Last updated — April 12, 2025

Global Privacy
Policy

This document explains how YEAR TECH, operating the Yera Connect platform, collects, uses, stores, shares, and protects your personal data across all our services.

GDPR CompliantUK GDPRCCPA ReadyAML/KYC Framework

Who We Are

Yera Connect is owned and operated by YEAR TECH. We act as the data controller of your personal data when you use Yera Connect directly, and may act as a data processor, service provider, or independent controller when providing services to business customers.

Company

YEAR TECH

Website

yeraconnect.io

Registration

85587192

VAT

NL863675001B01

Address

Julianalaan 34, 3708 BD Zeist

Privacy

privacy@yeraconnect.io

Our Relationship With You

If you visit our Website, contact us, create an account, complete verification, use wallet or transaction services, or connect a payment method, we generally process your personal data as a controller.

If you access Yera Connect through a third-party platform, merchant, integrator, partner, or business customer, that third party may also process your personal data under their own privacy policy. We are not responsible for the privacy practices of third parties operating independently from us.

Personal Data We Collect

"Personal data" means information that identifies, relates to, describes, or can reasonably be linked to an individual. We collect personal data through the following methods:

  • Information you provide to us directly
  • Information we collect automatically through your use of the Services
  • Information generated through your transactions and activity
  • Information received from third-party providers and partners
  • Information derived from blockchain networks, compliance checks, and transaction monitoring

Information You Provide to Us

4.1 Identification Information

  • Full legal name, date of birth, nationality, gender
  • Residential address, phone number, email address
  • Profile information, photographs, video, selfie images, or liveness check data
  • Proof of address (utility bills, bank statements, official correspondence)

4.2 Formal Identity & Verification

  • Passport, national ID card, driver's licence, residence permit
  • Tax identification number, visa or immigration status
  • Biometric verification results (where legally permitted)
  • Sanctions, watchlist, PEP, and adverse media screening results

4.3 Business & Institutional Information

  • Company name, registration number, registered and trading address
  • Articles of association, ownership and control information
  • Director, officer, shareholder, and beneficial owner details
  • Licences, regulatory status, source of funds and source of wealth

4.4 Financial & Payment Information

  • Bank account details, payment card details or limited card metadata
  • Transaction history, wallet balances, trading or exchange activity
  • Chargeback, refund, reversal, or payment dispute information
  • Tax identification or tax residency information

4.5 Crypto, Wallet & Blockchain Information

  • Wallet addresses, wallet type, public blockchain transaction data
  • Transaction hashes, asset type, amounts, network and gas fees
  • Blockchain analytics results, wallet risk scores
  • Information about connected or bound external wallets

4.6 Transaction Information

  • Transaction date/time, amount, status, exchange rate, fees
  • Asset type, payment method, merchant or integrator information
  • Device and session information linked to the transaction
  • Risk and compliance results

4.7 Employment or Professional Information

  • Employer name, occupation, job title, office location
  • Business email, business phone number, professional profile
  • Information required to assess source of funds or authorised representative status

4.8 Communications & Support Information

  • Messages to customer support, emails, chat messages, call records
  • Survey responses, feedback, complaints, support tickets
  • Attachments you provide and records of our responses

We may monitor or record support communications where permitted by law for quality, security, training, and compliance purposes.

Information We Collect Automatically

When you visit the Website or use the Services, we may automatically collect technical and usage information, including:

  • IP address, device identifiers, browser type, operating system, device type
  • Approximate location, time zone, pages viewed, links clicked, session duration
  • Authentication data, login history, clickstream data, API usage data
  • Error logs, security logs, cookie identifiers, analytics data
  • Fraud prevention signals, network information, user agent information

Cookies and Similar Technologies

We may use cookies, pixels, tags, SDKs, local storage, and similar technologies to operate the Website and Services.

  • Operate the Website and remember your preferences
  • Authenticate users and maintain sessions
  • Detect fraud and abuse, improve security
  • Analyse Website and Service usage and improve performance
  • Support marketing and advertising, where permitted

Some cookies are necessary for the Website and Services to function. Others may be optional and subject to consent where required by law. See our Cookie Policy for more information.

Information We Receive From Third Parties

7.1 Identity Verification & Compliance Providers

Identity verification results, document checks, sanctions screening results, risk scores, fraud signals, corporate records, and compliance alerts from KYC vendors, fraud prevention providers, and public records.

7.2 Financial Institutions & Payment Providers

Payment status, transaction references, chargeback information, fraud alerts, and payment risk signals from banks, card networks, acquirers, and payment institutions.

7.3 Crypto, Custody & Blockchain Providers

Wallet risk scores, transaction monitoring results, blockchain metadata, custody references, and network status from crypto liquidity providers, analytics companies, and exchanges.

7.4 Business Partners, Integrators & Merchants

Your name, contact details, customer reference, transaction details, wallet details, and risk information from third-party platforms where you access Yera Connect.

7.5 Public Sources

Government registers, company registries, sanctions lists, court records, insolvency registers, media reports, and public blockchain networks.

7.6 Marketing & Analytics Partners

Where permitted, information from marketing partners, advertising networks, analytics providers, and referral partners to understand interest in our Services.

Anonymised and Aggregated Data

We may create, use, and share anonymised or aggregated data that does not identify you, including aggregated transaction trends, usage statistics, fraud indicators, performance metrics, product analytics, research insights, and compliance trend data. Where data has been properly anonymised, it may not be treated as personal data under applicable law.

How We Use Personal Data

9.1 To Provide and Operate the Services

  • Create and manage accounts, authenticate users, process onboarding
  • Provide wallet functionality, process crypto and fiat transactions
  • Provide APIs, dashboards, hosted pages, and integrations
  • Manage disputes, refunds, chargebacks, and reversals

9.2 To Verify Identity and Comply With Law

  • Verify identity and conduct KYC, KYB, AML, CTF, and sanctions checks
  • Monitor transactions, screen wallet addresses, detect suspicious activity
  • Report to regulators, law enforcement, and tax authorities where required
  • Maintain records and comply with court orders and legal obligations

9.3 To Protect Security and Prevent Fraud

  • Detect unauthorised access, prevent account takeover, monitor login activity
  • Detect suspicious transactions and investigate fraud
  • Protect users, partners, and Yera Connect from abuse and cyberattacks
  • Secure APIs, systems, and infrastructure

9.4 To Communicate With You

  • Send account notices, transaction confirmations, and security alerts
  • Respond to support requests and manage complaints
  • Notify you about changes to our Terms, Privacy Policy, or Services

You cannot opt out of essential service, legal, security, or transaction communications.

9.5 To Send Marketing Communications

Where permitted, newsletters, product updates, promotions, event invitations, and educational content. You may opt out at any time via the unsubscribe link or by contacting privacy@yeraconnect.io.

9.6 To Improve and Develop Our Services

  • Analyse usage, improve functionality, and troubleshoot technical issues
  • Conduct research, test new features, and improve user experience
  • Improve compliance and fraud systems, develop new products

9.7 To Manage Our Business

  • Perform accounting, billing, audits, and risk management
  • Manage legal claims, enforce contracts, maintain insurance
  • Support corporate governance and evaluate corporate transactions

How We Share Personal Data

We do not sell your personal data in the ordinary meaning of selling personal information for money.

11.1 Service Providers

Hosting, cloud infrastructure, IT, cybersecurity, identity verification, fraud prevention, sanctions screening, blockchain analytics, payment processing, customer support, analytics, marketing, accounting, legal, and compliance providers.

11.2 Financial Institutions & Payment Partners

Banks, payment processors, card networks, acquiring banks, payment institutions, e-money institutions, settlement providers, and fiat on/off-ramp providers for transaction processing, fraud management, and compliance.

11.3 Crypto, Custody & Blockchain Providers

Crypto liquidity providers, exchanges, custody providers, wallet providers, blockchain infrastructure, transaction monitoring, and blockchain analytics vendors.

11.4 Business Partners, Merchants & Integrators

Account status, onboarding status, verification results, transaction status, compliance-related restrictions, and wallet information with partners through whose platform you access Yera Connect.

11.5 Legal, Regulatory & Law Enforcement

Regulators, law enforcement, courts, tax authorities, government agencies, sanctions authorities, financial intelligence units, and supervisory authorities where required or permitted by law.

11.6–11.8 Advisers, Corporate Transactions & Consent

  • Lawyers, auditors, accountants, insurers, and consultants
  • Buyers, investors, lenders, or successors in connection with mergers, acquisitions, or restructuring
  • Third parties where you direct us to do so or give us consent

Third-Party Sites, Apps, and Services

The Website or Services may contain links to third-party websites, apps, wallets, exchanges, payment providers, merchants, or services. Third-party services collect and process your personal data independently under their own privacy policies. We are not responsible for third-party privacy practices. You should review the privacy policy of any third-party service before using it.

Blockchain Data

Important: You should not use the Services unless you understand that blockchain transactions may be public, permanent, and irreversible.

Crypto transactions may be recorded on public blockchain networks. Public blockchain data may include wallet addresses, transaction amounts, timestamps, transaction hashes, and other transaction metadata. Because blockchain networks are decentralised and public, we may not be able to delete, modify, or restrict access to information recorded on a blockchain.

Automated Decision-Making and Profiling

We may use automated systems to support security, fraud prevention, compliance, sanctions screening, transaction monitoring, wallet screening, risk scoring, and onboarding decisions. These systems may determine whether to approve, reject, delay, review, suspend, or restrict an account, transaction, or service request.

Where required by law, you may have the right to request human review of certain automated decisions, express your point of view, contest a decision, or obtain more information about the logic involved.

International Data Transfers

We may process and store personal data in countries other than where you are located. Where applicable law requires safeguards for international data transfers, we use appropriate measures including:

  • Adequacy decisions issued by relevant data protection authorities
  • Standard contractual clauses and data processing agreements
  • Transfer impact assessments
  • Technical and organisational safeguards and contractual protections
  • Other legally recognised transfer mechanisms

How We Protect Personal Data

We use technical, organisational, administrative, and physical safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction:

  • Access controls, authentication measures, and encryption where appropriate
  • Logging and monitoring, network security controls, secure development practices
  • Vendor due diligence, staff training, internal policies, and incident response
  • Data minimisation practices, confidentiality obligations, and restricted access

No system is completely secure. You are responsible for keeping your account credentials, devices, wallets, private keys, and authentication methods secure. Notify us immediately if you suspect unauthorised access.

Data Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention periods depend on:

  • The type of personal data and purpose of processing
  • Legal and regulatory requirements including AML, sanctions, and tax obligations
  • Dispute limitation periods and fraud prevention needs
  • Whether your account remains active
  • Whether retention is required by a provider, regulator, or court

We may retain KYC, KYB, AML, transaction, compliance, and payment records for longer periods where required or permitted by law. When personal data is no longer needed, we may delete it, anonymise it, aggregate it, or securely retain it where required by law.

Children's Privacy

Yera Connect is not intended for children. We do not knowingly collect personal data from anyone under the age of 18 or the legal age required to use the Services in their jurisdiction, whichever is higher. If you believe a child has provided personal data to us, contact us at privacy@yeraconnect.io. If confirmed, we will take appropriate steps to delete or restrict that data.

Your Privacy Rights

Depending on where you live and the applicable law, you may have the following rights:

Access personal data we hold about you
Correct inaccurate or incomplete data
Request deletion of personal data
Request restriction of processing
Object to certain processing
Withdraw consent at any time
Request data portability
Object to direct marketing
Request information about automated decisions
Request human review of automated decisions
Lodge a complaint with a data protection authority
Exercise other rights under applicable law

To exercise your rights, contact us at privacy@yeraconnect.io. We may need to verify your identity before responding. Some rights may be limited by legal, regulatory, AML, or fraud prevention requirements.

Marketing Choices

You may opt out of marketing emails by using the unsubscribe link in any email or contacting us at privacy@yeraconnect.io. Even if you opt out of marketing, we may still send important non-marketing communications including service notices, transaction confirmations, account alerts, compliance requests, security notices, and legal updates.

California and Other US State Privacy Rights

If you are in California or another US state with applicable privacy laws, you may have additional rights including:

  • Know what personal information we collect, use, disclose, or share
  • Access and correct personal information
  • Delete personal information
  • Opt out of certain sharing or targeted advertising
  • Limit use of sensitive personal information, where applicable
  • Receive information about categories of third parties to whom data is disclosed
  • Not be discriminated against for exercising privacy rights

We do not knowingly sell personal information. Some analytics or advertising activities may be considered "sharing" or "targeted advertising" under certain US state laws. Where applicable, we will provide required opt-out mechanisms. Contact us at privacy@yeraconnect.io.

EEA, UK, and Swiss Users

If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have rights under applicable data protection laws. Contact us at privacy@yeraconnect.io to exercise those rights. You may also have the right to lodge a complaint with your local data protection supervisory authority.

Data Breaches

If we become aware of a personal data breach, we will assess the incident and take appropriate steps in accordance with applicable law. Where required, we may notify affected individuals, regulators, providers, partners, or other relevant parties. We may not provide notice where not legally required, where the incident does not create relevant risk, or where notice would compromise security, legal obligations, or investigations.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top. Where required by law or where changes are material, we may provide additional notice via email, Website notice, account notice, or dashboard notification. Your continued use of Yera Connect after an updated Privacy Policy becomes effective constitutes your acknowledgement of the updated policy.

How to Contact Us

If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our handling of personal data, please contact us. Include enough information for us to identify you and understand your request.

General Enquiries

info@yeraconnect.io

🔒

Privacy Requests

privacy@yeraconnect.io

Legal Matters

legal@yeraconnect.io

📍

Registered Address

Julianalaan 34, 3708 BD Zeist