This Policy describes how SpeedyX collects, uses, processes, and protects your personal data when you access and use our Platform and Services.
Effective 12 March 2026 · Version 1.0
This Privacy Policy ("Policy") describes how Zentropy Digital Limited ("we", "us", "our") collects, uses, processes, and protects the personal data of users ("you", "your") when you access and use our Platform and Services.
We are committed to protecting your privacy and operating transparently in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable, and all other relevant privacy legislation.
This Policy applies to all users of our website, mobile application, and related services. By using our Platform, you acknowledge that you have read and understood this Policy. Our Platform provides technology access to regulated crypto-asset services performed by a licensed Virtual Asset Service Provider. Identity verification, AML screening, and certain data processing functions are carried out by our regulated service partner and authorised third-party providers. This Policy covers all processing activities relating to your use of our Platform.
The data controller for your personal data is: Zentropy Digital Limited, Suite 8800, 61 Bridge Street, Kington, Herefordshire, United Kingdom.
We have assessed our processing activities and determined that the appointment of a Data Protection Officer is not mandatory under applicable law. For all data protection enquiries, please contact us at dp@speedyxchange.com.
We collect the following categories of personal data when you use our Platform:
Your full legal name, date of birth, nationality, government-issued identification documents (passport, national ID, driver's licence), photograph, and proof of address. For biometric verification, facial recognition and liveness detection may be used through our KYC provider. Biometric data is processed only for verification and is not permanently stored in raw form.
Email address, phone number, username, encrypted password, account creation date, and communication preferences.
Company name, registration number, registered address, corporate documents, director and UBO (Ultimate Beneficial Owner) information, shareholding structure, and authorised signatory details.
Deposit and withdrawal records, transaction history, wallet addresses, virtual IBAN and banking details, asset balances, transaction amounts, currencies, counterparty information, and timestamps.
AML/CTF screening results, sanctions screening outcomes, PEP status assessments, adverse media screening results, risk scores and classifications, KYC/KYB verification outcomes, and Travel Rule compliance data.
Device type, operating system, browser type, IP address (including derived geolocation data), unique device identifiers, access logs, session information, and usage patterns.
Email correspondence with our support team, support ticket submissions and responses, in-app messages, and complaint records.
Records of your consent to our Terms, this Policy, marketing communications, and any withdrawal of consent.
During account registration, identity verification, transaction initiation, support requests, and any other direct interaction with the Platform.
We engage authorised third-party identity verification providers to process your identity documents and biometric data during onboarding. You provide your data directly to the verification provider, who shares verification results with us.
We use blockchain analytics providers to screen wallet addresses and transactions for risk indicators, sanctions exposure, and suspicious activity. These providers analyse publicly available blockchain data.
When you make fiat deposits, withdrawals, or payments through banking partners, those partners share transaction confirmation data and limited personal data required to process your instructions.
We screen your information against publicly available and commercially licensed sanctions lists, PEP databases, adverse media sources, and other compliance databases as required by AML/CTF law.
Technical data about your device and usage is collected automatically through cookies, pixels, and similar technologies when you access the Platform.
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Account creation and service delivery | Identity, contact, account data | Contract (Art. 6(1)(b)) |
| Identity verification (KYC/KYB) | Identity, biometric, corporate data | Legal obligation (Art. 6(1)(c)) + substantial public interest (Art. 9(2)(g)) |
| AML/CTF screening and monitoring | Compliance, transaction, screening data | Legal obligation (Art. 6(1)(c)) |
| Sanctions and PEP screening | Identity, compliance data | Legal obligation (Art. 6(1)(c)) |
| Transaction processing | Financial, transaction data | Contract (Art. 6(1)(b)) |
| Fraud prevention and security | Device, transaction, usage data | Legitimate interests (Art. 6(1)(f)) |
| Legal and regulatory compliance | All relevant categories | Legal obligation (Art. 6(1)(c)) |
| Customer support | Contact, communications data | Contract / Legitimate interests |
| Platform improvement and analytics | Device, usage data | Legitimate interests (Art. 6(1)(f)) |
| Marketing (with consent only) | Contact, preference data | Consent (Art. 6(1)(a)) |
Your personal data may be transferred to and processed in countries outside your home jurisdiction, including countries that may have different data protection standards. Where such transfers occur, we ensure that appropriate safeguards are in place, including:
Transfer Impact Assessments are conducted as required to evaluate the adequacy of protection in destination countries.
| Data Category | Retention Period |
|---|---|
| KYC/KYB and AML records | 8–10 years after account closure (as required by AML law) |
| Transaction records | 10 years (regulatory and accounting requirement) |
| Account and identity data | Duration of account plus 8 years |
| Communications and support data | Up to 24 months unless needed for disputes or legal proceedings |
| Device and usage data | 12 months (extended for fraud/security investigations) |
| Marketing preference data | 24 months from last interaction or opt-out |
| Legal hold data | As long as required by law, litigation, or regulatory inquiry |
Subject to applicable law, you have the following rights in respect of your personal data:
To exercise any of these rights, please contact us at: dp@speedyxchange.com. We will respond within 30 days. We may require identity verification before acting on your request.
Please note that certain rights may be limited or unavailable where processing is required by law, for example where records must be retained under AML/CTF legislation.
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities in accordance with applicable law.
Our Platform is not directed at children under the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that personal data of a minor has been collected, we will delete it promptly. If you believe we have inadvertently collected data from a minor, please contact us immediately.
We may update this Policy from time to time to reflect changes in our practices, technology, regulatory requirements, or other factors. We will notify you of material changes via email or prominent notice on the Platform. Your continued use of the Platform after the effective date of any update constitutes acceptance of the updated Policy.
For any questions, concerns, or requests regarding this Policy, please contact us at:
Legal Name: Zentropy Digital Limited
Address: Suite 8800, 61 Bridge Street, Kington, Herefordshire, United Kingdom
Email: dp@speedyxchange.com