Privacy Policy
How we collect, use, protect and share your personal information. Last updated: 27 May 2025.
1. Data Controller
AuraTrade AI LLC ("Company", "we", "us", "our"), a Delaware corporation (Entity No. 7284916), is the data controller responsible for your personal data. Our Data Protection Officer (DPO) can be contacted at dpo@auratrad.ai or at The Gherkin, 30 St Mary Axe, Level 28, London EC3A 8BF, United Kingdom.
2. Data We Collect
We collect only the personal data necessary to operate your account and comply with legal obligations:
- Account Data: Email address, username, password hash, account creation date and IP address.
- KYC Documents: Government-issued photo identification, proof of address, and biometric data (facial verification) where required by AML regulations or when your account exceeds defined thresholds.
- Financial Data: Cryptocurrency wallet addresses, transaction history, deposit and withdrawal records. We do not collect or store bank account or credit card details.
- Technical Data: IP address, browser type, device identifiers, operating system, access logs, and session data collected automatically.
- Communications: Support tickets, live chat transcripts, and email correspondence with our team.
- Referral Data: Referral codes used and affiliate relationships for commission tracking.
3. Legal Bases for Processing (GDPR)
For users in the European Economic Area and United Kingdom, we process your data under the following legal bases:
- Contract performance: To provide Platform services and process transactions.
- Legal obligation: To comply with AML, KYC, FATF, FinCEN, and applicable financial regulations.
- Legitimate interests: For fraud prevention, security monitoring, and Platform improvement.
- Consent: For marketing communications (where you have opted in).
4. KYC & AML Data Processing
As required by FinCEN (US) regulations, FATF recommendations, and applicable national AML laws, we process KYC data for the following purposes:
- Identity verification and customer due diligence (CDD/EDD).
- Screening against OFAC, EU, UN, and HMT sanctions lists.
- Suspicious activity monitoring and reporting to Financial Intelligence Units (FIUs).
- Politically Exposed Person (PEP) screening.
KYC and AML records are retained for a minimum of 5 years from the end of the business relationship or last transaction, as required by FATF Recommendation 11 and applicable national legislation. This retention is mandatory and cannot be waived by data deletion requests.
5. Data Security
We implement industry-leading security measures to protect your personal data:
- Encryption at rest: AES-256 encryption for all sensitive data stored in our databases.
- Encryption in transit: TLS 1.3 for all data transmitted between your browser and our servers.
- Access controls: Role-based access control (RBAC) with multi-factor authentication required for all staff accessing personal data.
- Infrastructure security: Hosted on ISO 27001-certified cloud infrastructure with 24/7 intrusion detection and SIEM monitoring.
- Third-party audits: Annual penetration testing by Hacken and CertiK with published results.
- Breach notification: We will notify affected users and relevant supervisory authorities within 72 hours of discovering a personal data breach, in accordance with GDPR Article 33.
6. Data Sharing & Third Parties
We do not sell your personal data. We may share data with:
- KYC providers: Identity verification platforms (e.g., Sumsub, Onfido) subject to data processing agreements.
- Cloud infrastructure: AWS and Cloudflare under EU Standard Contractual Clauses (SCCs) and Data Privacy Framework certification.
- Legal authorities: Law enforcement agencies, financial intelligence units, and regulators where required by applicable law or court order.
- Professional advisors: Legal counsel and auditors under professional confidentiality obligations.
7. International Data Transfers
Your data may be transferred to and processed in countries outside your jurisdiction. Where we transfer personal data from the EEA or UK, we rely on EU Standard Contractual Clauses (SCCs), UK IDTA, or the EU-US Data Privacy Framework as appropriate transfer mechanisms. A copy of our transfer impact assessments is available on request.
8. Cookies & Tracking
We use minimal, strictly necessary cookies for:
- Authentication: Session tokens to keep you securely logged in.
- Security: CSRF tokens and fraud prevention signals.
- Analytics: Anonymised usage analytics via privacy-respecting tools (no Google Analytics). No cross-site tracking or advertising cookies are used.
9. Your Rights
Subject to applicable law and mandatory retention obligations (including AML record-keeping), you have the following rights:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data where no legal obligation requires retention.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent for marketing at any time.
To exercise your rights, contact dpo@auratrad.ai. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (e.g., ICO in the UK, CNIL in France, or relevant US state privacy authority).
10. Data Retention
We retain personal data only for as long as necessary:
- Account data: For the duration of your account plus 2 years after closure.
- KYC/AML records: Minimum 5 years as required by financial regulation.
- Transaction logs: 7 years for tax and audit compliance.
- Support communications: 3 years from the date of the interaction.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified to you by email or a prominent notice on the Platform at least 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.