Privacy Policy

Contents

1. Introduction

2. About Us

3. What is “Personal Data”?

4. How We May Use Your Personal Data

5. Lawful Basis for Processing

6. How We May Share Your Personal Data

7. Data Transfers

8. How We Secure Your Personal Data

9. Retention

10. Your Rights in Relation to Your Personal Data

11. Cookies and tracking technologies

12. Contacts

13. Changes to this Notice


1. Introduction

This Privacy Notice defines how Komainu collects, uses, stores and protects personal. It describes the types of personal data we process, the purposes for which it is used, and the rights individuals have in relation to their personal data under the General Data Protection Regulation, and other applicable data protection regulations in the relevant jurisdictions in which Komainu operates.

As the “data controller”, we are responsible for deciding how we process and store your personal data.

When we refer to “you” or “your” in this Notice, we mean the individual whose personal data we process.


2. About Us

We are a digital asset custody and financial services provider.

We are incorporated and registered in a number of jurisdictions. The details of these can be found on our website at https://komainu.com/entities/.


3. What is “Personal Data”?

“Personal data” is any information relating to an identified, or identifiable, natural person. Some types of personal data are more sensitive in nature and therefore requires greater protection – this is referred to as “special category data”.

We process personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ.


4. How We May Use Your Personal Data

How we use your personal data depends on your relationship with us and how you interact with our services:

4.1   Suppliers (including external consultants, vendors and service providers)

We collect identity and contact information, such as names, email addresses, phone numbers, and organisational information (including signatures). This is required to enable us to set up supplier accounts, communicate effectively with our suppliers, process payments, and manage agreements.

4.2   Clients

We collect identity and contact information, including names, email addresses, organisations, gender, job title, employment history, nationality, and date of birth, along with proof of identification, “Know Your Client” documentation and biometric data. We process this personal data to facilitate onboarding, conduct risk assessments, process requests, manage assets, calculate fees, and administer marketing activities.

4.3   Marketing Subscribers, Business Contacts, Social Media Users

We collect identity and contact information, including names, email addresses, phone numbers, organisations, job title, and location, as well as specific details like dietary requirements, and business information. We process this data to organise and manage events, accommodate dietary needs, and build on-going business relationships.

4.4   Website visitors, General enquirers

We collect limited technical information about how visitors use our website, such as pages viewed, interactions and device or browser details, to maintain security and improve performance.

Some of this information is obtained using cookies and other similar tracking technologies (see Cookies and Tracking Technologies for more information). Most cookies on this website are non-essential and require your consent before being set. Necessary cookies are always active, as they are essential for the website to function properly. You can withdraw your consent, or manage your preferences at any time, via the Cookiebot link in the footer of our website.

We will also use information that you provide to us in connection with an enquiry, to enable us to respond to you. This will include names, contact details and information submitted as part of your enquiry.


5. Lawful Basis for Processing

Where required by applicable data protection regulations, we rely on the following lawful bases for processing this information:

  • Performance of a contract, for instance, when communicating with suppliers regarding invoices, payments, or account queries
  • Legal obligation, for instance, when collecting and recording identification information for client controllers (directors and shareholders)
  • Consent, where you have chosen to provide it (for example, if you have consented to receiving marketing communications, which you can withdraw at any time)
  • Legitimate interests, where we have a legitimate interest to process your personal data such as when we administer client onboarding

6. How We May Share Your Personal Data

We may disclose your personal data to the following recipients:

  • Our suppliers, vendors and services providers where necessary
  • Professional advisers, including auditors, insurers and consultants, where necessary to obtain professional advice, support governance arrangements or manage insurance matters
  • Banks, payroll providers and financial institutions, to process payments, and other financial transactions

7. Data Transfers

As a global organisation, we may transfer personal data to other Komainu subsidiaries, suppliers, service providers and other third parties located outside the United Kingdom (UK), European Union (EU) and European Economic Area (EEA), including to countries that are not recognised as providing an adequate level of data protection. Where we do so, we ensure that appropriate safeguards are in place to protect personal data, such as the use of standard contractual clauses or other approved transfer mechanisms in accordance with the applicable data protection regulatory requirements.

If you would like more information about the international transfers we make and the safeguards we use to protect personal data, please contact us via privacy@komainu.com.


8. How We Secure Your Personal Data

We record, store and transmit your personal data in both paper and electronic formats. To ensure your personal data remains secure, we have implemented various technical and organisational measures to protect your personal data from loss, unauthorised use or access, alteration, or disclosure to unauthorised individuals.

We restrict access to your personal data to employees, contractors and trusted third parties who process personal data on our behalf. Our contracts with these parties include appropriate confidentiality clauses to protect the confidentiality of your data.

When selecting data processors (organisations that process personal data under our written instructions), we ensure they provide appropriate guarantees to safeguard your personal data.


9. Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

If you would like further information regarding how long we store your personal data, please contact privacy@komainu.com.


10. Your Rights in Relation to Your Personal Data

Subject to applicable data protection regulatory requirements, you have a number of rights in relation to your personal data which may include:

  • The right to be informed about how we collect and use your personal data
  • The right of access, which allows you to request a copy of your personal data and certain supplementary information
  • The right to rectification, which allows you to ask us to correct inaccurate personal data or complete data that is incomplete
  • The right to erasure (sometimes referred to as the ‘right to be forgotten’), which enables you to request the deletion your personal data in certain circumstances. However, this is a qualified right and does not apply in all situations. For example, we may need to retain your personal data where processing is necessary to comply with a legal obligation
  • The right to restrict processing allows you to ask us to limit how we use your personal data in certain circumstances, for example where you contest the accuracy of the data or object to our processing
  • The right to data portability, which allows you to receive personal data you have provided to us and reuse it across different services, where applicable
  • The right to object to the processing of your personal data in certain circumstances, particularly where processing is based on legitimate interests
  • Rights relating to automated decision-making and profiling, including the right not to be subject to a decision based solely on automated processing, where that decision produces legal or similarly significant effects

If you wish to exercise any of these rights, please contact privacy@komainu.com.


11. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to improve functionality, analyse website usage and support security. Further information about the cookies we use, including how to manage your preferences, is available via our cookie banner and on the cookie settings accessible on the bottom left of our website footer.

12. Contacts

Our Head of Enterprise Risk has responsibility for ensuring that this Notice remains accurate and up to date. If you have any questions about this Notice, or how we process your personal data, please contact privacy@komainu.com.

If you are dissatisfied with how we process your personal data, you also have the right to lodge a complaint with your local data protection authority. Details of the relevant authorities are provided below:

12.1 Jersey

Jersey Information Commissioner’s Office (ICO) address is:

Jersey Office of the Information Commissioner
2nd Floor, 5 Castle Street
St. Helier, Jersey
JE2 3BT

12.2 Singapore

The Personal Data Protection Commission’s (PDPC) address is:

10 Pasir Panjang Road

#03-01 Mapletree Business City

Singapore 117438

Website: https://www.pdpc.gov.sg/complaints-and-reviews 

12.3 United Kingdom

The Information Commissioner Office’s address is:

The Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

United Kingdom

Website: https://ico.org.uk/global/contact-us/contact-us-public/

12.4 United Arab Emirates

The Data Office’s official website: https://uaelegislation.gov.ae/en 


13. Changes to this Notice

Any future changes to this Notice will be posted on our website and, where appropriate, via email notification. Unless otherwise specified, all such changes will be effective immediately after they are posted on our website.

Privacy Notice last updated: August 2026