Privacy policy
Privacy Policy for the Website, AML/KYC Procedures, and Order Processing
Revision Date: July 2, 2026
This Privacy Policy sets out the procedures for processing the personal data and other information of Users when using the website https://dinoex.io/, creating Orders, undergoing AML/KYC verification, and interacting with the DinoExchange Service.
1.1. Data Controller: Dino Exchange
1.2. Service: DinoExchange, website https://dinoex.io/.
1.3. Contact for Personal Data Requests: dinoex777@gmail.com.
1.4. If the actual Data Controller differs from the website owner, domain administrator, payment recipient, or the entity processing Orders, information regarding the Data Controller and the persons processing personal data on behalf of the Data Controller shall be disclosed to the User before the processing of personal data begins.
2.1. Identity Data: surname, first name, patronymic (where applicable), date of birth, citizenship, identity document details, photo/scan of the identity document, selfie with the document, video identification, signature, and information regarding an authorized representative.
2.2. Contact Information: telephone number, email address, messenger accounts, user accounts, residential address/country of residence, and preferred language of communication.
2.3. Financial Information: banking details, masked payment card numbers, bank name, receipts, payment confirmations, bank statements, transaction amount, transaction date, payment purpose, and information confirming ownership of the bank account or payment card.
2.4. Digital Currency Information: wallet addresses, blockchain network, transaction hashes, transaction amounts, transaction history, AML Risk Score, blockchain analytics results, and information regarding the origin of digital currency.
2.5. Technical Data: IP address, cookies, user-agent, device information, session identifiers, security logs, information regarding activity on the Website, and the date and time of access.
2.6. Communications: correspondence, voice messages, video identification recordings, screenshots, files, inquiries, complaints, and responses provided by the Service.
2.7. Risk-Related Information: sanctions, PEP, and AML indicators, information regarding matches against internal and external risk lists, fraud indicators, and the results of banking and payment verification procedures.
2.8. The Service does not request special categories of personal data unless such information is necessary to comply with applicable law, protect the Service's rights, or process a specific Order. Users shall not submit such information unless specifically requested by the Service.
3.1. Creation, processing, execution, cancellation, refund, and administration of User Orders.
3.2. Identification of the User, verification of the User's authority to dispose of fiat funds and digital currency, and confirmation of the source of funds.
3.3. Conducting AML/KYC verification, sanctions screening, blockchain analytics, fraud detection, verification of transfers made without the customer's voluntary consent, and the assessment of other risk indicators.
3.4. Communicating with the User, sending notifications, requesting documents, providing Order status updates, and delivering legally significant communications.
3.5. Protecting the rights and legitimate interests of the Service, banks, payment systems, other Users, and third parties; retaining evidence relating to Orders, claims, and disputes.
3.6. Complying with applicable laws and with requests from banks, payment systems, courts, law enforcement agencies, and other competent authorities.
3.7. Ensuring the information security of the Website, preventing abuse, technical errors, cyberattacks, spam, and unauthorized access.
3.8. Analyzing Website performance and improving the quality of the Service, provided that such analytics do not conflict with the User's selected cookie preferences or applicable legal requirements.
4.1. Acceptance of the User Agreement and the necessity of processing personal data for the creation and execution of an Order.
4.2. The User's consent to the processing of personal data, including separate consent where required by applicable law.
4.3. Compliance with obligations arising under applicable law and the requirements of banks, payment systems, courts, and competent authorities.
4.4. Protection of the legitimate interests of the Service, the User, banks, payment systems, and third parties, provided that such interests do not override the rights and freedoms of the data subject.
4.5. If the Service uses photographs, video recordings, or other data to verify the User's identity, such information may be processed as biometric personal data, subject to the User's separate consent where required by applicable law.
5.1. Personal data may be disclosed to banks, payment systems, payment infrastructure operators, AML/KYC and blockchain analytics providers, hosting providers, IT contractors, telecommunications operators, legal advisers, auditors, governmental authorities, courts, and law enforcement agencies.
5.2. Personal data shall be disclosed only to the extent necessary for processing an Order, conducting verification, ensuring security, complying with applicable law, protecting the Service's rights, or responding to a lawful request.
5.3. Persons processing personal data on behalf of the Service shall be required to maintain confidentiality and to use such data solely for the purposes specified by the Service.
5.4. The Service does not sell Users' personal data to third parties and does not disclose such data for independent third-party marketing purposes without the User's separate consent.
6.1. Where the Service uses foreign hosting services, analytics services, communication platforms, AML/KYC providers, cloud storage services, or technical support providers, personal data may be transferred across national borders.
6.2. Before any cross-border transfer of personal data, the Data Controller shall comply with the requirements of applicable law, including notification of the competent authority where such notification is required.
6.3. The User is informed that personal data may be transferred across borders for the purposes of Order processing, AML/KYC verification, security, and communication with the User.
6.4. If cross-border data transfers to a particular country are prohibited or restricted by a competent authority, the Service reserves the right to refuse to process the Order or to modify the technical method of processing personal data.
7.1. Personal data shall be retained for the period necessary to achieve the purposes of processing, execute the Order, conduct verification procedures, resolve claims, protect the Service's rights, and comply with applicable legal requirements.
7.2. Documents and information relating to AML/KYC procedures, Orders, payments, transactions, claims, and disputes may be retained for the applicable statutory limitation period and for a longer period where required by law, banks, payment systems, or competent authorities.
7.3. Once the purposes of processing have been fulfilled, personal data shall be deleted, anonymized, or archived where continued retention is required by law or for the protection of the Service's legal rights.
7.4. The User may request the deletion of their personal data; however, such deletion may be restricted where the data is required for compliance with applicable law, AML/KYC verification, protection of the Service's rights, resolution of claims, or fraud prevention.
8.1. The Website may use essential cookies necessary for the operation of the Website, security, user authentication, preservation of Order status, and fraud prevention.
8.2. Analytical, advertising, and other non-essential cookies shall be used only in accordance with applicable law and the User's cookie preferences.
8.3. The User may restrict the use of cookies through their browser settings. Restricting essential cookies may result in improper functioning of the Website or make it impossible to process an Order.
8.4. The Website should include a separate cookie banner allowing Users to choose cookie categories and providing a link to this Privacy Policy.
9.1. The User has the right to obtain information regarding the processing of their personal data and to request the correction, restriction, or deletion of such data in the cases provided for by applicable law.
9.2. The User has the right to withdraw their consent to the processing of personal data. Withdrawal of consent may make it impossible to continue processing the Order or providing the Services where such data is necessary for the execution of the Order, AML/KYC verification, or compliance with applicable legal requirements.
9.3. A User's request must contain sufficient information to identify the User and confirm the User's right to submit such a request. The Service reserves the right to request additional information in order to prevent the disclosure of personal data to unauthorized third parties.
9.4. Responses to User requests shall be provided within the timeframes and in the manner prescribed by applicable law.
10.1. The Service implements appropriate organizational and technical measures to protect personal data against unauthorized access, destruction, alteration, blocking, copying, disclosure, and other unlawful processing.
10.2. Access to personal data shall be granted only to persons whose access is necessary for Order processing, AML/KYC verification, security, technical support, legal compliance, or the fulfillment of applicable legal obligations.
10.3. The User is solely responsible for maintaining the security of their devices, messaging applications, email accounts, digital wallets, payment cards, and user accounts. The Service shall not be liable for any data breach resulting from the compromise of the User's devices or accounts.
11.1. The Service reserves the right to amend this Privacy Policy by publishing a new version on the Website.
11.2. The new version shall become effective upon its publication unless another effective date is specified therein.
11.3. Continued use of the Website and the creation of new Orders after publication of the revised version shall constitute the User's acknowledgment of the amendments.
This consent is recommended to be presented as a separate form or checkbox and should not be combined with the User Agreement where applicable law requires separate consent.
1. I, the User of the DinoExchange Service, freely, voluntarily, and in my own interests, hereby give the Data Controller my consent to process my personal data for the purposes of creating and processing Orders, conducting AML/KYC verification, verifying the source of funds, confirming my authority to dispose of fiat funds and digital currency, preventing fraud, complying with applicable legal requirements, and protecting the rights of the Service.
2. This consent applies to the categories of data specified in the Privacy Policy, including identification data, contact information, financial information, technical data, digital currency information, correspondence, documents, photographs, video recordings, AML/KYC verification results, and risk indicators.
3. I consent to the disclosure of my personal data to banks, payment systems, AML/KYC providers, blockchain analytics providers, IT contractors, legal advisers, governmental authorities, and other persons to the extent necessary for the purposes of processing.
4. I acknowledge that my personal data may be transferred across national borders when foreign technical service providers, analytics providers, communication platforms, or AML/KYC providers are used.
5. If photographs, video recordings, or other data are used to verify my identity and are recognized as biometric personal data under applicable law, I hereby provide separate consent to the processing of such data for identification and KYC verification purposes.
6. This consent shall remain valid until the purposes of processing have been fulfilled or until it is withdrawn by me, unless further processing is required by law, for the protection of the Service's rights, for the resolution of claims, for AML/KYC verification, or for the retention of evidence relating to an Order.
7. I confirm that I have read and understood the DinoExchange Privacy Policy, User Agreement, and AML/KYC Policy.
