This Privacy Policy explains how Chainers ("we", "us", or "our") collects, holds, utilizes, discloses, and protects your personal data when you interact with our website, software tools, and related technology services. We are dedicated to safeguarding your personal data in strict compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller Information
Chainers operates as the data controller responsible for personal information gathered through the Platform. In handling your personal records, we abide by core data protection principles: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
2. Categories of Information We Collect
We collect information you provide directly, data gathered automatically through technology telemetry, and details acquired through verified identity networks:
- Identity and Contact Data: Full name, verified email address, telephone contact details, and residential jurisdiction.
- Verification Records: Government-issued identification documents, proof of address records, and associated anti-money laundering (AML) screening data where regulatory onboarding is mandated.
- Technical and Device Telemetry: Internet Protocol (IP) addresses, device hardware identifiers, browser user-agent profiles, operating system specifications, and session connection timestamps.
- Platform Activity Data: Analytical execution preferences, algorithmic configuration parameters, page view sequences, referral origins, and interaction latencies.
3. Lawful Grounds and Purposes of Processing
Under the UK GDPR, we process personal information strictly where an established lawful basis applies:
- Contractual Performance: To configure your user account, execute requested algorithmic commands, maintain service availability, and facilitate platform features.
- Legal and Regulatory Compliance: To satisfy statutory anti-money laundering, fraud prevention, sanctions screening, and financial record-keeping mandates.
- Legitimate Interests: To improve algorithmic efficiency, harden system security against cyberattacks, detect unusual market misuse, and monitor server load balancing.
- Consent: Where you have provided express consent for direct marketing notices or optional analytics cookies, which you may withdraw at any time.
4. Sharing and Disclosure of Information
We do not sell, rent, or lease your personal data to commercial marketers. We share personal information only with trusted entities operating under rigorous confidentiality and security covenants, including:
- Cloud Infrastructure Providers: ISO-certified hosting providers, database clusters, and distributed firewall networks supporting platform resilience.
- Identity Verification Specialists: Regulated verification and AML screening agencies assisting with statutory due diligence.
- Professional Advisors: Qualified legal counsel, financial auditors, and forensic consultants operating under professional confidentiality obligations.
- Law Enforcement Authorities: Regulatory bodies, courts, or law enforcement agencies when compelled by a valid statutory order or court decree in the United Kingdom.
5. International Data Transfers
Where personal data is transferred or processed outside the United Kingdom, we ensure equivalent protections are maintained. Transfers are conducted utilizing UK International Data Transfer Agreements (IDTA), standard contractual clauses approved by the Information Commissioner’s Office (ICO), or transfers to jurisdictions recognized by the UK government as offering adequate data protection safeguards.
6. Data Security and Retention
We implement robust technical and organizational measures to safeguard your personal data against accidental loss, unauthorized access, alteration, or disclosure. These measures include TLS 1.3 cryptographic protocols, encrypted rest storage (AES-256), multi-factor administrative access, and regular vulnerability audits.
We retain personal records only for as long as necessary to fulfill the purposes for which they were collected, or to satisfy applicable legal, statutory audit, and regulatory record-retention requirements under UK law (typically up to seven years after account termination).
7. Your Statutory Rights
Under UK data protection legislation, you are entitled to exercise the following rights regarding your personal records:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal information.
- Right to Erasure: Request deletion of your personal records where statutory grounds for retention no longer apply.
- Right to Restriction: Request suspension of processing while accuracy or objections are reviewed.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing founded upon legitimate business interests or direct promotional communications.
8. Cookies and Tracking Mechanisms
The Platform uses essential technical cookies necessary for session integrity, CSRF defense, and navigation safety. Non-essential analytical cookies are deployed only with your prior explicit consent, which can be modified or revoked through your browser settings at any moment.
9. Contact and Regulatory Inquiries
If you wish to exercise any statutory privacy rights, require clarification on our data handling protocols, or have inquiries regarding this Privacy Policy, please submit your request to our compliance team. You also maintain the right to submit a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk).