Privacy Policy for ZE Nyse Finance Exchange

Last Updated: October-10, 2024

Welcome to ZE Nyse Finance Exchange’s Privacy Policy (“Privacy Policy”). Please take a few minutes to read this policy carefully before providing us with any information about you or any other person.

Content

1.    Introduction

2.    Purpose

3.    Who We Are

4.    What Data We Collect About You

5.    How We Collect Your Data

6.    How We Use Your Data

7.    Disclosures of Your Data

8.    International Transfers

9.    Data Security

10.                        Data Retention

11.                        Your Legal Rights

1. Introduction

At ZE Nyse Finance, we respect your privacy and are committed to protecting your personal data. We take our data protection responsibilities seriously, ensuring compliance with applicable laws, including Japan’s Act on the Protection of Personal Information (JAPPI) and other relevant regulations. This Privacy Policy outlines how we collect, process, and safeguard your personal data when you use our services.

2. Purpose

This Privacy Policy describes how ZE Nyse Finance collects, processes, and protects your personal data in connection with:

·      Use of products, services, or applications offered on our website (nysefinance.com or other affiliated platforms) and mobile application (“App”), including cryptocurrency trading, mutual fund investments, social trading, copy trading, over-the-counter (OTC) trading, token splash trading, classic trade, peer-to-peer (P2P) trading, and futures trading (collectively, the “Services”).

·      Interaction with our websites (“Site”) or App, including account creation and customer support.

This policy applies to all personal data processing activities carried out by ZE Nyse Finance across our Services and App. It informs you of your privacy rights and how data protection principles protect you. Please read this Privacy Policy alongside any other notices we provide when collecting or processing your data. This policy supplements other notices and does not override them. In case of conflict, this Privacy Policy prevails.

Our Services, Site, and App are not intended for minors under 18 years of age, and we do not knowingly collect data from minors.

3. Who We Are

Data Controller

ZE Nyse Finance, operated by FISCO. is the data controller responsible for handling your personal data. We determine the means and purposes of processing activities carried out through our platform.

Contact Details

For any issues related to the processing of your personal data, please contact us at info@nysefinance.com

Changes to This Policy

We regularly review our Privacy Policy. This version was last updated on June 5, 2025. Please check periodically for updates. We will notify you of material changes through effective communication channels, such as email or website notices.

Your Duty to Inform Us

It is important that the personal data we hold is accurate and up-to-date. Please inform us of any changes to your personal data during your relationship with us.

Third-Party Links

Our Site, App, or related interfaces may include links to third-party websites, plug-ins, or applications (“Third-Party Sites”), including those of our mutual fund partners: Nomura Asset Management, Daiwa Asset Management, Mitsubishi UFJ Asset Management, Sumitomo Mitsui DS Asset Management, Nikko Asset Management, FSSA Investment Managers, JPMorgan Asset Management, Goldman Sachs Asset Management, M&G Investments, and BOCI-Prudential Asset Management. Clicking these links may allow third parties to collect or share your data. We are not responsible for their privacy policies and encourage you to review them.

4. What Data We Collect About You

Personal Data

Personal data refers to any information relating to an identified or identifiable individual. We collect the following categories of personal data:

·      Identity Data: Full name, maiden name, username, date of birth, biometric information (e.g., facial image for identity verification), national identity card, passport, driver’s license, or other identification documents.

·      Contact Data: Country of residence, email address, telephone numbers, proof of address documentation.

·      Financial Data: Bank account details, payment card details, virtual currency accounts, stored value bode-accounts.

·      Transactional Data: Details of transactions to and from you, including cryptocurrency trades, mutual fund investments, and other activities on our Services.

·      Technical Data: Internet protocol (IP) address, login data, browser type and version, device type and model, time zone, location data, language settings, operating system, platform, diagnostics data (e.g., crash logs), and other device-related information.

·      Profile Data: Username, password, user identification number, account email, requests for products or services, interests, preferences, feedback, and communications with our support team.

·      Usage Data: Information about how you use our Site, App, and Services, including device download time, interaction types, and event details.

·      Marketing and Communications Data: Preferences for receiving marketing from us or third parties, communication preferences, and survey responses.

We may collect special categories of data, such as biometric data (e.g., facial images) for identity verification and fraud prevention, in collaboration with third-party subcontractors.

5. How We Collect Your Data

We collect personal data through:

·      Direct Interactions: You provide Identity Data, Contact Data, Financial Data, Profile Data, and Marketing and Communications Data by filling out forms, submitting identification documents, contacting support, or using our Services (e.g., trading or investing in mutual funds).

·      Automated Technologies: We collect Technical Data, Transactional Data, and Usage Data via cookies, server logs, and other tracking technologies as you interact with our Site or App.

·      Social Media Widgets: Our Site may include social media plug-ins or buttons (e.g., X, Facebook, Telegram) that collect Technical Data or Usage Data when you interact with them.

·      Third Parties: We may receive data from mutual fund partners (e.g., Nomura Asset Management or JPMorgan Asset Management), identity verification agencies, fraud prevention agencies, or public sources (e.g., KYC checks).

6. How We Use Your Data

Lawful Basis

We process your personal data only when permitted by applicable laws, such as Japan’s APPI, using the following bases:

·      Performance of a Contract: Processing necessary to fulfill a contract with you (e.g., providing trading or mutual fund services).

·      Legitimate Interests: Processing for our or a third party’s interests, provided your rights do not override these interests.

·      Compliance with Legal Obligations: Processing to meet legal requirements, such as anti-money laundering (AML) regulations.

·      Consent: Processing based on your explicit consent for specific purposes (e.g., marketing).

Purposes and Legal Bases

Purpose/Activity

Categories of Personal Data

Legal Basis

Register you as a new customer

Identity Data, Contact Data, Financial Data

Performance of a contract

Comply with AML and KYC requirements

Identity Data, Contact Data, Financial Data, Transactional Data, Technical Data, Profile Data

Compliance with a legal obligation

Process and deliver Services (e.g., crypto trading, mutual fund investments via Daiwa Asset Management, social trading, copy trading)

Identity Data, Contact Data, Financial Data, Transactional Data, Technical Data

Performance of a contract, Consent (if required)

Prevent abuse of Services or promotions

Identity Data, Contact Data, Financial Data, Transactional Data, Technical Data, Marketing and Communications Data

Legitimate interests (safeguarding platform integrity)

Manage customer relationships (e.g., surveys, updates)

Identity Data, Contact Data, Profile Data, Transactional Data, Marketing and Communications Data

Performance of a contract, Consent (if required)

Process payments, fees, and charges

Identity Data, Contact Data, Financial Data, Transactional Data

Performance of a contract

Comply with legal obligations (e.g., crime prevention, fraud checks)

Identity Data, Contact Data, Financial Data, Transactional Data, Technical Data, Profile Data, Usage Data, Special Categories Data (e.g., KYC data, biometric scans)

Compliance with a legal obligation, Legitimate interests (preventing fraud)

Conduct surveys, prize draws, or competitions

Identity Data, Contact Data, Profile Data, Usage Data, Marketing and Communications Data

Performance of a contract, Consent (if required)

Analyze customer behavior for marketing and business growth

Identity Data, Contact Data, Profile Data, Usage Data, Marketing and Communications Data

Legitimate interests (improving services)

Administer and protect our platform (e.g., troubleshooting, security)

Identity Data, Contact Data, Financial Data, Technical Data, Transactional Data, Usage Data

Legitimate interests (business operations, security)

Deliver relevant content and advertisements

Identity Data, Contact Data, Profile Data, Usage Data, Technical Data, Marketing and Communications Data

Legitimate interests (marketing strategy), Consent (if required)

Use data analytics to improve Services

Technical Data, Usage Data, Marketing and Communications Data

Legitimate interests (enhancing user experience)

Make product or service recommendations

Identity Data, Contact Data, Technical Data, Usage Data, Profile Data, Marketing and Communications Data

Legitimate interests (business growth), Consent (if required)

Automated Decision-Making

We may use automated decision-making (e.g., for onboarding or fraud detection) based on software algorithms. These decisions may impact you, such as approving your account or flagging suspicious activity. You have the right to oppose automated decisions; contact us for details.

Marketing

We may use your data to suggest relevant products or services (e.g., mutual fund investments or trading features). You will receive marketing communications only if you have consented or have not opted out after using our Services.

Third-Party Marketing

We will obtain your opt-in consent before sharing your data with third parties (e.g., M&G Investments) for marketing purposes.

Opting Out

You can opt out of marketing communications via links in our messages or by updating your preferences in your account. Service-related messages (e.g., transaction confirmations) are unaffected.

Cookies

We use cookies to enhance your experience. You can manage cookie preferences through your browser settings, but disabling cookies may affect Service functionality.

Change of Purpose

We use your data only for the purposes for which it was collected, unless a compatible purpose arises. We will notify you of any unrelated purpose and explain the legal basis.

7. Disclosures of Your Data

We may share your personal data with:

·      Mutual Fund Partners: Nomura Asset Management, Daiwa Asset Management, Mitsubishi UFJ Asset Management, Sumitomo Mitsui DS Asset Management, Nikko Asset Management, FSSA Investment Managers, JPMorgan Asset Management, Goldman Sachs Asset Management, M&G Investments, and BOCI-Prudential Asset Management for managing mutual fund investments.

·      Third-Party Service Providers: Entities assisting with transaction processing, identity verification, or fraud prevention.

·      Regulatory Authorities: To comply with legal obligations, such as Japan’s Financial Services Agency (FSA) requirements.

·      Business Transfers: In case of mergers, acquisitions, or restructurings, subject to the same data usage purposes.

Third parties are required to protect your data in accordance with applicable laws.

Blockchain-Specific Disclosures

Some Services use blockchain technology, which records transactions immutably. Data added to the blockchain cannot be removed, ensuring transparency but limiting deletion options.

8. International Transfers

As a global platform, we may transfer your data outside Japan to third parties, including our mutual fund partners or service providers. We ensure protection through:

·      Transfers to countries with adequate data protection levels (e.g., EU-recognized jurisdictions).

·      Standard Contractual Clauses approved by relevant authorities.

Contact us for details on transfer mechanisms.

9. Data Security

We implement robust security measures, including SSL encryption, cold storage for cryptocurrencies, and two-factor authentication (2FA), to protect your data from unauthorized access, loss, or alteration. Note that our 2018 security breach (with funds refunded) highlights that no platform is immune to risks. We limit data access to authorized personnel and have procedures to address suspected breaches, notifying you and regulators as required.

10. Data Retention

We retain your data based on its nature, sensitivity, and purpose, in compliance with legal requirements (e.g., Japan’s APPI mandates retaining AML-related data for at least 7 years after the end of our relationship). We may retain data longer for litigation, audits, or fraud prevention. You may request deletion, subject to legal restrictions (see Section 11).

11. Your Legal Rights

Under Japan’s APPI and other applicable laws, you have the right to:

·      Access: Request access to your personal data.

·      Rectification: Correct inaccurate or incomplete data.

·      Erasure: Request deletion, subject to legal obligations (e.g., blockchain data may not be erasable).

·      Object: Oppose processing based on legitimate interests or for marketing purposes.

·      Restrict Processing: Suspend processing in certain cases (e.g., to verify data accuracy).

·      Data Portability: Receive your data in a structured, machine-readable format (where applicable).

·      Withdraw Consent: Revoke consent for processing, though this may limit Service access.

·      Oppose Automated Decisions: Challenge decisions made solely by automated means.

·      Complain: Contact Japan’s Personal Information Protection Commission or your local data protection authority.

To exercise these rights, contact info@nysefinance.com  We may verify your identity and respond within one month, as required by law. No fee is typically charged, but we may charge for excessive or unfounded requests.

Contact Us

For questions about this Privacy Policy, contact info@nysefinance.com Verify all communications through official ZE Nyse Finance channels to avoid phishing scams.

ZE Nyse Finance, operated by FISCO., is committed to protecting your privacy while delivering innovative financial services. Your trust is our priority.

© 2025 ZE Nyse Finance. All rights reserved.