GOLDENGATEX PRIVACY AND PERSONAL DATA PROCESSING POLICY
POLICY 1. General provisions
1.1. This Policy defines the procedure for processing, storing and protecting personal data of users of the site goldengatex.net
1.2. Personal data operator: GOLDENGATEX.
1.3. The User provides active consent to this Policy by means of a mandatory checkbox when creating an Application.
1.4. The following definitions are used in this Policy:
1.4.1 Personal Data is any information related to a directly or indirectly identified individual (user).
1.4.2. Processing – any action (operation) or set of actions with personal data, including collection, recording, systematization, accumulation, storage, clarification, use, transfer (provision, access), blocking, deletion.
1.4.3 Operator – a person who organizes and/or performs the processing of personal data.
1.4.4. The User is an individual using the Operator's services.
2. Composition of the processed data
2.1. Contact information: e-mail, Telegram ID, other contacts provided by the User.
2.2. Application data: amounts, payment details (within the limits entered by the User), TxID, addresses of crypto wallets, correspondence with support.
2.3. Technical data: IP, user-agent, cookies, date/time of anti-fraud metrics; type of action performed on the Site (click, hover, etc.); last visit and activity; screen resolution; User device type; User location; User language; language of the operating system, device, browser User; information about the theme of the User's device (day or night); the class of the HTML element that is clicked on
2.4. KYC/SoF data: User's identity documents, his photo as biometric personal data; address confirmation; User's card data; statements/receipts/explanations, and other evidence of the origin of funds.
3. Purposes of personal data processing
3.1. Provision of website functionality and Application execution.
3.2. AML/KYC/SoF-control, fraud prevention, ensuring the safety of Users and operations.
3.3. User support, review of claims and dispute resolution.
3.4. Performance of duties at the request of authorized bodies, if there are legitimate grounds.
4. Legal grounds for processing personal data
4.1. User's consent.
4.2. Execution of the user agreement (public offer) and provision of services.
4.3. Legitimate interests of the Operator in ensuring security, fraud prevention and compliance with AML procedures.
5. Transfer of personal data to third parties
5.1. The Operator has the right to transfer personal data to third parties only to the extent necessary for the purposes specified in this Policy, including:
5.1.1. at the legitimate request of the competent authorities;
5.1.2. contract handlers (hosting, e-mail/chat providers, infrastructure contractors) – strictly to the extent necessary for the work;
5.1.3. AML analyzers – in the amount of addresses/txids/ technical parameters of verification.
5.2. The Operator does not provide access to Users' personal data on a paid basis and does not disclose them to third parties, except in cases listed in clause 5.1 of this Policy.
6. Personal data retention periods
6.1. Application data and logs: 36 months.
6.2. KYC/SoF materials: 5 years.
6.3. If there is a claim/dispute, the storage may be extended until the end of the proceedings.
6.4. After the expiration of the storage period, personal data must be destroyed.
7. Secure data collection and protection
7.1. Data transmission is carried out over secure channels (HTTPS/TLS).
7.2. KYC/SoF materials are accepted only through secure channels/forms/personal account (if available), access to them is limited.
7.3. The access of the Operator's employees to the data is provided by roles based on the “need to know” principle only to the extent necessary for the proper performance of their duties.
7.4. Access to KYC/SoF materials and key operations is being logged.
7.5. Storage protection measures are applied (including encryption/backup control, if available), as well as data minimization (only the necessary is requested).
7.6. The User is obliged to independently ensure the security of their devices and accounts.
8. User Rights
8.1. The User has the right to request information about data processing, correction, updating, clarification, deletion (if there are no grounds for storage).
8.2. Withdrawal of consent is possible by contacting support; however, the use of the service may be restricted if processing is necessary for AML/security/ execution of the Application.
9. Contact details of the Operator
9.1. Regarding the processing of personal data, you can contact the Operator: info@goldengatex.net