Last updated: July 2026
This Privacy Policy describes how Traffic Infrastructure Limited, a company established in Hong Kong (“Company”, “we”, “us” or “our”), collects, uses, discloses, stores and protects personal data.
It applies to personal data handled through:
A separate Personal Information Collection Statement is presented when we collect personal data directly from you.
For Hong Kong privacy purposes, the Company is the data user responsible for the personal data described in this policy.
Where the EU General Data Protection Regulation, UK GDPR or similar legislation applies, the Company will generally act as the controller of that personal data.
This may include:
This may include:
This may include:
We do not request online-banking passwords, private wallet keys, recovery phrases or authentication codes. You should never provide them to us.
This may include:
This may include:
This may include:
We may retain emails, secure messages, support requests, complaints, instructions, confirmations and records of meetings or calls.
We may obtain personal data from:
If you provide another person’s personal data, you must be authorized to do so and ensure that the person receives any notice required by applicable law.
We process personal data for the following purposes:
| Purpose | Typical GDPR legal basis, where applicable |
|---|---|
| Customer onboarding and account administration | Contractual necessity; legitimate interests |
| Identity, ownership and authority verification | Legal obligation; contractual necessity; legitimate interests |
| Source-of-funds and transaction-purpose assessment | Legal obligation; legitimate interests in preventing misuse and managing risk |
| Sanctions, PEP, fraud and blockchain screening | Legal obligation; legitimate interests in compliance, security and fraud prevention |
| Arranging and settling customer transactions | Contractual necessity |
| Fees, refunds, reconciliation and accounting | Contractual necessity; legal obligation |
| Customer support and communications | Contractual necessity; legitimate interests |
| Cybersecurity and access control | Legal obligation; legitimate interests |
| Audit, tax and business records | Legal obligation; legitimate interests |
| Complaints, investigations and legal claims | Legal obligation; legitimate interests; establishment or defence of legal claims |
| Service improvement and analytics | Legitimate interests; consent where required |
| Direct marketing | Consent or legitimate interests where permitted, with an opt-out |
| Corporate transactions and restructuring | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we consider the necessity of the processing and its potential effect on individual rights. You may contact us for information about a relevant assessment.
We do not use consent where processing is necessary to provide the requested service or comply with an applicable obligation. Where consent is used, it may be withdrawn at any time without affecting earlier lawful processing.
Public blockchains are independently operated, distributed records. Wallet addresses, transaction amounts, timestamps and transaction hashes may be publicly visible and permanently replicated.
The Company generally cannot amend, suppress or delete information recorded on a public blockchain. A deletion request can therefore apply to personal data controlled in our off-chain systems but cannot compel alteration of the underlying blockchain.
You must not provide us with a private key, seed phrase or wallet-recovery credential.
We may use technology to:
Material alerts and adverse onboarding or transaction decisions should ordinarily receive human review. Our systems are intended to support reviewers rather than make legally or similarly significant decisions solely through automated processing.
If we introduce solely automated decisions producing legal or similarly significant effects, we will provide any additional notice and safeguards required by applicable law. Where applicable, you may request human intervention, express your position and contest the decision.
We do not disclose confidential screening rules where disclosure would undermine fraud prevention, security, legal restrictions or the rights of others.
We may disclose personal data to:
Service providers may process personal data only for authorized purposes and are expected to be subject to appropriate confidentiality, security and retention obligations.
We do not disclose personal data to an issuer or blockchain participant merely because a public wallet transaction is visible, although those parties may independently observe public blockchain activity.
We do not sell personal data for money.
We do not sell or share personal data as those terms are defined under the California Consumer Privacy Act for cross-context behavioural advertising, and we do not use personal data for targeted advertising based on activity across unrelated businesses.
If these practices change, we will update this policy and provide legally required notices and opt-out mechanisms.
We do not use or disclose sensitive personal information to infer characteristics about individuals for advertising purposes.
Our administration is based in Hong Kong. Personal data may be processed in Hong Kong and in other countries where our service providers operate.
Where EU, UK or other cross-border transfer requirements apply, we will use an available lawful transfer mechanism, which may include:
Safeguards may include encryption, pseudonymization, access restrictions, transfer-risk assessments and contractual controls.
You may contact us for information about the transfer mechanism relevant to your personal data.
We retain personal data according to its purpose, sensitivity, applicable obligations and the need to establish or defend legal claims.
Typical periods are:
| Record category | Typical retention |
|---|---|
| Completed onboarding, customer, transaction, accounting and tax records | At least seven years after the transaction or end of the relationship |
| Screening and transaction-monitoring records | Generally seven years, or longer where legally required |
| Unsuccessful or withdrawn applications | Normally up to two years, unless a longer fraud-prevention, legal or investigation hold applies |
| Complaints and disputes | Duration of the matter plus the applicable limitation period |
| Security and audit logs | Normally 12–24 months unless required for an investigation |
| Marketing preferences | Until withdrawal, plus a minimal suppression record |
| Cookies | According to the duration stated in our cookie settings or Cookie Notice |
We may retain information longer where required by law, court order, investigation, regulatory request, sanctions requirement, dispute or legal hold.
When personal data is no longer required, we take reasonable steps to delete it, anonymize it or securely isolate it from ordinary use. Public blockchain records are not controlled or erasable by us.
We use administrative, physical and technical safeguards appropriate to the nature and risk of the personal data processed. These may include:
No transmission or storage system is completely secure. You are responsible for protecting account credentials and promptly notifying us of suspected unauthorized access.
Rights vary by jurisdiction and are subject to legal exceptions.
Under the Personal Data (Privacy) Ordinance, you may request access to personal data held about you and correction of inaccurate personal data. A reasonable fee may be charged for an access request where permitted.
Where GDPR or UK GDPR applies, you may have rights to:
Residents of California and certain other US states may, subject to applicable thresholds and exceptions, have rights to:
Because we do not sell or share personal information for targeted advertising, there is presently no such processing from which to opt out.
Submit a request through:
Please describe the request and the relationship through which we collected your data. We may request information reasonably necessary to verify identity, authority and jurisdiction.
An authorized agent must provide evidence of authority, and we may verify the request directly with the individual where permitted.
We will respond within the period required by applicable law. If a request is refused or restricted, we will explain the applicable reason where legally permitted and provide appeal information where required.
Our services are intended for businesses and persons aged 18 or older acting in a business capacity. We do not knowingly offer services to or collect personal data directly from children.
If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
Our website may link to third-party websites or services. Their privacy practices are governed by their own notices, not this policy.
Liquidity providers, banks and other independent transaction participants may act as separate controllers or data users for information they receive. You should review their privacy notices where applicable.
Please contact us first so that we can investigate a privacy concern.
You may also complain to an applicable authority, including:
We may update this policy to reflect changes in our services, systems, providers or legal obligations.
The updated policy will be posted with a revised “Last updated” date. Where a change is material, we will provide additional notice through the website, customer portal, email or another appropriate channel.