1.1. This Personal Data Processing Policy (hereinafter referred to as the "Policy") has been prepared in accordance with applicable personal data protection standards and governs the collection, processing, storage, and protection of personal data of users of the website https://otc.cardex.online/ (the "Website") by Cardex (hereinafter referred to as the "Company" or the "Controller").

1.2. By using the Website, the User agrees to the terms of this Policy.

1.3. The Company reserves the right to update this Policy. The current version is always available on the Website and indicates the date of the latest update.
1. General Provisions
Privacy Policy
7.3. The User may disable cookies at any time through their browser settings. Disabling strictly necessary cookies may impair the functionality of the Website.
For any questions regarding this Privacy Policy, please contact:
Email: marketer@xcomp.team
11. Contact Information
10.1. The Website and the Company's services are intended solely for individuals who:
-Are at least 18 years of age; and
-Possess full legal capacity under applicable law.

10.2. The Company does not knowingly collect personal data from minors. If such data is identified, it will be deleted without undue delay. If you are a parent or legal guardian and believe that your child has provided personal data to the Company, please contact us using the contact details provided in Section 11 of this Policy.
10. Age Restrictions
8.1. The Company implements organizational and technical measures to protect personal data, including:
-SSL/TLS encryption of transmitted data;
-Access control restrictions;
-Regular security monitoring and audits;
-Employee training on data protection requirements.

8.2. The Company takes all reasonable organizational and technical measures to prevent unauthorized access, disclosure, alteration, or destruction of Users' personal data.

8.3. In the event of a personal data breach, the Company shall promptly take measures to:
-Contain and remediate the incident, including restoring system integrity and eliminating its causes;
-Notify affected Users and competent supervisory authorities where required by applicable law.
8. Data Security
6.1. The Company does not sell or disclose Users' personal data to third parties for commercial purposes.

6.2. Personal data may be disclosed in the following cases:
-Service Providers
-The Company may engage trusted contractors (including technical service providers, hosting providers, and analytics providers) to support the operation of the Website. Such contractors process personal data solely on behalf of the Company and under data processing agreements.
-Legal Requirements
-Personal data may be disclosed to competent governmental authorities where required by applicable law, including for compliance with AML/CFT obligations.
-Corporate Transactions
-In the event of a merger, acquisition, reorganization, or other corporate restructuring, personal data may be transferred to the legal successor, provided that all obligations regarding data protection remain in force.

6.3. The Company uses servers operated by trusted service providers. Personal data may be processed on servers located outside the User's country of residence. In addition, the Company may transfer Personal Data to its affiliates, partners, and service providers located in various countries worldwide.

6.4. Where Personal Data is processed on servers outside the User's country of residence or transferred to third countries or international organizations, the Company implements appropriate technical, organizational, and contractual safeguards to ensure the protection of Personal Data. Such safeguards are intended to ensure compliance with applicable data protection laws and maintain an adequate level of protection in accordance with this Policy.
6. Disclosure of Data to Third Parties
5.1. Personal data submitted through inquiries and requests is retained for as long as necessary to fulfill the relevant request and no longer than three (3) years from the last interaction with the User, unless otherwise required by applicable law.

5.2. Data required to comply with AML/KYC obligations is retained for at least five (5) years following the end of the business relationship in accordance with FATF standards and applicable legislation.

5.3. Technical data (logs and cookie data) is retained for no longer than twelve (12) months.
5. Data Retention
4.1. Where consent serves as the legal basis for processing, such consent is obtained in an informed, freely given, and explicit manner.

4.2. The User may withdraw consent at any time by sending a request to the email address specified in this Policy.

4.3. Withdrawal of consent to receive marketing communications does not affect the processing of data necessary for the performance of contractual obligations or compliance with legal requirements.

4.4. The Company may collect Personal Data through:
-Information provided directly by the User;
-Information collected automatically through tracking technologies;
-Information received from third parties;
-Information obtained from publicly available sources.
4. Obtaining Consent
2.1. When submitting an inquiry, application, or request through forms or other communication channels available on the Website, the Company may collect and process the following categories of data.

Contact Data (provided voluntarily)
-First and last name;
-Email address;
-Phone number;
-Message/request content;
-Any other information voluntarily provided by the User.

Automatically Collected Technical Data
-Device IP address;
-Browser type and version;
-Operating system;
-Information about pages visited and time of visit.
2. Data Collected
7.1. The Website uses cookies and similar technologies to ensure proper functionality, analyze website traffic, and improve the user experience.

7.2. Categories of cookies used:
7. Cookies
Remembering User preferences
9.1. In accordance with applicable law, each User shall have the following rights:

9.1.1. Right of Access. The User has the right to obtain confirmation as to whether the Company processes their personal data and, where such processing takes place, to obtain access to and a copy of such personal data.

9.1.2. Right to Rectification. The User has the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

9.1.3. Right to Erasure ("Right to be Forgotten"). The User has the right to submit a written request to the Company for the deletion of specific personal data. Such request shall be considered subject to applicable data retention requirements under applicable law. In certain circumstances, personal data may not be deleted where their retention is necessary for the Company to comply with its legal obligations.

9.1.4. Right to Restriction of Processing. The User has the right to request the restriction of the processing of their personal data. Such restriction may apply, inter alia, where the User contests the accuracy of the personal data or the lawfulness of the processing.

9.1.5. Right to Data Portability. The User has the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit such data to another controller without hindrance from the Company.

9.1.6. Right to Object to Processing. The User has the right to object to the processing of their personal data where the Company cannot demonstrate compelling legitimate grounds for such processing or where the processing is carried out for direct marketing purposes.

9.1.7. Right to Withdraw Consent. The User has the right to withdraw their consent to the processing of their personal data at any time. In such event, the Company may be unable to provide certain products or services.

9.2. To exercise any of the foregoing rights, the User may contact the Company using the contact details specified in this Policy. The Company shall respond as soon as reasonably practicable. Where additional time is required to process the request, the Company shall notify the User in writing of the expected timeframe for consideration of the request.
9. Data Subject Rights
Website traffic statistics (Google Analytics and similar services) Functional
Website functionality and authentication
Purpose:
Functional
Analytics
Strictly Necessary (Technical)
Type:
Legal obligation
Legitimate interest
Consent
Legal obligation
Performance of a contract;
Legal obligation
Legal Basis (GDPR):
Compliance with regulatory requirements
Technical operation of the Website
Sending advertising and marketing materials
Compliance with AML/KYC/Compliance requirements
User identification to provide access to services
Purpose of Processing:
3.1. Personal data is processed for the following purposes:
3. Purposes and Legal Bases for Processing
We use cookies to ensure the Website functions properly, remember your preferences, and improve your browsing experience. By continuing to use the Website, you agree to the use of cookies in accordance with our Privacy Policy.
Accept