Privacy Policy
2771493 Alberta Ltd.
- Business name
- 2771493 Alberta Ltd.
- Registered office
- 200-1001 1 ST SE, Calgary, Alberta, T2P 5G3, Canada
- Regulatory status
- Registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Services Business. Registered activities include dealing in virtual currency.
- Privacy contact
- [email protected]
Purpose and Scope
This Privacy Policy (the “Policy”) applies to Personal Information handled by 2771493 Alberta Ltd. (the “Company”, “we”, “us” or “our”) in connection with the Company’s website, customer account interface and related online services (the “Platform”), and the fiat-to-Virtual-Currency and Virtual-Currency-to-fiat exchange services described in the Terms and Conditions (the “Services”).
For the purposes of this Policy, “Personal Information” means information about an identifiable individual, including information that can reasonably be linked to an identifiable individual. Capitalized terms not defined in this Policy have the meaning given to them in the Terms and Conditions.
This Policy covers Personal Information collected during registration and onboarding, identity and account verification, use of the Platform, exchange transactions, customer support, compliance reviews and the ongoing administration of the customer relationship.
Privacy Laws and Accountability
The Company handles Personal Information in accordance with applicable Canadian privacy requirements, including Alberta’s Personal Information Protection Act (PIPA) and, where applicable, the Personal Information Protection and Electronic Documents Act (PIPEDA), together with other privacy requirements that may apply to a particular processing activity.
The Company is responsible for Personal Information under its control and maintains appropriate policies and practices to comply with applicable privacy laws. Questions, requests and complaints relating to privacy may be submitted using the contact details set out in Section 20.
The Company also has legal record-keeping, anti-money laundering, anti-terrorist financing, sanctions, fraud-prevention and regulatory reporting obligations. Those obligations may require the Company to collect, use, retain or disclose certain Personal Information even where consent would not otherwise be required or where an Account has been closed.
Categories of Personal Information
Depending on how you use the Services and the requirements applicable to your Account or transaction, the Company may collect the following categories of Personal Information:
3.1 Identity and profile information, such as your full legal name, date of birth, residential address, country of residence, citizenship or other relevant geographic information, occupation or principal business, contact information and tax residence or tax information where required.
3.2 Identity-verification information, including identification-document details and images, proof of address, verification method and result, and selfie, liveness or facial-comparison information used to verify that the person presenting an identity document is its legitimate holder. Depending on the verification method, this may include biometric information.
3.3 Financial and banking information, such as bank-account details, account-ownership evidence, payment references, financial circumstances, and Source of Funds, Source of Virtual Currency or Source of Wealth information where required for compliance purposes.
3.4 Wallet and blockchain information, including Wallet addresses, evidence of Wallet ownership or control, transaction hashes, blockchain network information, relevant Wallet and transaction history, blockchain-risk or attribution information and related counterparties where relevant.
3.5 Transaction and Order information, including exchange direction, fiat and Virtual Currency amounts, currencies or assets, exchange rates, timestamps, settlement information, payment-provider or banking references, source and destination information and transaction status.
3.6 Compliance and risk information, including sanctions and financial-crime screening results, customer risk information, enhanced due diligence information, transaction-monitoring information, fraud or security review information and records of compliance decisions.
3.7 Travel Rule and counterparty information, where applicable, including required information concerning an originator, beneficiary, relevant account or reference number, counterparty Virtual Currency service provider and transfer.
3.8 Technical and security information, including IP address, derived geolocation where available, device and session information, authentication and access records, timestamps and other technical indicators used to operate and protect the Platform and detect unauthorized or suspicious activity.
3.9 Communications and support information, including emails, customer enquiries, complaints, information provided during a compliance review and records of communications relating to your Account or transactions.
The Company does not require your private keys, seed phrase or Wallet recovery phrase and will not ask you to provide them.
How We Collect Personal Information
The Company may collect Personal Information:
- directly from you when you create or maintain an Account, submit information or documents, communicate with us, or request or complete an Order;
- through electronic identity-verification, screening, Wallet-verification and other compliance processes used in connection with the Services;
- from banks, payment providers, liquidity providers, Wallet providers, Virtual Currency service providers and other counterparties involved in an Order or transfer;
- from public blockchain networks and blockchain-analysis sources in connection with Wallet and transaction screening;
- from public, regulatory, sanctions, fraud-prevention or other lawful sources used to verify information or assess legal and financial-crime risk; and
- automatically through Platform, authentication, session and security logs when you access or use the Platform.
The Company seeks to limit the collection, use and disclosure of Personal Information to information that is reasonably necessary for the identified purposes and does not collect Personal Information indiscriminately.
Where Personal Information is collected from a third party rather than directly from you, the Company will do so only where permitted or authorized by Applicable Law and for purposes described in this Policy or otherwise permitted by law.
Cookies and Similar Technologies
The Platform may use cookies, local storage, pixels and similar technologies to operate and secure the Platform, maintain sessions, remember preferences, improve functionality, understand how the Platform is used, and detect and prevent fraud or security incidents.
Some cookies and similar technologies are necessary for the operation and security of the Platform. Where the Company uses non-essential cookies or similar technologies for purposes requiring consent under Applicable Law, the Company will provide an appropriate mechanism for obtaining and managing consent.
You may also be able to manage certain cookie preferences through your browser or other controls made available by the Platform. Disabling certain cookies or similar technologies may affect the functionality or availability of some features of the Platform.
Public Blockchain Information
Virtual Currency transactions may be recorded on public or otherwise independently operated blockchain networks. Wallet addresses, transaction hashes, amounts and related blockchain information may therefore be publicly visible and may be associated with you when linked to your Account or transaction.
The Company does not control public blockchain networks and generally cannot erase, reverse or alter information recorded on a blockchain. A privacy request concerning information held by the Company does not require the Company to remove information from a blockchain that the Company does not control.
Purposes for Collection and Use
The Company collects and uses Personal Information only for reasonable and lawful purposes connected with the Services and its legal obligations, including to:
- create, administer and secure your Account and provide the Platform and Services;
- verify your identity, age, residential and geographic information, bank account and Wallet ownership or control;
- process, reconcile, execute and settle Orders and related fiat and Virtual Currency transfers;
- perform customer due diligence, risk assessment, sanctions and financial-crime screening, enhanced due diligence and ongoing monitoring;
- perform Wallet and blockchain screening, investigate transaction or fraud indicators, and assess the Source of Funds, Source of Virtual Currency or Source of Wealth where required;
- collect, exchange and retain Travel Rule information where applicable;
- prevent, detect and investigate fraud, account takeover, unauthorized access, money laundering, terrorist financing, sanctions evasion and other unlawful or prohibited use;
- maintain records, audit trails and evidence required for legal, regulatory, compliance, security, accounting and dispute-resolution purposes;
- make reports and disclosures required or permitted by Applicable Law and respond to lawful requests from competent authorities;
- communicate with you about your Account, Orders, verification, security, complaints and other operational or legally required matters; and
- protect the Company, customers, service providers and the integrity, availability and security of the Platform.
Electronic Verification and Screening
The Company may use electronic and automated tools to support identity-document authentication, liveness and facial comparison, sanctions and financial-crime screening, Wallet verification or attribution, blockchain analytics, fraud detection and transaction monitoring.
These tools may generate verification results, risk indicators, alerts or recommendations. Such information may be considered together with information provided by you and other relevant information when the Company assesses an Account, transaction or compliance matter.
Automated or technology-assisted tools may support the Company’s assessment and decision-making processes. Where necessary, relevant results may be subject to human review before a final decision is made.
The use of a technology provider does not transfer the Company’s responsibility for the handling of Personal Information or for decisions made in connection with the Services.
Consent and Processing Required by Law
Where consent is required by Applicable Law, the Company will obtain consent in a manner appropriate to the nature and sensitivity of the Personal Information and the purpose of the collection, use or disclosure.
The Company will not rely on this Privacy Policy alone as consent where Applicable Law requires separate, express or otherwise specific consent.
Certain Personal Information may be collected, used or disclosed without consent where permitted or required by Applicable Law. This may include processing necessary to comply with AML/ATF, sanctions, fraud-prevention, regulatory reporting, court-order, law-enforcement, legal, security or other legally authorized requirements.
Where consent is required and you provide it, you may withdraw your consent subject to Applicable Law, contractual restrictions, reasonable notice and the Company’s legal or regulatory obligations. Withdrawal of consent may affect the Company’s ability to provide some or all of the Services.
Service Providers and Other Recipients
The Company may disclose Personal Information to service providers and counterparties where reasonably necessary to provide the Services, operate the Platform or meet legal and compliance obligations. These may include:
- identity-verification, screening and compliance technology providers;
- blockchain analytics and Travel Rule technology providers;
- banks, payment providers, liquidity providers and other financial or settlement counterparties;
- hosting, cybersecurity, authentication and other technology providers;
- professional advisers, auditors, consultants, insurers and other persons supporting the Company’s legal, regulatory or operational functions; and
- FINTRAC, courts, law-enforcement agencies, sanctions authorities, tax authorities and other competent governmental or regulatory authorities where disclosure is required or permitted by law.
Service providers are given access to Personal Information only to the extent reasonably necessary for the function they perform, subject to contractual, confidentiality, security and oversight arrangements appropriate to their role.
Processing Outside Canada
Some Personal Information may be processed or stored outside Canada in connection with the Company’s use of specialized service providers. Under current core compliance arrangements, certain identity-verification and screening information may be processed or stored in Belgium, and certain blockchain-analytics information may be processed in the United States.
Personal Information processed outside Canada may be subject to the laws of the jurisdiction in which it is processed and may be accessible to courts, law-enforcement or governmental authorities in accordance with those laws. Other approved financial or technology providers may process Personal Information in the jurisdiction in which the relevant service is provided; where Applicable Law requires additional country-specific notice, the Company will provide that notice.
The Company remains responsible for Personal Information under its custody or control when it is processed outside Canada and takes reasonable contractual, organizational and technical measures to protect such information.
Information about the Company’s use of service providers located outside Canada, including the purposes for which Personal Information is processed and the jurisdictions in which it may be processed or stored, may be obtained by contacting the Company in writing to [email protected].
Legal, Regulatory and Compliance Disclosures
The Company may disclose Personal Information where required or permitted by Applicable Law, including for FINTRAC reporting, sanctions or terrorist-property requirements, court or regulatory orders, law-enforcement requests, tax requirements, investigations, legal proceedings, fraud prevention or the establishment, exercise or defence of legal rights.
Certain financial-crime reports, investigations, screening information and related compliance records are confidential. The Company may be prohibited from informing you that a report or disclosure has been made or from providing information that would reveal confidential monitoring, investigative or regulatory-reporting information.
Retention of Personal Information
The Company retains Personal Information only for as long as reasonably necessary for the purposes for which it was collected, for a related legitimate business or security purpose, or to satisfy legal, regulatory, compliance, accounting, fraud-prevention and dispute-resolution requirements.
Certain customer identification, transaction, Virtual Currency transaction, Travel Rule, compliance and regulatory records are subject to mandatory retention periods under applicable AML/ATF and other laws. The applicable retention period may vary depending on the type of record and the legal requirement. Where a five-year statutory retention period applies, the Company will retain the relevant records for at least the applicable statutory period, subject to the applicable statutory commencement date and any longer period required or permitted by law, including where necessary for an investigation, audit, legal proceeding or preservation requirement.
Safeguards and Security
The Company uses reasonable administrative, technical and organizational safeguards appropriate to the sensitivity of the Personal Information and the nature of the Services. These safeguards are intended to protect Personal Information against unauthorized access, collection, use, disclosure, alteration, loss or destruction.
Where the Company collects or uses biometric information or other highly sensitive Personal Information, the Company will obtain express consent where required by Applicable Law and will apply safeguards appropriate to the sensitivity of the information.
Access to customer and compliance information is restricted according to role and need. The Company also maintains oversight of material service providers, record-access controls, transaction and security logging, and procedures for responding to suspected security or privacy incidents.
No internet-based service, information system or blockchain network can be guaranteed to be completely secure. You are responsible for protecting your Account credentials, email account, devices and external Wallets in accordance with the Terms and Conditions.
Depending on the nature and sensitivity of the Personal Information, safeguards may include access controls, role-based permissions, authentication controls, encryption or equivalent protections, security logging and monitoring, confidentiality obligations, secure transmission mechanisms, service-provider controls, backup and recovery measures and secure disposal procedures.
Accuracy and Updating Your Information
The Company takes reasonable steps to keep Personal Information as accurate, complete and up to date as is necessary for the purposes for which it is used. You are responsible for providing accurate information and for notifying the Company when material information changes.
The Company may request updated information or renewed verification where information has changed, appears incomplete or inconsistent, or must be updated for legal, compliance, fraud-prevention or security purposes.
Access to and Correction of Personal Information
Subject to Applicable Law, you may request access to Personal Information about you that is in the Company’s custody or control and may request correction of information that is inaccurate or incomplete. You may also request information about the existence, use and disclosure of your Personal Information, including information about the purposes for which it has been used or disclosed and, where required by Applicable Law, the organizations or categories of organizations to which it has been disclosed. Requests should be submitted in writing to [email protected].
The Company may ask for information necessary to verify your identity and locate the relevant records before responding. The Company will respond within the period required by Applicable Law and may charge a reasonable fee only where permitted by law and after giving any notice required by law.
Access may be limited or refused where Applicable Law requires or permits this, including where disclosure would reveal Personal Information about another person, legally privileged or confidential information, confidential commercial information, or information that cannot lawfully be disclosed because of a financial-crime report, investigation or other legal restriction. Where required, the Company will explain the basis for a refusal.
Account Closure, Deletion Requests and Withdrawal of Consent
You may request closure of your Account in accordance with the Terms and Conditions. Account closure does not automatically result in deletion of Personal Information. The Company may continue to retain and use records where required or permitted for legal, regulatory, AML/ATF, sanctions, fraud-prevention, security, accounting, dispute-resolution or legal-claim purposes.
Where you request deletion or withdrawal of consent, the Company will assess the request in accordance with Applicable Law. Canadian privacy laws may permit or require the Company to retain certain Personal Information, including where necessary for AML/ATF, regulatory, fraud-prevention, security, accounting, dispute-resolution, legal or other lawful purposes. Where the Company is required or permitted to retain information, the request will not override the applicable retention or preservation requirement.
Privacy and Security Incidents
The Company maintains procedures to identify, assess, document and respond to suspected privacy and security incidents involving the loss of, unauthorized access to, use or disclosure of Personal Information. Where required by Applicable Law, the Company will notify the applicable privacy regulator and, where required, affected individuals within the timeframes required by law.
The Company will assess incidents in accordance with the applicable legal threshold, including whether there is a real risk of significant harm to affected individuals. The Company will maintain records of privacy breaches and security incidents as required by Applicable Law.
Changes to this Privacy Policy
The Company may amend this Privacy Policy from time to time to reflect changes in Applicable Law, the Services, technology, security requirements, service-provider arrangements or the Company’s Personal Information handling practices. The most current version of this Privacy Policy will be published on this page.
Where a change is material and Applicable Law requires additional notice or consent, the Company will provide the required notice or obtain the required consent before the change is applied in the manner required by law.
Questions, Requests and Complaints
Questions about this Privacy Policy, the Company’s handling of Personal Information, requests for access or correction, and privacy complaints may be submitted using the contact details below:
- Company
- 2771493 Alberta Ltd.
- [email protected]
- Registered office
- 200-1001 1 ST SE, Calgary, Alberta, T2P 5G3, Canada
If you are not satisfied with the Company’s response, you may have the right to make a complaint to the Office of the Information and Privacy Commissioner of Alberta or, where PIPEDA applies, the Office of the Privacy Commissioner of Canada.