Legal

Privacy Policy

Your privacy is important to us. This policy explains how Exbit collects, uses, stores, and protects your personal data.

Categories

Data we collect

Eight categories of personal data power the Exbit platform. Each card explains why we collect it and how long we keep it.

Identity

Legal name, date of birth, nationality, government ID number.

Why: KYC, AML and sanctions screening.
Retention: 5 years after closure.

Contact

Email, phone number and residential address.

Why: Account notices, 2FA, security alerts.
Retention: Active account + 3 years.

Financial

Tokenised bank and card references, crypto deposit/withdrawal addresses.

Why: Settle fiat and crypto transfers.
Retention: 7 years (tax records).

Device & network

IP address, user-agent, device fingerprint, geolocation.

Why: Fraud detection and session integrity.
Retention: 24 months.

Usage

Trades, logins, pages viewed, API calls, feature interactions.

Why: Product analytics and audit trails.
Retention: 24 months (raw), 5 years (aggregated).

Communications

Support tickets, live-chat transcripts, inbound emails and call notes.

Why: Case handling and quality assurance.
Retention: 3 years after closure.

KYC documents

Scans of passport/ID, selfie, proof-of-address, liveness video frames.

Why: Identity verification under FATF rules.
Retention: 5 years after closure.

Marketing preferences

Consent records, newsletter topics, campaign-response signals.

Why: Honor opt-ins and opt-outs precisely.
Retention: Consent lifetime + 3 years.

Your rights

GDPR & CCPA rights

Exercise any of these rights by emailing our Data Protection Officer. We respond within 30 days.

Access

Request a copy of every piece of personal data Exbit holds about you.

How: [email protected]

Rectification

Correct anything inaccurate or incomplete on your profile or in our records.

How: [email protected]

Erasure

Ask us to delete your data, subject to mandatory AML retention periods.

How: [email protected]

Portability

Receive your data in a structured, machine-readable format (JSON/CSV).

How: [email protected]

Restrict processing

Pause our processing of your data while a complaint or correction is resolved.

How: [email protected]

Object to processing

Object to processing based on legitimate interest, including direct marketing.

How: [email protected]

Withdraw consent

Revoke any consent you previously gave, effective from the date of withdrawal.

How: [email protected]

Lodge a complaint

File a complaint with your national data-protection authority (CNIL, ICO, BfDI, etc.).

How: [email protected]

Sub-processors

Third-party processors

These vendors process data on our behalf under strict GDPR-compliant contracts.

NameService typeRegionData shared
AWSCloud infrastructureGlobalAll (encrypted at rest)
CloudflareCDN & DDoS protectionGlobalRequest metadata
JumioKYC vendorUS / EUIdentity documents
OnfidoKYC vendorEU / UKIdentity documents
SumsubKYC vendorEUIdentity documents
StripePayment railsUS / EUFinancial (tokens)
PlaidBank account linkingUSFinancial (tokens)
SendGridTransactional emailUSContact & communications
SegmentAnalytics pipelineUSMinimal (pseudonymous)
PagerDutyIncident responseUSMinimal (staff only)
IntercomSupport toolUS / EUCommunications
DatadogObservabilityUS / EUMinimal (logs/metrics)
GitHubSource control / issuesUSMinimal (staff only)
ChainalysisBlockchain analyticsUSFinancial (addresses)