This Privacy Policy (the "Policy") describes what data the BitMoment platform (the "Platform", the "Service", "BitMoment") processes, for what purposes, on what grounds, to whom data may be transferred and what protection measures are applied.
This Policy forms an integral part of the User Agreement. By using the Service, you confirm that you have read this Policy, agree to it and undertake to comply with it. See also: User Agreement, AML/KYC Policy, Cookie Policy, Procedure for Law-Enforcement Requests.
1. General Provisions
1.1. The data-processing operator is BitMoment. The applicable law and the procedure for resolving disputes are determined by the User Agreement.
1.2. This Policy applies to all data processed in connection with the use of the Service. By using the Service, the user acknowledges that the processing of data to the extent and for the purposes described in this Policy is necessary for the provision of the Service and agrees to it.
1.3. The Platform determines the composition, purposes, methods and periods of data processing at its discretion within the limits set out in this Policy, based on the need to provide the Service, ensure security and comply with the requirements of applicable law.
1.4. The Service is not intended for persons who have not reached the age from which applicable law permits the independent use of similar services. The Platform does not purposefully collect data of such persons.
2. Terms and Definitions
| Term | Meaning |
|---|---|
| Data | Any information relating to the user, directly or indirectly, including identification, contact, technical and behavioural data. |
| Identification data | Information enabling identity to be established (name, date of birth, document details, facial image, etc.). |
| Technical data | IP address, device identifiers, browser data, access logs, device fingerprint and other information generated when using the Service. |
| Operator | BitMoment as the person determining the purposes and methods of data processing. |
| Service provider (processor) | A third party processing data on the instructions and in the interests of the Platform. |
| Processing | Any operation with data: collection, recording, storage, use, transfer, anonymisation, deletion and others. |
3. What Data Is Processed
3.1. Identification and verification (KYC) data: name, date of birth, citizenship, country of residence, details of an identity document, photograph of the document and the face (selfie), information on politically-exposed-person status and beneficial owner.
3.2. Contact and account data: email address, telephone number, nickname, identifiers of linked channels (including Telegram), authentication data (in protected form).
3.3. Operational data: information on advertisements, trades, disputes, correspondence within trades and disputes, reviews, ratings, referral activity, balances and transactions.
3.4. Cryptocurrency data: deposit and withdrawal crypto-addresses, transaction hashes, results of blockchain analytics and risk assessment of addresses and transactions.
3.5. Technical data: IP address, IP-based geolocation, data on VPN/proxy/hosting, device identifiers and fingerprint, browser and operating-system data, access logs, cookies and similar technologies (see the Cookie Policy).
3.6. Data obtained from third parties: results of screening against sanctions and other lists, data of verification and blockchain-analytics providers, information received from competent authorities.
3.7. The Platform is entitled to process other data where this is necessary for the provision of the Service, the ensuring of security, the resolution of disputes or compliance with the requirements of applicable law.
4. Purposes of Processing
4.1. Data is processed, among other things, for the following purposes:
- the provision and functioning of the Service, the performance of the User Agreement;
- registration, identification and verification of the user, access control;
- compliance with AML/CFT requirements, screening, transaction monitoring, risk assessment (see the AML/KYC Policy);
- ensuring security, preventing fraud, detecting multi-accounts and unlawful activity (digital dossier of devices, IP and links);
- resolving disputes and handling enquiries;
- improving, analysing and developing the Service;
- informing the user about the operation of the Service and significant changes;
- protecting the rights and legitimate interests of the Platform, complying with the requirements of competent authorities and applicable law.
4.2. The Platform is entitled to anonymise and aggregate data and to process such data without the restrictions of this Policy.
5. Grounds for Processing
5.1. Processing is carried out on grounds permitted by applicable law, including: the necessity of performing the User Agreement; the user's consent expressed in the manner established by the User Agreement; the necessity of complying with the requirements of applicable law (including AML/CFT); the Platform's legitimate interests in ensuring security, preventing abuse and protecting rights.
5.2. By using the Service, the user provides the consent necessary for the purposes of this Policy. The scope of obligations independently assumed by the Platform is limited to the minimum necessary for the functioning of the Service and compliance with applicable law.
6. Transfer of Data to Third Parties
6.1. The Platform is entitled to engage service providers and to transfer data to them to the extent necessary for the performance of their functions, including: providers of blockchain analytics and address scoring; providers of sanctions and other lists; document-verification services; infrastructure, cloud, communication and analytics providers; mailing and support providers.
6.2. The Platform is entitled to transfer data to competent and law-enforcement authorities in the cases provided for by applicable law, in accordance with the Procedure for Law-Enforcement Requests, without an obligation to notify the user where notification is prohibited by applicable law or may impede an investigation.
6.3. The Platform is entitled to transfer data to legal successors in the event of reorganisation, merger, or the sale of the business or part of it, subject to compliance with the principles of this Policy.
6.4. The engagement of service providers does not relieve the Platform of liability within the limits established by applicable law; transfer is carried out on terms ensuring confidentiality.
7. Cross-Border Transfer and Storage
7.1. Data may be processed and stored on servers and with service providers located outside the user's country of residence, including in the Platform's jurisdiction of regulation. By using the Service, the user acknowledges the necessity of such cross-border transfer for the provision of the Service and agrees to it within the limits permitted by applicable law.
7.2. The Platform applies reasonable measures to protect transferred data to the maximum extent permitted by applicable law.
8. Retention Period
8.1. Data is retained for the period necessary for the purposes of processing and for the period established by applicable law for identification documents and information on transactions (as a rule, no less than five years from the termination of the relationship with the user or the completion of the transaction), unless applicable law provides for a different period.
8.2. Upon expiry of the retention period, data is deleted or anonymised. Deletion of an account does not entail the deletion of data the retention of which is mandatory under applicable law or is necessary to protect the rights of the Platform, resolve disputes and comply with AML/CFT requirements.
9. Data Security
9.1. The Platform applies organisational and technical data-protection measures (including encryption of sensitive data at rest, access control, logging) appropriate to the nature of the processing, to the maximum extent permitted by applicable law.
9.2. No method of transferring or storing data is absolutely secure. The Platform does not warrant the absolute security of data and is not liable for the consequences of unauthorised access not caused by its fault, to the maximum extent permitted by applicable law. The user independently ensures the protection of the user's authentication data and devices (see "Security").
10. User Rights and Their Exercise
10.1. Within the limits provided for by applicable law, the user is entitled to request information on the processing of the user's data, its rectification or deletion. Requests are sent to legal@bitmoment.pro.
10.2. The exercise of user rights is carried out to the extent and in the manner permitted by applicable law and may not lead to a breach of AML/CFT requirements, the rights of third parties, or impede the protection of the Platform's rights. The Platform is entitled to refuse to satisfy a request if its performance is contrary to applicable law, AML/CFT requirements or is capable of impeding an investigation, without an obligation to disclose the grounds for refusal in cases where such disclosure is prohibited or undesirable for security reasons.
10.3. The Platform is entitled to conduct reasonable verification of the applicant's identity before performing a request in order to prevent abuse.
11. Cookies and Similar Technologies
11.1. The Service uses cookies and similar technologies. The procedure for their use is set out in the Cookie Policy.
12. Technical Nature of the Service
12.1. The Platform provides a technical capability for P2P interaction and an escrow service; it is not a bank, financial adviser or party to transactions between users. This does not cancel the Platform's actual AML/CFT role. The scope of data-processing obligations attributable to the Platform is limited to its actual role as a technical intermediary, to the maximum extent permitted by applicable law.
13. Limitation of Liability and Indemnification
13.1. To the maximum extent permitted by applicable law, the Platform is not liable for losses and consequences caused by the user's provision of inaccurate data, the actions of third parties, unauthorised access not caused by the Platform's fault, or the application of the control and data-processing measures provided for by this Policy and the AML/KYC Policy.
13.2. The user shall indemnify the Platform for documented losses and costs, and shall satisfy third-party claims, arising from the user's provision of inaccurate data or breach of this Policy.
13.3. The provisions of this section are not intended to exclude liability to the extent that such exclusion is not expressly permitted by applicable law; to that extent, they apply to the maximum permissible degree.
14. Severability
14.1. The recognition of any provision of this Policy as invalid or unenforceable does not entail the invalidity of the remaining provisions. An invalid provision is applied and construed to the maximum extent permitted by applicable law so as to achieve its original purpose; in all other respects the Policy remains in force. All provisions apply "to the maximum extent permitted by applicable law".
14.2. The applicable law and the procedure for resolving disputes are determined by the User Agreement.
15. Amendments to the Policy
15.1. BitMoment is entitled, at its discretion, to amend this Policy in connection with changes to the Service, changes in applicable law or on other grounds.
15.2. The current version of the Policy is published at /support/docs/privacy-policy. The version history is available at /support/docs/privacy-policy/history.
15.3. The procedure for accepting this document and the legal consequences of its amendment are determined by the User Agreement, of which this document forms an integral part. Consent is expressed in the manner established by the User Agreement and does not require separate confirmation for each version.
16. Contacts
For matters relating to this Policy, data processing and official requests, please contact:
- Email (AML/KYC, official requests): legal@bitmoment.pro
- Email (general support): support@bitmoment.pro
- Telegram support: @BitMomentSupportBot
The procedure for handling requests from competent authorities is set out in the document "Procedure for Law-Enforcement Requests".
Operator: BitMoment.
