Privacy Policy

Effective Date: August 20, 2026

Entity: Conduit Digital Holdings Pte. Ltd. (UEN: 202488910Z)

Contact Email: privacy@conduitdigital.io / dpo@conduitdigital.io

Conduit Digital Holdings Pte. Ltd. (“Conduit,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal data when you visit our website, access our decentralized application interfaces, or use our digital asset infrastructure services (collectively, the “Services”).

This policy complies with the Singapore Personal Data Protection Act 2012 (PDPA) and, where applicable, the European Union General Data Protection Regulation (GDPR).

Data Controller Information

Conduit Digital Holdings Pte. Ltd. is a private limited company incorporated in the Republic of Singapore. For any privacy-related inquiries or to exercise your rights under the PDPA, please contact our Data Protection Officer (DPO) at dpo@conduitdigital.io.

Information We Collect

We collect information directly from you, automatically through your interactions with our interface, and from third-party verification partners:

  • Identity & Onboarding Data: Full legal name, date of birth, nationality, national identification or passport numbers, government photo IDs, and tax identification numbers.
  • Contact Data: Email address, phone number, and physical billing/residential address.
  • Financial & Compliance Data: Wallet addresses, source of funds declarations, bank account details, investor status (e.g., Accredited Investor verification under Singapore law), and transaction histories.
  • Technical & Usage Data: IP addresses, device identifiers, browser types, operating systems, cookie preferences, and interaction logs with our web interface.
  • Blockchain Network Data: Public blockchain addresses, smart contract interactions, transaction hashes, and signed message payloads.

How We Collect Personal Data

  • Direct Interactions: When you complete onboarding forms, submit KYC/AML documents, request support, or subscribe to communications.
  • Automated Technologies: Via cookies, server logs, and web analytics tools when navigating our website.
  • Third-Party Service Providers: From identity verification services (e.g., KYC vendors), sanction screening platforms, and blockchain analytics engines (e.g., Chainalysis).

Purpose and Legal Basis for Processing

We process personal data for the following essential business and regulatory purposes:

  • Regulatory Compliance: Fulfilling Anti-Money Laundering (AML), Countering the Financing of Terrorism (CFT), and Know Your Customer (KYC) requirements under Monetary Authority of Singapore (MAS) directives and applicable international laws.
  • Contract Performance: Processing transaction requests, managing user access to platform modules, and facilitating minting/redemption operations.
  • Security & Fraud Prevention: Detecting unauthorized access, preventing smart contract abuse, monitoring platform integrity, and enforcing geofencing controls.
  • Legitimate Interests: Analyzing interface usage, improving software features, and communicating operational updates.

Disclosure of Personal Data

We do not sell your personal data. We disclose your data only to trusted recipients as required by law or to operate our Services:

  • Regulatory Authorities: MAS, tax authorities, or legal enforcement bodies upon valid request or statutory obligation.
  • Service Providers: Identity verification partners, cloud hosting providers (e.g., AWS/GCP), security auditors, and legal/financial advisors bound by strict confidentiality terms.
  • Banking & Custodial Partners: Licensed financial institutions or digital asset custodians managing reserve assets or escrow accounts.
  • Corporate Transactions: In connection with a merger, acquisition, asset sale, or corporate restructuring.

Cross-Border Data Transfers

As a Singapore-based platform operating globally, your personal data may be transferred, stored, or processed outside Singapore. Whenever such transfers occur, we ensure that your personal data receives a level of protection comparable to that required under the Singapore PDPA, typically via standard contractual clauses or binding corporate rules.

Data Retention

Under Singapore regulatory requirements, we retain personal data and transaction records for a minimum of 5 to 7 years following account closure or termination of the business relationship to fulfill statutory legal and AML/CFT record-keeping mandates.

Your Legal Rights

Subject to statutory exemptions, you hold the following rights under the PDPA and applicable privacy regulations:

  • Access & Correction: Request a copy of your personal data or request corrections to inaccurate data.
  • Withdrawal of Consent: Withdraw consent to marketing communications or non-essential data processing.
  • Erasure: Request deletion of personal data where legal retention mandates no longer apply.

To exercise your rights, email legal@conduitdigital.xyz. We respond to verified requests within 30 days.

See also our Terms of Service.