TransferBank — Terms & Conditions and Privacy Policy
Effective date: August 29, 2025
This combined document provides the legally binding Terms & Conditions governing your use of TransferBank and the Privacy Policy explaining how we process personal data. Please read carefully. If you do not agree, do not use our Services.
Placeholders to replace: [Legal Entity Name], [Registered Address], [Country of Incorporation], [Company Number], [Contact Email], [DPO Email], [EU/UK Representative], [Governing Law Country/State], [Arbitration Venue], [Supervisory Authority], [Consumer Complaint Email].
1) Definitions
- “TransferBank”, “we”, “us”, “our” — [Legal Entity Name], incorporated in [Country of Incorporation], company number [Company Number].
- “Services” — international exchange services for digital assets (including cryptocurrencies) and, where applicable, fiat on/off-ramps, wallet tools, price quotes, order routing, and related support.
- “Digital Assets” — cryptographic tokens, coins and other digital representations of value recorded on distributed ledgers.
- “User”, “you”, “your” — any natural or legal person accessing or using the Services.
- “KYC/AML” — “Know Your Customer” and anti-money laundering/counter-terrorist financing measures under applicable law.
- “VASP Travel Rule” — FATF Recommendation 16 information-sharing obligations for virtual asset transfers.
2) Who We Are & Scope
TransferBank is an international exchange service operated by [Legal Entity Name], with its registered office at [Registered Address]. We are not a bank or investment advisor and do not provide personalized investment, tax, or legal advice.
- These Terms govern access to and use of the Services worldwide, subject to local restrictions.
- By creating an account or using the Services, you accept these Terms and our Privacy Policy.
- Corporate users must ensure an authorized representative accepts these Terms on their behalf.
3) Eligibility & Restricted Jurisdictions
- You must be at least 18 years old (or the age of majority in your jurisdiction) and have the legal capacity to enter into contracts.
- You confirm you are not subject to sanctions or located in embargoed/otherwise restricted jurisdictions and are not on any government sanctions/denied-party lists (e.g., OFAC, EU, UK, UN).
- We may restrict or refuse Services in certain jurisdictions due to regulatory or risk considerations. Restricted jurisdictions include those designated by applicable sanctions and high-risk lists.
4) Services; No Financial Advice; Risks
- No Advice. Information on our website/app is for general information only. It does not constitute investment, financial, legal, accounting or tax advice.
- Market Risks. Digital assets are volatile. Values may fluctuate significantly and may become worthless. You may lose all funds.
- Technology Risks. Blockchain congestion, network forks, smart-contract bugs, wallet loss, and cyber events may affect transactions.
- Regulatory Risks. Regulations may change and impact availability, pricing, or legality of certain assets/activities.
- Irreversibility. Most blockchain transfers are irreversible and final once broadcast/confirmed.
5) Accounts, KYC/AML & Travel Rule
- Registration. You must provide accurate, current information and keep it updated. We may require identity, address, source-of-funds, and other documentation.
- Verification. We use third-party vendors (e.g., identity verification and sanctions screening providers) to perform KYC/AML checks. You authorize us to share necessary data with such vendors under contractual safeguards.
- Travel Rule. Where applicable, you authorize us to collect/transmit originator/beneficiary information to other VASPs or obliged entities for qualifying transfers.
- Monitoring. Transactions may be monitored for AML/CFT, sanctions, fraud and compliance purposes. Suspicious activity may be reported to competent authorities without notice.
- Security. You are responsible for safeguarding your credentials, MFA, devices and recovery information. Notify us immediately of suspected compromise.
6) Fees, Limits, Taxes & Refunds
- Fees. We disclose fees and network costs prior to order execution where feasible. Network fees may vary.
- Limits. We may impose per-transaction, daily, monthly or rolling limits; limits may change based on verification level and risk.
- Taxes. You are solely responsible for reporting and paying any taxes arising from use of the Services.
- Refunds/Chargebacks. Digital-asset transfers are typically non-refundable. Fiat refunds (if any) are evaluated case-by-case subject to AML/sanctions review.
7) Acceptable Use & Prohibited Activities
You agree not to use the Services for illegal purposes, including but not limited to:
- Money laundering, terrorist financing, fraud, sanctions evasion or prohibited financial services.
- Distribution of malware or attempts to compromise the Services.
- Activities violating IP rights, privacy, or applicable consumer/financial regulations.
We may refuse, block, freeze or reverse transactions (where possible) and/or suspend accounts if we reasonably suspect policy breaches or legal violations.
8) Intellectual Property & Licenses
- All content and software in the Services are owned by TransferBank or our licensors and protected by IP laws.
- We grant a limited, revocable, non-exclusive, non-transferable license to access and use the Services as permitted by these Terms.
- Do not copy, modify, reverse-engineer, or create derivative works except as allowed by law.
9) Suspension & Termination
- We may suspend or terminate access with or without notice for suspected policy breaches, legal requests, risk concerns, or prolonged inactivity.
- We may retain and/or freeze assets where required by law or court/authority order.
- Certain clauses survive termination (e.g., AML obligations, IP, limitations of liability, dispute resolution).
10) Disclaimers, Warranties & Liability
- AS IS. The Services are provided “as is” and “as available” without warranties of any kind unless required by law.
- No Guarantee. We do not guarantee uninterrupted, error-free, or secure operation.
- Limitation. To the maximum extent permitted by law, we are not liable for indirect, incidental, special, punitive or consequential damages, or lost profits/revenue/data.
- Cap. Our aggregate liability for claims relating to the Services will not exceed the fees you paid us in the 3 months preceding the event giving rise to the claim (or the minimum amount required by law).
- Indemnity. You agree to indemnify and hold us harmless from claims arising from your misuse of the Services or breach of these Terms.
11) Governing Law, Disputes & Complaints
These Terms are governed by the laws of [Governing Law Country/State] without regard to conflicts of laws rules.
Complaint Handling
First, contact us at [Consumer Complaint Email] with a detailed description. We aim to respond within 30 days.
Dispute Resolution
Option A (Courts): Exclusive jurisdiction of courts located in [Arbitration Venue or City] unless mandatory law states otherwise.
Option B (Arbitration): Binding arbitration under the rules of [Arbitration Institution] in [Arbitration Venue], language: English. (Choose one option and delete the other.)
Language. The English version of these Terms prevails over translations.
12) Changes to the Terms
We may modify these Terms at any time. Updates take effect when posted with a new effective date. Continued use after changes means you accept the updated Terms.
Privacy Policy
TransferBank respects your privacy and processes personal data in accordance with applicable laws, including GDPR/UK-GDPR and, where relevant, CCPA/CPRA and other regional laws.
1) Controller & Contact
Controller: [Legal Entity Name], [Registered Address].
Contact (privacy): [Contact Email] • DPO: [DPO Email].
EU/UK Representative (if required): [EU/UK Representative and address].
Supervisory Authority (example): If you are in the EEA/UK, you can lodge a complaint with your local authority or [Supervisory Authority].
2) Data We Collect
A. Data you provide
- Identification: name, DOB, nationality, ID documents, selfies/biometrics (where lawful).
- Contact: email, phone, address.
- Financial: payment instruments, wallet addresses, transaction details.
- Compliance: source of funds/wealth, occupation, sanctions/PEP screening results.
- Support: communications, tickets, feedback.
B. Data we collect automatically
- Technical: IP, device IDs, OS/browser, language, time zone.
- Usage: pages viewed, clicks, session metadata, referral URLs.
- Security: logs, fraud signals, login history, risk scores.
- Cookies/SDKs: essential and optional (see Cookies section).
C. Data from third parties
- KYC/AML vendors (identity verification, sanctions/PEP lists, adverse media).
- Financial partners (banks, payment processors, other VASPs under Travel Rule).
- Analytics, security, and cloud providers.
3) Purposes & Sources
- Provide and operate the Services; process orders and transfers.
- Comply with legal obligations (KYC/AML, sanctions screening, Travel Rule, bookkeeping).
- Prevent fraud and secure accounts; investigate suspicious activity.
- Customer support, service communications, incident notices.
- Improve performance, usability and features; analytics/metrics.
- Marketing with your consent and subject to opt-out rights.
4) Legal Bases (GDPR/UK-GDPR)
- Contract — to deliver the Services you request.
- Legal obligation — KYC/AML, sanctions, accounting, consumer protection.
- Legitimate interests — security, fraud prevention, service improvement.
- Consent — certain cookies, marketing, biometrics where required.
- Vital interests/Public interest — where applicable (e.g., preventing serious crime).
5) Sharing & International Transfers
- Service providers / processors: cloud hosting, analytics, KYC/AML, support, communications.
- Financial institutions & VASPs: to process payments/transfers and comply with Travel Rule.
- Authorities & regulators: where required by law, court order, or for enforcement of rights.
- Corporate transactions: mergers, acquisitions or restructuring, subject to safeguards.
Cross-border transfers: We use appropriate safeguards, such as EU Standard Contractual Clauses (and UK Addendum), plus technical/organizational measures.
6) Security
- Encryption in transit (TLS) and at rest (where applicable), access controls, MFA support, logging and monitoring.
- Vendor due diligence and minimum security requirements.
- Incident response procedures and breach notification as required by law.
7) Data Retention
We retain personal data only as long as necessary for the purposes described, including to meet legal/AML record-keeping obligations, resolve disputes, and enforce agreements. See Annex B for indicative periods.
8) Your Rights
GDPR/UK-GDPR (EEA/UK)
- Access, rectification, erasure, restriction, objection, portability.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your supervisory authority.
CCPA/CPRA (California)
- Right to know, delete, correct, and non-discrimination.
- Opt-out of “sale” or “sharing” of personal information (links below).
- Limit the use/disclosure of sensitive personal information.
Requests. Email us at [Contact Email]. We will verify your identity (and authority, if an agent) before acting on requests.
10) Children
Our Services are not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children.
11) Changes to this Privacy Policy
We may update this Privacy Policy periodically. Material changes will be posted with a new effective date and, where required, we will seek consent.
Contact & Notices
TransferBank — [Legal Entity Name][Registered Address]
Email: [Contact Email]
DPO: [DPO Email]
Annexes
Annex A — Sub-processors (Illustrative)
We rely on carefully selected providers under data-processing agreements:
Category | Purpose | Region |
---|---|---|
Cloud hosting | App/DB infrastructure | EU/US/UK (SCCs where needed) |
KYC/AML | Identity verification, sanctions/PEP screening | Global |
Analytics/Security | Usage metrics, threat detection | Global |
Comms | Email/SMS notifications | Global |
Payments | Card/bank processing, VASP transfers | Global |
We maintain an up-to-date list available upon request or via our status/privacy page.
Annex B — Indicative Data Retention Schedule
Data Category | Typical Retention | Notes |
---|---|---|
Account profile | Active + 6 years | To service account and for legal claims. |
KYC/AML records | 5–10 years | Subject to AML laws of the relevant jurisdiction(s). |
Transaction records | 7–10 years | Tax and accounting requirements. |
Security logs | 12–24 months | Fraud prevention and incident response. |
Marketing consents | Until withdrawn + audit period | Proof of consent. |
Support tickets | 2–4 years | Customer service history, dispute handling. |
When retention expires, we securely delete or anonymize data unless further retention is legally required.
Annex D — US/California Consumer Links
Wire these links to your actual preference center/API endpoints.Annex E — Glossary
- Processor: A party that processes personal data on behalf of the Controller.
- PEP: Politically Exposed Person.
- SCCs: EU Standard Contractual Clauses for international data transfers.