 

How will a complaint be dealt with?

 

A complaint will be dealt with by (a) an individual not directly concerned with the subject of the complaint or (b) a compliance officer. If the Company can resolve the complaint within one (1) week following the day it was received, the Company will send the complainant the investigation result together with an explanation of the Company’s decision. Where the complaint is not genuine or does not include necessary information, no investigation will be carried out and customer will be informed accordingly, if applicable.

 

If further investigation is required, the Company will send the complainant an acknowledgement of receipt of their complaint within one (1) week following the day it was received. The Company will aim to provide the complainant with a written reply within four (4) weeks from the date the complaint is received. A final response will be issued within two (2) months from the date the complaint is received. The aforesaid timeline is an indicative only and not a commitment, as the processing of a complaint may be subject to various factors, such as the complexity of the complaint and any subsequent communications with the complainant for the purpose of seeking further information or clarification. When an investigation is taking longer than two (2) months to complete, an interim report will be issued depending on individual circumstances and the complexity of the case.

 

If customers are not satisfied with the Company’s response?

 

If customers are not satisfied with the decision, customers may request the Company to review the decision by providing new material information or evidence or refer the matter to other relevant regulators or relevant authorities.

 

For complaints or disputes that cannot be resolved via the complaint process set out above, the dispute resolution process as set out in the Investor Business Terms at Section 64 shall apply.

عرض المزيد
icon

HashKey Global Team

API User Terms
 

(Last update:   18/7/2024)

THESE TERMS, TOGETHER WITH THE INVESTOR BUSINESS TERMS, RELATED ACCOUNT OPENING DOCUMENTS, THE EXCHANGE RULES, ANY OTHER RELEVANT AGREEMENTS INTO WHICH THE CLIENT AND HBML HAVE ENTERED, CONSTITUTE THE ENTIRE AGREEMENT AND CONTAINS IMPORTANT TERMS AND CONDITIONS APPLICABLE TO THE ACCOUNT.

HBML MAY IN ITS ABSOLUTE DISCRETION DISCLOSE TO THE CLIENT THE RISKS OF THE CLIENT’S USE OF THE SERVICES FROM TIME TO TIME. THESE TERMS DO NOT FULLY DISCLOSE THE RISKS OR MATERIAL ASPECTS OF CONDUCTING TRANSACTIONS OR USING THE SERVICES. THE CLIENT SHOULD NOT CONSTRUE THESE TERMS AS LEGAL, TAX OR FINANCIAL ADVICE. HBML IS NOT ACTING AS THE CLIENT’S FINANCIAL ADVISOR AND THE CLIENT MUST NOT REGARD HBML AS ACTING IN THAT CAPACITY. THE CLIENT SHOULD CONSULT ITS OWN INDEPENDENT PROFESSIONAL ADVISORS BEFORE ENTERING INTO ANY TRANSACTION AND ONLY USE THE SERVICES IF THE CLIENT HAS FULLY UNDERSTOOD THE NATURE, THE CONTRACTUAL RELATIONSHIP INTO WHICH HE IS ENTERING, ALL RELEVANT TERMS AND CONDITIONS AND THE NATURE AND EXTENT OF THE CLIENT’S EXPOSURE TO LOSS. THE CLIENT HAS BEEN RECOMMENDED TO READ THESE TERMS CAREFULLY AND RETAIN THESE FOR THE CLIENT’S RECORDS.

 

To :

HashKey Bermuda Limited (also known as HashKey Global)

c/o Carey Olsen Services Bermuda Limited, Rosebank Centre,

5th Floor, 11 Bermudiana Road, Pembroke, HM 08, Bermuda

(“HBML” or the “Company”)

 

The Client agrees to be bound by the following terms and conditions which will apply to any use of API related services which HBML may in its absolute discretion provide to the Client from time to time.

 

1. Risk Disclosures

This clause provides you with basic facts about trading through HashKey API (as defined hereunder). Trading through Hashkey API increases the risk posed to your account security and may result in the compromise of your account credentials and the loss of funds that you have deposited into your Account. It is important that you fully understand the risks involved in using HashKey API.

Using HashKey API will allow you to use, access, call, command, query or request the API to take certain actions in relation to your Account for and on your behalf.

Prior to using HashKey API, you must verify your identity through an API Key (as defined hereunder). You will, therefore, be required to create an API Key on our site. The API Key is a representation, verification, and authentication of your identity to us and is comprised of a public and a private key pair.

An API client that uses your API Key can operate the API to give user instructions. When you do so, you are authorizing that API client to send us user instructions on your behalf. Thus, when using an API client, you should always ensure that the security of the said client or device from which you access such client, is sufficiently and adequately secure from compromise. 

Certain external service providers may require you to give them your API Key to support convenience services. Giving away your API Key is akin to giving away your login credentials. Giving away your API Key to a third party also means the third-party can and will have access to all your Account details, data, and authority to make and give instructions to our API on your behalf. You should exercise extreme caution in verifying the credibility and reliability of third parties that request for your API Key.

APIs are subject to certain limitations such as limits for pulling or pushing data. API functions are also limited by the API commands that are available. APIs may also be victim of poor computer engineering and as a result suffer erroneous application or result in compromise.

You should understand and study the HashKey Global Exchange API Documentation (“API Documentation”) that is updated on our website from time to time with the prevailing limitations. These limitations, updates on bugs, addition, amendment, or removal of commands will affect your existing API client setup. Such changes may altogether affect (if on-going) the functioning of HashKey API and accordingly our services to you.

We may at times make amendments to HashKey API without prior notice to you or without updating the API Documentation. This may impact your use of HashKey API and you therefore understand and accept the risks set out in the Risk Disclosures herein and accept that it is your sole responsibility to keep yourself consistently updated on changes to the API Documentation and or these Terms (as defined hereunder).

 

2. Definitions and Interpretation

2.1 Defined terms shall have the same meaning as ascribed to it in the Investor Business Terms between the Client and the Company, otherwise in these API User Terms (“these Terms”), the following words and expression shall have the following meanings: -

“Agreement” means these Terms, being the written agreement between the Client and HBML regarding the access and operation of HashKey API as amended from time to time;

"API" means application programming interface;

“API Key” means a key or such license provided by HBML to access HashKey API (as defined below).

 

2.2 In the event of, and only to the extent of, any conflict or inconsistency among or between any provisions of these Terms and the Investor Business Terms, the Investor Business Terms shall prevail in so far as is necessary to resolve the conflict or inconsistency.

 

3. Services and Restrictions

3.1 HashKey API. Subject to the terms and conditions listed in these Terms, HBML hereby grants you a limited, non-exclusive, non-sublicensable, non-transferable, non-assignable and revocable license, to electronically access and use HashKey API solely for the following purposes:

  • Access information provided by HBML via the API (“HashKey API”) as permitted by HBML;
  • Retrieve market data of HBML;
  • Initiating and cancelling trading, withdrawal and transfer transactions on HBML; and
  • Retrieve asset balance.

HBML will provide the Client with an API Key to access and use HashKey API. This API Key, being the exclusive property of HBML, may be terminated or revoked at HBML's sole discretion if the Client's use of HashKey API is deemed to breach this Agreement. HBML reserves the right to update HashKey API from time to time, and such updates may necessitate Client action, including but not limited to, acceptance of any additional terms. In the event of such updates, the Client does not have the right to terminate this Agreement but is responsible for ensuring their use of HashKey API complies with the latest version and these Terms. Furthermore, HBML reserves the right to terminate this Agreement immediately at its sole discretion, particularly in instances where the Client breaches the terms of this Agreement. Upon such termination, the Client shall immediately stop using HashKey API. HBML may independently communicate with any relevant third-party, including third-parties to whom the Client has communicated its API Key, to provide notice of the termination of the Client’s right to use HashKey API.

 

3.2 Restrictions

(a) You shall not use HashKey API in any manner that is not authorized by this Agreement expressively.

(b) You shall not lease, sell, sublicense, assign, or otherwise transfer your rights to access Hashkey API to a third party.

(c) You shall not use Hashkey API for purposes of monitoring the availability of any HashKey Global products for competitive purposes.

(d) You shall not use Hashkey API for collecting, caching, aggregating, or storing data accessed via HashKey API other than for purposes allowed under this Agreement. You may not share such data or content with third parties in any manner without HBML’s prior written consent.

(e) You shall not use Hashkey API for any application that constitutes or uses in conjunction with spyware, adware, or any other malicious programs or codes.

(f) You shall not use Hashkey API to encourage, promote, or participate in illegal activity, violating intellectual property rights or privacy rights or Terms listed in this Agreement.

(g) You shall not use Hashkey API in a way that will exceed a reasonable usage, excessive request volume, or otherwise impacts the stability of HashKey Global's servers.

(h) You shall not modify or alter Hashkey API.

(i) You shall not attempt to circumvent any limitations on API requests HBML put in place.

 

3.3 Service Availability. HBML will use reasonable efforts to ensure that Hashkey API is available for use by the Client. However, HBML does not guarantee uninterrupted or error-free operation of Hashkey API, and shall not be liable for any loss or damages resulting from Hashkey API being temporarily unavailable due to technical issues beyond our control.

 

3.4 Data Protection and Privacy. The Client acknowledges that they have read and understood HBML's Privacy Policy as published on its website, which sets out how HBML collects, stores, uses, and protects the Client's personal data. By using Hashkey API, the Client consents to the collection and use of their data in accordance with HBML's Privacy Policy.

 

4. Content and IP Ownership

Except as otherwise provided in this Agreement, HBML retains all rights, title and interest in all intellectual property rights and improvements thereto associated with Hashkey API. You shall not take any action inconsistent with HBML’s ownership of Hashkey API and its content. If Client violates any portion of this Agreement, the license granted hereunder may be terminated at any time.

 

5. Security and Stability

You acknowledge that it is in the best interests of both parties that HashKey Global maintains a stable and secure environment. Thus, HBML reserves the right to change the method of access to Hashkey API. You also acknowledge and agree that, HBML may, in its sole discretion, temporarily suspend your access to Hashkey API (for example, by disabling your API Key) under this Agreement to minimize security threats and protect the operational stability and security of the HashKey Global system.

 

6. Indemnity and Exclusion of Liability

6.1 The Client hereby agrees to fully indemnify HBML, HBML’s directors, officers, employees, HBML’s Associated Entities and nominees and HBML’s Affiliates and keep all such persons indemnified against all claims, actions, liabilities, proceedings against any of such persons and bear any losses, costs, charges or expenses (including legal fees) (together “Losses”) which they may suffer in connection with a breach of this Agreement by Client save to the extent that such Losses arise directly or predominantly as a result of HBML’s negligence, fraud or willful default.

 

6.2 To the maximum extent permitted under applicable laws, HBML shall not be liable for any Losses suffered by the Client as a result of or in connection with the Client’s utilizing any of the services or in connection with these Terms other than Losses arising directly as a result of any gross negligence, fraud, or willful default on HBML’s part, or that of HBML’s Associated Entities, nominees or affiliates. HBML shall in no event be liable for any loss of profit, indirect, special or consequential damages of any kind or the default of HBML’s directors, officers, employees, Associated Entities, nominees or Affiliates or any person, firm or company through or with whom transactions are effected for the Account.

 

7. Representations, Warranties and Undertaking

7.1 Representations

The Client hereby warrants, represents and undertakes to HBML that:

(a) The Client is entering into these Terms as principal and is not trading on behalf of any other person unless HBML is notified otherwise in writing, in which case, the Client warrant that the Client is expressly authorized by the Client’s principal to effect all transactions pursuant to these Terms and the Client’s principal will duly perform all the obligations and liabilities arising out of these Terms, failing which the Client will be liable to HBML as if the Client were the principal in respect of such obligations and liabilities;

(b) (If being a natural person) The Client is of legal age to form a binding contract; or (If being a body corporate) the Client is validly incorporated and existing under the laws of its place of incorporation and has full power and capacity to enter into and perform the Client’s obligations hereunder;

(c) (If being a body corporate) The Client’s entry into of these Terms has been duly authorized by the Client’s governing body and does not breach the Client’s Articles of Association (and the Memorandum of Association if the Client has the same) or other constitutional documents (as applicable);

(d) The information provided by the Client to HBML through HashKey Global or otherwise from time to time is true, accurate and complete in all respects;

(e) The Client will enter into Digital Assets and/or Securities transactions solely in reliance upon the Client’s own judgment and investigations on the Digital Assets and/or Securities;

(f) These Terms constitutes a valid and legally binding agreement on the Client enforceable in accordance with its terms;

(g) These Terms and performance of the Client’s obligations contained herein do not and will not:

(i) contravene any existing applicable law, statute, ordinance, rule or regulation or any judgement, decree or permit to which The Client is subject; or

(ii) conflict with or result in any breach of the terms of or constitute any default under any agreement or other instrument to which the Client is a party or subject or by which any of the Client’s property is bound;

(h) Unless otherwise agreed by HBML, the Client is and will remain to be the beneficial owner of the Digital Assets and/or Securities in the Account free from any lien, charge, equity or encumbrance save as created by these Terms and will not charge, pledge or allow to subsist any charge or pledge over the Digital Assets and/or Securities or monies in the Account or grant or purport to grant an option over any Securities or monies in the Account without HBML’s prior written consent;

(i) The Client is the person ultimately responsible for originating the Instruction in relation to each transaction in the Account and shall stand to gain the commercial or economic benefit of such transactions and/or bear their commercial or economic risk (except where such other person or entity has been disclosed to HBML in writing and the arrangement has been agreed by HBML);

(j) The Client is solely and wholly responsible for the security of the Client’s Account and have not revealed any login details (including email address and/or passwords) of the Client’s Account to any unauthorized person. All actions being conducted through the Account are duly authorized by the Client.

 

7.2 The Client further undertakes that:

(a) The Client agrees that it shall use HashKey API at its own risks and is solely responsible for ensuring the security and integrity of its own devices, systems and applications;

(b) The Client’s right to use HashKey API may subject to additional terms, including limitations on use, found on the individual API Documentations of each API which we may amend from time to time without prior notice to the Client;

(c) The Client’s API Key is our sole means of verifying its access to HashKey API. The Client has read the Risk Disclosures above and understood the risks in relation to sharing, giving away or losing its API Key to any third-party.

(d) The Client is solely responsible for the security of its API Key and any compromise therefrom. HBML shall not be liable for executing any instructions or commands arising from the use of the Client’s API Key by any third-party.

(e) The Client agrees to immediately notify us upon becoming aware of any unauthorized use of HashKey API through its API Key. 

(f) The Client agrees that we may monitor its use of HashKey API to improve the service, track usage, to ensure compliance with these terms, or for security purposes.

(g) The Client agrees that HBML may audit its use of HashKey API or its API clients to the extent that we reasonably believe to verify compliance with this Agreement and identify security issues that may affect our service or our users. The Client agrees to cooperate with such audits and provide evidence that its use of HashKey API or its API clients complies with this Agreement. We reserve the right to immediately terminate the Client’s access to HashKey API should the Client refuse to cooperate with such audits or if this audit reveals that HashKey API was used in any way that contravene the terms of this Agreement or that we deem, in our sole discretion, constitute a security threat to our service or our users.

(h) The Client shall not misrepresent or mask its API client's identity when using HashKey API. The Client agrees that if he misrepresents or masks its API client's identity, HBML reserves the right to limit and restrict its use of HashKey API without prior notice.

(i) The Client agrees and shall cause its API client to use HashKey API in accordance with our published technical and other specifications, including all security requirements and procedures found on our website.

 

7.3 Repeating Nature

The representations, warrants and undertakings under this Clause shall be deemed to be repeated immediately before each Instruction is given or executed.

 

8. General Provisions

8.1 Invalidity

If anyone or more of the provisions contained in these Terms shall be invalid, unlawful or unenforceable in any respect under any applicable law, the validity, legality and enforceability of the remaining provisions contained herein shall not in any way be affected or impaired.

 

8.2 Assignment

(a) This agreement shall benefit and be binding on HBML and the Client, their respective successors and subject to this Clause 8.3, any permitted assignee or transferee of some or all of HBML’s rights or obligations under these Terms.

(b) The Client may not assign or transfer all or any of the Client’s rights or obligations under these Terms.

(c) HBML may assign or transfer all or part of HBML’s rights, benefits and obligations hereunder to such person(s) and disclose to a potential transferee or any other person proposing to enter into contractual arrangements with HBML in relation to these Terms such information about the Client as HBML may at HBML’s absolute discretion think fit.

 

8.3 Non-Waiver

Failure or delay in exercising any rights, power or privilege by HBML in respect of these Terms shall not operate as a waiver, nor shall a single or partial exercise, enforcement or waiver of any such rights, power or privilege preclude HBML from further exercise, enforcement, or the exercise or enforcement of any other right, power of privilege hereunder.

 

8.4 Joint and Several Liabilities

If the Client consists of more than one person, then the liabilities of each such person hereunder shall be joint and several. Any notice, payment or delivery by HBML to either or any one of the joint account holders shall be a full and sufficient discharge of HBML’s obligations to notify, pay or deliver under these Terms.

 

8.5 Material Change

Either party will notify the other in the event of any material change to the information contained in these Terms or provided to the other party pursuant to these Terms.

 

8.6 Disclaimer of Liabilities

To the maximum extent permitted under applicable laws, neither HBML, HBML’s Associated Entities or nominees nor HBML’s Affiliates shall be liable for any delay or failure to perform obligations and any losses, damages or costs resulting therefrom so long as they have acted in good faith. HBML will not be liable for any loss or damage that is caused by any malfunction of third party API client or other related interactions with any third party software with HashKey API. Moreover, HBML’s Associated Entities and nominee and HBML’s Affiliates shall not be held responsible for any consequences resulting whether directly or indirectly from any events not within their control including without limitation government restrictions, imposition of emergency procedures, exchange ruling, third party’s conduct, suspension of trading, war, strike, market conditions, civil disorder, acts or threatened acts of terrorism, natural disasters, or any other circumstances beyond their control whatsoever.

 

9. Language

These Terms are written in an English version and a Chinese version. In the event of any conflict between the two versions, the English version shall take precedence.

 

10. Amendment

HBML shall have absolute rights to amend, delete or substitute any of the terms herein or add new terms to these Terms. The Client should visit the website from time to time for obtaining the latest Agreement and read the terms thereof. Such amendment, deletion, substitution or addition shall be deemed as effective and incorporated herein (and shall form part of these Terms) on the date of publication of the revised Agreement. The Client may raise written objection within fourteen (14) Business Days after the publication of the revised Agreement at the website, failing which it shall be deemed an acceptance of such amendment, deletion, substitution or addition.

 

If the Client has any queries relating to these Terms, please address them by email to global-api@hashkey.com


 

عرض المزيد
icon

HashKey Global Team

HashKey Global News Release Standard Terms and Disclaimers
Unless otherwise specified, the following should be read in conjunction with any and all news releases by HashKey Global.
 
This material is for general information purposes only. It does not constitute, nor should be interpreted as, any form of solicitation, offer or recommendation of any product or service. It does not constitute investment, tax or legal advice. In no event should any news release be considered as recommendation of a particular type of digital asset.
 
This material may include market data prepared by HashKey Global or data from third party sources. While HashKey Global makes reasonable efforts to ensure the reliability of such third-party information, such information may have not been verified. Graphics are for reference only. We make no representation or warranty, express or implied, to the timeliness, accuracy or completeness of the information in this material. Information may become outdated, including as a result of new plans, regulations or changes in the market. In making investment decisions, investors should not solely rely on the information contained in this material. The risk of loss in trading digital assets can be substantial and is not suitable for all investors.
 
Any forward-looking statements in this material is subject to several conditions, uncertainties and assumptions. We undertake no obligation to update or revise any forward-looking statements.

All trademarks, logos, and brand names used in this material are the property of their respective owners.
Unless the context otherwise requires, they are used for illustrative purposes only and do not imply any
endorsement, authorization, partnership, sponsorship, or affiliation with us.
 
The English version shall prevail if there is any inconsistency between the English and Chinese versions.
 
Where participation in campaigns or events of HashKey Global is involved
 
Participation in any campaign or event of HashKey Global does not guarantee eligibility, acceptance, or receipt of any rewards, benefits, or incentives. No rewards, benefits or incentives may be exchange for cash or other products. HashKey Global may impose certain criteria, requirements, or limitations for participation, and it reserves the right to deny or disqualify individuals or entities from participating in the campaign or event at any time. HashKey Global reserves the right to make changes, modify, or cancel the campaign or event or the eligibility of any participant at any time at its sole discretion, including due to internal control, system issues or other circumstances, without any prior notice or liability.
 
Participation in any campaign or event of HashKey Global may involve the acquisition of digital assets. Please be aware that digital assets, including cryptocurrencies, are highly volatile and subject to market risks. The value of digital assets can fluctuate significantly, and there is no guarantee of profit or preservation of capital. You should carefully consider your own risk tolerance and financial situation before participating in the campaign or event.
 
Participants are responsible for complying with all applicable laws, regulations, and guidelines related to the acquisition, possession, use, or trading of digital assets. It is your responsibility to ensure that your participation in any campaign or event of HashKey Global is lawful in your jurisdiction and that you meet any required legal and regulatory obligations. Besides these standard terms and disclaimers, campaign or event is subject to specific terms and conditions applicable to it. A person who is not a party to these terms and conditions has no rights to enforce any of their terms.
 
To the fullest extent permitted by law, HashKey Global, its affiliates, partners, and employees shall not be held liable for any direct, indirect, incidental, consequential, or special damages arising from participant’s participation in any campaign or event of HashKey Global, including but not limited to any loss of funds, profits, business, potential profits, data, or reputation.
 
HashKey Global reserves the ultimate discretion regarding the rules and rewards of any campaign or event of HashKey Global. HashKey Global’s decision is final.
 
For enquiries, please contact HashKey Global media team at luna.wang@hashkey.com or HashKey Global customer service at support@global-cs.hashkey.com.
 
HashKey Global
 
HashKey Global is a digital asset trading platform operated by HashKey Bermuda Limited under a Type F license granted by the Bermuda Monetary Authority. This information does not constitute an offer, solicitation, or recommendation for any investment product. Investing and trading virtual assets involve risks. HashKey Global does not service users from Hong Kong, United States, Mainland China and certain other jurisdictions in compliance with laws and regulations. Certain services, features, and campaigns may not be available in your jurisdiction.
 
Risk Warning About HSK: Please be aware that HSK is now listed and available for trading on HashKey Global and several other exchanges. However, it may still be subject to various trading restrictions in accordance with applicable laws and regulations. These restrictions may include limiting HSK trading solely to eligible professional investors in select locations and subject to regulatory approval. There is also no guarantee of the continued listing status of HSK on any exchange. The trading of HSK may be suspended and HSK may be delisted due to reasons beyond HashKey Global and its affiliates’ control. The value of HSK remains subject to substantial risk and may diminish or fluctuate significantly in response to various market conditions and other factors beyond HashKey Global and its affiliates’ control. HashKey Global and its affiliates make no warranties, express or implied, in relation to HSK or any rewards and disclaim any liability relating thereto.
عرض المزيد
icon

HashKey Global Team

HashKey Global Token Management Rules
Preamble
Objectives. The HashKey Global Token Management Rules (these “Rules”) are developed in order to foster the sustainable
development of the HashKey Global platform, safeguard the rights and interests of trading participants, and offer guidance
on the rights and obligations of Project Teams.
Definitions. Unless otherwise expressly provided, the following terms in these Rules shall have the meanings as specified:
(1) “Exchange Rules”: shall refer to the HashKey Global - Exchange Rules and any rules (including but not limited to these Rules)
in relation to any token offerings or trading which HashKey Global may implement and publicize on its website from time to time.
(2) “HashKey Global”: shall refer to the virtual asset trading platform branded “HashKey Global” which is operated by HashKey Bermuda Limited.
(3) “Project”: shall refer to the underlying project, assets, or business that the Token is designed to represent or support .
(4) “Project Team”: shall refer to any entity responsible for the issuance, development or operation of the Token Project, i.e., the
legal entity, team, natural person or beneficial owner of the Token listed or to be listed on HashKey Global, or the representative
willing to take responsibility for a community-based decentralized Token without a recognized Project Team.
(5) “Token”: shall refer to the cryptographic digital proof of interest traded on HashKey Global, including digital assets that represent
ownership, utility, or other rights within a blockchain or decentralized network.
(6) “Monitoring Tag”: Tokens with Monitoring Tags exhibit notably higher volatility and risks compared to other listed tokens.
These tokens are closely monitored by the platform. These tokens are at risk of no longer meeting our listing criteria and being
suspended from trading or delisted from the platform.
Chapter I General Provisions
Article 1 General Requirements. To allow HashKey Global to perform due diligence on the Project and the Token, set out below is a non-exhaustive list of general requirements and information which a Project Team shall provide to HashKey Global before its Token may be approved to be listed on HashKey Global for trading:
(1) background of management, development team, and any of its known key members;
(2) regulatory status of the Token in major jurisdictions;
(3) supply, demand, maturity and liquidity of the Token;
(4) technical aspects of the Token;
(5) development of the Token;
(6) market and governance risks of the Token;
(7) legal risks associated with the Token;
(8) utility offered, novel use cases facilitated, technical structural or cryptoeconomic innovation, or administrative control exhibited by the Token and supporting information on viability of the Project not dependent on continuous inflow into the Token;
(9) enforceability of any rights extrinsic to the Token (for example, rights to any underlying assets) and the potential impact of the Token’s trading activity on the underlying markets; and
(10) assessment on the money laundering and terrorist financing risks associated with the Token.
The Project Team shall comply with all Exchange Rules, policies and procedures that apply to the Project, the Project Team and the Token in effect or as amended from time to time, and any conditions attached to a listing which HashKey Global considers appropriate at its sole discretion.
HashKey Global may attach to a listing any conditions that it considers appropriate, and vary or revoke the condition(s) when deemed necessary upon listing or at any time the Token is listed on HashKey Global.
 
Article 2 Non-security. The Token shall not be a security token and will not become a security token unless with the prior written consent of HashKey Global. The Project Team is responsible for maintaining the non-security status of the Token and will not make any changes that could cause the Token to be classified as a security. HashKey Global reserves the right to delist the Token upon any change in the non-security status of the Token at its sole discretion.
Chapter II Information Disclosure Article 3 Information Disclosure Obligations.
The Project Team shall disclose all information that may have a material impact on the Token, market activity
of the Token or the Project Team in a timely and transparent manner, and ensure that all the information
disclosed are true, accurate and complete, not deceptive or misleading, and does not omit any material facts or considerations.
Article 4 Forms of Information Disclosure.
From the date of publication of these Rules, the Project Team shall make regular and ad-hoc disclosures available
promptly on its official website. The information disclosed shall include, but not be limited to, the progress of code
updates, market activities, institutional investment, community development, regulatory action and any other important
aspects of information.
Article 5 Ad-Hoc Disclosures.
An ad-hoc disclosure refers to the disclosure that shall be made by a Project Team
in addition to the regular disclosure in the event of any special incidents occurring. All such incidents shall be disclosed
and HashKey Global shall be notified in writing within twenty-four (24) hours of such occurrence. The special incidents
herein provided include, but are not limited to, change or loss of contact of core team members, major technical incidents,
changes in the direction of product and technical development, major legal risks involving the core team, significant
negative news or public opinions, and any other incidents that may have a significant impact on or could reasonably
be expected to cause the fluctuations on the price of the Token (including the unlocking and the buyback of a locked Token).
The content of an ad-hoc disclosure shall include, but not be limited to, the reasons for the occurrence, the process,
the basic facts, and the results of the incident.
Article 6 Exceptions to Information Disclosure.
If the information to be disclosed by the Project Team involves any state secrets or if the disclosure may have conflict with
public interests, such information may be withheld with HashKey Global's consent.
Chapter III Inquiry and Review Article 7 Inquiries and Responses.
HashKey Global shall have the right to inquire to the Project Team about the Token and/or the Project from time to time.
The Project Team shall actively cooperate with and respond to the inquiries within twenty-four (24) hours.
Article 8 Forms of Inquires.
HashKey Global may make an inquiry to a Project Team by contacting: (1) the official email address provided by the Project Team;
(2) the phone number provided by the Project Team; or (3) the instant messaging application accounts provided by the Project
Team, such as via Telegram.
Article 9 Content of Inquires.
The content of an inquiry may include, but not be limited to, the fulfillment of the commitments made in the whitepaper
or on the official website, the employment and Token holdings of core team members, the progress of the product and
technical development, and other factors that may have a significant impact on or could reasonably be expected to cause
the fluctuations on the price of the Token (including the unlocking and the buyback of a locked Token).
Article 10 Results of Inquiries.
HashKey Global may at its sole discretion, determine whether a Project Team has violated these Rules based on the factors
such as whether the Project Team has cooperated with the inquiries, the level of cooperation, and the content of the responses.
HashKey Global may take relevant actions to deal with the violations in accordance with the procedures set forth in Chapter IV.
The actions may be notified to the Project Team or the users through the means specified in Article 8 or through an announcement.
Article 11 Routine Reviews.
HashKey Global shall have the right to conduct regular or ad-hoc reviews of the Project and the Project Team, for the following
circumstances: (1) significant aspects of whitepaper commitments; (2) security reviews of the code; (3) other factors that may
have impact on or could reasonably be expected to cause the fluctuations on the price of the Token, such as changes of positions
held by the Project Team or other major Token holders, and the fulfillment of the commitment to lock the Token; (4) changes
in core team members; or (5) any other aspects considered necessary to be reviewed at HashKey Global’s discretion, including
but not limited for purposes of risk management, corporate governance, internal controls and compliance with laws and regulations
. Article 12 Special Reviews.
HashKey Global may initiate a special review if: (1) the Project Team is reported by the users or is revealed by the news media to
be involved in the circumstances specified in Article 11, and the Project Team has not made any response to such report or revelation,
or the response is not sufficient to disprove such involvement of the circumstances specified thereof; (2) significant risk is identified
in a routine review, or (3) any other circumstances that HashKey Global may deem necessary to initiate a special review at its discretion,
including but not limited for purposes of risk management, corporate governance, internal controls and compliance with laws and regulations.
Article 13 On-Site Investigations.
HashKey Global may visit and supervise the Project Team and conduct on-site investigations on a regular or ad-hoc basis according
to actual needs (consent from the Project Team not to be unreasonably withheld). The Project Team shall actively cooperate with
HashKey Global’s on-site investigation. The content of the investigation may include, but not be limited to, those specified in Article 9.
If the Project Team refuses to, intentionally obstructs or otherwise fails to cooperate with HashKey Global's investigation, HashKey Global
may decide to take relevant actions against the Project team in accordance with these Rules at its sole discretion, including but not limited
to the delisting of the Token from HashKey Global.
Article 14 Cooperative Obligations of the Project Team.
The Project Team is obliged to actively cooperate with HashKey Global for routine and special reviews. The Project Team shall also actively
respond to or rectify the related issues reported from the users, the inquiries raised from the news media, and the risk notices addressed
from relevant regulatory authorities. HashKey Global may take relevant actions against the Project Team in accordance with these Rules in
the event that the Project Team fails to fulfill the cooperative obligations herein. Such actions may be notified through the means specified
in Article 8 or through an announcement.
Chapter IV Handling of Violations Article 15 Implementations of Monitoring Tag Warnings.
HashKey Global shall have the right to, at its sole discretion, implement a Monitoring Tag warning on a Token according to the risk associated
and severity of a violation of the Exchange Rules and place a “Monitoring Tag” on the relevant trading pairs to alert the users of the risk of
trading such Token.
15.1 Trigger Events of Monitoring Tag Warnings.
The Monitoring Tag warnings will be triggered if any of the following events are identified, present or occur from the Project, the Project
Team or the Token (the “Trigger Events”):
(1) the Project Team fails to update or disclose information about the Project or the Token, including but not limited to, the Project Team’s
official website, whitepaper, and ad-hoc disclosure incidents set forth in Article 5; (2) the average daily transaction volume of any trading
pairs of the Token is less than USDT30,000 or other equivalent tokens for more than 30 consecutive days; (3) the Project has poor liquidity,
i.e., the spread exceeds 2% for three consecutive days, fewer than 15 price tiers of orders are placed on either side of the market, the top 10%
bid/ask market depth is worth less than USDT10,000 or other equivalent Tokens, or the price of the Project has been found to be manipulated
(the price deviates from the market price by 10% or more); (4) any considerations as HashKey Global may, at its discretion, deem it necessary
to place a Monitoring Tag upon a comprehensive assessment by means of inquiry, routine review, special review, on-site investigation, etc.;
or (5) any other circumstance arises that can be assessed as a serious violation at HashKey Global’s discretion, including but not limited for
purposes of risk management, corporate governance, internal controls and compliance with laws and regulations.
15.2 Lifting of Monitoring Tag Warnings.
HashKey Global shall have the right to lift the Monitoring Tag warning on a case-by-case basis if such Project Team have taken appropriate
rectifications and the Project, the Project Team or the Token have been reviewed as no longer meeting any of the Trigger Events.,
Article 16 Trading Suspension, and Token Delisting.
HashKey Global shall have the right to, at its sole discretion, suspend the trading or delist the Token, according to the severity of the following
circumstances:
(1) the Monitoring Tag warning is not lifted within thirty (30) calendar days from the date of its implementation;
(2) implementation of new regulatory standards and other compliance issues that, as determined by HashKey Global, requires the suspension of trading or delisting of the Token;
(3) the Project, the Project Team or the Token posed significant regulatory risks, including but not limited to, that the Token constitutes a “security” in a jurisdiction and HashKey Global is unable to and/or unwilling to prevent its users from that jurisdiction from holding and/or trading the Token;
(4) blockchain or related technology becomes compromised or defective;
(5) the Project or the Token is no longer supported or maintained by the Project Team or others;
(6) complaints or material allegations by users or other third parties, which are related to significant issues such as gross negligence, wilful misconduct or fraud;
(7) the Project Team or any of its memebers conducts or is involved in any illegal activity(ies) within any jurisdiction(s), such as money laundering, fraud or pyramid selling;
(8) any threatened, pending or active legal proceeding or claim (whether civil, criminal, or administrative, formal or informal, or direct or indirect) against the Project Team;
(9) the Project Team is suspected of manipulating the market and the circumstances are serious;
(10) the Project Team is unreachable within a specified period indicated to it;
(11) any changes to Project Team members which HashKey Global considers to have material adverse impact on the Project or the Token;
(12) any core member of the Project Team has been found of significant fraud or deception, including but not limited to, misappropriation of the raised Tokens, unknown whereabouts of the Project development team, cease to support the Project technology, intentionally concealment of material facts of the Project, disclosure or creation of materially fraudulent, false or misleading information;
(13) the dissolution of the Project development team or resignation of core team members without the consent of the Project community, resulting in the inability to continue development;
(14) there is a lack of liquidity in the Token’s market over a time period to be determined as appropriate by HashKey Global;
(15) no order of the Token is recorded over a time period to be determined as appropriate by HashKey Global after initial listing;
(16) the Project Team changes supply of the Token without giving prior notice to HashKey Global;
(17) the Project Team unlocks the Tokens without fulfilling the commitment made in the whitepaper or in other forms;
(18) the Project Team conducts a hard fork, token migration, token split, token merge, and rebranding of the Token without giving prior notice to HashKey Global;
(19) the Project Team has caused significant losses to HashKey Global and/or users due to security issues in the main net or the contract, and the Project Team fails to reimburse HashKey Global for the losses and/or compensating its users for the losses that they suffer;
(20) other risks and hazards exist in the Project or the Token, such as hacking, coins stealing, concealment of additional issuance, and double spend attack;
(21) the average daily transaction volume of any trading pairs of the Token is less than USDT10,000 or other equivalent tokens for more than 30 consecutive days;
(22) there is no immediate action taken or solution given by the Project Team in the event of any crisis, as deemed by HashKey Global, that is causing detrimental impact to HashKey Global, the HashKey Group generally and/or any trading participant, including but not limited to, discovery of inaccurate information, technical issues on the Token, security breach, etc.;
(23) the Project Team conducts any activity(ies) that damages the reputation of HashKey Global or the HashKey Group generally, and adversely affecting any trading participant’s interest;
(24) the Project develops close association with prohibited categories of business;
(25) the Project Team has materially breached the Listing Agreement entered into between Hashkey Global and the Project Team;
(26) the Project Team has materially breached the Exchange Rules and the breach cannot be or has not been cured within fourteen (14) days;
(27) any such circumstances as agreed between HashKey Global and the Project Team, including but not limited to, any circumstances specified in a Listing Agreement; or
(28) other circumstance(s) that, at the sole discretion of HashKey Global, is/are sufficient for removal of the Token from HashKey Global, including any circumstances which causes the Token to be no longer eligible or appropriate to continue to be listed.
In the case of trading suspension, the trading and deposit of the Token shall be suspended, but the users will be able to continue to hold a position of the Token. The Project Team is obliged to address all violations and ensure compliance with the Exchange Rules to HashKey Global’s satisfaction before the suspension can be lifted. HashKey Global reserves the right to delist the Token, provided that the trading of the Token has been continuously suspended for a prolonged time, or if any violations have not been or cannot be remedied, as determined by HashKey Global.
Article 17 Liquidation and Termination of Trading.
The liquidation process shall be determined by HashKey
Global on a case-by-case basis. In the case of delisting, liquidation process shall commence on the date the
delisting decision is made. Upon completion of the liquidation process, trading of such liquidated Token will
cease and the Token will be officially delisted. The termination of trading will be notified to the Project Team or
the users through the means specified in Article 8 or through an announcement on HashKey Global.
 
Article 18 Liability.
The Project Team shall be liable for any losses caused to HashKey Global, the users or any
other third parties resulting from or by reason of any breach of these Rules.
Chapter V Supplementary Provisions
 
Article 19 Some Projects may have privileged roles that possess the authority to unilaterally perform administrative
actions, such as modifying network functionality or seizing user funds, which, if misused, can pose a threat to the
secure custody of customers' assets by HashKey Global. It is strongly recommended that Project Teams adhere to
the principle of "least privilege”, whereby privileged roles should have narrow scopes limited to essential functionalities.
Project Teams are encouraged to renounce unnecessary privileges and, if unavoidable, to establish comprehensive
policies and procedures for quorum-based key management and usage, particularly for actions affecting balances
of trading participants.
Article 20 In the event of any discrepancy between these Rules and any other rules or
announcements previously published by HashKey Global, these Rules shall prevail. In the event of any discrepancy
between the English language version of these Rules and any translation of these Rules in a foreign language, the
respective English version shall prevail.
Article 21 HashKey Global reserves the right to amend these Rules from time
to time and the right of final interpretation. Such amendments shall take immediate effective upon being published
on HashKey Global’s website. Project Teams and trading participants are responsible for referring to the latest Rules
as uploaded on HashKey Global’s website.
Article 22 Project Teams are forbidden from disclosing any information in relation to the listing until HashKey Global
(or its affiliates) issues our listing announcement.
 
Article 23 These Rules shall take effect from the date of publication.
Disclaimer: The analysis regarding the suitability of a Token for listing may change over time as digital assets, regulatory statements, and interpretations evolve. It is recommended that each Project Team consults with their own legal advisors to obtain legal guidance on these matters. HashKey Bermuda Limited and its affiliates, directors, officers, employees, agents, and attorneys do not provide legal advice or act as attorneys for any specific Project Team.
عرض المزيد
icon