Privacy Policy

As of September 2026

IN SUMMARY: Luso Digital Assets (hereinafter, "Luso") uses the data necessary to provide and protect the Services, to identify Customers, and to comply with legal obligations. Some Services are provided by partners who may process data on their own behalf. Transactions on public blockchain networks are, by their nature, visible and cannot be deleted by Luso. Data subjects may exercise their rights under the GDPR by contacting legal@lusodigitalassets.com. The following sections explain each type of data processing in detail.

1. Introduction and Identification

This Privacy Policy explains how Luso, a legal entity headquartered at Rua Princesa D. Amélia, No. 20 L, 9000-019 Funchal, Portugal, collects, uses, stores, shares, and protects personal data in connection with the Website, the Platform, and the services provided directly or accessible through third-party partners.

For processing operations whose purposes and means are determined by Luso, Luso acts as the data controller, in accordance with Regulation (EU) 2016/679 of April 27, 2016 ("GDPR"), Law No. 58/2019 of August 8, and other applicable legislation.

This Policy is provided for informational purposes only. Its availability or a statement that the user has taken note of its content does not constitute general consent to data processing. Whenever processing is based on consent, consent will be requested in a specific, free, informed, and unambiguous manner, and may be withdrawn at any time.

2. Scope of Application and Recipients

This Policy applies to customers, potential customers, visitors to the Website, users of the Platform, representatives, attorneys-in-fact, employees, officers, partners, and beneficial owners of corporate customers, beneficiaries or counterparties to transactions, and any other individuals whose data is processed in connection with the Services.

The Website, the Platform, and the Services are not intended for individuals under the age of 18; therefore, Luso does not intentionally allow minors to create accounts. If Luso becomes aware that it has processed a minor's data without an appropriate legal basis, it will take the necessary measures to delete or anonymize such data, without prejudice to any legal obligations regarding data retention.

This Policy should be read in conjunction with the Terms and Conditions, the Cookie Policy, the specific notices presented during onboarding, and, where applicable, the privacy policies of partners who provide services on their own behalf.

3. Role of Luso and Partner Entities

The Platform integrates its own services and services provided by third parties. The entity that determines the purposes and means of each processing operation is responsible for compliance with the GDPR. The presentation of a service within an integrated experience does not, in and of itself, alter the responsibility of each entity.

Luso as the data controller: Luso determines the purposes and means, specifically, for account management and the contractual relationship, customer support, Platform security, the AML/CFT procedures it conducts, compliance with its legal obligations, complaint management, and its own communications.

Processors: Certain suppliers process data solely on behalf of and in accordance with Luso's documented instructions, including providers of cloud hosting, IT infrastructure, cybersecurity, communications, technical support, identity verification, or analytics, to the extent that they do not determine their own purposes. These suppliers are bound by contract, confidentiality obligations, and appropriate security measures.

Independent Data Controllers: Some partners process data to comply with their own legal obligations or to provide services directly to the Customer. This applies to financial institutions, payment service providers, crypto-asset service providers, public authorities, and other regulated partners, to the extent that they act on their own behalf. In such cases, the privacy policy of the entity in question also applies.

Joint controllership: If Luso and another entity jointly determine the purposes and means of data processing, specific information will be provided regarding joint controllership and the essential elements of the agreement entered into between the entities, including the point of contact for exercising rights.

3.1. Integrated Services and APIs

When a Service is made available on a white-label basis, through an embedded integration, application programming interface (API), or joint digital pathway, Luso will identify, at the appropriate time, the entity with which the Customer enters into a contract and the role of each party involved in data processing. The use of Luso's brand, domain, or interface does not necessarily mean that all processing is determined exclusively by Luso.

Luso will maintain up-to-date information on the Website or within the Service regarding the main partners that receive data as independent data controllers. If an integration materially changes the identity of the data controller, the purposes, or the recipients, the Customer will be informed before the new processing takes place, unless the law permits or requires otherwise.

4. Collection of Personal Data

In compliance with the obligation to take appropriate measures to provide concise, transparent, legible, and easily accessible information regarding data processing, please review the table below for more information on this topic.

Depending on the service used and the capacity in which the individual is involved, Luso may process the following categories of data:

Identification data: first name, last name, date and place of birth, age, gender when necessary, nationality, signature, photograph, username, civil and tax identification numbers, copy of identification document, and its validity details.

Contact data: residential and tax address, email address, phone number, and other contact information provided.

Professional and corporate data: occupation, employer, economic activity, position, powers of representation, equity interests, ownership and control structure, directors, representatives, attorneys-in-fact, partners, and beneficial owners.

AML/CFT and risk data: purpose and nature of the business relationship, source and destination of funds, source of assets, income, financial situation, information on politically exposed persons and public office holders, sanctions, adverse news, verification results, risk classification, and supporting documentation.

Financial and payment data: IBAN, bank or payment account identification, banking institution, information required for deposits, withdrawals, payments, refunds, and billing.

Cryptoasset and transaction data: wallet addresses, account identifiers, transaction hash, type and quantity of assets, currency, amount, date and time, blockchain network, fees, origin and destination, payer, payee, counterparty, and information required for transfers of funds or cryptoassets.

Account and profile data: account credentials and identifiers, preferences, applicable limits, account status, usage history, interactions with features, feedback, and survey responses.

Technical and security data: IP address, device identifiers, operating system, browser, time zone, language, access and activity logs, security events, authentication, access attempts, incident information, and data necessary for fraud prevention.

Communication and support data: messages, calls (when legally recorded), requests, complaints, documents submitted, contractual communications, contact preferences, and customer support history.

Marketing and usage data: consents, opt-outs, communication preferences, interaction with communications, browsing data, and cookies or similar technologies, as set forth in the Cookie Policy.

Succession and representation data: information regarding death, certificates, proof of heirs status, powers of attorney, identification and contact information for heirs, heads of household, representatives, and other interested parties.

Luso does not seek to collect data regarding health, racial or ethnic origin, religion, sex life, or sexual orientation, unless such information is provided incidentally and unsolicited or there is a specific legal basis for doing so. Data that is not necessary will be deleted or masked whenever possible.

Throughout the business relationship, we may request additional documentation to comply with legal obligations. This additional evidence may include, but is not limited to, documents necessary to verify any information provided or proof of the origin of the client's funds and/or wealth. When a remote identity verification procedure uses a photograph, video, or proof of life, specific information will be provided, and the conditions and safeguards set forth in the GDPR and applicable legislation will be applied.

In compliance with obligations regarding the prevention of money laundering, terrorist financing, fraud, sanctions, and other illegal activities, Luso may process information regarding suspected violations, reports to authorities, convictions, security measures, fines, or sanctions, in accordance with the GDPR and Law No. 83/2017 of August 18, as currently in force.

5. Source of Personal Data

Luso may obtain personal data from the following sources:

  • directly from the data subject, through onboarding, forms, contracts, communications, support requests, and account usage;
  • automatically, through the Website, the Platform, the devices used, activity logs, and cookies or similar technologies;
  • from representatives, attorneys-in-fact, client entities, beneficial owners, heirs, counterparties, payors, payees, or other parties involved in a transaction;
  • from technology partners, KYC providers, fraud prevention entities, financial institutions, payment or crypto-asset service providers, and other partners involved in the provision of the service;
  • from public or legally accessible sources, including commercial registries, beneficial owner databases, sanctions and PEP lists, public decisions, news reports, search engines, and information recorded on public blockchain networks;
  • from judicial, law enforcement, tax, regulatory, supervisory authorities, or other legally authorized entities.

When data is not obtained directly from the data subject, Luso will provide the information required under the GDPR within the applicable timeframes, unless a legal exception applies, namely when providing the information is impossible, disproportionate, or legally prohibited.

6. Purposes and Legal Bases

Luso processes only data that is adequate, relevant, and limited to what is necessary for the purposes set forth below. The same data may be used for more than one purpose, provided there is a legal basis applicable to each processing activity.

Purpose

Main Categories

Onboarding, eligibility assessment, and account creation

Identification, contact information, professionals, corporate information, account, and supporting documentation.

Management of the contractual relationship and provision of Services

Account, profile, identification, contact information, financial data, transactions, technical data, communications, and preferences.

Provision of the non-custodial wallet, swaps, DeFi, and integrations

Wallet addresses, transactions, network, authentication, technical data, and account data.

Access to Partner Services

Identification, contact information, financial data, account, transactions, and legally required information.

AML/CFT, Sanctions, Fraud Prevention, and Risk Assessment

Identification, contact information, professional data, corporate data, financial data, source of funds and assets, PEPs, sanctions, adverse news, transactions, risk, violations, and supporting evidence.

Information Accompanying Transfers and Verification of Self-Hosted Wallets

Payer, payee, distributed address, account, document, address, date and place of birth, LEI, and transfer details.

Security, Authentication, Incident Prevention, and Response

Technical data, device, access, events, authentication, communications, transactions, and fraud indicators.

Support, complaints, audits, supervision, and rights protection

Identification, contact information, communications, account, transactions, documents, complaints, and information necessary for the process.

Tax compliance and reporting of cryptoassets, including DAC8/CARF

Tax identification, residency, tax ID number, entity, controlling persons, transactions, assets, and amounts subject to reporting.

Contractual and Operational Communications

Name, contact information, account, service status, security, and contractual information.

Marketing of Luso Products or Services

Identification, contact information, customer relationship, preferences, consent, opt-out, and interaction with communications.

Analysis, improvement, and development

Usage data, technical data, feedback, surveys, and aggregated or anonymized data.

Death, succession, representation, and inactive accounts

Identification, contact information, account information, certificates, authorization, powers of attorney, transactions, and communications.

Corporate restructuring or change of control

Data strictly necessary for the contractual relationship, account information, contact information, and outstanding obligations.

Purpose Limitation for AML/CFT: Data processed pursuant to anti-money laundering and counter-terrorism financing legislation shall not be used, on that basis, for incompatible commercial purposes.

7. Mandatory Nature of Data and Consequences of Failure to Provide It

Some data is necessary to enter into and perform the contract; other data is required by law. When data is mandatory, Luso will indicate this at the time of collection.

The absence, inaccuracy, or insufficiency of data may prevent the opening of an account or access to a particular service, delay or prevent a transaction, result in the application of limits, enhanced due diligence measures, suspension, or closure of the account, or require a report to authorities when required by law.

Data used solely for marketing, non-essential cookies, surveys, or other optional features is not a condition for contracting the Services.

8. Recipients and Data Sharing

Luso only uses the user's personal data when permitted by law. Data will only be disclosed when necessary, proportionate, and legally permitted, and may be shared with the following recipients:

  • Regulated partners that directly provide EMT, payment, banking, or cryptoasset services, acting as independent data controllers when processing data for their own purposes and obligations;
  • Providers of wallet infrastructure, cloud services, hosting, databases, authentication, communications, support, cybersecurity, identity verification, risk analysis, fraud prevention, and blockchain analysis, acting as data processors or independent data controllers depending on the specific service;
  • Financial institutions, payment service providers, crypto-asset service providers, and counterparty entities necessary for the execution or traceability of transfers;
  • Aggregators, decentralized protocols, and blockchain networks with which the Customer chooses to interact through the Platform, taking into account the public or decentralized nature of such infrastructures;
  • Consultants, auditors, certified public accountants, insurance companies, attorneys, and other professional service providers bound by confidentiality;
  • Bank of Portugal, the Portuguese Securities Market Commission, the Tax and Customs Authority, the Financial Intelligence Unit, the Central Department of Investigation and Criminal Prosecution, judicial, law enforcement, regulatory, and supervisory authorities, or other competent public entities;
  • Potential acquirers, investors, or advisors in the context of a merger, acquisition, financing, reorganization, or change of control, subject to confidentiality and data minimization.

When a recipient is an independent data controller, Luso has no control over the timelines and decisions adopted by that entity in the performance of its own obligations. When the recipient acts as a data processor, Luso remains responsible for selecting the service provider, entering into the contract required by the GDPR, and issuing appropriate instructions, including regarding the exercise of rights and the erasure of data.

Does the user have to inform Luso of any changes to their personal data?

It is important that the personal data processed by Luso remain accurate, complete, and up-to-date. To that end, the user must inform Luso whenever changes occur to their personal data during the term of their relationship with Luso.

As the data subject, you also have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning you, as well as the completion of incomplete personal data, including by submitting a supplementary statement.

9. Blockchain Networks and Decentralized Protocols

Public blockchain networks record information such as wallet addresses, identifiers, and transaction details in a distributed manner. This information is accessible to anyone, and although it is typically pseudonymous, it may constitute personal data when it can be linked to an identified or identifiable individual.

Luso does not control public networks and cannot delete, alter, or reverse data that has been confirmed on them. The exercise of rights will therefore be accommodated with respect to the systems and copies under Luso's control, but may not allow for the deletion of a validated record on a blockchain. Whenever possible, Luso will take measures such as limiting internal links between the Customer's identity and public addresses, subject to legal obligations regarding data retention and traceability.

10. International Data Transfers

Luso prioritizes the processing and storage of data within the European Economic Area ("EEA"). However, certain suppliers, partners, counterpart entities, or technology networks may be located in or allow access from third countries.

When Luso is responsible for an international transfer, it will ensure that a valid legal basis exists, namely an adequacy decision by the European Commission, standard contractual clauses, applicable binding rules, or a legal exemption, supplemented, when necessary, by an assessment of the level of protection and additional technical or organizational measures.

The data subject may request information about the applicable mechanism and, where permitted, a copy of the relevant safeguards by contacting legal@lusodigitalassets.com. The transmission of information in the context of cryptoasset transfers to service providers established outside the Union will only occur when the requirements of the GDPR and applicable legislation can be met.

11. Data Retention

Luso retains data only for as long as necessary to fulfill the purposes for which it was collected, taking into account legal obligations, the duration of the contractual relationship, the need for evidence, statutes of limitations, the existence of disputes or investigations, and the principles of data minimization and retention limitation.

Category/Purpose

Retention Period or Criteria

Account, Contract, and Provision of Services

During the term of the contractual relationship and, after its termination, for the period necessary to fulfill obligations and to assert, exercise, or defend rights, in accordance with applicable legal time limits.

AML/CFT and relationship documentation

Seven years after the Customer's identification or, in the case of a business relationship, after its termination, pursuant to Law No. 83/2017, without prejudice to any additional retention periods required by law.

AML/CFT Documents and Transaction Records

Seven years from the execution of the transaction, even if the business relationship has ended, without prejudice to any pending proceedings or investigations.

Information Accompanying Transfers—Travel Rule

Five years in accordance with Regulation (EU) 2023/1113, without prejudice to any additional retention periods required by national law, particularly when such information forms part of the AML/CFT records subject to a seven-year retention period.

DAC8/CARF, when Luso is the reporting entity

Ten years from the end of the relevant reporting period, pursuant to Law No. 26/2026 of June 3.

Tax, accounting, and billing data

For the retention periods established in applicable tax and accounting legislation.

Complaints, audits, and disputes

Until final resolution and, thereafter, for the period necessary to prove and defend rights or comply with legal requirements.

Technical and security records

For the period defined in the internal retention policy, commensurate with the security purpose, which may be extended in the event of an incident, investigation, fraud, or legal obligation.

Marketing

Until consent is withdrawn or the right to object is exercised. Luso may retain a minimal record of the withdrawal or objection to ensure compliance and demonstrate compliance.

Potential customers and inquiries without a contract

For the period necessary to respond to and follow up on the inquiry, after which the data will be deleted or anonymized in accordance with the internal retention policy, unless consent is provided or there is a basis for further retention.

Cookies and analytics data

For the periods specified in the Cookie Policy and in the consent management mechanism.

Once the applicable retention periods have expired, the data will be securely deleted or anonymized, unless it must be retained due to judicial or administrative proceedings, an investigation, an order from an authority, or another legal obligation.

12. Data Security

Luso implements technical and organizational measures appropriate to the risk, designed to ensure the confidentiality, integrity, availability, and resilience of its systems and services, as well as to prevent the destruction, loss, alteration, disclosure, or unauthorized access to personal data.

These measures may include access control based on a need-to-know basis, multi-factor authentication, encryption in transit and, where applicable, at rest, segregation of environments, event logging and monitoring, backups, vulnerability management, business continuity, incident response, training, confidentiality, and vendor assessment.

The technological infrastructure relies on cloud infrastructure providers, whose use is subject to configuration, contracts, risk assessment, and appropriate security measures. No system offers absolute security; for this reason, Luso maintains procedures for prevention, detection, response, and recovery, and will notify the CNPD and data subjects when required by law.

13. Profiling and Automated Decisions

Luso may use automated tools to support identity verification, fraud detection, blockchain analysis, transaction monitoring, alert triage, limit enforcement, and risk classification. These processing activities may involve profiling to assess risks of fraud, money laundering, terrorist financing, sanctions, security, or misuse.

Whenever a decision produces legal effects or significantly affects the data subject, Luso will not rely exclusively on automated processing without a legal basis and appropriate safeguards. Where applicable, the data subject may request human intervention, present their point of view, and challenge the decision. Information about the logic used will be provided in a meaningful manner, without compromising trade secrets, security, or mechanisms for preventing illegal acts.

14. Users' Legal Rights

Under applicable law, the data subject may exercise the following rights:

Access: to obtain confirmation regarding the processing of their data, access their data, and receive the information required by law.

Rectification: to correct inaccurate data and complete incomplete data.

Erasure: request the deletion of data when the legal conditions are met, without prejudice to retention obligations and the limitations inherent in public blockchain networks.

Restriction: request the suspension or restriction of processing in the situations provided for in the GDPR.

Objection: object, on grounds related to their particular situation, to processing based on legitimate interest. In direct marketing, the right to object may be exercised at any time, free of charge, and without the need to provide a justification.

Portability: to receive or transmit to another controller the data provided by the data subject, in a structured, commonly used, and machine-readable format, when the processing is based on consent or a contract and is carried out by automated means.

Withdrawal of Consent: to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.

Automated decisions: not to be subject to a decision based solely on automated processing that produces significant legal or similar effects, except where legally permitted and accompanied by safeguards.

Complaint: to file a complaint with the CNPD or another competent supervisory authority, without prejudice to other administrative or judicial remedies.

15. Exercising Rights

Requests must be sent to legal@lusodigitalassets.com, specifying the right you wish to exercise and providing sufficient information to locate the data. Luso may request additional information strictly necessary to verify your identity and prevent unauthorized disclosure.

Exercising these rights is free of charge. When a request is manifestly unfounded or excessive, particularly due to its repetitive nature, Luso may charge a reasonable fee that reflects the administrative costs or refuse to comply, providing a justification for the decision.

Luso will respond without undue delay and, as a general rule, within one month of receipt. This period may be extended by two months when necessary, taking into account the complexity and number of requests. The data subject will be informed of the extension and the reasons for it within one month.

Certain rights may be limited by law, particularly to protect investigations, reports of suspicious transactions, confidentiality obligations, the rights of third parties, or AML/CFT obligations. Where legally permitted, Luso will explain the limitation and the available remedies.

16. Marketing Communications and Cookies

Luso will only send electronic marketing communications when there is a valid legal basis to do so. When there is no prior customer relationship or when the communication concerns products or services different from those previously purchased, prior consent will be requested.

In the context of a customer relationship, Luso may promote its own products or services similar to those purchased, in accordance with Law No. 41/2004, ensuring that the Customer has the option to opt out at the time of data collection and in each communication. Opting out is free of charge and can be done via the link provided in the message or by contacting Luso.

Luso will not disclose data to third parties for their own marketing purposes without specific consent or another independent legal basis that has been duly communicated. The use of analytical or advertising cookies or other technologies that are not strictly necessary, including Google Analytics when used, depends on consent managed through the cookie mechanism. For more information, see the Cookie Policy.

17. Changes to the Policy

The Policy may be updated to reflect changes in laws, regulations, technology, operations, partners, or Services. The updated version will be posted on the Website with an indication of the effective date. When the change is material, Luso will take reasonable steps to provide prior notice or request new consent, if the modified processing depends on it.

18. Complaints

Data subjects are encouraged to contact Luso in advance at legal@lusodigitalassets.com so that Luso can review and respond to the matter. This does not affect the right to file a complaint at any time with the National Data Protection Commission ("NDPC") or with the competent supervisory authority in the Member State of permanent residence, place of work, or location of the alleged infringement.

NDPC - National Data Protection Commission: www.cnpd.pt

19. Contact Information

Data Controller: Luso Digital Assets, Lda.

Headquarters: Rua Princesa D. Amélia, n.º 20 L, 9000-019 Funchal, Portugal.

General contact for privacy matters:legal@lusodigitalassets.com.

DPO Contact:dpo@lusodigitalassets.com

Data subjects may contact Luso through the Compliance Department or the respective Data Protection Officer for any questions related to the processing of their personal data, as well as to exercise the rights set forth in this Privacy Policy and in applicable data protection laws.