Privacy Policy.
What we collect, why we collect it, who we share it with, and the rights you have over it. No dark patterns, no buried opt-outs.
Data Controller
Stigmarix LLC (filing number LC014778460), a limited liability company registered in Missouri, USA, with its principal office at 2345 Grand Blvd, Kansas City, MO 64108, USA, is the data controller for personal data processed through the Services.
What We Collect
| Category | Examples | Source |
|---|---|---|
| Identity | Full name, date of birth, nationality, government ID images, selfie, proof of address | You, during KYC |
| Contact | Email, phone, postal address | You |
| Financial | Bank account details, payment card metadata, deposit/withdrawal history, trade history, wallet addresses | You + banking partners |
| Account | Username, hashed password, 2FA secrets, API keys, session tokens | You + our systems |
| Device & technical | IP address, device ID, browser type, OS, app version, approximate location | Automatic |
| Usage | Pages viewed, features used, orders placed, preferences, support conversations | Automatic |
| Compliance | Sanctions-screening results, PEP status, source-of-funds documentation | Third-party providers + us |
How We Use It
- Provide the Services — create your account, authenticate you, execute trades, process deposits and withdrawals.
- Verify identity — comply with our legal obligations under the UK Money Laundering Regulations 2017.
- Prevent fraud and abuse — detect suspicious activity, investigate security incidents.
- Support you — respond to tickets, resolve disputes, communicate service updates.
- Improve the platform — aggregated analytics, A/B testing, product research.
- Marketing — only with your consent, and always with a one-click unsubscribe.
Legal Basis (UK GDPR)
| Purpose | Lawful basis |
|---|---|
| Providing the Services under your account | Contract — Art. 6(1)(b) |
| KYC, AML, sanctions screening, record-keeping | Legal obligation — Art. 6(1)(c) |
| Fraud prevention, security, service improvement | Legitimate interests — Art. 6(1)(f) |
| Marketing emails, optional analytics cookies | Consent — Art. 6(1)(a) |
International Transfers
Most personal data stays within the UK and the EEA. Where transfers outside the UK/EEA are necessary, we rely on UK International Data Transfer Agreements or the EU Standard Contractual Clauses with the UK Addendum.
Retention Periods
| Data | Period |
|---|---|
| KYC records, transaction logs | 5 years after account closure |
| Tax & accounting records | 6 years (HMRC) |
| Account & trade history | For the life of your account + 5 years |
| Support tickets | 3 years after resolution |
| Marketing preferences | Until you withdraw consent |
| Server & security logs | 13 months |
How We Protect It
- AES-256 encryption at rest; TLS 1.3 in transit.
- Hardware security modules (HSM) for signing keys; MPC for crypto custody.
- Mandatory 2FA for staff; just-in-time privileged access; full audit logs.
- Annual SOC 2 Type II audit and a public security bounty programme.
Your Rights
Under the UK GDPR you have the right to access, rectify, erase, restrict, port, and withdraw consent for your data. Email Contact support to exercise these rights.
Children
The Services are not directed at persons under 18. We do not knowingly collect personal data from children.
Changes
Material changes are communicated by email and in-app notice at least 30 days before they take effect.
Contact & Complaints
Data Protection Officer
Stigmarix LLC
2345 Grand Blvd, Kansas City, MO 64108, USA
Email: Contact support
We collect the data we need to run a regulated crypto platform. We don't sell it, we don't profile-ad you. You can see, correct, export, or delete most of it on request.