Privacy Policy
Last Updated: 7th July, 2026
Infini Labs and its affiliated entities responsible for providing the Services (collectively, "Infini" , "we" , "us" or "our" ) are committed to protecting your privacy and handling your Personal Data in a lawful, fair and transparent manner. We recognize the importance of safeguarding Personal Data and are committed to Processing it in accordance with applicable data protection laws and industry best practices.
This Privacy Policy explains how we collect, use, disclose, share, store, transfer, protect and otherwise Process your Personal Data when you access or use our websites, mobile applications, application programming interfaces ("APIs"), digital platforms or any other products and services that we make available (collectively, the "Services" ).
This Privacy Policy describes, among other things:
- the categories of Personal Data we collect and the sources from which we collect it;
- the purposes for which we Process your Personal Data and the legal bases on which we rely;
- how we share and disclose Personal Data with service providers, business partners and other recipients;
- how we protect, retain and securely manage Personal Data;
- your privacy rights and the choices available to you under applicable data protection laws; and
- how you can contact us regarding this Privacy Policy or the Processing of your Personal Data.
Please read this Privacy Policy carefully before using our Services. By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires your consent for specific Processing activities, we will obtain such consent before carrying out those activities.
1. Basic Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below unless the context requires otherwise.
- Infini / we / us / our: refers to Infini Labs and the relevant affiliated entity that provides the Services to you and determines the purposes and means of Processing your Personal Data. Depending on the Services you use, the applicable Controller will be identified during your onboarding process, in the relevant service agreement, or otherwise communicated to you.
- Personal Data: means any information relating to an identified or identifiable natural person ("Data Subject"). An identifiable natural person is one who can be identified, directly or indirectly, by reference to identifiers such as a name, identification number, location data, online identifier, wallet address, or one or more factors specific to that person's physical, physiological, genetic, mental, economic, cultural or social identity. Personal Data does not include information that has been irreversibly anonymized.
- Processing: means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, making available, alignment, combination, restriction, erasure or destruction.
- Controller: means the natural or legal person that, alone or jointly with others, determines the purposes and means of Processing Personal Data. For the purposes of this Privacy Policy, the Controller is the relevant Infini entity providing the applicable Services to you.
- Processor: means a natural or legal person that Processes Personal Data on behalf of the Controller. Processors may include identity verification providers, cloud service providers, payment processors, banking partners, blockchain analytics providers, customer support providers and other authorized service providers engaged by Infini.
- Data Subject: means an identified or identifiable natural person whose Personal Data is Processed by Infini.
- Recipient: means any natural or legal person, public authority, agency or other body to whom Personal Data is disclosed, whether or not they are a Third Party.
- Third Party: means any natural or legal person, public authority, agency or body other than the Data Subject, the Controller, the Processor and persons who, under the direct authority of the Controller or Processor, are authorized to Process Personal Data.
- Supervisory Authority: means an independent public authority established under applicable data protection laws that is responsible for monitoring and enforcing compliance with such laws, including, where applicable, supervisory authorities established under the GDPR.
- Services: means the websites, mobile applications, APIs, software platforms and other digital products or services operated or provided by Infini, including, where applicable, digital wallet services, stablecoin payment services, fiat payment services, virtual account services, card services, merchant services, API services and other related financial technology services.
- Account: means a user account registered with Infini to access or use one or more of the Services.
- Identity Verification (KYC): means the procedures used to verify a user's identity and comply with applicable anti-money laundering ("AML"), counter-terrorist financing ("CTF"), sanctions, fraud prevention and other regulatory obligations. Such procedures may include document verification, biometric verification, liveness detection, sanctions screening, politically exposed person ("PEP") screening and other legally required verification measures.
- Business Customer: means a legal person or other organization that uses the Services for business or commercial purposes. Where applicable, identity verification may also include Know Your Business ("KYB") procedures.
- Wallet Address: means a public blockchain address or other distributed ledger identifier associated with a blockchain wallet. A Wallet Address may constitute Personal Data where it can reasonably be linked, directly or indirectly, to an identified or identifiable individual.
- Digital Assets: means cryptocurrencies, stablecoins, tokenized assets or other blockchain-based digital representations of value that are supported by the Services from time to time.
- Profiling: means any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, including to analyze or predict aspects concerning that person's preferences, interests, behavior, location, reliability or risk.
- Automated Decision-Making: means a decision made by automated means without meaningful human involvement, including decisions based on Profiling where applicable.
- Applicable Data Protection Laws: means all applicable laws and regulations governing the Processing of Personal Data, including, where applicable, the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and any other applicable privacy and data protection laws in jurisdictions where Infini provides its Services.
2. Personal Data We Collect
We collect Personal Data only where it is necessary to provide our Services, comply with legal and regulatory obligations, protect the security and integrity of our platform, or where you have provided your consent where required by applicable law.
The Personal Data we collect depends on the Services you use and how you interact with us. We may collect Personal Data directly from you, automatically when you use our Services, from publicly available sources, or from trusted third parties where permitted by law.
2.1 Information You Provide to Us
When you create an Account, use our Services or communicate with us, we may ask you to provide information such as:
- your name;
- email address;
- telephone number;
- residential address;
- date of birth;
- nationality;
- country of residence; and
- other information necessary to establish and manage your Account.
2.2 Identity Verification Information
To comply with applicable legal and regulatory requirements, we may ask you to verify your identity.
Depending on the Services you use, we may collect:
- government-issued identification documents;
- photographs or selfies;
- proof of address;
- tax identification information where required;
- information about your occupation;
- information regarding the source of your funds or wealth where required by law;
- information relating to your business, beneficial owners or authorized representatives if you are using our Services on behalf of an organization.
2.3 Payment and Transaction Information
When you make, receive or facilitate payments through our Services, we may collect information relating to your transactions, including:
- payment method;
- transaction amount;
- currency;
- payment date and time;
- merchant information;
- settlement information; and
- other information necessary to complete the transaction.
2.4 Digital Asset and Wallet Information
If you use our digital asset or wallet-related Services, we may collect information relating to your digital asset activities, including:
- wallet addresses;
- blockchain transaction information;
- supported digital asset balances;
- deposit and withdrawal records; and
- publicly available blockchain information associated with your use of the Services.
2.5 Financial Information
Depending on the Services you use, we may collect information relating to your financial profile, including:
- account balances;
- transaction history;
- income or asset verification documents where required;
- investment or yield information; and
- other information necessary to provide the Services or comply with legal obligations.
2.6 Device and Usage Information
We use this information to operate, secure and improve our Services.
When you access or use our Services, we automatically collect certain technical information, including:
- IP address;
- browser type;
- operating system;
- device identifiers;
- language settings;
- access times;
- pages visited;
- usage logs;
- cookies and similar technologies; and
- other technical information necessary to maintain the security and performance of the Services.
2.7 Information from Third Parties
Where permitted by applicable law, we may receive Personal Data from trusted third parties, including:
- identity verification providers;
- payment service providers;
- banking partners;
- blockchain analytics providers;
- fraud prevention providers;
- public authorities;
- publicly available databases; and
- publicly accessible blockchain networks.
2.8 When You Do Not Provide Personal Data
Some Personal Data is required for us to provide certain Services or comply with applicable legal obligations.
If you choose not to provide the requested Personal Data, we may be unable to:
- create or maintain your Account;
- verify your identity;
- provide certain Services;
- process transactions; or
- comply with our legal and regulatory obligations.
3. How We Use Personal Information
We use your Personal Data only where permitted by applicable law and only for the purposes described in this Privacy Policy. Depending on the Services you use and how you interact with us, we may Process your Personal Data for one or more of the following purposes.
3.1 To Provide and Manage Our Services
We use your Personal Data to:
- create, verify and maintain your Account;
- provide access to our Services and related functionalities;
- authenticate your identity;
- process your applications and requests;
- administer your Account and maintain our relationship with you;
- provide customer support;
- communicate with you regarding your Account, transactions and the Services;
- provide the products and Services you request.
3.2 To Process Payments and Transactions
We use your Personal Data to:
- process deposits, withdrawals, payments and transfers;
- execute digital asset transactions;
- facilitate settlement and reconciliation;
- process virtual account and card-related transactions;
- generate transaction confirmations and statements;
- maintain transaction records;
- support payment processing and related operational activities.
3.3 To Comply with Legal and Regulatory Obligations
We use your Personal Data where necessary to:
- comply with applicable laws, regulations and regulatory requirements;
- perform identity verification;
- conduct customer due diligence and ongoing monitoring;
- prevent money laundering, terrorist financing, fraud and sanctions violations;
- comply with tax, accounting and record-keeping obligations;
- respond to requests from courts, regulators, supervisory authorities and law enforcement agencies;
- establish, exercise or defend legal rights where required by law.
3.4 To Protect the Security and Integrity of Our Services
We use your Personal Data to:
- authenticate users and protect Accounts;
- detect, investigate and prevent unauthorized access;
- identify suspicious or fraudulent activities;
- monitor the security and integrity of our systems;
- protect our users, employees, business partners and infrastructure;
- investigate security incidents and respond to cyber threats;
- prevent abuse, misuse and other unlawful activities.
3.5 To Improve and Develop Our Services
We use your Personal Data to:
- understand how users interact with our Services;
- analyze usage trends and customer preferences;
- improve the functionality, usability and performance of our Services;
- develop new products, features and technologies;
- conduct testing, quality assurance and research;
- diagnose technical issues and improve system reliability;
- personalize your experience where permitted by applicable law.
3.6 To Communicate With You
We use your Personal Data to:
- respond to your enquiries and requests;
- provide customer support;
- notify you about important service updates;
- send security alerts and transaction notifications;
- communicate changes to our Services, policies or legal terms;
- provide information relevant to your Account or your use of the Services.
3.7 To Send Marketing Communications
You may withdraw your consent or unsubscribe at any time by following the instructions contained in our communications or by contacting us.
Where permitted by applicable law, we may use your Personal Data to:
- send newsletters;
- provide product updates;
- inform you about new features and Services;
- send promotional communications;
- invite you to surveys, events or marketing campaigns.
We do not sell your Personal Data or permit third parties to use your Personal Data for their own direct marketing purposes without your consent.
3.8 To Exercise and Protect Our Legal Rights
We may use your Personal Data where necessary to:
- establish, exercise or defend legal claims;
- resolve disputes;
- enforce our agreements, policies and Terms of Service;
- protect our legal rights, property and legitimate interests;
- support audits, investigations and legal proceedings.
3.9 For Other Compatible Purposes
We may also Process your Personal Data for purposes that are compatible with the purposes for which it was originally collected, where permitted by applicable law.
Where we intend to Process your Personal Data for a purpose that is materially different from the purpose for which it was originally collected, we will provide you with appropriate notice and, where required by applicable law, obtain your consent before such Processing takes place.
3.10 Processing in Accordance with Applicable Law
We Process your Personal Data only where we have a valid legal basis under applicable data protection laws.
Depending on the circumstances, the legal basis for Processing may include:
- your consent;
- the performance of a contract to which you are a party or in order to take steps at your request before entering into a contract;
- compliance with a legal obligation to which we are subject;
- the protection of your vital interests or those of another natural person;
- the performance of a task carried out in the public interest or in the exercise of official authority; or
- our legitimate interests, provided that such interests are not overridden by your interests, fundamental rights or freedoms.
4. How We Share and Disclose Your Personal Data
We do not sell your Personal Data.
We share or disclose your Personal Data only where it is necessary to provide our Services, comply with legal or regulatory obligations, protect our legitimate interests, or where you have instructed us to do so or provided your consent where required by applicable law.
Depending on the circumstances, we may share your Personal Data with the following categories of recipients.
4.1 Service Providers
We may share your Personal Data with carefully selected third-party service providers who perform services on our behalf, including providers of:
- cloud hosting and infrastructure;
- identity verification and authentication;
- payment processing and settlement;
- customer support services;
- fraud prevention and security monitoring;
- blockchain analytics;
- data storage and backup;
- information technology and system maintenance;
- communications and notification services; and
- professional advisory services, including legal, accounting, auditing and consulting services.
4.2 Companies Within the Infini Group
Where necessary to provide the Services, operate our business or support internal administration, we may share your Personal Data with other companies within the Infini group.
All group companies are required to Process Personal Data only for the purposes described in this Privacy Policy and in accordance with applicable data protection laws.
4.3 Financial Institutions and Payment Partners
To provide payment-related Services, we may share Personal Data with financial institutions and payment partners, including:
- banks;
- payment service providers;
- card networks;
- card issuers;
- acquiring institutions;
- settlement partners;
- virtual account providers; and
- other financial institutions involved in processing your transactions.
4.4 Compliance and Risk Management Partners
Where required to comply with applicable legal or regulatory obligations or to protect the security of our Services, we may share Personal Data with:
- identity verification providers;
- AML and sanctions screening providers;
- blockchain analytics providers;
- fraud prevention providers;
- transaction monitoring providers;
- compliance service providers; and
- other authorized risk management partners.
4.5 Regulatory Authorities and Law Enforcement
We may disclose your Personal Data where required or permitted by applicable law to:
- regulatory authorities;
- supervisory authorities;
- courts;
- law enforcement agencies;
- tax authorities; or
- other competent governmental authorities.
4.6 Professional Advisers
We may disclose Personal Data to our professional advisers, including lawyers, auditors, accountants, consultants and insurers, where such disclosure is necessary for obtaining professional advice, complying with legal obligations, conducting audits or protecting our legal interests.
4.7 Corporate Transactions
If we are involved in a merger, acquisition, investment, financing, corporate restructuring, reorganization, sale of assets or business transfer, your Personal Data may be transferred as part of that transaction.
Where required by applicable law, we will notify you before your Personal Data becomes subject to a different privacy policy or is transferred to a different Controller.
4.8 With Your Instructions or Consent
We may disclose your Personal Data to other persons or organizations where:
- you request or authorize us to do so;
- you have provided your consent; or
- disclosure is otherwise permitted or required by applicable law.
4.9 Protection of Rights and Safety
We may disclose Personal Data where we believe, in good faith, that such disclosure is necessary to:
- protect the rights, property or safety of Infini;
- protect the rights, property or safety of our users or others;
- prevent fraud, financial crime or security incidents;
- investigate violations of our Terms of Service or other policies; or
- establish, exercise or defend legal claims.
4.10 Safeguards When Sharing Personal Data
Whenever we share or disclose Personal Data, we implement appropriate contractual, technical and organizational safeguards designed to protect your Personal Data.
Where required by applicable law, we enter into appropriate data processing agreements or other legally required contractual arrangements with recipients who Process Personal Data on our behalf.
Where recipients Process Personal Data as independent Controllers, they are responsible for their own compliance with applicable data protection laws.
5. Cookies and Similar Technologies
When you access or use Infini's websites or applications, we may use Cookies and similar technologies to automatically collect some information. Cookies are small text files stored on your device. In addition, we may also use similar technologies, such as web beacons, pixel tags, embedded scripts and log files (hereinafter collectively referred to as "Cookies and Similar Technologies"), to help us understand the usage of the Services, enhance website performance and optimize user experience. We and authorized third-party service providers may use the above Cookies and Similar Technologies (i) Cookies or small data files stored on your device, and (ii) other similar technologies (including web beacons, pixel tracking, embedded scripts, location identification technologies and logging technologies, collectively referred to as "Cookies"), to automatically collect information related to your use of the Services, and use such information only within the scope of achieving the purposes described in this Privacy Policy.
For mobile applications, we may use technologies functionally similar to Cookies, including application identifiers, local storage technologies, software components and other technologies that support the operation, security, authentication and performance of the Services. These technologies are used only for the purposes described in this Privacy Policy and in accordance with applicable law.
You have the right to disable non-essential Cookies at any time. However, please note that disabling some Cookies may affect some functions or Services of the website, such as inability to remember login status or personalized recommendations. If you do not wish to receive cookies, most browsers support the following operations: (i) prompt you when receiving cookies by adjusting settings, allowing you to decide whether to accept them autonomously; (ii) disable existing cookies; or (iii) set the browser to automatically reject cookies. Please note that these operations may affect the website usage experience, and some functions or Services may experience abnormalities or even be completely unusable. Depending on your device and operating system version, it may not be possible to completely clear all cookies. In addition, if you want to uniformly reject cookies on all browsers and devices, you need to set them separately in each browser on each commonly used device. You can also prevent the system from automatically downloading images that may contain technical codes through email option settings—these codes can help us identify whether you have accessed the email and performed related operations.
The purposes for which we use cookies and similar technologies include:
- Ensuring the normal operation of the websites and services, including authentication and session management;
- Analyzing website traffic and usage behavior to identify popular content and improve navigation;
- Improving functionality and overall performance, such as remembering your preferences and settings;
- Enhancing security and preventing fraudulent behavior, such as detecting abnormal logins;
- Supporting content display or promotional activities related to the Services with your explicit consent.
The legal basis for setting cookies is the legitimate interests under Article 6(1)(f) of the General Data Protection Regulation (hereinafter "GDPR") (if applicable), and your consent under Article 6(1)(a) of the GDPR under the premise of complying with legal requirements. Where the use of cookies is necessary for fulfilling a contract in initiating or continuing a contractual relationship, the legal basis is Article 6(1)(b) of the GDPR.
6. Mobile Applications
6.1 Mobile Application Information
When you access or use our mobile application, we may automatically collect certain information relating to your mobile device and application environment, including:
- device model;
- operating system and version;
- application version;
- device identifiers;
- language and regional settings;
- time zone;
- IP address;
- network connection information;
- application usage logs;
- diagnostic information; and
- other technical information necessary for the operation, security and performance of the Services.
6.2 Mobile Device Permissions
Depending on the features of the Services that you choose to use, our mobile application may request access to certain functions or permissions available on your mobile device.
These permissions may include access to:
- the camera, to capture identity verification documents, payment information or QR codes;
- your photo library, to upload documents, images or other information that you choose to provide;
- notifications, to deliver transaction confirmations, security alerts, service updates and other account-related communications;
- biometric authentication features supported by your device, where you choose to enable biometric login;
- location information, where necessary for security, fraud prevention or compliance purposes; and
- other device functions where access is necessary to provide specific features of the Services.
You may refuse or withdraw these permissions at any time through your device settings. However, certain features of the Services may not function properly if the relevant permissions are disabled.
6.3 Notifications
Where permitted by applicable law, our mobile application may send notifications relating to your Account and your use of the Services.
These notifications may include:
- login and authentication alerts;
- transaction confirmations;
- payment status updates;
- security notifications;
- service announcements;
- changes to our Services or policies; and
- marketing communications where you have provided any consent required under applicable law.
6.4 Biometric Authentication
Where supported by your device and enabled by you, our mobile application may allow you to authenticate your identity using biometric authentication technologies made available by your device, such as facial recognition or fingerprint authentication.
Biometric authentication is performed by your device operating system or device manufacturer.
Infini does not collect, store or otherwise have access to your biometric templates or biometric credentials.
We receive only confirmation that the authentication process has been successfully completed in order to facilitate secure access to your Account.
6.5 Security and Fraud Prevention
To protect the security of our Services, our users and our business operations, we may collect and Process certain device-related information necessary to identify security risks, detect unauthorized access, prevent fraud and comply with applicable legal and regulatory obligations.
Such information may include technical information relating to your device, application environment, authentication activities, security events and other indicators reasonably necessary to protect the integrity, availability and security of the Services.
We use this information solely for legitimate security, fraud prevention, compliance and risk management purposes.
6.6 Application Performance and Diagnostics
We may collect limited diagnostic and performance information relating to the operation of our mobile application to:
- maintain the stability and reliability of the Services;
- identify and resolve technical issues;
- improve functionality and user experience;
- monitor application performance; and
- develop, maintain and improve our products and Services.
7. Blockchain Public Information
Certain information recorded on public blockchain networks is publicly available by design and may be collected or analyzed by us in connection with the Services.
Where permitted by applicable law, we may combine publicly available blockchain information with Personal Data that you provide directly to us or that we receive from trusted third parties. We do so only where necessary to:
- public wallet addresses;
- blockchain transaction records;
- transaction hashes;
- token balances;
- transfers, deposits and withdrawals;
- interactions with blockchain networks or smart contracts; and
- other publicly available blockchain data associated with your use of the Services.
- provide the Services;
- verify transactions;
- comply with applicable legal and regulatory obligations;
- conduct anti-money laundering, sanctions screening and fraud prevention activities;
- assess and manage risk;
- investigate suspicious or unauthorized activities; and
- protect the security, integrity and reliability of our Services.
8. Children's Personal Information
Our Services are not directed to, and are not intended for, children below the age required by applicable law to validly use our Services or provide consent for the Processing of Personal Data.
We do not knowingly collect or Process Personal Data from children. If you are below the applicable age under the laws of your jurisdiction, you should not access or use our Services or provide any Personal Data to us unless permitted by applicable law and, where required, with the involvement of your parent or legal guardian.
If we become aware that we have collected Personal Data from a child in violation of applicable law, we will take reasonable steps to delete such Personal Data without undue delay, unless we are legally required or permitted to retain it.
If you believe that a child has provided Personal Data to us in violation of this Privacy Policy or applicable law, please contact us using the contact details provided in Section 16 (Contact Us) .
9. Third-Party Websites and Services
Our Services may contain links to, integrate with, or enable access to third-party websites, applications, platforms or services that are operated by independent third parties.
This Privacy Policy applies only to the Processing of Personal Data by Infini in connection with our Services. It does not apply to the privacy practices of third parties that operate independently from us, unless expressly stated otherwise.
When you access or interact with a third-party website or service, your Personal Data may be collected and Processed directly by that third party in accordance with its own privacy policy, terms of use and applicable legal obligations. We encourage you to review the privacy policies of those third parties before providing them with your Personal Data or using their services.
In certain circumstances, our Services may integrate with third-party providers, including payment service providers, financial institutions, identity verification providers, blockchain service providers, cloud service providers or other business partners. Where those third parties Process Personal Data on our behalf, they do so under appropriate contractual safeguards and applicable data protection laws. Where they Process Personal Data as independent Controllers, they are responsible for their own compliance with applicable data protection laws.
The inclusion of a link to, or integration with, a third-party website or service does not constitute an endorsement of that third party or its privacy practices. Except where required by applicable law, Infini is not responsible for the privacy practices, content, security or services provided by independent third parties.
10. Third-Party Wallet Extensions
Some of our Services allow you to connect, access or interact with third-party digital asset wallets or wallet connection services.
When you choose to connect a third-party wallet, we may receive certain information necessary to facilitate the requested Services, such as your public wallet address, blockchain network information and transaction-related information. We do not receive or have access to your private keys, seed phrases or wallet credentials.
Your use of any third-party wallet or wallet connection service is subject to the terms, conditions and privacy policy of the relevant wallet provider. We encourage you to review those policies before connecting your wallet or conducting transactions through such services.
Where a third-party wallet provider Processes your Personal Data as an independent Controller, it is responsible for its own compliance with applicable data protection laws and privacy obligations.
The availability of a wallet connection through our Services does not constitute an endorsement of the third-party wallet or its privacy practices. Except where required by applicable law, Infini is not responsible for the operation, security or privacy practices of independent third-party wallet providers.
11. Cross-Border Transfer of Personal Data
Because we operate internationally, your Personal Data may be transferred to, stored in or accessed from countries or territories outside the country or region in which it was originally collected.
10.1 Transfers Within the Infini Group
Where necessary to provide the Services or support our internal business operations, we may transfer Personal Data between companies within the Infini group.
All group companies are required to Process Personal Data in accordance with this Privacy Policy, applicable data protection laws and appropriate internal data protection measures.
10.2 Transfers to Third-Party Service Providers
We may transfer Personal Data to trusted third-party service providers located in different jurisdictions where they provide services on our behalf, including:
- cloud hosting providers;
- payment service providers;
- banking partners;
- identity verification providers;
- customer support providers;
- blockchain analytics providers;
- fraud prevention providers;
- information technology providers;
- communications providers; and
- other service providers necessary for the operation of our Services.
10.3 Safeguards for International Transfers
Where Personal Data is transferred internationally, we implement appropriate safeguards in accordance with applicable data protection laws.
Depending on the circumstances, these safeguards may include:
- transfers to countries or territories that have been recognized as providing an adequate level of data protection by the relevant competent authority;
- the use of the European Commission's Standard Contractual Clauses ("SCCs") or other approved contractual safeguards;
- Binding Corporate Rules ("BCRs"), where applicable;
- approved certification mechanisms or codes of conduct where available; or
- any other lawful transfer mechanism recognized under applicable data protection laws.
10.4 Transfers Based on Legal Derogations
Where no other lawful transfer mechanism is available, we may transfer Personal Data where permitted under applicable law, including where:
- you have explicitly consented to the transfer after being informed of the possible risks;
- the transfer is necessary for the performance of a contract with you;
- the transfer is necessary for important reasons of public interest;
- the transfer is necessary for the establishment, exercise or defence of legal claims; or
- another derogation under applicable data protection laws applies.
10.5 Protection of Your Personal Data
Whenever Personal Data is transferred internationally, we take reasonable technical, organizational and contractual measures designed to ensure that your Personal Data continues to receive an appropriate level of protection.
These measures may include:
- encryption;
- access controls;
- contractual confidentiality obligations;
- vendor due diligence;
- security assessments;
- ongoing monitoring of service providers; and
- other safeguards appropriate to the nature of the Processing.
10.6 Further Information
You may contact us using the details provided in Section 16 (Contact Us) if you would like further information regarding the safeguards that apply to international transfers of your Personal Data or, where applicable, request a copy of the relevant transfer mechanism, subject to applicable legal restrictions.
12. Security of Personal Data
We maintain appropriate technical, organizational and physical security measures designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed by us.
Our security measures are designed taking into account the nature of the Personal Data we Process, the risks associated with the Processing activities and applicable legal requirements.
11.1 Security Measures
We implement appropriate security measures, which may include:
- encryption of Personal Data during transmission and, where appropriate, at rest;
- access controls based on the principle of least privilege;
- multi-factor authentication for privileged access where appropriate;
- network and infrastructure security controls;
- system monitoring and intrusion detection mechanisms;
- regular vulnerability assessments and security testing;
- logging and monitoring of security events;
- secure software development and change management practices; and
- employee training and awareness on information security and data protection.
11.2 Access to Personal Data
Access to Personal Data is restricted to employees, contractors and authorized service providers who require such access for legitimate business purposes.
All personnel with access to Personal Data are subject to appropriate confidentiality obligations and receive training on their responsibilities regarding the protection of Personal Data.
11.3 Service Providers
Where we engage third-party service providers to Process Personal Data on our behalf, we require them to implement appropriate technical and organizational measures to protect Personal Data and to Process such data only in accordance with our documented instructions and applicable data protection laws.
Where required by applicable law, we enter into appropriate contractual arrangements, including data processing agreements, with such service providers.
11.4 Security Incidents
Although we take reasonable measures to protect Personal Data, no method of transmission over the Internet or method of electronic storage is completely secure.
Accordingly, while we strive to protect your Personal Data, we cannot guarantee its absolute security.
If we become aware of a Personal Data Breach that is likely to result in a risk to your rights and freedoms, we will respond in accordance with applicable law, including notifying the relevant supervisory authority and affected individuals where required.
11.5 Reporting Security Concerns
If you believe that your Personal Data has been compromised, accessed without authorization or otherwise misused, please contact us immediately using the contact details provided in Section 16 (Contact Us) .
We will investigate the matter promptly and take appropriate measures in accordance with applicable law and our internal security procedures.
13. Data Rentention
We retain your Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including providing our Services, complying with legal and regulatory obligations, resolving disputes, enforcing our agreements and protecting our legitimate interests.
Where technically or legally required, we may retain limited information to comply with ongoing legal obligations, resolve disputes or protect our legal rights.
The length of time for which we retain Personal Data depends on a number of factors, including:
- the nature and sensitivity of the Personal Data;
- the purposes for which the Personal Data was collected and Processed;
- the Services you use;
- applicable legal, regulatory, tax, accounting and reporting requirements;
- applicable limitation periods for legal claims; and
- our legitimate business needs.
- comply with anti-money laundering, counter-terrorist financing and sanctions obligations;
- comply with tax, accounting and financial reporting requirements;
- establish, exercise or defend legal claims;
- investigate fraud, security incidents or regulatory matters; or
- comply with requests from competent authorities.
We also take reasonable steps to ensure that the Personal Data we Process is accurate, complete and, where necessary, kept up to date. Where we become aware that Personal Data is inaccurate or outdated, we will take reasonable steps to correct, update or delete it, as appropriate.
14. Your Privacy Rights
Depending on your location and the applicable data protection laws, you may have one or more of the following rights in relation to your Personal Data.
13.1 Right of Access
You have the right to request confirmation as to whether we Process your Personal Data and, where applicable, obtain access to that Personal Data and related information.
13.2 Right to Rectification
You have the right to request that inaccurate or incomplete Personal Data be corrected or updated.
13.3 Right to Erasure
You may request the deletion of your Personal Data where permitted by applicable law.
Please note that this right is not absolute. We may retain certain Personal Data where we are legally required or permitted to do so, including for compliance with legal obligations, fraud prevention, dispute resolution or the establishment, exercise or defence of legal claims.
Where Personal Data has been recorded on a public blockchain, technical limitations may prevent us from deleting or modifying such information.
13.4 Right to Restriction of Processing
You may request that we restrict the Processing of your Personal Data in circumstances permitted by applicable law.
13.5 Right to Data Portability
Where applicable, you may request a copy of your Personal Data in a structured, commonly used and machine-readable format and request that it be transmitted to another controller where technically feasible.
13.6 Right to Object
You have the right to object to certain Processing activities, including Processing based on our legitimate interests and, where applicable, Processing for direct marketing purposes.
13.7 Right to Withdraw Consent
Where we rely on your consent as the legal basis for Processing, you may withdraw your consent at any time.
Withdrawal of consent will not affect the lawfulness of any Processing carried out before your consent was withdrawn.
13.8 Rights Related to Automated Decision-Making
Where applicable law provides such rights, you may request not to be subject to a decision based solely on automated Processing, including Profiling, where that decision produces legal or similarly significant effects concerning you, except where permitted by applicable law.
13.9 Right to Lodge a Complaint
If you believe that we have not handled your Personal Data in accordance with applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority in your jurisdiction.
This right does not affect any other administrative or judicial remedies that may be available to you.
13.10 Exercising Your Rights
You may exercise your privacy rights by contacting us using the contact details provided in Section 16 (Contact Us) .
To protect your Personal Data and the rights of others, we may request additional information to verify your identity before responding to your request.
We will respond to your request within the time period required by applicable law.
In certain circumstances permitted by applicable law, we may refuse or limit a request, including where an exemption applies. If we refuse your request, we will explain the reasons unless prohibited by applicable law.
Where permitted by applicable law, we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive or repetitive.
15. Legal Bases for Processing Personal Data
Where the General Data Protection Regulation ("GDPR"), the UK GDPR or other applicable data protection laws require us to identify the legal basis for Processing your Personal Data, we rely on one or more of the following legal bases.
| Processing Activity | Purpose | Legal Basis |
|---|---|---|
| Account registration and account management | To create, administer and maintain your Account and provide the requested Services | Performance of a Contract (Article 6(1)(b) GDPR) |
| Identity verification (KYC / KYB) | To verify identity and comply with legal and regulatory requirements | Legal Obligation (Article 6(1)(c) GDPR) |
| Payment processing and transaction execution | To process payments, transfers, settlements and digital asset transactions | Performance of a Contract (Article 6(1)(b) GDPR) |
| Customer support | To respond to enquiries and provide assistance | Performance of a Contract (Article 6(1)(b)) and Legitimate Interests (Article 6(1)(f)) |
| Fraud prevention, cybersecurity and platform security | To detect fraud, unauthorized access and security threats | Legitimate Interests (Article 6(1)(f)) and, where applicable, Legal Obligation (Article 6(1)(c)) |
| Anti-money laundering, sanctions screening and regulatory compliance | To comply with AML, CTF, sanctions, tax and other legal obligations | Legal Obligation (Article 6(1)(c) GDPR) |
| Risk management and transaction monitoring | To assess risk, prevent financial crime and protect our Services | Legitimate Interests (Article 6(1)(f)) and, where required, Legal Obligation (Article 6(1)(c)) |
| Service improvement, analytics and product development | To improve, test and develop our Services | Legitimate Interests (Article 6(1)(f)) |
| Marketing communications | To send newsletters, product updates and promotional information | Consent (Article 6(1)(a)) where required by law, or Legitimate Interests (Article 6(1)(f)) where permitted |
| Cookies and similar technologies | To operate, secure and improve our Services | Performance of a Contract (Article 6(1)(b)), Legitimate Interests (Article 6(1)(f)) or Consent (Article 6(1)(a)), depending on the type of Cookie and applicable law |
| Compliance with legal proceedings | To comply with court orders, regulatory requests and legal claims | Legal Obligation (Article 6(1)(c)) |
| Protection of legal rights | To establish, exercise or defend legal claims | Legitimate Interests (Article 6(1)(f)) |
Legitimate Interests
Where we rely on our legitimate interests as the legal basis for Processing, we carefully assess whether our interests are balanced against your rights, freedoms and reasonable expectations.
Our legitimate interests may include:
- protecting the security and integrity of our Services;
- preventing fraud and financial crime;
- improving and developing our products and Services;
- maintaining the stability and reliability of our platform;
- enforcing our legal rights and contractual arrangements; and
- supporting our day-to-day business operations.
Consent
Where Processing is based on your consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of any Processing carried out before your consent was withdrawn.
Where applicable law requires your consent before we Process your Personal Data, we will request such consent before carrying out the relevant Processing activities.
Changes to the Legal Basis
If we intend to Process your Personal Data for a purpose that is materially different from the purpose for which it was originally collected, or if we intend to rely on a different legal basis where required by applicable law, we will provide you with additional information before such Processing takes place.
16. Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our Services, business operations, legal or regulatory requirements, technological developments or other operational needs.
Where we make changes to this Privacy Policy, we will update the "Last Updated" date at the beginning of this Privacy Policy.
If the changes materially affect the way in which we Process your Personal Data or otherwise significantly affect your rights, we will provide appropriate notice in accordance with applicable law. Depending on the nature of the changes, such notice may be provided through our website, mobile application, email, in-product notifications or other appropriate communication channels.
Where required by applicable law, we will obtain your consent before the updated Privacy Policy becomes effective.
We encourage you to review this Privacy Policy periodically to remain informed about how we collect, use, disclose and protect your Personal Data.
Your continued use of the Services following the effective date of an updated Privacy Policy constitutes your acknowledgement of the revised Privacy Policy, except where applicable law requires your explicit consent before the changes take effect.
17. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your privacy rights or would like further information regarding our Processing of your Personal Data, please contact us using the details below.
Privacy Team
Email:
contact@infini.money
Website: https://www.infini.money
Where required by applicable law, contact details for our Data Protection Officer ("DPO"), EU Representative and/or UK Representative will be made available through our website or otherwise provided to you.
We may request additional information to verify your identity before responding to your request.