CrediumCanada
How it worksPricingComplianceSupport
How it worksPricingComplianceSupport
  1. Credium Canada
  2. Privacy Notice — Canada

Privacy Notice — Canada

Version 1.0 · 25 September 2026 · CREDIUM DIGITAL LTD.

On this page
  1. 1. Who is responsible
  2. 2. Information we collect and why
  3. 3. Consent and choices
  4. 4. Who may receive information
  5. 5. Processing locations
  6. 6. How long we keep information
  7. 7. Security and incidents
  8. 8. Your rights and complaints
  9. 9. Website technologies
  10. 10. Changes to this notice

1. Who is responsible

CREDIUM DIGITAL LTD. is responsible for personal information handled for this Canadian service. Contact CREDIUM DIGITAL LTD. — Privacy at support@credium.com, using “Privacy” in the subject line, or write to 170–422 Richards Street, Vancouver, BC V6B 2Z4, Canada.

We apply Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA) and other applicable privacy requirements according to their scope. This notice covers visitors, applicants, customers and individuals connected with business customers, including representatives, directors and beneficial owners.

2. Information we collect and why

InformationPurposes
Name, contact details, residential or business address, date of birth and identification documents or verification recordsVerify identity and eligibility; communicate; meet legal recordkeeping requirements.
Company registrations, business activity, ownership, directors and representativesVerify the business, beneficial ownership, authority and the intended relationship.
Bank/payment account details, wallet addresses and proof of control or ownershipEstablish me-to-me ownership; reconcile deposits; execute, deliver and return assets.
Orders, balances at external sources where relevant evidence is requested, transaction history, sources of funds/assets and associated documentsAssess lawful source and activity; price and reconstruct conversions; prevent fraud; comply with financial crime obligations.
Sanctions, politically exposed person and relevant adverse-information screening resultsAssess eligibility and risk; conduct monitoring and mandatory compliance checks.
Document images, selfies, liveness and biometric verification data where usedAuthenticate identity and prevent impersonation; subject to a specific notice and consent where required.
IP address, device and security signals, access logs and location information where necessary and lawfully collectedProtect access, detect fraud and apply relevant geographic restrictions. Precise device location is explained and requested where used.
Communications, support and complaint recordsResolve enquiries and disputes; maintain service and compliance records.

We collect information from you, your authorised representatives, identity and screening providers, relevant public sources, banks or other institutions involved in the service, and blockchain records. We do not request seed phrases, private keys or unrelated payment credentials.

3. Consent and choices

We explain required information and relevant disclosures when you apply or use the service. Identity, ownership, transaction and compliance information is necessary for the service; if it cannot lawfully be obtained or used, we may be unable to onboard you or execute an order.

We obtain meaningful consent where required, including express consent for sensitive processing where applicable. Uses that are not necessary for the service, such as optional marketing or an unrelated service referral, require the applicable separate choice. You may withdraw consent by contacting us, subject to legal and contractual restrictions. Withdrawal can prevent continued service but does not erase records we must retain or prohibit disclosures authorised or required by law.

Acceptance of our terms is not permission for an unspecified recipient to use your data for an unrelated purpose.

4. Who may receive information

  • Identity and compliance providers, including Sumsub: information needed to verify identity or business details, perform screening, prevent fraud and support lawful verification-data exchange. A transfer through Sumsub remains subject to the permitted purpose, necessary data and the recipient's lawful entitlement.
  • Banks, payment institutions, EMIs and crypto institutions involved in an order: identity, account and transaction information necessary for funding, settlement, returns, fraud prevention and their applicable legal duties, including required transfer information.
  • Liquidity providers: relevant information only where necessary for a particular lawful compliance or transaction purpose. Acting as a treasury supplier does not automatically entitle an LP to all customer identity files or transaction history.
  • Hosting, security, communications and support providers: information necessary to operate and protect the service or handle your enquiry, with access limited to their role.
  • Professional advisers, auditors and competent authorities: information needed for professional advice, required oversight, legal proceedings or a valid legal obligation or request.

Some recipients process information on our behalf under contractual instructions. Regulated institutions may also use information as independent organisations to meet their own legal responsibilities; their privacy notices apply to that processing. We identify the relevant provider and explain any materially different data use when required before it occurs.

Information is not made available to the Bulgarian Credium entity merely because the companies share a brand. The companies maintain separate customer and AML records and access controls. There is no automatic shared onboarding or group-wide customer database under this notice.

Required personal transfer information is exchanged through approved secure channels; we do not put identity documents or Travel Rule identity details on a public blockchain. Blockchain addresses, amounts and transaction hashes can nevertheless be public and may be linked to a person by others.

5. Processing locations

Our primary infrastructure is hosted in Canada. Authorised personnel may access information from Canada, Italy and the United Arab Emirates for their assigned functions. Service providers may process information in other countries according to their service arrangements. Primary hosting in Canada does not mean that all processing takes place exclusively in Canada.

We assess overseas handling, restrict access, use contractual safeguards and provide further information about relevant provider processing on request. Information handled abroad may be subject to lawful access by authorities in that jurisdiction. A cross-border transfer does not remove Credium's responsibility for information under its control.

6. How long we keep information

We apply the retention schedule in our AML and records policies, with a period appropriate to each category and purpose:

CategoryRetention approach
Exchange, transfer and receipt records; identity-method and transaction-specific recordsGenerally at least five years from creation, subject to the applicable record-specific rule.
Prescribed customer/entity, beneficial-ownership and relevant PEP/HIO records; core due-diligence and acceptance historyAt least five years after the last business transaction, under the applicable statutory or company rule.
Regulatory reports and submission evidenceAt least five years from submission under the applicable statutory or company rule; underlying records retain their own applicable periods.
Investigation and refusal case filesAt least five years from case closure, subject to any later applicable expiry.
Abandoned onboarding without a transaction or reportNormally no more than twelve months after abandonment, only where justified by a lawful purpose; relevant evidence may be retained in a restricted investigation file.
Ordinary security logsNormally twelve months; evidential logs follow the related record and incidents or legal requirements may require longer.
Privacy breach records within PIPEDA's scopeAt least twenty-four months from determining that a breach occurred.

Where information is used to make a decision directly affecting an individual, we also apply any applicable minimum retention period, including BC PIPA's one-year requirement. A record subject to several rules is kept until all applicable periods have expired.

Raw biometric material, liveness recordings, document images and precise location data require a separate necessity and retention assessment. They are not automatically retained for the entire AML customer-file period merely because they were collected during verification. We explain the relevant biometric processing and retention when that method is used.

A documented legal hold may extend retention for a complaint, investigation, litigation or other lawful preservation requirement. At expiry, information is securely deleted or irreversibly anonymised, including applicable provider copies and scheduled backup expiry. We do not apply a blanket ten-year period or indefinite retention to all personal information.

7. Security and incidents

We use access restrictions, authentication, encryption, logging and organisational controls appropriate to the sensitivity of the information. Provider access is limited to authorised purposes. No system eliminates every risk: unauthorised access can expose identity and financial information and lead to fraud or other harm.

We investigate security incidents, take containment and remedial measures and make regulatory reports and individual notifications where required by the applicable law.

8. Your rights and complaints

Subject to applicable law and its exceptions, you can ask what personal information we hold, how it has been used or disclosed, request access and correction, withdraw consent and challenge our handling of information. We verify your identity proportionately before responding. We respond within the applicable legal period and explain any permitted extension, restriction or refusal where required.

Deletion is subject to mandatory retention, legal holds and other lawful grounds; it is not an unconditional right to remove transaction or AML evidence. Access may be restricted to protect other individuals, confidential reporting or a lawful investigation.

Write to support@credium.com with the subject “Privacy”. If your concern is unresolved, you may contact the competent privacy authority, including the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia, according to their jurisdiction.

9. Website technologies

The website uses technical storage for functions such as language preferences and, where applicable, authentication and security. Your browser lets you manage or clear stored information; disabling necessary storage can affect functionality.

The page's font resources are delivered through Google Fonts, which receives technical connection information such as your IP address when your browser requests those resources. In-app chat and verification services have their own technical components and relevant notices when used. Optional analytics or marketing technologies require the applicable information and choice before activation.

10. Changes to this notice

We publish the current version and its effective date on this page. Material new purposes or disclosures are explained before they apply, and renewed consent is obtained where required. The version applicable to a prior consent or order remains recorded.

CREDIUM DIGITAL LTD.

170–422 Richards Street, Vancouver, BC V6B 2Z4, Canada

BC incorporation BC1582240 · FINTRAC MSB N300001308

support@credium.com

Service
  • Overview
  • How it works
  • Pricing and execution
  • Support and complaints
Legal
  • Terms of service
  • Privacy Notice
  • Key risks
  • Prohibited activities
Compliance
  • Regulatory information
  • AML / CTF Statement
  • FINTRAC registry

FINTRAC registration is not an endorsement or licence of the business. Crypto-assets are not bank deposits and are not covered by Canadian deposit insurance. Services are subject to eligibility and applicable law.

© CREDIUM DIGITAL LTD. All rights reserved.