1.1. This PRIVACY POLICY (“Policy”) applies to all personal data of Users that the Yifi.io Service and any related applications (including, without limitation, mobile applications) (the “Service”) may receive from Users during their use of the Service.
The Service is owned by Exchangeify Corp., registration number 155777159, registered at 55 Building, 21st Floor, Office 3, Panama City, Republic of Panama.
1.2. Use of the Service constitutes the User’s unconditional consent to this Policy and to the terms of data collection and processing set forth herein; if the User does not agree with these terms, they should refrain from using the Service. By using the Service, you accept the terms of this Policy and our Terms of Use, and you consent to the collection, use, disclosure, and storage of your information as described in this Policy. If you have not already done so, please also review the Terms of Use. The Terms of Use contain provisions that limit our liability to you and require the resolution of any disputes with us on an individual basis, rather than as a class or representative action. IF YOU DO NOT AGREE WITH ANY PART OF THIS PRIVACY POLICY OR OUR TERMS OF USE, PLEASE DO NOT USE THE SERVICE.
2.1. Personal Data – any information directly or indirectly relating to a specific or identifiable individual (data subject), including standard data automatically received by the HTTP server when accessing the Service and subsequent User actions (host IP address, User operating system type, website pages visited by the User, etc.).
2.2. Terms of Use – an agreement between the User and the Operator containing all necessary and material terms for using the Service, providing access to the Service, and the User’s use of the Service, whereby this Policy is an integral part of the Terms of Use.
2.3. User (data subject, User) – an individual who visits, downloads, or otherwise uses the Service, regardless of whether they actually use the Service’s features.
2.4. Operator – Exchangeify Corp., registration number 155777159, registered at 55 Building, 21st Floor, Office 3, Panama City, Republic of Panama, which manages the Service and owns the Service.
2.5. Services means the YiFi Earn service and the YiFi Swap service as described in their respective Service Terms.
2.6. Cookies – small text files, usually consisting of letters and numbers, that are stored on your computer or mobile device when visiting websites. When you revisit these websites, cookies allow the Service to recognize the User’s device. Cookies cannot read data from your hard drive and do not have access to cookies set by other websites. Cookies are not used for tracking Users or for marketing purposes.
2.7. Destruction of Personal Data – actions resulting in the impossibility of determining the ownership of personal data by a specific User without excessive financial and organizational costs.
2.8. Processing of Personal Data – any action (operation) or set of actions (operations) performed with personal data using automated means or without them, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data and other actions for the purpose of complying with the Terms of Use and providing access to the Service.
3.1. This Policy regulates the processing of personal data in the interaction between the Operator and the User in connection with the use of the Service.
3.2. The Service adheres to the principle of “Data protection by Design” and minimizes the collection and processing of User data.
3.3. This Policy is developed in accordance with the requirements of:
3.3.1. Applicable legislation, including the laws of the jurisdictions where the Operator’s companies are registered;
3.3.2. Agreements concluded by the Operator;
3.3.3. Other regulatory documents, taking into account modern requirements in the field of personal data protection.
3.4. This Policy is published on the Service’s website.
4.1. The Operator may process the following User data when the User utilizes the “YiFi Earn” and “YiFi Swap” Services:
4.2. The Service does not process personal data that directly identifies the User, including:
4.3. Registration, account creation, or identity verification is not required to access the core functionality of the Services. To operate, the Services process certain data strictly necessary to construct, route, and execute the on-chain transactions that the User independently signs (for example, public wallet addresses). Such data does not directly identify a User by name. However, because a public wallet address and the associated on-chain activity may, in combination with other information available to us (such as IP address or on-chain analytics), render the User identifiable, this data constitutes personal data. We process it in accordance with this Policy and with applicable data-protection law, including Law 81 of March 26, 2019 of the Republic of Panama.
4.4. The Service is non-custodial and does not store private keys, seed phrases, or confidential User credentials. All digital assets remain fully under the control of Users through their own wallet software.
4.5. Our Services are not intended to be accessed or used by children, minors or persons who are not of legal age. If you are a parent or guardian and you have reason to believe your child or ward has provided us with their personal data without your consent, please contact us.
5.1. Personal data of Users obtained during the use of the Service may be processed solely for the purposes of the Service’s operation, namely:
5.2. The processing of personal data is limited to achieving specific, pre-determined, and lawful purposes. Processing of personal data incompatible with the purposes for which it was collected is not permitted.
5.3. The Operator may assign the processing of User personal data to third parties only with the User’s consent, in accordance with applicable law and/or within the framework of an agreement with the User.
5.4. When personal data processing is assigned to a third party, the Operator must define the list of actions (operations) with personal data that the third party will perform, as well as the purposes of processing, and obligate the third party to maintain the confidentiality of personal data and ensure its security during processing; requirements for the protection of processed personal data must also be established.
5.5. When User personal data is transferred, access is granted only to specially authorized persons, and such persons are entitled to access only those personal data necessary for the performance of their official duties.
6.1. The Operator collects and processes your personal data based on and in connection with the performance of the Terms of Use.
6.2. In the course of processing personal data, the Operator performs the following actions: collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of information and other actions for the purpose of complying with the Terms of Use and providing access to the Service.
6.3. Personal data is stored on electronic media.
7.1. The User has the right to:
7.2. The User must bear in mind that the deletion of personal data or withdrawal of consent to data processing may result in the partial or complete inability to use the functionalities of the Service.
8.1. In processing personal data, the Operator takes necessary legal, organizational, and technical measures and ensures their implementation to protect personal data from unauthorized or accidental access, destruction, alteration, blocking, copying, provision, dissemination of personal data, as well as from other unlawful actions concerning personal data.
8.2. The Service undertakes to protect User information with the same care as it protects its own data and network.
8.3. The Service employs various security measures to help keep User information safe. However, the Service cannot guarantee that these measures will prevent all attempts to circumvent privacy or security settings on its website and application, whether due to unforeseen circumstances or unlawful actions. Accordingly, the Service provides no express or implied warranties that such access can be completely prevented.
9.1. The Operator undertakes to keep any confidential information obtained in its possession strictly confidential and takes all necessary measures to ensure the confidentiality of such information and to prevent its unlawful disclosure or unauthorized use.
10.1. The Operator uses cookies when the User visits the Service. This section explains what these technologies are, why the Service uses them, and the rights of Users regarding control over their use.
10.2. Cookies are small text files, usually consisting of letters and numbers, that are stored on your computer or mobile device when visiting websites. When you revisit these websites, cookies allow the Service to recognize the User’s device. Cookies cannot read data from your hard drive and do not have access to cookies set by other websites.
10.3. The Service uses cookies solely to ensure the proper functioning of the Service, including:
Cookies are not used for tracking Users or for marketing purposes.
10.4. Cookie Management. The User may configure their browser to block or delete cookies; however, this may limit the functionality of the Service, including preventing proper wallet connection and interface display.
11.1. The destruction of the User’s personal data is carried out in the following cases:
11.1.1. Upon achieving the purposes of their processing or if the need to achieve such purposes is lost, within a period not exceeding thirty (30) days from the date the purpose of personal data processing is achieved, unless otherwise provided by an agreement to which the User is a party, or by another agreement between the Operator and the User;
11.1.2. In the case of unlawful processing of personal data, or upon lawful withdrawal of personal data, within a period not exceeding ten (10) business days from the date such fact is identified;
11.1.3. Upon the expiration of the personal data retention period established in accordance with applicable law and the Operator’s organizational and administrative documents, including the withdrawal of the User’s consent to personal data processing;
11.1.4. Upon receipt of an order from an authorized body for the protection of data subjects’ rights or a court decision;
11.1.5. The parties acknowledge and agree that the Operator may, at its discretion, destroy copies of personal data, including in the event of unauthorized access to personal data by third parties.
12.1. The Service operates as a non-custodial interface and aggregator and does not take custody or control of Users’ funds. The Service does not transfer identity documents or KYC identifiers to third parties, because it does not collect them. However, in order to operate, the Service does transfer personal data — namely public wallet addresses, IP addresses, and other technical connection data — to the recipients described below. As stated in clause 4.3, such data does not identify a User by name but nonetheless may constitute personal data.
12.2. When a User performs operations through the Service, the public address of their wallet is automatically transmitted to:
12.3. Each such recipient acts as an independent data controller, operator. Each processes data under its own privacy policy and terms, over which we have no control and for which we accept no responsibility. Certain of these transfers are an inherent technical requirement of blockchain infrastructure and are necessary to execute the transaction the User has requested.
12.4. Off-chain exchange providers may, at their sole discretion, require identity verification (KYC/AML) directly from the User as a condition of completing a transaction. Any such identity or verification data is collected and processed by that provider as an independent controller, and not by us; we do not request, receive, store, or process it. We recommend that Users review the privacy policy and terms of any third-party provider before transacting.
12.5. Yifi.io provides a partner-level API and related tools that allow third parties to integrate the Services into their own products, as governed by the Partner Agreement. Where the Service is accessed through a partner integration, data about the partner’s end Users flows to us to render the aggregation and yield-tracking functionality. In that scenario:
13.1. The User consents to the cross-border transfer of personal data to the territory of other countries for the processing of personal data at the location of the copyright holder for the purposes specified in Section 5 of this Policy.
13.2. The Operator may carry out cross-border transfers of personal data to countries that both do and do not ensure reliable protection of the rights of data subjects, for the purposes specified in Section 5 of this Policy.
13.3. Before initiating a cross-border transfer of personal data, the Operator must ensure that the foreign country to which the personal data is to be transferred provides reliable protection of the rights of data subjects.
13.4. Cross-border transfer of personal data to territories of foreign countries that do not meet the above requirements may be carried out only with the User’s written consent to the cross-border transfer of their personal data and/or under an agreement to which the User and the Operator are parties.
13.5. The Operator undertakes to take reasonable efforts to ensure that third parties receiving access to personal data through cross-border transfers implement the necessary technical and administrative measures to protect the transferred personal data.
14.1. Users have the right to send their requests to the Operator by email: [email protected] regarding the use of personal data.
14.2. The Operator undertakes to review and respond to the User’s request within thirty (30) days from the date of receipt.
14.3. All correspondence received by the Operator from Users (written or electronic communications) is confidential information and shall not be disclosed without the User’s written consent. Personal data and other information about the User submitting the request may not be used without the User’s explicit consent for any purposes other than responding to the request, except in cases explicitly provided for by law.
15.1. The Operator may place links to third-party websites on the Service, which may redirect Users to such third-party resources. The Operator is not responsible for the collection, processing, or deletion of User personal data by such third parties, or for the content of these websites. For more information, please refer to the privacy policies of the respective third parties, available via these links.
16.1. We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, in accordance with the principles of purpose limitation and proportionality (data minimization).
16.2. Because the core functionality of the Service is non-custodial and account-free, the volume of data we retain is limited. In particular:
16.3. We will delete personal data when its storage no longer has a legal basis, when it has not been (or is no longer) authorized, or when the retention period has expired.
16.4. We keep personal data accurate and up to date to the extent it remains under our control. Users may request rectification, updating, deletion (cancellation), or blocking of their personal data as described in the “User Rights” section.
17.1. The period of processing of personal data processed by the Operator shall be equal to the period of fulfillment of the Operator’s obligations or until the withdrawal of consent by the User or the termination of the Operator’s activities.
17.2. Withdrawal of consent is carried out by the User or their representative by sending a written statement to the Operator, drafted in free form, in such a way that it allows reliable identification of the person who signed and submitted the statement, as well as the basis of the representative’s authority. The statement must be sent to the following email address: [email protected].