SpeedyX
  • English
  • Español
  • Deutsch
  • Français
About Us Business Personal Payments Fees & Limits Blog Security
Legal

Privacy Policy

This Policy describes how SpeedyX collects, uses, processes, and protects your personal data when you access and use our Platform and Services.

Effective 12 March 2026 · Version 1.0

This Privacy Policy ("Policy") describes how Zentropy Digital Limited ("we", "us", "our") collects, uses, processes, and protects the personal data of users ("you", "your") when you access and use our Platform and Services.

We are committed to protecting your privacy and operating transparently in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable, and all other relevant privacy legislation.

This Policy applies to all users of our website, mobile application, and related services. By using our Platform, you acknowledge that you have read and understood this Policy. Our Platform provides technology access to regulated crypto-asset services performed by a licensed Virtual Asset Service Provider. Identity verification, AML screening, and certain data processing functions are carried out by our regulated service partner and authorised third-party providers. This Policy covers all processing activities relating to your use of our Platform.

1. Data Controller

The data controller for your personal data is: Zentropy Digital Limited, Suite 8800, 61 Bridge Street, Kington, Herefordshire, United Kingdom.

We have assessed our processing activities and determined that the appointment of a Data Protection Officer is not mandatory under applicable law. For all data protection enquiries, please contact us at dp@speedyxchange.com.

2. Personal Data We Collect

We collect the following categories of personal data when you use our Platform:

2.1 Identity and Verification Data

Your full legal name, date of birth, nationality, government-issued identification documents (passport, national ID, driver's licence), photograph, and proof of address. For biometric verification, facial recognition and liveness detection may be used through our KYC provider. Biometric data is processed only for verification and is not permanently stored in raw form.

2.2 Contact and Account Data

Email address, phone number, username, encrypted password, account creation date, and communication preferences.

2.3 Corporate and Business Data (for business accounts)

Company name, registration number, registered address, corporate documents, director and UBO (Ultimate Beneficial Owner) information, shareholding structure, and authorised signatory details.

2.4 Financial and Transaction Data

Deposit and withdrawal records, transaction history, wallet addresses, virtual IBAN and banking details, asset balances, transaction amounts, currencies, counterparty information, and timestamps.

2.5 Compliance and Screening Data

AML/CTF screening results, sanctions screening outcomes, PEP status assessments, adverse media screening results, risk scores and classifications, KYC/KYB verification outcomes, and Travel Rule compliance data.

2.6 Device and Technical Data

Device type, operating system, browser type, IP address (including derived geolocation data), unique device identifiers, access logs, session information, and usage patterns.

2.7 Communications Data

Email correspondence with our support team, support ticket submissions and responses, in-app messages, and complaint records.

2.8 Consent and Preference Data

Records of your consent to our Terms, this Policy, marketing communications, and any withdrawal of consent.

3. How We Collect Your Personal Data

3.1 Directly From You

During account registration, identity verification, transaction initiation, support requests, and any other direct interaction with the Platform.

3.2 Third-Party KYC and Verification Providers

We engage authorised third-party identity verification providers to process your identity documents and biometric data during onboarding. You provide your data directly to the verification provider, who shares verification results with us.

3.3 Blockchain Analytics and Transaction Monitoring

We use blockchain analytics providers to screen wallet addresses and transactions for risk indicators, sanctions exposure, and suspicious activity. These providers analyse publicly available blockchain data.

3.4 Banking and EMI Partners

When you make fiat deposits, withdrawals, or payments through banking partners, those partners share transaction confirmation data and limited personal data required to process your instructions.

3.5 Public Databases and Regulatory Sources

We screen your information against publicly available and commercially licensed sanctions lists, PEP databases, adverse media sources, and other compliance databases as required by AML/CTF law.

3.6 Automated Collection

Technical data about your device and usage is collected automatically through cookies, pixels, and similar technologies when you access the Platform.

4. Purposes and Legal Basis for Processing

PurposeData UsedLegal Basis (GDPR)
Account creation and service deliveryIdentity, contact, account dataContract (Art. 6(1)(b))
Identity verification (KYC/KYB)Identity, biometric, corporate dataLegal obligation (Art. 6(1)(c)) + substantial public interest (Art. 9(2)(g))
AML/CTF screening and monitoringCompliance, transaction, screening dataLegal obligation (Art. 6(1)(c))
Sanctions and PEP screeningIdentity, compliance dataLegal obligation (Art. 6(1)(c))
Transaction processingFinancial, transaction dataContract (Art. 6(1)(b))
Fraud prevention and securityDevice, transaction, usage dataLegitimate interests (Art. 6(1)(f))
Legal and regulatory complianceAll relevant categoriesLegal obligation (Art. 6(1)(c))
Customer supportContact, communications dataContract / Legitimate interests
Platform improvement and analyticsDevice, usage dataLegitimate interests (Art. 6(1)(f))
Marketing (with consent only)Contact, preference dataConsent (Art. 6(1)(a))

5. Data Sharing and Recipients

We share your personal data with the following categories of recipients, in each case only to the extent necessary:

5.1 Regulated Service Partner

Our licensed Virtual Asset Service Provider partner receives your identity, transaction, and compliance data to perform regulated functions including custody, execution, AML review, and Travel Rule compliance. This partner is bound by applicable data protection law and our contractual agreements.

5.2 KYC/AML Verification Providers

Third-party identity verification and AML screening providers receive your identity and compliance data to perform verification services on our behalf.

5.3 Banking and EMI Partners

Banking and electronic money institution partners receive limited personal and transaction data necessary to process fiat deposits, withdrawals, and settlements.

5.4 Competent Authorities and Regulators

We may disclose your personal data to law enforcement agencies, financial intelligence units, supervisory authorities, courts, or other governmental bodies where required or permitted by applicable law.

5.5 Legal and Professional Advisors

We may share personal data with our lawyers, auditors, and professional advisors where necessary to protect our legal rights or comply with our obligations.

5.6 Corporate Transactions

In the event of a merger, acquisition, corporate restructuring, or similar transaction, your personal data may be transferred to a successor entity.

We do not sell, rent, or otherwise commercially disclose your personal data to third parties for their own marketing or commercial purposes.

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside your home jurisdiction, including countries that may have different data protection standards. Where such transfers occur, we ensure that appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) for transfers from the EEA;
  • UK International Data Transfer Addendum where applicable;
  • Adequacy decisions recognised by the European Commission or applicable authority; or
  • Other legally recognised transfer mechanisms under applicable data protection law.

Transfer Impact Assessments are conducted as required to evaluate the adequacy of protection in destination countries.

7. Data Retention

Data CategoryRetention Period
KYC/KYB and AML records8–10 years after account closure (as required by AML law)
Transaction records10 years (regulatory and accounting requirement)
Account and identity dataDuration of account plus 8 years
Communications and support dataUp to 24 months unless needed for disputes or legal proceedings
Device and usage data12 months (extended for fraud/security investigations)
Marketing preference data24 months from last interaction or opt-out
Legal hold dataAs long as required by law, litigation, or regulatory inquiry

8. Your Rights

Subject to applicable law, you have the following rights in respect of your personal data:

  • Right of Access — to obtain a copy of your personal data held by us;
  • Right to Rectification — to request correction of inaccurate or incomplete data;
  • Right to Erasure — to request deletion of your data, subject to legal retention obligations;
  • Right to Restriction — to request that we limit processing while a dispute is under review;
  • Right to Portability — to receive your data in a structured, machine-readable format;
  • Right to Object — to object to processing based on legitimate interests or for direct marketing;
  • Right to Withdraw Consent — where processing is based on consent, to withdraw it at any time; and
  • Right to Lodge a Complaint — with your local supervisory authority.

To exercise any of these rights, please contact us at: dp@speedyxchange.com. We will respond within 30 days. We may require identity verification before acting on your request.

Please note that certain rights may be limited or unavailable where processing is required by law, for example where records must be retained under AML/CTF legislation.

9. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS) and at rest;
  • Multi-factor authentication for account access;
  • Role-based access controls limiting data access to authorised personnel;
  • Regular security assessments and penetration testing;
  • Audit logging and monitoring of system access;
  • Staff training on data protection and security; and
  • Data protection by design and by default principles embedded in our systems.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities in accordance with applicable law.

10. Cookies

We use cookies and similar tracking technologies to enable core Platform functionality, maintain session security, and analyse usage patterns. We use:

  • Strictly necessary cookies required for the Platform to function;
  • Performance and analytics cookies to understand how users interact with our Platform; and
  • Functional cookies to remember your preferences.

You can control cookies through your browser settings. Disabling certain cookies may limit access to some Platform features. You will be asked for your consent to non-essential cookies when you first visit our Platform via our cookie consent banner. See our Cookies Notice for more detail.

11. Children

Our Platform is not directed at children under the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that personal data of a minor has been collected, we will delete it promptly. If you believe we have inadvertently collected data from a minor, please contact us immediately.

12. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, regulatory requirements, or other factors. We will notify you of material changes via email or prominent notice on the Platform. Your continued use of the Platform after the effective date of any update constitutes acceptance of the updated Policy.

13. Contact Us

For any questions, concerns, or requests regarding this Policy, please contact us at:

Legal Name: Zentropy Digital Limited
Address: Suite 8800, 61 Bridge Street, Kington, Herefordshire, United Kingdom
Email: dp@speedyxchange.com