Legal & Compliance

Terms of ServicePrivacy PolicyAML & KYC PolicyDispute ResolutionFee ScheduleRestricted JurisdictionsCookie Policy

Compliance contact

For legal inquiries:

legal@peermarkt.com
compliance@peermarkt.com

Privacy Policy

Global — GDPR, NDPR, POPIA, CNDP Compliant

Version

1.0

Effective date

1 January 2025

Last updated

1 January 2025

1. Introduction & Data Controller

This Privacy Policy explains how $PeerMarkt("Company," "we," "us") collects, uses, stores, and shares personal data when you use our Platform. This Policy applies globally and is designed to comply with the EU General Data Protection Regulation (GDPR), UK GDPR, Nigeria Data Protection Regulation (NDPR 2019 / NDPA 2023), South Africa Protection of Personal Information Act (POPIA), Morocco Law 09-08 (CNDP), Kenya Data Protection Act 2019, and the California Consumer Privacy Act (CCPA/CPRA).

Data Controller: $PeerMarkt Operating Entity | DPO Contact:privacy@peermarkt.com | EU Representative: [EU Entity] | UK Representative: [UK Entity]

2. Data We Collect

2.1 Account Registration Data

DataPurposeLegal Basis
Full legal nameAccount creation, KYCContract (GDPR Art. 6(1)(b))
Email addressAccount managementContract (GDPR Art. 6(1)(b))
Phone numberSecurity, 2FA, trade alertsLegitimate interests
Date of birthAge verification, KYCLegal obligation (Art. 6(1)(c))
Country of residenceSanctions screeningLegal obligation
Password (hashed, bcrypt)AuthenticationContract

2.2 KYC / Identity Verification Data

DataPurposeBasis
Government-issued IDIdentity verification (AML law)Legal obligation
NIN (Nigeria)AML/KYC per SEC/CBN requirementsLegal obligation
Ghana CardAML/KYC per BoG requirementsLegal obligation
CNI (Morocco/Ivory Coast)AML/KYC per local lawLegal obligation
Selfie / liveness checkLiveness verification (biometric)Legal obligation + consent
Source of fundsAML risk assessmentLegal obligation
Proof of addressAddress verificationLegal obligation

Biometric data (facial recognition) constitutes Special Category Data under GDPR Article 9, processed under Article 9(2)(g) (substantial public interest for AML compliance). Where technically feasible, we store a cryptographic hash of identity documents rather than raw images to minimize data exposure.

2.3 Transaction Data

DataPurposeBasis
Trade historyPlatform operation, dispute resolutionContract
Cryptocurrency wallet addressesTransaction execution, Travel RuleLegal obligation
Payment proof documentsDispute resolutionContract + Legitimate interests
Transaction amountsFee calculation, tax reportingLegal obligation
Blockchain transaction dataCompliance analyticsLegal obligation

2.4 Technical & Device Data

DataPurposeBasis
IP addressFraud prevention, geo-restrictionLegitimate interests
Device fingerprintFraud detection, SIM-swap preventionLegitimate interests
Browser / OSPlatform compatibilityLegitimate interests
Access logsSecurity monitoring, audit trailLegal obligation

3. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract performance (GDPR Art. 6(1)(b)) — account operation, trade execution, fee processing
  • Legal obligation (GDPR Art. 6(1)(c)) — KYC, AML compliance, sanctions screening, tax reporting, record retention
  • Legitimate interests (GDPR Art. 6(1)(f)) — fraud prevention, platform security, service improvement
  • Consent (GDPR Art. 6(1)(a)) — marketing communications, optional enhanced features (withdrawable)

4. Data Retention

Data CategoryRetention PeriodBasis
Account dataDuration of account + 5 years post-closureAML record-keeping
KYC documents5 years from account closure or last tradeFATF Rec. 11; local AML law
Transaction records5 years from transaction dateAML / Tax law
Biometric data90 days post-verification (result kept 5 yrs)Proportionality; AML
IP / access logs12 monthsSecurity; proportionality
Support communications3 yearsLegitimate interests
Deleted account data5 years in archived/anonymized formLegal obligation

After applicable retention periods, data is securely deleted using NIST 800-88 guidelines or irreversibly anonymized. Anonymized data may be retained indefinitely for analytical purposes.

5. Data Sharing

5.1 Third-Party Processors

RecipientPurposeLocationSafeguard
Smile ID / SumsubKYC verificationAfrica / EUDPA + SCCs
Chainalysis / TRMBlockchain screeningUSSCCs
VercelPlatform hostingUS / EUSCCs + DPA
SupabaseDatabaseUS / EUSCCs + DPA
ResendTransactional emailUSSCCs
TwilioSMS / WhatsApp alertsUSSCCs + DPA
SentryError monitoringUSSCCs

5.2 Legal & Regulatory Disclosure

We disclose personal data without prior notice where required by court order, subpoena, or lawful request from law enforcement or regulatory authorities (EFCC, NFIU, SARB, FIC, AMRF-CI, CENTIF, BAM, CMA, or other competent bodies). AML/CTF reporting (SAR/STR filings) are subject to the tipping off prohibition — we cannot notify you if a suspicious activity report has been filed.

6. International Data Transfers

For transfers of personal data outside the originating jurisdiction:

  • EU/EEA to third countries: Standard Contractual Clauses (SCCs) — Commission Decision 2021/914
  • UK transfers: International Data Transfer Agreements (IDTA)
  • Nigeria (NDPR): Personal data transferred abroad only where the receiving country has adequate protections or Nigerian Data Protection Commission (NDPC) approved mechanisms are in place
  • South Africa (POPIA): Cross-border transfers only to countries providing comparable protection per POPIA Section 72, or subject to binding contractual obligations
  • Morocco (CNDP / Law 09-08): Cross-border transfers require prior authorization from CNDP or be to a country with equivalent protection. Sensitive KYC data is stored on servers within Morocco or the EU where feasible
  • Kenya: Transfers comply with Data Protection (General) Regulations 2021 requirements

7. Your Rights

RightDescriptionHow to Exercise
AccessReceive a copy of your personal dataprivacy@peermarkt.com
RectificationCorrect inaccurate dataAccount settings or request
ErasureDelete data where no legal obligation to retainprivacy@peermarkt.com
RestrictionRestrict processing while dispute is pendingprivacy@peermarkt.com
PortabilityReceive data in machine-readable formatprivacy@peermarkt.com
ObjectObject to processing based on legitimate interestsprivacy@peermarkt.com
Automated decisionsRequest human review of automated KYC decisionscompliance@peermarkt.com

We cannot delete data we are legally required to retain for AML, sanctions, or tax compliance. In such cases we will inform you of the limitation and restrict processing to the minimum required by law.

Response timeframe: 30 days from receipt of request (extendable by 60 days for complex requests). Supervisory authority complaints: EU (national DPA), UK (ICO ico.org.uk), Nigeria (NDPC), South Africa (Information Regulator), Morocco (CNDP), Kenya (ODPC).

8. Data Security

  • AES-256 encryption for sensitive data at rest including KYC documents and PII fields
  • TLS 1.3 for all data in transit
  • Role-based access controls — minimum necessary access principle
  • Multi-factor authentication required for all staff accessing personal data
  • Regular penetration testing and security assessments
  • Incident response plan — breaches notified to supervisory authority within 72 hours (GDPR) / 72 hours (NDPR) / as required by applicable law
  • Staff data protection training — annual, mandatory

9. Africa-Specific Provisions

9.1 Nigeria (NDPR / NDPA 2023)

We comply with the Nigeria Data Protection Act 2023 and NDPR 2019. We are registered as a Data Controller with the Nigeria Data Protection Commission (NDPC) where required. Nigerian users have all rights under NDPA Section 34, including the right to lodge a complaint with the NDPC at ndpc.gov.ng.

9.2 South Africa (POPIA)

We comply with the Protection of Personal Information Act 4 of 2013 (POPIA). Our Information Officer is responsible for ensuring POPIA compliance. South African users may lodge complaints with the Information Regulator at inforeg.org.za. We do not process Special Personal Information without the explicit consent of the data subject unless otherwise permitted by POPIA.

9.3 Morocco (CNDP / Law 09-08)

We are registered with the Commission Nationale de contrôle de la Protection des Données à caractère personnel (CNDP) under registration number [Number]. Moroccan users have rights of access, rectification, and deletion under Law 09-08. KYC data of Moroccan residents is stored in the EU or Morocco in accordance with CNDP transfer requirements. Cross-border transfers require CNDP authorization or adequacy determination.

9.4 Kenya (DPA 2019)

We comply with the Data Protection Act 2019 and Data Protection (General) Regulations 2021. Kenyan users may lodge complaints with the Office of the Data Protection Commissioner (ODPC).

10. California Privacy Rights (CCPA/CPRA)

WE DO NOT SELL YOUR PERSONAL INFORMATION. WE DO NOT SHARE YOUR PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING.

California residents have additional rights under CCPA/CPRA:

  • Right to Know: What personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion (subject to legal retention obligations)
  • Right to Correct: Correct inaccurate personal information
  • Right to Non-Discrimination: We will not discriminate for exercising CCPA rights
  • Right to Limit Sensitive PI Use: We use sensitive personal information only for AML compliance — not for inferring characteristics

To exercise California rights, contact privacy@peermarkt.com. We verify identity before processing requests. Response within 45 days (extendable by 45 days).

11. Children's Privacy

The Platform is not directed to children under 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact privacy@peermarkt.com and we will promptly delete it.

12. Changes to This Policy

We notify you of material changes via email 30 days before the effective date. For minor changes, we update the "Last Updated" date and post notice on the Platform. Continued use after the effective date constitutes acceptance of the revised Policy.

On this page

1. Introduction & Controller2. Data We Collect3. Legal Basis for Processing4. Data Retention5. Data Sharing6. International Transfers7. Your Rights8. Data Security9. Africa-Specific Provisions10. California (CCPA/CPRA)11. Children's Privacy12. Changes to This Policy
peermarkt

Peer power unleashed. The world's first publicly-controlled crypto exchange combining decentralized freedom with institutional-grade security.

Legal

  • Terms & Conditions
  • Privacy Policy
  • Dispute Resolution
  • Fees

Company

  • About Us
  • Why PeerMarkt
  • Become a Merchant
  • Join Waitlist

Support

  • Help Center
  • FAQ
  • Learn to Trade
  • Report a Bug
© 2026 PeerMarkt. Engineered for the future of finance.
AML PolicyRisk DisclosurePrivacy PolicyCookie Policy