Privacy policy
Introduction
Thank you for reading our privacy policy.
We respect your privacy and are committed to protecting your personal data. This policy explains how we look after your personal data, your privacy rights, and how the law protects you.
Who we are: Depending on your jurisdiction and residency, your personal data is controlled by the applicable Layer Flow Gateway entity (collectively referred to as “LFG”, “the Company”, “we”, “us”, or “our”):
United Arab Emirates & Global Users: Layer Flow Gateway FZCO, a company registered in the Dubai World Trade Centre (DWTC) free zone, UAE (Licence No. L-3426).
United Kingdom Users: Layer Flow Gateway Ltd, registered in England and Wales (Company No. 15106550).
United States Users: Layer Flow Gateway, Inc., incorporated in Delaware, USA (Delaware File No. 10054149).
The specific entity corresponding to your jurisdiction acts as the data controller for the personal data processed in connection with our Services.
Contact: legal@getlfg.app (Data Privacy Team) - Support: support@getlfg.app
This Privacy Policy explains how LFG collects, uses, shares and protects personal data when you use our website, application, and related services (the “Services”). In strict alignment with our Terms of Service, our Services are purely non-custodial software tools and are not made available to residents, citizens, or entities within prohibited jurisdictions listed in our Global Availability Statement.
This Policy complies with applicable regional data protection frameworks, including:
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
UK Data Protection Act 2018 and UK GDPR
Applicable United States Federal and State Privacy Laws
We provide non-custodial software. We do not hold private keys or seed phrases and we do not initiate, transmit, or settle blockchain transfers.
This Privacy Policy should be read together with our Terms of Service.
1. Scope & Eligibility
1.1 This Policy applies strictly to the personal data we process about users (businesses and individuals) who reside or operate within our approved operational jurisdictions, as well as website visitors and contacts (e.g., support, sales) from allowed regions.
1.2 The Services are intended for adults (18+). We do not knowingly collect personal data from children.
1.3 If your residency, incorporation, principal place of business, or operational footprint shifts to a prohibited jurisdiction listed in our Global Availability Statement, you are no longer eligible to use the Services, and any ongoing data processing activities under this platform will be terminated.
2. The Data We Collect
To maintain a privacy-first, non-custodial software layer, we limit data collection to the absolute technical minimum required to operate our SaaS platform, manage accounts, and prevent financial crime:
Account / KYC / KYB Data: Name, date of birth, nationality, ID/passport details, liveness/biometric verification (for allowed individual accounts), business licence, ownership/UBO details, corporate registration files, and company contact details.
Profile & Settings: Company name, logo, wallet labels, and configuration preferences.
Support & Communications: Enquiries, emails, chat messages, and support ticket details.
Billing Metadata: Contact details, subscription plan history, invoices, and payment statuses. We never store or view full payment card numbers; our payment providers give us tokenised references only.
Device & Technical Logs: App version, device type, IP addresses (used strictly for geo-fencing, anti-circumvention, and fraud monitoring), server logs, crash reports, and system diagnostic data.
Public Blockchain Data: Public wallet addresses you explicitly connect or interact with, transaction hashes, token contract metrics, and network timestamps.
Compliance Signals: Risk/sanctions flags and Travel Rule data where required to facilitate data pass-through.
LFG explicitly guarantees that it does not collect, view, or store your wallet's private keys, seed phrases, or backup words. These remain entirely on your device and are completely inaccessible to us.
3. How We Use Personal Data
In accordance with applicable law (including Article 6 UAE PDPL, Article 6 UK GDPR, and US statutory frameworks), we process personal data under the following lawful grounds:
To Provide and Operate the Services — basis: contract performance (maintaining your software account and delivering SaaS workflows).
Onboard & Verify (KYC/KYB) — basis: legal obligation / contract performance.
AML/CFT Screening & Travel Rule Data Pass-Through — basis: legal obligation / public interest (facilitating mandated compliance reporting to regulated counterparties).
Risk Management & Fraud Prevention — basis: legitimate interests of the platform / legal obligation.
Territorial Enforcement & Geo-fencing — basis: legitimate interests / legal obligation (ensuring users from sanctioned or banned regions are prevented from accessing the app).
Customer Support & Communications — basis: contract performance.
Billing & Accounting — basis: contract / legal obligation.
Service Improvement & Infrastructure Stability — basis: legitimate interests.
We do not engage in the monetization, profiling, or selling of user data to third-party advertising or marketing networks.
4. Automated Decisions & Profiling
We use automated risk and sanctions signals to enable or disable certain interface features (such as token swaps or off-ramp rails) and to help prevent financial crime. You may contact us at legal@getlfg.app to request a human review of an automated decision, to express your view, or to contest an access limitation.
5. Sharing Your Information
Because LFG operates purely as a technology interface, we share personal data only as needed to provide and secure the Services or as required under explicit legal compliance frameworks:
Regulated Counterparties: Virtual Asset Service Providers (VASPs), Payment Service Providers (PSPs), or Electronic Money Institutions (EMIs) integrated into our platform ecosystem, strictly to facilitate your explicit payment or settlement instructions (e.g., passing public addresses to an on/off-ramp provider) or to handle Travel Rule compliance pass-through data.
Vendors & Tech Providers: Third-party sub-processors (cloud hosting, system security, compliance analytics, customer support software) operating under strict data-handling and confidentiality agreements.
Professional Advisers & Competent Authorities: Legal counsel, corporate auditors, and government regulators where required by applicable laws in the United Arab Emirates, the United Kingdom, or the United States.
Corporate Restructuring: In the event of a merger, acquisition, or corporate asset sale, your personal data will remain fully protected under the terms of this Policy.
SMS & Text Messaging (CTIA Compliance): Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
6. International Transfers
As a multi-jurisdictional platform, personal data may be processed on servers located outside your home country. Any cross-border transfer of personal data is handled strictly in accordance with statutory protections:
UAE Operations: Conducted under Article 22 of the UAE PDPL.
UK Operations: Conducted using UK International Data Transfer Agreements (IDTA) or UK Addendum Standard Contractual Clauses under the UK GDPR.
US Operations: Conducted using industry-standard technical safeguards, data encryption, and standard privacy contractual terms.
7. Security
We apply industry-standard technical and organisational controls, including AES-256 data encryption at rest, TLS 1.2+ encryption for data in transit, network firewall isolation, role-based internal data access permissions, and multi-factor authentication (MFA) for administrative networks. Because no transmission or storage method is completely secure, you remain responsible for securing your personal device and keeping backup words, seed phrases, and account credentials strictly confidential.
8. Retention
We retain personal data only as long as needed to fulfill our operational services or as dictated by applicable legal baselines:
AML/CFT and Identity Verification Records: At least five (5) years post-account closure to comply with statutory compliance and anti-financial crime reporting thresholds.
Tax, Invoicing, and Corporate Accounting Records: At least seven (7) years.
System Backups: Automatically overwritten or permanently purged every ninety (90) days.
Data may be retained for longer windows if required to manage active legal claims, historical corporate disputes, or ongoing fraud prevention investigations.
9. Your Rights Under Applicable Law
Subject to technical limitations and statutory exemptions under applicable privacy legislation (UAE PDPL, UK GDPR, or US State Privacy Laws), you possess the following explicit data privacy rights:
Right to Access & Portability: You may request confirmation of whether we are processing your data and receive a clear, machine-readable copy of your personal data records.
Right to Rectification: You can request the immediate correction of inaccurate, outdated, or incomplete data.
Right to Erasure (Right to be Forgotten): You may request the deletion of your personal data when it is no longer required for active contractual performance, legal obligation, or auditing baselines.
Right to Restrict or Object: You may object to automated software processing, profiling, or restrict specific data handling workflows.
Right to Withdraw Consent: Where a processing activity is based explicitly on your consent, you may withdraw that consent at any time.
US State-Specific Privacy Rights: US residents may also have additional rights to know what personal information is collected, request non-discrimination for exercising privacy rights, and opt out of certain data processing activities.
To exercise any of these statutory rights, please contact our privacy team directly at legal@getlfg.app.
10. Non-Custodial Wallets & Blockchain Limitations
LFG provides a non-custodial software interface and has zero custody over your cryptographic funds. Deleting the LFG application from your device or closing your account does not move your digital assets, cannot restore lost keys, and will not delete public blockchain logs. By their structural design, public blockchain infrastructure logs (such as public wallet addresses, transaction weights, and hashes) are immutable and cannot be altered, corrected, or erased by us.
11. Cookies & Similar Technologies
We use essential, first-party technical cookies and SDK variables to keep your account session secure, preserve interface preferences, and run basic performance analytics to monitor platform crashes. Where optional tracking tools are used, we will explicitly ask for your consent inside the app.
12. Contact, Complaints & Corporate Authority
If you wish to ask questions or make a formal complaint regarding this Privacy Policy, our data workflows, or our security frameworks, please reach out to our team:
Data Privacy Email: legal@getlfg.app
General Support Email: support@getlfg.app
Corporate Registered Addresses:
UAE / Global: Layer Flow Gateway FZCO, Level 17, Sheikh Rashid Tower, Dubai World Trade Centre, Dubai, United Arab Emirates (Licence No. L-3426).
United Kingdom: Layer Flow Gateway Ltd, Level 5a Maple House, 149 Tottenham Court Road, London, United Kingdom, W1T 7NF (Company No. 15106550).
United States: Layer Flow Gateway, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States of America (Delaware File No. 10054149).
We acknowledge all data inquiries within five (5) business days and strive to deliver a final evaluation or response within thirty (30) days. If we are unable to resolve your privacy concern directly, you retain the legal right to escalate the matter to your applicable supervisory authority:
UAE Users: Emirates Data Office (under the UAE PDPL).
UK Users: Information Commissioner’s Office (ICO).
US Users: Applicable State Attorney General or the Federal Trade Commission (FTC).
13. Changes to This Policy
We may update this Privacy Policy from time to time to align with software feature additions, changes in corporate layout, or updates to regional laws. We will publish the updated Policy with a new effective date and, where the changes are material, notify you via an in-app prompt or email broadcast.
14. Definitions (Extract)
Personal Data: Any information relating to an identified or identifiable natural person.
Data Controller: The entity that determines the method, purpose, and structural criteria of personal data processing.
Travel Rule: The international compliance tracking framework requiring the transmission of minimum sender and receiver identifiers during digital asset transfers between virtual asset service providers.
Public Blockchain Data: Immutable data written directly to a public distributed ledger (such as wallet addresses, transaction hashes, gas costs, and transfer amounts).
Plain-English Summary (Non-binding)
We collect the absolute minimum personal data needed to run, secure, and geo-fence our non-custodial software platform. We have zero visibility over your private keys and cannot touch your funds. We share metadata only when you instruct us to (such as interacting with an on-ramp) or when strictly necessary for regulatory pass-through (like the Travel Rule). We operate through our corporate entities in Dubai, the UK, and the USA, strictly adhering to UAE, UK, US, and international privacy standards.
Last updated