tharwa

Privacy Policy

Last updated: August 17, 2026

1. Who is responsible for your data

1.1 The controller of your personal data is Tharwa Global Holdings Ltd, a company incorporated in the British Virgin Islands with company number 2193214 and registered office at Keyway Chambers, 3rd floor, Quastisky building, Road Town, Tortola, British Virgin Islands ("Tharwa", "we", "us"). Tharwa determines the purposes and means of processing your personal data in connection with the Interface described in the Terms of Service.

1.2 You can contact us about anything in this Policy at privacy@tharwa.finance, or by post at the registered office above.

1.3 Tharwa has appointed a Data Protection Officer, who can be reached at dpo@tharwa.finance. Where a supervisory authority requires a designated representative in a particular jurisdiction, that representative's details are set out in section 12.

2. What this Policy covers

2.1 This Policy explains what personal data we collect when you use tharwa.finance, app.tharwa.finance, our documentation, and any other interface we operate (together, the "Interface"), why we collect it, the legal basis on which we do so, who we share it with, how long we keep it, and the rights you have.

2.2 This Policy does not cover third-party services you may reach from the Interface, including wallet providers, exchanges, bridges and blockchain networks. Those services have their own privacy policies. Public blockchain data is outside our control and is addressed at section 6.

3. What we collect

3.1 Wallet and transaction data. When you connect a wallet we receive its public address and can see the transactions associated with it on the relevant blockchain. We record your acceptance of the Terms of Service against that address, with the version accepted and the time.

3.2 Identity verification data. Before you access certain functions we require identity verification, which is carried out by a specialist provider on our behalf. Depending on the function and the amounts involved, this may include your name, date of birth, nationality, residential address, an image of a government-issued identity document, and a live image or short video of your face for comparison against that document. The facial comparison involves processing of biometric data, which is a special category of personal data. Section 5 explains the basis on which we process it.

3.3 Contact and communication data. If you contact us, subscribe to updates, or participate in a community programme, we collect the contact details you provide and the content of your communications with us.

3.4 Technical and usage data. When you use the Interface we collect your IP address, approximate location derived from it, device and browser type, pages visited, and interactions with the Interface. Some of this is collected through cookies and similar technologies, which are described in section 9.

3.5 Access restriction data. We use your IP address and related signals to determine whether you are accessing the Interface from a jurisdiction from which access is restricted. Where access is refused, we record the country and time of the attempt. We do not retain your full IP address for that purpose beyond what is operationally necessary.

3.6 Programme and incentive data. If you participate in any points, rewards or governance programme, we collect the wallet addresses, activity and allocation data necessary to operate it.

4. Why we process your data and on what basis

4.1 To provide the Interface and perform our agreement with you, including recording acceptance of the Terms, enabling connection of your wallet, and displaying your positions. Basis: performance of a contract.

4.2 To verify your identity and screen against sanctions and other lists where required before you access particular functions. Basis: compliance with legal obligations to which we are subject, and our legitimate interest in preventing fraud, money laundering and sanctions evasion and in protecting the Interface and other users.

4.3 To restrict access from jurisdictions in which the Interface is not offered, and to maintain records demonstrating that restriction. Basis: compliance with legal obligations and our legitimate interest in operating lawfully.

4.4 To operate, secure, maintain and improve the Interface, to detect and prevent abuse, and to analyse how the Interface is used. Basis: our legitimate interest in operating a secure and functional service. Analytics that are not strictly necessary are subject to your consent under section 9.

4.5 To communicate with you about the Interface, respond to your enquiries, and, where you have agreed, send you updates. Basis: performance of a contract, our legitimate interest in communicating with users, and consent for marketing communications, which you may withdraw at any time.

4.6 To operate points, rewards or governance programmes in which you participate. Basis: performance of the programme terms.

4.7 To establish, exercise or defend legal claims, and to respond to lawful requests from courts, regulators and law enforcement. Basis: legitimate interest and legal obligation.

5. Biometric and other special category data

5.1 Identity verification may involve facial comparison, which processes biometric data. We do this only where verification is required for the function you are seeking to access, and only through our verification provider, which processes it on our documented instructions.

5.2 Before that processing takes place you will be asked for your explicit consent, separately from any other consent, and told what will be collected, why, by whom, and how long it will be kept. You may decline, in which case you will not be able to access functions that require verification, but you may continue to use any function that does not.

5.3 In addition to your explicit consent, we rely on the necessity of the processing for compliance with anti-money-laundering and sanctions obligations that apply to the functions concerned. Where you withdraw consent, we will cease further biometric processing but may be required by law to retain records of verification already completed for the period stated in section 8.

5.4 Biometric templates generated during verification are used only for the comparison and are not retained by us after verification is complete. Our provider's retention is limited to the period necessary to complete verification and any period it is required by law to retain records.

6. Blockchain data

6.1 Transactions on public blockchains are recorded permanently and publicly and cannot be modified or deleted by us or anyone else. Your wallet address and its transaction history are visible to anyone. If you link your identity to a wallet address, that link may allow others to associate public transaction data with you. We cannot erase, rectify or restrict blockchain data, and rights that depend on doing so cannot be exercised in respect of it.

7. Who we share your data with

7.1 Service providers who process data on our behalf and on our instructions: identity verification providers, hosting and infrastructure providers, analytics providers (subject to section 9), communication and support tools, and professional advisers. Each is bound by contract to protect your data and use it only for the purpose we specify.

7.2 Regulators, courts, law enforcement and other authorities, where required by law, where necessary to comply with legal process, or where we consider it necessary to protect our rights, the Interface or other users.

7.3 A successor or acquirer, in connection with any reorganisation, merger, sale or transfer of our business or assets, subject to that person assuming the obligations in this Policy.

7.4 We do not sell your personal data and do not share it with third parties for their own marketing.

8. How long we keep it

8.1 Wallet, acceptance and transaction records: for the duration of your use of the Interface and for seven years thereafter, or such longer period as required for the establishment or defence of legal claims.

8.2 Identity verification records, excluding biometric templates: for five years after the end of the relationship or the completion of the last transaction to which they relate, being the period required by applicable anti-money-laundering rules, or longer where required by a specific legal obligation.

8.3 Access restriction logs: aggregated by country and date, indefinitely; any full IP address associated with them, for no longer than thirty days.

8.4 Communications and support records: for three years after the last contact.

8.5 Technical and analytics data: for the periods stated in the cookie notice at section 9.

8.6 At the end of the applicable period we delete or irreversibly anonymise the data.

9. Cookies and similar technologies

9.1 The Interface uses cookies and similar technologies. Strictly necessary cookies, which are required for the Interface to function and to keep it secure, are set without consent. All other cookies, including analytics and any performance or preference cookies, are set only with your consent, which you give or refuse through the consent banner presented before any such cookie is set.

9.2 You may withdraw or change your consent at any time through the persistent cookie settings control on the Interface. Refusing non-essential cookies does not affect your ability to use the Interface.

9.3 The categories of cookies we use, their purposes, their providers and their durations are set out in the cookie notice accessible from the consent banner and the footer of the Interface.

10. International transfers

10.1 We and our service providers may process your data in countries other than the one in which you are located. Where we transfer personal data that is subject to the data protection laws of the European Economic Area, the United Kingdom or the British Virgin Islands to a country that has not been recognised as providing adequate protection, we do so under a lawful transfer mechanism, which will ordinarily be contractual clauses in the form approved by the relevant authority, supplemented where necessary by additional safeguards. Details of the mechanism applying to any transfer are available on request.

11. Your rights

11.1 Depending on where you are located and which law applies to our processing of your data, you may have the right to access the personal data we hold about you; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to certain processing; to receive data you provided to us in a portable format; and to withdraw any consent you have given, without affecting the lawfulness of processing before withdrawal.

11.2 You may exercise these rights by contacting privacy@tharwa.finance. We may need to verify your identity before responding. We will respond within the period required by applicable law, ordinarily one month, which may be extended where a request is complex.

11.3 You have the right to complain to a supervisory authority. If you are in the EEA or the UK, that is the authority in your country of residence or place of work; if you are in the British Virgin Islands, it is the Office of the Information Commissioner; if you are elsewhere, it is the authority responsible for data protection in your jurisdiction. We would welcome the opportunity to address your concern first.

11.4 We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, other than the automated screening involved in identity verification and sanctions checks, which is subject to human review on request.

12. Applicable law and legacy data

12.1 Tharwa is a British Virgin Islands company and its processing of personal data is governed by the Data Protection Act 2021 of the British Virgin Islands. Where we process personal data of individuals in the European Economic Area or the United Kingdom in the course of offering the Interface to them or monitoring their behaviour, the General Data Protection Regulation and the UK GDPR respectively also apply, and this Policy is drafted to comply with them.

12.2 The Interface is not offered to persons in the United Arab Emirates. Personal data relating to individuals in the United Arab Emirates that was collected before that restriction took effect continues to be held only for the retention periods in section 8 and for the purposes of complying with legal obligations, establishing or defending legal claims, and completing the orderly closure of any position. In respect of that data, we continue to recognise the rights conferred by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and requests may be made under section 11.

13. Children

13.1 The Interface is not directed at persons under 18 and we do not knowingly collect personal data from them. If we learn that we hold personal data of a person under 18 we will delete it.

14. Security

14.1 We apply technical and organisational measures appropriate to the risk to protect personal data against unauthorised access, loss, alteration and disclosure. No system is completely secure. If we become aware of a breach affecting your personal data that we are required to notify to you, we will do so without undue delay.

15. Changes to this Policy

15.1 We may update this Policy from time to time. The date at the top shows when it was last changed. Material changes will be notified through the Interface. Continued use after a change constitutes acceptance of the updated Policy to the extent permitted by law; where consent is required for a change, we will ask for it.

16. Contact

16.1 Privacy enquiries and rights requests: privacy@tharwa.finance. Data Protection Officer: dpo@tharwa.finance. General enquiries: team@tharwa.finance. Post: Tharwa Global Holdings Ltd, Keyway Chambers, 3rd floor, Quastisky building, Road Town, Tortola, British Virgin Islands.

Privacy Policy | Tharwa