Privacy Policy
1. INTRODUCTION
Coingalaxy Pty Ltd (“Coingalaxy”, “we”, “our”, or “us”) is committed to protecting your personal information and complying with applicable data protection and privacy laws. In Australia, this includes the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). In Europe, we comply with the General Data Protection Regulation (EU) 2016/679 (GDPR), and in Mexico, we comply with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
This Privacy Policy sets out our approach to the collection, use, storage, disclosure, and protection of your personal data. It also explains your rights and how you can access or correct your data, or lodge a complaint.
This Policy operates in conjunction with our Terms of Service. Copies of this Policy are available free of charge on our website (coinreserve.net) or by contacting our Privacy Officer.
In this Policy:
- ‘Disclosing’ means providing personal data to third parties outside of Coingalaxy.
- ‘Personal information’ or ‘personal data’ refers to any information relating to an identified or identifiable individual.
- ‘Sensitive information’ refers to special categories of personal data including data on race, ethnicity, religion, politics, health, sexual orientation, and union membership.
- ‘Privacy Officer’ refers to the appointed Data Protection Officer (DPO) or designated privacy lead for handling inquiries or complaints.
- ‘Use’ means any action taken involving personal data including storing, processing, or analysing.
- ‘Platform’ is defined as per our Terms of Service.
2. WHAT KINDS OF PERSONAL INFORMATION DO WE COLLECT AND HOLD?
We may collect a wide range of personal information including:
- Identity and contact details: Full name, date of birth, addresses, email addresses, phone numbers, employment data, identification documents, and utility bills.
- Financial and transactional information: Bank and digital currency account details, transaction history, preferences, and behavioural data.
- Technical and device information: IP addresses, browser type and version, operating system, device identifiers, cookies, and metadata.
- Communications and support history: Records of interactions, support requests, or technical issues logged via our Platform or helpdesk.
Failure to provide required data may result in limited access to our services.
3. HOW DO WE COLLECT PERSONAL INFORMATION?
We collect personal data directly from you, including when:
- You register, create an account, or complete onboarding forms;
- You contact us via phone, email, or live chat;
- You interact with our website or Platform.
We may also collect information from third-party providers such as:
- Identity verification services;
- Referral partners;
- Public registries.
Where we collect data from third parties, we take reasonable steps to notify you and confirm your consent if required.
Sensitive data will only be collected with your consent unless an exemption applies under applicable law.
4. COOKIES AND ONLINE TRACKING
Our website uses cookies and similar tracking technologies. These help:
- Improve the functionality and usability of our Platform;
- Monitor performance and usage;
- Provide relevant marketing or advertising content.
You can manage cookie settings via your browser. Disabling cookies may affect your user experience.
5. UNSOLICITED PERSONAL INFORMATION
If we receive personal data that we did not actively request:
- We will assess whether it is necessary for our functions;
- If not, we will securely delete or anonymise the data, as required under both Australian law and the GDPR’s data minimization principles.
6. WHO DO WE COLLECT PERSONAL INFORMATION ABOUT?
We may collect information about:
- Current and prospective customers;
- Business partners and service providers;
- Staff and applicants (for internal purposes).
7. WHY DO WE COLLECT PERSONAL INFORMATION?
We use your personal information for purposes including:
- Providing our services, including onboarding and account maintenance;
- Communicating with you regarding your account;
- Fulfilling legal and regulatory obligations (e.g., AML/CTF, taxation, dispute resolution);
- Conducting risk, fraud, or financial crime assessments;
- Informing you about updates or promotions;
- Performing analytics and service improvements;
- Ensuring cybersecurity and data integrity.
We do not use personal data for purposes inconsistent with the reason it was collected, unless permitted by law or with your explicit consent (as required under GDPR and LFPDPPP).
8. WHO DO WE DISCLOSE PERSONAL INFORMATION TO?
Your data may be disclosed to:
- Our affiliates, partners, and subsidiaries;
- Cloud storage and IT infrastructure providers;
- Identity verification, compliance, and KYC service providers;
- Financial institutions and payment processors;
- Government agencies and regulators (e.g., AUSTRAC, ASIC, CNBV, or EU regulators);
- Legal, tax, or professional advisors;
- Parties involved in corporate transactions (e.g., M&A);
- Dispute resolution bodies or courts;
- Any party you authorise us to share information with.
Where disclosure occurs outside Australia, the EU, or Mexico, we take appropriate safeguards (e.g., Standard Contractual Clauses or equivalent agreements) to ensure data protection compliance.
9. INTERNATIONAL DATA TRANSFERS
We may transfer data across jurisdictions, including to Southeast Asia, Europe, and Mexico. When doing so, we ensure:
- The recipient has adequate data protection standards;
- Appropriate safeguards such as GDPR Article 46 mechanisms or Mexico’s applicable contractual clauses are in place;
- You are notified if required.
10. HOW WE SECURE YOUR PERSONAL INFORMATION
We take robust technical and organizational security measures to protect data, including:
- Password-protected systems and two-factor authentication;
- Role-based access controls;
- End-to-end encryption of sensitive transmissions;
- Secure storage via Microsoft Azure and AWS platforms;
- Employee training and background checks.
11. DIRECT MARKETING
We may contact you for direct marketing only where:
- It complies with the Privacy Act, GDPR, and LFPDPPP;
- You have provided your consent or we have a legitimate interest;
- You are given a clear and simple opt-out mechanism in each communication.
You may also request:
- To opt out of all future marketing;
- Disclosure of the data source (where permitted under law).
12. MAINTAINING YOUR PERSONAL INFORMATION
We aim to ensure your data is accurate and current. You may:
- Update or correct your information by contacting us;
- Request corrections to inaccurate or outdated information;
- Expect us to notify third parties of changes, where applicable.
13. ACCESSING YOUR PERSONAL INFORMATION
You may request access to your personal data at any time. We will:
- Respond within 30 days;
- Require proof of identity;
- Provide data unless a lawful exception applies (e.g., legal privilege or unreasonable impact on others).
14. UPDATES TO THIS POLICY
We may amend this Policy in response to changes in law, operations, or data processing practices. We encourage regular review of our privacy practices. Where required by GDPR or LFPDPPP, we will notify you of significant changes and seek your renewed consent where necessary.
15. OUR RESPONSIBILITIES
Management ensures:
- Ongoing training for all personnel on privacy compliance;
- Regular audits and internal reviews;
- Appropriate escalation and accountability measures for data breaches or policy violations;
- Designation of a Data Protection Officer or equivalent contact person.
16. COMPLAINTS AND CONTACT INFORMATION
For privacy inquiries or complaints, please contact our Privacy Officer at: support@coinreserve.net
If unresolved, you may escalate your complaint to:
- Australia: Office of the Australian Information Commissioner (OAIC) – enquiries@oaic.gov.au
- European Union: Your local Data Protection Authority – Submit complaint
- Mexico: Instituto Nacional de Transparencia (INAI) – atencion@inai.org.mx
Risk Disclosure Statement
Coingalaxy Pty Ltd ("We", "Us", "Our", "Coingalaxy", the "Company") is authorised and registered with the Australian Transaction Reports and Analysis Centre (AUSTRAC). In addition, Coingalaxy complies with regulatory obligations and consumer protection standards in the European Union (under directives such as MiFID II, the GDPR, and EMD2) and Mexico (as required by the Ley Fintech, the Financial Consumer Protection Bureau (CONDUSEF), and relevant CNBV guidelines).
IMPORTANT – PLEASE READ CAREFULLY
This Risk Disclosure Statement ("Statement") is a general overview of risks associated with the financial products and services provided by Coingalaxy. This Statement is not intended to be legal, financial, or investment advice. Coingalaxy makes no representation that the investments or services described herein are appropriate for you. This Statement should not be the sole source of your decision-making.
Before engaging with our platform, services, or products, you should assess the potential risks and obtain independent professional advice appropriate to your circumstances. Investing in financial instruments, including digital assets and derivatives, involves risks that may result in partial or total loss of capital.
GENERAL RISK FACTORS
- Systemic Risk: Failure of interconnected financial institutions may impact market function.
- Market Risk: Prices may fluctuate due to economic, political, or external factors.
- Currency Risk: FX volatility may impact cross-border investments.
- Interest Rate Risk: Changes in rates affect asset value.
- Issuer Risk: The risk of insolvency by an equity or debt issuer.
- Credit Risk:
- Default Risk: Borrowers or counterparties may default.
- Counterparty Risk: Third parties may fail to meet obligations.
- Liquidity Risk: You may be unable to exit positions without incurring significant losses, especially in illiquid markets.
- Criminal Risks: Corruption, fraud, and theft in certain jurisdictions may impact investment outcomes.
REGULATORY AND LEGAL RISKS
Different jurisdictions impose varying legal obligations. Regulatory changes, currency controls, and nationalisation can affect investments. In the EU, MiFID II mandates clear risk disclosures and consumer protections. In Mexico, the Ley Fintech and CNBV circulars establish rules for fintech operations and investor protection. Coingalaxy complies with these frameworks to the extent applicable.
TAX RISK
Tax treatment of digital assets and financial products may vary by jurisdiction and change over time. In the EU, local tax laws and DAC7 reporting obligations may apply. In Mexico, SAT regulations govern income reporting. You should consult a qualified tax professional.
SUSPENSIONS OF TRADING
Market volatility may cause delays, halts, or suspensions of trading, limiting your ability to buy or sell assets. Stop-loss orders may not be effective in extreme conditions.
OPERATIONAL AND TECHNOLOGICAL RISKS
System outages, cyberattacks, and technological failures may interrupt access to your account or delay trade execution. Coingalaxy maintains redundancy systems, but risk cannot be entirely eliminated.
INTERNET AND ONLINE ACCOUNT SECURITY
Online platforms carry inherent security risks. You are responsible for securing your account credentials. Any communication or transaction via the internet is at your own risk.
CONFLICTS OF INTEREST
We may face actual or perceived conflicts of interest. Please refer to our Conflicts of Interest Policy for details on mitigation and management.
PRODUCT-SPECIFIC RISKS
- Equities: Subject to price volatility and issuer risk.
- Debt Securities: Subject to interest rate, credit, and liquidity risks.
- Money Market Instruments: Offer lower returns with interest rate and credit risk exposure.
- FOREX: Highly leveraged; influenced by geopolitical, economic, and environmental events.
- Options: Complex derivatives that may lead to total capital loss. Both buyers and sellers bear significant risk.
- Futures/Forwards: May result in unlimited losses. Contingent liability contracts may require margin calls.
- Warrants: Highly geared, may expire worthless.
- Private Equity: High risk, low liquidity, limited transparency.
- Real Estate: Impacted by economic, political, and environmental factors.
- Hedge Funds: Unregulated, high-risk strategies, and complex structures.
- Commodities: High volatility and exposure to physical delivery or regulatory shifts.
- Structured Products: Depend on underlying instruments. May include credit event clauses and valuation delays.
MARKET DISRUPTION EVENTS AND EARLY TERMINATION
Market disruption events may lead to valuation delays, suspension of trading, or early termination of instruments. These are defined under ISDA protocols or as per issuer terms.
FINAL STATEMENT
This Statement is intended to fulfil our disclosure obligations under applicable Australian, European, and Mexican law. We encourage you to read this alongside our Terms of Service, Privacy Policy, and other regulatory documents available on our website.
If you have questions or require clarification, contact us at support@coinreserve.net.
Conflicts of Interest Policy
Coingalaxy Pty Ltd (ABN 50 643 368 496) (“Coingalaxy”, “We”, “Us”, or “Our”) is an AUSTRAC-registered Digital Currency Exchange provider. This Conflicts of Interest Policy (“Policy”) sets out our commitment to the fair treatment of clients and to upholding integrity in all jurisdictions in which we operate.
Purpose
The purpose of this Policy is to outline how Coingalaxy identifies, manages, and discloses any actual or potential conflicts of interest arising during the course of its business activities. The Policy ensures compliance with relevant regulatory requirements in each jurisdiction and preserves the transparency and fairness of our services.
Scope
This Policy applies to Coingalaxy, its directors, officers, employees, contractors, agents, and any other person directly or indirectly linked to the Company. It is applicable across all investment and financial services offered by the Company.
Conflicts may arise:
Framework for Conflict Management
Coingalaxy has adopted internal systems and procedures to ensure that conflicts of interest are properly identified, assessed, and mitigated. Where conflicts cannot be entirely prevented, they must be disclosed clearly to affected clients.
The Company:
Identification of Conflicts
Conflicts of interest may include (but are not limited to):
A “relevant person” includes:
All employees and management are required to report actual or potential conflicts to the Compliance Officer (CO) without delay.
Management and Mitigation Measures
Coingalaxy applies the following practices to manage conflicts:
Specific Controls
To prevent and manage conflicts, the Company has implemented:
Segregation of Assets
To protect client funds and assets, Coingalaxy:
Prohibited Business Conduct
The following conduct is strictly prohibited:
Employee Obligations
All employees must:
Disclosure Requirements
When organisational arrangements are not sufficient to fully mitigate risks, Coingalaxy will:
Disclosures by Employees and Management
Employees and management must disclose:
Compliance Review and Oversight
The Compliance Officer is responsible for:
This Policy remains subject to regulatory updates and guidance issued by AUSTRAC, the European Securities and Markets Authority (ESMA), and the financial authorities in each relevant operating jurisdiction.