Privacy Policy
How we collect, use, and protect your data
Last updated: September 2025
This Privacy Policy describes how Rules Holdings BVI Ltd. ("Bumba", "we", "us", or "our") collects, uses, and shares information about you when you use our virtual asset exchange and custody services.
1. Introduction
Rules Holdings BVI Ltd. is authorized and regulated by the Financial Services Commission of the British Virgin Islands as a Virtual Asset Service Provider (VASP) under license number VASP/24/007, permitted to provide virtual asset exchange and custody services for accepted virtual assets.
We are committed to protecting your privacy and handling your personal data responsibly and in compliance with applicable data protection laws, including:
- BVI Data Protection Act 2021
- Brazilian Lei Geral de Proteção de Dados (LGPD)
- EU General Data Protection Regulation (GDPR) where applicable
- UAE Personal Data Protection Law (PDPL) where applicable
2. Information We Collect
2.1 Identifying Information
When you create an account and use our services, we collect:
- Full legal name and date of birth
- Government-issued identification documents (passport, ID card, driver's license)
- Nationality and country of residence
- Photographs and selfies for identity verification
2.2 Contact Information
- Email address
- Phone number
- Physical address
2.3 Financial Information
- Bank account details for fiat deposits/withdrawals
- PIX keys and payment information
- Cryptocurrency wallet addresses
- Transaction history and trading activity
- Source of funds documentation
2.4 Compliance Data
- Tax identification numbers (CPF, CNPJ)
- Risk assessment information
- Sanctions screening results
- Politically Exposed Person (PEP) status
2.5 Technical Data
- IP addresses and device information
- Browser type and operating system
- Login timestamps and session data
- Cookies and similar tracking technologies
3. How We Collect Information
Direct Collection: Information you provide when registering, verifying your identity, making transactions, or contacting support.
Third Parties: We may receive information from:
- Identity verification providers (e.g., Sumsub)
- Sanctions and compliance screening services
- Credit reference agencies
- Regulatory authorities and law enforcement
- Public records and databases
Automatic Collection: Our servers automatically collect technical data when you access our platform through cookies, server logs, and analytics tools.
4. How We Use Your Information
We process your personal data for the following purposes:
- Service Provision: To create and manage your account, process transactions, and provide customer support
- Legal Compliance: To comply with KYC/AML regulations, tax reporting requirements, and respond to legal requests
- Security: To detect, prevent, and investigate fraud, unauthorized access, and other illegal activities
- Communication: To send transaction confirmations, security alerts, and service updates
- Improvement: To analyze usage patterns and improve our services
- Marketing: With your consent, to send promotional materials about our products and services
5. Legal Basis for Processing
We process your personal data based on one or more of the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you
- Legal Obligation: Processing required to comply with applicable laws and regulations
- Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, platform security)
- Consent: Processing based on your explicit consent (e.g., marketing communications)
- Vital Interests: Processing necessary to protect your vital interests or those of another person
6. Information Sharing and Transfers
We may share your information with:
- Group Companies: Our affiliates, including Kinetic (Brazil) for fiat processing
- Service Providers: Third parties who assist us in providing services (identity verification, custody, banking)
- Regulatory Bodies: Financial regulators, tax authorities, and law enforcement when required by law
- Professional Advisors: Lawyers, auditors, and consultants under confidentiality obligations
International Transfers: Your data may be transferred to countries outside your residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by relevant data protection authorities.
7. Data Security
We implement industry-standard security measures to protect your personal data, including:
- Encryption of data in transit (HTTPS/TLS) and at rest
- Multi-factor authentication for account access
- Regular security audits and penetration testing
- Access controls and employee training
- Secure cloud infrastructure with validated security controls
- 24/7 monitoring for security threats
While we take every reasonable precaution, no system can guarantee absolute security. You are responsible for safeguarding your credentials and enabling available security features.
8. Data Retention
We retain your personal data for as long as necessary to:
- Provide our services while your account is active
- Comply with legal, regulatory, and tax obligations (typically up to 7 years after account closure)
- Resolve disputes and enforce our agreements
- Maintain records for audit and compliance purposes
When data is no longer required, we will securely delete or anonymize it in accordance with our data retention policies.
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Restriction: Request that we limit processing of your data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Automated Decisions: Not be subject to decisions based solely on automated processing
Note that some rights may be limited where we have overriding legitimate interests or legal obligations.
10. Exercising Your Rights
To exercise your privacy rights or ask questions about this policy:
Data Protection Contact:
Email: [email protected]
We will respond to all legitimate requests within 30 days. We may ask you to verify your identity before processing your request.
You may withdraw consent for marketing communications at any time using the unsubscribe link in our emails or by contacting us directly.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep you logged in and remember your preferences
- Understand how you use our platform
- Provide security features
- Analyze and improve our services
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of our platform.
12. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify relevant supervisory authorities within required timeframes
- Inform affected users without undue delay
- Describe the nature of the breach and data affected
- Explain the likely consequences and measures taken
- Provide recommendations for protecting yourself
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through:
- Notices on our website
- Email notifications to registered users
- In-app announcements
We encourage you to review this policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
Rules Holdings BVI Ltd.
Craigmuir Chambers, Road Town, Tortola, VG1110
British Virgin Islands
Data Protection Officer: [email protected]
General Inquiries: [email protected]
If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.