QOVA Exchange

Privacy Policy

Last updated: March 2026 — Version 1.0

QOVA Exchange ("QOVA," "we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform. It applies to all users globally and addresses the requirements of the Brazilian General Data Protection Law (LGPD — Lei 13.709/2018) and the European General Data Protection Regulation (GDPR — Regulation 2016/679).

1. Data Controller

The data controller responsible for processing your personal data is:

QOVA Exchange S.A.

Registered in El Salvador under the Digital Assets Service Providers Law (DASP Law)

Email: privacy@qovaexchange.com

2. Data We Collect

We collect personal data in the following categories:

2.1 Registration and Identity Data

  • Full legal name
  • Email address
  • Date of birth
  • Country of residence
  • Phone number (including international dialing code)
  • Government-issued identification (CPF, passport, national ID — number and type)

2.2 KYC / AML Verification Data

  • Copies of identity documents submitted for verification
  • Selfie or liveness check images (when applicable)
  • Source of funds declarations
  • PEP (Politically Exposed Person) screening results
  • Sanctions and watchlist screening results

2.3 Financial and Transaction Data

  • Deposit and withdrawal records
  • Conversion and trading history
  • Wallet addresses and transaction hashes
  • Bank account details (IBAN/SWIFT) when applicable

2.4 Technical and Usage Data

  • IP address and approximate geolocation
  • Browser type and version
  • Device identifiers
  • Login timestamps and session data
  • Platform usage patterns and navigation logs

2.5 Communications Data

  • Support ticket contents
  • Email and in-platform messages
  • Feedback and survey responses

3. How We Use Your Data

We use your personal data for the following purposes:

  • Account creation and management — to register you, authenticate your identity, and provide access to our services.
  • KYC/AML compliance — to verify your identity and comply with anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under El Salvador law, the EU's AMLD6, and applicable international standards (FATF).
  • Service delivery — to process deposits, conversions, and withdrawals; maintain your account balance; and facilitate transactions.
  • Security and fraud prevention — to detect suspicious activity, prevent unauthorized access, and protect you and our platform.
  • Legal and regulatory obligations — to maintain records required by financial regulators and law enforcement authorities.
  • Customer support — to respond to your inquiries and resolve issues.
  • Platform improvement — to analyze usage patterns and improve our products (anonymized or aggregated data).
  • Marketing communications — where you have given explicit consent, to inform you of new features, promotions, and updates. You may withdraw consent at any time.

4. Legal Basis for Processing

PurposeGDPR BasisLGPD Basis
Account managementContract (Art. 6(1)(b))Contract performance (Art. 7, VI)
KYC/AML complianceLegal obligation (Art. 6(1)(c))Legal obligation (Art. 7, II)
Fraud preventionLegitimate interest (Art. 6(1)(f))Legitimate interest (Art. 7, IX)
MarketingConsent (Art. 6(1)(a))Consent (Art. 7, I)
Platform improvementLegitimate interest (Art. 6(1)(f))Legitimate interest (Art. 7, IX)

5. Data Sharing and Third Parties

We may share your personal data with the following categories of third parties:

  • KYC/Identity verification providers — third-party services that verify the authenticity of your identity documents and conduct sanctions screening.
  • Cloud infrastructure providers — servers and databases used to host and operate the platform. All providers are bound by data processing agreements and appropriate safeguards.
  • Banking and payment partners — financial institutions that process SWIFT transfers or fiat settlements.
  • Compliance and legal authorities — government bodies, financial regulators, law enforcement, and courts when required by applicable law.
  • Professional advisors — lawyers, auditors, and accountants bound by professional confidentiality obligations.

We do not sell, rent, or trade your personal data to third parties for commercial purposes.

6. International Data Transfers

Your data may be processed in countries outside your country of residence, including El Salvador, the European Economic Area (EEA), and other jurisdictions where our service providers operate.

For transfers involving EEA/UK personal data to third countries, we use appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Binding Corporate Rules with verified processors

For Brazilian users, international transfers comply with LGPD Art. 33 requirements, including consent and appropriate safeguards.

7. Data Retention

Data CategoryRetention PeriodBasis
Account and registration data5 years after account closureAML/KYC legal obligation
KYC verification data5–10 years after last transactionFATF / regulatory requirement
Transaction records10 yearsFinancial record-keeping
Communication logs3 yearsDispute resolution / legal
Technical/usage data13 monthsSecurity and fraud detection
Marketing consent recordsUntil withdrawal + 3 yearsProof of consent

8. Your Rights (LGPD / GDPR)

Depending on your country of residence, you have the following rights regarding your personal data:

Access (Art. 15 GDPR / Art. 18 LGPD)

You can request a copy of all personal data we hold about you.

Rectification (Art. 16 GDPR / Art. 18 LGPD)

You can request correction of inaccurate or incomplete data.

Erasure / Right to be Forgotten (Art. 17 GDPR / Art. 18 LGPD)

You can request deletion of your data, subject to legal retention obligations (e.g., AML records cannot be deleted before the mandatory retention period).

Portability (Art. 20 GDPR / Art. 18 LGPD)

You can request your data in a structured, machine-readable format.

Restriction of Processing (Art. 18 GDPR)

You can request that we limit how we process your data in certain circumstances.

Object to Processing (Art. 21 GDPR)

You can object to processing based on legitimate interests or for direct marketing.

Withdraw Consent (Art. 7(3) GDPR / Art. 8 LGPD)

Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

Complaint to Supervisory Authority

EU/EEA users: You may lodge a complaint with your national Data Protection Authority. Brazilian users: You may contact the ANPD (Autoridade Nacional de Proteção de Dados).

To exercise any of these rights, contact us at privacy@qovaexchange.com. We will respond within 30 days. Identity verification may be required before processing your request.

9. Cookie Policy

QOVA Exchange uses cookies and similar tracking technologies to operate and improve the platform.

Strictly Necessary

Session authentication tokens, CSRF protection. Cannot be disabled — required for the platform to function.

Functional

Language preferences, UI settings stored in localStorage. These do not track you across sites.

Security

Device fingerprinting for fraud detection and suspicious login alerts.

Analytics (opt-in)

Aggregated usage statistics to improve the platform. Only activated with your explicit consent.

10. Children's Privacy

QOVA Exchange services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will immediately terminate the account and delete all associated data. If you believe a minor has created an account, please contact us at privacy@qovaexchange.com.

11. Data Security

We implement industry-standard technical and organizational security measures, including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • bcrypt password hashing with per-user salts (minimum 12 rounds)
  • Time-based one-time passwords (TOTP) for two-factor authentication
  • Short-lived JWT access tokens (15 minutes) with rotating refresh tokens
  • Role-based access control (RBAC) limiting internal data access
  • Immutable audit logs for all account and compliance events
  • Account lockout after repeated failed authentication attempts
  • Regular security assessments and penetration testing

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authorities within 72 hours and affected users without undue delay, as required by GDPR Art. 33-34 and LGPD Art. 48.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory obligations. We will notify you of material changes via email or a prominent notice on the platform at least 30 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the updated policy. The current version and effective date are always shown at the top of this page.

13. Contact and DPO

For any privacy-related questions, to exercise your data rights, or to reach our Data Protection Officer (DPO), please contact us:

Data Protection Officer

Email: privacy@qovaexchange.com

Response time: up to 30 calendar days

For urgent security matters, use the subject line "SECURITY — URGENT".