How Bitzaro Maple Capital Ltd. collects, uses, stores and protects your personal data when you use this website and our services.
This privacy policy aims to give you information on how Bitzaro collects and processes your personal data through your use of this website, including any data you may provide through this website when you purchase a product or service.
The following phrases are to be understood as follows:
In accordance with Article 13 sections 1 and 2 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”), and applicable Canadian privacy laws, the controller of personal data is Bitzaro Maple Capital Ltd., a company incorporated in Canada under registration number BC1273635, with its registered address at 150-10451 Shellbridge Way, Richmond, BC V6X 2W8, Canada, e-mail address: support@bitzaro.com (the “Controller”).
Where applicable, the GDPR applies to individuals located in the European Economic Area (“EEA”).
For any questions or concerns relating to personal data, privacy, or data protection, please contact Bitzaro at support@bitzaro.com.
A Client’s personal data may be accessed by the Controller’s employees, contractors, or associates who are authorised to process such data on behalf of the Controller and only to the extent necessary for the performance of their duties. Personal data may also be disclosed to entities to which the Controller entrusts the processing of personal data, including providers of accounting, legal, compliance, information technology, cloud hosting, customer support, marketing, and organisational services that enable the Controller to provide its services, maintain the Website, and conduct its business operations (the “Cooperating Entities”).
In particular, personal data may be shared with third-party service providers performing identity verification, transaction monitoring, fraud prevention, and other compliance-related services as part of the Controller’s Know Your Customer (“KYC”) and anti-money laundering and counter-terrorist financing obligations, in accordance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (Canada) and applicable regulations, as well as other applicable laws.
Personal data may be disclosed to competent public authorities, including law enforcement agencies, regulators, courts, or other governmental bodies, where such disclosure is required by applicable law, regulation, court order, or binding request, or where it is necessary for the prevention, detection, or investigation of crime, fraud, or other unlawful activities.
Personal data may also be transferred to entities belonging to the Controller’s corporate group or to entities with capital or personal ties to the Controller, to the extent necessary for the provision of services, internal administrative purposes, risk management, compliance, or business continuity.
The Controller exercises due diligence in selecting its Cooperating Entities and ensures, at the stage of concluding agreements and throughout the cooperation, that such entities provide appropriate technical and organisational measures to protect personal data and ensure a level of protection required by applicable data protection laws, including the GDPR where applicable.
Personal data is stored and processed in Canada and Singapore, and may also be processed in other jurisdictions where the Controller, its affiliates, or its Cooperating Entities maintain facilities or engage service providers, including for the purposes of cloud hosting, information technology support, data analytics, customer support, identity verification, transaction monitoring, and compliance operations.
Where personal data is transferred to or processed in a jurisdiction outside the country of the data subject’s residence, the Controller ensures that such transfers are carried out in accordance with applicable data protection laws and are subject to appropriate safeguards. These safeguards may include contractual protections, technical and organisational security measures, and internal policies designed to protect personal data against unauthorised access, loss, misuse, or disclosure.
For personal data relating to individuals located in the European Union, any transfer of personal data outside the European Economic Area is carried out in accordance with the GDPR, using appropriate transfer mechanisms and safeguards recognised under applicable data protection laws.
The Controller ensures that personal data is processed lawfully, fairly, and transparently, and in accordance with applicable data protection laws, including Canadian privacy legislation (such as the Personal Information Protection and Electronic Documents Act – PIPEDA) and, where applicable, the General Data Protection Regulation (GDPR).
The Controller collects and processes only such personal data as is necessary for the performance of contracts, the provision of services, compliance with legal and regulatory obligations, or other legitimate purposes described in this Privacy Policy. Personal data is not processed beyond these purposes unless required or permitted by applicable law or with the data subject’s consent where such consent is required.
The Controller implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, misuse, or disclosure, taking into account the nature of the data and the risks associated with its processing.
The Controller does not knowingly process personal data of individuals under the age of 18 or of persons who lack full legal capacity, unless such processing is carried out through a duly authorised legal representative and is permitted by applicable law.
Where the GDPR applies, personal data is processed on the following bases:
Verification is conducted in accordance with applicable anti-money laundering and counter-terrorist financing laws, including the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (Canada) and other applicable regulations.
Verification may include identity verification, proof of residence, screening, and risk-based checks (source of funds/wealth). Verification is performed via automated tools and manual review. Automated processes may approve, flag for manual review, or reject applications.
Personal data is retained as follows:
Clients may exercise the following rights, subject to applicable law:
Requests should be sent to the Controller. Additional information may be required to verify the identity of the requesting individual. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.