1. INTRODUCTION
- We respect your privacy and are committed to protecting your personal data. This privacy policy (“Privacy Policy”) explains how we collect, use, and process your personal data and sets out your rights as a data subject.
- This Privacy Policy applies when you use our services accessible via website https://www.teroxx.com/ (“Website”) or mobile application (“App”), interact with us on our social media accounts, including Facebook, Instagram, LinkedIn, YouTube, X, and Tik Tok (“Social Accounts”) or contact us by other means, including by email or phone.
- In this Privacy Policy “personal data” (“Personal Data”) refers to any information or set of information that can directly or indirectly identify you, such as your name, surname, email address and other similar details.
- When processing Personal Data, we adhere to the requirements of the General Data Protection Regulation 2016/679 (EU) (“GDPR”), other applicable laws, as well as the guidelines set by relevant supervisory authorities.
- If you use our services or interact with us in any other way, we assume you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, we kindly ask you to stop engaging with us in any form.
- The Website, App, Social Accounts may link to external sites, such as partner websites or other projects. This Privacy Policy does not apply to them. Please review the privacy policies of third-party sites before sharing personal information herein.
- Security is highly important to us. We take all reasonable measures to protect Personal Data from loss, theft, misuse and unauthorized access, disclosure, alteration and destruction, including industry standard security and encryption features.
- We may update the Privacy Policy from time to time, so we recommend reviewing the Website regularly to stay informed about any changes.
2. ABOUT US
- The data controller of your Personal Data is UAB “Teroxx Worldwide” (“Teroxx” or “we”), company code 305956215, address Vilniaus str. 31, Vilnius, Lithuania. We have appointed a data protection officer (“DPO”) and you can contact our DPO via email: dpo@teroxx.eu.
3. COLLECTION OF DATA
- We may collect your Personal Data in the following ways:
- directly from you when you use our services via Website or App;
- directly from you when you subscribe to our newsletter, contact us via email, phone, Social Accounts or communicate with us in other ways;
- we may collect information from other available sources, such as third-party platforms for enhanced due diligence checks, security searches, and as part of our Know-Your-Customer (“KYC”) and Know-Your-Transaction (“KYT”) checks.
- If you provide Personal Data about yourself or others, it is your responsibility to ensure it is accurate, complete, and up to date, and to obtain any necessary consents from others or inform them that you shall share their Personal Data with We may ask you to confirm that you have the right to share such data with us.
4. CATEGORIES OF PERSONAL DATA AND THEIR SOURCES
- We may collect the following Personal Data:
Sources of Personal Data |
Categories and Types of Personal Data |
Information we receive from you |
|
Information collected from your use of our services |
|
Information from others |
We obtain and analyse information about you from our third-party sources such as KYC, KYT vendors, for example, public blockchain data, such as transaction ID’s, transaction amounts, wallet address, timestamps or transactions or events, listing on any sanctions lists. |
5. PURPOSES OF PROCESSING AND LEGAL BASES
- We use your Personal Data for:
Purposes |
Legal bases |
Managing our contractual relationship with you: (i) creation and maintenance of your account; (ii) delivery of our services to you, such as handling of your transactions, provision of support services. |
Processing is necessary to enter into and perform the contract with you (GDPR 6(1)(b)). Processing is necessary to comply with our legal obligations under applicable laws and regulations, when we are providing services to you (GDPR 6(1)(c)). |
Checking and verifying your identity We are generally required to collect various pieces of your Personal Data to properly identify or verify your identity and comply with other specific anti-money laundering (“AML”), Counter-Terrorism Financing (“CTF”) and sanctions laws and regulations. |
Processing is necessary to enter into and perform the contract with you (GDPR 6(1)(b)) Processing is necessary to comply with our legal obligations under applicable laws and regulations, including AML, CTF and sanctions laws and regulations (GDPR 6(1)(c)). Processing of your Biometric data is necessary for reasons of substantial public interest based on EU or EU Member State law (GDPR 9 2(g)). |
Protecting against fraud, ensuring safety, security, and integrity of Teroxx services We use your Personal Data to check your identity and address, protect against fraud, comply with financial crime laws and to confirm that you are eligible to use our services. We also use this data to help us better understand your financial circumstances and manage fraud risks related to your Teroxx account. |
Processing is necessary to enter into and perform the contract with you (GDPR 6(1)(b)) Processing is necessary to comply with our legal obligations under applicable laws and regulations, including AML, CTF and sanctions laws and regulations (GDPR 6(1)(c)). Processing is necessary for legitimate interests of ours and other customers to ensure safety of our services (GDPR 6(1)(f)). |
Marketing If you agree, we shall send you newsletters and ask your opinion about our services. Your Personal Data may be shared with our service providers who help us deliver news and assess service quality. After sending news, we may collect information on how you interact with it, like whether you opened the message or clicked on links. This helps us send you more relevant and personalized updates. You can withdraw your consent at any time via an unsubscribe link in newsletters and/or settings in the App.
|
Your consent (GDPR 6(1)(a)). Processing is necessary for legitimate interests of ours to help us send you more relevant and personalized updates (GDPR 6(1)(f)). |
Improving our products and services We may process your Personal Data to improve our services and for you to have a better user experience.
|
Processing is necessary for the purpose of the legitimate interest pursued by us to improve our services and enhance our user experience (GDPR 6(1)(f)). |
Administration of inquiries about our activities and services In case you contact us asking about our services or activities, we shall process your Personal Data to provide you with our reply.
|
Your consent (GDPR 6(1)(a)). Processing is necessary for the purpose of the legitimate interest pursued by us to administer your inquiry (GDPR 6(1)(f)). |
Protecting our business, enforcing our rights We may use your Personal Data to recover debts from you, if any, to share it with government authorities, law enforcement authorities, etc., if required, to defend ourselves and our staff, to protect our property, etc.
|
Processing is necessary to comply with our legal obligations under applicable laws and regulations (GDPR 6(1)(c)). Processing is necessary for the purpose of the legitimate interest pursued by us to defend ourselves, our business and staff (GDPR 6(1)(f)).
|
Management of our Social Accounts Personal Data or any other information that you choose to post on the wall of our social media accounts is visible to other visitors, therefore, before posting any comment, please make sure that it does not contain sensitive personal data of yours or anybody else, the message that you want to post is not offensive, discriminatory or in any other way violates the law or the rights of other people. We reserve the right to delete any information that you post on our wall, if it violates the law or the rights of other people. |
Your consent (GDPR 6(1)(a)). Processing is necessary for the purpose of the legitimate interest pursued by us to effectively manage Social Accounts (GDPR 6(1)(f)). |
- For customer onboarding , we may make automated decisions regarding you. Additionally, we may use technology to assess your personal situation and various factors to anticipate risks or potential outcomes, also known as profiling. This helps us operate our services efficiently while ensuring that decisions are fair, consistent, and based on accurate information. If an automated decision or profiling significantly impacts you, you have the right to request a human review of the decision. You may also provide your input and challenge the outcome.
6. PRINCIPLES WE RELY ON WHEN PROCESSING YOUR PERSONAL DATA
- We collect and process only the Personal Data, which is necessary to achieve the purposes of Personal Data processing specified by us.
- When processing your Personal Data, we shall:
- comply with the applicable laws, including the GDPR;
- process your Personal Data lawfully, fairly and transparently;
- collect your Personal Data for clearly defined and legitimate purposes and we shall not use it beyond those, unless allowed by law;
- correct or delete inaccurate Personal Data promptly;
- retain Personal Data only as long as needed for its purpose;
- secure your Personal Data through appropriate technical and organizational security measures and limiting access to your Personal Data to only necessary staff.
7. SHARING OF YOUR PERSONAL DATA
- We may share your Personal Data with:
- We may share information about you with other members of the Teroxx group of companies so we can provide the best service across our group. They are bound to keep your information in accordance with this Privacy Policy and following the requirements stipulated in our internal agreements.
- We may also share your information with certain service providers, which are processing Personal Data on our behalf. For example, IT service providers (maintenance/support, development, etc.), hosting and cloud service providers, database providers, email providers, SaaS/software providers, statistics, market research or business analytics service providers, debt collection agencies, identity verification and KYC service providers, KYT service providers, other service providers. Our service providers will be required to meet our standards on processing information and security and enter into agreements with us. The information we provide them, including your Personal Data, will only be provided to the extent necessary for the provision of services to us.
- We may share your Personal Data with our partners, such as banking and financial services partners, payments networks, etc.
- We shall share certain Personal Data of yours with recipients and their financial institutions to whom you transfer money.
- We may share your Personal Data with law enforcement and pre-trial investigation authorities, courts and other dispute resolution authorities, as well as other individuals or entities performing functions mandated by law, in accordance with the procedure stipulated by the legislation of the Republic of Lithuania. We provide these entities with information that is required by law or as specified by the entities themselves.
- We may also transfer data, if necessary, to companies that would buy or acquire our business or engage in joint activities or other forms of cooperation with us, as well as to companies established by us.
- We may disclose Personal Data to other third parties, such as legal service providers, financial institutions, credit and payment institutions, auditors, etc.
- We generally process Personal Data within the EU/EEA, but in some cases your Personal Data may be transferred outside the EU/EEA. The transfer of your Personal Data outside the EU/EEA is based on:
- an adequacy decision adopted by the European Commission, which means that the European Commission has recognized the country in which the third party is established and/or carries on business as providing an adequate level of protection of personal data; or
- a data processing or sharing agreement that describes such transfer and includes Standard Contractual Clauses for international transfers; or
- your consent to the transfer of your Personal Data outside the EU/EEA, when you initiate such transfer; or
- other legal grounds.
8. RETENTION OF YOUR PERSONAL DATA
- We will keep your Personal Data:
- for as long as necessary to achieve the original purpose we collected it for;
- in line with laws applicable to our business.
- Depending on the purpose of Personal Data processing we may retain your Personal Date:
Purposes for processing Personal Data |
Personal Data retention periods |
Managing our contractual relationship with you |
We shall keep your Personal Data for no longer than 10 years after our business relationship ends. |
Identity verification |
We shall keep your Personal Data for no longer than 10 years after our business relationship ends. |
Protecting against fraud, ensuring safety, security, and integrity of Teroxx services |
We shall keep your Personal Data for no longer than 10 years after our business relationship ends. |
Marketing |
For 3 years from the consent provision or until it is withdrawn. The consent (prove that the consent has been provided) shall be stored for 2 years counting from the date indicated above. Survey data: during the survey and 1 year after the survey ends. Promotional games and campaigns: during the promotional game or campaign and for 1 year after it ends. |
Improving our products and services |
For as long as it is necessary to pursue our purpose. |
Administration of inquiries about our activities and services |
During the communication period and for 1 year after it ends. |
Protecting our business, enforcing our rights |
During the legal dispute and for 5 years after a non-judicial dispute ends, or for 10 years after a judicial dispute ends. |
Management of social accounts |
According to the settings of the platform or user. |
- The retention of Personal Data for periods longer than specified above may only be carried out when:
- It is necessary for us to defend ourselves against claims, demands, or lawsuits and to exercise our rights.
- There are reasonable suspicions of illegal activity under investigation.
- Personal data is required for the proper resolution of a dispute or complaint.
- There are other grounds provided for by legal acts.
9. YOUR RIGHTS
- As a data subject, you have the following rights in relation to your Personal Data:
- the right to be informed: you have the right to be provided with clear, transparent and easily understandable information about how we use your Personal Data and your rights. This is why we are providing you with the information in this Privacy Policy;
- the right to access: you have the right to access the Personal Data we hold about you;
- the right to rectification: you have the right to ask us to rectify your Personal Data if it becomes inaccurate;
- the right to erasure: you have the right to ask us to erase your Personal Data. If Personal Data is erased under your request, we will only retain such copies of the information which are necessary for us to protect our or third parties’ legitimate interests, comply with governmental orders, resolve disputes, troubleshoot problems, or enforce any agreement you have entered with us;
- the right to restrict processing: you have the right to restrict our processing of your Personal Data in certain circumstances, including if we no longer need your Personal Data but you would like us to retain it to ensure its continued availability to you in connection with any legal claims;
- the right to data portability: you have rights to obtain and reuse your Personal Data for your own purposes across different services in certain circumstances;
- the right to object: you have the right to object at any time to processing of Personal Data concerning you which is based on legitimate interests of ours or third parties. If we can show compelling legitimate grounds for processing your Personal Data which override your interests, or we need your Personal Data to establish, exercise or defend legal claims, we can continue to process it. Otherwise, we must stop using the relevant Personal Data;
- the right to withdraw consent: where you may have provided your consent to the collection, processing and transfer of your Personal Data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time;
- the right to ask us to carry out a human review of an automated decision if we make such: if we make an automated decision about you that significantly affects you, you can ask us to carry out a manual review of this decision;
- the right to lodge a complaint: you have the right to lodge a complaint with the relevant data protection supervisory authority.
- We may refuse to fulfil your rights, except for the right to withdraw consent, where we are not permitted to comply with your request under the GDPR. You can find more information on the exercise of your rights in our Rules on the Implementation of Data Subjects’ Rights.
- You can withdraw your consent or exercise any of your rights set out above by contacting us via email: dpo@teroxx.eu.
- In principle, we cannot accept verbal requests (telephone or face-to-face) as we may not be able to deal with your request immediately without first analyzing it and reliably identifying you. Your request should contain a detailed, accurate description of the Personal Data you want access to or against which you want to exercise your rights. When there are reasonable doubts regarding your identity, you might be asked by us to provide a copy of a document, which helps us to verify your identity. It can be any document such as your ID card or passport. Our use of the information on your identification document is strictly limited: the data will only be used to verify your identity and will not be stored for longer than needed for this purpose.
- Upon receipt of your request or instruction regarding the processing of your Personal Data, we will respond within 1 month from the date of the request and will either carry out the actions specified or inform you why we are unable to do so. If necessary, the time limit may be extended by additional 2 months due to the complexity and number of requests. In this case, we will notify you of the extension within 1 month of receiving your request.
10. PROTECTION OF YOUR PERSONAL DATA
- We take the security of your Personal Data seriously, ensuring it is handled responsibly and safely, protecting it from loss, unauthorized access, or changes. We have implemented both physical and technical measures to protect your information from accidental or unlawful destruction, damage, alteration, disclosure or any other unauthorized processing. The level of security we apply depends on the risks involved in processing your Personal Data.
- Our employees are under a written obligation not to disclose or distribute your Personal Data to any unauthorized third party.
11. CONTACT US
- If you have any questions, feedback, or concerns about how we handle your Personal Data, or if you would like to exercise rights as a data subject, feel free to reach out to us: dpo@teroxx.eu.
- You have the right to make a complaint regarding the privacy or data processing issues at any time. You can complain in the EU member state where you live or work, or in the place where the alleged breach of data protection law has taken place. In Lithuania, the State Data Protection Inspectorate, address L. Sapiegos g. 17, Vilnius, Lithuania, e-mail: ada@ada.lt, is the competent authority for data protection issues. We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance.
12. FINAL PROVISIONS
- We may update this Privacy Policy at any time. Such updated Privacy Policy will take effect from the date of publishing on our Website.
- If we amend this Privacy Policy, we will notify you by posting the updated Privacy Policy on the Website, via App, or your email if you have provided one, or through other means of communication.
Version 1.0