Harv-X
Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how Harv-X and the Operating Entity (“we”) process personal data when you use the Platform, aligned with financial-platform good practice (transparency, minimisation, security and data-subject rights).
If you disagree, you must not use Harv-X.
1. Controller
The controller is the Harv-X Operating Entity (platform at https://harv-x.com). Corporate identification will be completed in this Policy once company registration is finalised. Privacy contact: privacy@harv-x.com.
2. Data we collect
Account data: email, phone, password (hash), language, preferences.
Verification (KYC) data: name, ID document, selfie, address, date of birth and other compliance fields.
Trading data: ads, orders, declared payment methods, amounts, currencies, escrow status, dispute messages and evidence.
Technical data: IP, device, logs, cookies/SDKs needed for security and operation.
3. Purposes and legal bases
Service delivery and contract performance (account, P2P matching, escrow).
Legal compliance (AML/CFT, fraud prevention, tax or authority duties where applicable).
Legitimate interests: security, product improvement, abuse prevention, support.
Consent: where required (e.g. optional marketing).
4. Recipients and processors
We may share data with cloud, KYC, anti-fraud, support and professional advisers under contract and only as needed.
We do not sell personal data. We may disclose data to authorities when legally required.
Other Users see only what is needed to complete an order (e.g. payment details you provide for that trade).
5. International transfers
If data is processed or stored outside your country, we apply appropriate safeguards (e.g. standard contractual clauses) where required.
6. Retention
We keep data while the account is active and thereafter for dispute, accounting, AML and limitation periods, then delete or anonymise securely.
7. Security
We apply reasonable technical and organisational measures (encryption in transit, access control, monitoring). No system is fully secure; report suspected compromise promptly.
8. Your rights
Under applicable law (e.g. GDPR) you may request access, rectification, erasure, restriction, portability and objection, and withdraw consents. You may complain to a supervisory authority.
To exercise rights: privacy@harv-x.com. We may verify identity before responding.
9. Cookies
We use essential cookies for session, security and language. Non-essential cookies, if introduced, will be managed with consent where legally required.
10. Children
Harv-X is not directed at minors. If we detect an underage account without capacity, we will close it and delete data as appropriate.
11. Changes
We may update this Policy. The current version is posted with a date. Material changes may be notified via the Platform or email.
Policy adapted to the Harv-X model. Validate with legal/DPO advice before processing real customer data in production.