Who this Policy covers
This Policy applies to:
- Visitors to the Website.
- Merchants and their authorized personnel.
- Beneficial owners and representatives of Merchants.
- End-Users completing payments via Halfin-powered checkout interfaces.
Merchant-controlled data
This Policy does not apply to personal data Merchants process about their own customers using Halfin as a technical service. Merchants are independent data controllers for that data.
Data controller
The data controller for personal data collected through the Services is Halfin. Entity details and registered office: [to be inserted before publication].
Privacy questions and rights requests: [email protected]
Data we collect — from Website visitors
We collect the following categories of personal data from Website visitors:
- Technical data: IP address, device type, operating system, browser type and version, screen resolution, language settings, referrer URL, pages viewed, time spent, and similar.
- Cookies and analytics: identifiers, session data, and behavioral analytics as described in our Cookie Policy.
Data we collect — from Merchants during onboarding (KYB)
During onboarding (KYB) we collect:
- Business information: legal entity name, registration number, jurisdiction of incorporation, registered office, business address, trading name, website, business description, industry codes.
- Beneficial ownership and control: names, dates of birth, nationality, addresses, identification documents, and ownership percentages for directors, beneficial owners (typically 25%+), and authorized signatories.
- Identification documents: government-issued ID (passport, national ID, driver's license), proof of address (utility bill, bank statement).
- Financial information: banking details, payment history, source of funds, source of wealth where relevant.
- Compliance information: sanctions screening results, PEP status, adverse media findings.
Data we collect — from Merchants during ongoing use
During ongoing use of the Services we collect:
- Transaction data: invoice records, payment records, payout records, wallet addresses, amounts, timestamps, network details, statuses.
- Dashboard activity: logins, actions taken, API key usage, webhook deliveries, audit log entries.
- Communications: support tickets, emails, and other correspondence.
Data we collect — from End-Users completing payments
From End-Users completing payments we collect:
- Transaction details: wallet address from which payment originates, amount, timestamp, network.
- Technical data: IP address, device type, and similar as described above.
- No KYC by default: End-Users do not register accounts and do not undergo identity verification through Halfin for the purpose of paying an invoice. End-Users completing a transaction are not asked for personal identification documents.
Lawful basis for processing
We process personal data on the following lawful bases:
- Contractual necessity: to provide the Services to Merchants and complete End-User transactions.
- Legal obligation: to comply with AML, sanctions, tax, accounting, and other regulatory requirements.
- Legitimate interests: to operate, secure, and improve the Services; to prevent fraud; to enforce these Terms; to defend legal claims.
- Consent: for optional cookies, marketing communications, and similar purposes where consent is required.
Legitimate-interest balancing
Where we rely on legitimate interests, we balance them against the rights and interests of the data subject.
How we use personal data
We use personal data to:
- Provide and operate the Services.
- Verify the identity of Merchants and their beneficial owners (KYB).
- Conduct sanctions and PEP screening.
- Detect, investigate, and prevent fraud, money laundering, and other unlawful activity.
- Monitor transactions for compliance and risk purposes.
- Provide customer support and respond to inquiries.
- Send service notifications, security alerts, and operational communications.
- Comply with legal obligations and respond to lawful requests from authorities.
- Defend and exercise legal claims.
- Improve platform reliability, security, and feature design.
- Send marketing communications where consent has been provided.
We do not sell personal data
We do not sell personal data to third parties.
Sharing of personal data — subprocessors
We share personal data with the following categories of recipients. Subprocessors are data processors acting on our behalf:
- Identity verification and KYB providers: to verify Merchant identity and beneficial ownership.
- Sanctions and PEP screening providers: to comply with AML and sanctions obligations.
- Hosting and infrastructure: cloud hosting, CDN, DNS, monitoring.
- Email and notifications: transactional and operational communications.
- Analytics: website usage analytics where consent has been obtained.
- Customer support tooling: ticketing, helpdesk, and live chat.
Sharing of personal data — other recipients
All subprocessors are contractually bound to comply with confidentiality, data protection, and security obligations consistent with applicable law. A current list of subprocessors is available on request and will be published as an addendum.
Regulators, law enforcement, and similar: we may disclose personal data to financial intelligence units, law enforcement, tax authorities, and regulators where required by law, court order, or in connection with lawful investigations.
Successors and corporate transactions: in the event of a merger, acquisition, sale of assets, or similar corporate transaction, personal data may be transferred to a successor entity subject to equivalent privacy protections.
Professional advisors: lawyers, accountants, auditors, and similar advisors under confidentiality obligations.
International data transfers
Personal data may be transferred to and processed in jurisdictions outside the data subject's country of residence, including jurisdictions that may not provide an equivalent level of legal protection.
Where personal data is transferred to a jurisdiction that does not provide equivalent protection, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, UK International Data Transfer Agreement, or other lawful transfer mechanisms.
Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- KYB and AML records: retained for at least five (5) years after the end of the business relationship, or longer where required by applicable law.
- Transaction records: retained for at least five (5) years after the transaction, or longer where required.
- Communications: retained for as long as needed for support, dispute resolution, and legal defense.
- Website analytics: retained according to cookie expiration and analytics provider defaults; see the Cookie Policy.
- Marketing data: retained until consent is withdrawn.
Deletion after retention
After the retention period, personal data is securely deleted or anonymized.
Data subject rights
Subject to applicable law, you have the right to:
- Access: obtain confirmation of whether we process your personal data and a copy of that data.
- Rectification: correct inaccurate or incomplete personal data.
- Erasure: request deletion of personal data where the legal basis no longer applies and no overriding obligation requires retention.
- Restriction: restrict processing in certain circumstances.
- Objection: object to processing based on legitimate interests.
- Portability: receive your personal data in a structured, commonly used, machine-readable format.
- Withdraw consent: where processing is based on consent, withdraw consent at any time without affecting prior processing.
- Lodge a complaint: with a supervisory authority in your jurisdiction.
Exercising your rights
To exercise any of these rights, contact [email protected]. We will respond within the timeframes required by applicable law (typically one month).
We may need to verify your identity before processing a rights request to prevent unauthorized disclosure.
Some rights may be limited where exercising them would conflict with our legal obligations (for example, AML retention duties) or with the rights of other persons.
Security
We implement organizational and technical security measures appropriate to the risks of processing, including:
- Encryption in transit (TLS) and at rest where appropriate.
- Access controls, including role-based access for personnel.
- Network segmentation and firewall protection.
- Logging, monitoring, and intrusion detection.
- Regular security reviews.
- Vendor due diligence for subprocessors.
Security limitations
No system is fully secure. We cannot guarantee the absolute security of personal data, but we will notify affected data subjects and supervisory authorities of any breach in accordance with applicable law.
Cookies and similar technologies
We use cookies and similar technologies on the Website. Details on the categories of cookies used, their purposes, retention periods, and how to manage your preferences are described in the Cookie Policy.
Children
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take steps to delete it.
Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Website, by email, or through the dashboard. The "Last updated" date at the top of this Policy reflects the most recent revision.
Contact
Privacy inquiries and rights requests: [email protected]
Data Protection Officer (if appointed): [to be confirmed]
Registered office and entity: [to be inserted before publication]