Data Privacy Office

Privacy Policy

Last Updated: May 20, 2026

1. Information Collection

Iron Bridge Banking collects personal and corporate data to fulfill legal requirements, perform verification, and deliver digital asset services. This includes identifying corporate representatives (names, email addresses, phone numbers, passport credentials), corporate records (articles of association, ultimate beneficial ownership details, corporate registration files), and transaction log records.

Additionally, we automatically capture telemetry, network logs, and device data (IP addresses, operating system specifications, access timestamps, and API usage stats) to safeguard account access and prevent unauthorized transactions.

2. Usage & Data Processing

We process your data based on several legal grounds: to perform contracts, to comply with anti-money laundering (AML) and counter-terrorist financing (CTF) mandates, and to satisfy legitimate business interests.

Data is utilized to: onboard corporate clients, execute institutional trades, manage custody vaults, route orders through liquidity pools, detect and prevent fraud, optimize platform loading performance, and communicate security updates.

3. Information Sharing

We do not sell, rent, or lease your personal or corporate data to third parties. Information is shared strictly under confidential arrangements with trusted third-party service providers, banking partners, and custody aggregators who help operate our systems.

Furthermore, Iron Bridge Banking reserves the right to disclose client data to national security bodies, regulatory authorities (e.g., relevant financial or banking regulators), or judicial tribunals if required by binding subpoena, regulatory reporting mandates, or AML inquiries.

4. Cryptographic Security

Client records and transactional databases are guarded using bank-grade cryptographic protocols. Iron Bridge Banking implements AES-256 encryption for data at rest and Transport Layer Security (TLS 1.3) for data in transit.

Access controls are strictly partitioned within our network. Cryptographic key materials are segmented across highly secure, hardware security modules (HSMs) and verified using Multi-Party Computation protocols, ensuring zero centralized vulnerabilities.

5. International Transfers

Because Iron Bridge Banking serves a global market, client information may be stored, processed, or transferred across international boundaries, including locations outside the UK, the European Economic Area (EEA), or the United States.

All cross-border data transfers comply with statutory frameworks, incorporating standard contractual clauses (SCCs) and robust data protection audits to guarantee an equivalent degree of privacy protection across foreign jurisdictions.

6. Data Retention

Iron Bridge Banking retains client information only as long as necessary to perform platform operations or to comply with applicable statutory timelines.

Pursuant to financial regulations and anti-money laundering regulations, we are required to maintain customer identification records, ultimate beneficial ownership dossiers, and transaction logs for a minimum of five (5) to seven (7) years following account closure.

7. Regulatory Data Rights

Depending on your geographical jurisdiction, corporate representatives may have specific individual rights under frameworks like the General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA).

These include the right to request access to personal data, request rectification of errors, request erasure (subject to statutory AML retention overrides), object to processing, or request data portability. To submit a request, contact our privacy division.

8. DPO Contact & Updates

We may revise this Privacy Policy periodically to reflect technological adjustments, regulatory developments, or product adaptations. Revisions will be published directly here, with an updated timestamp at the header.

If you have questions regarding our data usage practices, or wish to communicate with our Data Protection Officer, please contact our legal desk via email at dpo@ironbridgebanking.com or write to our corporate address.