Privacy Policy
This Policy describes what personal data ASIRU LIMITED (Hong Kong, registration number 80997831, address: Room 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong; the “Operator”, “we”) collects when you use the ASIRU service at asirucapital.com, for what purposes and on what legal bases, with whom it is shared, how long it is kept and what rights you have.
1. Operator and contacts
1.1. The data controller is ASIRU LIMITED. For questions about personal data processing and to exercise your rights contact: george@asiru.capital (Compliance Officer) or noreply@asirucapital.com (support).
2. Applicable law
2.1. Processing is carried out in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong. For users in the European Union we follow the General Data Protection Regulation (GDPR); for citizens of the Russian Federation — Federal Law No. 152-FZ “On Personal Data”, including the data localisation requirement (see section 6).
3. What data we collect
- Order data: exchange direction and amount, payout details (wallet address, phone number, bank details), e-mail address, Telegram username.
- Account data: e-mail address, password (hashed), order and balance history.
- Verification data (KYC): full name, citizenship, date of birth, phone number, residential and/or registered address, images of the identity document, selfie and visual/video verification materials.
- Entity verification data (KYB): registration details, information on directors, representatives, ownership structure and beneficial owners, documents confirming authority.
- Source of funds data: documents and explanations confirming Source of Funds / Source of Wealth — where risk factors are present.
- Transaction data: blockchain addresses and transaction hashes, AML/KYT analysis results and risk scores.
- Technical data: IP address, browser and device data, time of visit, cookies, referral source.
- Correspondence with support by e-mail.
4. Purposes and legal bases
- performance of the exchange agreement (creating, executing and supporting orders, payouts, refunds, support);
- compliance with anti-money laundering and counter-terrorist financing legislation, including identification, verification, sanctions and PEP screening, transaction monitoring, record keeping and reporting to competent authorities;
- security of the service, prevention of fraud and abuse;
- operation of the account and the partner programme;
- service improvement and traffic analytics (based on consent to cookies/analytics);
- communication with the user regarding their order or request.
5. Who receives the data
5.1. We do not sell personal data and do not use it for third-party advertising. Data is shared only with the following categories of recipients:
- AML/KYT blockchain analytics providers — in particular Crystal and other specialised providers; they receive addresses and transaction hashes;
- KYC/KYB providers and aggregators — for automated identification and verification, sanctions and PEP screening;
- payment providers, banks and blockchain infrastructure — to the extent necessary to pay out an order;
- infrastructure providers: hosting, cloud storage, e-mail, notification services;
- analytics services (Google Analytics) — anonymised technical data, with your consent;
- competent public authorities, including the Joint Financial Intelligence Unit (JFIU) of Hong Kong — where legally required, including without notifying the user.
5.2. All processors are bound by agreements limiting the use of data to the purposes stated in this Policy.
6. Cross-border transfer and storage location
6.1. The Operator is incorporated in Hong Kong; data may be processed in Hong Kong and in the jurisdictions of the providers listed in section 5, with appropriate safeguards.
6.2. Personal data of citizens of the Russian Federation is recorded, systematised, accumulated, stored, updated and retrieved using databases located in the Russian Federation. In particular, the Russian cloud service Yandex Disk is used for storage.
7. Retention
- data obtained in KYC/KYB, AML checks and source-of-funds checks, including check results — at least 5 years after the relationship with the user ends;
- order and transaction data — at least 5 years after execution of the order;
- account data — for the life of the account and thereafter within the periods above;
- technical logs and cookies — up to 12 months, unless a longer period is required to investigate an incident.
After these periods data is deleted or anonymised.
8. Security
8.1. Verification data is stored encrypted; access is restricted to authorised staff to the extent of their duties. Access control, logging, backups and encrypted transport are applied. Staff involved in processing receive internal training on data protection and AML/KYC.
9. Your rights
9.1. You may request access to your data, its correction, erasure, restriction of processing, and withdraw consent by writing to george@asiru.capital. We respond within 30 days. Withdrawal of consent does not apply to data whose retention is required by anti-money laundering legislation for the statutory period.
9.2. Users in the EU may lodge a complaint with their national supervisory authority; users in Hong Kong — with the Office of the Privacy Commissioner for Personal Data.
10. Cookies and analytics
10.1. The Site uses cookies for the session, remembering language and settings and, with your consent, for traffic analytics (Google Analytics). You can disable cookies in your browser; some features may then be unavailable. Data processing by analytics services is governed by their own policies.
11. Minors
11.1. The Service is intended only for persons over 18. We do not knowingly collect data of minors; if you become aware of such processing, let us know and the data will be deleted.
12. Links to other sites
12.1. The Site may contain links to third-party resources; we are not responsible for their content or data practices.
13. Changes to this Policy
13.1. We may update this Policy; the current version is always published on this page. Continued use of the service after publication constitutes acceptance of the changes.