Privacy Policy
1. Who we are and what this policy covers
This Privacy Policy (this “Policy”) explains how Lisk Ltd, Offices of TMF (Cayman) Ltd, 4th Floor, Monaco Towers, 11 Dr. Roy's Drive, P.O. Box 10338, Grand Cayman KY1-1003, Cayman Islands, with company number 432683 (“Company”, “we”, “us”, or “our”), collects, uses, discloses and protects personal data in connection with: (a) our proprietary software platform, user interface, dashboards, APIs, mobile apps and related technology (the “Platform”); (b) our websites and web applications (the “Site”); and (c) our related business operations, including onboarding, support and marketing. It also explains the cookies and similar technologies we use (see Section 17, which forms our cookies policy).
The Platform is a business-to-business, non-custodial software orchestration layer through which business clients (each a “Client”) access regulated financial services provided by third-party regulated service providers (each a “Regulated Service Provider”), and other services as may be available by the Platform. The Company is a technology provider only; it does not provide banking, payment, custody, exchange or other regulated financial or crypto-asset services, does not hold or control private keys to Client wallets, and does not custody Client funds or digital assets.
This Policy applies to personal data of individuals connected with our Clients and prospective Clients, such as directors, beneficial owners, authorised users and other personnel (“Users”), and of visitors to the Site. Capitalised terms not defined in this Policy have the meanings given in our Terms of Service (the “Terms”).
Controller. For the personal data described in this Policy, the Company acts as a controller, meaning that it determines the purposes and means of the processing, except where this Policy states otherwise. Each Regulated Service Provider is a separate, independent controller of the personal data it processes to provide its own services (see Section 6).
Applicable standards. We handle personal data in accordance with the Cayman Islands Data Protection Act (as revised) and, where it applies to our processing of personal data of individuals located in the European Economic Area, in alignment with Regulation (EU) 2016/679 (“GDPR”). Where this Policy refers to a legal basis, it refers to the corresponding basis under these laws.
Contact. Questions, requests and complaints regarding this Policy or our handling of personal data may be directed to legal@lisk.com. We have not appointed a statutory data protection officer, as we are not required to do so; the contact above handles all data protection matters.
2. This Policy and the Terms
This Policy should be read together with the Terms, into which it is incorporated. Where the Terms describe our data-related rights and obligations, this Policy provides the corresponding privacy notice. Your use of the Regulated Services is separately governed by the privacy policy of the applicable Regulated Service Provider, which you accept when you accept the applicable Provider Terms.
3. Personal data we collect
- Account and registration data. Name, business email address, telephone number, job title, organisation and role, authentication identifiers and credentials (managed through our authentication provider), and account settings of Users.
- Onboarding and verification data. Information and documentation submitted through the Platform's onboarding interface to enable the applicable Regulated Service Provider to verify the Client and its personnel: the identity of directors, beneficial owners and Users (including name, date of birth, nationality, residential address, identification document details and copies); and information on the nature and purpose of the Client's intended use. As described in Section 6, this data is collected for transmission to the applicable Regulated Service Provider, which performs the verification.
- Wallet and transaction data. Wallet addresses, public keys, transaction identifiers, amounts, counterparty addresses, timestamps and related metadata, including data recorded on public blockchain networks and data concerning Orders and Transactions initiated through the Platform. We never collect or store your private keys or recovery credentials, which are generated and controlled through third-party wallet infrastructure such that you, and not the Company, control the wallet.
- Usage, device and technical data. IP address, device and browser type, operating system, device identifiers, user e-mail and role, push notification tokens, log-in records, pages viewed, features used, interaction events, session information, timestamps, technical logs and error and diagnostic data (with personal identifiers redacted before transmission to our error-monitoring provider).
- Communications and support data. The content of your communications with us, including support requests, complaints, messages entered into the support chat widget on the Site or Platform, and email correspondence, together with related contact details and metadata.
- Marketing and prospect data. Business contact details of prospective Clients and their personnel, records of marketing preferences, and engagement with our communications and Site.
Special categories and criminal offence data. We do not intentionally collect special category personal data. We do not request data relating to criminal convictions or offences; however, such data may be received or revealed incidentally in the course of onboarding, our screening against Sanctions Lists and publicly available sources, or information you or your organisation choose to provide, and where this occurs we process it only to the extent necessary for the financial crime prevention purposes described in Section 5 and as permitted by Applicable Law. Identification documents transmitted during onboarding may incidentally reveal certain information (for example, a photograph); any biometric or enhanced verification is performed by the applicable Regulated Service Provider under its own privacy policy, not by us. You must not submit special category personal data through the Platform except where expressly requested through the onboarding interface, consistent with the Terms. If you believe you have accidentally submitted special category personal data, please contact us at the details in Section 1 so that we can take appropriate steps.
Aggregated data. We may also use and share aggregated or de-identified data, such as statistical or usage data, for any lawful purpose, including analytics, benchmarking and product improvement, consistent with the Terms. Aggregated data may be derived from personal data but is not personal data where it does not directly or indirectly identify you. If aggregated data is ever combined with personal data so that you can be identified, we treat the combined data as personal data under this Policy.
4. How we collect personal data
We collect personal data:
- directly from you, when you register, complete onboarding, use the Platform, contact support or communicate with us;
- from your organisation, where the Client or its administrators provide details of Users, directors or beneficial owners;
- automatically, through your use of the Platform and the Site, including through cookies and similar technologies described in Section 17;
- from public blockchain networks, which record wallet addresses and transactions on a public, decentralised and immutable basis;
- from the Regulated Service Providers, for example onboarding status, account references and Transaction confirmations; and
- from publicly available sources and screening databases used in the checks described in Section 5.
5. Purposes and legal bases
We process personal data for the following purposes, relying on the legal bases indicated:
| Purpose | Personal data | Legal basis |
|---|---|---|
| Creating and administering Accounts; authenticating Users; providing the Platform and its features; providing support and handling complaints | Account and registration data; usage and technical data; communications data | Performance of a contract (the Terms); legitimate interests in administering the relationship where the data subject is not party to the Terms (e.g. personnel of the Client) |
| Collecting onboarding information through the Platform interface for transmitting it to the applicable Regulated Service Provider for verification, onboarding, ongoing due diligence and Transaction monitoring | Onboarding and verification data | Performance of a contract (taking steps to enable access to the Regulated Services); legitimate interests in enabling the Client's access and meeting our contractual commitments to the Regulated Service Providers |
| Applying our own risk-based checks, controls and monitoring to maintain high standards of financial crime prevention on the Platform, including sanctions screening and reporting suspicious activity to the applicable Regulated Service Provider and, where required or permitted, to authorities | Account, onboarding, wallet, transaction and usage data | Legitimate interests in preventing financial crime, protecting the Platform and meeting our contractual commitments to the Regulated Service Providers; compliance with legal obligations to which we are subject, where applicable |
| Enabling you to submit Orders to the applicable Regulated Service Provider through the Platform interface, and displaying Transaction and balance information; keeping records of your interactions with the Platform | Wallet and transaction data; usage and technical data | Performance of a contract; legitimate interests in maintaining accurate records to discharge our contractual obligations and comply with Applicable Law |
| Securing the Platform, preventing fraud and abuse, monitoring performance and diagnosing errors | Usage, device and technical data | Legitimate interests in network and information security and service integrity |
| Analysing how the Platform and Site are used, to improve them and develop new features (using our analytics provider, and aggregated or de-identified data where possible) | Usage and technical data; cookie data | Consent (for non-essential cookies and similar technologies); legitimate interests in understanding and improving our services (for analysis not involving such technologies) |
| Operating the support chat widget (including its AI-assisted responses) | Communications data; visitor and browser data collected by the widget | Legitimate interests in providing effective support; consent for associated non-essential cookies |
| Sending service communications, receipts, disclosures and notices required under the Terms or by a Regulated Service Provider | Account and communications data | Performance of a contract; legitimate interests; compliance with legal obligations, where applicable |
| Business-to-business marketing to Clients and prospects, including newsletters and product updates | Marketing and prospect data | Consent |
| Securing the Platform; detecting, preventing and investigating suspected fraud, misuse and security incidents; maintaining appropriate audit trails; investigating complaints and disputes; and establishing, exercising or defending legal claims; corporate transactions; complying with court orders and lawful requests | Any of the above, as relevant | Legitimate interests; compliance with legal obligations, where applicable |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by the interests, rights and freedoms of the individuals concerned, taking into account the business-to-business nature of the Platform and the safeguards described in this Policy. You may request further information about these assessments using the contact details in Section 1. Where processing is necessary for a contract and the data is not provided, we may be unable to provide the Platform or enable access to the Regulated Services, and we will notify you if this is the case at the time.
Change of purpose. We will only use personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use personal data for an unrelated purpose, we will update this Policy and, where required by Applicable Law, notify you and explain the legal basis which allows us to do so. We may process personal data without your knowledge or consent where this is required or permitted by Applicable Law.
6. Onboarding and Regulated Service Providers
Independent controllers. The Company and each Regulated Service Provider are separate, independent controllers, unless otherwise expressly provided in the Terms and this Policy. Neither processes personal data as a processor on behalf of the other. Each determines its own purposes and means of processing, publishes its own privacy policy, and is separately responsible for its own compliance.
The KYB/KYC pass-through and our own checks. When you complete onboarding, the information and documents you submit are collected through the Platform interface for transmission to the applicable Regulated Service Provider, which performs identity verification, AML/CFT onboarding, ongoing due diligence and Transaction monitoring under its own compliance programme and privacy policy. Our role in this flow is to collect and transmit the data and to retain the technical records described in Section 11; verification decisions are made by the Regulated Service Provider, not by us. Separately from this pass-through, we may ourselves process onboarding and verification data, together with account, wallet, transaction and usage data, in order to apply our own risk-based checks, controls and monitoring for financial crime prevention purposes, including sanctions screening and the reporting of suspicious activity, in order to maintain high standards of financial crime prevention on the Platform and to meet our contractual commitments to the Regulated Service Providers, as described in Section 5 and in the Terms.
Data becomes the provider's data. Consistent with the Terms, personal data provided to a Regulated Service Provider through or in connection with the Platform is deemed that provider's data upon the creation of your account with it, and is thereafter processed by that provider in accordance with the applicable Provider Terms and its privacy policy. Data held by us and data held by a Regulated Service Provider may be identical or overlapping; each of us independently controls the data it holds.
Ongoing sharing. During the relationship, we may share with the applicable Regulated Service Provider updated verification and due diligence information, records of your interactions with the Platform, suspicious activity reports, complaints concerning the Regulated Services, and any information reasonably required for the provider to comply with its legal or regulatory obligations or respond to enquiries from authorities, as described in the Terms.
7. Blockchain data
Wallets and Transactions operate on public blockchain networks. Wallet addresses and transaction records are recorded on a public, decentralised and immutable ledger that is not operated or controlled by the Company, are visible to anyone, and cannot be altered or deleted by us or by any single party. To the extent such data constitutes personal data, certain rights, in particular erasure and rectification, cannot be exercised against the blockchain itself. We recommend that you treat wallet addresses as potentially identifying and consider this permanence before transacting. Our blockchain indexing provider processes only public on-chain data (wallet addresses, balances and transaction receipts) to display balances and confirmations within the Platform.
8. Support chat and AI features
Support chat widget (HubSpot). The Site and web application include a customer-support chat widget provided and operated by HubSpot, Inc. and its affiliates (“HubSpot”), which includes AI-assisted customer service functionality configured and operated under HubSpot's terms. The AI functionality is provided by HubSpot and any AI sub-processors HubSpot engages under its data processing agreement, not by us; we do not integrate any AI or large language model provider directly into the Platform. HubSpot's legal documentation, including its privacy policy and data processing agreement, is available at https://legal.hubspot.com/legal-center.
What the chat processes. The widget processes what you type into the chat, together with standard widget data (page URL, browser information, a visitor identifier and any contact details you provide in the conversation). Its knowledge sources are our publicly available knowledge base and product website, and it accesses our customer relationship management system solely to identify whether you are an existing customer or a new prospect. It has no access to, or integration with, Platform account, wallet, transaction or onboarding (KYB) data.
What it can and cannot do. The chat provides conversational customer-support responses: answering general questions about our products and features, providing information about product transitions, offering basic technical support from the available knowledge sources, and redirecting you to a human representative where it cannot resolve an enquiry. It is informational only and cannot take actions on your behalf or make changes to your Account: its only action capability is creating or updating sales lead or opportunity records in our customer relationship management system. It cannot access balances, execute Transactions, access Wallets or change Account settings. Please do not enter sensitive personal data, credentials, Private Keys or confidential business information into the chat.
AI Features of the Platform. As at the date of this Policy, the support chat is the only AI-capable component we make available, and the Platform does not currently include integrated AI Features. If and when AI Features are made available within the Platform (as described in Clause 11 of the Terms), inputs and outputs will be processed by us and, where applicable, by third-party AI model providers acting as our sub-processors, solely to provide and secure those features and improve their performance for you, and we will update this Policy (including the provider table in Section 9) before doing so.
9. Recipients and service providers
We share personal data with the following categories of recipients, in each case limited to what is necessary for the stated purpose:
(a) Regulated Service Providers: as independent controllers, as described in Section 6.
(b) Service providers (processors) who process personal data on our behalf, under contracts that restrict their use of the data to providing their services to us. Our current principal providers are:
| Provider | Service | Data involved |
|---|---|---|
| Lisk Labs Ltd. | Software engineering, system hosting/operations, product design, customer support, and operational/marketing services for the Lisk Platform. | Customer support and contact details; technical/system diagnostic logs; platform usage analytics; marketing interaction data; and, under controlled time-limited access, Platform data including account, onboarding identity, wallet, transaction, payment-method and uploaded-file data. |
| Clerk | Authentication and account management (sign-in, user and organisation accounts, invitations) | Name, email address, organisation and role data |
| Cloudflare | bot detection and abuse prevention on account sign-up (Cloudflare Turnstile) | IP address, device and browser metadata (e.g., User-Agent header, TLS fingerprint, operating system), and client interaction signals/telemetry |
| Privy | Non-custodial wallet infrastructure (wallet provisioning; authorisation of on-chain transactions) | Wallet addresses, device passkey public keys, transaction-signing requests (private keys never held by us) |
| Envio | Blockchain indexing (reading on-chain balances and transaction receipts) | Public on-chain data only (wallet addresses, transactions) |
| Twilio SendGrid | Transactional and notification email delivery | Recipient name, email address, message content |
| Google (Firebase Cloud Messaging) | Mobile push notification delivery | Device push tokens, notification content |
| Google LLC (and its affiliates, e.g., Google Ireland Limited) | Remote app configuration, feature updates, and app version management (Firebase Remote Config) | Device identifiers (such as Firebase Installation IDs), IP address, app version details, and device metadata (e.g., operating system, device model, system language, and locale) |
| Amazon Web Services (AWS) | Cloud hosting and file storage | Platform data in transit and at rest, including uploaded files |
| Sentry | Error monitoring and diagnostics | Personal identifiers in error messages, tags and user details are redacted before transmission |
| Amplitude | Product analytics | Usage events, device and technical data, identifiers |
| HubSpot | Customer relationship management and support chat widget, including AI-assisted chat operated by HubSpot and its AI sub-processors under HubSpot's data processing agreement (https://legal.hubspot.com/legal-center) | Chat content, visitor and browser data, business contact details, lead and opportunity records |
Our service providers may change over time. We will update our list when material changes occur, and a current list will be posted on our Platform.
(c) Other recipients. We may also disclose personal data to: our Affiliates and our professional advisers, subcontractors and service providers, auditors and insurers; the financial institution and payment service provider partners of the Regulated Service Providers, where required in connection with the Regulated Services; regulatory, supervisory, tax, law enforcement and other authorities, where required or permitted by Applicable Law or our contractual commitments (including, where lawful, without notice to you); and an actual or prospective acquirer, investor or successor in connection with a corporate transaction, reorganisation or financing, subject to appropriate confidentiality protections. We do not sell personal data.
10. International transfers
We operate from the Cayman Islands, and the recipients, service providers, processors, affiliates, or sub-contractors described in this Policy (including our hosting, analytics, error-monitoring, and customer support providers) are located in various jurisdictions, including the United States, Switzerland and the European Economic Area. Where personal data originating from the EEA is transferred to a jurisdiction not recognised as providing an adequate level of protection (such as transfers to certain US-based service providers), we implement appropriate safeguards, including: (a) adequacy decisions of the European Commission, where available (including the EU-U.S. Data Privacy Framework, where applicable); (b) the European Commission's Standard Contractual Clauses, incorporating the module applicable to the transfer (controller-to-controller or controller-to-processor), and (c) in limited circumstances, another lawful transfer mechanism or derogation permitted by Applicable Law, in each case together with supplementary measures where needed. In addition, transfers of personal data originating from the Cayman Islands to recipients in third countries are conducted in accordance with the international transfer rules under the Cayman Islands Data Protection Act.
Each Regulated Service Provider is responsible for its own onward transfers under its own privacy policy. You may request further information about the safeguards applied, and copies of the relevant clauses, by contacting us at the details in Section 1. We monitor developments in adequacy decisions and transfer mechanisms and will update our safeguards as required.
11. Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, and thereafter delete or irreversibly anonymise it. Our principal retention periods are:
- Records of your interactions with the Platform are retained as follows:
- Transactional and account records (including orders initiated, transaction and KYB history, timestamps, and core technical identifiers): seven (7) years from the date of the relevant interaction or account closure, as applicable, or such longer period as may be required to discharge our contractual obligations or comply with Applicable Law, consistent with Clause 15.1 of the Terms.
- Operational and technical logs (such as system, application, and security logs): retained on a rolling basis for approximately 90 days, except where longer retention is necessary to investigate security incidents, suspected fraud, complaint, dispute or legal claim, or comply with Applicable Law.
These periods may be updated to reflect applicable legal obligations or updated contractual commitments.
Onboarding (KYB) documentation: Identity documents and file scans (e.g., government IDs, utility bills) are collected for transmission to the applicable Regulated Service Provider, which retains them under its own policy; we do not store these document files long-term. However, we retain specific structured identity data fields—including the name, date of birth, residential address, email, phone number, and role of directors and beneficial owners—in our database for the duration of the Client relationship and for up to seven years after account closure, where necessary and as may be extended to comply with Applicable Law, to maintain accurate business records, satisfy contractual obligations, or comply with Applicable Law.
- Account and registration data: for the duration of the relationship and thereafter for the period in (a), to the extent forming part of our records.
- Support and chat communications: up to [24] months from resolution, unless required longer for complaints, disputes or legal claims.
- Marketing data: until you object or withdraw consent, plus a suppression record to honour your preference.
- Error and diagnostic data: short rolling periods, with personal identifiers redacted at source.
Following closure of your Account, we have no obligation to store Client Data and may permanently delete it, subject to the retention periods above and Applicable Law, consistent with Clause 18.7 of the Terms. Data recorded on public blockchains cannot be deleted by us (see Section 7).
12. Security
We implement and maintain administrative, physical and technical safeguards designed to protect personal data, appropriate to its nature and no less rigorous than industry standards, including encryption in transit and at rest, access controls based on business need, personnel training, redaction of personal identifiers in diagnostic tooling, and secure disposal policies. No system is completely secure, and you are responsible for the security of your own systems, devices and credentials, including devices and backup services used in connection with your wallet. If we become aware of a personal data breach affecting you, we will act in accordance with Applicable Law and, where the Terms apply, Clause 14.7.
13. Your rights
You have the following rights in relation to the personal information we hold about you in the EEA and, where applicable, under the Cayman Islands Data Protection Act. Please note that some of these rights will only apply in certain circumstances and some of them may be limited where we have an overriding interest or legal obligation to continue to process the data or where data may be exempt from disclosure due to reasons of confidentiality obligations.
- Access: you are entitled to ask us if we are processing your data and, if we are, you can request access to your personal data. This enables you to receive a copy of the personal data we hold about you and certain other information about it;
- Correction: you are entitled to request that any incomplete or inaccurate personal data we hold about you is corrected;
- Erasure: you are entitled to ask us to delete or remove personal data in certain circumstances. There are exceptions where we may refuse a request for erasure. For example, we may be unable to erase or amend data that we are required to retain (Section 11), data whose disclosure restrictions apply (for example, where notification of a report is prohibited), or data recorded on public blockchains (Section 7);
- Portability: you may request to receive certain personal data you have provided to us in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller;
- Restriction: you are entitled to request the restriction of processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, where processing is unlawful and you oppose erasure, or where we no longer need the personal data but you require it for the establishment, exercise, or defence of legal claims. Where processing is restricted, we may continue to store the personal data but will not otherwise process it unless permitted by applicable law;
- Objection: where we are processing your personal data based on legitimate interests (or those of a third party), you may challenge this. However, we may be entitled to continue processing your information. You also have the right to object where we are processing your personal information for direct marketing purposes;
- Automated decisions: you may contest any automated decision made about you where this has a legal or similar significant effect and ask for it to be reconsidered; and
- Consent: where we are processing personal data with consent, you can withdraw your consent.
To exercise these rights, contact us at the details in Section 1. We may need to verify your identity, and we will respond within the timeframes required by Applicable Law.
Rights in respect of data controlled by a Regulated Service Provider should be exercised against that provider under its own privacy policy; we will redirect requests where appropriate.
Complaints: you may lodge a complaint with a supervisory authority; in the Cayman Islands, the Office of the Ombudsman; in the EEA, the authority of your place of residence, work or the alleged infringement.
14. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. The AI-assisted support chat described in Section 8 provides informational responses only; its sole automated action is the creation or updating of sales lead or opportunity records, which has no legal or similarly significant effect on you, and it cannot make or influence any decision affecting your Account, your Transactions or your access to the Platform. In case we implement risk-based checks and monitoring, such data shall inform decisions that involve human review. The Regulated Service Providers may carry out their own automated screening and verification as described in their privacy policies, for which they are independently responsible. Any AI Features made available on the Platform are informational and workflow-support tools only and do not execute Transactions autonomously.
15. Marketing communications
We may send marketing about our services to Clients, their personnel and prospects, where you have consented. You can opt out at any time using the unsubscribe link in any message or by contacting us, and we will honour your preference promptly. Service communications required under the Terms (such as receipts, disclosures and notices) are not marketing and will continue while you use the Platform.
16. No consumers and no children
The Platform is a business-to-business service and is not directed at consumers or at anyone under 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from an individual under 18, we will take steps to delete it and may suspend or close the relevant access. Personal data of Users and other personnel is processed in their professional capacity.
18. Third-party service providers and links
The Platform interoperates with Third-Party Services, including the Regulated Services, wallet infrastructure, blockchain Protocols and the other services described in the Terms, and the Site may link to third-party websites. Those services and sites are governed by their providers' own privacy policies, which we encourage you to review, and this Policy does not apply to them.
19. Changes to Policy
We may update this Policy from time to time, including to reflect changes to the Platform, our service providers, Applicable Law or our contractual commitments to the Regulated Service Providers. We will post the updated version with a revised date and, for material changes, notify you by email or through the Platform. Changes take effect as described in Clause 16 of the Terms. It is important that the personal data we hold about you is accurate and current; please keep us informed if your personal data changes during your relationship with us.
20. Contacts and complaints
If you have any questions, concerns or complaints about this Policy or our handling of personal data, please contact us at legal@lisk.com or at our registered office marked for the attention of the Legal Department. We will investigate and respond in accordance with Applicable Law.