OFFCODE
Sign inCreate account

Privacy Policy

OFFCODE · Dubai, UAE — governed by the laws of the United Arab Emirates.

Last updated: May 13, 2026

1. Who we are and what this policy covers

OFFCODE is a cryptocurrency platform operated by OFFCODE, headquartered in Dubai, United Arab Emirates, at the domain offcode.pro, offering services for buying, selling, custody and trading of crypto assets, serving a global market.

This Privacy Policy describes how we collect, use, share, store and protect your personal data, adopting international data protection standards (including the principles of the UAE PDPL and the GDPR) and international anti-money-laundering (AML) practices aligned with the FATF recommendations.

By using our services, you agree to the terms described below. If you disagree, you must stop using the platform and request the deletion of your account under the terms of section 9.

2. Personal data collected

We collect the following data, classified by purpose:

  • (a) Identification data: full name, official identity document number (e.g., CPF/RG/CNH for residents in Brazil, or equivalent document), date of birth, nationality, gender, marital status, occupation.
  • (b) Contact data: residential address, email, mobile phone number.
  • (c) Verification data (KYC): photo/scan of an official document (front and back), selfie with the document, proof of address from the last 3 months (electricity, water or phone bill, or bank statement).
  • (d) Financial data: transaction history on the platform, balances, deposits and withdrawals, source IP of operations.
  • (e) Usage data: IP address, user-agent (browser, operating system), access date and time, pages visited, devices used.
  • (f) Platform-generated data: order history, fills, futures positions, conversions performed, authentication logs, security events.

For business (corporate) users (KYB): we additionally collect the company registration number, constitutive documents (articles of incorporation/bylaws), and the list of partners and legal representatives with their identification data.

3. Purposes and legal bases

We process your personal data on the following internationally recognized legal bases:

Performance of a contract: creating and managing your account, processing spot, futures, conversion, deposit and withdrawal operations.

Compliance with a legal obligation: mandatory KYC under international anti-money-laundering standards (AML/FATF); reporting suspicious transactions to the competent authorities when required.

Legitimate interest: fraud and money-laundering prevention, monitoring against cyberattacks, continuous improvement of services.

Consent: marketing communications, newsletters, push notifications, affiliate programs — you can revoke this at any time at /preferencias.

Risk management: risk analysis on significant withdrawals, holds on suspicious operations.

4. Data sharing with third parties

We do not sell your personal data. We share it with third parties strictly when necessary to operate our services or comply with legal obligations:

Essential subprocessors:

  • Supabase (US): authentication and identity — stores email, password hash, session data and 2FA.
  • AWS KMS (US, us-east-1): cryptographic keys for wallet custody — never has access to your identifiable personal data.
  • Cloudflare (US/Global): CDN, WAF, DDoS protection — processes access logs, IP and user-agent for up to 30 days.
  • DigitalOcean (US): hosting of the database and application.
  • Resend (US): delivery of transactional emails (verification, OTP, notifications).
  • Execution venue (BVI): futures execution engine — receives order execution data (no direct PII).

Public authorities: competent regulatory, tax and law-enforcement authorities — upon a valid legal request or a regulatory obligation applicable to OFFCODE.

Commercial partners: only with your explicit consent, in a referral program or opt-in integrations.

5. International data transfer

Some subprocessors (Supabase, AWS, Cloudflare, DigitalOcean, Resend) operate servers in different jurisdictions, mainly in the United States. We carry out international transfers under the following safeguards:

  • Data Processing Agreements (DPA) with each subprocessor, containing standard protection clauses;
  • Providers certified under recognized frameworks (SOC 2, ISO 27001);
  • Technical assurance of encryption at rest (AES-256) and in transit (TLS 1.3);
  • You can request the up-to-date list of subprocessors and their locations via [email protected].

6. Cookies and similar technologies

We use cookies and local storage to operate the platform. Categories:

Strictly necessary: login session, theme preferences (dark/light), language, hide-balances. These do not require consent as they are essential to the operation of the service.

Functional: persisting preferences such as the default category on /markets, favorite pair on /futures. Not shared with third parties.

Analytics (subject to consent): Cloudflare Web Analytics — cookieless, with no individual identification. Only aggregated pageview statistics.

You can block cookies in your browser settings, but this may degrade essential functionality (login, persistence of preferences).

7. Data security

We implement technical and organizational measures aligned with international frameworks (SOC 2, ISO 27001) and industry best practices:

  • Encryption at rest: AES-256 on sensitive fields (KYC documents, banking data).
  • Encryption in transit: TLS 1.3 with HSTS preload on all connections.
  • Key custody: AWS KMS, with segregation by function (gas, liquidity, perpetuals, master).
  • Multi-factor authentication: TOTP 2FA mandatory on withdrawals above US$ 50; email OTP on withdrawals above US$ 50; manual approval on withdrawals above US$ 10,000.
  • Monitoring: real-time anomaly detection, velocity limits (3 withdrawals/hour per user).
  • Address whitelist: withdrawal addresses must be pre-registered with a 24-hour cooldown.
  • Continuous auditing: immutable logs of all financial operations (double-entry accounting journal), periodic review of privileged access.
  • Team training: information security policies, just-in-time access, principle of least privilege.

Technical details on custody at /security.

8. Data retention

We retain your personal data for as long as necessary to fulfill the purposes described, in accordance with the applicable legal obligations:

5 years (after account closure): transactional data, KYC, operation records — in accordance with international anti-money-laundering (AML) standards and applicable limitation periods.

5 years: audit logs of financial operations.

2 years (after the last interaction): marketing data, newsletters.

Indefinite: anonymized data used for internal statistical analysis.

After the legal periods end, data is securely deleted or irreversibly anonymized.

9. Your rights as data subject

You have the following rights over your personal data:

  • (I) Confirmation and access: to know whether we process your data and obtain a copy in a structured format.
  • (II) Correction: to request the correction of incomplete, inaccurate or outdated data.
  • (III) Anonymization, blocking or deletion: for data that is unnecessary, excessive or processed in non-compliance.
  • (IV) Portability: to receive your data in CSV or JSON format for use with another provider.
  • (V) Deletion: of data processed on the basis of consent, except where there is a legal retention obligation.
  • (VI) Information about sharing: an up-to-date list of subprocessors and purposes.
  • (VII) Information about withholding consent: the consequences of refusing consent.
  • (VIII) Withdrawal of consent: for processing based on consent.

To exercise any right, email [email protected] or open a ticket at /contact with the subject "Privacy". We respond within 15 business days.

If you find our response unsatisfactory, you may contact the competent data protection authority in your jurisdiction of residence.

10. Data Protection Officer (DPO)

We have appointed a Data Protection Officer (DPO) as the channel for communication with data subjects and data protection authorities:

Email: [email protected]

Headquarters: Dubai, United Arab Emirates

Role: to handle data subject requests, communicate with data protection authorities, advise employees on privacy and oversee compliance.

11. Minors

Our services are intended exclusively for people over 18 years of age. We do not knowingly collect data from minors. If we identify a minor's registration, we will close the account and delete the data immediately, except where we are required to retain it by legal requirement.

If you are a parent or guardian and suspect that a minor under your care has created an account, contact us at [email protected] so we can take action.

12. Changes to this policy

We may update this Privacy Policy periodically to reflect regulatory changes, new services or best practices. Substantial changes will be communicated at least 30 days in advance via:

  • Email to the registered address;
  • Notice in the platform dashboard after login;
  • Update of the "Last updated" field at the top of this page.

If you do not agree with the changes, you may request the closure of your account before they take effect.

13. Final provisions

This Policy is governed by the laws of the United Arab Emirates. Any dispute will be settled in the competent courts of Dubai, UAE, without prejudice to mandatory rights guaranteed by the data protection legislation of the data subject's jurisdiction of residence.

Should any provision be deemed invalid or unenforceable, the remaining provisions will remain in full force and effect.

Last updated: May 13, 2026.