Bitroa Exchange (hereinafter referred to as the “Company”) is doing its best to protect and safely manage users’ personal information. The information protection policy explains the information collected, purpose of use, and protection measures when users use the company's services (hereinafter referred to as "services").
Risks of Virtual Asset Trading
Personal Information Collection items and Methods
- The company may collect the following personal information to provide services: When registering as a member: email address, password, phone number, identification information (e.g. ID card, address, etc.)
- When using the service: transaction history, deposit/withdrawal records, device information (IP address, browser information, etc.)
- When requesting customer support: User inquiry content and related information
- Automatically collected information: cookies, access times, usage patterns, etc.
- The company collects personal information when users sign up for membership, use services, or request customer support. In addition, the company collects personal information when users sign up for membership, use services, or request customer support.
- We may collect additional data to improve the quality of the service and enhance security. This data may include access time of user
- It may include information on the user's activity records and interactions within the service. The company requests the minimum amount of information when collecting personal information, and obtains prior consent if additional data collection is required. Also
- We do not collect sensitive information without the user's consent. Users may refuse to provide personal information at any time, but in this case, use of some services may be restricted.
Purpose of using Personal Information
- The company uses the collected personal information for the following purposes:
- Service provision and operation (transaction processing, deposit/withdrawal management, etc.)
- Account Security and Authentication
- Comply with legal obligations and meet regulatory requirements
- Customer Support and Inquiry Response
- Improve services and optimize user experience
- Fraud prevention and illegal activity prevention
- Providing customized services and utilizing marketing
- System error analysis and service optimization
- Developing new services and improving features
- Responding to internal audit and legal requirements
- Analysis of users' service usage patterns and provision of customized content
- The company focuses on using personal information to improve users’ service experience and strengthen security. In particular, it operates an AI-based security system to prevent fraud and illegal activities, and takes measures to quickly block suspicious activities through an abnormal transaction detection system.
Personal Information Retention Period
- The company retains personal information for the period required by relevant laws and regulations, and immediately destroys it when the retention period expires. Membership registration information:
- Immediately deleted upon withdrawal of membership (exception applies in cases where there is a legal obligation)
- Transaction and financial information: Retained for at least 5 years in accordance with applicable laws
- Customer inquiry and support information: stored for up to 3 years
- Marketing and advertising data: immediately deleted upon withdrawal of user consent
- Access records and log data: stored for up to 1 year
- The Company destroys your personal information in a secure manner when it is no longer needed. The method of data destruction is secure
- We may use a software deletion method or a physical destruction method. In addition, upon user request, we will delete information to the extent that legal requirements are met.
Provision and Sharing of Personal
- Information to third parties The company does not provide personal information to third parties without the user's consent. However, it may be provided only when there is a legal obligation or in the following cases:
- When the user's consent is provided When there is a legal request (court order, government agency request, etc.)
- When sharing with trusted partners (payment service providers, identity verification agencies, etc.) for service provision
- When receiving technical support to improve internal services and enhance security
- When providing anonymized data for marketing and advertising
- The information provided is shared only to the extent absolutely necessary, and partners are required to comply with the company's personal information protection standards. The company will notify users so that they can easily check it in the event of third-party provision.
Personal Information
- Protection measures The company implements the following security measures to safely protect users' personal information:
- Data encryption (during transmission and storage)
- Access control and authority management Periodic security checks and monitoring Implementation of security training for internal employees and affiliates
- Application of multi-authentication system and reinforcement of security protocol
- Recording of user activity logs and operation of anomaly detection system
- Application of network firewall and intrusion detection system
- Operation of automated system to prevent data leakage To strengthen personal information protection, the company regularly conducts security checks and introduces the latest security technologies to prevent data leakage.
User's Rights and Choices Users
- May exercise the following rights regarding their personal information at any time:
- Request to view, correct, or delete personal information
- Request to restrict or object to data processing
- Withdraw consent to provide personal information
- Request to close account and delete data
- Request to portability of personal information (data can be transferred to other services)
- Opt-out of use of data for marketing purposes and change notification settings
- These requests can be made through customer support, and the company will promptly process them in accordance with relevant laws. In addition, users have the right to refuse use of data for marketing purposes, and can manage this through settings.
Use of Cookies and Tracking
- Technologies The Company uses cookies and similar technologies on its websites and applications to improve user experience and provide customized services.
- Essential cookies: Cookies that are essential to provide the service.
- Analytics cookies: Cookies that analyze service usage patterns to improve performance
- Marketing cookies: Cookies for tailored advertising and promotional purposes
- Users can manage or block the use of cookies through their browser settings. However, if you block cookies, some functions may not work properly. It may not work commercially.
- Request to portability of personal information (data can be transferred to other services)
- Opt-out of use of data for marketing purposes and change notification settings
- These requests can be made through customer support, and the company will promptly process them in accordance with relevant laws. In addition, users have the right to refuse use of data for marketing purposes, and can manage this through settings.
Use of Cookies and Tracking
The Company may change this Privacy Policy, and will notify you in advance if there are any significant changes. The changed policy will be effective from the date of notification.
International Data Transfers
The Company may transfer your personal information to other countries to provide global services. In this case, the personal information of the country in question. We comply with data protection laws and take steps to ensure secure data transmission.
Inquiries
If you have any questions relating to our privacy policy and your rights and obligations arising from these policy terms, or if you intend to exercise your rights stated in this privacy policy, please contact support@peer-kr.com.