PontisGlobe

Privacy Policy

Last Updated: May 2026

1. Information We Collect

PontisGlobe collects the following categories of personal data when you use our platform:

Identity & KYC Information

  • Full legal name, date of birth, nationality, and place of birth
  • Government-issued identification documents (passport, national ID, driver's licence)
  • Selfie / biometric data for identity verification
  • Proof of address (utility bill, bank statement)
  • For businesses: company registration documents, director and beneficial owner information, proof of business address

Contact Information

  • Email address, phone number, residential address
  • Communication preferences

Financial Information

  • Bank account details and wallet addresses
  • Transaction history, amounts, currencies, and beneficiaries
  • Source of funds and wealth declarations where required

Technical Data

  • IP address, device type, browser type
  • Cookies and session data
  • Application access logs and timestamps

Communications

  • Customer support chat transcripts and email correspondence
  • Survey responses and feedback submissions

2. How We Use Your Information

We process your personal data for the following purposes:

  • To verify your identity and comply with KYC/AML regulatory obligations
  • To process, execute, and confirm your transactions
  • To provide customer support and respond to enquiries
  • To detect, investigate, and prevent fraud, money laundering, and other financial crime
  • To comply with applicable laws, regulations, sanctions requirements, and court orders
  • To send you transactional and service notifications
  • To improve the Platform and develop new services
  • To conduct risk assessments and ongoing monitoring
  • To comply with tax reporting obligations in applicable jurisdictions

3. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract: Processing necessary to provide you with PontisGlobe services
  • Legal Obligation: Processing required to comply with AML, KYC, sanctions, tax, and other applicable laws
  • Legitimate Interests: Fraud prevention, platform security, and improvement of services
  • Consent: Where you have given explicit consent (e.g., marketing communications) — which you may withdraw at any time

4. Data Sharing & Disclosure

We do not sell your personal data. We may share your information with:

  • Regulated identity verification and KYC service providers
  • Banking partners, payment processors, and liquidity providers necessary to execute your transactions
  • Blockchain analytics providers for AML transaction monitoring
  • Sanctions and PEP screening providers
  • Regulatory authorities, financial intelligence units, and law enforcement where required by law
  • Legal and professional advisors under strict confidentiality obligations
  • Group companies and affiliated entities of PontisGlobe , bound by equivalent data protection standards

All third-party processors are subject to contractual data protection obligations consistent with applicable law.

5. International Data Transfers

As a global business, PontisGlobe may transfer your personal data across jurisdictions. Where we transfer data outside of the originating jurisdiction (e.g., from the EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent frameworks.

6. Data Retention

We retain your personal data for as long as is necessary to fulfil the purposes described in this Policy, and as required by applicable law. Specifically:

  • KYC documentation and transaction records: minimum 5 years from the date of the last transaction or account closure, in compliance with AML regulations
  • Communication records: 3–5 years from the date of correspondence
  • Account data: retained for the life of your account plus 5 years post-closure

After the applicable retention period, data will be securely deleted or anonymised.

7. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data where legally permissible (note: AML/legal retention requirements may limit this right)
  • Right to Restriction: Request that we limit how we process your data in certain circumstances
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at contact@pontisglobe.com. We will respond within 30 days (or as required by applicable law).

8. Cookies

PontisGlobe uses cookies and similar tracking technologies to enhance your experience on the Platform. You can manage your cookie preferences through your browser settings or our cookie preference centre at the time of your first visit.

9. Security

We implement industry-standard security measures to protect your personal data, including:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Multi-factor authentication for all account access
  • Regular penetration testing and security audits
  • SOC 2-aligned security controls across our infrastructure
  • Strict internal access controls on a need-to-know basis

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to you via email or platform notification with 14 days' notice. Your continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.

11. Contact for Privacy Matters

For any privacy-related enquiries, requests, or complaints, please contact us at contact@pontisglobe.com.