Privacy policy
Revision date — 10 August 2026
1. General provisions
This Privacy Policy (hereinafter — the "Policy") sets out the principles governing the collection, use, storage, transfer and protection of Users' personal data by the Company.
Capitalised terms used in this Policy and not defined herein shall have the meanings given to them in the User Agreement (Sections 1–3).
By using the Service, the User confirms that they have read this Policy and consents to the processing of their personal data in accordance with its terms and applicable law.
2. Data collected
2.1. Telegram profile data
During interaction with the Telegram bot, the User's unique Telegram ID, name, profile photo and other data available through the Telegram API are collected.
This information is used solely to identify the User and to enable the operation of the Service.
2.2. Transaction data
When the User carries out operations such as the exchange or transfer of virtual assets, the Company may record wallet addresses, transaction hashes and asset types. This information is necessary for the technical execution of transactions and for AML compliance.
2.3. AML/KYC data
The Company does not carry out regular KYC verification upon registration and does not by default collect or store identity documents of the User. In exceptional cases — where funds are frozen or blocked by a Partner Exchange or a Liquidity Provider, where a Custodial Wallet is blocked in accordance with clause 10.6 of the User Agreement, or upon the demand of competent state authorities — the Company may request minimal identification information from the User solely for the purpose of resolving the relevant situation. Such data, if collected, is processed confidentially and deleted once the situation has been resolved.
At the same time, for the operation of the Custodial service the Company retains operational data relating to the User's Custodial Wallets: their addresses, transaction history and securely encrypted private keys. This data does not constitute identity documents and is used solely for the provision of services and for compliance purposes.
2.4. Activity logs
Information on the User's activity within the Service is collected, including commands sent and operations performed. This is used to ensure the proper functioning of the system and to provide technical support.
2.5. Data minimisation principle
The Company retains the data necessary for the operation of the Custodial service and for compliance purposes: the Telegram ID, the mapping of Custodial Wallets to the User, transaction history, and securely encrypted private keys to the wallets under the Company's management.
The Company does not retain identity documents on a permanent basis and does not collect personal data beyond what is necessary for the provision of services and for AML and statutory compliance.
3. Use of data
3.1. User data is used solely for:
- the provision of services and the operation of the Service's functionality;
- technical maintenance, security and improvement of the Platform;
- responding to legal or regulatory requests in the cases provided for by law.
3.2. Personal data is processed on the following legal bases:
- the User's consent, given upon use of the Platform;
- the necessity to perform the contract with the User;
- compliance with the Company's legal obligations, including in the field of AML/CFT.
4. Data sharing
The Company does not sell or transfer User data to third parties. Disclosure of information is permitted solely pursuant to an official request from competent authorities, duly issued in accordance with applicable law.
At the same time, the Company reserves the right to refuse to provide data to any domestic or foreign state authorities (including law enforcement, judicial and tax authorities and financial intelligence units) where their requests are unfounded, do not meet legal requirements or have not been issued in accordance with the established procedure.
5. Data retention
The Company retains data only for as long as is necessary for:
- legal and operational purposes;
- compliance with record-keeping obligations under AML/CFT requirements;
- handling customer support requests.
Once these purposes have been achieved, the data is deleted.
6. Security
The Company applies reasonable and adequate organisational and technical safeguards, storing private keys to Custodial Wallets using encryption and access controls. Access to the keys is restricted to authorised personnel and granted solely on a need-to-know basis for the operation of the Service.
However, it cannot guarantee 100% security in the transmission of data over the Internet, including via Telegram.
7. User rights
The User has the right to:
- request access to their data or its deletion;
- request the rectification of inaccurate information.
Requests may be submitted through the official contact channel or by email: info@crypto-office.com.
8. International data transfers
For the purposes of the Company's operations, personal data may be processed or stored on servers located outside the Republic of Panama, in jurisdictions with equivalent data protection standards.
9. Amendments to this Policy
The Company reserves the right to amend this Privacy Policy.
Updates take effect immediately upon publication on the official website. Continued use of the Platform constitutes the User's acceptance of the updated version of the Policy.
10. Governing law and contacts
This Policy is governed by the laws of the Republic of Panama.
For all matters relating to the use of the Service, the User may contact the Company using the following contact details:
Legal name: SoftVision Innovations S.A.
Registered address: 10th Floor, Plaza 2000 Tower, 50th Street, Panama, Republic of Panama
Registration number (RUC): 155765203
Phone: +971 52 725 0099
Email: info@crypto-office.com
Website: https://crypto-office.com
Support service: via the Telegram bot @office_app_support_bot