KIMEL.Exchange

Legal

Privacy Policy

KIMEL.Exchange · Last updated: July 11, 2026

At Kimel Exchange, we respect and protect the privacy of our customers. This Privacy Policy (“Policy”) explains how we handle the information we receive when you access our services at https://kimelexchange.com. Please read this Policy carefully before using any of our services.

Amendment of the Policy

This Policy is presented in its most up-to-date version. Kimel Exchange may amend the Policy over time, including to comply with changes in applicable law. All changes come into force from the moment they are published on this page, unless a different period is indicated in the text of the amendments. We will make reasonable efforts to provide additional notice of material amendments, but we ask you to check this page regularly for the latest version.

1. What Information We Collect

Depending on the service you use, we may collect the following types of information: email address, exchange transaction data (including deposited and paid-out assets, amounts, wallet addresses, transaction hashes and timestamps), correspondence with our support team, and data collected via cookies and similar technologies.

We may collect general technical information about your device and usage ("Technical Usage Data"), including, where available: session ID, IP address, approximate location (country), device ID, operating system and version, browser type and version, and language settings. Such information is used for system administration, security, problem solving, and service improvement.

Where our risk management system requires identity verification (see the Terms of Use), our KYC provider collects identity documents and related verification data on our behalf, acting as an independent data controller.

Our website uses cookies to analyze visits and deliver a better product. You may refuse or limit cookies; in that case, we will use only cookies necessary for the operation of the website (technical and session cookies). You may delete cookies at any time in your browser settings.

2. Why We Collect Your Personal Information

We collect the minimum scope of personal data required to provide the services and support your privacy rights. We process your information to: execute and track exchange transactions; provide customer support; comply with our legal obligations, including anti-money-laundering and counter-terrorist-financing requirements; detect and prevent fraud and financial crime; keep the services running securely; and analyze and improve the services.

If you provide your email address, we may use it to contact you regarding your transactions and, with your consent, to send service updates. You may opt out of non-essential emails at any time. Your email address will not be provided to third parties for marketing purposes.

We do not use automated processing of personal data to make decisions that produce legal effects concerning you, other than automated transaction risk screening required for compliance purposes, the results of which are subject to human review. We do not sell, trade, rent, or loan users’ personal data to any third party for monetary reward.

3. Legal Grounds for Processing

We rely on the following grounds for data processing:

  • your explicit informed consent, expressed through consent forms and acceptance of this Policy;
  • performance of the exchange service you request;
  • compliance with our legal obligations;
  • our legitimate interests, including securing and improving the services and preventing fraud.

You may withdraw your consent or request erasure of information collected by us at any time; however, without certain data we may be required to terminate or significantly limit your access to the services, and some data must be retained by law (see Section 6).

4. Sharing Personal Information with Other Parties

We may share your information with:

  • KYC provider — where verification is required, identity documents you submit are stored and processed by our third-party KYC provider, acting as an independent data controller; its privacy policy applies to that processing.
  • Blockchain analytics providers — transaction data (wallet addresses, transaction hashes) is screened through third-party compliance tools to meet our AML obligations.
  • Service providers under contract that help operate parts of our business (hosting, analytics, customer support tooling). Our contracts prohibit them from selling your information.
  • Third-party exchange services — where your transaction is processed through a third-party processor or exchange aggregator (see Section 6 of the Terms of Use), data necessary to execute the transaction is shared with that party.
  • Law enforcement and regulatory agencies, where required by law (see our Law Enforcement Request Guidelines).

Third-party analytics companies may collect Technical Usage Data and cookies to help us analyze and improve the services. Third-party services we use implement technical and organizational measures for secure processing of personal data, as specified in their privacy policies.

5. Protection of Personal Information

We take the security of your data seriously. We will not permit third parties to contact you directly on an unsolicited basis in relation to their own products or services. We observe generally accepted standards to protect your information. In particular, we have taken at least the following measures:

  • Encryption of all network connections through which data is transmitted.
  • Vulnerability and security testing of our systems at least once every 12 months.
  • Access controls protecting confidential data, including strong authentication for administrative access.
  • Incident response processes tested at least once every 12 months.
  • Automated monitoring of logs and security events, with alerts for abnormal or security-related activity.

Our employees and contractors are bound by confidentiality obligations when accessing personal data. We cannot guarantee that these measures will prevent every unlawful attempt to circumvent privacy or security settings. If a data breach occurs, we undertake to notify affected users and the competent authority as quickly as possible and to make every effort to minimize negative consequences.

6. Data Retention

We retain your information only as long as necessary to fulfill the purposes outlined in this Policy, and as required to meet legal obligations (including anti-money-laundering record-keeping requirements applicable to us), resolve disputes, and enforce agreements.

If you request deletion of your personal data, we will fulfill the request within two (2) weeks by deleting personal data to the extent allowed by applicable laws and regulations. Please note that certain data — including transaction records subject to AML retention requirements — must be retained for legal, regulatory, or technical purposes notwithstanding a deletion request.

7. About Us

KIMEL View S.A., a company incorporated in the Republic of Panama. Registered address: Plaza 2000 Tower, 10th Floor, 50th Street, Panama City, Republic of Panama.

For any inquiries and requests regarding this Policy or your personal data, please contact us at compliance@kimelexchange.com.