Legal

Privacy Policy

Last updated: July 2026

1. About this policy

This Privacy Policy describes how Traffic Infrastructure Limited, a company established in Hong Kong (“Company”, “we”, “us” or “our”), collects, uses, discloses, stores and protects personal data.

It applies to personal data handled through:

A separate Personal Information Collection Statement is presented when we collect personal data directly from you.

2. Our role and contact details

For Hong Kong privacy purposes, the Company is the data user responsible for the personal data described in this policy.

Where the EU General Data Protection Regulation, UK GDPR or similar legislation applies, the Company will generally act as the controller of that personal data.

3. Personal data we process

3.1 Identity and contact information

This may include:

3.2 Corporate, ownership and authority information

This may include:

3.3 Financial and source-of-funds information

This may include:

We do not request online-banking passwords, private wallet keys, recovery phrases or authentication codes. You should never provide them to us.

3.4 Blockchain and virtual-asset information

This may include:

3.5 Screening and risk information

This may include:

3.6 Technical and website information

This may include:

3.7 Communications

We may retain emails, secure messages, support requests, complaints, instructions, confirmations and records of meetings or calls.

4. Sources of personal data

We may obtain personal data from:

If you provide another person’s personal data, you must be authorized to do so and ensure that the person receives any notice required by applicable law.

5. Purposes and legal bases

We process personal data for the following purposes:

PurposeTypical GDPR legal basis, where applicable
Customer onboarding and account administrationContractual necessity; legitimate interests
Identity, ownership and authority verificationLegal obligation; contractual necessity; legitimate interests
Source-of-funds and transaction-purpose assessmentLegal obligation; legitimate interests in preventing misuse and managing risk
Sanctions, PEP, fraud and blockchain screeningLegal obligation; legitimate interests in compliance, security and fraud prevention
Arranging and settling customer transactionsContractual necessity
Fees, refunds, reconciliation and accountingContractual necessity; legal obligation
Customer support and communicationsContractual necessity; legitimate interests
Cybersecurity and access controlLegal obligation; legitimate interests
Audit, tax and business recordsLegal obligation; legitimate interests
Complaints, investigations and legal claimsLegal obligation; legitimate interests; establishment or defence of legal claims
Service improvement and analyticsLegitimate interests; consent where required
Direct marketingConsent or legitimate interests where permitted, with an opt-out
Corporate transactions and restructuringLegitimate interests; legal obligation

Where we rely on legitimate interests, we consider the necessity of the processing and its potential effect on individual rights. You may contact us for information about a relevant assessment.

We do not use consent where processing is necessary to provide the requested service or comply with an applicable obligation. Where consent is used, it may be withdrawn at any time without affecting earlier lawful processing.

6. Public blockchains

Public blockchains are independently operated, distributed records. Wallet addresses, transaction amounts, timestamps and transaction hashes may be publicly visible and permanently replicated.

The Company generally cannot amend, suppress or delete information recorded on a public blockchain. A deletion request can therefore apply to personal data controlled in our off-chain systems but cannot compel alteration of the underlying blockchain.

You must not provide us with a private key, seed phrase or wallet-recovery credential.

7. Verification, profiling and automated processing

We may use technology to:

Material alerts and adverse onboarding or transaction decisions should ordinarily receive human review. Our systems are intended to support reviewers rather than make legally or similarly significant decisions solely through automated processing.

If we introduce solely automated decisions producing legal or similarly significant effects, we will provide any additional notice and safeguards required by applicable law. Where applicable, you may request human intervention, express your position and contest the decision.

We do not disclose confidential screening rules where disclosure would undermine fraud prevention, security, legal restrictions or the rights of others.

8. Disclosure of personal data

We may disclose personal data to:

Service providers may process personal data only for authorized purposes and are expected to be subject to appropriate confidentiality, security and retention obligations.

We do not disclose personal data to an issuer or blockchain participant merely because a public wallet transaction is visible, although those parties may independently observe public blockchain activity.

9. Sale, sharing and targeted advertising

We do not sell personal data for money.

We do not sell or share personal data as those terms are defined under the California Consumer Privacy Act for cross-context behavioural advertising, and we do not use personal data for targeted advertising based on activity across unrelated businesses.

If these practices change, we will update this policy and provide legally required notices and opt-out mechanisms.

We do not use or disclose sensitive personal information to infer characteristics about individuals for advertising purposes.

10. International transfers

Our administration is based in Hong Kong. Personal data may be processed in Hong Kong and in other countries where our service providers operate.

Where EU, UK or other cross-border transfer requirements apply, we will use an available lawful transfer mechanism, which may include:

Safeguards may include encryption, pseudonymization, access restrictions, transfer-risk assessments and contractual controls.

You may contact us for information about the transfer mechanism relevant to your personal data.

11. Retention

We retain personal data according to its purpose, sensitivity, applicable obligations and the need to establish or defend legal claims.

Typical periods are:

Record categoryTypical retention
Completed onboarding, customer, transaction, accounting and tax recordsAt least seven years after the transaction or end of the relationship
Screening and transaction-monitoring recordsGenerally seven years, or longer where legally required
Unsuccessful or withdrawn applicationsNormally up to two years, unless a longer fraud-prevention, legal or investigation hold applies
Complaints and disputesDuration of the matter plus the applicable limitation period
Security and audit logsNormally 12–24 months unless required for an investigation
Marketing preferencesUntil withdrawal, plus a minimal suppression record
CookiesAccording to the duration stated in our cookie settings or Cookie Notice

We may retain information longer where required by law, court order, investigation, regulatory request, sanctions requirement, dispute or legal hold.

When personal data is no longer required, we take reasonable steps to delete it, anonymize it or securely isolate it from ordinary use. Public blockchain records are not controlled or erasable by us.

12. Security

We use administrative, physical and technical safeguards appropriate to the nature and risk of the personal data processed. These may include:

No transmission or storage system is completely secure. You are responsible for protecting account credentials and promptly notifying us of suspected unauthorized access.

13. Your privacy rights

Rights vary by jurisdiction and are subject to legal exceptions.

13.1 Hong Kong

Under the Personal Data (Privacy) Ordinance, you may request access to personal data held about you and correction of inaccurate personal data. A reasonable fee may be charged for an access request where permitted.

13.2 European Economic Area and United Kingdom

Where GDPR or UK GDPR applies, you may have rights to:

13.3 United States

Residents of California and certain other US states may, subject to applicable thresholds and exceptions, have rights to:

Because we do not sell or share personal information for targeted advertising, there is presently no such processing from which to opt out.

14. Exercising your rights

Submit a request through:

Please describe the request and the relationship through which we collected your data. We may request information reasonably necessary to verify identity, authority and jurisdiction.

An authorized agent must provide evidence of authority, and we may verify the request directly with the individual where permitted.

We will respond within the period required by applicable law. If a request is refused or restricted, we will explain the applicable reason where legally permitted and provide appeal information where required.

15. Children

Our services are intended for businesses and persons aged 18 or older acting in a business capacity. We do not knowingly offer services to or collect personal data directly from children.

If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.

16. Third-party services and links

Our website may link to third-party websites or services. Their privacy practices are governed by their own notices, not this policy.

Liquidity providers, banks and other independent transaction participants may act as separate controllers or data users for information they receive. You should review their privacy notices where applicable.

17. Complaints

Please contact us first so that we can investigate a privacy concern.

You may also complain to an applicable authority, including:

18. Changes to this policy

We may update this policy to reflect changes in our services, systems, providers or legal obligations.

The updated policy will be posted with a revised “Last updated” date. Where a change is material, we will provide additional notice through the website, customer portal, email or another appropriate channel.

Questions about this policy or your personal data: admin@otc.business. See also our Personal Information Collection Statement.