Privacy Policy
Last updated 1 May 2026
This policy describes what personal data CoinPoint processes, for what purposes, and on what legal grounds. By using the service, you agree to these terms.
1. General Provisions
The data controller is CoinPoint (hereinafter the "Service"). This policy applies to all interactions with the website, Telegram bot, and Service staff.
By completing a transaction or submitting data through Service channels, you confirm that you have read this policy and agree to its terms.
2. What Data We Collect
We collect only the data necessary to provide the service, comply with legal requirements, and ensure the security of transactions.
- contact details: Telegram username, email address, phone number, if you provide them;
- verification data (KYC): copies of identity documents, selfie, proof of address — only when required under AML/KYC policy;
- transaction data: amounts, currencies, payment details, timestamps;
- technical data: IP address, device and browser type, access logs — for fraud prevention and debugging.
3. Purposes of Processing
Personal data is processed for the following purposes:
- fulfilling your exchange or payment instruction and related communications;
- meeting AML/KYC obligations and preventing fraudulent transactions;
- responding to your enquiries and improving service quality;
- complying with applicable law and requests from authorised authorities.
6. Your Rights
With regard to your personal data, you have the right to:
- receive a copy of the data we hold about you;
- request correction of inaccuracies or additions;
- request deletion of data, except for information that must be retained under AML/KYC and other legal requirements;
- withdraw previously given consent to the extent permitted by applicable law;
- lodge a complaint with the competent data protection authority if you disagree with the processing.
7. Contact Us
Requests regarding the processing of personal data should be sent via the Contacts section or through Telegram. We aim to respond within one business day; for data subject rights requests — no later than the deadline set by law.