HoneyB Privacy Policy

Effective date: September 1, 2026

1. About this Policy

The HoneyB website and platform are operated by Amber Capital SPC, a Cayman Islands company (“Amber”, “we”, “us”). HoneyB is a brand name, not a separate legal entity.

“Personal Data” means information that identifies or relates to an individual. This Policy explains how we handle Personal Data on the HoneyB website and platform (the “Platform”). It covers visitors, applicants, account holders and the people of our business customers. Amber is the data controller.

This Policy is a notice, not a contract term. It prevails over our Terms of Use and any feature-specific terms on privacy matters.

We may change this Policy and will post it with a new effective date. Where a change is material, we tell you through the Platform or by email before it takes effect.

2. Personal Data we collect

Profile and contact data (name, date of birth, nationality, home address, email, telephone number)

Why we use it — To open and run your account, contact you and, with your consent, send you marketing

Who receives it — Service providers acting on our instructions

Identity-verification and screening data (identity documents, proof of address, tax residence, occupation, origin of funds and wealth; a selfie and liveness check where you choose it and the biometric data derived from it; identity, sanctions and risk-screening results)

Why we use it — To confirm who you are and to meet anti-money-laundering and sanctions duties

Who receives it — Our identity-verification provider and other service providers acting on our instructions; regulators, law enforcement and courts where the law requires

Business-customer data (owners, control persons, directors, signatories and authorised users; corporate documents)

Why we use it — To verify and screen a business customer and run its account

Who receives it — Our identity-verification provider and other service providers acting on our instructions; regulators where the law requires

Eligibility and tax-status information (the questionnaire answers you give when you apply; tax forms and self-certifications)

Why we use it — To confirm that you may use the Platform and to meet tax-reporting duties

Who receives it — Service providers acting on our instructions; tax authorities where the law requires

Wallet and transaction data (wallet addresses, on-chain activity, transaction records, bank account details)

Why we use it — To carry out and record what you ask us to do and to prevent financial crime

Who receives it — Financial institutions and infrastructure providers; service providers acting on our instructions

Device, log and usage data (IP address, device and browser data, log data, cookie identifiers)

Why we use it — To keep the Platform secure, fix faults and understand how it is used

Who receives it — Service providers acting on our instructions

Communications (your messages to us, our replies, support records)

Why we use it — To answer you and keep a record

Who receives it — Service providers acting on our instructions

We obtain this data from you, from our identity-verification provider and the databases it checks, from public registers, sanctions lists and other public sources, from financial institutions and payment providers, and from your device.

We need your account and verification data to comply with the law and to provide the Platform. Without it we cannot open or keep your account. Biometric verification is optional, as section 3 explains.

We also use Personal Data to establish and defend legal claims.

We will never ask you for a private key or recovery phrase.

Where you use on-chain features, your transactions are recorded on public blockchains we do not control. Those records are permanent and public.

If you act for a business customer, give this Policy to the people whose details you provide before you submit them. They have the rights in sections 9 and 10 and can exercise them with us.

3. Identity verification and biometric data

We verify identity and screen applicants and customers through a specialist identity-verification provider that acts on our instructions. For its own purposes it is an independent controller, and its own privacy notice is presented to you during verification. The checks are automated. A person reviews any adverse or unclear result before we decide. Decisions are made by Amber, not by the provider. You may ask us to review a decision. We re-screen you during the relationship.

We collect biometric data only with your explicit consent, given in the verification flow. A manual verification route is available and may take longer. Declining biometric verification is not by itself a ground for refusal. You may withdraw your consent at any time. Withdrawal does not affect what we did before it.

4. How we disclose Personal Data

We disclose Personal Data to:

  • service providers for technology and operations, hosting, IT, security, payments and communications, and our identity-verification provider, all acting on our instructions.
  • financial institutions and infrastructure providers needed to provide a service.
  • parties you ask us to share with.
  • professional advisers and auditors.
  • regulators, law enforcement and courts, where the law requires.
  • a buyer or successor in a corporate transaction.
  • recipients of de-identified or aggregated data that no longer identifies you.

We do not sell Personal Data or share it for third-party marketing.

Some recipients are outside the Cayman Islands, including in the United States and other countries where our providers operate. We transfer Personal Data only where the destination gives adequate protection or another lawful safeguard applies. You can ask us for details or a copy of the safeguards.

Third-party sites and services linked from the Platform have their own privacy notices.

5. Cookies and tracking

Essential cookies keep the Platform working, hold your session and protect against abuse. We set other cookies only where you consent through the cookie banner. We do not currently use analytics cookies. You can change or withdraw your choices at any time through the cookie controls or your browser. We do not currently respond to browser Do Not Track signals.

6. Security

We protect Personal Data with access controls, encryption in transit and at rest, access logging and monitoring, confidentiality duties on our people, and due diligence on our providers. No system is completely secure. Where an incident affects your Personal Data, we will inform you and any authority as the law requires.

7. Retention

We keep Personal Data only as long as needed for the purposes in this Policy, for our legal obligations and for unresolved claims, then delete or anonymise it. Where anti-money-laundering law applies, identification records, including records of applications that do not lead to an account, are kept for at least five years after the relationship ends or the application is decided, and transaction records for at least five years after the transaction. Selfie and liveness images, and the biometric data derived from them, are deleted once verification is complete and evidenced. Account, device and communications data are kept while your account is open and for as long as a claim could be brought afterwards. Visitor device and usage data, and communications from people without an account, are kept only as long as needed for security, fault-fixing and answering you. Marketing preferences are kept until you withdraw consent.

8. Children

The Platform is for persons aged 18 or over. We do not knowingly collect data from anyone younger. We delete it on discovery.

9. Your rights

The Cayman Islands Data Protection Act (2021 Revision) gives you rights over your Personal Data. Subject to the conditions the law sets, you may:

  • ask for access to the Personal Data we hold about you.
  • ask us to correct data that is inaccurate or incomplete.
  • ask us to erase data, or stop processing it, in the cases the law defines.
  • object to direct marketing at any time.
  • ask us to restrict processing where that applies.

Write to contact@honeybtc.com to exercise a right. We will first ask for information that confirms your identity.

We cannot delete records we must keep under anti-money-laundering, sanctions or tax law, and we will tell you where that applies.

You may complain to the Office of the Ombudsman of the Cayman Islands.

10. EEA and UK residents

This section applies where the EU General Data Protection Regulation (GDPR) or the UK GDPR governs our handling of your Personal Data. Amber is the controller. Our lawful bases are:

  • contract, for your account and our communications.
  • legal obligation, for verification, screening and compliance records, and for disclosures a court or authority requires.
  • legitimate interests, for security, for improving the Platform, for establishing and defending legal claims and, where a Cayman Islands duty is not an EU or UK legal obligation, for preventing financial crime.
  • consent, for marketing and non-essential cookies.
  • explicit consent under Article 9(2)(a), for biometric data.

You have the rights those laws give: access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You may complain to your supervisory authority. Transfers out of the EEA or the UK use the EU Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum.

11. Contact

Questions and requests: contact@honeybtc.com.