Privacy Policy - Captiros AI

Privacy Policy

Captiros Global Holdings Ltd.

Trading as Captiros AI

Effective Date: July 21, 2021
Last Updated: February 6, 2026

Your Privacy Matters

Captiros Global Holdings Ltd. ("Captiros," "we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our Platform and Services. By accessing or using the Captiros platform, you consent to the practices described in this Privacy Policy.

1

INFORMATION WE COLLECT

We collect various types of information to provide, maintain, and improve our Services. The categories of information we collect include:

1.1 Personal Identification Information

When you register for an account or use our Services, we collect:

  • Full legal name
  • Date of birth
  • Email address
  • Telephone number
  • Residential address
  • Nationality and country of residence
  • Government-issued identification documents (passport, driver's license, national ID card)
  • Photograph or selfie for identity verification
  • Social Security Number, Tax Identification Number, or equivalent (where required by law)

1.2 Financial Information

  • Bank account numbers and routing information
  • Credit or debit card information
  • Cryptocurrency wallet addresses
  • Payment processor account details
  • Transaction history and account balances
  • Investment portfolio information
  • Source of funds documentation
  • Income and net worth information (for compliance purposes)

1.3 Technical and Usage Information

When you access and use our Platform, we automatically collect:

  • IP address and geolocation data
  • Device information (device type, operating system, browser type and version)
  • Unique device identifiers
  • Log data (access times, pages viewed, actions taken)
  • Cookies and similar tracking technologies
  • Clickstream data and navigation patterns
  • Performance and diagnostic data

1.4 Communications and Correspondence

  • Customer support inquiries and responses
  • Email correspondence
  • Chat messages and transcripts
  • Survey responses and feedback
  • User-generated content and reviews

1.5 Information from Third-Party Sources

We may receive information about you from third-party sources, including:

  • Identity verification and KYC service providers
  • Credit bureaus and fraud prevention agencies
  • Payment processors and financial institutions
  • Public databases and government registries
  • Marketing and analytics partners
  • Social media platforms (if you choose to link accounts)
2

HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

2.1 Account Creation and Management

  • Create and maintain your user account
  • Verify your identity and eligibility
  • Process registrations and authenticate users
  • Manage account security and access controls

2.2 Service Provision and Platform Operations

  • Provide access to Platform features and Services
  • Process deposits, withdrawals, and fund transfers
  • Execute investment transactions and portfolio management
  • Generate AI-powered trading signals and market analysis
  • Maintain and improve Platform functionality

2.3 Regulatory Compliance and Legal Obligations

  • Comply with Anti-Money Laundering (AML) and Know Your Customer (KYC) requirements
  • Conduct sanctions screening and counter-terrorist financing (CTF) checks
  • Prevent fraud, financial crimes, and prohibited activities
  • Respond to legal requests, court orders, and regulatory inquiries
  • Maintain records as required by applicable laws

2.4 Security and Fraud Prevention

  • Monitor for suspicious activities and unauthorized access
  • Detect and prevent security threats and cyberattacks
  • Protect against identity theft and account takeover
  • Investigate security incidents and policy violations

2.5 Communications and Customer Support

  • Respond to inquiries, support requests, and complaints
  • Send transactional notifications and account alerts
  • Provide important updates about Platform changes or policies
  • Deliver marketing communications (with your consent)

2.6 Analytics and Platform Improvement

  • Analyze user behavior and platform usage patterns
  • Improve user experience and interface design
  • Develop new features and services
  • Conduct research and statistical analysis
  • Optimize performance and troubleshoot technical issues
3

LEGAL BASIS FOR PROCESSING (GDPR/UK GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data based on the following legal grounds:

Contractual Necessity

Processing is necessary to perform our contract with you, including account creation, service provision, and transaction processing.

Legal Obligation

Processing is required to comply with applicable laws, regulations, and legal obligations, including AML/KYC requirements.

Legitimate Interests

Processing is necessary for our legitimate business interests, such as fraud prevention, security, analytics, and platform improvement, provided these interests are not overridden by your rights.

Consent

Where required by law, we obtain your explicit consent for certain processing activities, such as marketing communications. You may withdraw consent at any time.

4

INFORMATION SHARING AND DISCLOSURE

Important: We do NOT sell, rent, or trade your personal information to third parties for their marketing purposes. We only share information as described below.

We may share your information with:

4.1 Service Providers and Business Partners

Third-party vendors who provide services on our behalf, including:

  • Payment processors and banking partners
  • Identity verification and KYC/AML service providers
  • Cloud hosting and infrastructure providers
  • Customer support and communication platforms
  • Analytics and data processing services
  • Cybersecurity and fraud prevention providers

4.2 Financial Institutions

Banks, intermediary banks, correspondent banks, payment processors, and cryptocurrency exchanges necessary to process your transactions, deposits, and withdrawals.

4.3 Regulatory and Legal Authorities

Government agencies, regulatory bodies, law enforcement, and courts when required or permitted by law, including:

  • Compliance with legal obligations and regulatory requirements
  • Response to lawful requests, subpoenas, and court orders
  • Cooperation with investigations and enforcement actions
  • Protection of legal rights and prevention of illegal activities

4.4 Corporate Transactions

In connection with mergers, acquisitions, divestitures, restructuring, bankruptcy, or sale of assets, your information may be transferred to successor entities or acquirers.

4.5 Affiliates and Subsidiaries

Companies within the Captiros corporate family for business operations, analytics, and service provision purposes.

4.6 With Your Consent

Any other third parties with your explicit consent or at your direction.

5

DATA SECURITY

We implement robust technical, administrative, and physical security measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction, including:

Encryption

256-bit SSL/TLS encryption for data in transit and AES encryption for data at rest

Access Controls

Multi-factor authentication, role-based access controls, and principle of least privilege

Secure Infrastructure

Enterprise-grade cloud hosting with redundancy, firewalls, and intrusion detection

Monitoring

24/7 security monitoring, logging, and incident response procedures

Employee Training

Regular security awareness training and strict confidentiality obligations

Audits & Testing

Regular security audits, vulnerability assessments, and penetration testing

Important Notice: While we implement industry-leading security measures, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and should notify us immediately of any unauthorized access.

6

DATA RETENTION

We retain your personal information for as long as necessary to:

  • Provide Services and maintain your account
  • Comply with legal, regulatory, tax, and accounting obligations (typically 7-10 years for financial records)
  • Resolve disputes and enforce agreements
  • Prevent fraud and ensure security
  • Fulfill legitimate business purposes

After account termination or closure, we may retain certain information in archived or backup systems for the periods required by law or legitimate business purposes. Upon expiration of retention periods, we securely delete or anonymize personal information.

Typical Retention Periods: Active account data is retained for the duration of your account plus applicable legal retention periods. Transaction records are retained for 7-10 years. Marketing communications data is retained until you opt out. Technical logs are typically retained for 90 days to 2 years.

7

YOUR PRIVACY RIGHTS

Depending on your location, you may have the following rights regarding your personal information:

Right to Access

Request a copy of the personal information we hold about you

Right to Rectification

Correct inaccurate or incomplete information

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal information (subject to legal retention requirements)

Right to Restriction of Processing

Limit how we use your personal information

Right to Data Portability

Receive your personal information in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes

Right to Withdraw Consent

Withdraw previously given consent for processing activities

Right to Lodge a Complaint

File a complaint with your local data protection authority

How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: privacy@captirosai.com

Mail: Captiros Global Holdings Ltd., Data Protection Officer, Cannon Bridge House, 25 Dowgate Hill, London EC4R 2YA, United Kingdom

We will respond to your request within 30 days (or as required by applicable law). We may require verification of your identity before processing your request.

8

INTERNATIONAL DATA TRANSFERS

Captiros operates globally, and your personal information may be transferred to, stored, and processed in countries outside your country of residence, including the United Kingdom, European Economic Area, United States, and other jurisdictions where our service providers operate.

When we transfer personal information internationally, we implement appropriate safeguards to ensure adequate protection, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs)
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules for intra-group transfers
  • Vendor contractual obligations ensuring appropriate data protection

By using our Services, you acknowledge and consent to the international transfer of your personal information in accordance with this Privacy Policy.

9

COOKIES AND TRACKING TECHNOLOGIES

We use cookies, web beacons, pixels, and similar tracking technologies to enhance your experience, analyze platform usage, and deliver personalized content. Types of cookies we use include:

Essential Cookies

Necessary for platform functionality, security, and authentication. Cannot be disabled.

Performance Cookies

Collect analytics data about how you use the Platform to help us improve performance.

Functional Cookies

Remember your preferences and settings to provide enhanced features.

Marketing Cookies

Track your activity to deliver relevant advertising and measure campaign effectiveness.

You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may limit Platform functionality.

10

CHILDREN'S PRIVACY

Our Services are NOT intended for individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18 years of age.

If we become aware that we have collected personal information from a child under 18, we will take immediate steps to delete such information from our systems. If you believe we have collected information from a minor, please contact us immediately at privacy@captirosai.com.

11

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated through:

  • Email notification to your registered email address
  • Prominent notice on the Platform
  • In-app notifications

The "Last Updated" date at the top of this Privacy Policy indicates when the most recent changes were made. Your continued use of the Platform after changes become effective constitutes acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

CONTACT US

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

Captiros Global Holdings Ltd.

Cannon Bridge House, 25 Dowgate Hill

London EC4R 2YA, United Kingdom

Privacy Inquiries:

privacy@captirosai.com

General Inquiries:

legal@captirosai.com

EU/UK Data Protection Authority: If you are located in the European Economic Area or United Kingdom and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority or the UK Information Commissioner's Office (ICO).

CONSENT AND ACKNOWLEDGMENT

By accessing or using the Captiros Platform and Services, you acknowledge that you have read, understood, and agree to the collection, use, disclosure, and processing of your personal information as described in this Privacy Policy.

GDPR Compliant
Data Encrypted
Privacy First

© 2021-2026 Captiros Global Holdings Ltd. All rights reserved.