Privacy Policy

PRIVACY POLICY OF THE UNIONXBIT SERVICE

1. General Provisions

1.1. This Privacy Policy (hereinafter referred to as the “Policy”) defines the procedure for collecting, processing, storing, and protecting the personal data of users (hereinafter referred to as the “User”) of the UnionXbit exchange service (hereinafter referred to as the “Service”).

1.2. This Policy has been developed in accordance with international personal data protection standards, including the principles of the GDPR (General Data Protection Regulation of the EU), and applies throughout the entire territory where the Service is provided.

1.3. By using the Service, the User expresses their full and unconditional consent to the terms of this Policy. If the User disagrees with any part of this Policy, they must cease using the Service.

2. Categories of Data Collected

2.1. The Service may collect the following categories of personal data:

  • Registration data: email address, mobile phone number, login, password (in hashed form).
  • Identification data (KYC): last name, first name, patronymic; date and place of birth; citizenship; identity document details (series, number, date of issue, issuing authority); registration and actual residence address; photographs/scans of documents; selfie with document; video verification recordings.
  • Payment data: bank card details (first 6 and last 4 digits, expiration date), bank account numbers, cryptocurrency wallet addresses, transaction history.
  • Technical data: IP address; device information (type, model, operating systеm, browser version, user-agent); cookies; geolocation; time zone; actions on the Website (clicks, page views).
  • AML data: transaction verification results, risk scores, tags received from AML providers (Getblock, Crystal, etc.), information regarding connections with suspicious addresses.
  • Communication data: correspondence with support service, inquiries, complaints.

3. Purposes of Personal Data Processing

3.1. The Service processes personal data solely for the following purposes:

  • identification and verification of the User (KYC);
  • execution of exchange orders and transaction processing;
  • combating money laundering and terrorist financing (AML/CFT);
  • ensuring security and preventing fraud;
  • improving the quality of the Service, analyzing user experience;
  • technical support and providing information on order status;
  • compliance with applicable legal requirements and cooperation with government authorities.

4. Legal Grounds for Processing

4.1. The processing of personal data is carried out on the following grounds:

  • the User’s consent, expressed during registration and use of the Service;
  • performance of a contract (the User Agreement) between the Service and the User;
  • the legitimate interest of the Service in preventing financial crimes and ensuring security;
  • compliance with legal obligations under applicable law.

5. Transfer of Personal Data to Third Parties

5.1. The Service may transfer the User’s personal data to third parties only in the following cases:

  • To AML providers (Getblock, Crystal, etc.) – for transaction verification and risk score calculation. These companies are obligated to ensure the confidentiality and security of the data.
  • To payment partners (banks, payment systems, processors) – for processing fiat transfers and executing orders.
  • To verification partners (e.g., Sumsub) – for conducting KYC checks.
  • To government authorities – upon an official reasoned request as part of investigations, legal proceedings, or legal requirements.

5.2. The Service requires all third parties to implement adequate data protection measures and to use the data only for the specified purposes.

6. Data Retention Periods

6.1. The User’s personal data is stored for the duration of the account’s validity, and after its closure – for at least 5 (five) years from the date of the last transaction or inquiry.

6.2. Upon expiration of the retention period, the data is destroyed or anonymized.

7. Data Protection Measures

7.1. The Service takes the necessary organizational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, distribution, as well as from other unlawful actions:

  • use of secure data transfer protocols (HTTPS, SSL/TLS);
  • encryption of confidential information during storage;
  • differentiation of employee access to data;
  • regular data backup;
  • monitoring of unauthorized access attempts.

7.2. Access to data is granted only to authorized employees who have been instructed on handling confidential information.

8. Cookies

8.1. The Service uses cookies to ensure the functionality of the website, collect statistics, and improve user experience. The User may configure their browser to refuse cookies; however, this may affect the availability of certain functions.

9. Amendments to the Privacy Policy

9.1. The Service has the right to unilaterally amend this Policy. The current version is always available on the Website. Amendments take effect upon publication.

9.2. Continued use of the Service after amendments are made implies the User’s consent to the new version.

Choose file
Give
Get
Exchange
days
hours

Мы работаем ПН-ПТ с 10:00 до 20:00 по МСК. Будем рады видеть Вас в рабочее время!