This Privacy Policy constitutes a comprehensive framework governing how Bridgenix and its affiliated entities, subsidiaries, and related companies (collectively referred to as "Bridgenix," "we," "us," or "our") collect, process, utilise, store, transfer, and disclose personal data and information relating to our platform users, customers, and visitors (referred to as "you," "your," or "data subjects"). This Policy establishes the foundation for our data protection practices and applies universally to all personal data collected and processed by Bridgenix through our comprehensive suite of services, including but not limited to our primary website platforms, proprietary payment infrastructure, mobile applications across all operating systems, application programming interfaces (APIs), software development kits (SDKs), merchant integration tools, and any other technological solutions, services, or products we provide under the Bridgenix brand (collectively, the "Services").
Bridgenix operates as a global financial technology platform specialising in payment processing. Our commitment to protecting your privacy and ensuring the security of your personal data forms the cornerstone of our operational philosophy. We recognise that trust is fundamental to our relationship with our users, and we maintain this trust through unwavering transparency, adherence to the highest international data protection standards, and strict compliance with applicable data protection laws and regulations across all jurisdictions in which we operate.
Our data protection framework is built upon compliance with major international privacy legislation, including but not limited to the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and its amendment the California Privacy Rights Act (CPRA), the UK Data Protection Act 2018, the Personal Data Protection Act of Singapore (PDPA), the Lei Geral de Proteção de Dados (LGPD) of Brazil, and various other regional and national financial privacy regulations that govern payment processing platforms globally.
Bridgenix collects and processes various categories of personal data that are essential for the provision of our Services, compliance with our legal and regulatory obligations, and the maintenance of the security and integrity of our platform. The comprehensive nature of our data collection reflects the stringent requirements of financial services regulation, anti-money laundering compliance, and the unique challenges associated with digital asset processing.
Our identity verification processes collect comprehensive personal identification information necessary for compliance with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations across multiple jurisdictions. This includes your complete legal name as it appears on government-issued identification documents, any previous names, maiden names, or aliases you may have used, your date of birth, gender identity, nationality, and current country of residence. We also collect detailed contact information including your primary email address, physical postal addresses both current and historical, telephone numbers including mobile and landline numbers, and emergency contact information where applicable.
Government-issued identification documents form a critical component of our verification process, including passport information, national identity cards, driver's licenses, social security numbers or equivalent national identification numbers, and other official documentation that establishes your identity and legal status. Additionally, we collect proof of address documentation such as utility bills, bank statements, government correspondence, or lease agreements to verify your current residential address.
Our biometric verification processes may include the collection of selfies, video verification data, and other biometric identifiers used for identity confirmation and ongoing authentication. This biometric data is processed using advanced facial recognition technology and liveness detection systems to prevent fraud and ensure the security of your account.
The processing of financial and transactional data is fundamental to our Services and encompasses a broad range of information related to your financial activities and digital asset transactions. This includes comprehensive bank account details such as account numbers, routing numbers, SWIFT codes, International Bank Account Numbers (IBANs), and other banking identifiers necessary for facilitating fiat currency transactions and withdrawals.
Payment card information, while not stored directly on our systems in full, is processed through our payment processing partners and includes card numbers, expiration dates, and security codes necessary for processing transactions. We maintain detailed transactional records including complete transaction histories, amounts, dates and times, sender and recipient details.
We also collect and maintain records of your account balances across various currencies, information regarding the source of your funds and wealth for compliance purposes, and portfolio composition. This financial data is essential for providing accurate account management, transaction processing, and regulatory reporting.
For business accounts and corporate clients, we collect extensive professional and employment-related information necessary for business verification and compliance with corporate KYC requirements. This includes your job title, professional roles and responsibilities, company name and registration details, business registration numbers, tax identification numbers, and other corporate identifiers.
We also collect information regarding corporate ownership structures, ultimate beneficial owner (UBO) information, details of authorised signatories, board members and key personnel, business contact information, and documentation establishing the legitimacy and regulatory compliance of your business operations. This information is critical for ensuring compliance with anti-money laundering regulations and preventing the use of our platform for illicit activities.
Our technical data collection encompasses comprehensive information about your interaction with our Services, including detailed IP address logs, device information such as device type, operating system, unique device identifiers, and hardware specifications. We collect browser type and version information, time zone settings, and geolocation data derived from IP addresses to ensure appropriate regulatory compliance and service delivery.
Website and application usage data forms a significant component of our technical data collection, including pages visited, services accessed, clickstream data, engagement metrics, session duration, and user behaviour patterns. This information is used to optimise our Services, improve user experience, and detect potential security threats or fraudulent activities.
We maintain comprehensive log data including access times, error reports, API usage statistics, and system performance metrics. This technical data is essential for maintaining the security and reliability of our Services while also enabling us to provide personalised and efficient service delivery.
All communications between you and Bridgenix are recorded and maintained for quality assurance, compliance, and support purposes. This includes information provided in support tickets, email correspondence, live chat logs, and recordings of phone conversations where legally permitted. We also collect survey responses, feedback, testimonials, and other communications you provide to us voluntarily.
Additionally, we may collect publicly available information from social media platforms where you interact with our official accounts, participate in our community forums, or otherwise engage with our public communications. This information is used to better understand our user community and improve our Services.
We employ a comprehensive suite of cookies, web beacons, pixel tags, and other tracking technologies to enhance your experience with our Services. These technologies help us analyse website traffic, personalise content, maintain session integrity, and implement security measures. Essential cookies are necessary for basic functionality, while analytics cookies help us understand user behaviour and improve our Services.
Marketing cookies enable us to deliver targeted content and advertisements based on your interests and usage patterns, while security cookies help detect and prevent fraudulent activities. You maintain control over most cookie settings through your browser preferences, though disabling certain cookies may impact the functionality of our Services.
Our data collection practices employ multiple methodologies designed to ensure comprehensive coverage while maintaining transparency and user control. These methodologies reflect industry best practices and regulatory requirements for financial services platforms operating in the digital asset space.
The primary method of data collection involves direct submission from users through our various interfaces and touchpoints. This occurs when you create an account with our platform, complete our comprehensive onboarding process, submit verification documentation, or apply for enhanced service features. Direct collection also occurs when you complete forms on our website or within our mobile applications, communicate with our support team through various channels, or participate in surveys, promotional activities, or community events.
Our user interfaces are designed to clearly indicate when personal data is being collected, the purposes for which it will be used, and your rights regarding that data. We implement progressive data collection practices, gathering only the information necessary for each stage of your relationship with our platform while providing clear explanations for why specific information is required.
As you navigate and interact with our Services, we automatically collect technical and usage data through sophisticated tracking and monitoring systems. This automated collection includes information gathered through cookies, web beacons, and similar technologies that monitor your interaction patterns, preferences, and behaviour on our platform.
Our automated systems continuously monitor for security threats, fraudulent activities, and compliance violations, collecting data necessary to maintain the integrity and security of our Services. This includes behavioural analysis, pattern recognition, and anomaly detection systems that operate continuously to protect both individual users and the broader platform ecosystem.
We supplement our direct data collection with information obtained from authorised third-party sources, including licensed identity verification services, sanctions screening providers, credit bureaus, and other financial data providers. These sources are essential for comprehensive due diligence and compliance with regulatory requirements.
We also collect information from publicly available sources, including government registries, public blockchain data where legally permissible, and other legitimate public records. While we may analyse public blockchain data for compliance and security purposes, we do not actively seek to re-identify individuals from pseudonymous blockchain transactions.
Business partners and affiliates may provide additional data where you have engaged with them and provided appropriate consent for data sharing. All third-party data collection is conducted in accordance with applicable privacy laws and our contractual obligations with these partners.
Bridgenix processes personal data exclusively for legitimate, lawful purposes that align with our business objectives, regulatory obligations, and user expectations. Our processing activities are grounded in recognised legal bases under applicable data protection laws and are subject to regular review and assessment to ensure continued compliance and proportionality.
The primary purpose of our data processing activities is to provide, maintain, and improve our core Services. This includes creating and managing user accounts, facilitating the onboarding process for new users, processing transactions, executing automated trading instructions, and providing comprehensive customer support and technical assistance.
We process personal data to personalise your experience on our platform, deliver tailored content and features based on your preferences and usage patterns, and maintain the technical infrastructure necessary for secure and efficient service delivery. This processing is essential for fulfilling our contractual obligations to you and ensuring that our Services meet your expectations and requirements.
Our platform operations also require processing personal data to analyse usage patterns, identify areas for improvement, develop new products and features, and maintain the overall performance and reliability of our Services.
As a financial services platform, Bridgenix is subject to extensive regulatory requirements that mandate the collection and processing of personal data. These obligations include compliance with Anti-Money Laundering (AML) regulations, Know Your Customer (KYC) requirements, sanctions screening, and politically exposed person (PEP) identification across multiple jurisdictions.
We process personal data to fulfil financial reporting obligations, tax compliance requirements, and other legal obligations mandated by regulatory authorities in the jurisdictions where we operate. This includes generating reports for regulatory authorities, responding to lawful requests from law enforcement agencies, and maintaining records as required by applicable laws and regulations.
Our compliance processes also involve ongoing monitoring and screening of transactions and account activities to detect and prevent money laundering, terrorist financing, and other financial crimes. This processing is essential for maintaining our regulatory licenses and ensuring the integrity of the global financial system.
The security of our platform and the protection of our users' assets and information is paramount to our operations. We process personal data to monitor and detect suspicious or fraudulent activities, implement and maintain robust security measures, and investigate potential violations of our terms of service and internal policies.
Our security systems employ advanced analytics, machine learning, and artificial intelligence technologies to identify patterns indicative of fraudulent behaviour, unauthorised access attempts, and other security threats. This processing enables us to provide proactive protection for our users and maintain the integrity of our platform.
We also process personal data to implement authentication and access controls, maintain audit trails of account activities, and respond to security incidents when they occur. This processing is essential for protecting both individual users and the broader platform ecosystem from security threats and malicious activities.
Our internal operations require processing personal data for record-keeping, administrative purposes, and business analytics. This includes maintaining accurate financial records, conducting internal audits, ensuring operational efficiency, and analysing market trends and user behaviour to inform business decisions.
We process personal data to generate insights about platform usage, transaction patterns, and user preferences that enable us to optimise our Services and develop new offerings. This processing is conducted in accordance with privacy-by-design principles and, where possible, utilises aggregated and anonymised data to minimise privacy impact while maximising business value.
Our business analytics also support risk management activities, including credit risk assessment, operational risk monitoring, and compliance risk evaluation. This processing enables us to maintain a sustainable and compliant business while providing valuable services to our users.
Where legally permissible and in accordance with your preferences, we process personal data to provide you with important updates regarding your account, changes to our Services, and modifications to our policies and procedures. This processing ensures that you remain informed about developments that may affect your use of our Services.
We also process personal data to provide information about new products, services, promotions, and events that may be of interest to you, in accordance with your communication preferences and applicable marketing laws. You maintain full control over your marketing preferences and have the right to opt out of marketing communications at any time.
Our communication processing includes maintaining preference centres, managing subscription lists, and ensuring compliance with anti-spam regulations and other communication-related legal requirements. This processing is essential for maintaining appropriate and legal communication with our user base.
Bridgenix maintains strict policies regarding the disclosure and sharing of personal data, ensuring that any sharing is conducted only when necessary for legitimate business purposes, regulatory compliance, or user benefit. Our disclosure practices are designed to maintain the confidentiality and security of your personal data while enabling us to provide comprehensive services and meet our legal obligations.
Access to personal data within Bridgenix is strictly controlled through role-based access controls and the principle of least privilege. Only authorised personnel who have a legitimate business need to access specific types of personal data are granted such access, and all access is subject to comprehensive audit trails and monitoring systems.
Our employees and contractors undergo rigorous background checks, security training, and are bound by strict confidentiality agreements that extend beyond the termination of their employment or engagement with Bridgenix. Regular access reviews ensure that permissions remain appropriate and that any changes in job responsibilities are reflected in data access privileges.
We maintain detailed records of all access to personal data, including the identity of the accessor, the time and nature of access, and the business justification for such access. This comprehensive audit trail enables us to detect and investigate any unauthorised access attempts and ensure accountability for data handling practices.
Bridgenix engages carefully vetted service providers and business partners who assist us in delivering our Services and maintaining our operations. These relationships are governed by comprehensive data processing agreements that establish strict requirements for data protection, security, and confidentiality.
Our service providers include payment processors and financial institutions that facilitate fiat currency transactions, identity verification and fraud prevention services that support our compliance programs, cloud hosting and infrastructure providers that maintain our technical platform, and customer support and communication platforms that enable us to assist our users effectively.
We also work with audit firms, legal advisors, and professional consultants who may require access to personal data in the course of providing their services. Additionally, marketing and analytics providers may receive aggregated and anonymised data to help us understand market trends and improve our Services.
All service providers are contractually obligated to maintain the same level of data protection that we provide directly, and they are prohibited from using personal data for their own independent purposes. We conduct regular assessments of our service providers' data protection practices and maintain the right to audit their compliance with our requirements.
Bridgenix cooperates fully with regulatory authorities and law enforcement agencies in accordance with applicable laws and regulations. We disclose personal data when required by law, regulation, court order, or other lawful governmental requests, including disclosures necessary to comply with AML/KYC obligations, tax reporting requirements, and investigations of financial crimes.
Our cooperation with authorities includes providing information necessary for regulatory examinations, responding to subpoenas and search warrants, and assisting in investigations of suspected criminal activities. We maintain detailed records of all such disclosures and ensure that they are conducted in accordance with applicable legal procedures and protections.
Where legally permissible, we may notify affected users of requests for their personal data, unless such notification is prohibited by law or court order. We also maintain the right to challenge requests that we believe are overly broad, legally insufficient, or otherwise inappropriate.
In connection with any merger, acquisition, sale of assets, financing, or other corporate transaction involving Bridgenix, personal data may be transferred to the acquiring or resulting entity. We ensure that appropriate safeguards are in place to protect personal data throughout any such transaction and that the receiving entity commits to maintaining equivalent data protection standards.
We provide advance notice to affected users whenever possible regarding any corporate transaction that may result in the transfer of their personal data. Such notices include information about the receiving entity, any changes to data protection practices, and the rights available to users regarding their personal data.
Any corporate transaction involving personal data is structured to ensure continuity of service and protection for our users while enabling legitimate business operations and growth opportunities.
Bridgenix has implemented a comprehensive, multi-layered security framework designed to protect personal data from unauthorised access, alteration, disclosure, or destruction. Our security measures are continuously reviewed, updated, and enhanced to address evolving threats and maintain compliance with the highest international security standards.
Our access control systems implement strict role-based access controls (RBAC) that ensure access to personal data is limited to authorised personnel with legitimate business needs. Multi-factor authentication (MFA) is mandatory for all access to systems containing personal data, and we employ advanced authentication technologies including biometric verification where appropriate.
User account security is enhanced through optional but recommended MFA for platform access, device registration and management systems, and advanced authentication options including hardware security keys. We continuously monitor for suspicious authentication attempts and implement adaptive authentication measures that respond to risk indicators.
Our access control systems maintain comprehensive audit logs of all access attempts, successful authentications, and data access activities. These logs are regularly reviewed and analysed to detect potential security threats and ensure compliance with our security policies.
Our technical infrastructure is deployed in highly secure cloud environments provided by leading cloud service providers who maintain industry-leading certifications including SOC 2 Type II, ISO 27001, and other relevant security standards. These environments provide physical security, network security, and infrastructure redundancy that exceeds industry standards.
We implement comprehensive monitoring and logging systems that track all system activities, user behaviours, and potential security threats in real-time. Our Security Operations Centre (SOC) operates continuously to monitor for indicators of compromise, analyse security events, and respond to potential threats.
Network security measures include firewalls, intrusion detection and prevention systems, distributed denial-of-service (DDoS) protection, and network segmentation that isolates sensitive systems from general network traffic. These measures provide multiple layers of protection against external threats and unauthorised access attempts.
We maintain a comprehensive incident response plan that addresses various types of security incidents, including data breaches, system compromises, and service disruptions. Our incident response team includes security professionals, legal counsel, and communications specialists who can rapidly respond to and contain security incidents.
Our business continuity planning includes regular data backups, disaster recovery procedures, and system redundancy that ensures service availability even in the event of major system failures or security incidents. We conduct regular testing of our incident response and business continuity procedures to ensure their effectiveness.
In the event of a security incident that may affect personal data, we are committed to providing timely notification to affected users and regulatory authorities as required by applicable laws. Our incident response procedures prioritise the protection of personal data and the restoration of normal operations while maintaining transparency with affected parties.
All Bridgenix’s employees undergo comprehensive security training that covers data protection requirements, security best practices, and incident reporting procedures. This training is regularly updated to address new threats and regulatory requirements, and all employees are required to complete annual security awareness training.
Our security training programs include specific modules on handling personal data, recognising and reporting security threats, and maintaining the confidentiality of user information. Employees with access to sensitive systems receive additional specialised training appropriate to their roles and responsibilities.
We maintain a culture of security awareness throughout our organisation, encouraging employees to report potential security issues and providing clear procedures for escalating security concerns. Regular security communications and updates ensure that all employees remain informed about current threats and security requirements.
Bridgenix maintains comprehensive data retention policies that balance the need to retain personal data for legitimate business purposes with privacy principles that minimise data retention to what is necessary and proportionate. Our retention practices are designed to comply with legal requirements while providing clarity and control to our users.
As a financial services platform, we are subject to extensive regulatory requirements that mandate specific retention periods for various types of data. Financial regulations typically require retention of transactional records, identity verification documentation, and customer communications for periods ranging from five to seven years after account closure or transaction completion.
Anti-money laundering regulations require us to maintain comprehensive records of customer due diligence activities, transaction monitoring results, and suspicious activity reports for extended periods to support ongoing compliance and regulatory examinations. These retention requirements vary by jurisdiction but generally establish minimum retention periods that we must observe.
Tax reporting obligations in various jurisdictions require retention of financial records and transaction data for specific periods to support tax compliance and respond to tax authority inquiries. We maintain personal data necessary to fulfil these obligations for the required retention periods established by applicable tax laws.
Beyond regulatory requirements, we retain personal data for legitimate business purposes including contract performance, dispute resolution, and the provision of ongoing services to our users. This includes maintaining account information necessary to provide customer support, process transactions, and fulfil our ongoing contractual obligations.
We retain analytical and usage data to support business operations, product development, and service improvement initiatives. This data is typically aggregated and anonymised where possible to minimise privacy impact while providing valuable insights for business decision-making.
Historical data retention also supports our ability to detect and investigate fraudulent activities, maintain audit trails for compliance purposes, and provide continuity of service for long-term users. We balance these legitimate business needs with privacy principles to ensure that retention periods are appropriate and proportionate.
When personal data is no longer required for its original purpose and applicable retention periods have expired, we implement secure deletion procedures that ensure data is permanently and irreversibly removed from our systems. Our deletion procedures address both primary storage and backup systems to ensure complete data removal.
Where complete deletion is not feasible due to technical constraints or legal requirements, we implement anonymisation or pseudonymisation techniques that render personal data non-identifiable while preserving its utility for legitimate purposes such as analytics or compliance monitoring.
Our data lifecycle management systems automatically identify data that has reached the end of its retention period and initiate appropriate deletion or anonymisation procedures. These systems are regularly audited to ensure they operate correctly and completely remove data as intended.
We provide users with comprehensive tools and procedures for managing their personal data throughout its lifecycle. This includes the ability to request copies of their personal data, request corrections to inaccurate information, and request deletion of data where legally permissible.
Our user-initiated data management procedures include identity verification requirements to ensure that requests are legitimate and authorised. We typically respond to user requests within the timeframes established by applicable data protection laws, providing clear communication about the status and outcome of requests.
Where we cannot fulfill a user's request due to legal requirements or legitimate business needs, we provide clear explanations of the reasons for any limitations and information about alternative measures that may be available to address the user's concerns.
Bridgenix operates across multiple jurisdictions and may transfer personal data internationally as part of our normal business operations. We implement comprehensive safeguards to ensure that international transfers of personal data maintain appropriate levels of protection regardless of the destination jurisdiction.
We employ multiple legal mechanisms to ensure that international transfers of personal data are conducted in compliance with applicable data protection laws. These include reliance on adequacy decisions issued by relevant regulatory authorities, implementation of Standard Contractual Clauses (SCCs) approved by data protection authorities and obtaining explicit consent from users where appropriate.
For transfers to countries that have been deemed to provide adequate protection by relevant authorities such as the European Commission, we rely on these adequacy decisions as the legal basis for transfers. We continuously monitor the status of adequacy decisions and adjust our transfer practices as necessary to maintain compliance.
Where adequacy decisions are not available, we implement Standard Contractual Clauses or other appropriate safeguards approved by data protection authorities to ensure that transferred data receives equivalent protection to that provided in the originating jurisdiction. These contractual measures are supplemented by additional technical and organisational measures where necessary.
We conduct comprehensive Transfer Impact Assessments (TIAs) for international transfers to jurisdictions that may present additional risks to personal data protection. These assessments evaluate the legal and practical landscape of recipient countries, including local laws that may affect data protection, the availability of legal remedies, and the overall environment for data protection.
Our TIAs consider factors such as government surveillance laws, data localisation requirements, and the independence and effectiveness of data protection authorities in recipient countries. Based on these assessments, we implement supplementary safeguards such as additional encryption, data minimisation, or alternative transfer mechanisms to ensure appropriate protection.
We regularly review and update our TIAs to reflect changes in legal and practical conditions in various jurisdictions and adjust our transfer practices accordingly. This ongoing assessment ensures that our international transfer practices remain compliant and appropriate.
Where required by local laws or regulations, we implement data localisation measures that ensure personal data remains within specific jurisdictions or regions. This includes maintaining local data processing facilities, implementing geo-blocking measures for sensitive data, and ensuring that data processing activities comply with local regulatory requirements.
We work closely with local legal counsel and compliance experts in each jurisdiction where we operate to ensure that our data processing activities align with local requirements and cultural expectations. This localised approach enables us to provide our Services globally while respecting regional differences in data protection requirements.
Our regional compliance programs include regular training for local staff, implementation of jurisdiction-specific policies and procedures, and ongoing monitoring of regulatory developments that may affect our operations in each region.
Bridgenix is committed to providing users with comprehensive rights and controls over their personal data, in accordance with applicable data protection laws and our commitment to privacy and transparency. We have implemented systems and procedures that enable users to exercise their rights effectively while maintaining the security and integrity of our platform.
Users have the right to request access to the personal data we hold about them, including detailed information about how their data is processed, the purposes for processing, and the categories of third parties with whom their data may be shared. We provide comprehensive responses to access requests that include all relevant information in a clear and understandable format.
Our data portability procedures enable users to obtain their personal data in structured, commonly used, and machine-readable formats that facilitate transfer to other service providers. This includes transaction histories, account information, and other data that users may wish to port to alternative platforms or services.
We maintain user-friendly interfaces that allow users to access much of their personal data directly through their account dashboards, providing immediate access to account information, transaction histories, and privacy settings without requiring formal requests.
Users have the right to request correction of inaccurate or incomplete personal data, and we provide straightforward procedures for submitting rectification requests. Our systems are designed to facilitate prompt correction of errors while maintaining appropriate verification procedures to ensure the accuracy of corrected information.
We proactively monitor data quality and implement automated systems that detect and flag potential data accuracy issues. When we identify inaccuracies, we take steps to correct them promptly and notify affected users of the corrections where appropriate.
Our data accuracy procedures include regular validation of information against authoritative sources, implementation of data quality rules that prevent the entry of obviously incorrect information, and user notification systems that alert users to potential accuracy issues.
Users have the right to request deletion of their personal data under certain circumstances, including when the data is no longer necessary for its original purpose, when consent is withdrawn, or when the data has been unlawfully processed. We evaluate deletion requests carefully to ensure they are appropriate and legally compliant.
Our deletion procedures address both primary data storage and backup systems to ensure complete removal of personal data when deletion is appropriate. We provide clear communication about the scope and timeline of deletion activities and any limitations that may apply due to legal requirements or technical constraints.
Where immediate deletion is not possible due to regulatory requirements or legitimate business needs, we implement measures to restrict processing of the data and provide clear timelines for when deletion will be completed.
Users have the right to request restriction of processing of their personal data under certain circumstances, such as when the accuracy of the data is contested or when processing is unlawful. We implement technical and organisational measures to restrict processing while maintaining the data for legitimate purposes.
Users also have the right to object to processing of their personal data for certain purposes, particularly for direct marketing or processing based on legitimate interests. We provide clear and accessible procedures for users to exercise these rights and modify their preferences.
Our preference management systems enable users to control how their data is used for various purposes, including marketing communications, analytics, and personalisation features. These controls are designed to be user-friendly and provide granular options for managing data use.
Where we rely on consent as the legal basis for processing personal data, we provide clear and accessible mechanisms for users to withdraw their consent at any time. Consent withdrawal does not affect the lawfulness of processing conducted before withdrawal, but it prevents future processing based on that consent.
Our consent management systems provide users with detailed information about the purposes for which consent is requested, the types of data that will be processed, and the consequences of providing or withholding consent. We implement granular consent controls that allow users to consent to specific processing activities while declining others.
We regularly review and refresh consent where appropriate, particularly for marketing activities and other processing that may not be essential to our core Services. Our consent refresh procedures ensure that consent remains current and reflects users' actual preferences.
Users have the right to lodge complaints with relevant supervisory authorities if they believe their data protection rights have been violated. We provide information about relevant supervisory authorities and assist users in understanding their rights and options for seeking redress.
We maintain internal complaint handling procedures that enable users to raise concerns about our data protection practices and receive prompt responses and resolution. Our complaint procedures are designed to address concerns efficiently while ensuring appropriate investigation and corrective action.
We also participate in alternative dispute resolution mechanisms where available and appropriate, providing users with additional options for resolving data protection concerns outside of formal regulatory processes.
Bridgenix recognises that certain populations may require special protection and consideration in our data processing activities. We have implemented specific policies and procedures to address the needs of vulnerable populations while maintaining compliance with applicable laws and regulations.
Our Services are not intended for use by individuals under the age of 18, or such other age as may be considered the age of majority in their jurisdiction. We do not knowingly collect personal data from children, and we implement age verification procedures to prevent minors from creating accounts or using our Services.
In the event that we discover we have inadvertently collected personal data from a minor, we take immediate steps to delete such information from our systems and notify the relevant authorities as required by applicable laws. We also implement additional safeguards to prevent future collection of data from minors.
Our age verification procedures include document verification, behavioural analysis, and other techniques designed to identify potential underage users. We regularly review and update these procedures to ensure their effectiveness in protecting minors.
We implement enhanced due diligence procedures for Politically Exposed Persons (PEPs), their family members, and close associates, as required by anti-money laundering regulations. These procedures involve additional data collection and verification requirements designed to assess and manage the elevated risks associated with these individuals.
Our enhanced due diligence procedures include source of wealth verification, ongoing monitoring of account activities, and regular review of PEP status. We maintain specialised systems and procedures for identifying and managing PEPs throughout their relationship with our platform.
We also implement enhanced monitoring and reporting procedures for other high-risk individuals, including those from high-risk jurisdictions or those engaged in high-risk activities. These procedures are designed to prevent money laundering and other financial crimes while providing appropriate service to legitimate users.
Bridgenix, its subsidiaries, affiliates, third-party partners, and service providers may transfer, store, and process your personal information across multiple jurisdictions worldwide, including but not limited to the United States, United Kingdom, European Union member states, Singapore, Canada, and other countries where we maintain operational facilities or data centres.
Depending on your jurisdiction of residence, you may exercise certain privacy rights regarding your personal information. Requests relating to your privacy rights may be submitted by contacting [email protected]. If any rights listed below are not provided under the applicable law in your jurisdiction, Bridgenix reserves discretion in providing such rights voluntarily.
You may request that we provide you with a copy of your personal information held by us. This includes the right to obtain your personal data in a structured, commonly used, and machine-readable format and, where technically feasible, to have such data transmitted directly to another service provider.
You may request correction or updating of any personal information held by Bridgenix that is incomplete, inaccurate, or outdated. You may update certain information directly through your account profile settings.
You may request deletion of your personal information, subject to applicable legal requirements and our legitimate business interests. Upon account closure, we will retain or delete information associated with your account as described in our data retention policy.
Where processing of your personal information is based on your consent, you may withdraw such consent at any time. Withdrawal of consent will not affect the lawfulness of processing conducted prior to such withdrawal.
You may have the right to object to or restrict our processing of your personal information based on our legitimate interests, public interest, or for direct marketing purposes. We may continue processing where permitted or required by applicable law. You may opt out of marketing communications through your account settings or by contacting our support team.
We will not discriminate against you for exercising any privacy rights provided to you under applicable law, including by denying services, charging different prices, or providing different levels of service quality.
To protect your privacy and security, we may take reasonable steps to verify your identity before complying with your request. Under certain data privacy laws, you may designate an authorized agent to make requests on your behalf, subject to proper authorization and verification procedures.
These rights are not absolute and may be limited or denied where: (a) granting access or portability would adversely affect the rights and freedoms of others; (b) necessary to protect our rights and properties; (c) as otherwise permitted by applicable law.
If you are a United States resident, additional information about how we use your information and your privacy rights is available in our United States Privacy Notice, which supplements this Privacy Policy. Terms defined in applicable U.S. state privacy laws, including the California Consumer Privacy Act (as amended), have the same meaning when used in our supplemental U.S. Privacy Notice.
If you have questions, concerns, or complaints regarding this Privacy Policy or our privacy practices, please contact us through:
Email: [email protected]
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons. We will post any changes to this Privacy Policy on this page and, where appropriate, provide reasonable notice of material changes before they take effect or as otherwise required by applicable law. The date of the last update is identified at the top of this Privacy Policy.
We may provide additional "just-in-time" disclosures or information about our data collection or use practices in the context of specific services. These contextual notices may supplement or clarify our privacy practices or provide additional choices regarding how we use your information.
This Privacy Policy is effective as of 10th July 2025. For questions about this Privacy Policy or our privacy practices, please contact our Data Protection Officer at [email protected].
Company Name: Bridgenix Limited
Company Address: Unit A7, 12/F Astoria Bldg 34, Ashley Rd, Tsim Sha Tsui, Hong Kong
Company Registration Number: 78304583
Bridgenix Privacy Policy - Last Updated: 15th July 2025
This Privacy Policy governs your use of Bridgenix's payment processing services. By using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.