> For the complete documentation index, see [llms.txt](https://help.getlfg.app/p/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.getlfg.app/p/agreements/regulatory-position-statement.md).

# Regulatory position statement

## Introduction

Thank you for reviewing our Privacy Policy and Regulatory Position Statement.

We respect your privacy and are committed to protecting your personal data. This policy explains how we collect, handle, use, and safeguard your personal data, your privacy rights, and how the law protects you when you use our software interface.

**Who We Are:** Depending on your jurisdiction and residency, your personal data is controlled by the applicable Layer Flow Gateway entity (collectively referred to as “LFG”, “the Company”, “we”, “us”, or “our”):

* **United Arab Emirates & Global Users:** **Layer Flow Gateway FZCO**, a company registered in the Dubai World Trade Centre (DWTC) free zone, UAE (Licence No. L-3426).
* **United Kingdom Users:** **Layer Flow Gateway Ltd**, registered in England and Wales (Company No. 15106550).
* **United States Users:** **Layer Flow Gateway, Inc.**, incorporated in Delaware, USA (Delaware File No. 10054149).

The specific entity corresponding to your jurisdiction acts as the data controller for personal data processed in connection with our Services.

**Contact:** <legal@getlfg.app> (Data Privacy Team) - **Support:** <support@getlfg.app>

This Privacy Policy explains how LFG collects, uses, shares, and protects personal data when you use our software platform, website, and related services (the “Services”). As outlined in our Terms of Service, our Services are purely non-custodial software tools and are strictly **not made available** to residents or entities within prohibited jurisdictions as defined in our Global Availability Statement (including sanctioned regions, mainland China, and other restricted territories).

This Policy complies with applicable regional data protection regulations, including:

* **UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)**
* **UK Data Protection Act 2018 and UK GDPR**
* **Applicable United States Federal and State Privacy Laws**

We provide non-custodial software infrastructure that interoperates with user-controlled wallets. We do not hold private keys or seed phrases, and we do not initiate, transmit, or settle blockchain transfers. This Policy should be read directly in conjunction with our Terms of Service.

## 1. Scope & Eligibility

1.1 This Policy applies strictly to data processing involving users (businesses and individuals) who reside or operate within our approved operational jurisdictions as defined in our Global Availability Statement.

1.2 If your residency, incorporation, principal place of business, or operational footprint changes to a prohibited jurisdiction listed in our Global Availability Statement, you are no longer eligible to use the Services, and your data processing activities under this platform will be terminated.

## 2. Data We Collect

To maintain a privacy-first, non-custodial software layer, we limit data collection to the absolute technical minimum required to operate our SaaS platform and prevent financial crime:

* **Account Registration Data:** Name, email address, corporate/business registration documents (for KYB), and account credentials.
* **Identity & Compliance Data:** Cryptographic verification data, compliance/sanctions screening metrics, and probabilistic risk flags processed via our integrated identity partners.
* **Public Blockchain Data:** Public wallet addresses, token balances, transaction hashes, and timestamps.
* **Technical Log Data:** IP addresses (used strictly for geo-fencing and fraud monitoring), device operating system, browser type, and software version data.

*LFG explicitly guarantees that it does not collect, view, or store your wallet's private keys, seed phrases, or backup words. You maintain absolute, exclusive control over your cryptographic assets.*

## 3. Lawful Basis for Processing

Depending on your contracting entity and jurisdiction, we process your personal data under the following lawful grounds (pursuant to Article 6 UAE PDPL, Article 6 UK GDPR, and US statutory frameworks):

1. **Contractual Performance:** To provision and maintain your software account and deliver SaaS functionality.
2. **Legal Obligation:** To comply with federal and national regulations, anti-money laundering (AML) protocols, and authorized cross-border Travel Rule pass-through data requirements.
3. **Consent:** Where you explicitly choose to enable optional platform integrations or third-party features.
4. **Legitimate Interests:** To prevent fraud, enforce platform geo-fencing, secure our infrastructure, and manage corporate risk, provided these interests are not overridden by your fundamental privacy rights.

## 4. How We Use Personal Data

We use your data strictly to manage your SaaS account, enforce our geographic restrictions (geo-fencing), analyze indicative security risks, and pass through data to third-party providers at your explicit instruction (e.g., sending public addresses to integrated On/Off-Ramp providers). We do not engage in monetization, profiling, or selling of user data to third-party marketing networks.

## 5. Data Sharing and Third-Party Providers

Because LFG operates purely as an interface, certain features rely on third-party service providers (e.g., Web3Auth for non-custodial MPC key generation, compliance screening partners, and licensed fiat on/off-ramp networks). Your data is only shared with these providers to execute instructions explicitly initiated by you. All processing is bound by strict confidentiality and data-handling agreements under applicable laws (including UAE PDPL, UK GDPR, and US data privacy standard contractual clauses).

## 6. Cross-Border Transfers

Where personal data is transferred across international borders, we ensure appropriate safeguards are implemented:

* **UAE Operations:** Handled in accordance with Article 22 of the UAE PDPL.
* **UK Operations:** Conducted using approved International Data Transfer Agreements (IDTA) or UK Addendum Standard Contractual Clauses under the UK GDPR.
* **US Operations:** Conducted using industry-standard technical controls, encryption, and standard contractual privacy frameworks.

In all cases, end-to-end data encryption and strict technical protocols are applied to maintain international data integrity.

## 7. Data Retention Periods

* **Identity & Onboarding Logs (KYC/KYB):** Retained for a minimum of five (5) years post-account closure to fulfill global anti-financial crime and compliance record-keeping baselines.
* **SaaS Transaction Logs & Metadata:** Retained for seven (7) years for internal organizational auditing and dashboard stability.
* **System Backups:** Automatically overwritten or purged every ninety (90) days.

## 8. Data Security Measures

LFG implements industry-standard technical controls to defend your information, including AES-256 encryption for data at rest, TLS 1.2+ for data in transit, role-based internal access controls, and strict multi-factor authentication (MFA) requirements for administrative systems.

## 9. Your Rights Under Applicable Laws

Depending on your place of residency and the applicable contracting entity, you possess explicit statutory privacy rights:

* **Access & Portability:** The right to request confirmation of processing and a machine-readable copy of your personal data.
* **Rectification:** The right to request immediate correction of inaccurate or incomplete information.
* **Erasure ("Right to be Forgotten"):** The right to request deletion of data when it is no longer required for contractual, legal, or audit compliance.
* **Restriction & Objection:** The right to object to processing based on legitimate interests or restrict specific data handling workflows.
* **US State Privacy Rights:** US residents may also have specific statutory rights to know what personal data is collected, opt-out of certain processing activities, and be free from discrimination for exercising privacy rights.

To exercise any of these rights, contact our privacy team at <legal@getlfg.app>.

## 10. Support & Complaints

If you have a concern or complaint regarding how your data is managed, please contact us at <legal@getlfg.app>. We acknowledge all inquiries within five (5) business days and aim to provide a final resolution within thirty (30) days.

If we cannot resolve your issue directly, you retain the legal right to escalate the matter to your local supervisory authority:

* **UAE Users:** The **Emirates Data Office** (the central supervisory authority under the UAE PDPL).
* **UK Users:** The **Information Commissioner’s Office (ICO)** (UK supervisory authority).
* **US Users:** Applicable State Attorney General offices or the **Federal Trade Commission (FTC)**.

## 11. Corporate Details & Jurisdiction

Data processing governance and dispute resolution follow the applicable contracting entity and jurisdiction:

* **United Arab Emirates & Global:**
  * **Entity:** Layer Flow Gateway FZCO
  * **Address:** Level 17, Sheikh Rashid Tower, Dubai World Trade Centre, Dubai, UAE
  * **Licence No.:** L-3426
  * **Jurisdiction:** Laws of the United Arab Emirates / Courts of Dubai
* **United Kingdom:**
  * **Entity:** Layer Flow Gateway Ltd
  * **Address:** Level 5a Maple House, 149 Tottenham Court Road, London, United Kingdom, W1T 7NF
  * **Company No.:** 15106550
  * **Jurisdiction:** Laws of England and Wales / Courts of England and Wales
* **United States of America:**
  * **Entity:** Layer Flow Gateway, Inc.
  * **Address:** 131 Continental Dr, Suite 305, Newark, DE 19713, United States of America
  * **Delaware File No.:** 10054149 (Incorporated 2 January 2025)
  * **Jurisdiction:** Laws of the State of Delaware / State and Federal Courts located in Delaware, USA

## Plain-English Summary (Non-Binding)

We collect the absolute minimum data required to run, secure, and geo-fence our non-custodial software platform. We have zero visibility over your private keys and cannot touch your funds. We share metadata only when you instruct us to (such as interacting with an on-ramp) or when strictly necessary for regulatory pass-through (like the Travel Rule). We operate through our corporate entities in Dubai, the UK, and the USA, strictly adhering to UAE, UK, US, and international privacy standards.
