Privacy Policy
Introduction
This privacy policy governs the processing of personal data by the Damex Group, specifically relating to Digital Asset Management Ltd (a regulated DLT firm authorised by the GFSC in Gibraltar) and Damex Digital Limited (a limited liability company registered in Malta, authorised and regulated by the Malta Financial Services Authority as a Crypto-Asset Service Provider (CASP) under the Markets in Crypto-Assets Regulation (EU) 2023/1114). Together, these entities are collectively referred to as “Damex” or “Damex.io”.
Damex respects your privacy and is committed to protecting your personal data. This page enables you to view the privacy policy of either entity, informing you how we look after your personal data when you visit our website, use our App, purchase crypto-assets, or subscribe to our services, and tell you about your privacy rights.
This website and our services are not intended for persons under the age of 18, and we do not knowingly collect data relating to those persons.
Important Note on Blockchain Immutability Our services involve the use of Distributed Ledger Technology ("Blockchain"). By design, data written to a public blockchain (e.g., Bitcoin, Ethereum) is immutable, meaning it cannot be changed or deleted. When you transact on a public blockchain, details such as your wallet address and transaction hash are permanently recorded and publicly available. Damex cannot delete this data from the blockchain.
Select the privacy notice
Digital Asset Management Limited Privacy Notice
Last updated: 29 September 2026
This privacy notice explains how Digital Asset Management Limited collects and processes your personal data when you visit our website, use our application or Gibraltar services, contact us, apply for an account or subscribe to marketing communications.
Our website and services are not intended for anyone under 18, and we do not knowingly collect personal data relating to children.
This privacy notice should be read together with any additional privacy information provided for a particular service or interaction. That information supplements this notice and does not override it.
This Privacy Notice is provided in accordance with Regulation (EU) 2016/679 as applicable in Gibraltar (the "Gibraltar GDPR"), the Data Protection Act 2004 and other applicable Gibraltar data-protection legislation.
1. CONTROLLER AND CONTACT DETAILS
This notice applies where Digital Asset Management Limited is the controller of your personal data.
Digital Asset Management Limited is the controller when you visit damex.io, interact with its cookies, submit a website form or contact Damex through the website, unless the relevant page or form states otherwise.
It is also the controller when you apply for or use a service provided under its Gibraltar terms, as identified in your onboarding documents, account terms or service communications. Digital Asset Management Limited does not provide services to customers in the EEA; those services are provided by Damex Digital Ltd under a separate privacy notice.
- Digital Asset Management Limited, Unit C, 1st Floor, Chatham Counterguard Works, 17 Chatham Counterguard, Gibraltar GX11 1AA.
You can contact our Data Protection Officer at privacy@damex.io or at the Gibraltar address above.
2. THE DATA WE COLLECT ABOUT YOU
We may collect, use, store and transfer the following categories of personal data:
| Type of personal data | Examples of information collected |
|---|---|
| Identity and contact information | Name, date of birth, nationality, residential address, email address, telephone number, photographs and account identifiers. |
| Business and ownership information | Company details and information about directors, shareholders, beneficial owners, authorised representatives and persons associated with a business customer. |
| Account and service information | Application records, account status, wallet information, services used, customer preferences and information required to administer your account. |
| KYC and compliance information | Identification documents, proof of address, liveness-check information and verification results, source-of-funds and source-of-wealth information, sanctions and PEP screening results, adverse-media information, risk assessments, fraud indicators and compliance reviews. |
| Biometric verification information | Facial photographs or video, facial geometry or templates generated from them, liveness checks and face-match results, anti-spoofing indicators and related verification records, where biometric verification is used. |
| Financial, payment and transaction information | Bank and payment details, balances, wallet addresses, transaction hashes, amounts, dates, counterparties, beneficiaries, fees and payment references. This also includes originator and beneficiary information required under applicable Travel Rule requirements. |
| Tax and regulatory-reporting information | Tax residence, tax identification numbers and account or transaction information required for applicable tax and regulatory reporting. |
| Technical, usage and security information | IP address, device and browser information, approximate location, login and authentication records, website and service usage, cookie identifiers, technical logs and information relating to suspected fraudulent or unauthorised activity. |
| Communications and marketing information | Enquiries, support messages, complaints, instructions, correspondence, marketing preferences, consent records and opt-out requests. |
3. HOW IS YOUR PERSONAL DATA COLLECTED?
We collect personal data directly from you when you use our website, contact us, apply for an account, complete our identity-verification process or use our services.
When you visit our website, we may collect technical and usage information through cookies and similar technologies. Further information about the cookies we use and the choices available to you is provided in our Cookies Policy.
We may also receive personal data from identity-verification, screening, fraud-prevention, blockchain-analysis and Travel Rule providers; banks, payment providers, other crypto-asset service providers and transfer counterparties; public blockchains, official sanctions and PEP lists, company registers and other publicly available sources; and regulators or other competent authorities. We obtain and use information from these sources only where necessary for the purposes described in this notice and where permitted by applicable law.
Where we obtain personal data about you from another source, we provide the information required by applicable data-protection law within the relevant period, unless an exemption applies.
4. HOW WE USE YOUR PERSONAL DATA
We use personal data only where we have a lawful basis. The main purposes and lawful bases are:
| Purpose or activity | Type of personal data | Lawful basis including legitimate interests |
|---|---|---|
| Register you as a customer and assess your application | Identity and contact information; Business and ownership information; Account and service information | Steps before entering into a contract - Article 6(1)(b). This applies where you apply in your personal capacity. Compliance with a legal obligation - Article 6(1)(c). This applies where we must collect information about directors, beneficial owners or representatives for customer due diligence. Legitimate interests - Article 6(1)(f). Where necessary to assess a business-customer application, Damex has a legitimate interest in evaluating prospective business customers and their authorised representatives. |
| Verify identity and conduct customer due diligence, sanctions screening, ongoing monitoring and other AML/CFT checks | Identity and contact information;Biometric verification information; Business and ownership information; KYC and compliance information; Financial, payment and transaction information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with the AML/CFT, sanctions and regulatory obligations applicable to Digital Asset Management Limited. |
| Provide and administer accounts, wallets, payments, crypto-asset transfers and customer support | Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | Performance of a contract - Article 6(1)(b). This applies where you are the customer. Legitimate interests - Article 6(1)(f). Where we process information about directors, beneficial owners, authorised representatives or other business contacts, Damex has a legitimate interest in administering and supporting the business-customer relationship. |
| Collect and transmit originator and beneficiary information when processing crypto-asset transfers | Identity and contact information; Account and service information; Financial, payment and transaction information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with applicable Gibraltar requirements concerning transfers of funds and crypto-assets. |
| Collect, verify, retain and report tax-residency and reportable crypto-asset information to tax authorities, where required | Identity and contact information; Account and service information; Financial, payment and transaction information; Tax and regulatory-reporting information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with the tax-reporting requirements applicable to Digital Asset Management Limited. |
| Process transactions, payments, fees and refunds | Identity and contact information; Account and service information; Financial, payment and transaction information | Performance of a contract - Article 6(1)(b). Necessary to process transactions and payments under your agreement with Damex. |
| Detect and prevent fraud, misuse and unauthorised activity | Account and service information; KYC and compliance information; Financial, payment and transaction information; Technical, usage and security information | Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in preventing fraud, protecting customers and safeguarding its services and assets. Where monitoring is legally required, Damex relies on Article 6(1)(c). |
| Administer and protect our website, systems and services, including troubleshooting, maintenance and security monitoring | Account and service information; Technical, usage and security information | Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in operating its business and maintaining secure, available and reliable systems. Where a measure is legally required, Damex relies on Article 6(1)(c). |
| Manage our relationship with you, including service communications and notices about material changes | Identity and contact information; Account and service information; Communications and marketing information | Performance of a contract - Article 6(1)(b) where the communication concerns your service. Compliance with a legal obligation - Article 6(1)(c) where Damex is legally required to notify you. |
| Respond to enquiries, manage complaints and establish, exercise or defend legal claims | Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | Performance of a contract - Article 6(1)(b) where the matter concerns your service. Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in responding to enquiries, resolving disputes and protecting its legal rights. Article 6(1)(c) applies where complaint handling is legally required. |
| Use non-essential analytics or advertising cookies | Technical, usage and security information | Consent - Article 6(1)(a). You may withdraw your consent through our cookie settings at any time. |
| Marketing communications | Identity and contact information; Communications and marketing information | Consent – Article 6(1)(a). You may withdraw your consent at any time by using the unsubscribe option in our communications or contacting us. |
Where we ask you to provide personal data to enter into or perform a contract, or to comply with a legal obligation, that information is required. If you do not provide it, we may be unable to assess your application, open or maintain your account, provide a service or process a transaction. Information requested for optional purposes, such as marketing, is voluntary.
We do not generally seek to collect special categories of personal data, such as information about race or ethnicity, religious or philosophical beliefs, sex life or sexual orientation, political opinions, trade-union membership, health, or genetic data.
5. DISCLOSURES OF YOUR PERSONAL DATA
We disclose personal data only where necessary for a specific purpose and where permitted or required by law. We limit each disclosure to the personal data reasonably necessary and take appropriate measures to protect it.
Recipients may include:
- Damex Digital Ltd, where it provides operational or compliance support to Digital Asset Management Limited and the disclosure is necessary and lawful.
- SumSub, our principal KYC provider, for onboarding, identity verification, liveness checks, sanctions and PEP screening, and other customer due-diligence checks.
- Notabene and other Travel Rule technology providers, other crypto-asset service providers and transfer counterparties, for exchanging legally required originator and beneficiary information.
- Fireblocks and other wallet-infrastructure providers used to operate Damex’s digital-asset wallets and process related wallet and transaction information.
- Blockchain-analysis, transaction-monitoring and fraud-prevention providers.
- Banks, payment service providers and electronic money institutions, where necessary to process payments, transfers, withdrawals or other transactions.
- Cloud-hosting, business-communications, IT-support and cybersecurity providers used to operate and protect our systems and services.
- Marketing-communications providers, where you have consented to receive marketing.
- Legal advisers, accountants and auditors, where disclosure is necessary to obtain professional advice, complete an audit or meet a legal or regulatory requirement.
- Regulators, financial intelligence units, tax authorities, law-enforcement agencies, courts and other competent authorities, where disclosure is required or permitted by law.
- Prospective purchasers and their professional advisers in connection with a proposed merger, acquisition, restructuring or sale, subject to appropriate confidentiality and data-protection safeguards.
Where a disclosure involves an international transfer of personal data, we apply the safeguards described in the International Transfers section.
6. AUTOMATED PROCESSING
We use technology to support identity verification, screening, fraud detection, customer-risk assessment and transaction monitoring. These systems generate results, alerts or risk indicators but do not, by themselves, make a final decision that produces legal or similarly significant effects. Relevant adverse results are reviewed by authorised Damex personnel before a decision is made. If we introduce solely automated decision-making that produces such effects, we will provide the information and safeguards required by applicable law.
7. INTERNATIONAL TRANSFERS
We may transfer your personal data to recipients located outside Gibraltar.
Where Gibraltar data-protection law applies and personal data is transferred outside Gibraltar, we use a transfer mechanism permitted under that law and take steps designed to ensure that the data remains protected. These safeguards may include:
- Adequacy provisions: transfers to countries or territories recognised under applicable Gibraltar law as providing an adequate level of protection.
- Approved contractual safeguards: appropriate contractual protections and, where necessary, supplementary safeguards for transfers to countries or territories without an applicable adequacy provision.
Personal data may be transferred from Digital Asset Management Limited in Gibraltar to Damex Digital Ltd in Malta where necessary for the purposes described in this notice and where permitted under applicable data-protection law.
Where the EU GDPR also applies to particular processing, transfers outside the EEA are made under an appropriate mechanism under Chapter V of the EU GDPR, including an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism.
You may contact our Data Protection Officer at privacy@damex.io for further information about the safeguards used for international transfers and, where applicable, to request a copy.
8. RETENTION OF PERSONAL DATA
We retain personal data only for as long as necessary for the purposes for which it was collected and to comply with applicable legal, regulatory, accounting, reporting and contractual requirements. The periods below describe the principal retention rules; more detailed periods for individual systems and records are maintained in our internal retention schedule.
| Type(s) of personal data | Retention period | Reason for retention |
|---|---|---|
| Identity and contact information; Business and ownership information; KYC and compliance information; Tax and regulatory-reporting information | Generally five years after the business relationship ends or, for an occasional transaction, five years after the transaction is completed. A longer period may apply where required or permitted by applicable law or directed by a competent authority. | To comply with applicable AML/CFT, sanctions, customer due-diligence, record-keeping and regulatory obligations. |
| Account and service information | For the customer relationship and generally five years after it ends. Records required for a longer legal-claims, accounting or regulatory period are retained only for that longer applicable period. | To provide and administer the services, comply with regulatory obligations and establish, exercise or defend legal claims. |
| Financial, payment and transaction information; Account and service information | Generally five years from completion of the relevant transaction or termination of the business relationship, as applicable. A longer period may apply where required by accounting, tax, regulatory or legal requirements. | To maintain transaction records, comply with AML/CFT, accounting and regulatory requirements, investigate suspicious activity and establish, exercise or defend legal claims. |
| Identity and contact information; Financial, payment and transaction information | Generally five years from the relevant transfer or termination of the business relationship, subject to any longer period required by applicable law | To comply with applicable legal and regulatory requirements concerning transfers of funds and crypto-assets. |
| Tax and regulatory-reporting information; Identity and contact information; Account and service information; Financial, payment and transaction information | For the period required by applicable tax and regulatory-reporting laws, calculated from the relevant transaction, report, account closure or financial year | To comply with applicable tax and regulatory-reporting requirements. |
| KYC and compliance information; Financial, payment and transaction information | Generally five years from the relevant internal decision or submission to the competent authority. A longer period may apply where required by law or directed by a competent authority. | To comply with AML/CFT reporting, monitoring and record-keeping obligations and to assist competent authorities. |
| Identity and contact information; Business and ownership information; Account and service information; KYC and compliance information | Deleted when the onboarding process ends if no customer relationship is established, unless limited retention is necessary for fraud prevention, an investigation, a regulatory requirement, a legal claim or a legal hold | To conclude the application process, prevent repeated fraud or misuse and comply with any applicable legal or regulatory requirements. |
| Identity and contact information; Account and service information; Communications and marketing information | For up to three years after the enquiry or support matter is closed, unless it becomes part of a complaint, investigation or legal claim. | To respond to enquiries, provide support, maintain appropriate business records and resolve disputes. |
| Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | For five years after the matter is closed, or longer where required by an applicable limitation period, regulator, investigation or legal hold. | To investigate and resolve complaints and to establish, exercise or defend legal claims. |
| Identity and contact information; Communications and marketing information | Until you withdraw your consent, opt out or the information is no longer required for the relevant marketing purpose | To send marketing communications where permitted and to demonstrate compliance with applicable marketing and data-protection requirements. Limited contact information may be retained on a suppression list to ensure that your opt-out preference continues to be respected. |
| Technical, usage and security information | Routine technical, login and security logs are normally retained for up to 12 months. Records connected with suspected fraud, a security incident or an investigation may be retained for up to five years after the matter is closed, or longer where required by law or legal hold. | To maintain security, prevent fraud and misuse, investigate incidents and protect Damex, its customers and its services. |
| Technical, usage and security information | For the periods stated in our Cookies Policy | To operate the website, remember user preferences and, where you have consented, perform analytics or advertising activities. |
We may retain information for longer where necessary in connection with a regulatory enquiry, investigation, complaint, legal proceeding or legal hold. When personal data is no longer required, it is securely deleted or anonymised so that it can no longer identify you.
You may contact our Data Protection Officer at privacy@damex.io for further information about the retention period applicable to your personal data.
9. YOUR RIGHTS
Subject to applicable data-protection law and certain conditions, you may exercise the following rights in relation to your personal data.
Right to be informed
You have the right to receive clear and transparent information about how we collect and use your personal data. This Privacy Notice is intended to provide that information.
Right of access
You may ask us to confirm whether we process your personal data and request a copy of that data, together with information about how it is used and disclosed.
Right to rectification
You may ask us to correct personal data that is inaccurate or complete information that is incomplete. We may need to verify the accuracy of the new information you provide.
Right to erasure
You may ask us to delete your personal data where:
- it is no longer required for the purpose for which it was collected;
- you withdraw your consent and there is no other lawful basis for processing;
- you successfully object to the processing;
- the personal data has been processed unlawfully; or
- deletion is required to comply with a legal obligation.
This right is not absolute. We may retain personal data where processing remains necessary to comply with a legal or regulatory obligation, perform a task in the public interest or establish, exercise or defend legal claims. This may include AML/CFT, sanctions, tax, accounting and regulatory record-keeping requirements.
Right to restrict processing
You may ask us to restrict the processing of your personal data where:
- you contest its accuracy while we verify it;
- the processing is unlawful, but you do not want the information deleted;
- we no longer require the information, but you need it to establish, exercise or defend a legal claim; or
- you have objected to processing and we are considering whether our legitimate grounds override your rights.
Right to data portability
Where we process personal data that you provided to us by automated means and the processing is based on your consent or a contract, you may ask to receive that data in a structured, commonly used and machine-readable format. Where technically feasible, you may also ask us to transmit it directly to another controller.
This right does not generally apply to information that we have created or derived ourselves or to processing necessary to comply with a legal obligation.
Right to object
You may object to processing based on legitimate interests because of your particular circumstances. We will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary to establish, exercise or defend legal claims.
You may opt out of direct marketing at any time, including by using the unsubscribe option in a marketing communication. If you opt out of marketing, we may retain limited information on a suppression list to ensure that your preference continues to be respected. This will not prevent us from sending essential service, account, security or regulatory communications.
Rights relating to automated decision-making
Where applicable, you have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significantly affects you.
Where such processing is permitted by law, we will implement the required safeguards. These may include the right to request human intervention, express your point of view and contest the decision.
Right to withdraw consent
Where we rely on your consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before your consent was withdrawn.
Withdrawing consent may prevent us from continuing an optional activity that depends on that consent, but it will not automatically affect processing carried out under another lawful basis.
How to exercise your rights
To exercise any of these rights, contact our Data Protection Officer at privacy@damex.io.
We may ask for information necessary to confirm your identity and ensure that personal data is not disclosed to someone who is not entitled to receive it.
We will respond without undue delay and generally within one month. Where permitted by law, this period may be extended because of the complexity or number of requests. We will inform you of any extension and the reasons for it within the initial one month period.
Your rights are subject to the conditions, limitations and exemptions provided by applicable law. If we cannot comply with your request, we will explain the reason and inform you of any available complaint or appeal rights.
Right to lodge a complaint
You have the right to lodge a complaint with the Gibraltar Information Commissioner, acting through the Gibraltar Regulatory Authority.
Where the EU GDPR applies, you may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.
We would welcome the opportunity to address your concerns first, but you are not required to contact us before approaching a supervisory authority.
10. COOKIES
We use cookies and similar technologies for functionality, security, analytics and, where applicable, marketing. Non-essential cookies are used only where the required consent has been obtained. See our Cookies Policy for details and controls.
11. CHANGES TO THIS PRIVACY NOTICE
We may update this Privacy Notice from time to time to reflect changes to our services, processing activities or legal obligations. The latest version and the date it was last updated will be published on our website. Where appropriate, we will notify you of material changes.
Damex Digital Ltd Privacy Notice
Last updated: 29 September 2026
This privacy notice explains how Damex Digital Ltd collects and processes your personal data when you apply for an account, use our application or EEA services, contact us in relation to those services or subscribe to marketing communications.
Our services are not intended for anyone under 18, and we do not knowingly collect personal data relating to children.
This privacy notice should be read together with any additional privacy information provided for a particular service or interaction. That information supplements this notice and does not override it.
This Privacy Notice is provided in accordance with Regulation (EU) 2016/679 (the "EU GDPR"), the Data Protection Act (Chapter 586 of the Laws of Malta) and other applicable data-protection legislation.
1. CONTROLLER AND CONTACT DETAILS
This notice applies where Damex Digital Ltd is the controller of your personal data.
Damex Digital Ltd is the controller when you apply for or use services provided to customers in the European Economic Area. This will be identified in your onboarding documents, account terms or service communications.
General interactions with damex.io, including website forms and cookies, are controlled by Digital Asset Management Limited and are covered by its separate Privacy Notice.
- Damex Digital Ltd, MK Business Centre, 115A, Floor 2, Triq Il-Wied, Birkirkara, BKR 9022, Malta.
You can contact our Data Protection Officer at privacy@damex.io or at the Malta address above.
2. THE DATA WE COLLECT ABOUT YOU
We may collect, use, store and transfer the following categories of personal data:
| Type of personal data | Examples of information collected |
|---|---|
| Identity and contact information | Name, date of birth, nationality, residential address, email address, telephone number, photographs and account identifiers. |
| Business and ownership information | Company details and information about directors, shareholders, beneficial owners, authorised representatives and persons associated with a business customer. |
| Account and service information | Application records, account status, wallet information, services used, customer preferences and information required to administer your account. |
| KYC and compliance information | Identification documents, proof of address, liveness-check information and verification results, source-of-funds and source-of-wealth information, sanctions and PEP screening results, adverse-media information, risk assessments, fraud indicators and compliance reviews. |
| Biometric verification information | Facial photographs or video, facial geometry or templates generated from them, liveness checks and face-match results, anti-spoofing indicators and related verification records, where biometric verification is used. |
| Financial, payment and transaction information | Bank and payment details, balances, wallet addresses, transaction hashes, amounts, dates, counterparties, beneficiaries, fees and payment references. This also includes originator and beneficiary information required under applicable Travel Rule requirements. |
| Tax and regulatory-reporting information | Tax residence, tax identification numbers and account or transaction information required for applicable tax and regulatory reporting. |
| Technical, usage and security information | IP address, device and browser information, approximate location, login and authentication records, application and service usage, technical logs and information relating to suspected fraudulent or unauthorised activity. |
| Communications and marketing information | Enquiries, support messages, complaints, instructions, correspondence, marketing preferences, consent records and opt-out requests. |
3. HOW IS YOUR PERSONAL DATA COLLECTED?
We collect personal data directly from you when you contact us, apply for an account, complete our identity-verification process or use our services.
We may also receive personal data from identity-verification, screening, fraud-prevention, blockchain-analysis and Travel Rule providers; banks, payment providers, other crypto-asset service providers and transfer counterparties; public blockchains, official sanctions and PEP lists, company registers and other publicly available sources; and regulators or other competent authorities. We obtain and use information from these sources only where necessary for the purposes described in this notice and where permitted by applicable law.
Where we obtain personal data about you from another source, we provide the information required by applicable data-protection law within the relevant period, unless an exemption applies.
4. HOW WE USE YOUR PERSONAL DATA
We use personal data only where we have a lawful basis. The main purposes and lawful bases are:
| Purpose or activity | Type of personal data | Lawful basis including legitimate interests |
|---|---|---|
| Register you as a customer and assess your application | Identity and contact information; Business and ownership information; Account and service information | Steps before entering into a contract - Article 6(1)(b). This applies where you apply in your personal capacity. Compliance with a legal obligation - Article 6(1)(c). This applies where we must collect information about directors, beneficial owners or representatives for customer due diligence. Legitimate interests - Article 6(1)(f). Where necessary to assess a business-customer application, Damex has a legitimate interest in evaluating prospective business customers and their authorised representatives. |
| Verify identity and conduct customer due diligence, sanctions screening, ongoing monitoring and other AML/CFT checks | Identity and contact information; Biometric verification information; Business and ownership information; KYC and compliance information; Financial, payment and transaction information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with the AML/CFT, sanctions and regulatory obligations applicable to Damex Digital Ltd. |
| Provide and administer accounts, wallets, payments, crypto-asset transfers and customer support | Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | Performance of a contract - Article 6(1)(b). This applies where you are the customer. Legitimate interests - Article 6(1)(f). Where we process information about directors, beneficial owners, authorised representatives or other business contacts, Damex has a legitimate interest in administering and supporting the business-customer relationship. |
| Collect and transmit originator and beneficiary information when processing crypto-asset transfers | Identity and contact information; Account and service information; Financial, payment and transaction information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with applicable EU and Malta Travel Rule requirements. |
| Collect, verify, retain and report tax-residency and reportable crypto-asset information to tax authorities, where required | Identity and contact information; Account and service information; Financial, payment and transaction information; Tax and regulatory-reporting information | Compliance with a legal obligation - Article 6(1)(c). Necessary to comply with the tax-reporting requirements applicable to Damex Digital Ltd, including DAC8 where applicable. |
| Process transactions, payments, fees and refunds | Identity and contact information; Account and service information; Financial, payment and transaction information | Performance of a contract - Article 6(1)(b). Necessary to process transactions and payments under your agreement with Damex. |
| Detect and prevent fraud, misuse and unauthorised activity | Account and service information; KYC and compliance information; Financial, payment and transaction information; Technical, usage and security information | Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in preventing fraud, protecting customers and safeguarding its services and assets. Where monitoring is legally required, Damex relies on Article 6(1)(c). |
| Administer and protect our application, systems and services, including troubleshooting, maintenance and security monitoring | Account and service information; Technical, usage and security information | Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in operating its business and maintaining secure, available and reliable systems. Where a measure is legally required, Damex relies on Article 6(1)(c). |
| Manage our relationship with you, including service communications and notices about material changes | Identity and contact information; Account and service information; Communications and marketing information | Performance of a contract - Article 6(1)(b) where the communication concerns your service. Compliance with a legal obligation - Article 6(1)(c) where Damex is legally required to notify you. |
| Respond to enquiries, manage complaints and establish, exercise or defend legal claims | Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | Performance of a contract - Article 6(1)(b) where the matter concerns your service. Legitimate interests - Article 6(1)(f). Damex has a legitimate interest in responding to enquiries, resolving disputes and protecting its legal rights. Article 6(1)(c) applies where complaint handling is legally required. |
| Marketing communications | Identity and contact information; Communications and marketing information | Consent – Article 6(1)(a). You may withdraw your consent at any time by using the unsubscribe option in our communications or contacting us. |
Where we ask you to provide personal data to enter into or perform a contract, or to comply with a legal obligation, that information is required. If you do not provide it, we may be unable to assess your application, open or maintain your account, provide a service or process a transaction. Information requested for optional purposes, such as marketing, is voluntary.
We do not generally seek to collect special categories of personal data, such as information about race or ethnicity, religious or philosophical beliefs, sex life or sexual orientation, political opinions, trade-union membership, health, or genetic data.
5. DISCLOSURES OF YOUR PERSONAL DATA
We disclose personal data only where necessary for a specific purpose and where permitted or required by law. We limit each disclosure to the personal data reasonably necessary and take appropriate measures to protect it.
Recipients may include:
- Digital Asset Management Limited, where it provides operational or compliance support to Damex Digital Ltd and the disclosure is necessary and lawful.
- SumSub, our principal KYC provider, for onboarding, identity verification, liveness checks, sanctions and PEP screening, and other customer due-diligence checks.
- Notabene and other Travel Rule technology providers, other crypto-asset service providers and transfer counterparties, for exchanging legally required originator and beneficiary information.
- Fireblocks and other wallet-infrastructure providers used to operate Damex’s digital-asset wallets and process related wallet and transaction information.
- Blockchain-analysis, transaction-monitoring and fraud-prevention providers.
- Banks, payment service providers and electronic money institutions, where necessary to process payments, transfers, withdrawals or other transactions.
- Cloud-hosting, business-communications, IT-support and cybersecurity providers used to operate and protect our systems and services.
- Marketing-communications providers, where you have consented to receive marketing.
- Legal advisers, accountants and auditors, where disclosure is necessary to obtain professional advice, complete an audit or meet a legal or regulatory requirement.
- Regulators, financial intelligence units, tax authorities, law-enforcement agencies, courts and other competent authorities, where disclosure is required or permitted by law.
- Prospective purchasers and their professional advisers in connection with a proposed merger, acquisition, restructuring or sale, subject to appropriate confidentiality and data-protection safeguards.
Where a disclosure involves an international transfer of personal data, we apply the safeguards described in the International Transfers section.
6. AUTOMATED PROCESSING
We use technology to support identity verification, screening, fraud detection, customer-risk assessment and transaction monitoring. These systems generate results, alerts or risk indicators but do not, by themselves, make a final decision that produces legal or similarly significant effects. Relevant adverse results are reviewed by authorised Damex personnel before a decision is made. If we introduce solely automated decision-making that produces such effects, we will provide the information and safeguards required by applicable law.
7. INTERNATIONAL TRANSFERS
We may transfer your personal data to recipients located outside the European Economic Area (EEA).
Where the EU GDPR applies and personal data is transferred outside the EEA, we use an appropriate transfer mechanism and take steps designed to ensure that the data remains protected. These safeguards may include:
- Adequacy decisions: transfers to countries or territories that the European Commission has recognised as providing an adequate level of protection.
- Standard Contractual Clauses: European Commission-approved contractual clauses and, where necessary, supplementary safeguards for transfers to countries or territories without an adequacy decision.
Personal data may be transferred from Damex Digital Ltd in Malta to Digital Asset Management Limited in Gibraltar where necessary for the purposes described in this notice. As Gibraltar is outside the EEA, transfers to Gibraltar are protected using European Commission Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the EU GDPR.
You may contact our Data Protection Officer at privacy@damex.io for further information about the safeguards used for international transfers and, where applicable, to request a copy.
8. RETENTION OF PERSONAL DATA
We retain personal data only for as long as necessary for the purposes for which it was collected and to comply with applicable legal, regulatory, accounting, reporting and contractual requirements. The periods below describe the principal retention rules; more detailed periods for individual systems and records are maintained in our internal retention schedule.
| Type(s) of personal data | Retention period | Reason for retention |
|---|---|---|
| Identity and contact information; Business and ownership information; KYC and compliance information; Tax and regulatory-reporting information | Generally five years after the business relationship ends or, for an occasional transaction, five years after the transaction is completed. A longer period may apply where required or permitted by applicable law or directed by a competent authority. | To comply with applicable AML/CFT, sanctions, customer due-diligence, record-keeping and regulatory obligations. |
| Account and service information | For the customer relationship and generally five years after it ends. Records required for a longer legal-claims, accounting or regulatory period are retained only for that longer applicable period. | To provide and administer the services, comply with regulatory obligations and establish, exercise or defend legal claims. |
| Financial, payment and transaction information; Account and service information | Generally five years from completion of the relevant transaction or termination of the business relationship, as applicable. A longer period may apply where required by accounting, tax, regulatory or legal requirements. | To maintain transaction records, comply with AML/CFT, accounting and regulatory requirements, investigate suspicious activity and establish, exercise or defend legal claims. |
| Identity and contact information; Financial, payment and transaction information | Generally five years from the relevant transfer or termination of the business relationship, subject to any longer period required by applicable law | To comply with applicable legal and regulatory requirements concerning transfers of funds and crypto-assets. |
| Tax and regulatory-reporting information; Identity and contact information; Account and service information; Financial, payment and transaction information | For the period required by applicable tax and regulatory-reporting laws, calculated from the relevant transaction, report, account closure or financial year | To comply with applicable tax, DAC8, CARF and other regulatory-reporting requirements. |
| KYC and compliance information; Financial, payment and transaction information | Generally five years from the relevant internal decision or submission to the competent authority. A longer period may apply where required by law or directed by a competent authority. | To comply with AML/CFT reporting, monitoring and record-keeping obligations and to assist competent authorities. |
| Identity and contact information; Business and ownership information; Account and service information; KYC and compliance information | Deleted when the onboarding process ends if no customer relationship is established, unless limited retention is necessary for fraud prevention, an investigation, a regulatory requirement, a legal claim or a legal hold | To conclude the application process, prevent repeated fraud or misuse and comply with any applicable legal or regulatory requirements. |
| Identity and contact information; Account and service information; Communications and marketing information | For up to three years after the enquiry or support matter is closed, unless it becomes part of a complaint, investigation or legal claim. | To respond to enquiries, provide support, maintain appropriate business records and resolve disputes. |
| Identity and contact information; Account and service information; Financial, payment and transaction information; Communications and marketing information | For five years after the matter is closed, or longer where required by an applicable limitation period, regulator, investigation or legal hold. | To investigate and resolve complaints and to establish, exercise or defend legal claims. |
| Identity and contact information; Communications and marketing information | Until you withdraw your consent, opt out or the information is no longer required for the relevant marketing purpose | To send marketing communications where permitted and to demonstrate compliance with applicable marketing and data-protection requirements. Limited contact information may be retained on a suppression list to ensure that your opt-out preference continues to be respected. |
| Technical, usage and security information | Routine technical, login and security logs are normally retained for up to 12 months. Records connected with suspected fraud, a security incident or an investigation may be retained for up to five years after the matter is closed, or longer where required by law or legal hold. | To maintain security, prevent fraud and misuse, investigate incidents and protect Damex, its customers and its services. |
We may retain information for longer where necessary in connection with a regulatory enquiry, investigation, complaint, legal proceeding or legal hold. When personal data is no longer required, it is securely deleted or anonymised so that it can no longer identify you.
You may contact our Data Protection Officer at privacy@damex.io for further information about the retention period applicable to your personal data.
9. YOUR RIGHTS
Subject to applicable data-protection law and certain conditions, you may exercise the following rights in relation to your personal data.
Right to be informed
You have the right to receive clear and transparent information about how we collect and use your personal data. This Privacy Notice is intended to provide that information.
Right of access
You may ask us to confirm whether we process your personal data and request a copy of that data, together with information about how it is used and disclosed.
Right to rectification
You may ask us to correct personal data that is inaccurate or complete information that is incomplete. We may need to verify the accuracy of the new information you provide.
Right to erasure
You may ask us to delete your personal data where:
- it is no longer required for the purpose for which it was collected;
- you withdraw your consent and there is no other lawful basis for processing;
- you successfully object to the processing;
- the personal data has been processed unlawfully; or
- deletion is required to comply with a legal obligation.
This right is not absolute. We may retain personal data where processing remains necessary to comply with a legal or regulatory obligation, perform a task in the public interest or establish, exercise or defend legal claims. This may include AML/CFT, sanctions, tax, accounting and regulatory record-keeping requirements.
Right to restrict processing
You may ask us to restrict the processing of your personal data where:
- you contest its accuracy while we verify it;
- the processing is unlawful, but you do not want the information deleted;
- we no longer require the information, but you need it to establish, exercise or defend a legal claim; or
- you have objected to processing and we are considering whether our legitimate grounds override your rights.
Right to data portability
Where we process personal data that you provided to us by automated means and the processing is based on your consent or a contract, you may ask to receive that data in a structured, commonly used and machine-readable format. Where technically feasible, you may also ask us to transmit it directly to another controller.
This right does not generally apply to information that we have created or derived ourselves or to processing necessary to comply with a legal obligation.
Right to object
You may object to processing based on legitimate interests because of your particular circumstances. We will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary to establish, exercise or defend legal claims.
You may opt out of direct marketing at any time, including by using the unsubscribe option in a marketing communication. If you opt out of marketing, we may retain limited information on a suppression list to ensure that your preference continues to be respected. This will not prevent us from sending essential service, account, security or regulatory communications.
Rights relating to automated decision-making
Where applicable, you have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects or similarly significantly affects you.
Where such processing is permitted by law, we will implement the required safeguards. These may include the right to request human intervention, express your point of view and contest the decision.
Right to withdraw consent
Where we rely on your consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before your consent was withdrawn.
Withdrawing consent may prevent us from continuing an optional activity that depends on that consent, but it will not automatically affect processing carried out under another lawful basis.
How to exercise your rights
To exercise any of these rights, contact our Data Protection Officer at privacy@damex.io.
We may ask for information necessary to confirm your identity and ensure that personal data is not disclosed to someone who is not entitled to receive it.
We will respond without undue delay and generally within one month. Where permitted by law, this period may be extended because of the complexity or number of requests. We will inform you of any extension and the reasons for it within the initial one month period.
Your rights are subject to the conditions, limitations and exemptions provided by applicable law. If we cannot comply with your request, we will explain the reason and inform you of any available complaint or appeal rights.
Right to lodge a complaint
You have the right to lodge a complaint with the Information and Data Protection Commissioner of Malta.
- IDPC Address: Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema, SLM 1549, Malta.
- IDPC Email: idpc.info@idpc.org.mt
- Website: https://idpc.org.mt
- https://idpc.org.mt/file-a-complaint/
Where the EU GDPR applies, you may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work or the place of the alleged infringement.
We would welcome the opportunity to address your concerns first, but you are not required to contact us before approaching a supervisory authority.
10. CHANGES TO THIS PRIVACY NOTICE
We may update this Privacy Notice from time to time to reflect changes to our services, processing activities or legal obligations. The latest version and the date it was last updated will be published on our website. Where appropriate, we will notify you of material changes.