This Ethena Pay Privacy Policy (this "Policy") is applicable to all users of the Ethena Pay Platform and Services (the "Platform" and the "Services," each as described more completely under the Ethena Pay Terms of Use). The Platform and the Services consist only of software made available to users ("you" or "your") by Ethena Pay Ltd., a company incorporated and registered in Malta with company number C 114576 and registered office at 30/1 Kenilworth, Triq Sir Augustus Bartolo, Ta' Xbiex, XBX 1093, Malta (including its operators and affiliates, "we," "our," or "us"), acting as data controller for the purposes of the EU General Data Protection Regulation (2016/679) ("GDPR") and applicable national data protection laws, subject to and as governed by the Ethena Pay Terms of Use and this Policy. Our designated data protection contact can be reached at privacy@ethenapay.co. This Policy applies to information collected through your access to or use of the Platform and the Services, including through any websites, mobile or desktop applications, application programming interfaces (APIs), integrations, communications, or other digital properties or services operated, maintained, or controlled by us that link to or reference this Policy.
By registering for, accessing, or using the Platform or the Services, you accept and agree to be bound by this Policy. Any capitalized terms used in this Policy but not otherwise defined herein have the meanings assigned to such terms by the Ethena Pay Terms of Use.
1. Your Personal Information
1.1 Collection of information, including Personal Information
We collect information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you, your household, your account or profile, your device, or your use of the Platform or the Services ("Personal Information"). Personal Information does not include aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, except where applicable law provides otherwise. We may collect Personal Information that you provide through the Platform or the Services, including when you create or maintain an account or profile, connect a wallet or third-party account, submit payment or transfer instructions, communicate with us, or interact with our partners, suppliers, or Third-Party Providers. To the fullest extent permitted by applicable law, we may collect any of the following information (notwithstanding whether certain elements of any such information are or are not considered to be "Personal Information" or "Personal Data" under applicable privacy or data protection laws):
- Your name, company information, street address, email address, phone number, date of birth, government-issued photo identification and related information, taxpayer identification number, proof of address, source of funds information, biometric or liveness information, and other information or documentation requested for account opening, identity verification, fraud prevention, sanctions screening, transaction monitoring, tax, legal, regulatory, or compliance purposes;
- Information relating to your wallet, balances, card program access, payment or transfer instructions submitted through the Platform or the Services, and transaction-related information made available to us by Third-Party Providers, public blockchain networks, distributed ledgers, local payment rails, card networks, or other service providers in connection with the Services;
- Public wallet addresses, public keys, blockchain networks, token types, transaction hashes, transaction amounts, transaction timestamps, payment instructions, transfer recipients, payees, merchants, balance information, transaction status information, transaction history, account or profile settings, and card-program information (note: we do not ask you to provide, and you should not provide, any private key, seed phrase, wallet recovery phrase, or wallet password);
- Information about the devices, software, and networks you use to access the Platform or the Services, including IP address, device identifiers, session identifiers, device type, operating system, browser or client, referral URLs, session timestamps, feature usage metrics, system activity logs, performance data, error reports, audit logs, security events, and crash diagnostics; and
- Information about you from other sources, including our affiliates, partners, suppliers, Third-Party Providers, public blockchain networks, publicly available sources, and third parties with whom you have authorized a connection, integration, or data sharing arrangement.
1.2 Use of your Personal Information
Your Personal Information might be shared with Third-Party Providers, between us and our partners or suppliers, or to other entities based on any separate requests you might make to us. We do not sell your Personal Information to third parties, and we do not otherwise make commercial use of your Personal Information other than for business purposes directly related to supporting the provision of the Platform or the Services to you or as otherwise specified below. Categories of third parties with whom we share Personal Information include:
- identity verification and KYC/AML service providers;
- payment processors and card network operators;
- cloud hosting and infrastructure providers;
- analytics and performance monitoring providers;
- customer support platforms;
- fraud detection and security vendors;
- professional advisers (legal, audit, compliance); and
- regulators and law enforcement as required by law.
Each such third party is contractually required to process your Personal Information only for the purposes described in this Policy and to maintain appropriate security standards. Where we use third-party SDKs or analytics tools within our mobile applications, those SDKs may collect device identifiers, usage data, and crash diagnostics in accordance with their own privacy policies, which we encourage you to review. Our partners or suppliers who have access to some Personal Information are prohibited from selling this information (other than in anonymized or aggregated form) to third parties.
When you provide Personal Information like your phone number or email address, such as when registering for an account to use or access the Platform or the Services, we may use it to reach you to fulfill your request, answer your questions, verify your identity or eligibility, or obtain or associate additional information about you or your organization.
1.3 Lawful Bases and Purposes of Use
Where we process Personal Information of individuals in the European Economic Area ("EEA") or United Kingdom ("UK"), we do so on one or more of the following lawful bases under Article 6 GDPR:
performance of a contract with you or to take steps at your request prior to entering a contract;
- compliance with a legal obligation to which we are subject;
our legitimate interests (including fraud prevention, security, and service improvement), where those interests are not overridden by your rights; or
- your consent, where we have obtained it.
Where we rely on legitimate interests, you have the right to object to such processing (see Section 5 below).
To the fullest extent permitted by applicable law, we may also use your information as reasonably necessary to:
- Produce for our own purposes, in aggregated or anonymized form, any reports, analytics, research, or internal business insights;
- Optimize how we provide the Platform and the Services, including enhancements to design, maintenance, operations, or security;
- Customize or enhance your experience on the Platform or when using or accessing the Services, provide you with information on or access to our products or services or those of our partners or suppliers, support wallet, balance display, payment, transfer, card program, account management, and related functionality, or to communicate with you about those products or services;
- Comply with applicable legal processes, tax obligations, recordkeeping obligations, and governmental or regulatory requests; conduct or support identity verification, customer due diligence, sanctions screening, politically exposed person screening, adverse media screening, fraud screening, wallet screening, transaction monitoring, source-of-funds reviews, liveness checks, document verification, and other compliance, risk-management, or security reviews;
- Enforce the Ethena Pay Terms of Use and other applicable terms, policies, and agreements;
- Detect, prevent, investigate, and respond to fraud, misuse, security incidents, any activity prohibited by the Ethena Pay Acceptable Use Policy, or any other potential or suspected harmful or unlawful activity; and
- Protect the rights, property, or safety of us, our users, our partners or suppliers, Third-Party Providers, or others.
1.4 Our uses and purposes of Personal Information in the last year
Within the previous 12 months, we have only used Personal Information for the limited purposes identified in this Policy and have not sold any Personal Information about you but may have disclosed Personal Information of any of the below categories to our partners or suppliers for a professional business purpose. Although we never "sell" Personal Information, we may occasionally disclose Personal Information to Third-Party Providers or certain of our partners or suppliers for business purposes as necessary to (i) assess and improve the Platform or the Services or (ii) detect, stop, and report fraud, financial crimes, or improper access.
1.5 Disclosure of your Personal Information
We only disclose your Personal Information to those of our partners, suppliers, or other service providers with appropriate controls for handling and protecting your Personal Information, or otherwise to those Third-Party Providers whom you authorize to make a connection to the Platform or the Services. Except for Third-Party Providers to whom you separately authorize a connection or linked account, we impose contractual obligations on service providers to ensure they only use your Personal Information in accordance with applicable law as necessary to provide services to us or you. To the fullest extent permitted by applicable law, we may disclose whatever information we might have or know about you, including your Personal Information (including in an encoded or hashed format where appropriate), without providing you with additional notice or obtaining your consent, to:
- Third-Party Providers, consultants, advisors, auditors, and professional firms that provide advice, products, or services to us, or that help us operate, secure, or improve the Platform, the Services, or any other of our services, features, or content (or those of our partners or suppliers) and their value to users of the Platform or the Services, including identity verification and screening service providers, authentication providers, on-chain monitoring or analytics providers, custodians, financial institutions, stablecoin issuers, card issuers, payment networks and processors, cloud service providers, customer support vendors, and security vendors;
- A potential acquirer, successor, or other participant in connection with any merger, acquisition, reorganization, financing, bankruptcy, dissolution, or sale of all or substantially all of our business assets;
- Regulators, law enforcement authorities, courts, government agencies, or other third parties to whom disclosure of your information is required or permitted by applicable law, regulation, subpoena, court order, or legal process, or that is reasonably necessary to enforce or take appropriate action under the Ethena Pay Terms and Conditions or other agreements; or
- Other third parties when reasonably necessary to detect, prevent, or respond to fraud, misuse, security incidents, financial crimes, to address other legal, regulatory, operational, or compliance matters, or to protect the rights, property, or safety of us, our users, the Platform, the Services, or our partners and suppliers.
1.6 Your geolocation information
When you access or use the Platform or the Services, we may use cookies, device information, IP address information, network information, and similar technologies to discern your general geolocation information from the IP address associated with your computer or mobile device. We use this information to support general analytics, business, and communications functions, and to help discern your location within or connection to any jurisdiction that might be restricted under the Ethena Pay Terms of Use. You may be able to limit certain collection of geolocation information by adjusting your browser or device settings or disabling certain cookies (though you may not do so for the purpose or intent of circumventing any geographically based controls or restrictions), by ceasing use of or access to the Platform or the Services, or by cancelling or terminating your account in accordance with the Ethena Pay Terms of Use. We also reserve the right to block or restrict your access to the Platform or the Services for any reason (such as on the basis of your IP address or otherwise as provided in the Ethena Pay Terms of Use) and may reject any request to register for an account or access or use the Platform or the Services if we are unable to confirm your location.
1.7 Your responses to surveys or emails
We may from time to time administer, or work with a third party to administer, surveys to users of the Platform or the Services, or to visitors of any website or social media profile under our control. Additionally, if you receive emails or other communications from us requesting information in connection with your use of or access to the Platform or the Services, you may opt out of receiving non-essential or non-administrative communications by selecting "unsubscribe" at the footer of those communications, or by requesting to opt out in writing by contacting Ethena Pay Support. You may not opt out of communications that are necessary or reasonably related to your account, security, compliance, legal, transactional, or administrative matters.
1.8 How long we keep your information
We retain your Personal Information only for as long as is necessary for the purposes set out in this Policy and in compliance with applicable law. The table below sets out our standard retention periods by data category. Where a legal obligation requires retention beyond the period you maintain an active account, we retain data for the period mandated by that obligation, after which it is securely deleted or anonymized.
| Data category | Examples of data | Retention period |
|---|---|---|
| Identity and KYC/CDD documents | Name, date of birth, government-issued ID, proof of address, source of funds, biometric/liveness data | 5 years after the end of the business relationship |
| Transaction records | Payment instructions, transfer details, blockchain transaction data, card program records | 5 years from the date of the transaction |
| Sanctions, PEP, and adverse media screening results | Screening records and related due diligence outputs | Duration of the business relationship + 5 years after closure |
| Account profile and registration data | Email, phone, account settings | Duration of the account + 1 year after closure, unless a longer period is required by law |
| Device, technical, and usage data | IP address, device identifiers, session logs, crash diagnostics | 12 months from collection |
| Communications and support records | Emails, chat logs, support tickets | 3 years from the date of the communication |
| Survey and feedback data | Survey responses and product/service feedback | 2 years from collection |
| Marketing consent records | Consent and withdrawal records | Duration of consent + 3 years after withdrawal |
| Fraud detection and security incident records | Fraud alerts, investigation materials, security incident logs | 5 years from the date of the incident |
At the end of the applicable retention period, or following receipt of a valid deletion request (subject to the exceptions set out in Section 5.1(d)), we will securely delete or anonymize your Personal Information. Where deletion is not immediately possible (for example, because data is stored in backup archives), we will isolate the data from further processing and delete it as soon as practicable. We will not keep your Personal Information for longer than necessary for the purposes identified in this Policy, and we will not retain it where retention is not required or permitted by applicable law, regulation, legal process, contractual obligation, security need, compliance obligation, or legitimate business purpose.
1.9 Feedback
If you are accessing or using the Platform or the Services in any beta environment, in connection with any testing, in connection with any authorized bounty program, or otherwise, any written input or feedback you provide to us (or to our partners or suppliers via the official channels designated by us) is exclusively our property, including any bug reports, disclosure of actual or suspected errors or defects, or written evaluations of new features ("Feedback"). In providing Feedback, you agree to provide material, statistics, written statements, and other data and information that is not considered confidential to you or any company you might represent. We may use such Feedback for any purpose in our discretion, including informing improvements to the Platform or the Services or for use in press releases, public statements, user testimonials, or other business or marketing materials. We will own and retain all right, title, and interest in and to your Feedback, as well as the intellectual property rights in the Platform, the Services, and the underlying beta software (including any derivative works thereof), subject only to the limited license expressly set forth in the Ethena Pay Terms of Use. You do not acquire or retain any other rights, either express or implied or in whole or in part, in the Feedback or the Platform, the Services, or any underlying text, code, or schema.
1.10 Your responsibilities when submitting Feedback
You agree that Feedback does not and will not (a) contain or be recompilable into your Personal Information or the Personal Information of any third parties (including financial data, account information, or other personal information), (b) contain your or your company's original ideas or inventions or be provided to us subject to payment or conditions, (c) once conveyed to us, be considered the property or confidential information of anyone other than us, or (d) be used or distributed to any other persons or entities or for any other purpose except within our sole and absolute discretion. All rights not expressly granted hereunder or under the Ethena Pay Terms of Use are reserved to us. If you do transmit to us or our partners or suppliers by any means or by any media any materials or other information (including but not limited to Personal Information, ideas, concepts, or techniques for new or improved services and products), whether as Feedback or other information, data, questions, comments, suggestions, or otherwise, then you do so at your own risk. Although we will work as reasonable to remove or otherwise protect any Personal Information you include in such submissions in violation of this Section 1.10, you agree that such submissions could go unrestricted and might not be considered confidential or proprietary information or Personal Information of any kind unless and until you identify to us the details of your mistaken disclosure, and you accordingly automatically grant us and our assigns a non-exclusive, royalty-free, worldwide, perpetual, irrevocable license, with the right to sublicense, copy, transmit, distribute, create derivative works of, display, or otherwise use such information for any purpose and within our sole and absolute discretion.
1.11 Data security and safeguards
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and security of Personal Information that we collect, store, or process. These safeguards include, where appropriate, access controls, encryption, network security measures, monitoring, logging, and employee training. No method of transmission over the Internet or method of electronic storage is completely secure. Although we strive to protect your information, we cannot guarantee its absolute security. You acknowledge and agree that you provide your information to us at your own risk. You are responsible for maintaining the security of your own devices, credentials, authentication methods, private keys, seed phrases, wallet recovery phrases, and wallet software, and we are not responsible for the security of blockchain networks, distributed ledgers, non-custodial wallets, third-party wallets, third-party systems, local payment rails, card networks, or other systems, devices, or infrastructures not controlled by us. In the event of any suspected or confirmed data security incident involving Personal Information, we will investigate the incident and take reasonable steps to mitigate potential harm in accordance with internal policies and applicable law. Where required by applicable law, we will provide notice to affected individuals and relevant authorities within the timeframes prescribed by law.
1.12 International data transfers
The Platform and the Services are provided to you by us from Malta (or by one of our affiliates in a different jurisdiction, if and as identified under the Country-Specific Terms in Appendix 1 of the Ethena Pay Terms of Use). With sole exception to any Personal Information that is required to be held by a local data controller under applicable law, if you access or use the Platform or the Services from outside Malta, then you acknowledge and agree that your information, including Personal Information, could be transferred to, processed, and stored in Malta or other jurisdictions where we, our partners, suppliers, Third-Party Providers, or service providers maintain facilities. Such jurisdictions might have data protection or privacy laws that differ from those in your place of residence. Where we transfer Personal Information of EEA or UK data subjects to countries not recognized as providing an adequate level of data protection, we ensure that appropriate safeguards are in place in accordance with applicable law, including by entering into the European Commission's Standard Contractual Clauses (SCCs) (or the UK International Data Transfer Agreement / Addendum, as applicable) with the relevant recipients, or by relying on another transfer mechanism permitted under Chapter V of the GDPR. You may request a copy of the applicable transfer safeguards by contacting us at privacy@ethenapay.co.
1.13 Automated information processing; no professional advice
Certain features of the Platform and the Services might rely on automated processing, algorithms, and machine learning techniques to process information you provide to us or to any Third-Party Providers or to generate outputs, communications, or other information that we or any Third-Party Providers might provide or return to you. Any such information provided to you could be incomplete, inaccurate, outdated, or inappropriate for you, and under no circumstances should such information be considered advice of any kind, professional or otherwise.
1.14 Automated decision-making (EEA/UK)
For users in the EEA or UK: We may use automated decision-making, including profiling, in connection with identity verification, sanctions screening, fraud detection, transaction monitoring, and access eligibility assessments. Such decisions may have legal or similarly significant effects on you (for example, account suspension or transaction blocking). The logic involved includes automated comparison of your submitted information against regulatory watchlists, risk-scoring models, and behavioural analytics. You have the right to request human review of any such decision, to express your point of view, and to contest the decision by contacting us at privacy@ethenapay.co. This right does not apply where the decision is necessary for the performance of a contract with you or is required by applicable law.
1.15 Third-Party Services
The Platform and the Services could contain links to, integrate with, or enable access to third-party websites, platforms, applications, content, or services that are not owned or controlled by us but by certain of the Third-Party Providers or other third parties (the "Third-Party Services"), including identity verification and screening service providers, authentication providers, on-chain monitoring or analytics providers, custodians, financial institutions, stablecoin issuers, card issuers, payment networks and processors, cloud service providers, customer support vendors, and security vendors. This Policy applies to information collected by us through the Platform and the Services and to information that we receive from Third-Party Services in connection with our ongoing development, maintenance, and provision of the Platform or the Services. We do not control, and we are not responsible for, the privacy practices, data handling, security, or content of any third parties in connection with the delivery of any Third-Party Services. Your interactions with Third-Party Services, including account or profile linking, identity verification, wallet connections, payments, transaction processing, card program access, Digital Asset conversion, compliance screening, or other services provided by them, are governed by their respective privacy policies and terms and not by this Policy. We encourage you to review the privacy policies and terms of applicable Third-Party Services before providing corresponding third parties with your information, connecting accounts or wallets, or using any services made available through or in connection with the Platform or the Services.
2. Cookies
2.1 What cookies are
To ensure optimal performance and support your ability to use and access the Platform and the Services, we and our partners or suppliers, as well as other third parties, may install and use cookies. Cookies are small text files generated when you access the Platform or otherwise use or interact with the Services and are used to collect your internet browsing information. All cookies that we use are safe for your device and only process the information stored on your browser. These cookies cannot execute code, do not contain malware or viruses, and cannot be used to access content stored on your device.
2.2 How we use cookies
The use of cookies in connection with providing the Platform and the Services is critical or otherwise broadly integral to the performance of the Platform and the Services. We may also use certain non-essential cookies or similar tracking technologies for purposes like (a) analytics, to understand how you interact with the Services, (b) security, compliance, and fraud prevention, to detect fraud or misuse, and (c) optional purposes, such as personalization or marketing, where permitted by applicable law.
2.3 Blocking or deleting cookies
If you would like to reject cookies, or if you would like to remove the cookies to which you previously consented, you can modify your browser settings to block or delete cookies. The means by which you may refuse cookies in your web browser settings could vary depending on the browser or device you use. See your web browser's help menu for more information. If you choose to block or refuse any cookies that are essential to core functionality, then the Platform or the Services could become inaccessible, render them inoperable, or otherwise materially affect or hinder their performance.
2.4 "Do Not Track" and GPC signals
Some web browsers and devices permit users to enable "Do Not Track" signals or Global Privacy Control ("GPC") signals. At this time, except to the extent required to do so by applicable law, the Platform and the Services do not respond to or honor "Do Not Track" signals. Where required by applicable law, we recognize and process valid Global Privacy Control signals as a request to opt out of the sale or sharing of Personal Information, where applicable.
3. Information Collected Through Other Technologies
3.1 Web beacons
From time to time, we may use other tracking technologies similar to cookies called "web beacons" (or "tracking pixels" or "clear gifs") to monitor traffic patterns on the Platform, other interfaces or channels used by us, or between various features associated with the Services and to deliver or communicate with cookies. Web beacons are small graphics that display a unique identifier that allows us to recognize when someone has visited the Platform, interacted with a website, or opened an email from us. Web beacons help us to improve the performance of the Platform and the Services and understand whether a user visit is directed from certain external sources. Web beacons are largely reliant on cookies to function properly, so blocking or rejecting cookies can impair web beacon functionality and, in turn, the performance or efficiency of the Platform or the Services.
3.2 Local storage and similar technologies
From time to time, we may use browser-based local storage or other similar technologies (for example, HTML5 local storage, IndexedDB, or other local data caching mechanisms supported by your browser or device) to collect and store limited information about your use of the Platform and the Services, to remember your settings and preferences, to prevent fraud or misuse, and to support other operations. These technologies store data locally on your device and are typically managed through your browser or device settings. If you do not want us to store information using these local storage technologies, you can configure your browser or device to limit or disable local storage features where supported; however, doing so could impair the functionality or performance of some aspects of the Platform or the Services.
3.3 Targeted advertising
The Third-Party Providers and other third parties may use web beacons or other technologies in connection with your use of your device to send or display advertisements to you, but we do not enable targeted advertising on, through, or in connection with the Platform or the Services.
4. Important Restrictions
4.1 Geography
Use of and access to the Platform and the Services are available only in jurisdictions where we have expressly authorized the Platform or the Services to be available and where such use or access is not prohibited by applicable law, regulation, sanctions requirements, Third-Party Provider requirements, or our compliance, security, risk management, or operational controls. If you are located in, domiciled in, or accessing the Platform or the Services from any jurisdiction where the Platform or the Services are not authorized or are restricted, then you must not visit, access, or use the Platform or the Services or register or access any account or profile with us. You must not use a VPN, proxy, or any other method to obscure your geographic location if doing so is intended, or would tend, to circumvent geographic-based restrictions or controls we or any Third-Party Provider may impose in connection with maintaining and providing the Platform or the Services. We may reject any registration, restrict functionality, suspend access, or terminate access to the Platform or the Services if we are unable to confirm your location or if we determine that your location, domicile, residency, or access presents legal, regulatory, sanctions, security, compliance, risk management, or operational concerns.
4.2 Children's Privacy
The Platform and the Services are directed to a specific audience but not at children under the age of 18. We do not knowingly collect or solicit Personal Information or any other information from any person under the age of 18 or knowingly allow them to use or interact with the Platform or the Services. If you are under 18, you must not visit, access, or use the Platform or the Services, register or access any account or profile with us, or participate in or attend any forum, discussion, or event we might host. If we obtain actual knowledge that the Personal Information of a child under age 18 was or is being collected through the Platform or the Services, we will delete that information as quickly as possible. If you believe we might have collected any information from or about a child under the age of 18, please contact privacy@ethenapay.co immediately.
5. Treatment of Personal Information
5.1 Permitted Actions
You may request to take any of the below listed permitted actions in connection with any Personal Information that might be held by us or otherwise in connection with our provision of the Platform and the Services (each, a "Permitted Action"):
Know and confirm. You may request that we confirm whether we have or have processed any of your Personal Information, identify the general sources of such Personal Information, and disclose the general business purposes for which we have collected and used your Personal Information.
Access. You may request to access or have identified to you the certain Personal Information that we have collected from or about you.
Obtain copies. You may obtain copies of your Personal Information that you previously provided to us.
Request deletion. You may request deletion of Personal Information we have collected from you, subject to certain exceptions, such as if we continue to provide the Platform, the Services, or other products or services to you or your organization, or when we are required by applicable law or internal policy to retain your Personal Information.
Correct inaccuracies. You may request that we correct inaccurate Personal Information we have about you, taking into account the nature of such Personal Information and the purposes for its processing.
Opt out of processing for targeted advertising. If we ever begin adopting or permitting targeted advertising in connection with the provision of the Platform and the Services, you may opt out of the processing of your Personal Information for such purposes.
Opt out of information sales. If we ever begin adopting or permitting the sale of Personal Information in connection with the provision of the Platform and the Services, you may request that we do not sell your Personal Information to third parties, now or in the future.
Opt out of profiling. You may opt out of the processing of your Personal Information for profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
Restriction of processing. If you are located in the EEA or UK, you may request that we restrict the processing of your Personal Information in the circumstances set out in Article 18 GDPR (for example, where you contest the accuracy of your data or have objected to processing based on legitimate interests, pending verification).
Data portability. If you are located in the EEA or UK and we process your Personal Information on the basis of your consent or for the performance of a contract, you have the right to receive a copy of your Personal Information in a structured, commonly used, and machine-readable format, and to request that we transmit it to another controller where technically feasible (Article 20 GDPR).
Right to withdraw consent. Where we process your Personal Information on the basis of your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, contact us at privacy@ethenapay.co.
Right to lodge a complaint. If you are located in the EEA or UK and believe that our processing of your Personal Information infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority in your country of residence or the lead supervisory authority for our processing activities. For users in Malta, the competent authority is the Information and Data Protection Commissioner (
). For users in other EEA member states, a list of national supervisory authorities is available at
edpb.europa.eu/about-edpb/about-edpb/members_en
.
5.2 Submitting requests for Permitted Actions
To request any Permitted Action, submit it in writing to Ethena Pay Support with the subject line of "Requested Action Pertaining to User Personal Information." In your communication, be as specific as possible, identifying each of the specific points or types of Personal Information relevant to your request. We will endeavor to fulfill any Permitted Actions requested by you within a commercially reasonable time or otherwise in accordance with law. We will likely need to verify your identity before processing your request, such as by requiring you to log into your account or matching sufficient information provided by you with the information maintained in our systems (which could necessitate requesting additional Personal Information from you). We may in certain circumstances deny your request, particularly if we are unable to verify your identity or if otherwise permitted by applicable law, the reasons for which we will notify you by electronic communication or otherwise in writing.
5.3 Non-discrimination
We will not discriminate against any user in connection with their requested exercise of any of the actions listed in Section 5.1. If there are any specific non-discrimination rights that might be afforded to you relevant to your Personal Information under applicable law in the jurisdiction where you reside, then the exercise of such rights must be pursued in accordance with the Country-Specific Terms in Appendix 1 of the Ethena Pay Terms of Use.
5.4 Exercising any rights afforded to you under applicable law
If there are any specific non-discrimination rights that might be afforded to you relevant to your Personal Information under applicable law in the jurisdiction where you reside, or if applicable law affords you any other rights related to your Personal Information, then you must pursue the exercise of such rights in accordance with the Country-Specific Terms in Appendix 1 of the Ethena Pay Terms of Use.
6. Changes to This Privacy Policy
We may update or modify this Policy from time to time in our sole discretion to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes to this Policy, we will update the "Last Updated" date at the top of this Policy and provide advance notice of such changes through the Platform (for example, via an in-app notification or banner) and/or by email to the address associated with your account, at least 30 days before the changes take effect where required by applicable law or where reasonably practicable. For users in the EEA or UK, where material changes affect processing activities for which we rely on your consent, we will seek fresh consent before the new processing begins. Your continued use of or access to the Platform or the Services after any changes to this Policy become effective will constitute your acknowledgment of the updated Policy.
7. Contact Us
If you have any questions, concerns, or requests regarding this Policy or our privacy practices, please contact us at privacy@ethenapay.co.