LYNXFUSE Logo
LYNXFUSE

Privacy Policy

July 12, 2026

1. Introduction

LynxFuse Technology Co., Ltd. ("LynxFuse", "we", "us", "our", or "Service Provider") places great importance on the protection of the personal data of its users ("you", "your", or "User"). This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use LynxFuse's services, which include: - Crypto Trading Platform (Digital Asset Exchange Platform) - Digital Wallet / Crypto Wallet - AI Automation Services - Customer Relationship Management (CRM) System - Payment Processing Services This Policy has been prepared to comply with the Personal Data Protection Act B.E. 2562 (PDPA) of Thailand and the General Data Protection Regulation (GDPR) of the European Union for users located in the European Economic Area (EEA).

2. Information We Collect

We collect the following data:

2.1 Personal Data You Provide

| Data Category | Details | |---|---| | **Identity Data** | Full name, National ID number, Passport, Date of birth, Nationality | | **Contact Data** | Email address, Telephone number, Registered home address | | **Financial Data** | Bank account numbers, Digital wallet addresses, Transaction history, Asset deposit and withdrawal records | | **KYC (Know Your Customer) Data** | Photographs of ID card/passport, Selfie with ID card, Proof of address, Source of Funds, Financial status verification information | | **Authentication Data** | Account information, Hashed passwords, Biometric data (if applicable), Two-Factor Authentication (2FA) data | | **Communication Data** | Customer support conversation records, Feedback, Survey responses |

2.2 Automatically Collected Data

| Data Category | Details | |---|---| | **Device Data** | Device type, Operating system, Browser version, IP address, Language preference, Timezone | | **Usage Data** | Pages visited, Clicks, Session duration, Order history, Login records, Trading patterns | | **Geolocation Data** | Approximate location derived from IP address (for security screening and legal compliance) | | **Security Data** | List of trusted devices, Login history, Usage anomalies, Blocked IP addresses |

2.3 Information from Third Parties

We may receive information from: - **Credit Bureaus** — for financial status verification - **Government and Official Databases** — for AML/CFT (Anti-Money Laundering / Countering Financing of Terrorism) screening - **Identity Verification Providers** — for KYC verification - **Blockchain Explorers** — for transaction data on public blockchain networks

3. Purposes of Collection and Processing

We collect and use your personal data for the following purposes: | Purpose | Legal Basis (PDPA) | Legal Basis (GDPR) | |---|---|---| | **To provide services and perform the contract** — Account opening, trading, deposit and withdrawal of assets | Necessary for service provision (Contract) | Performance of a Contract (Art. 6(1)(b)) | | **To comply with legal obligations** — KYC, AML/CFT, reporting to regulatory authorities | Necessary for legal compliance (Legal Obligation) | Legal Obligation (Art. 6(1)(c)) | | **To prevent fraud and maintain security** — Fraud detection, suspicious transaction monitoring | Legitimate Interest | Legitimate Interest (Art. 6(1)(f)) | | **To improve services** — Data analysis, AI model development, user experience personalization | Consent or Legitimate Interest | Consent (Art. 6(1)(a)) or Legitimate Interest | | **For marketing and communications** — Sending news, special offers, educational content | Consent | Consent (Art. 6(1)(a)) | | **To comply with tax requirements** — Financial reporting, withholding tax | Necessary for legal compliance (Legal Obligation) | Legal Obligation (Art. 6(1)(c)) | | **For legal proceedings** — Dispute resolution, enforcement of legal rights | Legitimate Interest | Legitimate Interest (Art. 6(1)(f)) |

4. Cookies & Tracking Technologies

4.1 Types of Cookies We Use

LynxFuse uses cookies and similar technologies to enhance your user experience: | Cookie Type | Purpose | Retention Period | |---|---|---| | **Strictly Necessary Cookies** | Basic website functionality such as login, security, page loading | Session or persistent up to 12 months | | **Performance Cookies** | Website usage analytics, visitor counts, popular pages | Up to 24 months | | **Functional Cookies** | Remembering user preferences, language, region | Up to 12 months | | **Targeting/Advertising Cookies** | Displaying relevant advertisements, measuring ad performance | Up to 24 months (subject to consent) |

4.2 Cookie Management

You can manage your cookie settings through: - The **Cookie Consent Banner** displayed upon your first visit - **Browser Settings** to block or delete cookies - The **Cookie Preferences Center** in your LynxFuse account > **Note:** Disabling strictly necessary cookies may prevent you from using certain LynxFuse services.

4.3 Other Tracking Technologies

We may use the following technologies: - **Web Beacons / Pixel Tags** — for tracking email opens and page usage - **Local Storage / Session Storage** — for storing browser preference data - **Analytics Tools** — such as Google Analytics 4 (anonymized), Mixpanel, Amplitude - **Fingerprinting** — for fraud detection and prevention of duplicate accounts (necessary for security)

5. Data Sharing with Third Parties

5.1 Data Processors

We share only the necessary data with service providers under Data Processing Agreements (DPA): | Third Party | Purpose | Country | |---|---|---| | **Cloud Infrastructure Providers** (AWS, Google Cloud) | System hosting and data storage | Thailand, Singapore, United States | | **KYC/AML Service Providers** (e.g., Sumsub, Jumio, Onfido) | Identity verification and AML screening | Thailand, Singapore, EU | | **Payment Processors** | Fund transfers, banking connectivity | Thailand | | **Blockchain Analytics Providers** (e.g., Chainalysis, Elliptic) | Suspicious transaction monitoring | United States, EU | | **AI/ML Service Providers** | AI model development (using de-identified data) | Thailand, Singapore | | **CRM and Communication Providers** (e.g., Intercom, SendGrid) | Customer service and email delivery | United States, EU | | **Auditors** | Financial and compliance auditing | Thailand |

5.2 Legal Disclosures

We may disclose your personal data if: - **Required by law** — pursuant to a court order, or an order from a regulatory authority (SEC Thailand, AMLO, Bank of Thailand) - **Harm prevention** — to protect the rights, safety, or property of LynxFuse, its users, or the public - **Corporate restructuring** — in the event of a merger, sale of business, or corporate reorganization

5.3 International Data Transfers

Where personal data is transferred to countries that may have data protection standards different from those of Thailand or the EU, we will implement appropriate safeguards as required by law, such as: - Entering into **Standard Contractual Clauses (SCCs)** under the GDPR - Verifying that the destination country has an adequate level of data protection (**Adequacy Decision**)

6. Your Rights under PDPA and GDPR

6.1 Rights under PDPA (Personal Data Protection Act B.E. 2562)

As a data subject, you have the following rights: | Right | Details | |---|---| | **Right to be Informed** | You have the right to be informed of the details regarding the collection, use, and disclosure of your personal data | | **Right of Access** | You have the right to request access to the personal data we hold about you and to request a copy thereof | | **Right to Rectification** | You have the right to request the correction of any personal data that is inaccurate, incomplete, or misleading | | **Right to Erasure (Right to be Forgotten)** | You have the right to request the deletion or destruction of your personal data, subject to the conditions prescribed by law | | **Right to Restrict Processing** | You have the right to request the restriction of processing of your personal data in certain circumstances | | **Right to Data Portability** | You have the right to receive your personal data in a commonly readable format and to have it transmitted to another data controller | | **Right to Object** | You have the right to object to the collection, use, or disclosure of your personal data | | **Right to Withdraw Consent** | Where we rely on consent as a legal basis for processing, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to such withdrawal |

6.2 Additional Rights under GDPR (For EEA Users)

If you are located in the European Economic Area (EEA), you have the following additional rights: | Right | Details | |---|---| | **Right to Lodge a Complaint** | You have the right to lodge a complaint with the data protection authority in your country | | **Right regarding Automated Decision-Making** | You have the right to request human review of decisions made solely by automated means that produce legal effects concerning you (including AI-based credit scoring or risk assessment) | | **Right to Object to Direct Marketing** | You have the right to object to the use of your data for direct marketing purposes |

6.3 Exercising Your Rights

You may exercise the above rights by: 1. Logging into your LynxFuse account and going to **Settings > Privacy & Data** 2. Submitting a request via the form at **https://lynxfuse.com/privacy/request** 3. Contacting our Data Protection Officer (DPO) at **[email protected]** We will process your request within **30 days** as prescribed by law, and may extend this period by an additional 30 days if necessary, of which we will notify you in advance. > **Limitations:** In certain circumstances, we may be unable to fulfill your request if the law requires us to retain your data (e.g., KYC/AML data under the Anti-Money Laundering Act, which must be retained for no less than 5 years after the termination of the business relationship).

7. Data Security

7.1 Technical Measures

LynxFuse employs industry-standard security measures: | Measure | Details | |---|---| | **Encryption** | All data is encrypted in transit (TLS 1.3) and at rest (AES-256-GCM) | | **Password Storage** | Passwords are hashed using bcrypt / Argon2id; no plaintext passwords are stored | | **Private Key Management** | Digital wallet private keys are stored in Cold Wallet systems and Hardware Security Modules (HSM) | | **Access Control** | Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) for employees | | **Audit Logging** | Complete audit trail of all system access logs | | **Threat Detection** | SIEM (Security Information and Event Management) system, Intrusion Detection/Prevention Systems (IDS/IPS) | | **Security Testing** | Quarterly penetration testing and vulnerability assessments by external firms | | **Backup** | Encrypted off-site backups and regular disaster recovery testing |

7.2 Organizational Measures

- All employees undergo regular data security and PDPA/GDPR training - Execution of Non-Disclosure Agreements (NDA) and Data Processing Agreements (DPA) with employees and counterparties - **Principle of Least Privilege** — access to data is limited to what is necessary for job performance - Employee background checks prior to employment - Incident Response Plan (IRP) for data breaches

7.3 Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms: - LynxFuse will notify the Office of the Personal Data Protection Committee (PDPC) within **72 hours** as required under the PDPA - LynxFuse will notify you without undue delay through appropriate channels (email, SMS, in-app notification)

8. Data Retention & Deletion

8.1 Data Retention Periods

We will retain your personal data only for as long as necessary for the purposes set out in this Policy, or as required by law: | Data Type | Retention Period | Reason | |---|---|---| | **KYC/AML Data** | 5–10 years after termination of business relationship | Pursuant to the Anti-Money Laundering Act B.E. 2542 and its amendments | | **Transaction Data** | 7 years from the transaction date | Pursuant to the Revenue Code (taxation) | | **Account Data** | Throughout the duration of your use of the service + 90 days after account closure | Service provision and legal compliance | | **Usage Data** | Up to 24 months | Analysis and service improvement | | **Cookie Data** | As specified in the Cookies section | — | | **Communication Logs** | 2 years | Customer service and dispute resolution |

8.2 Data Deletion

Upon the expiry of the retention period, or when you exercise your right to erasure and we have no legal grounds to refuse: - Personal data will be securely deleted or anonymized - Data stored in backups will be deleted in the next deletion cycle pursuant to the backup policy - Data on the blockchain (recorded transactions) **cannot be deleted** due to the immutable nature of distributed ledger technology — however, personal data linked to wallet addresses will be disassociated

9. Changes to This Policy

LynxFuse reserves the right to update or modify this Privacy Policy from time to time. - **Material changes:** We will notify you at least **30 days** in advance via: - The email address you registered with - In-app / on-site notifications - A notice on our website at https://lynxfuse.com/privacy - **Minor changes:** May take effect immediately, with the "Last Updated" date at the top of this Policy being updated accordingly. We encourage you to review this Policy periodically to stay informed of any changes. Your continued use of LynxFuse's services after any modification takes effect constitutes your acceptance of the revised Policy.

10. Contact Information

### Data Protection Officer (DPO) | Channel | Details | |---|---| | **DPO Email** | [email protected] | | **Legal Department Email** | [email protected] | | **Telephone** | +66 89 351 9929 (Monday - Friday 09:00 - 18:00 ICT) | | **Address** | Flat Kheha Khlong Chan, Building 17 Floor, Bangkapi, Bangkok 10240 | | **Online Form** | https://lynxfuse.com/privacy/request | ### Regulatory Authorities | Authority | Details | |---|---| | **Office of the Personal Data Protection Committee (PDPC)** — Thailand | https://www.pdpc.or.th | | **Securities and Exchange Commission (SEC Thailand)** | https://www.sec.or.th | | **Anti-Money Laundering Office (AMLO)** | https://www.amlo.go.th | | **For EU users — data protection authority in your country** | List of authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en |
Free consultation