1. EXBI Cash UAB (“Company,” “we”) respects your privacy and complies with the General Data Protection Regulation (Regulation (EU) 2016/679). This Privacy Policy (“Policy”) explains the types of personal data we may collect on you, how we store and handle that data, and your rights in that regard. This Policy regulates privacy practices (collection, use, and disclosure) as to your personal information during your use of the Company services.
    2. The Company undertakes to make maximum efforts in order to protect your privacy. The Company uses the collected information about you to fulfill its contractual obligations and improve customer service.
    3. Please read this document carefully in order to understand our approach and policy regarding your personal data and how we will use your personal data.
    4. This Privacy Policy should be read in conjunction with our Terms of Use and Cookies Policy.
    1. The Company may collect and process Client data received directly from the Client, as well as automatically when the Client uses Company services.
    2. Client data received directly from the Client: 
      1. Last name and first name; 
      2. Photos and videos that you may send to us for AML/CTF Policy for verification purposes;
      3. Residential address and citizenship;
      4. Gender;
      5. Passport, ID, driver’s licence, or any identity document collected for verification purposes;
      6. Phone number and email address;
      7. Login information;
      8. Date and place of birth;
      9. PEP (politically exposed person) status;
      10. Sources of funds;
      11. Inquiries with the support team;
      12. Account balances and activity;
      13. Location and log data information that is generated by your use of the Company Website;
      14. Financial and transaction data, such as credit or debit card number, and bank account information; the name of the recipient and provider (where applicable);
      15. Other personal information that may be required by our AML/CTF Policy.
    3. The Company does not collect or process sensitive personal Client data, such as race or ethnic origin, political opinions, religious or philosophical beliefs, genetic or biometric data, health, sex life, or sexual orientation information.
    4. The Client may provide us with personal information by filling in the relevant forms on the Website or by providing us with such information by email or any other manner. This information includes Personal Data which was specified when registering on the Website, when subscribing to Company service, opening an Account, and verifying the identity of the Account holder or persons authorized to use it.
    5. Client data received automatically when the Client uses Company services:
      1. Technical information, including the IP address used to connect your computer to the internet, your Account login information, time zone setting, etc.
      2. Information about your visit, including date and time, products and services you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information, etc.
      3. Information about geo-location.
      4. Financial data and information on the use of services provided by our Website, including information on implemented transactions, including on transactions, information on the status of Accounts and cash flow on them, accrued fees, transactional account history, including account balance, payment records, and credit card usage.
      5. Other data the use of which is necessary for the operation of Company services and its improvement.
    1. The purpose of the collected data/information use and processing is to:
      1. Provide Company services;
      2. Verify an identity for compliance purposes (AML/CTF procedures, checks, etc.);
      3. Monitor, detect, and prevent fraud and other harmful activity (if any);
      4. Process the payments, as well as communication regarding the payments;
      5. Promote, analyze and improve Company services;
      6. Personalise your access to our website and Company services;
      7. Provide customer support;
      8. Notify you of the usage of our Website and Company services;
      9. Analyse errors to improve the operation of the Website;
      10. Comply with statutory obligations;
      11. Send marketing communications, etc.
    1. Clients have the following data protection rights:
      1. The right to delete Personal Data;
      2. The right to change or correct Personal Data, in particular when it is incorrectly stated;
      3. The right to object to or restrict the processing of Personal Data;
      4. The right to access Personal Data and/or copy of Personal Data, which the Client has provided to the Company, in a readable format.
      5. The right to lodge a complaint – the Client can contact the Company for a complain if the Client is not satisfied with our handling of Personal Data.
      6. The right to prohibit the use of your Data for marketing purposes. Before requesting Personal Data, the Company usually requests consent to disclose it to third parties for marketing purposes. The Client can use the right to prohibit the processing of Personal Data for marketing purposes.
    2. Implementation of some of the Clients rights may be limited, complicated, or completely exclude the possibility of further cooperation with us, depending on the situation.
    1. The Company will not disclose any of your personally identifiable information except when we have your permission or under special circumstances, such as when we believe in good faith that the law requires it or under the circumstances described below.
    2. We may also disclose your Personal Data in the following cases:
      1. Service Providers. The Company hires other companies to provide limited services on our behalf, including Website development and operation, sending postal mail or email, analyzing website use, processing payments, providing investor information and processing data. We will only provide those companies the information they need to deliver the service, and they are contractually prohibited from using that information for any other reason.
      2. Data in the Aggregate. We may disclose aggregated data that does not identify an individual person to prospective partners and other third parties.
      3. We may disclose your information in exceptional cases, for example, when we believe that we must disclose information to identify, contact, or bring legal action against someone who may be violating our Terms of Use or may be causing injury to or interference with our rights or property, other website users or customers, or anyone else who may be harmed by such activities. We may disclose or access account information when we believe in good faith that the law requires it and for administrative and other purposes that we deem necessary to maintain, service, and improve our products and services.
      4. The Company may buy or sell businesses or assets. In such transactions, confidential customer information generally is one of the transferred business assets. Personal Data of Clients may be disclosed to a potential buyer or seller.
      5. We may share your personal information with our marketing partners for the purposes of targeting, modeling, and/or analytics, as well as marketing and advertising. You may opt out of receiving directly from the emails you receive.
    1. The Company has implemented security measures to ensure the confidentiality of your Personal Data and to protect it from loss, misuse, alteration, or destruction. Only authorized persons of the Company have access to Clients’ Personal Data, and these persons are required to treat the information as confidential.
    2. The Company has implemented the following measures to protect Personal Data:
      1. 2-factor authentication;
      2. Logging of activities performed in the platform;
      3. Access controls and other measures to mitigate risks identified during the risk assessment process;
      4. All data processing systems operate in complete confidentiality;
      5. Password-protected directories and databases;
      6. All data can be restored in case of technical difficulties.
    3. In case the Client has reasons to think that interaction with the Company might be no longer secure, the Client has to contact the Company immediately. When appropriate, the Company shall notify those whose data may have been compromised and take other steps in accordance with the applicable law.
    1. The legal basis for Personal Data collection and processing shall be as follows:
      1. Your consent;
      2. An agreement where processing is necessary to fulfill the terms and conditions of the agreement between the Clients and the Company;
      3. Compliance with legal obligations, where the Company is required to request/receive and process, as well as store your Personal Data in order to comply with the requirements of applicable laws, e.g., AML/CTF laws;
      4. Usage of legitimate interest, for example, when processing is necessary to protect the Client from specific threats, such as fraud, security threats, etc.;
      5. Compliance with the provisions of applicable laws in order to conduct our business in line with regulatory requirements.
    1. This Privacy Policy and other relationships between the parties are governed by the Law of Lithuania.
    2. We keep your personal information to enable your continued use of EXBI Services for as long as it is required in order to fulfill the relevant purposes described in this Privacy Policy, as may be required by law, such as for tax and accounting purposes, or as otherwise communicated to you. Additionally, identity information and Sensitive Personal Data may be retained for eight years to comply with Anti-Money Laundering laws.
    1. Any changes we may make to our Privacy Policy in the future will be posted on this page, and where appropriate, a notification will be sent to you by email. We encourage you to check this page frequently to be aware of any updates or changes to the Privacy Policy.
    2. The Client agrees to such updates by continuing to access or use the services. If you do not agree to any updates to this Policy, you must stop using the services.
    1. If the Client has any questions or uncertainties regarding this Policy, the Client may contact the Company's support team by emailing to [email protected]