Draft framework · not in force

Privacy Policy

A review framework for the disclosures, operational facts, and jurisdiction-specific decisions required by Bitfoo’s final privacy policy.

Review status: Awaiting legal review

1. Scope and responsible entity

Identify who controls personal information, which websites and services are covered, and where the policy applies.

Information required before approval:

  • Verified Bitfoo legal entity name and address
  • Services and customer groups within scope
  • Privacy contact and escalation route

2. Information collected

Describe information collected directly, generated through service use, or received from approved providers.

Information required before approval:

  • Account, identity, billing, and support fields
  • Website, portal, server, security, and diagnostic logs
  • Domain-registration data and any registrar-required disclosures

3. Purpose and legal basis

Connect every category of information with a specific operational, contractual, security, or legal purpose.

Information required before approval:

  • Service delivery and account administration
  • Billing, fraud prevention, security, and support
  • Marketing choices and applicable consent or opt-out rules

4. Processors and disclosures

Explain which provider categories receive information and why.

Information required before approval:

  • Payment, domain, infrastructure, email, analytics, and support providers
  • Cross-border processing and transfer safeguards
  • Legal requests, business transfers, and abuse investigations

5. Retention and deletion

Define how long each material information category is retained and what happens after account closure.

Information required before approval:

  • Operational and backup retention schedules
  • Billing and legal record requirements
  • Deletion, anonymization, and restoration-window behavior

6. Privacy rights

Describe available access, correction, deletion, objection, restriction, portability, and complaint processes where applicable.

Information required before approval:

  • Identity-verification procedure
  • Jurisdiction-specific rights and response periods
  • Regulator or supervisory-authority information

7. Cookies and similar technologies

Inventory essential, preference, analytics, marketing, and third-party technologies used by the site and portal.

Information required before approval:

  • Actual cookie and local-storage inventory
  • Consent requirements and preference controls
  • Analytics configuration and retention

8. Security and incident handling

Describe safeguards at an appropriate level without making guarantees or publishing sensitive control detail.

Information required before approval:

  • Approved organizational and technical control summary
  • Breach assessment and notification process
  • Customer security responsibilities

9. Policy changes and contact

Set the effective-date, change-notice, and privacy-enquiry process.

Information required before approval:

  • Approved effective date and version history
  • Material-change notification method
  • Verified privacy contact details