Docs / Privacy Policy

Privacy Policy

Last updated: August 2026. This policy describes how Polis Exchange collects, uses, and protects your data.

1. Data We Collect

We collect the following categories of data:

  • Account data. Email address, password (hashed), and authentication tokens.
  • KYC data. Full name, date of birth, residential address, and document type submitted during identity verification.
  • Trading data. Order history, token balances, mint and redeem history, and fees paid.
  • Transaction data. Deposit and withdrawal records, including USDC transaction references.
  • Technical data. IP address, browser type, access timestamps, and API request logs for security monitoring.

2. How We Use Your Data

We use your data to:

  • Operate the exchange: process orders, mint and redeem tokens, and settle at EBITDA filings.
  • Verify your identity as required by anti-money laundering (AML) regulations.
  • Monitor for fraud, market manipulation, and suspicious activity.
  • Communicate with you about your account, settlements, and service changes.
  • Comply with legal obligations and respond to lawful requests from authorities.
  • Maintain audit trails for regulatory compliance.

3. Data Sharing

We do not sell your personal data. We may share data with:

  • Regulatory authorities when required by law or in response to lawful requests.
  • Service providers who help operate the exchange (e.g. data feeds for company valuations), under appropriate data protection agreements.
  • Auditors for compliance verification.

4. Data Retention

We retain your data for as long as your account is active. After account closure, we retain KYC records, transaction history, and audit logs for a minimum of 5 years as required by UK AML regulations. Technical logs (IP addresses, API access logs) are retained for 12 months for security monitoring.

5. Data Security

We employ industry-standard security measures including:

  • Encrypted password hashing (bcrypt).
  • JWT-based authentication with short-lived access tokens (15-minute expiry) and refresh tokens.
  • Optional TOTP-based two-factor authentication.
  • API key authentication for programmatic access with scoped permissions.
  • TLS encryption for all client-server communication.
  • Rate limiting to protect against abuse.

Despite these measures, no system is perfectly secure. You are responsible for safeguarding your credentials and API keys.

6. Your Rights

Under the UK GDPR, you have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data (subject to legal retention obligations).
  • Restrict or object to certain processing activities.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent for processing based on consent.

To exercise these rights, contact the exchange administrator. We will respond within 30 days.

7. Cookies

The Service uses essential cookies for authentication and session management. We do not use third-party tracking cookies, advertising cookies, or analytics cookies that profile your behavior across sites.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service. Continued use after changes take effect constitutes acceptance of the updated policy.

9. Contact

For privacy questions or to exercise your data rights, contact the exchange administrator through the in-app settings page.

← Docs