Privacy Policy
RavenChange Privacy and Personal Data Processing Policy
1. General Provisions
1.1. This Policy sets forth the procedures for the processing, storage, and protection of the personal data of users of the ravenchange.ru website.
1.2. Data Controller: RAVENCHANGE.
1.3. The user provides active consent to this Policy by checking the required checkbox when creating a Request.
1.4. The following definitions apply in this Policy:
1.4.1 Personal data any information relating to an identified or identifiable natural person (user).
1.4.2. Processing any action (operation) or set of actions involving personal data, including collection, recording, organization, storage, clarification, use, transfer (disclosure, access), blocking, and deletion.
1.4.3. Controller-a person who organizes and/or carries out the processing of personal data.
1.4.4. User-a natural person who uses the Controller services.
2. Scope of Processed Data
2.1. Contact information: email, Telegram ID, and other contact details provided by the User.
2.2. Request data: amounts, payment details (as entered by the User), TxID, cryptocurrency wallet addresses, correspondence with support (if any).
2.3. Technical data: IP address, user-agent, cookies, date/time of anti-fraud metrics; type of action performed on the Site (click, hover, etc.); last visit and activity; screen resolution; User device type; User location; User language; language of the User operating system, device, and browser; information about the User device theme (day or night); class of the HTML element clicked
2.4. KYC/SoF data: the User identity documents, their photograph as biometric personal data; proof of address; the User card details; statements, receipts, explanations, and other evidence of the origin of funds.
3. Purposes of Personal Data Processing
3.1. Providing the website functionality and fulfilling the Application.
3.2. AML/KYC/SoF compliance, fraud prevention, and ensuring the security of Users and transactions.
3.3. Providing user support, reviewing complaints, and resolving disputes.
3.4. Complying with requests from authorized authorities where there are legal grounds to do so.
4. Legal Bases for Processing Personal Data
4.1. User consent.
4.2. Performance of the User Agreement (public offer) and provision of services.
4.3. The Operator legitimate interests in ensuring security, preventing fraud, and complying with AML procedures.
5. Transfer of Personal Data to Third Parties
5.1. The Operator may disclose personal data to third parties only to the extent necessary for the purposes specified in this Policy, including:
5.1.1. in response to a lawful request from competent authorities;
5.1.2. to contracted processors (hosting providers, email/chat providers, infrastructure contractors) strictly to the extent necessary for their operations;
5.1.3. to AML analyzers to the extent of addresses, TxIDs, and technical verification parameters.
5.2. The Operator does not provide access to Users personal data for a fee and does not disclose such data to third parties except in the cases listed in Section 5.1 of this Policy.
6. Retention Periods for Personal Data
6.1. Application data and logs: 12 months.
6.2. KYC/SoF materials: 5 years.
6.3. In the event of a claim or dispute, the retention period may be extended until the resolution of the matter.
6.4. Upon expiration of the retention periods, personal data shall be destroyed.
7. Secure Data Collection and Protection
7.1. Data is transmitted via secure channels (HTTPS/TLS).
7.2. KYC/SoF documents are accepted only through secure channels, forms, or the personal account (if available), and access to them is restricted.
7.3. The Operator employees are granted access to data on a role-based need-to-know basis, limited to the information necessary for the proper performance of their duties.
7.4. Access to KYC/SoF materials and key operations is logged.
7.5. Data storage security measures are in place (including encryption and control of backups, if any), as well as data minimization (only necessary data is requested).
7.6. The user is responsible for ensuring the security of their own devices and accounts.
8. User Rights
8.1. The user has the right to request information about data processing, as well as to request the correction, updating, clarification, or deletion of data (if there are no grounds for retention).
8.2. Consent may be withdrawn by contacting support; however, use of the service may be restricted if processing is necessary for AML, security, or the fulfillment of an Application.
9. Operator Contact Information
9.1. For questions regarding the processing of personal data, please contact the Operator at: info@ravenchange.ru
