English translation based on the supplied Chinese draft.
1. Scope and acceptance
This Privacy Policy explains how BRIDYRA PTY LTD (Bridyra, we, us or the Platform) collects, uses, stores, shares, transfers and protects personal information when you access or use our website, applications, H5 pages, account systems, institutional interfaces, digital settlement features and related services. It applies to users, capital providers, institutional contacts, directors, beneficial owners and authorised representatives. By using the Services, you confirm that you have read and understood this Policy. Where separate consent is required, we will obtain it.
2. Our role as data processor
Depending on the relationship, Bridyra may act as an independent controller or as a service provider processing information on an institution’s instructions. For institutional debt-order data, responsibilities, lawful bases, authorisation chains and security duties are governed by applicable law and the relevant agreement.
3. Business boundaries and information sources
Bridyra receives genuine debt orders through partner institutions. Partners generally handle customer contact, document collection, preliminary review, authorisation and parts of ongoing service; Bridyra performs order review, standardisation, risk tiering, capital matching, digital settlement and long-term receivables management. Information may come from you, partners, KYC/KYB and AML providers, public sources and ledgers, regulators, sanctions lists, and systems that generate device, transaction and usage logs.
4. Information we collect
We may collect identity and account details; identity documents and verification or liveness data where lawful; tax residence and occupation; proof of address, source of funds and wealth; company, director, shareholder, beneficial-owner and authorisation data; sanctions, PEP, fraud and risk results; debt-order, credit, repayment and servicing information; balances, deposits, withdrawals, settlement, wallet, network, transaction-hash and confirmation data; IP, device, browser, language, timezone, cookie, SDK, access and error logs; and support tickets, emails, chats, calls and submitted files where lawful.
5. How we use information
With an appropriate legal, contractual or legitimate basis, or consent where required, we use information to create and verify accounts; perform KYC, KYB, AML, sanctions and fraud checks; receive and manage institutional debt orders; assess credit, risk and order integrity; match capital and orders; provide settlement and receivables management; process transactions and fees; provide support and notices; protect users and the Platform; improve products and models; conduct audit, tax, regulatory and dispute work; comply with lawful requests; and send product or brand information where permitted.
6. KYC, AML and screening
We may require identity or business verification, source-of-funds checks, sanctions and PEP screening, wallet-risk screening and transaction monitoring. We may use specialist providers. Refusing information required by law or our risk policy may prevent or suspend some Services.
7. Automated analysis and risk assessment
Rules, algorithms, statistical models, artificial intelligence and other automated tools may analyse identity, account activity, debt orders, credit attributes, funds and transactions for authenticity checks, risk tiering, matching, fraud and AML detection, or decisions requiring human review. Where law provides a right to challenge a significant solely automated decision, you may request human review through the contact details below.
8. Sharing and disclosure
We do not sell personal information as a business model. Subject to lawful purpose and data minimisation, we may share necessary information with partner institutions; KYC, AML, blockchain, cloud, payment, wallet, security, audit, legal and support providers; capital and receivables participants; and professional advisers or transaction parties in a financing, restructuring, merger, acquisition or asset sale. Identity data will be limited, de-identified or disclosed only as necessary where feasible.
9. International transfers
Information may be processed or stored in Australia and other countries supporting technology, compliance, payments, cloud services or institutional partnerships. Where required, we use contractual safeguards, access controls, encryption, minimisation and supplier review. Specific arrangements may be refined as systems and suppliers are finalised.
10. Blockchain and public-ledger data
USDT, USDC and related networks may record wallet addresses, transaction hashes, amounts, networks, block heights and times on public or semi-public ledgers. Confirmed records may be permanent, public and immutable; Bridyra cannot delete data written to third-party networks. Do not place unnecessary sensitive information in a memo or public field.
11. Data retention
We retain information only as long as needed for the collection purpose, contracts, legal and regulatory duties, risk management, audit, disputes and legitimate interests. Closing an account does not immediately delete KYC, AML, transaction, debt-order, contract or regulatory records, and public-ledger data is outside our control.
12. Information security
We use reasonable technical and organisational safeguards appropriate to our scale and risks, including encryption, secure storage, authentication, 2FA, transaction verification, least-privilege access, audit logs, monitoring, backups, recovery, vulnerability management and supplier assessments. No internet, financial or blockchain system is absolutely secure.
13. Cookies and similar technologies
Websites, Apps and H5 pages may use cookies, SDKs, local storage and similar technologies for login, security, preferences, performance, troubleshooting, fraud prevention and service improvement. Where required, choices are provided before non-essential analytics or advertising technologies are used.
14. Marketing and notices
Service, transaction, security, compliance and terms-update notices are necessary communications and may not be fully disabled. For non-essential marketing, we provide unsubscribe or preference controls where required.
15. Your data rights
Depending on local law, you may request access, a copy, correction, deletion, restriction, objection, portability, withdrawal of consent, human review of an automated decision, or make a complaint to a competent regulator. Rights are not absolute and may be limited by AML, regulatory, retention, contract, dispute, fraud-prevention or security duties. We may verify your identity before responding.
16. Children
Our financial and digital-asset Services are not intended for people below the applicable legal age or unable to enter a contract. Unless law or a specific product provides otherwise, users should be at least 18. We may restrict or close access where age requirements are not met.
17. Third-party services
Links or connections to identity, wallet, blockchain, payment, financial, cloud and other third-party services are governed by those providers’ own privacy policies and terms when they independently determine processing.
18. Complaints and regulators
Contact custom@bridyra.com first with enough information to identify the account and issue. We will investigate and respond within a reasonable period. You may also complain to an appropriate data-protection or regulatory authority where law permits.
19. Policy updates
We may update this Policy for legal, regulatory, product, technology, security, business or partnership changes. Material changes may be notified through the website, App, H5, account notices or email. The latest version will show its effective date.
20. Contact us
For privacy questions or rights requests, contact Bridyra at custom@bridyra.com.