Privacy Policy

Effective: March 2026 | Fastcad Solutions Ltd. ("Fastcad")

Fastcad Solutions Ltd. ("we", "us", "our") is committed to protecting the privacy of our customers. This policy explains how we collect, use, disclose, and safeguard your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the EU General Data Protection Regulation (GDPR) and the UK General Data Protection Regulation (UK GDPR).

Scope & Applicability

This policy applies to all users of our platform. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the GDPR-specific provisions in this policy apply to you in addition to our baseline PIPEDA obligations. Where GDPR provides stronger protections, those protections prevail.

Information We Collect

When you use our virtual currency exchange service, we may collect the following information during onboarding and transactions:

  • Full name, date of birth, employment details, and residential address
  • Government-issued identity documents (photographed in real-time)
  • Selfie photograph for liveness verification
  • Proof of address documentation
  • Source of wealth and source of funds documentation
  • Device identifiers, browser type, and IP address
  • Transaction details and history
  • Contact information (email address, phone number)
  • Cryptocurrency wallet addresses (for buy transactions)
  • Bank account and payment details (for sell transaction payouts)

Lawful Basis for Processing (GDPR Art. 6)

For users in the EEA/UK, we process personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)) β€” Processing necessary to provide our exchange services, execute your buy/sell transactions, and manage your account
  • Legal obligation (Art. 6(1)(c)) β€” Processing required by Canadian AML/ATF regulations, FINTRAC reporting obligations, and applicable EU/UK anti-money laundering directives
  • Legitimate interest (Art. 6(1)(f)) β€” Fraud prevention, platform security, service improvement, and transaction monitoring. We balance these interests against your rights and do not use this basis where your interests override ours
  • Consent (Art. 6(1)(a)) β€” Marketing communications and optional analytics, where applicable. You may withdraw consent at any time without affecting the lawfulness of prior processing

How We Use Your Information

  • To verify your identity and comply with Canadian AML/ATF regulations and applicable EU/UK anti-money laundering directives
  • To process your sell transactions (fiat payouts) and buy transactions (cryptocurrency delivery to your wallet)
  • To monitor transactions for suspicious activity as required by FINTRAC and applicable law
  • To communicate with you about your account and transactions
  • To improve our services and user experience
  • To enforce our Terms of Service and protect the security of our platform

Identity Verification

We use Sumsub, a third-party identity verification provider, to conduct our Know Your Customer (KYC) procedures. When you complete identity verification, your information is processed by Sumsub for document authenticity checks, liveness verification, watchlist screening (PEPs, sanctions), and adverse media screening. Sumsub acts as a data processor on our behalf under a Data Processing Agreement.

Data Sharing

We do not sell your personal information. We may share your information with:

  • Sumsub β€” for identity verification and compliance screening (Data Processor)
  • Payment processors β€” to facilitate fiat payouts (sell) and cryptocurrency delivery (buy) (Data Processors)
  • Cloudflare β€” for content delivery, edge computing, and database hosting (Data Processor)
  • Firebase (Google) β€” for authentication services (Data Processor)
  • Regulatory authorities β€” when required by law (e.g., FINTRAC reporting for transactions over $10,000 CAD)
  • Law enforcement β€” when legally compelled

All third-party service providers acting as data processors are bound by Data Processing Agreements that require them to process data only on our instructions and to implement appropriate security measures.

International Data Transfers

Your personal data may be transferred to and processed in countries outside the EEA/UK, including Canada and the United States. We safeguard these transfers through:

  • Adequacy decisions β€” Canada has an EU adequacy decision for transfers under PIPEDA
  • Standard Contractual Clauses (SCCs) β€” For transfers to countries without an adequacy decision (e.g., United States), we rely on EU-approved Standard Contractual Clauses with our processors
  • Supplementary measures β€” Including encryption in transit and at rest, access controls, and contractual obligations on sub-processors

You may request a copy of the relevant transfer safeguards by contacting us at info@fastcad.org.

Data Retention

We retain personal data only as long as necessary for the purpose it was collected:

  • Customer identification and KYC records β€” 5 years after the business relationship ends (Canadian AML regulations)
  • Transaction records β€” 5 years from the date of the transaction (FINTRAC requirement)
  • Suspicious transaction reports β€” As required by FINTRAC
  • Account profile data β€” Retained while your account is active, deleted within 90 days of account closure (subject to legal retention obligations above)
  • Server logs and IP addresses β€” 90 days
  • Marketing consent records β€” Retained for the duration of consent plus 1 year

Where legal retention periods conflict, the longer legally mandated period applies.

Data Security

We protect your information through encryption (TLS in transit, AES-256 at rest), access controls, regular security assessments, and secure data storage. All staff are trained on data protection responsibilities. We implement technical and organisational measures appropriate to the risk, in accordance with GDPR Art. 32.

Cookies & Tracking Technologies

Our platform uses the following categories of cookies and similar technologies:

  • Strictly necessary β€” Authentication tokens and session management required for the platform to function. These do not require consent
  • Functional β€” Theme preferences and language selection to improve your experience

We do not use advertising or third-party tracking cookies. We do not engage in cross-site tracking or profiling for marketing purposes. Device identifiers and IP addresses collected for security and fraud prevention are processed under our legitimate interest basis.

Your Rights

Under PIPEDA, you have the right to access your personal information, request corrections, withdraw consent (subject to legal obligations), and file a complaint with the Office of the Privacy Commissioner of Canada.

If you are located in the EEA or UK, you have the following additional rights under GDPR:

  • Right of access (Art. 15) β€” Obtain a copy of your personal data and information about how it is processed
  • Right to rectification (Art. 16) β€” Correct inaccurate or incomplete personal data
  • Right to erasure (Art. 17) β€” Request deletion of your personal data where there is no compelling reason for continued processing. This right is limited where we are required to retain data for legal or regulatory compliance (e.g., AML record-keeping)
  • Right to restrict processing (Art. 18) β€” Request that we limit how we use your data while a concern is being resolved
  • Right to data portability (Art. 20) β€” Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV)
  • Right to object (Art. 21) β€” Object to processing based on legitimate interest. We will stop unless we demonstrate compelling legitimate grounds
  • Rights related to automated decision-making (Art. 22) β€” See "Automated Decision-Making" below
  • Right to withdraw consent β€” Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at info@fastcad.org. We will respond within 30 days (or within one calendar month for GDPR requests). We may need to verify your identity before fulfilling your request.

Automated Decision-Making

We use automated systems for transaction monitoring and fraud detection. These systems may flag transactions for manual review based on amount, frequency, or risk patterns. We do not make solely automated decisions that produce legal effects or significantly affect you without human involvement. Transaction blocks triggered by automated monitoring are reviewed by a member of our compliance team.

Children's Data

Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly.

Data Breach Response

In the event of a personal data breach:

  • We will notify the Office of the Privacy Commissioner of Canada as required by PIPEDA where the breach poses a real risk of significant harm
  • For EEA/UK users, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33
  • We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)

Supervisory Authority

If you are in the EEA or UK and are not satisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.

Contact

For privacy inquiries, data subject requests, or to exercise your rights, contact us at:

Fastcad Solutions Ltd.
757 West Hastings St, PMB 818
Vancouver, BC V6C 1A1
Canada
info@fastcad.org

This policy is reviewed annually. Effective: March 2026.