Draft framework · not in force
Privacy Policy
A review framework for the disclosures, operational facts, and jurisdiction-specific decisions required by Bitfoo’s final privacy policy.
Review status: Awaiting legal review
1. Scope and responsible entity
Identify who controls personal information, which websites and services are covered, and where the policy applies.
Information required before approval:
- Verified Bitfoo legal entity name and address
- Services and customer groups within scope
- Privacy contact and escalation route
2. Information collected
Describe information collected directly, generated through service use, or received from approved providers.
Information required before approval:
- Account, identity, billing, and support fields
- Website, portal, server, security, and diagnostic logs
- Domain-registration data and any registrar-required disclosures
3. Purpose and legal basis
Connect every category of information with a specific operational, contractual, security, or legal purpose.
Information required before approval:
- Service delivery and account administration
- Billing, fraud prevention, security, and support
- Marketing choices and applicable consent or opt-out rules
4. Processors and disclosures
Explain which provider categories receive information and why.
Information required before approval:
- Payment, domain, infrastructure, email, analytics, and support providers
- Cross-border processing and transfer safeguards
- Legal requests, business transfers, and abuse investigations
5. Retention and deletion
Define how long each material information category is retained and what happens after account closure.
Information required before approval:
- Operational and backup retention schedules
- Billing and legal record requirements
- Deletion, anonymization, and restoration-window behavior
6. Privacy rights
Describe available access, correction, deletion, objection, restriction, portability, and complaint processes where applicable.
Information required before approval:
- Identity-verification procedure
- Jurisdiction-specific rights and response periods
- Regulator or supervisory-authority information
7. Cookies and similar technologies
Inventory essential, preference, analytics, marketing, and third-party technologies used by the site and portal.
Information required before approval:
- Actual cookie and local-storage inventory
- Consent requirements and preference controls
- Analytics configuration and retention
8. Security and incident handling
Describe safeguards at an appropriate level without making guarantees or publishing sensitive control detail.
Information required before approval:
- Approved organizational and technical control summary
- Breach assessment and notification process
- Customer security responsibilities
9. Policy changes and contact
Set the effective-date, change-notice, and privacy-enquiry process.
Information required before approval:
- Approved effective date and version history
- Material-change notification method
- Verified privacy contact details