Data Governance

Privacy Policy

A transparent account of how personal, financial, identity, and technical data is processed, protected, retained, and governed.

Effective Date
September 2026
Last Updated
September 2026
Platform
FibWealth (fibwealth.com)
§ 1

Regulatory Framework and Scope

FibWealth (“Company,” “we,” “us,” or “our”), operating via fibwealth.com, is committed to maintaining the highest standards of data security, cryptographic integrity, and global privacy compliance.

This Privacy Policy establishes how we collect, process, store, disclose, and safeguard personal, financial, and technical telemetry data when you access or interact with our platform. Our data processing activities are structured to comply with applicable global privacy, data protection, and financial regulatory frameworks, including without limitation:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and the UK Data Protection Act 2018 (UK GDPR).
  • California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA) (Cal. Civ. Code § 1798.100 et seq.).
  • Personal Data Protection Act 2012 (PDPA) of Singapore.
  • Financial Action Task Force (FATF) Recommendations, specifically Recommendation 16 ("Travel Rule") and related cross-border digital asset transmission directives.
  • EU 5th and 6th Anti-Money Laundering Directives (5AMLD / 6AMLD) and equivalent international Counter-Terrorist Financing (CTF) standards.

By registering an account, completing identity verification, or utilizing any services on fibwealth.com, you acknowledge and consent to the data practices described in this Policy. If you do not agree with this Policy, you must immediately terminate platform access and cease all interaction with our systems.

§ 2

Data Controller and Governance

For the purposes of the GDPR, UK GDPR, and related international data protection laws:

  • Data Controller: FibWealth operates as the primary Data Controller for account, verification, and ledger data processed across the platform.
  • Data Protection Office (DPO): We maintain a dedicated compliance and data protection office responsible for overseeing regulatory adherence, responding to Data Subject Access Requests (DSARs), and supervising security incident protocols.
§ 3

Lawful Bases for Data Processing (GDPR Art. 6 & 9)

We process personal and financial data strictly under established legal bases as defined by applicable statutory frameworks:

Lawful Basis
Contractual Necessity (Art. 6(1)(b))
Operational Scope
Executing core platform workflows, processing external deposits, calculating algorithmic daily profit distributions, allocating promotional deposit match bonuses, and facilitating authorized withdrawals.
Lawful Basis
Legal Obligation (Art. 6(1)(c))
Operational Scope
Fulfilling mandatory statutory obligations, including Know Your Customer (KYC), Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), sanctions screenings (e.g., OFAC, UN, EU consolidated lists), and tax reporting mandates.
Lawful Basis
Legitimate Interests (Art. 6(1)(f))
Operational Scope
Protecting platform infrastructure against distributed denial-of-service (DDoS) attacks, enforcing automated anti-arbitrage and capital lock policies, recording immutable audit logs, and mitigating financial fraud or multi-accounting exploits.
Lawful Basis
Explicit Consent (Art. 6(1)(a))
Operational Scope
Optional communications, marketing updates, or specific data processing actions where consent is legally mandated and explicitly granted.
§ 4

Categories of Data We Collect

FibWealth adheres strictly to principles of data minimization (GDPR Art. 5(1)(c)). We only collect data necessary to maintain financial precision, regulatory compliance, and platform security.

4.1. Identity and Verification Data (KYC/AML)

  • Full legal name, date of birth, nationality, and government-issued identification details (e.g., passport, national ID card, driver’s license).
  • High-resolution document scans, proof of address (e.g., utility bills, bank statements), and biometric facial verification data (processed via secure third-party KYC verification subprocessors).
  • Politically Exposed Person (PEP) and international sanctions clearance records.

4.2. Financial and Immutable Ledger Data

  • Digital asset wallet addresses, transaction hashes (tx_hash), deposit amounts, network confirmations, and asset rails.
  • Append-only ledger entries recording all credits, debits, capital locking timestamps, yield distribution allocations, and early forfeiture clawbacks.
  • Source-specific withdrawal records (Cash Capital, Distributable Profit, Matured Bonus, or Direct/Lifetime Affiliate Commission).

4.3. Authentication and Security Data

  • Primary email address, cryptographically hashed passwords (using industry-standard salted hashing algorithms; plaintext passwords are never stored or accessible), and Multi-Factor Authentication (MFA / 2FA) secret keys.
  • Active session tokens, device fingerprints, login timestamps, and password reset/verification tokens.

4.4. Technical, Network, and Telemetry Data

  • Internet Protocol (IP) addresses, browser user-agent strings, operating system signatures, and referral parameters (ref codes).
  • Immutable audit trail entries recording administrative and user-initiated system actions (capturing actor_id, action, target_entity, before_state, after_state, reason, and timestamp).
§ 5

Purposes of Processing and Automated Financial Logic

We process collected information for the following specific institutional objectives:

  1. Algorithmic Yield Distribution & Accounting: Calculating daily yield allocations strictly against an investor’s verified Effective Investment (\text{Effective Investment} = \text{Cash Investment} + \text{Active Bonus}) without manual discretion or bias.
  2. Automated Capital & Liquidity Controls: Enforcing mathematical capital holding locks (30-day cash capital lock; 60-day bonus principal lock) and automating atomic bonus clawbacks in the event of premature capital redemption.
  3. Affiliate Commission Attribution: Calculating direct 5% referral commissions on external cash deposits and 2% lifetime profit shares on referred daily realized returns, while strictly excluding bonus matches or internal reinvestments from duplicate commissions.
  4. Preventing System Gaming and Arbitrage: Detecting circular deposits, duplicate accounts, unauthorized automated scripts, and decimal manipulation.
  5. Regulatory Reporting and Auditability: Generating verifiable transaction histories for regulatory audits, tax reporting, and law enforcement compliance.
§ 6

Technical and Organizational Security Measures (TOMs)

Pursuant to Article 32 of the GDPR and SOC 2 / ISO/IEC 27001 security standards, FibWealth implements multi-tiered technical safeguards:

  • Zero-Knowledge Private Key Architecture: Platform and user hot/cold payment private keys and sensitive API credentials are fully decoupled from frontend client code and isolated within Hardware Security Modules (HSMs) and encrypted key management systems.
  • Cryptographic Transit & Storage Protection: All network communication is enforced via TLS 1.3 / HTTPS with strict HSTS headers. Database tables, backups, and private file storage (KYC documents) are encrypted at rest using AES-256.
  • Row-Level Security (RLS) & Access Controls: Database access is governed by strict PostgreSQL Row-Level Security policies ensuring unprivileged users cannot read, query, or mutate unauthenticated or administrative data. Administrative access requires mandatory 2FA and least-privilege Role-Based Access Control (RBAC).
  • Double-Entry Append-Only Ledger: The financial ledger operates under strict append-only constraints. Database triggers reject any direct UPDATE or DELETE mutations on financial records, ensuring non-repudiation.
  • Infrastructure Defense in Depth: Active rate limiting, Web Application Firewalls (WAF), SQL injection (SQLi) parametric validation, Cross-Site Scripting (XSS) sanitation, and automated dependency vulnerability scanning.
§ 7

Data Retention, Statutory Mandates, and Ledger Immutability

7.1. Statutory Anti-Money Laundering Retention

Under international AML/CFT directives (including 5AMLD/6AMLD and FATF guidelines), financial institutions must retain customer identification data, KYC records, and transaction documentation for a mandatory minimum period of five (5) to seven (7) years following the termination of the business relationship.

7.2. Immutable Ledger Accounting Policy

Because FibWealth operates on an institutional double-entry financial ledger:

  • Financial transactions, balance projections, and ledger entries cannot be erased or modified.
  • Any required balance correction is executed exclusively via an explicit, audited debit/credit adjustment entry.
  • Financial ledger entries and immutable audit logs are permanently maintained to guarantee mathematical continuity, proof-of-solvency, and historical auditability.
§ 8

Third-Party Subprocessors and International Data Transfers

8.1. Authorized Subprocessors

We engage accredited third-party service providers to deliver specialized operational infrastructure. All subprocessors are vetted for compliance with global security standards:

  • Identity & Document Verification: Accredited AML/KYC identity intelligence providers.
  • Cloud Infrastructure & Encrypted Storage: ISO 27001 and SOC 2 Type II certified data centers and S3-compatible private storage facilities.
  • Database & Caching Infrastructure: Managed PostgreSQL and distributed Redis instances operating under strict VPC peering and encryption.

8.2. Cross-Border Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, FibWealth ensures adequate legal protections are in place pursuant to GDPR Articles 44–49, utilizing:

  • Standard Contractual Clauses (SCCs): European Commission-approved model clauses implementing technical and organizational measures.
  • UK International Data Transfer Addendum (IDTA): Supporting cross-border UK data processing.
  • Adequacy Decisions: Transfers to jurisdictions officially recognized by relevant regulatory authorities as providing an adequate level of data protection.
§ 9

Data Subject Rights and Statutory Limitations

Depending on your jurisdiction, you may have specific statutory rights regarding your personal data under the GDPR, UK GDPR, CCPA/CPRA, or Singapore PDPA:

  • Right of Access (GDPR Art. 15): The right to obtain confirmation as to whether your personal data is being processed and receive a copy of your personal data.
  • Right to Rectification (GDPR Art. 16): The right to request correction of inaccurate or incomplete personal data (excluding immutable financial ledger history).
  • Right to Restriction of Processing (GDPR Art. 18): The right to restrict data processing under specific contested circumstances.
  • Right to Data Portability (GDPR Art. 20): The right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (GDPR Art. 21): The right to object to data processing based on legitimate interests or direct marketing.

9.1. Statutory Exceptions to the "Right to Erasure" (GDPR Art. 17(3))

The "Right to be Forgotten" / Right to Erasure is not absolute and is subject to statutory limitations under applicable law:

§ 10

California Privacy Rights (CCPA / CPRA Disclosures)

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • No Sale or Sharing of Personal Data: FibWealth does not sell, rent, monetize, or share your personal data with third parties for cross-context behavioral advertising.
  • Right to Know and Delete: California residents have the right to request disclosure of personal information collected, subject to the financial record retention exemptions under California Civil Code § 1798.145.
  • Non-Discrimination: We will not discriminate against any user for exercising their statutory privacy rights under California law.
§ 11

Cookies, Local Storage, and Telemetry

FibWealth utilizes strictly necessary cookies, session tokens, and browser local storage primitives solely to maintain authenticated sessions, CSRF protection, and user interface state.

  • Strictly Necessary Cookies: Essential for session validation, 2FA authorization flows, and load balancer routing. These cannot be disabled within platform settings as they are vital to security.
  • No Third-Party Tracking Pixels: We do not deploy third-party advertising tracking pixels, commercial ad networks, or social media data scrapers on authenticated investor or administration dashboards.
§ 12

Security Incident and Breach Notification Protocols

FibWealth maintains a structured Incident Response Plan in compliance with GDPR Articles 33 and 34:

  1. Detection & Containment: Immediate isolation of affected systems, revocation of compromised credentials, and activation of emergency security controls.
  2. Supervisory Notification: In the event of a confirmed personal data breach presenting a risk to the rights and freedoms of individuals, FibWealth will notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach.
  3. Data Subject Notification: If a breach is likely to result in a high risk to your personal rights and freedoms, we will notify affected users directly without undue delay via registered email and secure platform notifications.
§ 13

Children’s Privacy and Age Restrictions

FibWealth strictly prohibits access to individuals under the age of eighteen (18) years (or the age of legal majority in your jurisdiction). We do not knowingly collect, process, or maintain data from minors under the Children’s Online Privacy Protection Act (COPPA) or GDPR Article 8. Accounts discovered to belong to minors will be terminated immediately, and unverified data will be deleted subject to statutory legal holds.

§ 14

Amendments and Policy Versioning

FibWealth reserves the right to amend, update, or revise this Privacy Policy to reflect modifications in regulatory requirements, technological architecture, or platform operations.

  • All revisions will be posted with an updated Effective Date and registered within our administrative policy versioning records.
  • Material modifications affecting user privacy rights will be communicated via in-app dashboard notifications or direct email alerts prior to taking effect.
  • Continued access to fibwealth.com following the posting of an updated Policy constitutes binding acceptance of the revised terms.
§ 15

Contact and Data Protection Inquiries

To exercise your statutory data rights, submit a Data Subject Access Request (DSAR), or inquire about our privacy practices:

  • Investor Portal Support: Open a priority support ticket under the Security / Compliance category directly from your dashboard.
  • Email Communication: Contact our compliance team at compliance@fibwealth.com or privacy@fibwealth.com.
  • Platform Operations: FibWealth Legal & Data Protection Division, accessible via fibwealth.com.