Privacy Policy (Crypto Exchange)
1. GENERAL
1.1. This Privacy Policy (the Policy) has been developed in accordance with the laws of the Republic of Uzbekistan, including the Law of the Republic of Uzbekistan On Countering the Legalization of Proceeds from Criminal Activities, Financing of Terrorism and Financing the Proliferation of Weapons of Mass Destruction, Internal Control Rules for Countering the Legalization of Proceeds from Criminal activities, Financing of Terrorism and Financing the Proliferation of Weapons of Mass Destruction for Persons Engaged in Activities in the Field of Turnover of Crypto Assets, Rules for Trading Crypto Assets on a Crypto Exchange, and other legal acts regulating the processing and protection of personal data.
1.2. The Policy defines the procedure and conditions for collection, processing, storage, transfer and protection of personal data of customers and other participants in transactions carried out on the crypto exchange.
1.3. The purpose of this Policy is to ensure the protection of human and civil rights and freedoms when processing personal data, including the protection of the rights to privacy, personal and family secrets.
1.4. The following basic concepts are used in this Policy:
Crypto Exchange shall mean ASTERIUM Joint Stock Company, which has received a license to operate a crypto exchange in appropriate manner, ensuring the organization of trading in crypto assets.
Personal Data shall mean any information recorded on electronic, paper and (or) other tangible media, related to a specific individual or enabling his/her identification (the subject of personal data).
Personal Data Processing shall mean any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access) including cross-border, depersonalization, blocking, deletion, and destruction of personal data.
Client shall mean an individual or legal person who uses the services of the crypto exchange.
Beneficial Owner shall mean an individual who ultimately owns the property rights or controls the client, including a legal entity in whose interests a transaction with funds or other property is carried out.
1.5. The storage (deposit) of reports and personal data in accordance with the Rules for Trading Crypto-Assets on the Crypto-Exchange is carried out directly by the crypto-exchange, ASTERIUM Joint Stock Company:
- Name: Joint Stock Company ASTERIUM
- Location: Republic of Uzbekistan, Tashkent, Said Baraka Street, 12a
- Email address: [email protected]
- Phone number: 97 777 5558
2. PURPOSES OF PERSONAL DATA COLLECTION AND PROCESSING
2.1. Personal data is collected and processed by the crypto exchange for the following purposes:
2.1.1. Identification and verification of clients and their beneficial owners;
2.1.2. Establishing and maintaining contractual relationships with clients;
2.1.3. Providing access to the electronic platform of the crypto exchange;
2.1.4. Carrying out transactions for the purchase, sale and/or exchange of crypto assets;
2.1.5. Clearing and settlement of crypto-exchange transactions;
2.1.6. Fulfilling the obligations of the crypto exchange to counteract the legalization of proceeds from criminal activities, financing of terrorism and proliferation of weapons of mass destruction;
2.1.7. Compliance with legal requirements, including taxation;
2.1.8. Detection, suppression and prevention of fraudulent and other illegal actions;
2.1.9. Communication with clients regarding the provision of services;
2.1.10. Improving the quality of services provided and operation of the crypto exchange electronic platform.
3. SCOPE OF PERSONAL DATA
3.1. Depending on the category of the personal data subject, the crypto exchange may collect and process the following personal data:
3.1.1. For individuals:
• Surname, first name and patronymic;
• Date and place of birth;
• Taxpayer identification number or personal identification number of an individual;
• Citizenship information;
• Place of permanent and/or temporary residence;
• Details of the identity document (number and series of the document, date of issue and issuing authority);
• Mobile phone number;
• Email address and other contact details;
• Financial data required for transactions;
• Source of the funds' origin;
• Status of a public official (if available);
• Address of the crypto wallet;
• Details of transactions with crypto assets.
3.1.2. For individual entrepreneurs:
• All personal data specified in clause 3.1.1;
• Details of state registration as an individual entrepreneur;
• Types of activities carried out;
• Available licenses for the types of activities to be licensed.
3.1.3. For legal entities:
• Full and abbreviated name;
• Details of the state registration: date, number, name of the registering authority;
• Taxpayer identification number;
• Location (postal address);
• Details of available licenses: type of activity, license number and date of issue, issued by, validity period;
• Identification data of an individual acting on behalf of the legal entity;
• Details of the founders (shareholders, members) and their shares in the authorized capital;
• Amount of the registered and paid-up authorized capital;
• Details of management bodies (structure and personnel);
• Phone numbers;
• Personal data of the beneficial owners in accordance with clause 3.1.1.
3.2. The crypto exchange does not collect and process special categories of personal data related to race, nationality, political views, religious or philosophical beliefs, except in cases provided for by law.
4. PROCEDURE AND CONDITIONS OF PERSONAL DATA PROCESSING
4.1. The personal data are processed based on the client's consent to the processing of its personal data, except in cases provided for by law.
4.2. Consent to the processing of personal data may be given by the client or its representative in any form that allows to confirm that it is received, including:
• A written form;
• An electronic form when registering an account;
• Specific actions when using the electronic platform of the crypto exchange.
• Acceptance of the public offer
• Otherwise
4.3. The crypto exchange has the right to entrust the processing of personal data to a third party based on a contract concluded with this person, provided that such person complies with the principles and rules of personal data processing provided for by law.
4.4. The crypto exchange identifies and verifies clients and beneficial owners using reliable sources of information and documents in accordance with the laws on countering the legalization of proceeds from criminal activities, financing of terrorism and proliferation of weapons of mass destruction.
4.5. The crypto exchange applies enhanced due diligence measures for clients classified as high-risk, including public officials, their family members, and individuals close to public officials.
4.6. The crypto exchange has the right, with the consent of customers, to record audio or video conversations with them, including correspondence, and to store such information for at least 5 years.
4.7. The crypto exchange does not establish a relationship with:
• Minors;
• Persons included in the list of persons involved in or suspected of participating in terrorist activities or proliferation of weapons of mass destruction, in accordance with the laws on countering the legalization of proceeds from criminal activities, financing of terrorism and proliferation of weapons of mass destruction.
4.8. The personal data are processed both with and without the use of automation tools.
4.9. The crypto exchange takes the necessary measures to clarify incomplete or inaccurate personal data.
4.10. The crypto exchange shall regularly (at least once a year) update the data obtained during due diligence of clients and keep them up to date.
5. TRANSFER OF PERSONAL DATA
5.1. The crypto exchange has the right to transfer personal data of clients and other subjects of personal data to third parties in the following cases:
5.1.1. Transfer of personal data to a specially authorized state body (Department for Combating Economic Crimes under the General Prosecutor's Office of the Republic of Uzbekistan) on suspicious transactions identified during internal control, no later than one business day following the day of their detection;
5.1.2. Transfer of personal data to the National Agency for Advanced Projects of the Republic of Uzbekistan as part of its monitoring and control of compliance with the requirements of laws by the crypto exchange;
5.1.3. At the request of law enforcement, judicial or other government agencies in cases stipulated by law.;
5.1.4. In order to carry out clearing and settlement of transactions concluded on the crypto exchange;
5.1.5. With the consent of the personal data subject or in other cases provided for by law.
5.2. When transferring personal data to third parties, the crypto exchange shall:
5.2.1. Transfer personal data only to the extent necessary to achieve the transfer objectives;
5.2.2. Require third parties to respect the confidentiality of personal data transferred;
5.2.3. Ensure the security of the transmitted personal data using technical and organizational protection measures.
5.3. By submitting its personal data to the crypto exchange, the client confirms its full and unconditional consent to all types of processing, use and transfer provided for by the laws on personal data, including cross-border transfer and storage.
6. STORAGE OF PERSONAL DATA
6.1. Personal data are stored in a form that makes it possible to identify the subject of personal data, no longer than the purposes of personal data processing require, unless the period of personal data storage is defined by law or contract.
6.2. The crypto exchange is required to store information about transactions with crypto assets, cash or other property, as well as identification data and materials for proper customer verification, including business correspondence, the results of any analysis, for the time limits defined by law, but not less than five years after the transactions or termination of customer relations.
6.3. Personal data are stored electronically and/or on paper.
6.4. Electronic versions of documents containing personal data shall be archived programmatically, recorded on electronic media and stored by a responsible officer together with their list in a fireproof and sealed safe.
6.5. Paper documents containing personal data are stored in a specially equipped room or in a fireproof and sealed safe with limited access.
6.6. The crypto exchange provides backup of all data on transactions (operations) made by customers at the end of each day.
7. PERSONAL DATA PROTECTION
7.1. The crypto exchange takes the necessary legal, organizational and technical measures to protect personal data from unlawful or accidental access to them, destruction, modification, blocking, copying, provision, dissemination of personal data, as well as from other unlawful actions with respect to personal data.
7.2. These measures include:
7.2.1. Appointment of a responsible employee for organization of personal data processing and protection;
7.2.2. Publication of internal documents defining the policy of the crypto exchange regarding the processing of personal data, local regulations on the processing of personal data, as well as local regulations defining procedures aimed at preventing and detecting breaches of the law;
7.2.3. Application of legal, organizational and technical measures to ensure the security of personal data, including:
• Identification of threats to the security of personal data during their processing;
• Use of information protection tools that have passed the procedure for assessing compliance with legal requirements;
• Assessment of the effectiveness of measures taken to ensure the security of personal data;
• Setting rules for access to personal data;
• Control over the measures taken to ensure the security of personal data.
7.2.4. Detection of unauthorized access to personal data and taking appropriate measures;
7.2.5. Recovery of personal data modified or destroyed due to unauthorized access to them;
7.2.6. Control over the measures taken to ensure the security of personal data.
7.3. Only those employees of the crypto exchange who need such access to perform their official duties have access to personal data of clients.
7.4. Employees of the crypto exchange who have access to personal data shall:
• Not disclose personal data obtained in the course of performing their functions;
• Not use the information received for personal purposes or for the interests of third parties;
• Ensure the safety and return of documents received during the implementation of internal control;
• Comply with the requirements of this Policy and other local regulations of the crypto exchange in the field of personal data protection.
8. RIGHTS OF PERSONAL DATA SUBJECTS
8.1. The personal data subject has the right to:
8.1.1. To receive information regarding the processing of its personal data;
8.1.2. To clarify, block or destroy its personal data if the personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing;
8.1.3. To revoke its consent to the processing of personal data, if such consent has been given;
8.1.4. To appeal the actions or omissions of the crypto exchange to the authorized body for the protection of the rights of personal data subjects or in court;
8.1.5. To protect its rights and legitimate interests, including compensation for damages and (or) compensation for moral damage in court;
8.1.6. Other rights provided for by law.
8.2. The subject of personal data has the right to apply to the crypto-exchange with a request to provide it with information about the processing of his personal data. The crypto exchange shall provide such information within 15 days after receiving the request.
9. NOTIFICATION OF BREACHES OF PERSONAL DATA SECURITY
9.1. In case of detection of a breach of the security of personal data, which has led or may lead to unauthorized access, destruction, modification, blocking, copying, provision, dissemination of personal data, the crypto exchange shall:
9.1.1. Take immediate measures to eliminate the breach and minimize possible damage;
9.1.2. Notify the authorized body for the protection of the rights of personal data subjects about the breach in accordance with the procedure established by law;
9.1.3. Notify the subjects of personal data whose personal data has been affected by the breach, if such breach creates a high risk of breaching their rights and freedoms.
9.2. The notification of a breach of personal data security shall contain information about the nature of the breach, possible consequences, and measures taken to remove the breach and minimize possible damage.
10. RESPONSIBILITY
10.1. The crypto exchange and its personnel are responsible for breaching the requirements of the law on personal data and this Policy in accordance with the laws of the Republic of Uzbekistan.
10.2. Persons guilty of breaching the rules governing the processing and protection of personal data may be brought to disciplinary, administrative, civil or criminal liability in accordance with the procedure established by law.
10.3. The head of the crypto exchange and the responsible office are liable in case of breaching this Policy in accordance with the law.
11. FINAL PROVISIONS
11.1. This Policy comes into force from the moment of its approval by the head of the crypto exchange.
11.2. The crypto exchange has the right to make changes and additions to this Policy. The new version of the Policy comes into force after its approval by the head of the crypto exchange, unless otherwise provided by the new version of the Policy.
11.3. The current version of the Policy shall be publicly available on the official website of the crypto exchange.
11.4. In the event of changes in the laws of the Republic of Uzbekistan in the field of personal data and countering the legalization of proceeds from criminal activities, financing of terrorism and proliferation of weapons of mass destruction, this Policy shall apply to the extent that it does not contradict such laws, until appropriate changes are made.
11.5. Issues not regulated by this Policy shall be resolved in accordance with the applicable laws of the Republic of Uzbekistan.
This document is the intellectual property of Joint Stock Company ASTERIUM Joint Stock Company. Any copying, distribution or use of this document in whole or in part without the written permission of Joint Stock Company ASTERIUM is prohibited and is punishable by law.
© Joint Stock Company ASTERIUM
This document is published in its current version and updated by the legal team as changes occur.