Privacy Policy
Solicitor note: This document is a structural skeleton for GDPR-compliant privacy notice. All bracketed and lorem ipsum text must be reviewed by a qualified data protection solicitor before publication. A Data Protection Impact Assessment (DPIA) should be completed separately.
1. Who We Are
[LEGAL ENTITY NAME] ("Coinfidence", "we", "us", "our"), incorporated in [JURISDICTION] with registered number [COMPANY NUMBER], is the data controller responsible for your personal data.
Our Data Protection Officer (or designated contact) can be reached at: privacy@coinfidence.com
[Lorem ipsum dolor sit amet, consectetur adipiscing elit. Solicitor to confirm data controller status, joint controller arrangements if applicable, and ICO registration details.]
2. Data We Collect
We collect the following categories of personal data when you use our Services:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Name, date of birth, government ID, selfie for verification | Provided by you; verification partners |
| Contact Data | Email address, phone number, postal address | Provided by you |
| Financial Data | Bank account details, card numbers (tokenised), wallet addresses | Provided by you; payment processors |
| Transaction Data | Payment amounts, timestamps, currency, counterparty information | Generated by your use of Services |
| Technical Data | IP address, browser type, device identifiers, cookies | Collected automatically |
| Usage Data | Log data, feature usage, clickstreams, session recordings | Collected automatically |
| Communications | Support messages, email correspondence, survey responses | Provided by you |
| [ADDITIONAL CATEGORIES] | [Solicitor to complete] | [Solicitor to complete] |
3. How We Use Your Data
We use your personal data for the following purposes:
- Providing, operating, and improving the Services
- Verifying your identity and conducting KYC/AML checks
- Processing transactions and preventing fraud
- Complying with legal and regulatory obligations
- Communicating with you about your Account and the Services
- Analysing usage to improve platform performance and security
- [ADDITIONAL PURPOSES TO BE CONFIRMED BY SOLICITOR]
4. Legal Bases for Processing
Under the UK GDPR and applicable data protection law, we rely on the following legal bases:
- Contract: Processing necessary to perform our contract with you (e.g., processing payments, managing your Account).
- Legal obligation: Processing required to comply with applicable laws (e.g., AML/KYC, tax reporting, financial services regulation).
- Legitimate interests: Where our legitimate business interests outweigh your rights (e.g., fraud prevention, security, analytics).
- Consent: Where you have given explicit consent (e.g., marketing communications, non-essential cookies).
- [SPECIAL CATEGORY DATA - Solicitor to confirm legal basis and safeguards if applicable]
5. Data Sharing
We may share your personal data with the following categories of recipients:
- Payment processors and banking partners: To facilitate transactions
- Identity verification providers: To complete KYC requirements
- Cloud infrastructure providers: Hosting and data storage
- Fraud prevention services: To detect and prevent financial crime
- Regulatory and law enforcement authorities: Where required by law
- Professional advisors: Legal, accounting, and audit services
- [ADDITIONAL RECIPIENTS - Solicitor to complete list and confirm data sharing agreements]
We do not sell your personal data to third parties for their own marketing purposes.
6. International Data Transfers
[Lorem ipsum placeholder. Solicitor to draft provisions covering: identification of third countries receiving data, transfer mechanisms used (adequacy decisions, SCCs, BCRs), and any supplementary measures applied. Particular attention to post-Brexit UK transfer rules.]
7. Data Retention
[Lorem ipsum placeholder for retention schedule. Solicitor to draft retention periods for each data category, including AML record-keeping obligations (typically 5 years post-relationship end), transaction records, and criteria used to determine retention periods where statutory periods do not apply.]
8. Your Rights
Under applicable data protection law, you have the following rights in relation to your personal data:
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request).
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data in certain circumstances ("right to be forgotten").
Right to Restriction
Request that we restrict processing of your data in certain circumstances.
Data Portability
Receive your data in a structured, commonly used, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Automated Decisions
Not be subject to solely automated decisions with significant legal effects.
Withdraw Consent
Withdraw consent at any time where we rely on consent for processing.
To exercise any of these rights, please contact us at privacy@coinfidence.com or through our contact form. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
9. Cookies
[Lorem ipsum placeholder for cookie policy. Solicitor to draft provisions covering: categories of cookies (essential, functional, analytics, marketing), consent management, third-party cookies, and cookie retention periods. Should reference cookie banner/preference centre if deployed.]
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include [SPECIFIC MEASURES TO BE CONFIRMED WITH SECURITY TEAM AND SOLICITOR].
For more information about our security practices, see our Security page.
11. Children
The Services are not directed to individuals under [AGE]. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@coinfidence.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by [NOTIFICATION METHOD] before the changes take effect. The date at the top of this page indicates when the policy was last revised.
13. Contact
For privacy-related queries or to exercise your rights, contact our Data Protection contact:
- Email: privacy@coinfidence.com
- Post: [REGISTERED ADDRESS], Attn: Data Protection
- Online: Contact form