Privacy Policy

Version: 2.0 Effective Date: March 2, 2020 Last Updated: April 20, 2026

Table of Contents

  1. Introduction and Acceptance
  2. Definitions
  3. Personal Data Collected
  4. Purposes of Data Processing
  5. Legal Bases for Processing
  6. Data Sharing and International Transfer
  7. Data Retention and Storage
  8. Information Security
  9. Rights of the Data Subject
  10. User Responsibilities
  11. Platform Services and Data Implications
  12. Modification and Deletion of Data
  13. Contact and Communication Channels
  14. Final Provisions

1. Introduction and Acceptance

1.1. Purpose of this Document

This Privacy Policy ("Policy") governs the collection, use, storage, sharing, and protection of personal data of Users of the Inkryptus digital platform, comprising the official website (https://www.inkryptus.com), mobile application ("Inkryptus App"), and all integrated operating environments.

Inkryptus is committed to preserving the trust of its Users and to processing personal data in a transparent, secure, and lawful manner. This document describes what personal data is collected, how it is processed, with whom it may be shared, and what rights the User has in relation to their data throughout the provision of services offered by Inkryptus.

1.2. Acceptance of the Privacy Policy

By reading, understanding, and accepting this Privacy Policy, the User expressly declares agreement with all rights and obligations described herein.

Acceptance occurs when the User affirmatively consents through the consent mechanism provided during registration. By activating the consent button, the User indicates awareness and full agreement with how their personal information and data will be used.

If the User disagrees with this Policy, they should not proceed with the registration process. In such cases, Inkryptus requests that the User contact the support team through the channels indicated in Section 13 of this document to communicate the reason for disagreement.

Only after the User expresses acceptance will the Platform enable the registration form and grant access to the services offered by Inkryptus.

1.3. Changes and Updates

This Privacy Policy is subject to periodic review and improvement. Inkryptus may update, revise, or modify this Policy for technical, operational, regulatory, or security reasons.

When relevant changes require renewed consent, Inkryptus will publish the updated Policy on the Platform and request new acceptance from the User.

Material changes will be communicated to registered Users by email and through a prominent notice in the application. The User is responsible for periodically reviewing this Policy.

Continued use of the Platform after the effective date of any change constitutes acceptance of the updated conditions.

1.4. Relationship with the Terms of Use

This Privacy Policy must be interpreted in conjunction with the Inkryptus Terms of Use. In the event of a conflict between these documents, the provision that ensures greater protection to the data subject will prevail, subject to applicable legal and regulatory requirements.

All definitions established in the Terms of Use apply to this Policy, unless otherwise specified herein.

2. Definitions

For the purposes of this Policy, in addition to the definitions set forth in the Terms of Use, the following terms apply:

a) Personal Data: any information relating to an identified or identifiable natural person, including name, email, phone number, tax identification number, IP address, device identifiers, browsing data, and any other information that may directly or indirectly identify the User.

b) Processing: any operation performed with personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, combination, restriction, erasure, or destruction.

c) Data Controller: the entity that makes decisions regarding the processing of personal data. For the purposes of this Policy, Inkryptus acts as the Data Controller.

d) Data Processor: a natural person or legal entity that processes personal data on behalf of and under the instructions of the Data Controller.

e) Data Subject: the natural person to whom the personal data being processed refers.

f) Consent: a free, informed, and unequivocal expression of will by which the data subject agrees to the processing of their personal data for a specific purpose.

g) Anonymization: the process by which data loses the possibility of direct or indirect association with an individual, using reasonable technical means available at the time of processing.

h) LGPD: the Brazilian General Data Protection Law (Lei Geral de Protecao de Dados, Law 13,709/2018).

i) ANPD: the Brazilian National Data Protection Authority (Autoridade Nacional de Protecao de Dados), the public body responsible for overseeing compliance with the LGPD.

j) DPO (Data Protection Officer): the person appointed by Inkryptus to act as a communication channel between the company, data subjects, and the ANPD, reachable at dpo@inkryptus.com.

3. Personal Data Collected

3.1. Data Provided by the User

Inkryptus collects personal information when the User performs registration on the Platform or voluntarily provides information through email or other official channels.

Registration data includes: full name, nationality, phone number, and email address.

Additional data may be collected depending on the services used, including tax identification numbers (CPF/CNPJ), date of birth, residential address, identity documents, and proof of address, particularly when identity verification (KYC) procedures are required.

3.2. Data Collected Through Navigation and Devices

Inkryptus may automatically collect the following technical data during the User's interaction with the Platform:

(i) IP address of the device used to access Inkryptus services or products; (ii) interactions performed and user profiles connected to Inkryptus websites, applications, and related services; (iii) technical information from the server and the User's device; (iv) device attributes, including device ID, operating system, browser type, and model; (v) geolocation data from the device, when the User authorizes collection through their device settings; and (vi) access logs, session duration, pages visited, and navigation patterns within the Platform.

3.3. Cookies and Similar Technologies

Inkryptus may use cookies, pixels, web beacons, and similar technologies to improve the User experience, analyze usage patterns, and support marketing activities.

Collected data may be used for research, analysis, technology improvement, service enhancement, and marketing purposes, always in accordance with applicable data protection legislation.

Inkryptus does not disclose personal information or link User preferences, access patterns, and responses to their registration in an identifiable manner. When such information is shared for statistical purposes, it is done on a consolidated and anonymized basis.

4. Purposes of Data Processing

4.1. Service Provision and Account Management

Personal data is processed for the following operational purposes:

(i) provision of services and delivery of products contracted by the User; (ii) creation, validation, authentication, and maintenance of the User's account on the Platform; (iii) identification, authentication, and verification of requirements for the use of Inkryptus services and products; (iv) execution of features and operations requested by the User, including transactions, wallet management, staking, swap, harvest, and other Platform functions; and (v) improvement of services, including the analysis of contracted products to offer new features and solutions of interest to the User.

4.2. Security, Fraud Prevention, and Compliance

(i) prevention and resolution of technical or security issues; (ii) investigation and adoption of measures to prevent and combat illicit acts, fraud, financial crimes, and to ensure the safety of Inkryptus Users; (iii) prevention of fraud and ensuring User safety in identification processes, registration authentication, and device verification; (iv) identity verification, access authentication, and prevention of abuse or unlawful activities; and (v) cooperation or compliance with orders from courts, competent authorities, or supervisory bodies.

4.3. Communication and Notifications

(i) responding to requests and questions from Users; (ii) contacts via email, SMS, WhatsApp, phone, or other means of communication, including sending notifications or push messages related to Inkryptus services; (iii) communication with the User for the sending of operational notifications, security alerts, contractual updates, and responses to support requests; and (iv) sending of institutional or promotional communications, when applicable and permitted by legislation.

4.4. Improvement of Products and Services

(i) marketing, market and opinion research, and promotion of products and services, including the provision of offerings and sending of information about products, services, features, content, and other relevant events for the relationship with the User; (ii) performance analysis, security assessment, stability monitoring, and continuous improvement of the Platform, products, and services; and (iii) development of new features, services, and tools within the Inkryptus ecosystem.

(i) regular exercise of Inkryptus's rights, including the submission of documents in judicial and administrative proceedings, when necessary; (ii) compliance with legal or regulatory obligations, including anti-money laundering (AML/CFT), tax reporting, and data protection requirements; and (iii) cooperation with fiscal, regulatory, law enforcement, and judicial authorities, both domestic and international, whenever required by law.

The processing of personal data by Inkryptus occurs based on the legal bases provided in applicable legislation, including:

(i) Performance of a contract: processing necessary for the execution of the service agreement between Inkryptus and the User, including account creation, transaction processing, and service delivery;

(ii) Compliance with legal or regulatory obligations: processing required to fulfill identity verification procedures (KYC), anti-money laundering obligations (AML/CFT), tax obligations, and notifications to competent authorities;

(iii) Legitimate interest: processing necessary to ensure Platform security, prevent fraud, protect Users, improve features, and ensure service integrity, always observing the fundamental rights and freedoms of the data subject;

(iv) Consent: processing based on the User's free, informed, and unequivocal agreement, applicable to optional, specific, and previously informed purposes, such as receiving promotional communications.

When applicable, the User may revoke consents granted at any time, without prejudice to the lawfulness of processing carried out previously.

6. Data Sharing and International Transfer

6.1. Categories of Recipients

Inkryptus may share personal data with third parties only when necessary for the performance of services, compliance with legal obligations, or protection of the Platform's security and its Users.

Sharing may occur with:

(i) technology service providers responsible for infrastructure, hosting, cloud storage, information security, data analysis, and operational support; (ii) partners specializing in identity verification, fraud prevention, transaction monitoring, and compliance obligations; (iii) technical or operational partners necessary for the operation of specific Platform features or integration with other services, including fiat ramp providers; (iv) independent auditors, consultants, and professional service providers subject to confidentiality obligations; and (v) administrative, regulatory, fiscal, law enforcement, or judicial authorities when there is a legal or regulatory obligation or valid requisition.

6.2. International Data Transfer

In certain situations, personal data may be stored or processed outside the national territory, including when using technological infrastructure services or suppliers located in other countries.

In such cases, Inkryptus will adopt appropriate technical, organizational, and contractual measures to ensure the protection of personal data, observing applicable legislation and, when necessary, mechanisms recognized by the National Data Protection Authority (ANPD), such as specific contractual clauses, contractual safeguards, or transfer to countries with an adequate level of data protection.

6.3. Restrictions on Sharing

Inkryptus does not sell, rent, or make personal data available to third parties for unauthorized marketing purposes.

Inkryptus undertakes to restrict the use of and access to shared information to the minimum necessary for the stated legal purpose, preserving confidentiality, integrity, and data security in accordance with applicable data protection laws and international information security standards.

7. Data Retention and Storage

7.1. Retention Periods

During the entire period in which the User benefits from Inkryptus services or products, or maintains an active account, Inkryptus guarantees that the storage and processing of personal data will be maintained in a secure and controlled environment.

Personal data will be stored for the period necessary to fulfill the processing purposes described in this Policy, subject to legal, regulatory, and fiscal requirements.

7.2. Post-Termination Retention

Inkryptus may store Users' personal data for an additional period after the termination of the contractual relationship for the purpose of auditing compliance with legal or regulatory obligations, including the time necessary to comply with obligations imposed by public bodies, respond to lawsuits, or fulfill data retention requirements under applicable legislation.

After the applicable retention period, data may be retained in anonymized form or blocked, in accordance with applicable data protection laws and international data retention and minimization principles.

Inkryptus reserves the right to retain information for as long as deemed necessary to comply with current regulations in force, even after the User's account is closed.

8. Information Security

Inkryptus adopts technical and administrative security measures to protect the data of its Users, including encryption, access control, continuous monitoring, log recording, firewalls, and storage on secure servers.

These measures protect data against unauthorized access, leaks, accidental or unlawful destruction, alteration, or any other form of improper processing.

The User acknowledges that there is always an inherent risk in the transmission of information over the internet. Inkryptus is committed to using market-standard security practices to mitigate these risks, but does not guarantee absolute inviolability, recognizing the inherent nature of risk in digital systems and blockchain environments.

All information collected from Users travels securely over the internet and is protected by encryption.

9. Rights of the Data Subject

9.1. Applicable Rights

The User, as the holder of personal data, may at any time choose not to disclose their personal data to Inkryptus. However, certain personal data constitute essential requirements to enable user registration and access to services and products.

Under applicable data protection laws, including the LGPD, the User has the following rights:

(i) confirmation of the existence of processing activities; (ii) access to personal data and processing purposes; (iii) correction of incomplete, inaccurate, or outdated data (right of rectification); (iv) anonymization, blocking, or deletion of unnecessary data or data processed in non-compliance with the law (right of erasure or cancellation); (v) objection or opposition to processing; (vi) review of automated decisions made based on personal data; (vii) portability of data to another service provider, upon express request; (viii) revocation of consent, where applicable; and (ix) information on the sharing of data with third parties, including the right not to provide consent and to be informed about the related consequences.

9.2. How to Exercise Rights

These rights must be exercised through the institutional channel support@inkryptus.com, with the subject line "Request - Data Protection," or by contacting the Data Protection Officer at dpo@inkryptus.com.

Inkryptus may request proof of identity before fulfilling any request, in order to verify the legitimacy of the requester and protect the User's data from unauthorized access.

9.3. Response Timeframes

Requests related to data subject rights will be responded to within 15 (fifteen) calendar days of receipt, with a confirmation of receipt sent to the requester.

In cases of high complexity, the timeframe may be extended with notice to the data subject, subject to ANPD regulations.

Inkryptus is committed to acting with total transparency in the management and processing of User data.

10. User Responsibilities

The User guarantees the integrity and accuracy of the personal data provided on the Platform and assumes the corresponding liability if the data is not accurate or complete.

It is the User's responsibility to:

(i) keep registration data updated, especially the email address, ensuring that Inkryptus communications are not directed to spam or junk folders; (ii) provide truthful, complete, and up-to-date information during registration and throughout the use of the Platform; (iii) maintain the confidentiality of access credentials (login, password, and 2FA authentication); and (iv) notify Inkryptus immediately of any suspected unauthorized access or security breach.

11. Platform Services and Data Implications

By creating an Inkryptus account and using the Platform, the User may access the following services, each of which involves the processing of personal and transactional data:

(i) Wallet: deposit, withdrawal, purchase, sale, and swap of crypto assets compatible with the BNB Smart Chain (BEP20) network; (ii) Staking: creation and management of staking contracts, with daily reward distribution subject to a 25% performance fee on effective daily profit, with 75% credited to the User; (iii) Harvest and Compound: withdrawal or reinvestment of accumulated staking profits.

The User acknowledges that the choice of services offered by Inkryptus is made freely and consciously, and that Inkryptus cannot guarantee gains or positive results relating to any investment decisions made on the Platform.

Any information regarding past gains or positive results related to Inkryptus services is speculative in nature, based on the profitability obtained by the service in the most recent period, and does not constitute a promise of future returns.

12. Modification and Deletion of Data

The User may review and modify inconsistent or outdated personal information whenever necessary through the Platform settings or by contacting support.

The User may also request the deletion of their personal data when the relationship between the parties ends or when the data is no longer necessary for the purposes for which it was collected.

Inkryptus will process deletion requests within the limits established by applicable legislation, legal obligations, and regulatory requirements. Certain data may be retained in accordance with Section 7 of this Policy.

13. Contact and Communication Channels

Whenever the User needs to contact Inkryptus regarding matters related to this Privacy Policy or the processing of personal data, communication must be directed to the following official channels:

General support: support@inkryptus.com Data Protection Officer: dpo@inkryptus.com Security incidents: security@inkryptus.com

All communications directed through these channels will be internally recorded and handled in accordance with the priority levels defined in the Terms of Use.

The User acknowledges that any contact made outside the official @inkryptus.com domain, including messages via social media, instant messaging applications, personal emails, or unverified profiles, will not be considered a valid means of communication with Inkryptus and may represent an attempt at fraud or phishing.

14. Final Provisions

All practices described in this Privacy Policy apply to the processing of personal data and are subject to the legislation in force in each applicable jurisdiction.

Inkryptus may update or discontinue the Platform at any time, committing itself to act transparently with all its Users. In the event of platform discontinuity, Inkryptus will inform its Users at least 30 (thirty) days in advance.

In the event of any doubt, complaint, or request to exercise rights related to personal data, the User should contact Inkryptus through the official channels described in Section 13 of this Policy.

This Privacy Policy is governed by Brazilian law, including the General Data Protection Law (Law 13,709/2018), the Internet Civil Framework (Law 12,965/2014), the Consumer Protection Code (Law 8,078/1990), and complementary regulations, subject to the applicable legislation of each jurisdiction where the User is located.

Última actualización