1. Who we are
The controller of personal data processed under this Policy is BSV TRADING SOLUTION - FZCO, a company incorporated under the laws of the United Arab Emirates.
Trade Licence / Registration No. 53633 · License No. 56024
Registered address: DSO-IFZA, Dubai Silicon Oasis, IFZA, United Arab Emirates.
Premises: Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates.
Privacy requests: [email protected]
Security incidents: [email protected]
BSV Business is distinct from the BSV Market consumer marketplace at bsvmarket.com.
2. Scope
This Policy applies when you visit the Website, submit an access request or KYC/KYB materials, create or use a customer-portal, sandbox, or API account, correspond with us, or fund a prepaid balance.
It does not govern the BSV Market consumer marketplace, Merchant processing of End User data, or processing performed by your organisation as an independent controller.
Under the Client Agreement, BSV and the client are independent controllers of the personal data each processes. You must not send unnecessary End User personal data to BSV.
3. Personal data we collect
Depending on how you interact with us, we may process:
- Website and device data: IP address, approximate location, browser and device type, referring URL, pages viewed, timestamps, cookies, analytics identifiers, and theme preference.
- Enquiry and access-request data: name, business email, company legal name, country of incorporation, storefront or app URLs, business activity, use case, and expected monthly order volume.
- KYC/KYB and compliance data: company documents, directors, authorised signatories and beneficial owners, identification data, ownership, source-of-funds information, screening results, and allowlisted IP addresses.
- Account, portal, and API data: login identifiers, hashed credentials, roles, API keys, key-rotation events, allowlisted IPs, order and catalogue logs, audit trails, and support correspondence.
- Payment and funding data: prepaid-balance amounts, top-up references, bank-transfer references, and cryptocurrency transaction hashes, sending addresses, asset types, and networks.
- Communications data: emails, meeting notes, and materials exchanged for evaluation, onboarding, or support.
We do not seek special-category data. Identification documents collected for KYC/KYB are processed only for compliance and onboarding.
We ask clients not to send End User names, emails, or other consumer personal data unless a specific service requires it and a separate arrangement is in place.
4. How we collect it
- Directly from you or your organisation through forms, email, calls, onboarding packs, the portal, or the API.
- Automatically from your browser or API client through logs, cookies, and analytics.
- From the BSV Business access-request form at forms.bsvmarket.com/signup.
- From public registers, sanctions and watchlist databases, and screening providers.
- From payment institutions, banks, or blockchain networks when you fund an account.
- From affiliated companies in the BuySellVouchers group that provide hosting, security, or support.
5. Purposes and legal bases
We process personal data only where a legal basis applies under the UAE PDPL and, where applicable, the EU/UK GDPR.
- Operate and secure the Website: hosting, logs, fraud prevention, and theme preference — legitimate interests or contract.
- Respond to enquiries and access requests — pre-contract steps or legitimate interests.
- Perform KYC/KYB, AML/CFT, and sanctions screening — legal obligation, contract, or legitimate interests.
- Provide portal, sandbox, and API access — contract.
- Manage prepaid balances, invoicing, and tax records — contract or legal obligation.
- Provide support, improve the Website, protect BSV and clients, and establish or defend legal claims — legitimate interests and/or legal obligation.
Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
6. KYC, AML, and sanctions screening
Before granting API or production access, we require KYC/KYB checks. We may screen companies and related individuals against sanctions, embargo, watchlist, and PEP lists published by competent authorities.
We may refuse, suspend, or terminate access where documentation or risk assessment is incomplete or unsatisfactory. Screening tools may assist our review, but access decisions are not taken solely by automated means without human involvement.
7. Who we share data with
We do not sell personal data. We may share it with affiliated companies, infrastructure and security providers, analytics and font providers, form and communications tools, banks and payment institutions, crypto-network counterparties, screening providers, professional advisers, Merchants or authorities where required, and a buyer or successor in a business transfer.
Gift-card codes and inventory are commercial data. We do not use End User personal data to fulfil standard API orders.
8. International transfers
Personal data may be processed in the UAE and other countries where affiliates, cloud providers, or screening partners operate, including the United States and the European Economic Area. Where required, we use recognised transfer mechanisms, appropriate contractual clauses, consent, or another lawful exception.
9. Cookies and similar technologies
The Website uses bsv-business-theme in local storage to remember the light/dark theme, Google Analytics 4 (measurement ID G-1MQ2P1RRWC) for traffic analytics, and Google Fonts to load the Manrope typeface.
The Website currently does not display a cookie-consent banner. If you access it from the EU/UK, you may control analytics cookies through browser settings or Google's opt-out tools. We may add a consent mechanism later.
10. Retention
We keep personal data only as long as needed, including legal, AML, tax, and dispute-hold requirements. Typical periods include up to 14 months for analytics, 24 months for unsuccessful access requests, at least five years for KYC/KYB and account records, and typically five to seven years for payment and tax records.
11. Security
We implement measures appropriate to the risk, including access controls, encryption in transit, credential management, IP allowlisting, audit logging, and encrypted storage of protected inventory. No method of transmission or storage is completely secure.
Report suspected unauthorised access or compromise to [email protected]. We will notify authorities or affected individuals where required by law.
12. Your rights
Subject to the PDPL and GDPR where applicable, you may request access, correction, deletion, restriction, portability, object to legitimate-interest processing, withdraw consent, and avoid a decision based solely on automated processing where the law provides that right.
To exercise rights, email [email protected] with the subject “Privacy request — BSV Business”. We may verify your identity and authority to act for a company.
13. Complaints
Please contact us first. You may also complain to the UAE Data Office or, where GDPR applies, your local data-protection authority.
14. Children
BSV Business is a business service and is not directed at children under 18. We do not knowingly collect children's personal data.
15. Independent controllers and End Users
BSV does not issue gift cards or operate Merchant redemption platforms. You are responsible for giving your customers and End Users any privacy notice required for your resale or distribution. Do not rely on this Policy as their notice.
16. Changes
We may update this Policy from time to time. The “Last updated” date will change and material changes will be indicated on the Website. Continued use after an update constitutes acceptance unless applicable law requires another mechanism.
17. Contact
BSV TRADING SOLUTION - FZCO
DSO-IFZA, Dubai Silicon Oasis, IFZA, United Arab Emirates
Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE
[email protected] · [email protected]