Privacy policy

Revision date — 10 August 2026

1. General provisions

This Privacy Policy (hereinafter — the "Policy") sets out the principles governing the collection, use, storage, transfer and protection of Users' personal data by the Company.

Capitalised terms used in this Policy and not defined herein shall have the meanings given to them in the User Agreement (Sections 1–3).

By using the Service, the User confirms that they have read this Policy and consents to the processing of their personal data in accordance with its terms and applicable law.

2. Data collected

2.1. Telegram profile data

During interaction with the Telegram bot, the User's unique Telegram ID, name, profile photo and other data available through the Telegram API are collected.

This information is used solely to identify the User and to enable the operation of the Service.

2.2. Transaction data

When the User carries out operations such as the exchange or transfer of virtual assets, the Company may record wallet addresses, transaction hashes and asset types. This information is necessary for the technical execution of transactions and for AML compliance.

2.3. AML/KYC data

The Company does not carry out regular KYC verification upon registration and does not by default collect or store identity documents of the User. In exceptional cases — where funds are frozen or blocked by a Partner Exchange or a Liquidity Provider, where a Custodial Wallet is blocked in accordance with clause 10.6 of the User Agreement, or upon the demand of competent state authorities — the Company may request minimal identification information from the User solely for the purpose of resolving the relevant situation. Such data, if collected, is processed confidentially and deleted once the situation has been resolved.

At the same time, for the operation of the Custodial service the Company retains operational data relating to the User's Custodial Wallets: their addresses, transaction history and securely encrypted private keys. This data does not constitute identity documents and is used solely for the provision of services and for compliance purposes.

2.4. Activity logs

Information on the User's activity within the Service is collected, including commands sent and operations performed. This is used to ensure the proper functioning of the system and to provide technical support.

2.5. Data minimisation principle

The Company retains the data necessary for the operation of the Custodial service and for compliance purposes: the Telegram ID, the mapping of Custodial Wallets to the User, transaction history, and securely encrypted private keys to the wallets under the Company's management.

The Company does not retain identity documents on a permanent basis and does not collect personal data beyond what is necessary for the provision of services and for AML and statutory compliance.

3. Use of data

3.1. User data is used solely for:

  • the provision of services and the operation of the Service's functionality;
  • technical maintenance, security and improvement of the Platform;
  • responding to legal or regulatory requests in the cases provided for by law.

3.2. Personal data is processed on the following legal bases:

  • the User's consent, given upon use of the Platform;
  • the necessity to perform the contract with the User;
  • compliance with the Company's legal obligations, including in the field of AML/CFT.

4. Data sharing

The Company does not sell or transfer User data to third parties. Disclosure of information is permitted solely pursuant to an official request from competent authorities, duly issued in accordance with applicable law.

At the same time, the Company reserves the right to refuse to provide data to any domestic or foreign state authorities (including law enforcement, judicial and tax authorities and financial intelligence units) where their requests are unfounded, do not meet legal requirements or have not been issued in accordance with the established procedure.

5. Data retention

The Company retains data only for as long as is necessary for:

  • legal and operational purposes;
  • compliance with record-keeping obligations under AML/CFT requirements;
  • handling customer support requests.

Once these purposes have been achieved, the data is deleted.

6. Security

The Company applies reasonable and adequate organisational and technical safeguards, storing private keys to Custodial Wallets using encryption and access controls. Access to the keys is restricted to authorised personnel and granted solely on a need-to-know basis for the operation of the Service.

However, it cannot guarantee 100% security in the transmission of data over the Internet, including via Telegram.

7. User rights

The User has the right to:

  • request access to their data or its deletion;
  • request the rectification of inaccurate information.

Requests may be submitted through the official contact channel or by email: info@crypto-office.com.

8. International data transfers

For the purposes of the Company's operations, personal data may be processed or stored on servers located outside the Republic of Panama, in jurisdictions with equivalent data protection standards.

9. Amendments to this Policy

The Company reserves the right to amend this Privacy Policy.

Updates take effect immediately upon publication on the official website. Continued use of the Platform constitutes the User's acceptance of the updated version of the Policy.

10. Governing law and contacts

This Policy is governed by the laws of the Republic of Panama.

For all matters relating to the use of the Service, the User may contact the Company using the following contact details:

Legal name: SoftVision Innovations S.A.

Registered address: 10th Floor, Plaza 2000 Tower, 50th Street, Panama, Republic of Panama

Registration number (RUC): 155765203

Phone: +971 52 725 0099

Email: info@crypto-office.com

Website: https://crypto-office.com

Support service: via the Telegram bot @office_app_support_bot