Privacy

Last Updated: [30.10.2025]


1. Introduction


Welcome to OneWallet. This Privacy Policy governs the privacy relationship between you (“Client” or “you”) and OneWallet, including its holding company, subsidiaries, and affiliated entities (“OneWallet,” “we,” “us,” or “our”). It explains how we collect, use, store, share, and protect your personal data when you access or use our website, mobile applications, APIs, third-party applications relying on our API (together, the “Apps”), or any other official OneWallet communication channel (together, the “Services”).


This Privacy Policy is a legally binding agreement between you and OneWallet. We encourage you to read it carefully to understand how your data is used and protected. It is updated regularly to account for new services, updates, or changes in our business practices. Material changes will be communicated via notices on our platform, in-app notifications, or email. Continued use of OneWallet after updates constitutes acceptance of changes.


Unless stated otherwise, references in this policy relate to OneWallet’s Terms of Service, Cookie Policy, Chat Terms, and any other applicable terms governing the Services (collectively, “OneWallet General Terms”).


2. Definitions


  • Controller: Any entity within the OneWallet group acting as a personal data controller.

  • Processor: Any natural or legal person, authority, or body processing personal data on behalf of a Controller.

  • Personal Data: Any information relating to an identifiable natural person (“Data Subject”).

  • Privacy Laws: Applicable laws regarding personal data protection, including GDPR.

  • Processing: Any operation performed on Personal Data, including collection, storage, use, and deletion.


3. Information We Collect3.1 Client-Provided Information


We collect personal information you provide when registering or using our Services:


  • Identification information: Full name, date and place of birth, nationality, tax ID, copies of ID or passport, gender, PEP status, sanctions status.

  • Contact information: Address, email, phone number, social media handles, messages with our support team.

  • Employment and financial information: Occupation, source of funds, bank account, digital wallet information, assets on OneWallet.

  • Biometric data: Data derived from ID documents and photos for identity verification.

  • Voluntary data: Any additional data you provide through chat or other communications.


3.2 Information Collected Automatically


When you access our Apps:


  • Device and browser info: IP address, device type, OS, browser, device identifiers.

  • Service usage data: Activity logs, viewed content, app interactions, diagnostic info.

  • Cookies and similar technologies: For functionality, analytics, and personalization.


3.3 Information from Third Parties


We may receive personal data from:


  • Financial institutions: Banks providing transfers, account numbers, transaction data.

  • Card-issuing partners: Transaction records, fraud indicators.

  • Compliance and risk providers: Identity verification, AML, sanctions, fraud checks.

  • Public sources: Blockchain data, publicly accessible information.


Failure to provide requested Personal Data may prevent OneWallet from delivering certain services or fulfilling legal obligations.


4. Purposes and Legal Basis for Processing


We process Personal Data to provide our Services legally and transparently, under the following bases:


Purpose

Legal Basis

Data Category

Identity & Verification

Performance of Contract, Legal Obligation

ID info, Biometric data

Provision of Services

Performance of Contract

ID info, Contact info, Financial info

Service Functionality & Improvement

Legitimate Interests

Technical/usage data

Personalization

Legitimate Interests / Consent

Contact info, Financial info

Legal & Regulatory Compliance

Legal Obligation

ID info, Contact info, Financial info

Fraud & Security Monitoring

Legal Obligation / Legitimate Interests

ID info, Financial info, Contact info

Communications

Performance of Contract / Legitimate Interests

Contact info

Marketing

Consent

Contact info, Technical/usage data

Consent-Based Purposes

Consent

Depends on consent

Other Compatible Uses

Legal Obligation / Legitimate Interests

Depends on purpose


5. Automated Decision Making and Profiling


OneWallet may use automated systems for:


  • Identity verification

  • Account approval

  • Fraud and AML monitoring

  • Credit or digital asset lending decisions

  • Personalized recommendations


Data used may include client-provided info, usage data, or derived/inferred data. You have the right to contest automated decisions or request human intervention where legally applicable.


6. Sharing Personal Data with Third Parties


We may share Personal Data lawfully and with safeguards with:


  • Banking & payment partners

  • Compliance & risk providers

  • Card-issuing partners

  • AI or chat technology providers

  • Auditors, consultants, legal, or tax advisors

  • Marketing platforms (with consent)

  • Regulators, courts, and law enforcement authorities


Third parties may act as independent controllers and are responsible for their own privacy compliance. External links may collect data; we encourage review of their privacy policies.


7. International Transfers


Your data may be stored, processed, or transferred internationally. We use safeguards such as adequacy decisions or standard contractual clauses (SCCs) to ensure protection. Contact our Data Protection Officer for details.


8. Direct Marketing


We may send updates and promotions about OneWallet Services via email, push notifications, or other channels. You may opt out anytime via unsubscribe links or by contacting our DPO. Opting out places you on a suppression list, except if you opt back in.


9. Data Security


We implement technical and organizational measures:


  • ISO/IEC 27001 and SOC 2 Type 2 certified

  • 256-bit encryption

  • Firewalls, malware scanning, continuous monitoring

  • Access limited to authorized personnel

  • Confidentiality and regular training


Clients must keep account credentials secure; OneWallet will never ask for passwords or authentication codes.


10. Storage and Retention


We retain Personal Data only as long as necessary for:


  • Legal or regulatory compliance (typically 5+ years for AML)

  • Contractual purposes (account and transaction data)

  • Marketing suppression

  • Fraud prevention and operational needs


Data may be anonymized or securely deleted when no longer needed.


11. Your Rights


Under applicable Privacy Laws, you have the right to:


  • Access, correct, or delete your data

  • Restrict or object to processing

  • Data portability

  • Withdraw consent

  • Challenge automated decisions

  • Lodge a complaint with a data protection authority


Identity verification may be required before processing requests.


12. Children’s Privacy


OneWallet Services are not for individuals under 18. If we discover data from a child, it will be deleted, and the account closed. Parents/guardians can contact our DPO for assistance.


13. Contact Information


Data Protection Officer (DPO)
Email: dpo@onewallet.com
Address: [Insert address]


Provide full name, preferred communication method, country, type of request, and detailed description to help us respond efficiently.


14. Miscellaneous


OneWallet Services may not be available in all jurisdictions. Information about digital assets is for general informational purposes and does not constitute financial, tax, or legal advice. All investments carry risks, and past performance is not indicative of future results.