This Privacy Policy shall be effective starting on January 15th 2019.
Your privacy is important to us. Frontnode (“Frontnode”, “we”, “us” and “our”) respects and protects the privacy of visitors to our websites and customers who use our services.
This Privacy Policy describes how we collect, use, disclose, retain and otherwise process personal information when you access content we own or operate on the Frontnode website, referred to as the “Site(s)”, or use our related services collectively referred to as the “Services”.
Where Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), applies to our processing, personal information is processed in accordance with the GDPR. Where Canadian privacy legislation applies, processing is also subject to applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and, where applicable, the British Columbia Personal Information Protection Act (“BC PIPA”).
Please read this Privacy Policy carefully. If you have any questions about this Privacy Policy or our processing of personal information, please contact us through our Contact page.
1.1. By accessing or using our Services, you acknowledge that you have been provided with and have had an opportunity to read this Privacy Policy.
1.2. Where Frontnode relies upon consent as its legal basis for processing personal information, consent will be requested separately and in a manner appropriate to the relevant processing activity. Consent is processed pursuant to Article 6(1)(a) and Article 7 GDPR where the GDPR applies.
1.3. We may provide additional or “just-in-time” privacy notices in connection with specific Services or processing activities. Such notices supplement this Privacy Policy and may provide additional information concerning the collection, use or disclosure of personal information.
1.4. Certain personal information is necessary for Frontnode to provide the Services, perform its contractual obligations or comply with applicable law. Where you do not provide information that is necessary for these purposes, we may be unable to provide some or all of the Services.
2.1. We may amend this Privacy Policy from time to time to reflect changes to our Services, processing activities, legal obligations or business operations.
2.2. The current version of this Privacy Policy will be made available on our Site.
2.3. Where a change materially affects the manner in which we process personal information, we will provide additional notice where required by applicable law.
2.4. Where processing requires consent under Article 6(1)(a) GDPR or other applicable privacy legislation, an amendment to this Privacy Policy will not by itself constitute consent to a new processing purpose.
3.1. The legal entity operating Frontnode is the controller of personal information processed for the purposes described in this Privacy Policy unless otherwise stated.
3.2. Frontnode may engage third-party service providers that process personal information on our behalf. Where such providers act as processors within the meaning of Article 4(8) GDPR, their processing is governed by appropriate contractual arrangements in accordance with Article 28 GDPR.
3.3. In certain circumstances, Frontnode may disclose information to third parties that process such information as independent controllers. This may include financial institutions, regulatory authorities, law enforcement authorities and, where you have separately consented, selected commercial partners.
4.1. Information we collect
We collect personal information where this is necessary to provide our Services, comply with legal and regulatory requirements, protect Frontnode and its customers, or for the other purposes described in this Privacy Policy.
Depending upon the Services you use, we may collect:
Personal Identification Information, including your full name, date of birth, nationality, signature, photographs, telephone number, residential address and email address;
Formal Identification Information, including tax identification numbers, passport information, driver’s licence information, national identity card information and other government-issued identification information;
Financial Information, including bank account information, payment information, transaction history, trading information and tax-related information where relevant;
Transaction Information, including the parties to a transaction, transaction amounts, currencies, timestamps, payment information, blockchain addresses and transaction identifiers where applicable;
Employment Information, including occupation, employer, job title and professional role where relevant;
Online Identifiers and Technical Information, including IP address, device information, operating system, browser information, browser or device identifiers and other technical information concerning your use of the Services; and
Usage Data, including account activity, communications with customer support, authentication information, survey responses, click-stream data and information collected through cookies and similar technologies.
Further information regarding cookies and similar technologies is provided in our Cookie Policy.
4.2. Sources of personal information
We generally collect personal information directly from you.
We may also obtain personal information from third parties where necessary to provide the Services, verify information supplied by you, prevent fraud or comply with legal and regulatory obligations. Such sources may include identity verification providers, financial institutions, payment providers, fraud-prevention providers, sanctions and politically exposed persons databases, blockchain analytics services, public records and other lawful data sources.
Where Article 14 GDPR applies because information has not been obtained directly from you, Frontnode will provide the information required by Article 14 GDPR within the applicable period unless an exemption under Article 14(5) applies.
4.3. Purposes and legal bases for processing
Our primary purpose in collecting personal information is to provide secure, efficient and reliable Services. We process personal information for the following purposes:
a) To maintain legal and regulatory compliance
Frontnode processes identification, financial, transaction and related information to comply with applicable anti-money laundering, counter-terrorist financing, sanctions, fraud-prevention, regulatory reporting and record-keeping requirements.
This may include identity verification, customer due diligence, sanctions and politically exposed persons screening, source of funds or source of wealth checks, ongoing monitoring and investigation or reporting of suspicious transactions.
Where the GDPR applies, the principal legal basis is Article 6(1)(c) GDPR, processing necessary for compliance with a legal obligation. Processing may also be based upon Article 6(1)(f) GDPR where necessary for legitimate interests relating to financial crime prevention and protection of the Services, to the extent such interests are not overridden by the rights and interests of the data subject.
For Frontnode operations subject to Canadian AML/CFT legislation, these obligations include requirements arising under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and regulations made under that Act.
Where we are legally required to collect or retain information, failure to provide the required information may prevent us from establishing or continuing a customer relationship or providing particular Services.
b) To enforce our Terms and other agreements
Frontnode processes account, transaction and usage information to administer and enforce its contractual rights, collect fees, investigate breaches of our Terms and prevent misuse of the Services.
Where the GDPR applies, processing necessary to perform or enforce our agreement with you is based upon Article 6(1)(b) GDPR. Processing relating to the prevention or investigation of misuse, fraud or unlawful activity may additionally be based upon our legitimate interests under Article 6(1)(f) GDPR.
c) To provide Frontnode’s Services
We process personal information necessary to establish and administer your account and execute Services requested by you, including the purchase, sale, storage, transfer or other handling of Digital Currency or other financial instruments.
The legal basis is Article 6(1)(b) GDPR, where applicable, as the processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
d) To provide Service communications
We use your contact information to provide administrative, security, account and transaction-related communications.
Such communications may include transaction confirmations, account notifications, security notices, changes affecting the Services and other information necessary for the operation of your account.
The legal basis is Article 6(1)(b) GDPR where the communication is necessary for performance of our agreement with you, and Article 6(1)(c) GDPR where the communication is required by law.
e) To provide customer service
We process personal information when you contact us to answer questions, resolve disputes, investigate problems, collect fees or otherwise provide support.
The legal basis is Article 6(1)(b) GDPR where the processing relates to our contractual relationship with you and Article 6(1)(f) GDPR where processing is necessary for our legitimate interest in providing effective customer support, managing complaints and resolving disputes.
f) To ensure quality control
We may process information relating to customer interactions and use of the Services for internal quality control, training and operational review.
The legal basis is Article 6(1)(f) GDPR, where applicable, based upon our legitimate interest in maintaining and improving the accuracy, reliability and quality of the Services.
g) To ensure platform, network and information security
We process personal information to secure accounts and systems, verify access, detect unauthorised activity, combat fraud, spam, malware and other security threats, and investigate actual or suspected security incidents.
The legal basis is Article 6(1)(f) GDPR, based upon our legitimate interest in maintaining the confidentiality, integrity and security of the Services. Frontnode also implements technical and organisational safeguards in accordance with Article 32 GDPR where applicable.
h) For research and development purposes
We may analyse how customers use and interact with the Services in order to maintain, develop and improve Frontnode’s products, systems, website and applications.
Where possible and appropriate, aggregated or anonymised information will be used.
Where personal information is processed, the legal basis is Article 6(1)(f) GDPR, based upon our legitimate interest in developing and improving the Services.
i) To enhance your website experience
We may process technical and usage information to provide website functionality, remember preferences, understand how the Site is used and improve the customer experience.
Where processing is strictly necessary to provide functionality requested by you, the legal basis may be Article 6(1)(b) GDPR. Where processing is undertaken for our legitimate operational interests, the legal basis is Article 6(1)(f) GDPR.
Where cookies or similar technologies require consent, processing is based upon Article 6(1)(a) GDPR together with applicable electronic communications legislation, including Article 5(3) of Directive 2002/58/EC as implemented under applicable national law.
j) To facilitate corporate acquisitions, mergers or other transactions
We may process and disclose information where reasonably necessary to evaluate, negotiate or complete a merger, acquisition, restructuring, financing, transfer of business or assets or similar corporate transaction.
The legal basis is ordinarily Article 6(1)(f) GDPR, based upon our legitimate interest in managing and developing our business. Where processing is required by law, Article 6(1)(c) GDPR may apply.
k) To engage in Frontnode marketing activities
Where permitted by applicable law and subject to your communication preferences, we may send information concerning Frontnode products, Services, events, developments or promotional offers.
Where consent is required, the legal basis is Article 6(1)(a) GDPR and Article 7 GDPR. Electronic marketing is additionally subject to applicable electronic marketing legislation, including Article 13 of Directive 2002/58/EC as implemented under applicable national law and, where applicable, section 6 of Canada’s Anti-Spam Legislation.
You may withdraw marketing consent or unsubscribe from marketing communications at any time.
l) To share limited information with selected partners for marketing
Frontnode may disclose limited personal information to selected commercial partners so that those partners may contact you with information, offers or marketing concerning products or services that may be relevant to your interests.
Information disclosed under this consent is limited to:
a) your full name;
b) your email address; and
c) your telephone number.
Frontnode will not disclose identification documents, financial information, transaction information, cryptocurrency balances, wallet addresses or trading information to commercial partners for this marketing purpose under this consent.
d) aggregated account info.
Frontnode will not disclose identification documents, financial information, cryptocurrency balances, wallet addresses or trading information to commercial partners for this marketing purpose under this consent.
The legal basis for Frontnode’s disclosure is your consent under Article 6(1)(a), read together with Article 7 GDPR.
Any electronic marketing subsequently undertaken by a partner must comply with applicable electronic marketing legislation, including Article 13 of Directive 2002/58/EC as implemented under applicable national law and, where applicable, section 6 of Canada’s Anti-Spam Legislation.
You may withdraw your consent at any time. Withdrawal will apply to future disclosure by Frontnode and will not affect the lawfulness of processing carried out before withdrawal, in accordance with Article 7(3) GDPR.
5.1. We may disclose personal information where reasonably necessary for a purpose described in this Privacy Policy, including to:
identity verification, KYC, AML, sanctions screening, fraud prevention and blockchain analytics providers;
banks, payment service providers, card processors and other financial institutions involved in providing the Services;
technology, hosting, security, communications and other service providers acting on our behalf;
accountants, auditors, lawyers and other professional advisers;
governmental authorities, regulators, financial intelligence units, courts and law enforcement agencies where required or permitted by applicable law;
prospective purchasers, investors, financiers or advisers in connection with a corporate transaction; and
selected commercial partners where you have separately consented to disclosure in accordance with section 4.3(l).
5.2. Where a third party processes personal information on our behalf as a processor, Frontnode will enter into the arrangements required by Article 28 GDPR where applicable.
5.3. Where Frontnode is required to disclose personal information pursuant to a legal obligation, the legal basis under the GDPR is Article 6(1)(c). Disclosure to competent public authorities may also be governed by specific AML/CFT, sanctions, criminal procedure, tax, regulatory or other applicable legislation.
6.1. Frontnode operates internationally and may use service providers located in different jurisdictions. Personal information may therefore be transferred to or processed in a country other than the country in which you reside.
6.2. Where Chapter V GDPR applies to a transfer of personal information outside the European Economic Area, Frontnode will ensure that the transfer is based upon a mechanism permitted under the GDPR.
6.3. This may include:
an adequacy decision under Article 45 GDPR;
appropriate safeguards, including standard contractual clauses, under Article 46 GDPR; or
a derogation permitted under Article 49 GDPR where applicable.
6.4. Where applicable, transfers are made on the basis of an adequacy decision under Article 45 GDPR or Standard Contractual Clauses adopted by the European Commission pursuant to Article 46 GDPR. Information regarding the safeguards applicable to a particular transfer may be requested from Frontnode.
7.1. Frontnode retains personal information only for as long as necessary for the purposes for which it was collected or as required by applicable law, consistently with the storage limitation principle in Article 5(1)(e) GDPR.
7.2. Retention periods depend upon the nature of the information, the purpose of processing and applicable contractual, legal, regulatory, tax, accounting and AML/CFT obligations.
7.3. Certain customer identification, transaction and compliance records are subject to mandatory retention requirements. For operations subject to Canadian AML/CFT requirements, relevant records may be required to be retained for at least five years pursuant to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations.
7.4. Personal information that is no longer required will be deleted, anonymised or otherwise securely disposed of unless further retention is permitted or required by applicable law.
8.1. Frontnode may use automated systems in connection with identity verification, sanctions and PEP screening, transaction monitoring, fraud detection and risk assessment.
8.2. Where Frontnode makes a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR, Frontnode will provide the additional information required by Articles 13(2)(f) or 14(2)(g) GDPR and apply the safeguards required by Article 22 GDPR.
9.1. Where GDPR applies, you have, subject to the conditions and limitations contained in the GDPR, the right to:
obtain confirmation as to whether Frontnode processes your personal information and obtain access to such information under Article 15 GDPR;
request rectification of inaccurate or incomplete information under Article 16 GDPR;
request erasure of personal information in the circumstances provided by Article 17 GDPR;
request restriction of processing under Article 18 GDPR;
receive personal information in a structured, commonly used and machine-readable format and transmit that information to another controller where Article 20 GDPR applies;
object to processing based upon Article 6(1)(e) or Article 6(1)(f) GDPR under Article 21 GDPR;
object at any time to processing for direct marketing purposes under Article 21(2) GDPR;
withdraw consent at any time where processing is based upon Article 6(1)(a) GDPR, in accordance with Article 7(3) GDPR; and
lodge a complaint with a competent supervisory authority under Article 77 GDPR.
9.2. These rights are not absolute. Frontnode may continue to process or retain information where permitted or required by applicable law, including AML/CFT, sanctions, tax, accounting, fraud prevention or legal-claims requirements.
9.3. Where applicable Canadian privacy legislation applies, you may also have rights of access, correction, withdrawal of consent and complaint under PIPEDA or BC PIPA.
9.4. To exercise your rights, please contact us through our Contact page. We may require reasonable information to verify your identity before responding to a request.
10.1. Frontnode implements appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
10.2. Where the GDPR applies, security measures are maintained having regard to the requirements of Article 32 GDPR and the nature, scope, context and purposes of processing and the risks to individuals.
10.3. No technical system can guarantee absolute security. Frontnode therefore reviews and develops its security measures as appropriate having regard to changes in technology, threats and the nature of the information processed.
11.1. Questions concerning this Privacy Policy, Frontnode’s processing of personal information or the exercise of privacy rights may be submitted through the Contact page on the Site.
11.2. The identity, registered details and contact information of the legal entity operating Frontnode are provided on the Site.
11.3. Where the GDPR applies, you have the right under Article 77 GDPR to lodge a complaint with the supervisory authority competent in relation to your complaint.
11.4. Where Canadian privacy legislation applies, complaints may also be submitted to the competent federal or provincial privacy authority, as applicable.