This Personal Information Collection Statement explains how Traffic Infrastructure Limited, a company established in Hong Kong (“Company”, “we”, “us” or “our”), collects and uses personal data when you:
- apply for or maintain a customer account;
- act as a director, beneficial owner, authorized representative or contact person for a customer;
- request or use our agency on-ramp or related services;
- communicate with us; or
- use otc.business.
Please read this statement before providing personal data.
1. Personal data we collect
Depending on your relationship with us, we may collect:
- your name, date of birth, nationality, residential address, business contact details and signature;
- identity-document information and copies;
- photographs, electronic-verification results and, where necessary, liveness or facial-verification data;
- employment, position and authority to act for a customer;
- direct and indirect ownership, beneficial ownership and control information;
- company-registration documents, ownership charts, resolutions and authorization records;
- bank-account holder information and evidence concerning source of funds or source of wealth;
- transaction purpose, expected activity, payment instructions and settlement records;
- blockchain network, wallet address, transaction hash and wallet-ownership evidence;
- sanctions, politically exposed person, adverse-media, fraud and blockchain-screening results;
- communications, support requests, complaints and call or meeting records;
- IP address, device, browser, login, audit-log and website-usage information; and
- risk indicators and decisions generated from the information above.
We may obtain information from you, the customer you represent, other connected persons, company and beneficial-ownership registers, identity-verification providers, banks, liquidity providers, screening providers, blockchain analytics services, public blockchains, professional advisers and publicly available sources.
2. Why we collect and use personal data
We may use personal data to:
- identify and verify customers, beneficial owners, directors and authorized representatives;
- understand ownership and control structures;
- confirm authority to act;
- assess customer eligibility and transaction risk;
- verify source of funds, payment origin and wallet ownership;
- conduct sanctions, PEP, adverse-media, fraud and blockchain-risk screening;
- establish, administer and secure customer accounts;
- obtain and execute customer instructions;
- arrange purchases through liquidity providers;
- reconcile fiat payments, fees and virtual-asset settlements;
- provide transaction confirmations and customer support;
- prevent, detect and investigate fraud, misuse, security incidents and unlawful activity;
- maintain accounting, tax, transaction, audit and business records;
- manage legal claims, complaints and disputes;
- comply with applicable legal, regulatory, court, law-enforcement and reporting requirements;
- protect our rights, systems, personnel, customers and business partners; and
- improve the security, reliability and operation of our services.
Where GDPR or similar laws apply, we generally process personal data because processing is:
- necessary to take steps at your request or perform a contract;
- necessary to comply with legal obligations;
- necessary for our legitimate interests in operating a secure business, verifying customers, preventing fraud, managing risk and maintaining records;
- necessary to establish, exercise or defend legal claims; or
- based on consent, where consent is specifically requested.
You may withdraw consent at any time. Withdrawal does not affect processing already undertaken lawfully or processing supported by another legal basis.
3. Required and optional information
Fields marked as required are obligatory for onboarding, verification, account administration or transaction processing. If required information is not provided, we may be unable to:
- complete onboarding;
- verify your identity, ownership or authority;
- approve or execute a transaction;
- maintain the business relationship; or
- provide the requested service.
Information identified as optional may be withheld without preventing submission, although this may limit certain features or our ability to respond to a request.
4. Who may receive personal data
Where reasonably necessary for the purposes above, we may transfer personal data to the following classes of recipients:
- our directors, officers, employees and contractors with a business need to access it;
- banks, payment providers and financial institutions;
- liquidity providers, exchanges and transaction counterparties;
- identity, company, sanctions, PEP, adverse-media, fraud and blockchain-screening providers;
- cloud-hosting, storage, cybersecurity, communications and technical-support providers;
- auditors, accountants, insurers, lawyers and other professional advisers;
- potential purchasers, investors or successors involved in a proposed corporate transaction, subject to appropriate confidentiality safeguards;
- courts, law-enforcement bodies, regulators, tax authorities and other competent authorities; and
- other persons where you direct or authorize disclosure or where disclosure is legally permitted or required.
We do not sell personal data for money. We do not share personal data for cross-context behavioural advertising unless this statement and our Privacy Policy are updated and any legally required opt-out mechanism is provided.
5. International transfers
The Company is administered from Hong Kong. Some recipients or technology systems may be located outside Hong Kong, the European Economic Area, the United Kingdom or your place of residence.
Where legally required, we use appropriate transfer safeguards, which may include contractual protections, standard contractual clauses, transfer assessments, access controls and other supplementary safeguards. You may contact us for information about safeguards applicable to your data.
6. Screening and decisions
We use screening systems to identify sanctions, PEP, adverse-media, fraud and blockchain-risk indicators. These systems may produce alerts or risk indicators, but material adverse decisions should ordinarily be reviewed by authorized personnel.
Where applicable law gives you rights concerning a decision based solely on automated processing that produces legal or similarly significant effects, you may request human review, express your position and challenge the decision.
7. Public blockchain information
Blockchain wallet addresses and transactions may be publicly visible, permanent and independently replicated. We cannot alter or delete information written to a public blockchain by you, a liquidity provider or another participant.
We will seek to minimize unnecessary public linkage between a wallet address and directly identifying off-chain information.
8. Retention
Transaction, accounting, audit and tax records will generally be retained for at least seven years after the relevant transaction or the end of the business relationship.
Other personal data is retained only for as long as reasonably necessary for the purposes described above, including verification, fraud prevention, security, legal claims and dispute management. Longer retention may apply where required by law, court order, investigation or legal hold.
9. Your rights
Depending on your location and applicable law, you may have rights to:
- request access to personal data held about you;
- request correction of inaccurate or incomplete data;
- request deletion or erasure;
- restrict or object to processing;
- receive certain data in a portable format;
- withdraw consent;
- opt out of sale, sharing, targeted advertising or qualifying profiling;
- limit certain uses of sensitive personal information;
- request human review of certain automated decisions;
- appeal a refusal of a privacy request; and
- lodge a complaint with an applicable privacy or data-protection authority.
These rights may be limited by applicable exemptions, including record-retention, fraud-prevention, legal-claim and regulatory requirements.