Slaff GDPR Compliance Policy
Effective Date: 15.11.2024
1. Introduction
This GDPR Compliance Policy outlines how Slaff collects, processes, and protects personal data in accordance with the General Data Protection Regulation (GDPR). By using Slaff’s services, you consent to the processing of your personal data as described in this policy.
2. Scope of the Policy
This policy applies to all users of Slaff’s platform, including individual investors, business partners, and affiliates, whose personal data is processed by Slaff. The policy covers all services, including wallet management, tokenized investments, and referral programs.
3. Data Controller
Slaff is the data controller responsible for determining the purposes and means of processing your personal data. Contact details for Slaff's Data Protection Officer (DPO): Email: info@slaff.io
4. Data Collection
Slaff collects personal data you provide during registration and use of the platform, including:
- Identity Information: Name, date of birth, ID documents.
- Contact Information: Email address, phone number, physical address.
- Financial Information: Bank details, transaction history, investment preferences.
- Technical Data: IP address, device information, and usage analytics.
5. Legal Basis for Data Processing
Slaff processes your personal data based on the following legal grounds:
- Contractual Obligations: To fulfill our agreement with you.
- Legal Compliance: To meet AML, KYC, and other regulatory requirements.
- Legitimate Interests: To improve our services and protect platform security.
- Consent: For marketing communications and other optional services.
6. Data Usage
Your personal data is used for:
- Platform Services: Providing wallet management and investment opportunities.
- Identity Verification: Through KYC/KYB checks.
- Compliance: Ensuring compliance with AML regulations.
- Communications: Sending important updates, transaction confirmations, and promotional offers (if consented).
- Platform Enhancement: Enhancing platform performance and user experience.
7. Data Sharing
Slaff shares your personal data only when necessary:
- Third-party Service Providers: For verification (e.g., SumSub, Onfido), transaction processing, or marketing.
- Regulatory Authorities: To comply with legal obligations.
- Affiliates and Partners: For specific services or promotions.
- With Your Consent: For optional activities like external marketing campaigns.
8. Data Retention
Slaff retains personal data only as long as necessary to fulfill the purposes outlined in this policy or to comply with legal and regulatory obligations. After this period, your data is securely deleted or anonymized.
9. User Rights
Under GDPR, you have the following rights regarding your personal data:
- Access: Request access to the data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request the deletion of your data, subject to regulatory compliance.
- Restriction: Limit how your data is processed.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
To exercise your rights, contact our DPO at dpo@slaff.io.
10. Data Security
Slaff implements robust measures to protect your personal data, including:
- Encryption: Of sensitive information during storage and transmission.
- Access Controls: And two-factor authentication for user accounts.
- Regular Audits: And penetration testing to ensure system integrity.
- Secure Storage: Solutions that comply with GDPR standards.
11. International Data Transfers
Slaff may transfer your data to countries outside the European Economic Area (EEA). These transfers are conducted with appropriate safeguards, such as standard contractual clauses or equivalent legal mechanisms.
12. Cookies and Analytics
Slaff uses cookies to enhance user experience and analyze platform usage. Detailed information about our cookie policy is available on the website. Users can manage cookie preferences through browser settings.
13. Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, Slaff will notify affected users and relevant authorities within 72 hours of becoming aware of the breach.
14. Updates to the Policy
Slaff reserves the right to update this GDPR Compliance Policy. Any significant changes will be communicated via email or platform notifications.