Legal · Platform documentation

Privacy Policy

CIB INCEPTIONLast updated 11 April 2026

This Privacy Policy describes how CIB INCEPTION may collect, use, store, transfer, and protect personal data of users of the website, Telegram bot, mini app, wallet interfaces, staking functions, AI interface, and other related services (collectively, the “Services”).

By using the Services, you confirm that you have read this Privacy Policy and understand how your data may be processed.

1Definitions

“Personal Data”
means any information that directly or indirectly relates to a user.
“User”
means any individual or legal entity using the Services.
“Processing”
means any action involving data, including collection, recording, storage, use, transfer, analysis, modification, restriction, or deletion.
“Digital Assets”
means cryptocurrencies, stablecoins, tokens, and other digital units of value supported by the Services.
“Blockchain Data”
means public blockchain data, including addresses, transaction hashes, balances, and other on-chain information.
“Providers”
means third parties involved in enabling specific functions of the Services, including compliance, AML, KYC, KYT, payments, cards, analytics, hosting, cloud, exchange, staking, and customer support.
“Account”
means a user account within the Services.

2What Data We May Collect

Depending on how the Services are used, we may collect:

  • identification data;
  • contact data;
  • Telegram ID, username, and related technical identifiers;
  • Account data;
  • wallet data and blockchain activity data;
  • data relating to deposits, transfers, withdrawals, accruals, rewards, bonuses, and other transactions;
  • data relating to user actions within the interface;
  • device data, browser data, IP address, cookies, logs, session data, and technical analytics;
  • correspondence with support and messages sent through the Services;
  • KYC / AML documents and verification materials;
  • information relating to source of funds, origin of assets, and purpose of transactions;
  • fraud indicators, risk flags, compliance notes, and other internal assessment data;
  • any other data voluntarily provided by the user or required for the functioning of the Services.

3How We Obtain Data

We may obtain data:

  • directly from the user;
  • during registration, verification, and use of the Services;
  • from providers, contractors, and infrastructure partners;
  • from public registries, sanctions lists, PEP databases, and other lawful sources;
  • from blockchain networks and blockchain analytics systems;
  • from automated monitoring systems, fraud detection systems, and security tools.

4How We Use Data

We may use user data in order to:

  • provide access to the Services and maintain the Account;
  • process Digital Asset transactions;
  • display balances, accruals, transaction history, and statuses;
  • carry out AML, KYC, KYT, sanctions screening, fraud prevention, and compliance checks;
  • verify identity and eligibility to use the Services;
  • detect abuse, multi-accounting, and other bad-faith conduct;
  • support staking, yield, liquidity, and other products;
  • interact with payment, card, banking, custodial, exchange, and other providers;
  • maintain the security, stability, and technical functionality of the Services;
  • improve interfaces, processes, and user experience;
  • conduct internal audit, risk management, and protect the legitimate interests of the Services;
  • comply with requirements of law, regulators, courts, and competent authorities;
  • resolve disputes, claims, investigations, and incidents.

5Legal Bases for Processing

Depending on the circumstances, data may be processed on the following bases:

  • performance of a contract or steps prior to entering into a contract;
  • compliance with legal obligations;
  • protection of the legitimate interests of the Services, users, providers, and partners;
  • prevention of fraud, abuse, and other risks;
  • user consent, where required under applicable law;
  • other lawful bases permitted under applicable legislation.

6Blockchain Data

The user understands and agrees that blockchain networks are public systems.

This means that certain data, including wallet addresses, transaction hashes, token balances, and other blockchain metadata, may be publicly visible and accessible to an unlimited number of persons.

The Services do not control the public nature of blockchain networks and cannot guarantee the confidentiality of information that is public by design.

7Data Sharing

We may share data with:

  • providers and contractors involved in operating the Services;
  • compliance, AML, KYC, KYT, and blockchain analytics partners;
  • payment, card, banking, custodial, exchange, and liquidity partners;
  • hosting, cloud, technical, and security providers;
  • legal, audit, accounting, and other professional advisers;
  • governmental, regulatory, law enforcement, judicial, and other competent authorities where lawful grounds exist;
  • persons involved in a corporate restructuring, sale of business, merger, or similar transaction, where permitted by law.

Data is shared only to the extent necessary for the operation of the Services, compliance with law, performance of obligations, and protection of legitimate interests.

8International Data Transfers

Because the Services may rely on international infrastructure, user data may be processed and transferred across different jurisdictions.

By using the Services, the user understands and accepts that international data transfers may be a necessary part of service delivery, where permitted by applicable law.

9Data Retention

Data may be retained for as long as is reasonably necessary for:

  • providing the Services;
  • performing contractual obligations;
  • AML, compliance, sanctions, fraud prevention, and security purposes;
  • accounting, tax, and reporting purposes;
  • resolution of disputes, claims, and investigations;
  • protection of the legitimate interests of the Services;
  • compliance with legal requirements and mandatory requests.

Once retention is no longer necessary, data may be deleted, anonymized, restricted, or archived in accordance with applicable law and internal procedures.

10Data Security

Reasonable technical, organizational, and administrative safeguards are used to protect data.

Such measures may include:

  • access controls;
  • internal protection procedures;
  • event logging;
  • monitoring of suspicious activity;
  • encryption where applicable;
  • security reviews and technical assessments.

However, no system of storage, transmission, or processing can be considered completely secure.

11Fraud Prevention, Anti-Abuse, and Monitoring

In order to protect the Services, users, and partners, automated and non-automated mechanisms for monitoring, profiling, and risk assessment may be used.

Such mechanisms may be used to identify:

  • multi-accounting;
  • fake or nominee accounts;
  • abuse of staking, reward, and referral mechanisms;
  • suspicious transaction chains;
  • attempts to circumvent restrictions;
  • fraudulent or coordinated activity;
  • other signs of unlawful or bad-faith conduct.

As part of such procedures, internal risk flags, profiles, scores, alerts, and other assessment categories may be created and used in decisions relating to access, restrictions, review, freezing, or termination of service.

12Cookies and Technical Analytics

When using the website, web interfaces, or other digital access points, the following may be collected:

  • cookies;
  • session data;
  • device identifiers;
  • browser data;
  • operating system data;
  • referral data;
  • clickstream data;
  • crash logs;
  • performance data;
  • other technical and analytical metrics.

Such data may be used for:

  • proper operation of the Services;
  • security;
  • error diagnostics;
  • performance analysis;
  • improvement of interfaces and user experience.

13User Rights

Depending on applicable law, the user may have the right to:

  • request access to data;
  • request correction of inaccurate data;
  • request deletion of data;
  • request restriction of processing;
  • object to certain types of processing;
  • request data portability;
  • withdraw consent, where processing is based on consent.

Such rights may be limited where processing is necessary for:

  • compliance with law;
  • AML / CFT procedures;
  • sanctions control;
  • fraud prevention;
  • security purposes;
  • protection of the rights and legitimate interests of the Services;
  • investigations;
  • compliance with mandatory requirements of competent authorities.

14When Data May Not Be Deleted

Deletion, restriction, or modification of data may be refused where:

  • retention is required by law;
  • the data is required for AML, compliance, sanctions, fraud prevention, or security purposes;
  • the data is necessary for a dispute, claim, or investigation;
  • the data is connected to an ongoing investigation;
  • deletion would create a disproportionate risk for the Services, users, providers, or infrastructure.

15Minors

The Services are not intended for persons under the age of 18 or the age of majority in the relevant jurisdiction.

If it becomes known that data has been provided by a minor in violation of these rules, such data may be deleted and access may be restricted.

16Changes to This Privacy Policy

This Privacy Policy may be amended at any time. The updated version becomes effective upon publication unless stated otherwise.

Continued use of the Services after the changes take effect means that the user has reviewed the updated version and accepts it to the extent applicable.

CIB INCEPTION · Privacy Policy · Last updated 11 April 2026