Terms&Policies

banner banner

Privacy Policy

See all articles

HashKey Global Team

HashKey Global - Exchange Rules
 
 
 

HashKey Global - Exchange Rules

 
 
__________________________________________________________________________
HashKey Bermuda Limited (“HBML” or “we”) operates the HashKey Global. These HashKey Global - Exchange Rules (“Exchange Rules”) is an important document governing your use of HashKey Global. Please ensure you read it carefully and familiarise yourself with these Exchange Rules prior to and during your trading on the HashKey Global. These Exchange Rules are subject to change at our discretion and you are reminded to check the latest version on our website from time to time. You are also required to read our Privacy Policy, and Client Risk Disclosures Statement which impose additional requirements to these Exchange Rules. By depositing funds and/or trading on the HashKey Global you acknowledge that you have read, fully understood and accepted the terms in the aforesaid documents. For the avoidance of doubt, in the event of any inconsistency between those documents and these Exchange Rules, these Exchange Rules will prevail.
If you have any questions about these Exchange Rules, please contact us using the details below. In any event, we do not act as your advisors in any capacity and you should consult your independent professional advisors for any issues or questions you may have regarding entering into any contractual relationship with us.
 
____________________________________________________________________
 
 
 
 
 
 
 
 
 
 

Table of Contents

 
HashKey Global - Exchange Rules1
Part A – General6
Section 1 Interpretation6
1.1Definitions6
1.2Rules of Interpretation8
Section 2Introduction9
2.1HashKey Global9
2.2Token Admission and Review Committee11
Section 3About the Exchange Rules12
3.1Application12
3.2Status12
3.3Procedure where none laid down12
3.4General provisions12
Part B - Listing13
Section 4Listing Criteria13
4.1HBML Scope of Listing13
4.2General requirements13
4.3Additional requirements for Large-cap Digital Assets14
4.4Specific requirements for Security Tokens14
4.5Minimum requirements only14
Section 5Listing Procedure14
5.1Application procedure14
5.2Documents and information required14
5.3Interview and further information or document15
5.4Due diligence15
5.5Declarations and undertakings15
5.6Listing conditions15
5.7Listing fees and costs15
Section 6Withdrawal of listing application15
Section 7Listing Document16
7.1Information in Listing Document16
7.2Statements in Listing Document16
7.3Approval for dissemination17
7.4Amendment and variation of Listing Document17
7.5Distribution of Listing Document17
Part C – Continuing Obligations and Responsibilities of Issuers17
Section 8Notification requirement17
8.1Issuer’s obligation to notify17
8.2Disclosure to the market18
8.3HBML’s rights to request information18
Section 9 Payment of fees18
Section 10Financial information18
Section 11Maintenance of eligibility18
Section 12Self-reporting18
Part D – Removal of Digital Asset19
Section 13HBML’s power to remove a Digital Asset from HashKey Global19
13.1Relevant circumstances19
13.2Removal of Digital Asset from HashKey Global Warning20
Section 14Removal of Digital Asset from Platform request20
Section 15Removal of Digital Asset from HashKey Global Notification21
Section 16Withdrawal of Client Money and Digital Assets upon removal21
Section 17 Transfer of Listing21
Section 18Relisting21
Part E – Trading Participants21
Section 19Type of Trading Participants21
Section 20Eligibility22
20.1Individuals and institutions22
20.2Other criteria22
Section 21Application procedure22
Section 22Document and information required23
Section 23Declaration, undertakings and deposit requirement23
Section 24 HBML’s decision24
24.1Decision subject to receipt of all required information24
24.2Approval conditions24
Section 25Change of Professional Investor status after registration24
Part F – Account Opening and Trading Rules24
Section 26Trading on HashKey Global24
Section 27List of assets traded24
Section 28Permitted investors only25
Section 29Pre-funded trades only25
Section 30Trading channels25
Section 31Trading time25
Section 32Limits and price limits of an order25
Section 33Trading pairs25
Section 34Order types and Order time limit25
34.1Type of Orders25
34.2Order Time Limit26
Section 35Order execution methodology26
35.1Order Verification Rules26
35.2Order Priority27
35.3Execution of Order27
35.4Cancellation and amendment of Order28
35.5Conflicts of Interest28
Section 36Depositing and withdrawing Client’s fiat currencies and Digital Assets28
36.1Deposit/Withdrawal Procedures28
36.2General Rules for Deposit/Withdrawal28
Section 37Restricting, suspending, rejecting or cancelling Orders29
Section 38Clearing and settlement29
Section 39Preferred banking partners30
Part G – Trading Halt, Suspension and Resumption of Trading30
Section 40Criteria and procedure of trading halt, suspension and resumption of trading30
Section 41Notification of trading halt and suspension30
Part H – Custody of Digital Assets30
Section 44Title to Digital Assets31
Section 45Segregated accounts31
45.1Digital Assets31
45.2Client’s fiat currencies31
Part I – Prevention of market manipulation and abusive activities31
Section 46Identify market manipulative and abusive activities31
Section 47Reporting32
Section 48Market surveillance programme32
Part J – Fees32
Section 49Fees to be published on website32
Part K – Breach of these Exchange Rules32
Section 50HBML’s power to investigate32
Section 51Request to remedy33
Section 52Penalties33
Part L – Security of HashKey Global33
Section 53 Security measures33
Section 54System Maintenance and Interruptions34
54.1System Maintenance Arrangements34
54.2Unexpected Interruptions Handling34
Part M – Contact, Complaint Procedures and Dispute Resolutions35
Section 55Contact information of HashKey Global35
Section 56Complaint procedures35
Section 57Dispute resolution35
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Part A – General

Section 1 Interpretation

1.1Definitions

In these Exchange Rules, unless the context requires otherwise, the following terms shall have the meaning set forth below:
“Account” means the account (including its sub-account, if any) opened by a Trading Participant with HashKey Global for the purposes of utilizing the services at HashKey Global, including trading Digital Assets.
Account Opening and Trading Rules means HBML’s “Account Opening and Trading Rules” which governs such matters relating to opening an account and trading on HashKey Global as published on HashKey Global’s official website and updated from time to time.
AML means HBML’s anti-money laundering check which is to ensure that no illegally obtained funds or proceeds of criminal activities are used to conduct activities on HashKey Global.
API means application processing interface.
Associated Entity means HashKey Xpert Limited which:
  1. is a limited liability company incorporated in Hong Kong;
  2. holds a “trust or company service provider licence” (Licence No T006486) under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615 of the Laws of Hong Kong); and
  3. is an Affiliate of HBML.
Business Day means any day that is not a Saturday, Sunday or a public holiday and on which banks are generally open for business in Bermuda and Hong Kong.
BMA means the Bermuda Monetary Authority.
Exchange Rules means the HashKey Global - Exchange Rules as provided through the official website of HashKey Global from time to time.
HashKey Group means HashKey Digital Asset Group Limited and its affiliates.
HashKey Global means the Digital Asset trading platform branded “HashKey Global” which is operated by HBML.
HBML means HashKey Bermuda Limited (Registration number: 202302864), an exempted company limited by shares incorporated under the laws of Bermuda which has been granted a Class F licence by the Bermuda Monetary Authority under the Digital Asset Business Act 2018 to operate a digital asset trading platform, including its successor and assigns.
HKIAC means the Hong Kong International Arbitration Centre.
Hong Kong means the Hong Kong Special Administrative Region of the People’s Republic of China.
Issuer means any person approved by HBML under the Exchange Rules whose Digital Asset is listed on HashKey Global.
Issuer Applicant means any person whose Digital Asset is the subject of an application for listing on HashKey Global.
KYC means HBML’s “know your client” process which is for verifying the identity of the Trading Participants.
Listing Committee means the committee established by HBML as an independent decision maker for listing issues and a review body for decisions made by HBML.
Listing Document means a document that complies with Section 7.
Order means an instruction from a Trading Participant to either buy or sell a Digital Asset on HashKey Global.
Proscribed Person means a person who appears to HBML to:
(a)be in breach of any AML/CFT Requirements of any jurisdiction;
(b)appear in a list of persons with whom dealings are proscribed by the United Nations or another Government Agency or a regulatory authority under Applicable Laws; or
(c)act on behalf, or for the benefit of, any person described in paragraph (a) or (b);
Token Admission Policy and Procedures meansHBML’s internal policy and procedures which governs the process of listing and removal Digital Assets on HashKey Global, as updated from time to time.
Asset Operations Team means the team at HBML responsible for researching, reviewing, and gathering all the expert feedbacks for Listing Committee.
Trading Applicant means any person who is the subject of an application for opening an account and dealing in Digital Assets on HashKey Global.
Trading Participants means those persons and entities set out in Section 19 which are approved by HBML under the Exchange Rules to open an account and deal in Digital Assets on HashKey Global.
User means a user of HashKey Global, including Issuers, Issuer Applicants, Trading Participants and Trading Applicants.
Digital Assets means digital representations of value which may be in the form of digital tokens (such as digital currencies, utility tokens or security or asset-backed tokens), any other virtual commodities, crypto assets or other assets of essentially the same nature.
“we” means HBML.
  1.   Rules of Interpretation

  1. References in the Exchange Rules to Bermuda ordinances and to Bermuda statutory provisions shall be construed as references to those ordinances or statutory provisions as respectively modified (on or before the date hereof) or re-enacted (whether before or after the date hereof) from time to time and to any orders, regulations, instruments or subordinate legislation made under the relevant ordinances or provisions thereof which has been so re-enacted (with or without modifications).
  2. The headings are inserted for convenience only and shall not affect the construction of the Exchange Rules.
  3. Except where the context otherwise requires words denoting the singular include the plural and vice versa; words denoting any one gender include all genders; words denoting persons include incorporations and firms and vice versa.
  4. Except where the context otherwise requires references to the word include or including (or any similar term) are not to be construed as implying any limitation and general words introduced by the word other (or any similar term) shall not be given a restrictive meaning by reason of the fact that they are preceded by words indicating a particular class of acts, matters or things.
  5. Except where the context otherwise requires any reference to writing or written includes any method of reproducing words or text in a legible and non-transitory form.
  6. Except where the context otherwise requires references to times of the day are to that time in UTC+0 (Greenwich Mean Time) and references to a day are to a period of 24 hours running from midnight to midnight in UTC+0 (Greenwich Mean Time).
  7. References to Sections and Schedules are (unless the context requires otherwise) to sections of and schedules to the Exchange Rules.
  8. All representations, undertakings, warranties, indemnities, covenants, agreements and obligations given or entered into by more than one person are given or entered into severally unless otherwise specified.

Section 2Introduction

2.1HashKey Global

General

HashKey Global is an automated Digital Asset trading platform operated by HBML. Its mission is to provide safe, convenient and highly efficient services relating to Digital Assets to its customers. Neither HashKey Global nor HBML is a principal party to any transactions conducted via HashKey Global.

Regulatory

HBML is a Digital Asset trading platform granted a Class F licence by the Bermuda Monetary Authority under the Digital Asset Business Act 2018 to operate a digital asset trading platform.

Risk management

HBML maintains a sound risk management framework to identify, measure, monitor and manage the full range of risks arising from its businesses and operations.

Notifications to Authority

As an entity which is licensed by the BMA, HBML has ongoing reporting and notification obligations to the BMA and may be required to submit such information as may be specified and requested by the BMA and other law enforcement authorities from time to time.

Good Industry Practice

Apart from observing the regulatory regime of the BMA and other applicable compliance measures, HBML maintains and operates HashKey Global in accordance with good industry practices, which platform operators and entities engaged in internet trading incorporate into their information technology and cybersecurity risk management frameworks.

Security of HashKey Global

  1. HBML uses its best endeavours to manage and supervise the design, development, deployment and operation of HashKey Global in accordance with industry best practices and international standards to ensure that HashKey Global is appropriately secured against cyberattack, misuse or unauthorised access.
 
  1. HBML also has in place internal governance documentation and employs cybersecurity controls in accordance with industry best practices and international standards to protect HashKey Global from being abused and conducts regular reviews to ensure that security measures put in place are in line with changing market conditions and regulatory developments.

Exclusion of liability

While HBML commits to use all reasonable care in the performance of its duties under the Exchange Rules, neither HBML nor its Associated Entity will be in any way liable or responsible to any Users for any loss or liability arising from any act, default, omission or misconduct of HBML, except to the extent caused by its own gross negligence, fraud or wilful misconduct.

Records of trading

HBML is required to keep records of its operation of HashKey Global and its dealings with Client Money and Digital Assets of Trading Participants, and retain records in respect of transactions conducted in its systems, including:
  1. details of the Trading Participants;
  2. details of any restriction, suspension or termination of the access of any Trading Participants to HashKey Global;
  3. all notices and other information provided by HashKey Global to the Users; and
  4. routine daily and monthly summaries of trading in its systems.
Such information may be disclosed to third parties including the SFC, other regulators, law enforcement authorities and/or relevant Issuers as required from time to time.

Discretion of HBML

HBML may in its absolute sole discretion exercise powers granted under the Exchange Rules and applicable laws, including but not limited to accepting or rejecting any application or instructions. Unless as required under applicable laws, HBML will not give reasons for the exercise of any of its powers.

Forks

  1. When a hard fork is imminent, HBML will notify Users of the event and how HBML will handle it through email and announcement on HashKey Global’s website.
  2. HBML will suspend deposit and withdrawal requests until the hard fork is completed. This is to avoid the unnecessary risk of asset loss due to hard fork related security events.
  3. Depending on the specific events, HBML could suspend the trading of the Digital Assets involved until the hard fork is completed.
  4. HBML will update the product (e.g. name of Digital Asset) according to the consensus of the general blockchain and Digital Assets community.
  5. HBML will take a snapshot of Trading Participants’ asset for the Digital Asset involved at the block height right before the hard fork or right at the time of the hard fork. HBML will then distribute the new Digital Asset generated from the hard fork to the Trading Participants involved.
  6. HBML will provide deposit and withdrawal services for the new Digital Asset as a result of the hard fork. The new Digital Asset will be listed on HashKey Global according to HBML's listing rules and policies.
  7. HBML will provide 24/7 customer service with coverage aligned with exchange operation hours to cater for Trading Participants’ enquiries during a hard fork.

2.2Listing Committee

HBML will implement listing-related due diligence procedures in respect of HashKey Global. HBML will do so via the Listing Committee HBML.

Composition

  1. The Listing Committee will consist of the following members and any other person whom HBML’s directors deem appropriate, including but not limited to:
    1. a senior management of key business line, who will chair the LISTING COMMITTEE(“chairperson”);
 
  1. a senior management of compliance;
 
  1. a senior management of risk management; and
 
  1. a senior management of information technology.
The quorum for LISTING COMMITTEE meetings shall be more than half of the committee members. Decisions shall be determined by simple majority and, in the event of a tie, the chairperson of the meeting shall have the casting vote.
  1. In the case of any conflicts of interest, a LISTING COMMITTEE member is required to excuse himself from voting in respect of any listing applications which he may be interested in. Nonetheless, such LISTING COMMITTEE member may still be counted in the quorum at any such meeting at which any such listing application shall be considered.

Power and duty

  1. After the Asset Operations Team has conducted preliminary due diligence on Issuer Applicants and their Listing Documents, the LISTING COMMITTEE has the responsibility for the deliberation and review of the potential Digital Asset listing on HashKey Global. It has the power to:
 
  1. make decisions of material significance regarding Issuers, Issuer Applicants and the individuals concerned. These include approvals of listing applications, the imposition of any conditions if approvals are granted for the listing of Digital Assets and cancellations of listings; and
 
  1. act as a review body for listing recommendations made by the Asset Operations Team and has the final say regarding whether to approve the potential Digital Asset listing on HashKey Global.
    1. The chairperson of the LISTING COMMITTEE shall report to the board of directors of HBML on different areas of the activities of the LISTING COMMITTEE at the next meeting of the HBML board of directors following a meeting of the LISTING COMMITTEE.

Section 3About the Exchange Rules

  1. Application

The terms of the Exchange Rules are applicable to HBML and all Users.
  1. Status

The Exchange Rules govern all Users. HashKey Global will take into account the Exchange Rules in exercising its powers, functions and responsibilities hereunder or that are provided for by applicable laws.
  1. Procedure where none laid down

    1. In case no specific procedure is laid down in the Exchange Rules in connection with any actions required under the Exchange Rules, an application for directions should be made to HBML. Such direction shall be determined in the sole discretion of HBML.
    2. Actions performed in accordance with such directions of HBML shall constitute valid performance of such actions.
  1. General provisions

Time is of the essence

Time is of the essence in the performance of the Exchange Rules by Issuers, Issuer Applicants, Trading Participants and Trading Applicants.

Severance

If at any time any provision of the Exchange Rules is, or becomes, illegal, invalid or unenforceable in any respect, the legality, validity and enforceability of the remaining provisions of the Exchange Rules shall not be affected or impaired.

Variation of these Exchange Rules

HBML will provide a prior notice as soon as practicable to any amendment or variation of the Exchange Rules. Any variation to the Exchange Rules shall be binding only if it is in writing and is published on the official website of HashKey Global. Users who object to the amendments or variation will be given an opt-out option to terminate their Account and should send written objections to HBML within fourteen (14) Business Days after the publication of such amendment notice at HashKey Global’s website, failing which acceptance shall be deemed of such amendment, deletion, substitution or addition.

Third parties

These Exchanges Rules does not create or confer any rights or benefits enforceable by any person not a party to it except HBML’s Affiliates and nominees, and any other indemnified party may enforce its rights or benefits in the Agreement, including any indemnity, limitation or exclusion of liability; and a person who is a permitted successor or assignee of the rights or benefits of HBML under the Agreement may enforce those rights or benefits. Notwithstanding the foregoing, no consent from the persons referred to in this Clause shall be required for the parties to vary or rescind the Agreement (whether or not in a way that varies or extinguishes rights or benefits in favor of those third parties).
 

Governing laws

The Exchange Rules shall be governed by, and construed in all respects in accordance with, the laws of Hong Kong.

Part B - Listing

Section 4Listing Criteria

  1. General requirements

To allow HBML to perform due diligence on Digital Assets, set out below is a non-exhaustive list of general requirements and information which an Issuer Applicant shall provide to HBML before its Digital Assets may be approved to be listed on HashKey Global for trading:
  1. Background of management, development team, and any of its known key members;
  2. Regulatory status of Digital Asset in major jurisdictions;
  3. Supply, demand, maturity and liquidity of Digital Asset;Technical aspects of the Digital Asset;
  4. Development of the Digital Asset;
  5. Market and governance risks of the Digital Asset;
  6. Legal risks associated with the Digital Asset;
  7. Utility offered, novel use cases facilitated, technical structural or cryptoeconomic innovation, or administrative control exhibited by the Digital Asset and supporting information on viability of the project not dependent on continuous inflow into the Digital Asset;
  8. Enforceability of any rights extrinsic to the Digital Asset (for example, rights to any underlying assets) and the potential impact of the Digital Asset’s trading activity on the underlying markets; and
  9. Assessment on the money laundering and terrorist financing risks associated with the Digital Asset.

4.5Minimum requirements only

HBML endeavours to ensure that the decision-making process regarding the listing or removal of Digital Assets from HashKey Global is fair. Nonetheless, the listing requirements stated herein represent the minimum requirements only, and HBML may impose additional requirements as appropriate in approving the listing of any Digital Assets on HashKey Global.

Section 5Listing Procedure

5.1Application procedure

Preliminary application review

The Issuer Applicant should complete the application form provided by HBML (by email) and upon receipt, HBML will assess the admissibility of the Issuer Applicant and the relevant Digital Assets.

Full listing review

Upon the passing of the preliminary review, HBML will provide the Issuer Applicant a comprehensive list of required information and documents according to the class of underlying assets of the Digital Asset. Once HBML has received the fully-completed application pack from the Issuer Applicant, HBML will conduct a full listing review, including identifying any money laundering and terrorist financing risks which may arise in relation to the development and use of the relevant Digital Assets, services, business practices and technologies for both new and pre-existing products.

5.2Documents and information required

An application for listing shall be at least accompanied by copies of the following documents:
  1. Whitepaper: HBML will scrutinise all materials relevant to the offering including published information such as the whitepaper and any relevant marketing materials, as well as any projects associated with the Digital Asset as set out in its whitepaper and any previous major incidents associated with its history and development.
  2. Legal opinion: Written legal advice in the form of a legal opinion or memorandum on the legal and regulatory status of every Digital Asset that will be made available to Users, in particular, whether that Digital Asset falls within the definition of “securities” , and the implications for HBML.
 
  1. Smart Contract Audit: Smart contract audit report conducted by an independent assessor focused on reviewing and confirming the smart contract is not subject to any contract vulnerabilities or security flaws to a high level of confidence.
  2. Listing Document: please see Section 7 below for details.

5.3Interview and further information or document

HBML may require an Issuer Applicant to attend interviews, give presentations or provide any additional information or documents which HBML at its sole discretion considers to be necessary or relevant to assess the listing application.

5.4Due diligence

HBML will perform all reasonable due diligence on all Digital Assets before including them on HashKey Global for trading, and to verify that they continue to satisfy all listing criteria in accordance with the Token Admission Policy and Procedures and internal governance documentation. The Issuer Applicant agrees that HBML may at its sole discretion decide to engage independent experts to verify or assess the application and the Issuer Applicant authorises HBML to disclose information and documents obtained from the Issuer Applicant to such experts.

5.5Declarations and undertakings

HBML may require an Issuer Applicant to make a declaration or undertaking in respect of the listing application in a separate agreement to be entered into between HBML and the Issuer Applicant.

5.6Listing conditions

HBML may attach to a listing any conditions that HBML considers appropriate, and vary or revoke the condition(s) when deemed necessary upon listing or at any time the Digital Asset is listed on HashKey Global.

5.7Listing fees and costs

  1. Issuer Applicants shall pay such listing fees and charges as HBML may prescribe and set out prior to the full listing application review. HBML shall have the right to waive all or part of the listing fees or charges at its sole discretion. Unless otherwise agreed by HBML, all listing fees and charges paid are non-refundable in any event.
 
  1. The Issuer Applicants shall be solely responsible for their own costs and expenses incurred in relation to the listing application regardless of the outcome.
 

Section 6Withdrawal of listing application

  1. An Issuer Applicant may withdraw a listing application by notifying HBML through email according to the terms and conditions as may be prescribed by HBML.
 
  1. HBML may at its sole discretion discontinue to assess any listing application but shall give the lssuer Applicant written notice (including via email).
 

Section 7Listing Document

7.1Information in Listing Document

A Listing Document should provide a concise and user-friendly summary, in plain language, of the key features and risks of a Digital Asset, including but not limited to the information listed in this Section. HBML may change or require additional information on a case-by-case basis in its sole discretion:
  1. Name and type of Digital Asset;
  2. Name of Issuer Applicant;
  3. The business, financial position, management and prospects of the Issuer Applicant, including:
    1. Where applicable, all relevant corporate and financial documentation of the Issuer Applicant;
    2. Where applicable, particulars and operating history of the Issuer Applicant;
  4. Key features of the Digital Asset:
    1. What is the product and how does it work;
    2. What are the key risks;
    3. What is the material technology that supports the Digital Asset, upon which its operation and/or transferability relies, including any relevant consensus protocol;
    4. Any information that is specific to its product class;
  5. Where applicable, detailed documentation in respect of the Digital Asset and the underlying asset;
  6. an investigation of the blockchain protocol of the Digital Asset;
  7. an investigation of the security of the Digital Asset;
  8. an investigation of the financial metrics of the project;
  9. Project description (if applicable);
  10. Key features of the project, covering the leading project team, business model, technical development, token economy and community and other important information (if applicable); and
  11. the risk assessment which includes the project due diligence conducted covering all the items from section 4.2 where not already provided.

7.2Statements in Listing Document

  1. The Listing Document should detail the nature and risks that Trading Participants may be exposed to in trading Digital Assets and using HashKey Global.
  2. In addition, a Listing Document must contain the following statement (or other statement for Digital Assets that are securities, as HBML considers appropriate) in a prominent position:
“HashKey Bermuda Limited (“HBML”) is not the issuer of the Digital Asset and did not prepare or compile this document. Therefore, HBML is not responsible for the contents of this document, makes no representations as to its accuracy or completeness and is not liable for any loss howsoever arising from or in reliance upon any part of the contents of this document. Investors should exercise caution, read and understand the contents of this document, and obtain appropriate professional advice before investing. The listing of the Digital Asset at HashKey Global does not translate to HBML’s recommendation or endorsement of any Digital Asset, nor does it guarantee the commercial merits of a Digital Asset or its performance. It does not mean the Digital Asset is suitable for all investors nor is it an endorsement of its suitability for any particular investor or class of investors.”
  1.   Approval for dissemination

  1. No party must disseminate the Listing Document unless and until HBML has approved the application.
  2. HBML’s approval of the application is not a recommendation or endorsement of a Digital Asset nor does it guarantee the commercial merits of a Digital Asset or its performance. It does not mean the Digital Asset is suitable for all investors nor is it an endorsement of its suitability for any particular investor or class of investors. HBML takes no responsibility for the contents of the Listing Document and makes no representation as to its accuracy or completeness.
  1.   Amendment and variation of Listing Document

An Issuer shall submit relevant information and supporting documents to HBML for any changes related to the Digital Asset or contents of a Listing Document. The changes should only be implemented and published after endorsement by HBML is obtained.
  1.   Distribution of Listing Document

Listing Document shall only be distributed through such means as approved by HBML.

Part C – Continuing Obligations and Responsibilities of Issuers

Section 8Notification requirement

8.1Issuer’s obligation to notify

An Issuer has the obligation to immediately notify HBML of:
  1. any change in control of the Issuer, including a change in any entity which controls the composition of the Issuer’s board of directors, controls more than half of the voting rights in the Issuer, or holds more than half of the Issuer’s issued share capital;
  2. any material change in the Issuer’s corporate information, business and financial position;
  3. any information that may reasonably be expected to materially affect market activity and/or price of any Digital Asset that it issues;
  4. any change in particulars submitted to HBML in its initial application and Listing Document, including any change in any Digital Asset that it issues;
  5. any proposed hard fork, upgrade, token migration, token split, token merge, rebranding, or airdrop;
  6. any regulatory action or court proceedings taken against the Issuer;
  7. any statutory demand (or other equivalent demand to repay debt in the relevant jurisdiction) issued against the Issuer or its affiliates;
  8. any other circumstances which may adversely affect the interests of Trading Participants holding the Digital Asset listed by the Issuer; and
  9. any other circumstances which may adversely affect an Issuer’s ability to carry out its obligations under the Exchange Rules or applicable laws.

8.2Disclosure to the market

The Issuers shall proactively liaise with HBML to publish on HashKey Global notifications to Trading Participants of the relevant material information for each Digital Asset, including providing Trading Participants with access to up-to-date offering documents or information, and providing Trading Participants with material information as soon as reasonably practicable to enable Trading Participants to appraise the position of their investments (for example, any major events in relation to a Digital Asset or any other material information provided by Issuers).

8.3HBML’s rights to request information

HBML may make enquiries to, or request further information from, an Issuer regarding its Digital Asset from time to time. Issuers shall respond to such enquiries or requests of HBML promptly within the prescribed timeframe set out in HBML’s notice of request.

Section 9 Payment of fees

All Issuers shall pay all fees associated with the use of HashKey Global as agreed with HashKey Global from time to time or so specified by HBML, otherwise HBML may delist its Digital Assets from HashKey Global.

Section 10Financial information

Subject to the type of Digital Asset and as notified by HBML, an Issuer shall submit to HBML its audited annual financial statements within 1 month from its issuance and/or a valuation report of the underlying asset to the satisfaction of HBML, and/or any other information reasonably requested by HBML.

Section 11Maintenance of eligibility

As long as its Digital Asset is listed on HashKey Global, an Issuer has a continuing obligation to ensure the listing criteria and listing conditions (if any) are satisfied and that the Issuer is not otherwise prohibited from using HashKey Global by operation of laws or other regulations.

Section 12Self-reporting

Any obligation to report under these Exchange Rules shall be undertaken by an Issuer proactively without needing to be first demanded by HBML. In particular, the Issuer shall immediately report to HBML and cease trading on HashKey Global if it has reason to believe that it does not meet the listing criteria or listing conditions (if any), or is otherwise under an obligation to cease trading pursuant to applicable laws.

Part D – Removal of Digital Asset

Section 13HBML’s power to remove a Digital Asset from HashKey Global

HBML may remove a Digital Asset from HashKey Global in accordance with the Listing Policy and Procedures or internal governance documentation.

13.1Relevant circumstances

HBML may take into account the below circumstances while taking a decision to remove a Digital Asset from HashKey Global:
  1. implementation of new regulatory standards and other compliance issues;
  2. the Token or Project Team posed significant regulatory risks, including but not limited to, that the Token constitutes a “security” in a jurisdiction and HashKey Global is unable to and/or unwilling to prevent its users from that jurisdiction from holding and/or trading the Token;
  3. blockchain or related technology becomes compromised or defective;
  4. the Digital Asset is no longer supported or maintained by the Issuer or others;
  5. complaints by Users or other third parties, which are related to significant issues such as fraud;
  6. the relevant Issuer conducts or is involved in any illegal activity(ies) within any jurisdiction(s), such as money laundering, fraud or pyramid selling;
  7. any threatened, pending or active legal proceeding or Claim (whether civil, criminal, or administrative, formal or informal, or direct or indirect) against the Project Team;
  8. the relevant Issuer is suspected of manipulating the market and the circumstances are serious;
  9. the relevant Issuer’s team is unreachable within a specified period indicated to the Issuer;
  10. any changes to project team members which HBML considers to have material adverse impact on the Digital Asset or the underlying asset or project;
  11. any core member of the Project Team has been found of significant fraud or deception, including but not limited to, misappropriation of the raised Tokens, unknown whereabouts of the Project development team, cease to support the Project technology, intentionally concealment of material facts of the Project, disclosure or creation of materially fraudulent, false or misleading information;
  12. the dissolution of the project’s development team or resignation of core team members without the consent of the community, resulting in the inability to continue development;
  13. there is a lack of liquidity in the Digital Asset’s market over a time period to be determined as appropriate by HBML;
  14. no order of the Digital Asset is recorded over a time period to be determined as appropriate by HBML after initial listing;
  15. the Issuer changes supply of the Digital Asset without giving prior notice to HBML;
  16. the Issuer unlocks the Tokens without fulfilling the commitment made in the whitepaper or in other forms;
  17. the Issuer conducts a hard fork, token migration, token split, token merge, and rebranding of the Digital Asset without giving prior notice to HBML;
  18. the Project Team has caused significant losses to HashKey Global and users caused by security issues in the main net or the contract, and the Project Team fails to reimburse HashKey Global for the losses and/or compensating its users for the losses that they suffer;
  19. other risks and hazards exist in a Project, such as hacking, coins stealing, concealment of additional issuance, and double spend attack;
  20. market cap of the Digital Asset drops below USD 1,000,000.
  21. HashKey Global’s daily average transaction volume of the Digital Asset is less than USD100,000 or other equivalent tokens for more than 30 days;
  22. there is no immediate action taken or solution given by the Issuer in the event of any crisis, as deemed by HBML, that is causing detrimental impact to HBML, HashKey Global and/or the Trading Participants, including but not limited to, discovery of inaccurate information, technical issues on the Digital Asset, security breach, etc.;
  23. the Issuer conducts any activity(ies) that damages the reputation of HBML or HashKey Global, and adversely affecting the Trading Participants’ interest;
  24. breach of these Exchange Rules which the breach cannot be or has not been cured within 14 days; or
  25. other circumstance(s) that, in the sole discretion of HBML, is/are sufficient for removal of Digital Asset from HashKey Global, including any circumstances which causes the Digital Asset to be no longer eligible or appropriate to continue to be listed, and at the request of the BMA or applicable authorities.

13.2Removal of Digital Asset from HashKey Global Warning

Where appropriate and feasible, a warning (verbal or written) would first be given to the Issuer if any of the above events took place. A reasonable time period, usually about 14 days, would be given to the Issuer to mitigate and/or remedy the problem to the satisfaction of HBML. Failing which, HBML will take actions to remove the Digital Asset.

Section 14Removal of Digital Asset from Platform request

  1. Any person, including the Issuer, may request HBML to exercise its power to remove a Digital Asset from HashKey Global. Nonetheless, the decision to remove a Digital Asset shall be made in the sole discretion of HBML taking into account the circumstances set out in Section 13.
  2. The request should contain the following information:
    1. the Digital Asset involved;
    2. details of any circumstances which warrant a removal;
    3. copies of any documents that provide evidence that supports the request; and
    4. name, email address and telephone number of the person submitting the request.

Section 15Removal of Digital Asset from HashKey Global Notification

HBML will notify Users for removal events by sending system messages and issue a removal announcement on HashKey Global’s official website and the trading portal for Digital Assets or projects that trigger the removal condition 7 days in advance. Any pending order received before the announcement date shall be executed within such period.

Section 16Withdrawal of Client Money and Digital Assets upon removal

  1. Within 30 days from the date of removal announcement and where possible, Trading Participants shall transfer the relevant Digital Asset to their personal wallets or other trading platform accounts. Trading Participants should ensure that their personal wallets or other trading platform accounts support the relevant Digital Asset. HBML shall not be responsible for any loss or damage sustained by the Trading Participant arising from, or related to, the use of incompatible wallets or accounts. In certain instances for technical or compliance reasons HBML may decide to shorten the withdrawal period.
  2. HBML will provide reasonable notice regarding the withdrawal on HashKey Global’s official website and the trading portal. HBML is not liable for any loss or damage sustained by Trading Participants in circumstances under which a Trading Participant for any reason fails to withdraw the delisted Digital Asset before the deadline or fails to withdraw the Digital Asset due to events outside of HBML’s control.

Section 17 Transfer of Listing

An Issuer who wishes to conduct a transfer of listing from HashKey Global to another Digital Asset exchange platform will be treated as a removal and the Issuer shall submit a removal request in accordance with Section 14.

Section 18Relisting

An application for the listing of a Digital Asset on HashKey Global which was previously listed on HashKey Global will be treated as a new application for listing.

Part E – Trading Participants

Section 19Type of Trading Participants

Trading Participants must submit and execute Orders at HashKey Global through their Accounts and include the following categories:
  1. Entity Investors: corporations or institutions.
  2. Retail Clients or Retail Investors: any person other than an Entity Investor.

Section 20Eligibility

20.1Individuals and institutions

To be eligible to be registered as a Trading Participant, the person or entity must:
  1. acknowledge and agree that the products and services of HashKey Global may be provided by HBML with the support of its affiliates;
  2. be a natural or legal person or other body corporate with full legal capacity and authority to enter into this Agreement;
  3. in the case of an individual, be at least 18 years old or of legal age specified by applicable law in your jurisdiction of residence for a binding contract;
  4. in the case of an authorized person entering into these Terms on behalf of a body corporate, have all the necessary rights and authorities to bind such body corporate;
  5. not be a citizen of, resident of, or located in, any of the non-prohibited jurisdictions published on the official website of HashKey Global from time to time, or any jurisdiction where trading in the relevant Digital Asset is not permissible under applicable law, or reside in a country where the relevant products and services are inaccessible;
  6. have passed all compliance checks by HBML (including but not limited to KYC, AML and countering the financing of terrorism, and risk tolerance);
  7. not be a Proscribed Person; and
  8. have not previously been suspended or refused from using services provided by HashKey Global.

20.2Other criteria

HBML may from time to time change or impose additional criteria regarding the eligibility of Trading Participants without prior notice.

Section 21Application procedure

  1. An application to register as a Trading Applicant may be made by following the process as set out in the Account Opening and Trading Rules.
  2. After receiving all the required information, HBML will review the submitted information. During this process, HBML may ask for additional information from the Trading Applicant. The review will normally take 3 Business Days but may be longer depending on the circumstances. After the review, HBML will send feedback to the Trading Applicant by email.
 
  1. Once an application has successfully passed HBML’s review, the Trading Applicant’s initial account will be formally converted into a client account capable of trading.
  2. A Trading Participant is not allowed to open multiple accounts, unless these are in the form of sub-accounts.

Section 22Document and information required

  1. For the purposes of HBML’s KYC and AML processes, HBML may require a Trading Participant or Trading Applicant to provide the following information:
 
  1. Documentary evidence of the Trading Participant’s or Trading Applicant’s true and full identity, and his/her financial situation, investment experience, investment objectives and beneficial ownership information.
  2. Where a Trading Participant’s or Trading Applicant’s IP address is masked (for example, where access is via a virtual private network), the unmasked IP address, or else HBML may decline to provide services to that Trading Participant or Trading Applicant.
  3. Information regarding the Trading Participant’s or Trading Applicant’s business and risk profile and conduct ongoing due diligence on the business relationship, including wherever relevant an IP address with an associated time stamp, geo-location data, device identifiers, Digital Asset wallet addresses, and transaction hashes.
 
  1. HBML may also from time to time request information and documents to ascertain the identity, address and contact details of:
 
  1. the person or entity (legal or otherwise) ultimately responsible for originating the instruction in relation to a transaction;
 
  1. the identity, address and contact details of the person or entity (legal or otherwise) that stands to gain the commercial or economic benefit of the transaction and/or bear its commercial or economic risk; and
 
  1. the instruction given by the person or entity referred to in paragraph (b)(i) above.
 
  1. Where incomplete or suspicious information is provided, HBML reserves the right to reject, suspend or terminate the business relationship with the Trading Participant or Trading Applicant (as appropriate).

Section 23Declaration, undertakings and deposit requirement

  1. HBML may require a Trading Applicant to make a declaration or undertaking in respect of his/her application.
  2. HBML may require a Trading Applicant to deposit a sum of fiat currency to HBML’s designated bank account from his/her bank account with a licensed bank in Bermuda or supervised by a banking regulator of an eligible jurisdiction indicated by the BMA for remote onboarding, in order to verify the bank account information prior to the first trade. No interest will be paid on such deposit. The deposit will be credited to their ledger balance after the on-boarding procedures are completed.

Section 24 HBML’s decision

24.1Decision subject to receipt of all required information

HBML will only process the application after all of the requested information and documents are received in the condition in its sole satisfaction.

24.2Approval conditions

  1. HBML may impose conditions when approving a Trading Applicant’s application which it considers appropriate, and vary or revoke the condition(s) when deemed necessary.
  2. HBML and each Trading Participant, shall enter into a written client agreement which includes a provision stating that:
“In conducting any Digital Asset trading business activities, if we [ HashKey Bermuda Limited] solicit the sale of or recommend any product including any Digital Assets to you [the Trading Participant], the product must be reasonably suitable for you having regard to your financial situation, investment experience and investment objectives. No other provision of this agreement or any other document we may ask you to sign and no statement we may ask you to make derogates from this clause.”

Section 25Deleted

Part F – Account Opening and Trading Rules

Section 26Trading on HashKey Global

  1. HBML will follow the trading rules and trade verification procedures, which are briefly outlined below and as set out in detail in the Account Opening and Trading Rules, to provide Trading Participants with high-quality Digital Asset trading services and a first-class trading experience.
  2. When the trading rules change, HBML will inform Users as soon as possible by system notification and announcement on HashKey Global’s official website.
 
  1. Upon becoming aware of events such as hard forks and airdrops, HBML will notify Trading Participants as soon as practicable.

Section 27List of assets traded

The list of Digital Assets traded on HashKey Global is published on the official website of HashKey Global and will be updated from time to time.

Section 28Permitted investors only

  1. If a Trading Participant is an entity which in turn provides services or products of HashKey Global to its clients, such Trading Participant must satisfy HBML that all such clients and end users of HashKey Global are permitted investors under applicable laws.

Section 29Pre-funded trades only

  1. HBML will only execute a trade for a Trading Participant if there are sufficient Digital Assets and/or fiat currencies in the Account to cover the intended trade.
  2. HBML will not support trading outside HashKey Global and routing of Orders to other trading platforms or exchanges.

Section 30Trading channels

  1. Trading Participants should place an Order on the trading portal of HashKey Global.
  2. If a Trading Participant elects to place an Order through the API provided by HashKey Global, the API information and specifications can be found on the HashKey Global official website.

Section 31Trading time

Please refer to the HashKey Global official website for trading time.

Section 32Limits and price limits of an order

  1. As part of the account opening process, the Trading Participants’ risk tolerance would be evaluated in the categories of “conservative”, “cautious”, “moderate”, “active” and “aggressive”.
  2. Trading Participants can trade on HashKey Global only if their risk tolerance is higher than the level of "moderate", i.e. "active" or "aggressive". Different Types of Trading Participants with different risk tolerances will have different limit as set out in the Account Opening and Trading Rules.

Section 33Trading pairs

The list of trading pairs is published on the official website of HashKey Global.

Section 34Order types and Order time limit

An Order can only be submitted by a Trading Participant to HBML on HashKey Global.

34.1Type of Orders

  1. Market Order:
A market order is an order that does not specify a price. It is executed immediately upon entry. The size of the order that can be filled is dependent on the following conditions: 
  • the amount of liquidity available 
  • the price of the matching liquidity does not exceed the price band of the last executed price 
Any unexecuted portion of a market order is cancelled immediately. 
  1. Limit Order: A limit order is an order that specifies an execution price. The fill price of a limit order cannot be higher/lower than the limit price if the order is a buy/sell order.

34.2Order Time Limit

  1. Valid Until Cancelled (GTC—Good Till Cancelled):
Client GTC orders will remain valid until any of the following events occurs:
  • All the Orders are executed.
  • Trading Participants cancelled their Orders.
  • Orders are cancelled by the system. (For example: product removal)
 
  1. Execute Immediately or Cancel (IOC—Immediate Or Cancel): An IOC order is executed immediately. Any portion of an IOC order that cannot be filled immediately will be cancelled.

Section 35Order execution methodology

35.1Order Verification Rules

To mitigate potential user mistakes in order placement, HashKey Global adopts a transaction confirmation mechanism. The time involved below is expressed in time zone, i.e. UTC + 0 time.
When a Trading Participant places an Order, the HashKey Global platform will provide the User with following information:
  1. Order details:
    1. Order type
    2. Product
    3. Quantity
    4. Order time limit
  2. Order estimation:
    1. Transaction fee
    2. Transaction net amount (after deduction of transaction fee)
Once the transaction is executed, it cannot be cancelled. 
When the Order is successfully completed, the Trading Participant can review the following information about the Order on the platform:
  • Executed Time
  • Trading Symbol Name
  • Direction of the trade
  • Executed Price
  • Executed Volume
  • Fees
  • Total Volume of the order

35.2Order Priority

The orders of the HashKey Global platform are matched in the trading system according to price and then time priority;
  1. Price Priority: Bid orders with higher prices are ranked higher and ask orders with lower prices are ranked higher.
 
  1. Time Priority: Orders with the same price are ranked by their arrival time stamp. The earlier the order arrives at HashKey Global, the higher the ranking of the order.
 

35.3Execution of Order

  1. The procedures by which an Order is executed is set out in the Account Opening and Trading Rules.
  1. (i) When you place a limit order, HashKey Global will freeze the amount of asset that is involved in the order plus trading fee, i.e., either the maker or the taker fee, whichever is higher.
(ii)   When you place a market order, HashKey Global will determine if the available balance in trading account exceeds the total trading amount plus all necessary fees. Order entry will be blocked if the condition is not met.
(iii) When a buy order price and a sell order match in price, the maximal size of either orders that can be matched at the price will be executed. An order may be executed with multiple matching orders.

35.4Cancellation and amendment of Order

Trading Participants may submit a request to cancel any of their orders that are not fully matched on HashKey Global.

35.5Conflicts of Interest

(a) HBML may provide services to employees of HBML and its group companies and affiliates who can qualify to trade on HashKey Global (each referred to as a “Connected Party”).
(b)  Trading Participants’ interests are crucial to HBML.  In order to prevent conflicts of interest, HBML adopts the following best execution principles:
  1. Price: Bid orders with higher prices are ranked higher and ask orders with lower prices are ranked higher.
 
  1. Time: Orders with the same price are ranked by their arrival time stamp. The earlier the order arrives at HashKey Global, the higher the ranking of the order.
 
  1. Customer first: Where a Connected Party and a Trading Participant place Orders for the same Digital Assets at the same time and at the same price, Orders of Trading Participants have priority over Connected Party' Orders.
(c) In addition, HBML has internal governance documentation that regulates conflicts of interest. Such documentation applies to (including but not limited to) all employees and short-term and long-term consultants of the company. Once employees find a conflict of interest, they should report to their immediate supervisor or the compliance department of HashKey Digital Asset Group Limited immediately.

Section 36Depositing and withdrawing Client’s fiat currencies and Digital Assets

36.1Deposit/Withdrawal Procedures

Two-factor authentication must be enabled before Trading Participants can deposit and withdraw Digital Assets in their HashKey Global account. The steps for deposit and withdrawal of Digital Assets are set out in the FAQ of the official website of HashKey Global.

36.2General Rules for Deposit/Withdrawal

  1. (i) Deposit of Digital Assets: For deposit via personal wallet, the deposit transaction will be processed when a certain number of confirmations are reached and has completed HashKey Global’s internal review. The deposit will then be credited and displayed automatically displayed on client’s account.
Whereas for deposit via Third Party Exchange, the deposit transaction will also require HashKey Global’s internal review, which is subject to FATF’s Travel Rule Requirement.
Users are reminded to enter the correct deposit address as confirmed transactions on blockchain may be irreversible.
(ii) Deposits of fiat currencies (if and when applicable): Deposit transaction will be processed after the funds are received and cleared by our designated bank. The deposit will then be credited after it has completed internal review and displayed on the client's account.
  1. (i) Withdrawal of Digital Assets: After the withdrawal application is accepted, the confirmation will be sent to the requesting Trading Participant which delivery time will depend on the speed of the blockchain network. Therefore, the time for the requesting Trading Participants to receive the requested Virtual Assets may vary from a few minutes to several hours or longer.
The Trading Participant should make sure the correct address is entered. Otherwise, HashKey Global may not return the Client’s Digital Assets.
(ii) Withdrawal of fiat currencies (if and when applicable): After the withdrawal application is accepted, the request amount will be accredited in the Trading Participant’s bank account after processing by our designated bank, however, this may be subject to the bank’s procedures.
 
  1. Number of block confirmations for successful withdrawal application:
Block confirmation depends on network conditions. Delays may occur due to network congestion.
  1. HBML and Associated Entity will not conduct any deposits and withdrawals of User’s Digital Assets through any wallet address other than an address which belongs to the User and is whitelisted by HBML and Associate Entity, except under permitted circumstances specified by applicable authorities.

Section 37Restricting, suspending, rejecting or cancelling Orders

  1. In order to maintain the fair and orderly operation of HashKey Global, HBML may take the following actions as it considers appropriate:
  1. Restrict or suspend trading of a Digital Asset on HashKey Global;
  2. Reject or cancel any Orders; or
    1. Freeze any accounts.
    2. HBML may exercise its power under Section 37(a) in the following circumstances:
      1. Mismatching;
 
  1. Upon notice of any information that may reasonably be expected to materially affect market activity for and the price of any Digital Asset;
 
  1. Upon discovery of any market manipulative and abusive activities; or
 
  1. Any other circumstances which in the sole discretion of HBML will impair the fair and orderly operation of HashKey Global.

Section 38Clearing and settlement

  1. HBML may designate a system for the purpose of providing clearing and settlement services. All Trading Participants shall settle all Orders through the system and comply with the terms and conditions of the system as notified to Trading Participants from time to time.
 
  1. HBML may in its sole discretion determine a standard settlement period of each Digital Asset from time to time.

Part G – Trading Halt, Suspension and Resumption of Trading

Section 39Criteria and procedure of trading halt, suspension and resumption of trading

  1. HBML reserves sole discretion to halt or suspend trading on HashKey Global at such time and for such duration as it may determine in accordance with HBML’s internal policies, which provide the criteria and procedure for halting and suspending a Digital Asset from trading on HashKey Global, and the arrangements during trading suspension, outages and business resumption.
 
  1. An Issuer whose Digital Asset is suspended from trading on HashKey Global shall continue to comply with these Exchange Rules in so far as they are relevant to it.

Section 40Notification of trading halt and suspension

If HBML exercises its power to halt or suspend a Digital Asset from trading on HashKey Global, HBML will notify Users through email, system notification and announcement on HashKey Global’s official website.
Section 41HBML’s decision
HBML’s decisions made under this Part G are conclusive and binding on the Users. Unless otherwise determined by HBML pursuant to applicable law, no loss or damage sustained by the Trading Participants shall be compensated by HBML and all such rights of the Users are irrevocably waived.

Part H – Custody of Digital Assets

Section 42Custody arrangement
  1. HBML holds Digital Assets on behalf of Trading Participants in a segregated account established by its Associated Entity.
  2. HBML’s Associated Entity adopts security standards in accordance with industry best practices and international standards in relation to the custody of Digital Assets. HBML has an insurance policy covering the risks associated with the custody of Digital Assets held in both hot storage and cold storage.
  3. The Associated Entity shall only receive, send, store or engage in other activities involving airdrops, hard forks or other derivatives, enhanced or forked protocols, token burns or buybacks, or other similar events, upon receipt of and in accordance with specific instructions of HBML, to the extent supported by the Associated Entity.
  4. HBML will, through its Associated Entity, store no less than 90% of Trading Participants’ Digital Assets in cold storage (Hardware Security Module (HSM)) (i.e. private keys are kept offline without access to the internet), in order to minimise exposure to losses arising from a compromise or hacking of HashKey Global. HBML endeavours to minimise transactions out of the cold storage in which a majority of Trading Participants’ Digital Assets are held.

Section 43Title to Digital Assets

HBML appoints its Associated Entity as custodian of HBML relating to the storage of the Digital Assets of Trading Participants. HBML and its Associated Entity has no right, interest, or title in such custodial Digital Assets, except to the extent as provided in these Exchange Rules.

Section 44Segregated accounts

44.1Digital Assets

  1. All Trading Participants’ Digital Assets are held in a segregated account (i.e. an account designated as a client or trust account) established by HBML’s Associated Entity for the
 
  1. purpose of holding client assets and are segregated from the assets of the Platform Operator and its Associated Entity.
 
  1. For each type of Digital Asset, the wallets in HBML’s Associated Entity’s client wallet system constitute:
 
  1. hot wallet(s), which is further composed of individual client wallets and an aggregated client hot wallet; and
 
  1. aggregated cold wallet(s), into which no less than 90% of that particular type of Digital Asset should be stored.

44.2Client’s fiat currencies

  1. If and when deposits of fiat currencies are accepted on HashKey Global, HBML may also establish segregated accounts by the Associated Entity with an authorised financial institution in Bermuda or another bank in another jurisdiction permitted under applicable laws from time to time,
for safekeeping Client Money, into which fiat currencies received from or on behalf of a Trading Participant should be paid within one Business Day of receipt.

Part I – Prevention of market manipulation and abusive activities

Section 45Identify market manipulative and abusive activities

  1. HBML established and implemented internal governance documentation for the proper surveillance of HashKey Global in order to identify, prevent, and report any market manipulative and abusive activities.
  2. HBML also conducts post-trade monitoring to reasonably identify any:
    1. suspicious market manipulative or abusive activities; and
 
  1. market events or system deficiencies, such as unintended impact on the market, which call for further risk control measures.

Section 46Reporting

Upon becoming aware of any market manipulative or abusive activities, whether actual or potential, on HashKey Global, HBML is required to notify the Financial Intelligence Agency “FIA” of such matter as soon as practicable, provide the FIA with such additional assistance in connection with such activities as it might request and implement appropriate remedial measures.

Section 47Market surveillance programme

  1. HBML adopts a market surveillance system provided by a reputable and independent provider to identify, monitor, detect and prevent any market manipulative or abusive activities on HashKey Global.
  2. HBML is required to provide access to this system for the FIA to perform its own surveillance functions when required.

Part J – Fees

Section 48Fees to be published on website

  1. The current fee schedule adopted by HashKey Global could be found on the official website of HashKey Global which will be updated periodically without prior notice, unless required under laws of Bermuda.
  2. In relation to admission, the fee structure is designed to avoid any potential, perceived or actual conflicts of interest. In relation to trading, HBML will charge a percentage of the transaction amount daily. Different fees may apply based on the type of Order (including whether a Trading Participant is providing or taking liquidity), transaction size and type of Digital Assets transacted (if applicable). In relation to deposit and withdrawal, no deposit fee will be charged, and a different fixed withdrawal fee will apply based on the type of Digital Asset.
  3. HBML will transfer fees from the aggregated client hot wallet to HBML’s hot wallet daily at 00:00 (UTC+0 - Greenwich Mean Time).
  4. HBML may in its sole discretion and where applicable waive, reimburse, or pay for Trading Participants’ on-chain transaction fees (i.e. gas fees), including fees for transferring between an individual client’s wallet and other internal wallets, and withdrawals from HashKey Global as set out on the official website of HashKey Global.

Part K – Breach of these Exchange Rules

Section 49HBML’s power to investigate

  1. HBML may investigate any matter that relates to HashKey Global on its own initiative or upon receiving a complaint or enquiry from any person.
  2. Users under investigation shall promptly provide any necessary assistance to HBML during an investigation.
  3. HBML will retain a record of all investigations conducted.

Section 50Request to remedy

  1. Where a User is found to have breached the Exchange Rules or to have conducted its business in a manner that is detrimental or prejudicial to other Users of , HBML, HashKey Global or the public, HBML may, at its sole discretion, request the breaching User to remedy the breach.
  2. For the avoidance of doubt, HBML may impose other penalties on the breaching User, and there is no obligation on HBML to allow the breaching User to remedy the breach.

Section 51Penalties

HBML may impose any of the following penalties on the breaching User:
  1. public reprimand;
  2. suspension of account;
  3. termination of account; or
  4. any other penalty in the discretion of HBML which is permissible under applicable laws.

Part L – Security of HashKey Global

Section 52 Security measures

  1. HBML employs adequate, up-to-date and appropriate security controls to protect HashKey Global from being abused, including:
    1. robust authentication methods and technology to ensure that access to HashKey Global is restricted to authorised persons only;
    2. up-to-date data encryption and secure transfer technology, in accordance with industry best practices and international standards, to protect the confidentiality and integrity of information stored on HashKey Global and during transmission between internal and external networks;
    3. up-to-date security tools to detect, prevent and block any potential intrusion, security breach and cyberattack attempts; and
    4. adequate internal procedures and training for HBML’s employees and regular alerts and educational materials for Trading Participants to raise awareness of the importance of cybersecurity and the need to strictly observe security in connection with the system.
  2. HBML also has in place effective controls to enable it, where necessary, to:
 
  1. prevent “fat finger” errors such with respect to as input limits or thresholds for Order price and quantity;
  2. immediately prevent HashKey Global from accepting Orders which are, for example, suspicious fraudulent trades initiated by hackers; and
  3. cancel any unexecuted Orders.
 
  1. HBML will arrange at least annual technology audits by a qualified independent professional to ensure the adequacy, reliability, security and capacity of HashKey Global.

Section 53System Maintenance and Interruptions

53.1System Maintenance Arrangements

  1. When HBML needs to perform system maintenance, the following measures will be taken:
  1. evaluating the impact, start time and estimated end time of the maintenance in advance;
  2. notifying Users of the impact, start time and estimated end time of the maintenance as soon as possible though email, SMS, system notification and announcement on HashKey Global’s official website; and
  3. notifying Users via email and announcement on website of HashKey Global as soon as possible when the maintenance is over.
    1. If system maintenance requires suspension of transactions, HBML will take the following measures:
  4. evaluating the start time and estimated end time of trading suspension in advance;
  5. notifying Users of the transaction suspension arrangements through email, SMS, system notification and announcement on HashKey Global’s official website;
  6. starting system maintenance and suspend transaction;
  7. after the system maintenance has been completed, changing the status of all Orders to “cancelled”; and
  8. when trading functions return to normal, notifying Users through email, SMS, system notification and announcement on HashKey Global’s official website.

53.2Unexpected Interruptions Handling

  1. When the service or transaction is stopped unexpectedly due to technical reasons or other force majeure, HBML may take one or more of the following measures as appropriate: 
  1. suspending deposit and withdrawal temporarily;
  2. cancelling all Orders in the Order book;
  3. suspending trading function (including order placement, matching and cancellation);
  4. suspending login;
  5. suspending API functionality ; or
  6. closing the website service temporarily; or
  7. changing the status of all unfilled Orders to “cancelled”.
    1. In the event there is a service or transactional interruption, HBML will inform Users by email, SMS, system notification and announcement on HashKey Global’s official website.
    2. Upon resumption of the service or transactional interruption, HBML will inform Users by system notification and announcement on HashKey Global’s official website.

Part M – Contact, Complaint Procedures and Dispute Resolutions

Section 54Contact information of HashKey Global

Users can reach the Client Service Team via email at support@global-cs.hashkey.com

Section 55Complaint procedures

  1. Any complaint should be submitted to HBML through the official website of HashKey Global in accordance with HashKey Global’s Complaint Handling Procedure published on its official website.
  2. HBML will acknowledge receipt of complaints and review them for possible follow-up action. HBML is committed to dealing with complaints quickly. However, the period of time required for following up on the complaints depends on the circumstances of each case.
  3. All enquiries and complaints are treated in strict confidence. However, if circumstances require, HBML may need to disclose information to relevant authorities, regulators or agencies for further follow-up. HBML will seek the enquirer’s or complainant's consent before disclosing any personal information.

Section 56Dispute resolution

Any dispute, controversy, difference or claim arising out of, or relating to, the Exchange Rules, including the existence, validity, interpretation, performance, breach or termination thereof or any dispute regarding non-contractual obligations arising out of, or relating to, it shall be referred to and finally resolved by arbitration administered by the HKIAC under the HKIAC Administered Arbitration Rules in force when the Notice of Arbitration is submitted. The law of this arbitration clause shall be Hong Kong law. The seat of arbitration shall be Hong Kong. The number of arbitrators shall be three. The arbitration proceedings shall be conducted in English.
See more
icon

HashKey Global Team

HashKey Global Privacy Policy
HashKey Global Privacy Policy
 
Updated on 28 August 2026
 
HashKey Holdings Limited and its affiliates (collectively, “HashKey”, “we”, “us” or “our”) are a comprehensive digital asset group. HashKey operates globally and provides a range of services, including virtual asset trading, exchange, brokerage, custody and other related services. HashKey is committed to respecting and protecting your privacy and personal data. This Global Privacy Policy (this “Privacy Policy”) explains how the relevant HashKey entity collects, uses, stores, transfers, shares, discloses or otherwise processes your Personal Data when you access or use HashKey websites, mobile applications, account interfaces, online platforms and other related products or services (collectively, the “Services”).
For the purposes of this Privacy Policy, the HashKey entity that provides the relevant Services to you is generally responsible for the processing of your Personal Data in connection with those Services. “Personal Data” means any information relating to an identified or identifiable living individual, or any other similar term under applicable data protection laws, excluding the information processed anonymously. For the avoidance of doubt, this Privacy Policy is not a contract and does not itself create legal rights or obligations beyond those required by applicable law.
Our Services are designed exclusively for individuals who are 18 years of age or older. You must not access or use the Services if you are under 18 years old, do not meet the minimum age requirement applicable to the relevant Service or jurisdiction, or are otherwise legally restricted from using the Services. We do not knowingly collect Personal Data from children or minors. If you believe that a child or minor has provided Personal Data to us, please contact us so that we may take appropriate steps in accordance with applicable law.
Please read this Privacy Policy carefully before using or continuing to use the Services. If you do not provide certain Personal Data, we may be unable to provide the Services to you, process your account registration, complete identity verification, comply with legal or regulatory obligations, or make certain functions of the Services available.
This Privacy Policy is intended to operate as a global baseline. If you are located in, receive Services from, or interact with a HashKey entity established in Hong Kong, Singapore, Japan, the United Arab Emirates or Bermuda, please also review the jurisdiction-specific addendum applicable to you. If there is any inconsistency between the main body of this Privacy Policy and an applicable addendum, the addendum will prevail to the extent of that inconsistency.
This Privacy Policy is prepared and provided in English. In the event of any conflict between the English version and any other available translation, the English version shall prevail.
 

1. How We Collect and Use Your Personal Data

We collect Personal Data that you provide to us, Personal Data generated when you use the Services, and Personal Data obtained from third parties or public sources where permitted by applicable law.
 
1.1 Personal Data You Provide to Us
When you register for, apply for, subscribe to, or use the Services, we may collect Personal Data including:
 
1.1.1 Account registration and account administration. When you register for, apply for, subscribe to or use the Services, we may collect information associated with your account, including your name, username, email address, mobile phone number, account credentials, referral code, verification codes, preferred language, account settings and other information required to create, authenticate, administer and maintain your account.
 
1.1.2 Identity verification and due diligence. As a regulated virtual asset service provider, we may collect information required for identity verification, KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability and other compliance checks. This may include your date of birth, nationality, residential address, government-issued identification documents and numbers, photographs, selfie or liveness-check information, biometric verification information where required and permitted, tax information, source of funds or source of wealth information, occupation, employer information, beneficial ownership information, politically exposed person status, sanctions screening results, risk assessment results and other due diligence materials.
 
1.1.3 Financial, trading and transaction information. When you use the Services, we may collect information relating to your account and transactions, including bank account details, payment information, wallet addresses, transaction records, order history, trading activity, trading parameters and instructions, asset balances, deposit and withdrawal information, settlement details, risk profile, investor classification, suitability information and other information required for account administration, transaction processing, reporting or regulatory compliance.
 
1.1.4 Communications, support and complaints. When you contact us, submit feedback, make enquiries, lodge complaints, request support, appeal a decision or otherwise communicate with us, we may collect your contact details, account information, communication channel information, description of the issue, supporting materials, attachments, communications with us, call recordings or scripts, chat records, complaint and dispute records, and other information needed to verify your identity, understand your request, investigate the matter, provide support, resolve disputes and improve our Services.
 
1.1.5 Other information you choose to provide. We may also collect information that you submit through links, forms, surveys, events, promotions, campaigns, applications, onboarding questionnaires, due diligence requests or other interactions with us.
 
If you are an institutional or corporate customer, or act on behalf of such a customer, we may collect and process information relating to the relevant entity and its representatives, including corporate registration documents, incorporation details, business information, authorised representatives, directors, officers, employees, beneficial owners, controllers, traders, account administrators and other authorised persons. We may also collect information relating to account mandates, trading authorisations, API users, API credentials or identifiers, wallet addresses, transaction instructions, settlement details, access permissions, security settings and audit logs. We use this information to onboard and administer institutional or corporate accounts, verify authority and ownership structures, provide relevant Services, maintain account security, monitor account activities, and comply with legal and regulatory obligations.
 
If you provide Personal Data relating to another individual, you are responsible for ensuring that you have obtained all necessary authority, consent or other lawful basis to provide that information to us.
 
1.2 Personal Data Generated Through Your Use of the Services
 
To ensure the secure, stable and efficient operation of the Services, and to maintain account and transaction security, we may automatically collect or generate technical, usage, security and risk information when you access or use the Services. This may include:
 
1.2.1 We may collect device and technical information, such as your device model, device identifiers, operating system, browser type and version, IP address, language settings, time zone, network information, app version, crash logs and diagnostic information, in order to operate the Services, maintain technical compatibility, troubleshoot issues, improve performance and protect the security of our systems.
 
1.2.2 We may collect usage information, such as your login records, pages viewed, functions used, search and clickstream information, access dates and times, session duration, referral information, error reports and interaction records, in order to understand how the Services are used, support account administration, improve user experience, monitor service performance and develop or enhance our products and services.
 
1.2.3 We may collect security and risk information, such as account activity, authentication records, fraud indicators, suspicious activity reports, risk alerts, cybersecurity logs and information used to detect unauthorised, unlawful or non-compliant activities, in order to authenticate users, maintain account and transaction security, detect and prevent fraud, respond to security incidents and comply with legal and regulatory obligations.
 
1.2.4 We may collect approximate location information derived from IP address or similar technical data. We will collect precise location information only where the relevant function requires it, you have enabled the applicable device permission, and the collection is permitted by applicable law, for example to support security verification, fraud prevention, regulatory compliance or other location-based functionality notified to you where applicable.
 
Depending on the functions you use, we may request access to certain device permissions, such as camera, photo album or storage, push notification, file upload, biometric or liveness check, and, where applicable, microphone or location permissions. For example, camera or photo permissions may be required for identity verification, document upload, selfie or liveness checks; file upload permissions may be required when you submit onboarding, due diligence, source-of-funds, complaint or support materials; push notification permissions may be used for account, security, transaction or service alerts; and microphone or location permissions may be used only where the relevant function requires them and such use is notified to you.
 
We will request such permissions only where relevant to the function you use. If you decline a permission, the relevant function may not be available or may not operate properly, but this will not affect your use of other functions that do not require that permission. You may manage device permissions through your device or browser settings, subject to the functionality of the relevant device, operating system or browser.
 
1.3 Personal Data from Third Parties and Public Sources
 
Where permitted by applicable law, we may obtain Personal Data from HashKey group entities, service providers, business partners, banks, payment service providers, custodians, virtual asset service providers, blockchain analytics providers, identity verification vendors, credit reference or risk information providers, sanctions and politically exposed person databases, fraud prevention databases, government or regulatory sources, public registers, publicly available websites and other lawful sources. We use such information to verify your identity, conduct due diligence, assess account, wallet, transaction and counterparty risks, comply with legal and regulatory obligations, prevent fraud and unlawful activities, and provide, secure and improve the Services.
 
Certain virtual asset transactions are recorded on public or permissioned blockchains. Depending on the relevant network, wallet addresses, transaction hashes, timestamps, transferred amounts, digital signatures, smart contract identifiers and other on-chain information may be publicly visible, immutable or independently processed by third parties. We may collect, analyse and use on-chain information, including through blockchain analytics tools, and may combine it with other information we hold about you where permitted by applicable law, to provide the Services, verify transactions, assess wallet, transaction and counterparty risks, detect suspicious activity, comply with legal and regulatory obligations and respond to lawful requests from regulators, law enforcement agencies or other competent authorities.
 
1.4 How We Use Personal Data
 
We may use Personal Data for the following purposes:
 
1.4.1 We use Personal Data to process your application, registration, subscription and onboarding for the Services, create and administer your account, verify your identity, determine your eligibility to access the relevant Services, and perform KYC, AML/CTF, sanctions, anti-fraud, anti-bribery, tax, investor suitability, creditworthiness, financial standing, solvency and other compliance checks.
 
1.4.2 We use Personal Data to provide, administer, operate, maintain and improve the Services, including processing transactions, safeguarding assets, maintaining accounts, facilitating settlements, maintaining records, providing customer support and enabling the functionality of the Services. We also use Personal Data to authenticate your identity, maintain account and transaction security, detect anomalous transaction patterns, monitor account activity, protect users and assets, and preserve the integrity and security of the Services.
 
1.4.3 We use Personal Data to comply with legal, regulatory, tax, accounting, court, law enforcement, self-regulatory organization, industry body or governmental requirements, including requirements relating to virtual asset transfers, AML/CTF, sanctions, fraud prevention, market integrity, regulatory reporting, audits, investigations and lawful requests from competent authorities.
 
1.4.4 We use Personal Data to communicate with you regarding your account, transactions, security alerts, service updates, changes to terms or policies, customer support, dispute resolution and other operational matters. We may also use Personal Data to respond to and process enquiries, complaints, appeals, privacy-related requests and other communications from you.
 
1.4.5 We use Personal Data for internal administration, audit, record-keeping, risk management, legal claim management, business continuity, corporate governance and general business management. We may also use Personal Data to improve user experience, monitor service performance, troubleshoot technical issues, conduct data analytics, develop or enhance products and services, compile aggregated or anonymised statistics, conduct research, surveys, market analysis, events, campaigns and direct marketing where permitted by applicable law and, where required, with your consent.
 
1.4.6 We may use Personal Data for due diligence, restructuring, merger, acquisition, financing, asset sale, transfer of business or similar corporate transactions, and for other purposes that are directly related to the above, notified to you at the time of collection, authorised by you, or otherwise permitted by applicable law.
 
We will only process Personal Data where we have a lawful basis or are otherwise permitted to do so under applicable law. Depending on the jurisdiction and the nature of the processing, our lawful basis may include your consent, performance of a contract with you, compliance with legal or regulatory obligations, establishment, exercise or defence of legal claims, protection of vital interests, public interest grounds, or our legitimate business interests where recognised by applicable law. Where applicable law does not recognise legitimate interests as a lawful basis (for example, under the UAE PDPL), we will rely on your consent or another statutory basis recognised under that law, and any reference to legitimate interests in this Privacy Policy will not apply to you. If we intend to process your Personal Data for any other purpose not covered by this Privacy Policy, we will notify you beforehand and ensure that such processing fully complies with applicable data protection laws.
 
We may use automated systems, rules engines, artificial intelligence, machine learning models or analytics tools to support identity verification, fraud detection, sanctions screening, transaction monitoring, account security, customer risk rating and other compliance, security or risk management activities. Such technologies may process information to identify patterns, detect anomalies, assess risks, prioritise reviews, generate alerts or support operational decisions. These technologies are used as support tools and are not intended to replace human oversight where such oversight is required under applicable law, regulatory requirements or our internal procedures. Where an automated output may materially affect your access to the Services, account status or transaction permissions, we will apply human review where required by applicable law, regulatory requirements or our internal compliance procedures.
 
We may aggregate, de-identify or anonymise Personal Data so that it no longer identifies you, and use such information for analytics, service improvement, product development, security, risk management, research, statistical and other legitimate business purposes. Where information has been anonymised, we will keep and use it in anonymised form and will not attempt to re-identify it except where required or permitted by applicable law.
 

2. How We Use Cookies and Similar Technologies

We use cookies, software development kits, pixels, local storage and similar technologies to operate the Services, remember your preferences, support account login, maintain security, analyse usage, improve performance and, where permitted, measure or deliver marketing.
 
You may configure your browser or device settings to block or delete cookies and similar technologies. If you do so, certain functions of the Services may not work properly, and you may need to log in again or reset your preferences. Where required by applicable law, we will obtain your consent before using non-essential cookies or similar technologies.
 
For more information on our use of cookies and similar technologies, please refer to the applicable HashKey Cookie Policy.
 

3. How We Share, Transfer or Disclose Your Personal Data

We may share, transfer or disclose Personal Data as described below, subject to applicable law and appropriate safeguards.
 
3.1 HashKey Group Entities
 
We may share Personal Data within the HashKey group where necessary for the purposes described in this Privacy Policy, including account administration, group-wide compliance, risk management, customer support, technology operations, audit, legal and business management.
 
Cross-platform account integration. HashKey operates through affiliated entities in different jurisdictions and provides Services through multiple platforms and channels. Where you register for an account with one HashKey group entity, we may share relevant Personal Data with other HashKey group entities to facilitate an integrated account experience across HashKey platforms. Such sharing may enable us to recognise your existing HashKey account, create or maintain corresponding account profiles, provide access to Services offered by other HashKey entities, administer your account relationship, and apply consistent security, compliance and risk management controls across our platforms.
 
Cross-Entity Onboarding and Due Diligence Reliance. Where permitted by applicable law and where necessary for the provision of the relevant Services, we may also share and rely on certain information relating to your identity verification and due diligence processes, including KYC, AML/CFT and sanctions screening information, to facilitate onboarding, avoid unnecessary duplication of verification procedures, maintain consistent compliance standards and support regulatory obligations across HashKey entities. Where required by applicable law, we will obtain your consent or implement another lawful basis before such information is shared or relied upon.
 
Intra-Group AML/CFT Data Sharing. Where you hold accounts with, or are identified across, more than one HashKey group entity, authorised compliance personnel (including Money Laundering Reporting Officers or their equivalents) may share Personal Data about you between HashKey group entities for anti-money laundering, counter-terrorist financing and sanctions compliance purposes. Such sharing may include identity and verification data, customer risk ratings, politically exposed person and sanctions screening results, transaction monitoring alerts, and related compliance information. This sharing is subject to strict purpose limitation: it may be used only for AML/CFT, sanctions compliance and related regulatory purposes and not for commercial, marketing or other unrelated purposes. Where one HashKey entity is legally required to freeze or restrict your account under applicable sanctions legislation or regulatory direction, it may notify other HashKey group entities, which will independently assess whether a corresponding restriction is required under their own applicable law.
 
3.2 Service Providers, Agents and Contractors
 
We may disclose Personal Data to service providers, agents, contractors and professional advisers who support our business and operations, including providers of identity verification, compliance, fraud prevention and security services, blockchain analytics, technology infrastructure, cloud hosting, data storage, cybersecurity, communications, customer relationship management, marketing, analytics, artificial intelligence, payment processing, banking, custody, audit, legal, tax and other professional, administrative or operational services.
 
These third parties are authorised to access, process or store Personal Data only to the extent necessary to perform services for us or as otherwise permitted by applicable law. We take appropriate contractual, technical or organisational measures to require them to protect Personal Data, process it in accordance with our instructions where applicable, and retain it only as necessary for the relevant purposes.
 
3.3 Regulators, Government Authorities and Other Required Recipients
 
We may disclose Personal Data to courts, regulators, supervisory bodies, law enforcement agencies, tax authorities, government authorities, self-regulatory organisations, industry bodies, financial institutions or other third parties where required or permitted by law, regulation, court order, legal process, regulatory request, applicable rulebook, travel rule requirement or other compliance obligation. We may also disclose Personal Data where we reasonably consider disclosure necessary to protect our rights, property, users, employees, systems or the integrity of the Services; to detect, prevent or address fraud, security incidents, unlawful activity or violations of our terms or policies; or to manage legal, regulatory, operational or security risks.
 
3.4 Travel Rule and Virtual Asset Transfers.
 
As a regulated virtual asset service provider, we are required by FATF Recommendation 16 and applicable anti-money laundering laws to obtain, hold and transmit certain originator and beneficiary information in connection with virtual asset transfers that meet the applicable threshold. When you send or receive a virtual asset transfer that meets the applicable threshold, we will collect and transmit information about you (such as your name, account or wallet identifier, and in some cases your address, national identity number or date of birth) to, or receive such information from, the counterparty virtual asset service provider. This disclosure is a mandatory legal obligation that may take precedence over the data minimisation principle, and you will not be able to exercise your right to restrict or object to such processing to the extent it is required by applicable law.
 
3.5 Business Partners and Third Parties Involved in Your Transactions
 
Where necessary to provide the Services, facilitate transactions, support joint products or services, administer partnership, referral, rebate or other commercial programs, or otherwise fulfil your requests, we may share relevant Personal Data with banks, payment service providers, custodians, brokers, liquidity providers, virtual asset service providers, referral partners, joint marketing partners and other business partners involved in the relevant products, services or transactions. We will share only the Personal Data that is reasonably necessary for the relevant purpose and will do so in accordance with applicable law. Where required by applicable law, we will obtain your consent or rely on another lawful basis before sharing such Personal Data.
 
3.6 Corporate Transactions
 
If HashKey is involved in an actual or proposed merger, acquisition, restructuring, financing, asset sale, transfer of business, insolvency, joint venture or similar transaction, we may disclose or transfer Personal Data to counterparties, advisers and other participants in the transaction, subject to appropriate confidentiality and data protection arrangements where required.
 
3.7 With Your Consent or at Your Direction
 
We may share Personal Data with third parties where you have consented to, requested or authorised the sharing, or where the sharing is otherwise notified to you and permitted by applicable law.
 

4. Cross-Border Transfer of Personal Data

HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or otherwise processed in jurisdictions outside the jurisdiction in which it was originally collected or outside the jurisdiction where the relevant HashKey entity is established, including Hong Kong, Singapore, Japan, the United Arab Emirates, Bermuda and other jurisdictions where HashKey group entities, service providers or business partners operate.
 
Where we transfer Personal Data across borders, we will do so in accordance with applicable data protection laws. Depending on the applicable jurisdiction, this may include implementing contractual safeguards, conducting transfer impact assessments, ensuring a comparable or adequate level of protection, relying on your consent, relying on recognised certifications or other lawful transfer mechanisms, or applying other measures required or permitted by law.
 
Where the EU GDPR or UK GDPR applies, and your Personal Data is transferred from the European Economic Area or the United Kingdom to a jurisdiction that has not been recognised as providing an adequate level of protection, we will implement an appropriate transfer mechanism where required. Such mechanisms may include, as applicable, an adequacy decision or adequacy regulation, binding corporate rules for intra-group transfers, the European Commission’s standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or another transfer mechanism recognised under applicable law.
 
For individuals located in other jurisdictions, your Personal Data may be transferred to jurisdictions that provide an adequate or comparable level of protection, or to jurisdictions that may not provide the same level of protection as your home jurisdiction. In such cases, HashKey will take steps required by applicable law, which may include implementing appropriate technical, organisational, contractual or other safeguards to protect your Personal Data.
 
The specific safeguards we apply may vary depending on the jurisdictions involved and the applicable legal requirements. You may contact us using the details in Section 9 if you would like to request further information about the safeguards used for cross-border transfers, subject to applicable law and confidentiality restrictions.
 

5. How We Store and Protect Your Personal Data

We retain Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected, provide the Services, comply with legal and regulatory obligations, maintain records, resolve disputes, manage risks, enforce agreements, protect our rights and interests, and meet legitimate business needs where permitted by law.
 
When determining retention periods, we may consider the purpose for which the Personal Data is processed, whether retention is necessary to continue providing the Services, the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, applicable legal, regulatory, tax, accounting, AML/CTF, sanctions, audit and reporting requirements, and whether the Personal Data may be relevant to disputes, investigations or legal claims.
 
When Personal Data is no longer required for the purposes for which it was collected, and we are no longer required or permitted to retain it under applicable law, we will securely delete, destroy, anonymise or de-identify it in accordance with our internal retention policies and applicable legal requirements.
 
Mandatory Retention Under Financial Regulations. As a regulated virtual asset service provider, we are required by applicable anti-money laundering, counter-terrorist financing and financial regulatory laws to retain certain identity verification records, transaction records and related information for minimum statutory periods. Such statutory retention periods vary depending on the applicable jurisdiction and regulatory requirements. These retention obligations override your right to request deletion or erasure to the extent required by law. If you request deletion of Personal Data that we are legally required to retain, we will explain the basis for retention and retain the data only for the period and purposes required by law.
 
Biometric Information. Where we collect biometric verification information (such as selfie or liveness-check data) for identity verification, we retain it only for as long as necessary to complete the verification, comply with applicable financial regulatory or AML/KYC requirements, or as otherwise required or permitted by applicable law. We do not use, disclose or retain biometric information for any other commercial purpose. Where we use third-party identity verification providers, such providers will retain biometric information in accordance with their applicable privacy notices.
 
We take reasonable and practicable technical, administrative, physical and organisational measures to protect Personal Data against unauthorised or accidental access, processing, erasure, loss, use, disclosure, alteration or destruction. These measures may include access controls, authentication mechanisms, encryption, secure transmission, monitoring, internal policies, employee training, vendor due diligence and incident response procedures.
 
No method of transmission over the internet or method of electronic storage is completely secure. We therefore cannot guarantee absolute security. If you suspect misuse or loss of your Personal Data or account, or unauthorised access to your Personal Data or account, please contact us immediately.
 
In the event of a personal data breach, we will take reasonable steps to contain and investigate the incident and to notify affected individuals and the relevant data protection authority where required by applicable law. The timing, content and recipients of any such notification will comply with the requirements of the applicable jurisdiction, as further described in the relevant jurisdiction-specific addendum.
 

6. Direct Marketing

Where permitted by applicable law and, where required, with your consent, we may use your name, contact details, account or service preferences and related information to send you direct marketing or promotional communications by email, SMS, telephone, push notification, in-app message or other communication channels about HashKey products, services, features, market insights, campaigns, events, promotions or other information that we think may be of interest to you.
 
You may opt out of receiving direct marketing communications by using the unsubscribe mechanism included in the relevant communication, adjusting your account or communication preferences, or contacting us using the details in Section 9.
 
Even if you opt out of direct marketing communications, we may continue to send you communications that are necessary to provide the Services or comply with applicable law. These may include communications relating to identity verification, security verification, account administration, transactions, customer support, legal or regulatory notices, policy changes, service updates, dispute resolution, fraud prevention or other operational matters. These communications are not marketing communications, and you may not be able to opt out of receiving them where they are necessary for the provision of the Services or compliance with legal or regulatory obligations.
 

7. Third-Party Websites and Services

The Services may contain links to, integrate with, or otherwise enable you to access third-party websites, applications, platforms, products or services. These third parties operate independently from HashKey and may have their own terms, privacy policies and security practices.
 
Where you choose to access or use a third-party website, application or service, your interactions with that third party and any Personal Data you provide to them will be governed by their own terms and privacy policies, unless otherwise stated. HashKey is not responsible for the availability, content, security or privacy practices of any third-party website, application or service. We encourage you to review the applicable terms and privacy policies before using such services or providing Personal Data to them.
 

8. How You Can Exercise Your Personal Data Rights

Depending on your jurisdiction and the applicable law, you may have rights in relation to your Personal Data, including the right to:
  • request access to your Personal Data and information about how we process it;
  • request correction or updating of inaccurate or incomplete Personal Data;
  • request deletion, blocking, erasure, destruction, restriction or cessation of use of Personal Data in certain circumstances;
  • withdraw consent where we rely on consent as the basis for processing;
  • object to or opt out of direct marketing;
  • request portability of certain Personal Data where applicable;
  • request information about third parties to whom your Personal Data has been disclosed, where applicable; and
  • lodge a complaint with the relevant data protection authority.
Automated Decision-Making and Your Rights. Where an automated decision or automated processing produces legal effects or similarly significantly affects you, you may have the rights available under applicable law to request human review, express your point of view, provide additional information, or contest the decision. We will consider such requests in accordance with applicable law, regulatory requirements and our internal procedures.
 
On-Chain Data Limitation. Certain transaction information is recorded on public or permissioned blockchains and is, by the nature of such networks, publicly visible, immutable and not subject to deletion, correction or restriction by us. Your rights to request deletion, correction or restriction of Personal Data do not extend to on-chain data that we cannot reasonably modify. We will, however, restrict or delete the off-chain association between your identity and on-chain data where required by applicable law and where retention is no longer necessary for legal, regulatory or security purposes.
 
Exercise Your Rights. To exercise your rights, please contact us using the details in Section 9. When submitting a request, please specify the right you wish to exercise and how we can assist you. To protect your account and Personal Data, we may ask you to provide information to verify your identity and authority to make the request. We may also contact you for further details to clarify your request and expedite our response. These rights may be subject to limitations, exemptions, identity verification, fees and procedural requirements under applicable law. We may refuse, limit or defer a request where permitted or required by law, including where we need to retain Personal Data for legal, regulatory, security, risk management, dispute resolution or record-keeping purposes.
 
Self-Service Privacy Tools. Where available, you may exercise certain rights (such as accessing, downloading, exporting or updating your Personal Data, or managing your marketing preferences) directly through your account settings or the privacy tools provided within the Services. Where a self-service tool is not available for your request, or where applicable law requires additional verification, please contact us using the details in Section 9.
 

9. How to Contact Us

If you have questions, concerns, complaints or requests regarding this Privacy Policy or the processing of your Personal Data, please contact HashKey’s Data Protection Officer or privacy contact at:
 
HashKey’s Data Protection Officer coordinates privacy matters across the HashKey group. Where required by applicable law, the relevant HashKey entity providing the Services to you remains responsible for complying with its obligations under applicable data protection laws.
 
Where your request relates to a specific HashKey Service, platform or local entity, you may also contact the relevant customer support channel or local privacy contact listed in the applicable jurisdiction-specific addendum.
 

10. How We Update This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, business operations, legal requirements or privacy practices. We will publish the updated version on our website or through other appropriate communication channels. If we make material changes to this Privacy Policy, particularly changes that materially affect your rights or how we process your Personal Data, we may provide additional or more prominent notice where required or appropriate, such as by email, in-app notice, website announcement, special alert displayed through the Services or other appropriate means.
 
If applicable law requires us to obtain your consent to a change in how we process your Personal Data, we will do so before the relevant change takes effect.
 
If you do not agree with the updated Privacy Policy, you should stop using the Services. Your continued use of the Services after the updated Privacy Policy becomes effective will be handled in accordance with applicable law.
 
Jurisdiction-Specific Addenda
Each addendum supplements and forms part of this Privacy Policy. It applies only where the relevant local law applies to our processing of your Personal Data. In the event of any inconsistency between an addendum and the main body of this Privacy Policy, the addendum will prevail to the extent of that inconsistency. Unless otherwise stated, terms used in each addendum have the meanings given under the applicable local law.
In these addenda, terms such as “data user”, “organisation”, “controller” and “business operator” are used to reflect the terminology under the applicable local data protection laws. Unless otherwise indicated, they refer to the HashKey entity that determines the purposes and means of processing, or is otherwise responsible for handling, your Personal Data in connection with the relevant Services.
 

A. Hong Kong Addendum

This Hong Kong Addendum applies where the Personal Data (Privacy) Ordinance (Cap. 486) (the “PDPO”) applies to the processing of your Personal Data.
 
A.1 Data User
For Hong Kong Services, the relevant data user is generally Hash Blockchain Limited or the HashKey entity that provides the relevant Services to you.
Hong Kong contact:
Address: 14th Floor, Three Exchange Square, 8 Connaught Place, Central, Hong Kong
Email: dpo@hashkey.com or support@customer.hashkey.com
 
A.2 Collection Notice
When we collect Personal Data directly from you, we will take reasonably practicable steps to inform you of the purposes for which the Personal Data will be used, whether provision of the Personal Data is obligatory or voluntary, the consequences if you do not provide obligatory information, the classes of persons to whom the Personal Data may be transferred, and your rights to request access to and correction of Personal Data.
 
A.3 Use and Direct Marketing
We will use Personal Data for the purposes notified to you, purposes directly related to those purposes, or other purposes permitted by the PDPO. If we intend to use your Personal Data for a new purpose that is not the original or a directly related purpose, we will obtain your prescribed consent unless an exemption applies.
We will not use your Personal Data, or provide your Personal Data to another person for that person’s use, for direct marketing unless we have notified you of the prescribed information and obtained your consent or indication of no objection where required by the PDPO. You may require us to cease using or providing your Personal Data for direct marketing at any time without charge. Where we intend to provide your Personal Data to another person for that person’s use in direct marketing, we will notify you of the prescribed information and obtain your consent or indication of no objection as required under the PDPO, and you may likewise require us to cease such provision.
 
A.4 Processors and Transfers
Where we engage data processors to process Personal Data on our behalf, we will adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use, and to prevent Personal Data from being kept longer than necessary for processing.
 
A.5 Access and Correction
You have the right to request access to and correction of your Personal Data in accordance with the PDPO. You may also request information regarding our policies and practices in relation to Personal Data and the kinds of Personal Data held by us, to the extent required under the PDPO. We may charge a fee for processing a data access request where permitted by law.
 
A.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong, or any other competent authority available under applicable Hong Kong law.
 

B. Singapore Addendum

This Singapore Addendum applies where the Personal Data Protection Act 2012 of Singapore (the “PDPA”) applies to the processing of your Personal Data.
 
B.1 Organisation
For Singapore Services, the relevant organisation is generally HashKey Technology Services Pte. Ltd. or the HashKey entity that provides the relevant Services to you.
Singapore contact:
Address: 3 Church Street, Samsung Hub #28-06, Singapore 049483
Email: dpo@hashkey.com or support@sg-cs.hashkey.com
 
B.2 Consent, Notification and Withdrawal
We will collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate in the circumstances and, where required, after notifying you of the relevant purposes and obtaining your consent or relying on another basis permitted under the PDPA.
 
You may withdraw your consent by contacting us. If you withdraw consent, we will inform you of the likely consequences of withdrawal, which may include our inability to continue providing certain Services, processing transactions, maintaining your account or complying with regulatory requirements. After a reasonable period, we will cease the relevant collection, use or disclosure unless it is required or authorised under applicable law. Withdrawal of consent will not affect processing that occurred before withdrawal or processing that is required or authorised under applicable law.
 
If we change a purpose for which we collect, use or disclose Personal Data, we will ensure that the changed purpose remains reasonably relevant to the original purpose and will notify you or publicly announce the changed purpose, where required by applicable law.
 
B.3 Access and Correction
Subject to the PDPA, you may request access to your Personal Data, information about how it has been used or disclosed, and correction of inaccurate Personal Data. We may charge a reasonable fee for processing an access request where permitted by law.
 
We will respond to access or correction requests as soon as reasonably possible and, where required under the PDPA, within 30 days after receiving the request or inform you in writing within that period of the time by which we will be able to respond. Where we correct Personal Data, we may send the corrected Personal Data to organisations to which the Personal Data was disclosed within the period required by the PDPA, unless an exception applies.
 
If we determine, after reasonable investigation, that a requested correction is not required, we may annotate the relevant record to indicate that a correction request was made.
 
B.4 Transfer Outside Singapore
Where the PDPA applies, we will not transfer Personal Data outside Singapore unless we have taken appropriate steps to ensure that the recipient is bound by legally enforceable obligations or otherwise provides a standard of protection that is comparable to that required under the PDPA.
 
B.5 Data Breach
Where a data breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and in any case no later than 3 calendar days after we assess that the breach is notifiable, and will notify affected individuals in accordance with the PDPA.
 
B.6 Direct Marketing
Where you have given consent and have not subsequently opted out, we may from time to time use your Personal Data, including your name and contact details, to send you direct marketing or promotional communications, such as emails, messages or other communications containing news, promotions, events and marketing offers. The dispatch of such direct marketing communications may be undertaken by third-party service providers acting on our behalf.
 
If you do not wish to receive further direct marketing or promotional materials from us, you may opt out by using the unsubscribe mechanism in the relevant communication, adjusting your account or communication preferences, or contacting us through one of the channels set out in Section B.1. Where we send marketing or promotional messages to Singapore telephone numbers, we will comply with the Do Not Call provisions under the PDPA, including checking the relevant Do Not Call Registers where required, unless we have obtained the subscriber’s or user’s clear and unambiguous consent, evidenced in written or other accessible form, to receive such messages at that number. We will also honour any withdrawal of consent or opt-out request in accordance with applicable law.
 
B.7 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Data Protection Commission of Singapore or any other competent authority available under applicable Singapore law.
 

C. Japan Addendum

This Japan Addendum applies where the Act on the Protection of Personal Information of Japan (the “APPI”) applies to the processing of your Personal Data. In this Japan Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the APPI, unless the context otherwise requires.
 
C.1 Business Operator
For Japan Services, the relevant business operator handling personal information is generally HashKey Japan 株式会社 (HashKey Japan Co., Ltd.) or the HashKey entity that provides the relevant Services to you.
Japan contact:
Address: 2-3-2 Marunouchi, Chiyoda-ku, Tokyo 100-0005
Email: dpo@hashkey.com or support@jp-cs.hashkey.com
Telephone: 050-3204-4855
 
We will make available information required under the APPI regarding the business operator handling Personal Data, the purposes of use, procedures for requests concerning retained personal data, security control measures and contact point for complaints and enquiries, through this Privacy Policy or other appropriate notices.
For Japan Services, we will also handle Personal Data in accordance with applicable laws, regulations and the self-regulatory rules of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), where applicable.
 
C.2 Purpose of Use
We will specify the purpose of use of Personal Data as specifically as possible and will not use Personal Data beyond the scope necessary to achieve the specified purpose of use unless permitted by the APPI or other applicable law. If we directly acquire Personal Data from you in writing or by electronic means, we will expressly indicate the purpose of use in advance unless an exception applies.
 
For Japan Services, the purposes of use include those described in Section 1.4 and such additional purposes as may be notified in connection with Japan Services.
 
We may record telephone communications with customers where necessary to accurately understand the content of transactions, enquiries, complaints or requests.
 
C.3 Sensitive Personal Information
For Japan Services, “special care-required personal information” includes information requiring special care to avoid unfair discrimination, prejudice or other disadvantage, such as information relating to race, creed, social status, medical history, criminal record, victimisation by crime and other information specified under applicable Japanese laws and regulations. Other sensitive information includes information relating to labour union membership, family origin, registered domicile, healthcare and sex life, except where such information is publicly available or otherwise excluded under applicable rules.
 
We will not acquire, use or provide special care-required personal information or sensitive information to third parties except in the cases described in this Privacy Policy, including where such handling is permitted by laws or regulations, is necessary to protect life, body or property, is necessary for public health or child welfare, is necessary to cooperate with public authorities, is necessary for inheritance, withholding tax or similar procedures, is necessary for the proper operation of crypto asset services with the individual’s consent, or involves the use of biometric authentication information for identity verification with the individual’s consent.
 
C.4 Third-Party Provision and Outsourcing
For Japan Services, we will not provide Personal Data to third parties except with your consent or where otherwise permitted under the APPI.
 
Where we outsource all or part of the handling of Personal Data, we select service providers in accordance with our standards and exercises necessary and appropriate supervision, including by entering into contracts concerning the handling of Personal Data where appropriate.
 
C.5 Handling in Foreign Countries
HashKey operates globally. Your Personal Data may be transferred to, stored in, accessed from or processed in jurisdictions outside Japan, including by other HashKey group entities, cloud hosting providers, SaaS providers, KYC/AML and blockchain analytics vendors, and other service providers located in Hong Kong and other jurisdictions.
 
Where we transfer your Personal Data to a third party located in a foreign country, we will take necessary measures in accordance with the APPI and other applicable laws and regulations.
 
Specifically, unless permitted under the APPI, we will obtain your prior consent to the transfer of your Personal Data to a third party located in a foreign country. When obtaining such consent, we will provide you in advance with information concerning the personal information protection system in the foreign country where the third party is located, the measures implemented by the third party for the protection of personal information, and other information that serves as a reference to you, pursuant to the APPI.
 
Notwithstanding the above, we may transfer Personal Data without obtaining your consent in cases permitted under the APPI, including where the recipient is located in a foreign country recognized as having a personal information protection system at a level equivalent to Japan for protecting individual rights and interests (such as EU member states and the United Kingdom), or where the recipient has established a system necessary to continuously take measures equivalent to those required to be taken by the business operator handling personal information under the APPI.
 
Where we transfer your Personal Data to a third party located in a foreign country on the basis that the recipient has established a system necessary to continuously take the equivalent measures referred to above, we will take necessary measures to ensure the continuous implementation of such measures by the third party and, upon your request, will provide information regarding such necessary measures in accordance with the APPI.
 
For inquiries or requests for information regarding these matters, please contact our Japan contact indicated in Section C.1.
 
C.6 Joint Use
As described in Section 3.1 of this Privacy Policy, Personal Data may be jointly used among HashKey group entities for the purposes described in this Privacy Policy. Where such sharing constitutes “joint use” under the APPI, we will comply with the applicable requirements of the APPI, including identifying the HashKey entity responsible for the management of the jointly used Personal Data where required.
 
C.7 Security Control Measures
We implement the following security control measures to ensure the proper handling of retained Personal Data:
  • organizational security control measures
  • human security control measures
  • physical security control measures
  • technical security control measures
  • understanding of external environments
For details regarding the security control measures implemented by us, please contact our Japan contact indicated in Section C.1.
 
C.8 Data Breach Notification
In the event of a breach involving Personal Data that is reportable under the APPI, we will, in accordance with the APPI and PPC guidelines, report the breach to the Personal Information Protection Commission and notify the affected individuals, unless an exception applies. We will take reasonable steps to contain the breach, investigate its cause and scope, and implement measures to prevent recurrence.
 
C.9 Enquiries and Complaints
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Personal Information Protection Commission or any other competent authority available under applicable Japanese law.
 

D. United Arab Emirates Addendum

This United Arab Emirates Addendum applies where Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the “UAE PDPL”), applicable sectoral rules, or applicable virtual asset regulatory requirements apply to the processing of your Personal Data.
 
D.1 Controller
For UAE Services, the relevant controller is generally HashKey MENA FZE or the HashKey entity that provides the relevant Services to you.
UAE contact:
Address: Floor 5, Premises EPO-05-35 CVT Convention Tower Dubai World Trade Centre, Dubai, United Arab Emirates
Email: dpo@hashkey.com or support@mena-cs.hashkey.com
 
D.2 Lawful Basis
Where the UAE PDPL applies, we process Personal Data only where we have obtained your consent or another lawful basis recognised under the UAE PDPL or other applicable law. Such lawful bases may include, where applicable, processing necessary for the performance of a contract, compliance with legal obligations, protection of public interest or vital interests, establishment, exercise or defence of legal claims, scientific or statistical research, or other circumstances recognised under applicable law.
References in this Privacy Policy to lawful bases that are not recognised under the UAE PDPL do not apply where the UAE PDPL governs our processing.
 
D.3 Your Rights
Subject to the UAE PDPL and other applicable laws, you may have rights to request access to Personal Data, correction of inaccurate Personal Data, deletion of Personal Data, restriction or cessation of processing, transfer of Personal Data, withdrawal of consent, and objection to certain automated processing decisions, including where such decisions have legal effects or similarly significant effects on you.
 
D.4 Cross-Border Transfers
We will transfer Personal Data outside the UAE only where permitted under the UAE PDPL or other applicable rules, including where the destination jurisdiction provides an adequate level of protection, appropriate safeguards are implemented, you have provided consent where required, or another statutory exception applies.
 
D.5 VARA-Related Requirements
Where the relevant HashKey entity is subject to the Dubai Virtual Assets Regulatory Authority (“VARA”) Technology and Information Rulebook or other VARA requirements, we will comply with applicable personal data protection, data storage, transfer, privacy governance, breach reporting and record-keeping requirements.
Where required by VARA rules, HashKey will notify VARA as soon as possible and in any event within 24 hours following notification by us to a data regulator or data subject of any incident affecting or potentially affecting Personal Data, unless prohibited by applicable law.
 
D.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the UAE Data Office or any other competent authority available under applicable UAE law.
 

E. Bermuda Addendum

This Bermuda Addendum applies where the Personal Information Protection Act 2016 of Bermuda (the “PIPA”) applies to the processing of your Personal Data. In this Bermuda Addendum, references to “Personal Data” shall be construed as references to “personal information” as defined under the PIPA, unless the context otherwise requires.
 
E.1 Organisation
For Bermuda Services, the relevant organisation is generally HashKey Bermuda Limited or the HashKey entity that provides the relevant Services to you.
Bermuda contact:
Address: c/o Carey Olsen Services Bermuda Limited, Rosebank Centre, 5th Floor, 11 Bermudiana Road, Pembroke, HM 08, Bermuda
Email: dpo@hashkey.com or support@global-cs.hashkey.com
 
E.2 Use of Personal Data
We may process Personal Data where we have your consent, where processing is necessary to perform a contract with you, where processing is necessary to comply with a legal obligation, or where processing is necessary for our legitimate interests, in each case subject to PIPA.
You may also contact us to ask about the purposes for which your Personal Data is used and the means available to control or limit our use of your Personal Data, subject to PIPA and applicable exemptions.
 
E.3 Overseas Transfers
As we operate globally, your Personal Data may be transferred to and stored in jurisdictions outside of Bermuda. When transferring your Personal Data overseas, we will take appropriate measures to ensure that the recipient provides a level of protection comparable to that required under PIPA, including through contractual, organisational or technical safeguards where appropriate.
 
E.4 Security Breach Notification
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your Personal Data, we will notify you and the Privacy Commissioner in accordance with our obligations under PIPA, where such breach is likely to result in a real risk of significant harm to individuals.
 
E.5 Your Rights
Subject to PIPA, you may request access to, correction of, blocking of, erasure of or destruction of your Personal Data. Your request should be made in writing and include sufficient information for us to identify the relevant Personal Data and respond to your request.
We will acknowledge receipt of your request promptly and in any event no more than 2 business days after receiving it where required by our applicable procedures. We will respond within a reasonable period, generally no more than 45 days depending on the nature and complexity of the request, subject to extensions permitted under PIPA.
Certain rights described elsewhere in this Privacy Policy, including data portability or restriction of processing, may not be available under PIPA and will apply only to the extent required by applicable law.
 
E.6 Complaint
If you have concerns about our handling of your Personal Data, please contact us first so that we can review and respond to your concern. If you are not satisfied with our response, you may also contact the Privacy Commissioner for Bermuda or any other competent authority available under applicable Bermuda law.

See more
icon

User Agreement

See all articles

HashKey Global Team

Notice of Amendment to Investor Business Terms – Addition of Dormant Account Clause
Dear Valued Clients,
 
This notice is to inform you of an amendment to the Investor Business Terms (the “Terms”) between HashKey Bermuda Limited (“we” or “HBML”) and you. The amendment introduces a new clause regarding the management of dormant accounts.
 
Key Amendment Details
Clause 43.4 is updated to include a new subclause (a) as follows:
43.4 In addition to the above, HBML may suspend, restrict, or terminate the Account (and any accounts beneficially owned by related entities or affiliates of the Client), freeze, or lock the funds in all such Accounts, and suspend the Client's access to the HashKey Exchange where:
(a) the Client’s Account has been classified as a dormant account as reasonably determined by HBML;
(b) the Client acts in a manner that is abusive of the Account as reasonably determined by HBML;
(c) HBML decides not to provide any services in relation to the Account;
(d) where HBML detects unusual activity or suspects that the Account is being used to engage in illegal activities;
(e) if the Client fails to pay the fees and charges included or the Client fails to pay any amount owing to HBML or its Affiliates;
(f) the Account is subject to a government proceeding, criminal investigation, or other pending litigation;
(g) HBML is required to do so by a court order or command by a regulatory/government authority; or
(h) any other circumstance which requires HBML to do so.
 
The Terms incorporating this amendment will be available at: https://help.hashkey.com/hc/en-us/articles/13000983371036-Investor-Business-Terms
 
Effective Date
This amendment takes effect immediately upon the publication of this Amendment Notice.
 
Opt-Out Option
Clients who object to this amendment may exercise an opt-out right by terminating their Account under the Terms. To do so, you must submit written objections to HBML via email at support@global-cs.hashkey.com within fourteen (14) business days after the publication of this Amendment Notice on our Website. Failure to submit written objections within the specified period will result in your deemed acceptance of the amendment.
 
Continuity of Existing Terms
All other terms and conditions of the Terms remain unchanged and continue to be fully binding on you and HBML, except as expressly modified by this notice.
 
Should you have any questions about this amendment, please contact our CS team at support@global-cs.hashkey.com.
 
Thank you for your continued trust and cooperation.
 
Sincerely,
HashKey Global
See more
icon

GlobalOps

Risk Disclosure for Perpetuals Contracts on Lower Capitalization Tokens

While perpetual futures on tokens with lower capitalization may offer potential for high returns, they inherently carry elevated risks compared to more established assets. These risks include, but are not limited to:

  1. Extreme Price Volatility
    Lower capitalization tokens are highly susceptible to severe price fluctuations driven by market sentiment, speculative trading, or limited adoption. Prices may swing dramatically in short periods, potentially eroding investment value rapidly.
  2. Liquidity Constraints
    Lower liquidity may result in wider bid-ask spreads, slippage during trades, or difficulty exiting positions without significantly impacting the token’s price.
  3. Total Loss of Value
    Smaller projects face higher risks of failure, abandonment, or loss of utility, which could render tokens worthless. This includes risks of protocol flaws, mismanagement, or competition.
  4. Delisting Risk
    Exchanges may delist tokens that fail to meet evolving compliance, liquidity, or market stability standards. Delisting could permanently restrict access to trading venues.
  5. Governance and Development Risks
    Many lower capitalization projects lack mature governance frameworks or clear roadmaps. Changes in development teams, protocol rules, or tokenomics (e.g., inflationary supply schedules) may materially impact value.
  6. Regulatory Uncertainty
    Evolving regulations could disproportionately affect smaller tokens, including restrictions on trading, custody, or classification (e.g., securities designations).
  7. Cybersecurity Vulnerabilities
    Smaller projects may have less robust security infrastructure, increasing exposure to hacks, smart contract exploits, or network outages that could irreversibly harm token value.
  8. Concentration Risks
    A small group of holders (e.g., >5% ownership) may exert outsized influence over token prices or governance decisions, amplifying volatility.

Disclaimer
HashKey assumes no responsibility for losses incurred through trading lower capitalization tokens. These assets are speculative and unsuitable for risk-averse investors.

 

 

 

See more
icon

HashKey Global Team

Third Party Data Consent
By filling in/using a referral code or otherwise signing up to HashKey Global through a referred person,
you agree and consent that your transaction data and other client-identifiable data may be shared to
your referrer for purposes of referral rewards verification. You may withdraw this consent at any time
and we will promptly cease to share the data for the aforementioned purpose.
See more
icon

HashKey Global Team

Disclaimer

Disclaimer:

Participation in this event does not guarantee eligibility, acceptance, or receipt of any rewards, benefits, or incentives. HashKey Global may impose certain criteria, requirements, or limitations for participation, and it reserves the right to deny or disqualify individuals or entities from participating in the event. Hashkey Global reserves the right to make changes, modify, or cancel the event or the eligibility of any participant at any time at its sole discretion, including due to internal control, system issues or other circumstances, without any prior notice or liability.
To the fullest extent permitted by law, HashKey Global, its affiliates, partners, and employees shall not be held liable for any direct, indirect, incidental, consequential, or special damages arising from participant’s participation in the event, including but not limited to any loss of funds, profits, business, potential profits, data, or reputation.
HashKey Global reserves the ultimate discretion regarding the rules and rewards of the event.
HashKey Global is a digital asset trading platform operated by HashKey Bermuda Limited under a Type F license granted by the Bermuda Monetary Authority. This information does not constitute an offer, solicitation, or recommendation for any investment product. Investing and trading virtual assets involve risks. HashKey Global does not service users from Hong Kong, United States, Mainland China and certain other jurisdictions in compliance with laws and regulations. Certain services, features, and campaigns may not be available in your jurisdiction.


RISK WARNING ABOUT HSK:

Please be aware that HSK is not currently listed on any exchange and there is no guarantee that it will be listed in the future. As a result, HSK presently has no established market value. The timeline for the potential listing of HSK remains uncertain. In the event that HSK is successfully listed, it may be subject to various trading restrictions in accordance with applicable regulations and laws. These restrictions may include, but are not limited to, limiting the trading of HSK solely to eligible professional investors in select locations and subject to regulatory approval. The value of HSK is subject to substantial risk and may diminish or fluctuate significantly in response to various market conditions and other factors beyond HashKey Global's control. HashKey Global and its affiliates make no warranties, express or implied, in relation to HSK or any rewards and disclaims any liability relating thereto.

See more
icon

HashKey Global Team

Hashkey Global Complaints Handling Procedure

Customers may file a complaint if they are not satisfied with the services/ products provided or failed to be provided by HashKey Global (the “Company”). Once the Company has received customer complaint, the Company will deal with the matter as soon as practicable.

 

If you have a complaint with HashKey Global, you agree to first contact our customer support team where available to attempt to resolve such complaint. If we cannot resolve the complaint through our customer support team where available, you agree to use the complaints process set out in this document.

 

How can a complaint be made?

Customers can file customer complaint to the Company by email (global-complaints-hbel@hashkey.com), setting out the complaint in full details including but not limited to circumstances of the alleged incident.

 

What do customers need to provide when a complaint is lodged?

 

When a customer lodges a complaint, the Company requires certain information to verify the customer's membership. To help us resolve your complaint as quickly as possible, please provide the following details:

· Customer’s full name, address and other relevant personal details such as account;

· Number or account details to the extent that is necessary;

· A clear and honest outline of customer’s complaint;

· Copies of any supporting documents concerning the customer’s complaint; and

· Details of what customer would like the Company to do to rectify the situation.

 

Any personal information collected shall be subject to the applicable Privacy Policy.

 

How will a complaint be dealt with?

 

A complaint will be dealt with by (a) an individual not directly concerned with the subject of the complaint or (b) a compliance officer. If the Company can resolve the complaint within one (1) week following the day it was received, the Company will send the complainant the investigation result together with an explanation of the Company’s decision. Where the complaint is not genuine or does not include necessary information, no investigation will be carried out and customer will be informed accordingly, if applicable.

 

If further investigation is required, the Company will send the complainant an acknowledgement of receipt of their complaint within one (1) week following the day it was received. The Company will aim to provide the complainant with a written reply within four (4) weeks from the date the complaint is received. A final response will be issued within two (2) months from the date the complaint is received. The aforesaid timeline is an indicative only and not a commitment, as the processing of a complaint may be subject to various factors, such as the complexity of the complaint and any subsequent communications with the complainant for the purpose of seeking further information or clarification. When an investigation is taking longer than two (2) months to complete, an interim report will be issued depending on individual circumstances and the complexity of the case.

 

If customers are not satisfied with the Company’s response?

 

If customers are not satisfied with the decision, customers may request the Company to review the decision by providing new material information or evidence or refer the matter to other relevant regulators or relevant authorities.

 

For complaints or disputes that cannot be resolved via the complaint process set out above, the dispute resolution process as set out in the Investor Business Terms at Section 64 shall apply.

See more
icon

HashKey Global Team

API User Terms
 

(Last update:   18/7/2024)

THESE TERMS, TOGETHER WITH THE INVESTOR BUSINESS TERMS, RELATED ACCOUNT OPENING DOCUMENTS, THE EXCHANGE RULES, ANY OTHER RELEVANT AGREEMENTS INTO WHICH THE CLIENT AND HBML HAVE ENTERED, CONSTITUTE THE ENTIRE AGREEMENT AND CONTAINS IMPORTANT TERMS AND CONDITIONS APPLICABLE TO THE ACCOUNT.

HBML MAY IN ITS ABSOLUTE DISCRETION DISCLOSE TO THE CLIENT THE RISKS OF THE CLIENT’S USE OF THE SERVICES FROM TIME TO TIME. THESE TERMS DO NOT FULLY DISCLOSE THE RISKS OR MATERIAL ASPECTS OF CONDUCTING TRANSACTIONS OR USING THE SERVICES. THE CLIENT SHOULD NOT CONSTRUE THESE TERMS AS LEGAL, TAX OR FINANCIAL ADVICE. HBML IS NOT ACTING AS THE CLIENT’S FINANCIAL ADVISOR AND THE CLIENT MUST NOT REGARD HBML AS ACTING IN THAT CAPACITY. THE CLIENT SHOULD CONSULT ITS OWN INDEPENDENT PROFESSIONAL ADVISORS BEFORE ENTERING INTO ANY TRANSACTION AND ONLY USE THE SERVICES IF THE CLIENT HAS FULLY UNDERSTOOD THE NATURE, THE CONTRACTUAL RELATIONSHIP INTO WHICH HE IS ENTERING, ALL RELEVANT TERMS AND CONDITIONS AND THE NATURE AND EXTENT OF THE CLIENT’S EXPOSURE TO LOSS. THE CLIENT HAS BEEN RECOMMENDED TO READ THESE TERMS CAREFULLY AND RETAIN THESE FOR THE CLIENT’S RECORDS.

 

To :

HashKey Bermuda Limited (also known as HashKey Global)

c/o Carey Olsen Services Bermuda Limited, Rosebank Centre,

5th Floor, 11 Bermudiana Road, Pembroke, HM 08, Bermuda

(“HBML” or the “Company”)

 

The Client agrees to be bound by the following terms and conditions which will apply to any use of API related services which HBML may in its absolute discretion provide to the Client from time to time.

 

1. Risk Disclosures

This clause provides you with basic facts about trading through HashKey API (as defined hereunder). Trading through Hashkey API increases the risk posed to your account security and may result in the compromise of your account credentials and the loss of funds that you have deposited into your Account. It is important that you fully understand the risks involved in using HashKey API.

Using HashKey API will allow you to use, access, call, command, query or request the API to take certain actions in relation to your Account for and on your behalf.

Prior to using HashKey API, you must verify your identity through an API Key (as defined hereunder). You will, therefore, be required to create an API Key on our site. The API Key is a representation, verification, and authentication of your identity to us and is comprised of a public and a private key pair.

An API client that uses your API Key can operate the API to give user instructions. When you do so, you are authorizing that API client to send us user instructions on your behalf. Thus, when using an API client, you should always ensure that the security of the said client or device from which you access such client, is sufficiently and adequately secure from compromise. 

Certain external service providers may require you to give them your API Key to support convenience services. Giving away your API Key is akin to giving away your login credentials. Giving away your API Key to a third party also means the third-party can and will have access to all your Account details, data, and authority to make and give instructions to our API on your behalf. You should exercise extreme caution in verifying the credibility and reliability of third parties that request for your API Key.

APIs are subject to certain limitations such as limits for pulling or pushing data. API functions are also limited by the API commands that are available. APIs may also be victim of poor computer engineering and as a result suffer erroneous application or result in compromise.

You should understand and study the HashKey Global Exchange API Documentation (“API Documentation”) that is updated on our website from time to time with the prevailing limitations. These limitations, updates on bugs, addition, amendment, or removal of commands will affect your existing API client setup. Such changes may altogether affect (if on-going) the functioning of HashKey API and accordingly our services to you.

We may at times make amendments to HashKey API without prior notice to you or without updating the API Documentation. This may impact your use of HashKey API and you therefore understand and accept the risks set out in the Risk Disclosures herein and accept that it is your sole responsibility to keep yourself consistently updated on changes to the API Documentation and or these Terms (as defined hereunder).

 

2. Definitions and Interpretation

2.1 Defined terms shall have the same meaning as ascribed to it in the Investor Business Terms between the Client and the Company, otherwise in these API User Terms (“these Terms”), the following words and expression shall have the following meanings: -

“Agreement” means these Terms, being the written agreement between the Client and HBML regarding the access and operation of HashKey API as amended from time to time;

"API" means application programming interface;

“API Key” means a key or such license provided by HBML to access HashKey API (as defined below).

 

2.2 In the event of, and only to the extent of, any conflict or inconsistency among or between any provisions of these Terms and the Investor Business Terms, the Investor Business Terms shall prevail in so far as is necessary to resolve the conflict or inconsistency.

 

3. Services and Restrictions

3.1 HashKey API. Subject to the terms and conditions listed in these Terms, HBML hereby grants you a limited, non-exclusive, non-sublicensable, non-transferable, non-assignable and revocable license, to electronically access and use HashKey API solely for the following purposes:

  • Access information provided by HBML via the API (“HashKey API”) as permitted by HBML;
  • Retrieve market data of HBML;
  • Initiating and cancelling trading, withdrawal and transfer transactions on HBML; and
  • Retrieve asset balance.

HBML will provide the Client with an API Key to access and use HashKey API. This API Key, being the exclusive property of HBML, may be terminated or revoked at HBML's sole discretion if the Client's use of HashKey API is deemed to breach this Agreement. HBML reserves the right to update HashKey API from time to time, and such updates may necessitate Client action, including but not limited to, acceptance of any additional terms. In the event of such updates, the Client does not have the right to terminate this Agreement but is responsible for ensuring their use of HashKey API complies with the latest version and these Terms. Furthermore, HBML reserves the right to terminate this Agreement immediately at its sole discretion, particularly in instances where the Client breaches the terms of this Agreement. Upon such termination, the Client shall immediately stop using HashKey API. HBML may independently communicate with any relevant third-party, including third-parties to whom the Client has communicated its API Key, to provide notice of the termination of the Client’s right to use HashKey API.

 

3.2 Restrictions

(a) You shall not use HashKey API in any manner that is not authorized by this Agreement expressively.

(b) You shall not lease, sell, sublicense, assign, or otherwise transfer your rights to access Hashkey API to a third party.

(c) You shall not use Hashkey API for purposes of monitoring the availability of any HashKey Global products for competitive purposes.

(d) You shall not use Hashkey API for collecting, caching, aggregating, or storing data accessed via HashKey API other than for purposes allowed under this Agreement. You may not share such data or content with third parties in any manner without HBML’s prior written consent.

(e) You shall not use Hashkey API for any application that constitutes or uses in conjunction with spyware, adware, or any other malicious programs or codes.

(f) You shall not use Hashkey API to encourage, promote, or participate in illegal activity, violating intellectual property rights or privacy rights or Terms listed in this Agreement.

(g) You shall not use Hashkey API in a way that will exceed a reasonable usage, excessive request volume, or otherwise impacts the stability of HashKey Global's servers.

(h) You shall not modify or alter Hashkey API.

(i) You shall not attempt to circumvent any limitations on API requests HBML put in place.

 

3.3 Service Availability. HBML will use reasonable efforts to ensure that Hashkey API is available for use by the Client. However, HBML does not guarantee uninterrupted or error-free operation of Hashkey API, and shall not be liable for any loss or damages resulting from Hashkey API being temporarily unavailable due to technical issues beyond our control.

 

3.4 Data Protection and Privacy. The Client acknowledges that they have read and understood HBML's Privacy Policy as published on its website, which sets out how HBML collects, stores, uses, and protects the Client's personal data. By using Hashkey API, the Client consents to the collection and use of their data in accordance with HBML's Privacy Policy.

 

4. Content and IP Ownership

Except as otherwise provided in this Agreement, HBML retains all rights, title and interest in all intellectual property rights and improvements thereto associated with Hashkey API. You shall not take any action inconsistent with HBML’s ownership of Hashkey API and its content. If Client violates any portion of this Agreement, the license granted hereunder may be terminated at any time.

 

5. Security and Stability

You acknowledge that it is in the best interests of both parties that HashKey Global maintains a stable and secure environment. Thus, HBML reserves the right to change the method of access to Hashkey API. You also acknowledge and agree that, HBML may, in its sole discretion, temporarily suspend your access to Hashkey API (for example, by disabling your API Key) under this Agreement to minimize security threats and protect the operational stability and security of the HashKey Global system.

 

6. Indemnity and Exclusion of Liability

6.1 The Client hereby agrees to fully indemnify HBML, HBML’s directors, officers, employees, HBML’s Associated Entities and nominees and HBML’s Affiliates and keep all such persons indemnified against all claims, actions, liabilities, proceedings against any of such persons and bear any losses, costs, charges or expenses (including legal fees) (together “Losses”) which they may suffer in connection with a breach of this Agreement by Client save to the extent that such Losses arise directly or predominantly as a result of HBML’s negligence, fraud or willful default.

 

6.2 To the maximum extent permitted under applicable laws, HBML shall not be liable for any Losses suffered by the Client as a result of or in connection with the Client’s utilizing any of the services or in connection with these Terms other than Losses arising directly as a result of any gross negligence, fraud, or willful default on HBML’s part, or that of HBML’s Associated Entities, nominees or affiliates. HBML shall in no event be liable for any loss of profit, indirect, special or consequential damages of any kind or the default of HBML’s directors, officers, employees, Associated Entities, nominees or Affiliates or any person, firm or company through or with whom transactions are effected for the Account.

 

7. Representations, Warranties and Undertaking

7.1 Representations

The Client hereby warrants, represents and undertakes to HBML that:

(a) The Client is entering into these Terms as principal and is not trading on behalf of any other person unless HBML is notified otherwise in writing, in which case, the Client warrant that the Client is expressly authorized by the Client’s principal to effect all transactions pursuant to these Terms and the Client’s principal will duly perform all the obligations and liabilities arising out of these Terms, failing which the Client will be liable to HBML as if the Client were the principal in respect of such obligations and liabilities;

(b) (If being a natural person) The Client is of legal age to form a binding contract; or (If being a body corporate) the Client is validly incorporated and existing under the laws of its place of incorporation and has full power and capacity to enter into and perform the Client’s obligations hereunder;

(c) (If being a body corporate) The Client’s entry into of these Terms has been duly authorized by the Client’s governing body and does not breach the Client’s Articles of Association (and the Memorandum of Association if the Client has the same) or other constitutional documents (as applicable);

(d) The information provided by the Client to HBML through HashKey Global or otherwise from time to time is true, accurate and complete in all respects;

(e) The Client will enter into Digital Assets and/or Securities transactions solely in reliance upon the Client’s own judgment and investigations on the Digital Assets and/or Securities;

(f) These Terms constitutes a valid and legally binding agreement on the Client enforceable in accordance with its terms;

(g) These Terms and performance of the Client’s obligations contained herein do not and will not:

(i) contravene any existing applicable law, statute, ordinance, rule or regulation or any judgement, decree or permit to which The Client is subject; or

(ii) conflict with or result in any breach of the terms of or constitute any default under any agreement or other instrument to which the Client is a party or subject or by which any of the Client’s property is bound;

(h) Unless otherwise agreed by HBML, the Client is and will remain to be the beneficial owner of the Digital Assets and/or Securities in the Account free from any lien, charge, equity or encumbrance save as created by these Terms and will not charge, pledge or allow to subsist any charge or pledge over the Digital Assets and/or Securities or monies in the Account or grant or purport to grant an option over any Securities or monies in the Account without HBML’s prior written consent;

(i) The Client is the person ultimately responsible for originating the Instruction in relation to each transaction in the Account and shall stand to gain the commercial or economic benefit of such transactions and/or bear their commercial or economic risk (except where such other person or entity has been disclosed to HBML in writing and the arrangement has been agreed by HBML);

(j) The Client is solely and wholly responsible for the security of the Client’s Account and have not revealed any login details (including email address and/or passwords) of the Client’s Account to any unauthorized person. All actions being conducted through the Account are duly authorized by the Client.

 

7.2 The Client further undertakes that:

(a) The Client agrees that it shall use HashKey API at its own risks and is solely responsible for ensuring the security and integrity of its own devices, systems and applications;

(b) The Client’s right to use HashKey API may subject to additional terms, including limitations on use, found on the individual API Documentations of each API which we may amend from time to time without prior notice to the Client;

(c) The Client’s API Key is our sole means of verifying its access to HashKey API. The Client has read the Risk Disclosures above and understood the risks in relation to sharing, giving away or losing its API Key to any third-party.

(d) The Client is solely responsible for the security of its API Key and any compromise therefrom. HBML shall not be liable for executing any instructions or commands arising from the use of the Client’s API Key by any third-party.

(e) The Client agrees to immediately notify us upon becoming aware of any unauthorized use of HashKey API through its API Key. 

(f) The Client agrees that we may monitor its use of HashKey API to improve the service, track usage, to ensure compliance with these terms, or for security purposes.

(g) The Client agrees that HBML may audit its use of HashKey API or its API clients to the extent that we reasonably believe to verify compliance with this Agreement and identify security issues that may affect our service or our users. The Client agrees to cooperate with such audits and provide evidence that its use of HashKey API or its API clients complies with this Agreement. We reserve the right to immediately terminate the Client’s access to HashKey API should the Client refuse to cooperate with such audits or if this audit reveals that HashKey API was used in any way that contravene the terms of this Agreement or that we deem, in our sole discretion, constitute a security threat to our service or our users.

(h) The Client shall not misrepresent or mask its API client's identity when using HashKey API. The Client agrees that if he misrepresents or masks its API client's identity, HBML reserves the right to limit and restrict its use of HashKey API without prior notice.

(i) The Client agrees and shall cause its API client to use HashKey API in accordance with our published technical and other specifications, including all security requirements and procedures found on our website.

 

7.3 Repeating Nature

The representations, warrants and undertakings under this Clause shall be deemed to be repeated immediately before each Instruction is given or executed.

 

8. General Provisions

8.1 Invalidity

If anyone or more of the provisions contained in these Terms shall be invalid, unlawful or unenforceable in any respect under any applicable law, the validity, legality and enforceability of the remaining provisions contained herein shall not in any way be affected or impaired.

 

8.2 Assignment

(a) This agreement shall benefit and be binding on HBML and the Client, their respective successors and subject to this Clause 8.3, any permitted assignee or transferee of some or all of HBML’s rights or obligations under these Terms.

(b) The Client may not assign or transfer all or any of the Client’s rights or obligations under these Terms.

(c) HBML may assign or transfer all or part of HBML’s rights, benefits and obligations hereunder to such person(s) and disclose to a potential transferee or any other person proposing to enter into contractual arrangements with HBML in relation to these Terms such information about the Client as HBML may at HBML’s absolute discretion think fit.

 

8.3 Non-Waiver

Failure or delay in exercising any rights, power or privilege by HBML in respect of these Terms shall not operate as a waiver, nor shall a single or partial exercise, enforcement or waiver of any such rights, power or privilege preclude HBML from further exercise, enforcement, or the exercise or enforcement of any other right, power of privilege hereunder.

 

8.4 Joint and Several Liabilities

If the Client consists of more than one person, then the liabilities of each such person hereunder shall be joint and several. Any notice, payment or delivery by HBML to either or any one of the joint account holders shall be a full and sufficient discharge of HBML’s obligations to notify, pay or deliver under these Terms.

 

8.5 Material Change

Either party will notify the other in the event of any material change to the information contained in these Terms or provided to the other party pursuant to these Terms.

 

8.6 Disclaimer of Liabilities

To the maximum extent permitted under applicable laws, neither HBML, HBML’s Associated Entities or nominees nor HBML’s Affiliates shall be liable for any delay or failure to perform obligations and any losses, damages or costs resulting therefrom so long as they have acted in good faith. HBML will not be liable for any loss or damage that is caused by any malfunction of third party API client or other related interactions with any third party software with HashKey API. Moreover, HBML’s Associated Entities and nominee and HBML’s Affiliates shall not be held responsible for any consequences resulting whether directly or indirectly from any events not within their control including without limitation government restrictions, imposition of emergency procedures, exchange ruling, third party’s conduct, suspension of trading, war, strike, market conditions, civil disorder, acts or threatened acts of terrorism, natural disasters, or any other circumstances beyond their control whatsoever.

 

9. Language

These Terms are written in an English version and a Chinese version. In the event of any conflict between the two versions, the English version shall take precedence.

 

10. Amendment

HBML shall have absolute rights to amend, delete or substitute any of the terms herein or add new terms to these Terms. The Client should visit the website from time to time for obtaining the latest Agreement and read the terms thereof. Such amendment, deletion, substitution or addition shall be deemed as effective and incorporated herein (and shall form part of these Terms) on the date of publication of the revised Agreement. The Client may raise written objection within fourteen (14) Business Days after the publication of the revised Agreement at the website, failing which it shall be deemed an acceptance of such amendment, deletion, substitution or addition.

 

If the Client has any queries relating to these Terms, please address them by email to global-api@hashkey.com


 

See more
icon