BITISIE

Last updated: June 25, 2026

Your Privacy Matters

Privacy Policy

We are committed to protecting your personal information. This Policy explains in plain language what data we collect, why we collect it, how we use and protect it, and the choices you have.

Effective Date June 25, 2026
Version v1.1
GDPR Compliant Yes
CCPA Compliant Yes
Sections 16 sections

Our commitment in plain language: We collect only what we need to provide our services. We never sell your personal data. Your financial information stays private. You have the right to access, correct, or delete your data at any time. We use bank-grade encryption to protect everything. If you have questions, contact us or email support@bitisie.com.

01Introduction

Bitisie LLC ("Bitisie," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and protect information about you when you:

  • Visit our website at www.bitisie.com or any related digital property;
  • Create an account or use our investment management platform;
  • Communicate with us via email, live chat, telephone, or in person;
  • Use any of our wealth management, advisory, or financial planning services;
  • Subscribe to our newsletters, market insights, or research publications.

This Policy applies to all personal information we process, regardless of the format (electronic, paper, or verbal) and regardless of whether you are a prospective, current, or former client.

Our core commitment: We will never sell, rent, or trade your personal data to third parties for their marketing purposes. Your data is used to serve you, and nothing else.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our privacy practices, please do not use our Services.

02Who We Are

Bitisie LLC is an investment adviser registered with the U.S. Securities and Exchange Commission (SEC). For the purposes of applicable data protection laws, Bitisie is the data controller responsible for your personal information.

Our group includes the following entities that may process your personal data:

Entity Jurisdiction Regulator Role
Bitisie LLC United States SEC / FINRA Primary data controller
Bitisie (UK) Ltd United Kingdom FCA UK data controller
Bitisie Pte. Ltd. Singapore MAS APAC data controller
Bitisie DIFC Ltd United Arab Emirates DFSA ME data controller

Our Data Protection Officer (DPO) can be reached at dpo@bitisie.com. Our UK representative for GDPR purposes is Bitisie (UK) Ltd, 1 Canary Wharf, Level 32, London E14 5AB.

03Data We Collect

We collect the following categories of personal information, depending on the nature of your relationship with us:

3.1 Identity & Contact Information

  • Full legal name (first name, last name);
  • Date of birth and nationality;
  • Email address, telephone number, and postal address;
  • Country of residence and tax residency;
  • Government-issued identification (passport, driver's licence, national ID);
  • Profile photo (if voluntarily provided).

3.2 Financial & Investment Information

  • Bank account details (account number, sort code / routing number) for fund transfers;
  • Investment portfolio holdings, transaction history, and performance data;
  • Net worth, income, and liquidity information (for suitability assessments);
  • Investment objectives, risk tolerance, and investment horizon;
  • Tax identification numbers (SSN, EIN, NI number, TIN);
  • Referral codes used at account registration.

3.3 Technical & Usage Information

  • IP address, browser type and version, operating system;
  • Device identifiers and mobile device information;
  • Pages visited, links clicked, time spent on pages, and navigation patterns;
  • Login timestamps, session duration, and feature usage data;
  • Error logs and performance data.

3.4 Communication Records

  • Emails, live chat transcripts, and secure messages sent to or received from us;
  • Call recordings (where permitted by law and with prior notice);
  • Survey responses, feedback submissions, and testimonials (with consent).

3.5 Compliance & Due Diligence Information

  • KYC and AML verification documents and results;
  • PEP (Politically Exposed Person) and sanctions screening results;
  • Source of funds and wealth documentation;
  • Credit reference and identity verification outcomes.

We do not collect sensitive personal data (such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data) unless you expressly volunteer it or unless required by law. Where we do process such data, we will obtain your explicit consent.

04How We Collect Your Data

We collect personal information through the following channels:

4.1 Directly From You

  • When you complete our account registration form (name, country, email, password);
  • When you complete KYC/AML verification and upload identity documents;
  • When you communicate with us via email, live chat, phone, or in person;
  • When you fund your account or request withdrawals;
  • When you complete our financial planning questionnaires or risk assessments;
  • When you subscribe to our newsletters or download resources;
  • When you participate in surveys, promotions, or referral programmes.

4.2 Automatically Through Technology

  • Cookies and similar tracking technologies when you visit our website or use our platform (see Section 12);
  • Server logs that automatically record your IP address, browser, and access times;
  • Analytics tools that measure platform usage, performance, and user behaviour;
  • Security monitoring systems that detect and log unusual access patterns.

4.3 From Third Parties

  • Identity verification and KYC providers (e.g. Jumio, Onfido) who validate your documents;
  • Credit reference agencies for fraud prevention and suitability assessments;
  • Government and commercial databases for sanctions and PEP screening;
  • Our independent custodian for account and transaction data;
  • Social login providers (Google, Apple) if you choose to sign up using OAuth;
  • Data brokers, only to the extent necessary for compliance with applicable law.

05Why We Use Your Data

We use your personal information for the following purposes:

Purpose Description Legal Basis
Account Management Opening, operating, and maintaining your account; authenticating your identity; processing instructions. Contract performance
Service Delivery Providing portfolio management, financial planning, advisory, and all related services. Contract performance
Legal Compliance KYC/AML verification, tax reporting, regulatory filings, responding to legal requests. Legal obligation
Risk Management Fraud detection, sanctions screening, suitability assessments, credit risk evaluation. Legitimate interest / Legal obligation
Communications Sending account statements, trade confirmations, service updates, and mandatory notices. Contract performance / Legal obligation
Marketing Sending newsletters, market insights, and promotional content about our services. Consent (opt-in)
Platform Improvement Analysing usage data to improve our platform, features, and user experience. Legitimate interest
Security Protecting our platform, detecting threats, investigating breaches, and ensuring integrity. Legitimate interest / Legal obligation
Dispute Resolution Resolving complaints, managing legal claims, and enforcing our agreements. Legitimate interest / Legal obligation

We will not use your personal information for any purpose incompatible with those described above without first obtaining your consent or having another lawful basis to do so.

06Legal Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA), the United Kingdom, or other jurisdictions with similar data protection laws, we rely on the following legal bases under Article 6 of the GDPR (and equivalent legislation) to process your personal information:

  • Performance of a Contract (Art. 6(1)(b)): Processing necessary to open and manage your account, execute investment instructions, and provide the services you have engaged us for.
  • Compliance with a Legal Obligation (Art. 6(1)(c)): Processing required by applicable laws including SEC regulations, AML/KYC rules, tax reporting obligations, and financial record-keeping requirements.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, including fraud prevention, platform security, improving our services, and managing legal claims, provided these interests are not overridden by your rights and freedoms.
  • Consent (Art. 6(1)(a)): Where we rely on your consent, such as for marketing communications, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

For special category data (if applicable), we rely on explicit consent (Art. 9(2)(a)) or another applicable exception. You may request our full processing record at any time by contacting our DPO.

07How We Share Your Data

We do not sell your data. We do not sell, rent, or lease your personal information to any third party for commercial or marketing purposes ever.

We share your personal information only in the following limited circumstances:

7.1 Service Providers (Data Processors)

We engage carefully selected third-party service providers who process your data on our behalf under strict data processing agreements. These include:

  • Our independent custodian and executing brokers who hold your assets and execute trades;
  • Identity verification and KYC providers for account onboarding;
  • Cloud infrastructure providers for secure data storage and platform operations;
  • Email and communication platforms for delivering statements and service notifications;
  • Analytics and security vendors for platform improvement and threat detection;
  • Payment processors for fund transfers.

All service providers are required to maintain appropriate security standards and may only use your data for the specific purpose for which we have engaged them.

7.2 Regulatory & Legal Authorities

We may disclose your information to regulators, law enforcement agencies, courts, or other government bodies where required or permitted by applicable law, including but not limited to: the SEC, FINRA, FinCEN, IRS, FCA, MAS, DFSA, or in response to valid legal process such as subpoenas, court orders, or regulatory examinations.

7.3 Professional Advisers

We may share your information with our legal counsel, auditors, insurers, and other professional advisers who are bound by duties of confidentiality.

7.4 Corporate Transactions

In the event of a merger, acquisition, sale of assets, or restructuring of our business, your personal information may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy. We will notify you of any such transfer.

7.5 With Your Consent

We may share your information with other parties where you have given us your express consent to do so.

08International Data Transfers

As a global firm with offices in New York, London, Singapore, Dubai, Sydney, and São Paulo, your personal information may be transferred to and processed in countries outside your country of residence, including countries that may not offer the same level of data protection as your home jurisdiction.

When transferring personal data from the EEA or UK to countries not deemed "adequate" by the European Commission or the UK ICO, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs): We use the EU Commission's standard contractual clauses (2021/914) and the UK International Data Transfer Agreement (IDTA) as appropriate;
  • Adequacy Decisions: Transfers to countries with an adequacy decision from the European Commission or UK Secretary of State;
  • Binding Corporate Rules: Intra-group transfers within our global entity network are governed by our binding corporate rules;
  • Derogations: In limited circumstances, transfers may be necessary for the performance of your contract, the establishment or defence of legal claims, or on the basis of your explicit consent.

You may request a copy of the specific transfer mechanism we rely on for any particular transfer by contacting our DPO at dpo@bitisie.com.

09Data Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Our retention periods are as follows:

Data Category Retention Period Basis
Account & identity records Duration of relationship + 7 years SEC Rule 17a-4 / AML regulations
Transaction & trading records Duration of relationship + 7 years SEC Rule 17a-4
Financial planning documents Duration of relationship + 5 years Investment Advisers Act
KYC / AML documentation 5 years after account closure Bank Secrecy Act / FINCEN
Communication records 3 years after last communication Legitimate interest / Legal obligation
Marketing consent records Until consent withdrawn + 3 years GDPR / CAN-SPAM compliance
Website usage / cookies 13 months from collection Cookie consent / legitimate interest
Security logs 12 months Legitimate interest (security)

After the applicable retention period, personal data is securely deleted or anonymised. Where anonymisation is not possible (e.g. backup tapes), we restrict the data until deletion is feasible. Retention periods may be extended if required by ongoing legal proceedings or regulatory investigations.

10Security of Your Information

We take the security of your personal and financial information extremely seriously. We implement a comprehensive information security programme that includes:

  • Encryption: All data in transit is encrypted using TLS 1.3. All data at rest is encrypted using AES-256. Database fields containing sensitive financial information (e.g. account numbers) are encrypted at the field level;
  • Access Controls: Role-based access controls (RBAC) ensure that only authorised personnel can access your data, and only to the extent necessary for their role. All access is logged and monitored;
  • Multi-Factor Authentication (MFA): MFA is required for all employee access to systems containing personal data and is strongly recommended for client accounts;
  • Third-Party Audits: We undergo annual independent penetration testing, SOC 2 Type II audits, and are ISO 27001 certified;
  • Incident Response: We maintain a formal incident response plan and will notify affected individuals and relevant regulators of any data breach within the timeframes required by applicable law (72 hours under GDPR);
  • Employee Training: All employees receive mandatory annual security and privacy training.

While we employ industry-leading security measures, no system can guarantee absolute security. If you believe your account has been compromised, contact us immediately at security@bitisie.com.

11Your Privacy Rights

Depending on your location, you may have the following rights with respect to your personal information. We will respond to all valid requests within 30 days (extendable by an additional 60 days for complex requests, with notice).

Right of Access

Request a copy of the personal data we hold about you and information about how we use it.

Right of Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right of Erasure

Request deletion of your personal data where there is no compelling reason for its continued processing.

Right to Restrict Processing

Request that we restrict how we use your data while a dispute about accuracy or lawfulness is resolved.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent

Withdraw consent at any time where we rely on consent as our legal basis. This does not affect processing carried out before withdrawal.

Right to Lodge a Complaint

Lodge a complaint with your local data protection authority if you are unhappy with how we handle your data.

To exercise any of these rights, please submit a request to support@bitisie.com or write to our Data Protection Officer at the address in Section 16. We will verify your identity before processing your request and may need additional information to do so. There is no charge for exercising your rights, except where requests are manifestly unfounded, excessive, or repetitive.

12Cookies & Tracking Technologies

We use cookies and similar technologies (collectively, "cookies") to enhance your experience, analyse platform usage, and support our security measures. Cookies are small text files stored on your device when you visit our website.

Types of Cookies We Use

CategoryPurposeDurationYour Control
Strictly Necessary Session management, authentication, security, and basic platform functionality. Cannot be disabled without breaking the service. Session / 1 year Always active
Functional Remember your preferences, dark mode setting, language, and previously viewed content. 1 year Optional
Analytics Aggregate, anonymised data on how visitors use our platform to help us improve features and performance. 13 months Optional
Marketing Track interactions with our content across the web to deliver relevant advertisements. We do not use third-party advertising networks for targeted advertising within your investment account. 90 days Optional

Manage Your Cookie Preferences

Strictly Necessary

Required for the platform to function

Functional Cookies

Personalisation and preferences

Analytics Cookies

Help us improve platform performance

Marketing Cookies

Relevant content and advertising

You can also control cookies through your browser settings. Note that disabling all cookies may affect the functionality of our platform. To learn more about cookies, visit allaboutcookies.org.

13Children's Privacy

Our Services are not directed to, and we do not knowingly collect personal information from, individuals under the age of 18. If you are under 18, please do not use our Services or provide any personal information to us.

If we become aware that we have collected personal information from a child under 18 without verifiable parental consent, we will take immediate steps to delete that information and close the associated account. If you believe we may have inadvertently collected information from or about a minor, please contact us immediately at support@bitisie.com.

For clients who wish to establish custodial or UGMA/UTMA accounts for minor beneficiaries, such accounts are opened by and under the legal responsibility of the adult account holder (custodian), and the minor's information is processed solely for the purpose of administering the custodial account.

14California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, our business purposes for collecting it, and the categories of third parties with whom we share it;
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions permitted by law;
  • Right to Correct: You have the right to request correction of inaccurate personal information we hold about you;
  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising;
  • Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to what is necessary to perform the services you have requested;
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights, including by denying services, charging different prices, or providing a different level of service.

To submit a CCPA request, you may: (i) email support@bitisie.com; or (ii) contact us via live chat at contact.html. We will verify your identity before processing your request. You may designate an authorised agent to make a request on your behalf, in which case we will require written proof of authorisation.

Categories of Personal Information Collected (Last 12 Months)

CCPA CategoryExamplesSold?Shared?
IdentifiersName, email, IP addressNoService providers only
Financial InformationBank account, investment dataNoCustodian / broker only
Internet ActivityBrowsing history on our siteNoAnalytics vendors only
Professional / EmploymentOccupation (suitability form)NoNever
GeolocationCountry / state of residenceNoCompliance only
Sensitive Personal InfoGovernment ID, tax numbersNoKYC providers / regulators only

15Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services we offer, applicable laws, or regulatory requirements. When we make material changes, we will:

  • Send an email notification to the email address registered with your account;
  • Post a prominent notice on our website and within your account dashboard;
  • Update the "Last Updated" date at the top of this Policy;
  • For significant changes affecting your rights, seek fresh consent where required by law.

We encourage you to review this Policy periodically. The current version of this Policy will always be available at www.bitisie.com/privacy. Your continued use of our Services after the effective date of any revision constitutes your acceptance of the updated Policy, to the extent permitted by applicable law.

We maintain an archive of prior versions of this Privacy Policy. To request a prior version, please contact our DPO.

16Contact Us & Supervisory Authorities

16.1 Privacy Requests & DPO Contact

For all privacy-related enquiries, requests to exercise your rights, or questions about this Policy, please contact our Data Protection Officer:

Data Protection Officer

Bitisie LLC

Attn: Privacy & Data Protection
1270 Avenue of the Americas, Suite 3600
New York, NY 10020

dpo@bitisie.com

General Privacy

For privacy requests, data subject access requests, or general enquiries about how we handle your data:

support@bitisie.com

16.2 Supervisory Authorities

If you are not satisfied with our response to a privacy complaint, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction:

  • United States: Federal Trade Commission (FTC) — ftc.gov
  • European Union: Your local EU Data Protection Authority (list available at edpb.europa.eu)
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • Singapore: Personal Data Protection Commission (PDPC) — pdpc.gov.sg
  • UAE / DIFC: DIFC Commissioner of Data Protection — difc.ae

We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, and ask that you contact us in the first instance.

Questions about your privacy?

Our Data Protection Officer is available to answer any questions you have about how we handle your personal information.

© 2026 Bitisie LLC. All rights reserved. This Privacy Policy was last updated on June 25, 2026. Bitisie LLC is registered with the SEC as an investment adviser. This Policy does not constitute legal advice. If you require legal advice about your privacy rights, please consult a qualified solicitor or attorney in your jurisdiction.

Submit a Privacy Request