In this policy, we, us, our, and Fynzon P2P refer to Fynzon P2P. For more information about us and how to contact us, see Section 11. We respect your privacy and are committed to protecting it through our compliance with this Policy. This privacy policy (Policy) applies when we are acting as a data controller with respect to the personal data of our users. This Policy describes how we collect, use, and share personal data of consumer users across our platforms, including the Fynzon P2P website, Fynzon P2P's mobile and desktop application (the App), and services offered to users (collectively referred to as the Services), and from our partners and other third parties. When using any of our Services, you consent to the collection, transfer, storage, disclosure, and use of your personal data as described in this Policy. This Policy does not apply to anonymized data, as it cannot be used to identify you. Please read this Policy carefully to understand our policies and practices regarding your personal data and how we will treat it.
By accessing or using the Services, you agree to this Policy. Our Services also incorporate privacy controls which affect how we will process your personal data. Please refer to Section 5 for a list of rights regarding your personal data and how to exercise them. This Policy may change from time to time. Your continued use of the Services after we make changes is deemed acceptance of those changes, so please check the Policy periodically for updates.
There are three general categories of personal data we collect.
Information you give to usThe Account Data may be processed for the purposes of providing our Services, satisfying anti-money laundering and know-your-customer obligations, and ensuring the security of the Services, maintaining backups of our databases, and communicating with you. This information is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it, we may not be able to provide you with all the requested Services.
When you use the Services, we may automatically process information about your computer and internet connection (including your IP address, operating system, and browser type), your mobile carrier, device information (including device and application IDs), search terms, cookie information, as well as information about the timing, frequency, and pattern of your service use, and information about to the transactions you make on our Services, such as the name of the recipient, your name, the amount and type of cryptocurrency, and timestamp (Service Data).
The Service Data is processed for the purpose of providing our Services. The legal basis for this processing is the adequate performance of the contract between you and us, to enable us to comply with legal obligations, and our legitimate interest in being able to provide and improve the functionalities of the Services.
Information we collect from third partiesFrom time to time, we may obtain information about you from third-party sources as required or permitted by applicable law, such as public databases, credit bureaus, ID verification partners, resellers and channel partners, joint marketing partners, and social media platforms. ID verification partners use a combination of government records and publicly available information about you to verify your identity. Such information includes your name, address, job role, public employment profile, credit history, status on any sanctions lists maintained by public authorities, and other relevant data. We obtain such information to comply with our legal obligations, such as anti-money laundering laws. The legal basis for processing such data is compliance with legal obligations.
| Step | Action | Purpose/Description |
|---|---|---|
| 1. User Uploads Selfie | The user uploads a clear selfie image directly within the Fynzon App interface. | Initiates the identity verification process. |
| 2. Secure Storage (AWS S3) | The Fynzon backend securely stores the raw selfie image and generates a temporary, time-bound URL from our secure storage environment (Amazon Web Services S3). | Ensures the raw image is stored in a secure, compliant infrastructure. |
| 3. Face Extraction (Signzy API) | We pass the secure S3 URL to our third-party provider's (Signzy) Face Extraction API to calculate, isolate, and generate the unique facial geometry/region (the Face Data). | Converts the image into measurable, biometric data for comparison. |
| 4. Face Match (Signzy API) | The extracted Face Data is then compared with the photo captured from the user's provided government ID (e.g., Aadhaar) using Signzy’s Face Match API. | Determines the probability that the selfie and ID photo belong to the same person. |
| 5. Verification Result | Signzy returns a definitive match score to Fynzon. Based on internal thresholds, the user is subsequently marked as KYC Verified or KYC Failed in our system. | Completes the regulatory requirement and grants/denies access based on verification status. |
In this Section 4, we provide information about the circumstances in which your personal data may be transferred to countries outside the European Economic Area (EEA). We and our other group companies have offices in India, USA, and Singapore. To facilitate our operations, we may transfer, store, and process your information within those countries or with service providers based in Europe, India, Asia Pacific, and North America. Laws in these countries may differ from the laws applicable to your Country of Residence. For example, information collected within the EEA may be transferred, stored, and processed outside of the EEA for the purposes described in this Privacy Policy.
Where we transfer, store, and process your personal information outside of the EEA, we have ensured that appropriate safeguards are in place to ensure an adequate level of data protection. Transfers to our affiliated entities, to our service providers, and other third parties will be protected by appropriate safeguards, namely the use of standard data protection clauses adopted or approved by the European Commission or applicable certification schemes.
In this Section 5, we have summarised the rights that you have under data protection law based on whether you are a resident of the European Economic Area (EEA Resident) or you are not a resident of the EEA (Non-EEA Resident). Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.