PRIVACY POLICY
Effective date: 19 January 2026
Who We are?
This Privacy Policy is issued by Cypher Capital acting as the data controller ( “Cypher“, “We“, “Us,” or “Our“).
We are committed to protecting the privacy of Our users. As part of this commitment, it is important for Us to be transparent about how We handle the information that We (or others on Our behalf) collect about users, when We collect such information and how We use it.
This Privacy Policy applies to the website available at (https://cypherpayments.io) (the “Policy” and the “Website“) and related services (the “Services”).
In this Policy, you (“You“, “Your” or “User“) refers to any user of the Website.
For the purposes of the Policy, “Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or in combination with additional information that We have or that We have access to.
This Privacy Policy applies globally and is designed to comply with applicable data protection laws, including with the Personal Information Protection and Electronic Documents Act (PIPEDA) and where applicable, Regulation (EU) 2016/679 (GDPR).
When do We collect information about You?
We may collect Personal Data about You in the following circumstances:
- when You access or use the Website and the Services;
- when You communicate with Us via email, social media, or other channels; and
- when Our authorized partners and agents provide Us with information required to facilitate Your account or transactions.
You are under no legal obligation to provide Personal Data and any information You provide is given freely.
What type of information do We collect?
We may collect the following categories of Personal Data:
- Identity and Compliance Information: Government-issued identification, date of birth, and UBO (Ultimate Beneficial Owner) details required for AML/KYC compliance.
- Financial and Transaction Information: Bank account details, wallet addresses, transaction history, source of funds documentation, and settlement instructions.
- Website usage information: this information includes online activity logs, traffic information (including without limitation, IP address, time of access, date of access, web and mobile page(s) visited, language used, software crash reports). Some of this information may not identify You, and therefore does not constitute Personal Data.
- Website activity information: Whenever You use the Website, We may monitor Your use of the Services and record Your activity such as searches performed, content viewed, duration of visits and interactions with Website content.
- Communication information: when You contact Us, including via the Website, social media networks or any other communications channel, You may provide Us with Your full name, corporate affiliation, address, certain contact information (such as email address and telephone number) and the content of Your communication.
You are responsible for ensuring the accuracy of the information that You provide. Inaccurate information may affect Our ability to provide some Services, as well as Our ability to contact You as contemplated in this Policy.
Cookies and Similar Technologies
We use cookies and similar technologies to track activity on our Website. Non-essential Cookies are used only with Your consent, which You may withdraw at any time via the Cookie Policy (Insert link). For information about Cookie rentention timeframes, please review our Cookie Policy.
What is the Legal basis for Processing Your Personal Data?
We process Personal Data on the following legal grounds:
- Performance of a Contract: When processing is necessary to provide the Services.
- Legitimate Interests: including for fraud prevention, analytics, security and improving Services.
- Legal Obligations: To comply with applicable laws or regulatory requirements (including the Proceeds of Crime (Money Laundering) and Terrorist Financing Act).
- Consent: When You have provided explicit consent (e.g., marketing communications).
Data Protection and Security
We employ multiple layers of security including encryption, firewalls, and secure servers — to protect Your Personal Data.
All financial data is transmitted using secure socket layer (SSL) technology and stored in compliance with global data protection standards.
How do We use Personal Data?
We may use Personal Data for the following purposes:
- To operate and improve the Website and Services.
- To contact You for operational, customer support, or security purposes.
- To personalise content or offers.
- To respond to Your queries, requests or complaints.
- To send marketing materials, subject to Your consent.
- To support business operations, including, but not limited to, the Website (such activities include back office functions, business development activities, strategic decision making, financing management, etc.).
- To protect Our and third parties’ interests, rights and assets, including the initiation or exercise or defence of legal claims.
- To comply with legal and regulatory requirements.
What Rights do You have?
Depending on Your location and applicable law, You may have the rights to:
- Right to Access: Request a copy of the Personal Data We hold about You.
- Right to Rectification: Correct inaccurate or incomplete Personal Data.
- Right to Erasure (Right to be forgotten): Request deletion of Personal Data, subject to legal exceptions. Please note that as a regulated MSB, we are legally required to retain transaction and identify records for a minimum statutory period. We cannot delete data that we are obliged to retain for compliance purposes.
- Right to Restriction: Request limited processing under certain conditions.
- Right to Data Portability: Receive Your Personal Data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent where processing is based on consent.
- Right to Lodge a Complaint: Lodge a complaint with your local data protection authority if you believe you data has been handled unlawfully (e.g., Office of the Privacy Commissioner of Canada or your local Data Protection Authority in the EU).
You may exercise these rights by contacting Us at info@cypherpayments.io
Sharing of Personal Data
We will not disclose/share Personal Data about You to third parties except as detailed in this Policy.
We may transfer Personal Data with entities that control Us, are controlled by Us or are under common control or ownership.
We may share Personal Data about You for the following purposes:
- Upon Your consent or instruction;
- Third parties providing Us services related to the offering of the Services (including IT providers, identity verification services, and cloud hosting);
- Banking and Custodial partners: Authorized financial institutions and third-party custodians that hold funds or settle transactions on Your behalf, strictly for the purpose of executing Your financial instructions;
- Upon Your consent, third parties offering products or services that match Your needs or preferences;
- In the event that We sell, assign or transfer some or all of Our business or assets to a successor or acquirer, or if We are acquired by or merge with a third party, or if We file for bankruptcy or become insolvent, or any other situation where Personal Data may be sold, assigned or transferred to a successor or acquirer;
- To protect Our rights, property and interest or those of third parties;
- To comply with legal or regulatory requirements or court orders.
Transfer of Personal Data abroad
We may transfer your Personal Data outside the jurisdiction in which You reside and store it in other jurisdictions/countries, including to third-party entities We engage that are necessary for the provision of the Services (such as IT providers, identity verification services, cloud hosting providers, and banking or custodial partners). We ensure a comparable level of protection through contractual measures as required by PIPEDA and, for transfers from the EEA, we implement Standard Contractual Clauses approved by the European Commission.
Retention of Personal Data
We retain Personal Data only for as long as necessary for the fulfilment of the purposes for which such Personal Data is collected. We may retain Personal Data about You for longer periods, if We find it necessary to comply with legal requirements applicable to Us (such as record-keeping obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act). Once retention period expires, We securely delete or anonymise data.
Automated Decision Making and Profiling
As a financial institution, We use automated systems to monitor transactions and detect fraud. We may use these systems to make automated decisions regarding Your account eligibility or to flag suspicious activity (e.g., stopping a transaction that appears fraudulent). If You believe an automated decision was made in error, You may contact Us to request a manual review.
Children’s Privacy
Our Services are strictly intended for individuals aged 18 and older. We do not knowingly collect Personal Data from anyone under the age of 18. If We become aware that We have collected Personal Data from a minor without verification of parental consent, We will take steps to remove that information from Our servers.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Policy
We may update this Policy from time to time. Any changes will be posted on this page with an updated revision date, so please visit this page regularly for updates.
Contact Us
For privacy-related inquiries, please contact Us at info@cypherpayments.io

