Privacy Policy
Last Updated: 21 September 2026
This Privacy Policy (the “Privacy Policy”) provides a description of how the DWF Labs group of companies (the “Group”, each member a “Group Company”, and “we”, “our” or “us”) collect, use, disclose, transfer, retain and otherwise process Personal Data when you use or access our website (https://www.dwf-labs.com/), products, services, or applications that posts a link to this Privacy Policy (collectively, the “Services”)
By using the Services, you are agreeing to this Privacy Policy. Please read the following carefully to understand how we collect, use, disclose, and maintain information that can be used to identify you (“Personal Data”). By using the Services, you also agree to our collection, use, and disclosure practices, as well as any other activities described in this Privacy Policy, and, where your consent is required under the data protection law applicable to the relevant processing, you give that consent. If you do not agree with the terms of this Privacy Policy, you should immediately discontinue the use of the Services. The Services are not directed at, and are not intended for use by, persons under 18 years of age. No Group Company knowingly collects Personal Data from any such person.
This Privacy Policy is a group-level policy. It applies to every Group Company that processes Personal Data in connection with the Services, and covers Personal Data we process about visitors to our website and other users of the Services.
Some Group Companies hold a licence, registration or authorisation (each a “Regulated Group Entity”). A Regulated Group Entity may be subject to additional legal obligations to collect, verify, screen, monitor, report and retain Personal Data. Where a Regulated Group Entity’s client agreement or its own privacy notice conflicts with this Privacy Policy, that agreement or notice prevails in respect of the processing it covers.
1. Changes to Privacy Policy
We may change this Privacy Policy from time to time. In the event we make changes, the latest version of the Privacy Policy will be updated and posted on our website and will take effect when posted, and the “Last Updated” date will be revised accordingly. Your continued use of the Services indicates your consent to the revised Privacy Policy then posted. You are responsible for reviewing this Privacy Policy periodically. If you do not agree to a change, your sole remedy is to discontinue use of the Services.
2. The Group, the Relevant Data Controller and Applicable Law
“DWF Labs” is a trading name and brand used across the Group. It is not itself a legal entity, is not a data controller, and cannot be a respondent to any request or complaint. Each Group Company is a separate legal person.
Each Group Company is a separate data controller and is responsible only for its own processing of Personal Data. Except where expressly stated in this Privacy Policy, Group Companies do not act as joint data controllers, and no Group Company is responsible or liable for the processing carried out by any other Group Company.
Where two or more Group Companies jointly determine the purposes and means of processing — in particular group-wide customer due diligence, sanctions, watchlist and financial crime screening, group risk management, and consolidated regulatory and management reporting — those Group Companies act as joint data controllers in respect of that processing.
Because Group Companies are established in different jurisdictions, different data protection laws apply to different processing. Depending on the Group Company concerned and on your own location, these may include the EU General Data Protection Regulation and the UK GDPR, and the data protection laws of the jurisdictions in which Group Companies are established or operate. A Group Company may issue a supplementary or entity-specific privacy notice, or include data protection provisions in its client agreement or onboarding documentation. Where it does, that notice or agreement prevails over this Privacy Policy in respect of the processing it covers, and this Privacy Policy applies only to the extent it is not inconsistent.
This Privacy Policy does not apply to: (a) any third-party website, application, protocol or service, including those linked from our website; (b) any information you publish or transact on a public blockchain; or (c) any processing carried out by a Group Company under a separate notice or agreement.
3. Information collection
We collect Personal Data that you decide to share with us directly. At times, we may also require you to provide certain information in order to use certain parts of our Services, fulfil your requests, or provide you with certain services, or in order to comply with a legal or regulatory obligation to which the relevant Group Company is subject. We may collect the following information about you when you use the Services:
- Information contained within any messages you send to us (such as feedback and request for information).
- Identity and contact data, including your name, date and place of birth, nationality, residential and correspondence address, email address, telephone number, photograph, specimen signature and copies of identity documents.
- Verification and due diligence data, including identification and verification documents, proof of address, tax identification numbers and tax residence, employment or occupation, corporate constitutional documents, ownership structure and details of directors, shareholders and ultimate beneficial owners, source of funds and source of wealth information and supporting evidence, politically exposed person status, and the results of sanctions, watchlist, adverse media and risk screening.
- Financial and transaction data, including bank account details, virtual asset wallet addresses, on-chain transaction data, transaction history, counterparty information, and instructions you give us.
- Communications data, including the content and metadata of emails, messaging, call recordings, meeting notes and correspondence with any Group Company.
- Professional and relationship data, including your employer, role, regulatory status and any investor or client classification applicable to you.
- Other information that you choose to provide to us.
Our systems may also automatically collect the following information from you when you use our Services:
- Cookies, which is a small text file that can be stored on and accessed from your device when you visit our Services. We will only use strictly necessary cookies in connection with our website and the Services, and, where your consent is required and given, analytics and performance cookies.
- Google analytics information, including user information such as session statistics, approximate geolocation, browser and device information.
We may also obtain Personal Data about you from third parties and other sources, including other Group Companies, identity verification and due diligence providers, sanctions, watchlist and politically exposed person databases, adverse media and open-source intelligence providers, blockchain analytics and transaction monitoring providers, credit reference and fraud prevention agencies, public registers, regulators and law enforcement, your advisers and representatives, and counterparty virtual assets service providers.
Sensitive personal data. We do not seek sensitive personal data. However, screening required by anti-money laundering, counter-terrorist financing and sanctions legislation may generate or reveal information about criminal convictions or alleged offences, which may be sensitive personal data under the regimes that apply to Group Companies. Where the applicable law requires your explicit consent to that processing, by requesting or using the Services, you give it; where the processing is required or permitted by law without consent, we rely on that basis.
Providing certain Personal Data is a statutory or contractual requirement. If you do not provide it, or if the information you provide cannot be verified, the relevant Group Company may be unable to provide the Services and may be required to decline to onboard you or to suspend or terminate an existing relationship, in each case without liability to you.
You must ensure that any Personal Data you provide to us about another person (including a director, officer, beneficial owner, authorised signatory or adviser) is accurate, that you are entitled to provide it, and that you have informed that person of this Privacy Policy and obtained any consent required by the applicable law.
4. How we use information
We may use your Personal Data for the limited purpose of providing the Services and related functionality and services, and for the purposes of complying with the legal and regulatory obligations of the relevant Group Company, as described in this Privacy Policy and as permitted by applicable law. These purposes include circumstances where it is necessary to provide or fulfil the Services requested by or for you or where you have given us your express consent. We may use your Personal Data as follows:
- Operating and managing the Services; performing services requested by you, such as responding to your comments, questions, and requests, and providing information support; sending you technical notices, updates, security alerts, information regarding changes to our policies, and support and administrative messages; and compliance with legal and regulatory requirements.
- To communicate with you by e-mail and other methods of communication to respond to comments, questions, and other requests you send us. To contact you with special offers, promotions, and other information we believe will be of interest to you, where permitted by applicable law and subject at all times to your right to opt out.
- For other purposes such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Services, products, marketing, and your experience;
- Carrying out customer due diligence, enhanced due diligence and identity verification; screening you, your beneficial owners and your counterparties against sanctions, watchlist, politically exposed person and adverse media sources; assigning and reviewing risk ratings; and conducting ongoing monitoring, periodic reviews and transaction monitoring;
- Detecting, investigating, preventing and reporting money laundering, terrorist financing, proliferation financing, sanctions evasion, bribery, fraud, market abuse and other financial crime, including making reports to a competent authority in any jurisdiction in which a Group Company operates;
- Complying with legal, regulatory, licensing, supervisory, tax, reporting, disclosure and record-keeping obligations to which any Group Company is subject, and responding to requests, directions and inspections from regulators, courts and law enforcement;
- Operating the Group’s central compliance, risk and control functions, including group-wide screening and monitoring systems, group risk assessment, internal audit, consolidated management and regulatory reporting, and the administration and governance of the Group;
- Assessing and managing credit, counterparty, operational, legal, sanctions and reputational risk across the Group;
- Establishing, exercising or defending legal claims, enforcing our agreements and terms of use, and protecting the rights, property and interests of any Group Company, our clients and our personnel;
- Handling complaints, conducting audits, internal investigations and regulatory examinations, and evidencing our compliance;
- Recording and monitoring telephone calls and electronic communications for compliance, record-keeping, dispute resolution, quality and training purposes, where permitted by applicable law;
- Protecting the security, integrity and availability of our systems, networks and premises, and preventing and detecting unauthorised access; and
- Evaluating, negotiating and completing business transactions as described in this Privacy Policy.
5. Our legal bases for processing
The legal basis on which your Personal Data is processed depends on the data protection law applicable to the relevant Group Company and to the processing in question. The relevant Group Company processes Personal Data on the bases recognised by the applicable law, which will typically include performance of a contract with you or steps taken at your request, compliance with a legal obligation, your consent, the protection of vital interests, and, where that law recognises such a basis, the legitimate interests of the controller or of a third party.
Where a Group Company processes Personal Data in order to comply with a legal or regulatory obligation, including anti-money laundering, counter-terrorist financing, sanctions, tax reporting and record-keeping obligations, that processing does not depend on your consent. You cannot withdraw consent to it, and any right to object to it, to require its restriction or to require erasure does not apply.
Where we rely on your consent (for example, for optional marketing or for analytics cookies), you may withdraw it at any time by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect processing carried out on another basis.
6. How we share and disclose information
We will only share or disclose information that we collect in accordance with the practices described in this Privacy Policy and as required or permitted by applicable law. We do not otherwise disclose the Personal Data we collect about you, except as described herein or as otherwise disclosed to you at the time the data is collected. We may share your Personal Data with third-party vendors that perform tasks on our behalf and at our instruction. These third-party vendors may use your Personal Data only in connection with the services they perform on our behalf, and they are bound to protect your Personal Data in a manner substantively consistent with our own policies and practices, and with applicable law. We disclose personal information under the following circumstances:
6.1. Compliance with laws and law enforcement; protection and safety
For legal, protection and safety purposes, such as to:
- Comply with laws, including KYC and AML requirements.
- Respond to lawful requests and legal processes.
- Protect the rights and property of DWF Labs group of companies, our agents, customers, and others. This includes enforcing our agreements, policies and terms of use.
- Protect the safety of our employees and agents, our customers or any person.
- Make reports of suspicious activity to a competent authority in any other jurisdiction in which a Group Company operates, and comply with directions, notices, production orders and information requests from financial services regulators, tax authorities, law enforcement, courts and other competent authorities. Applicable law may prohibit the relevant Group Company from telling you that such a report has been or may be made, or from giving you the reason for any related delay, refusal, freeze or termination.
6.2. Affiliates
We may share your personal information with our subsidiaries and corporate entities affiliated for purposes consistent with this Privacy Policy. Personal Data is shared between Group Companies for the purposes of customer due diligence and identity verification, group-wide anti-money laundering, counter-terrorist financing and sanctions risk management, shared compliance, screening and monitoring systems, group risk management and consolidated reporting, internal audit, and administration.
6.3. Business transactions
When we enter into a business transaction, or negotiate a business transaction, involving a corporate divestiture, merger, consolidation, acquisition, reorganization, bankruptcy, sale or other transfer of all or a part of our business or assets.
6.4. Professional Advisors or third party service providers
We may share information with our professional advisors for purposes of audits and compliance with our legal obligations, including our auditors, legal advisers, compliance consultants and, where a Group Company is required to appoint one, its authorised representative or equivalent functionary. We may also share information with third-party service providers for business purposes, including fraud detection and prevention, security threat detection, payment processing, customer support, data analytics, information technology, storage, and transaction monitoring, cloud hosting, communications and cybersecurity providers. Such providers act on documented instructions and are bound by contractual confidentiality and security obligations.
6.5. Event partners
We may share your personal information with co-organizers, co-hosts and co-sponsors of any events, such as conferences, webinars, hackathons, whether in-person or virtual, that we organize, host or sponsor, where you have consented to that sharing or where it is otherwise permitted by applicable law.
Notwithstanding the above, we may share information that does not identify you (including information that has been aggregated or de-identified) except as prohibited by applicable law.
6.6. Counterparty virtual assets service providers and the travel rule
Where required by applicable law, a Group Company must obtain, hold, verify and transmit originator and beneficiary information in relation to virtual asset transfers, and share it with counterparty virtual assets service providers, custodians, exchanges and intermediaries, which may be located in any jurisdiction. That information may include your name, wallet or account identifier, address, identification number or date and place of birth. We cannot control how a recipient subsequently uses or discloses that information. Where required information is missing or cannot be verified, a transfer may be refused.
7. International transfers of Personal Data
The Group operates internationally and Group Companies are established in a number of jurisdictions. Your Personal Data may be transferred to, stored in and accessed from jurisdictions other than the one in which it was collected and other than your own, including by other Group Companies, service providers, counterparty virtual assets service providers, advisers and authorities. Some of those jurisdictions may not provide an equivalent standard of protection to your own. By using the Services and providing your Personal Data, you consent to such transfers where consent is the applicable basis.
Where a Group Company transfers Personal Data of data subjects in the European Economic Area or the United Kingdom out of those territories, it relies on the European Commission’s standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, or another lawful transfer mechanism. Where the data protection law of any other jurisdiction imposes conditions on the export of Personal Data, the relevant Group Company will comply with those conditions.
8. Retention of Personal Data
Each Group Company retains Personal Data only for as long as is necessary for the purpose for which it was collected, and thereafter deletes it or renders it anonymous, except where a longer retention period is required or permitted by law. Personal Data may be retained for longer where required by a regulator or court, where it is the subject of an investigation or report, or where it is needed to establish, exercise or defend legal claims.
A request for erasure will not override a retention obligation imposed by law. Where a Group Company is required to retain Personal Data it may refuse an erasure request in whole or in part and, where law prohibits disclosure, without giving reasons.
9. Security of Personal Data
We take practical steps to protect Personal Data from loss, misuse, modification, and unauthorised or accidental access, disclosure, alteration or destruction, including access controls and role-based permissions, encryption in transit and, where appropriate, at rest, network and endpoint security, logging and monitoring, staff confidentiality obligations and training, due diligence on service providers, and secure disposal. Security standards are set at Group level and implemented by each Group Company.
No method of transmission over the internet and no method of electronic storage is completely secure. While we take the steps described above, we cannot and do not guarantee the absolute security of Personal Data, and any transmission to us is at your own risk. To the maximum extent permitted by applicable law, no Group Company accepts liability for interception, corruption, loss, delay, unauthorised access or disclosure occurring outside its reasonable control. You are responsible for keeping your credentials, devices, private keys and seed phrases secure and for the Personal Data you choose to disclose to us or to any third party.
Where a personal data breach occurs, the relevant Group Company will assess it and notify affected data subjects and the relevant competent authority, to the extent and within the timeframes required by the applicable law.
10. Cookies and similar technologies
Strictly necessary cookies are required for the operation and security of the website and are set without your consent, as permitted by applicable law.
Analytics and performance cookies and similar technologies, including Google Analytics, are not strictly necessary. Where applicable law requires consent to their use, we will set them only if you have given that consent through our cookie banner or preference centre, and you may withdraw that consent at any time through the same mechanism or by contacting us. You may also block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the website from functioning.
11. Marketing communications
We will send you marketing communications only where you have consented or where we are otherwise permitted by applicable law to do so. You may opt out at any time by using the unsubscribe mechanism in the communication or by contacting us, and your opt-out will be applied across the Group. Opting out of marketing does not stop service, transactional, security, compliance or legal communications, which are necessary for the provision of the Services or for compliance with our obligations and which you cannot opt out of while the relationship continues.
12. Personal Data and public blockchains
Wallet addresses and transaction records on a public blockchain may constitute Personal Data. Public blockchains are decentralised, immutable and outside the control of every Group Company. We cannot amend, restrict, block or erase any data recorded on a public blockchain, and rights of rectification, erasure, restriction and objection cannot be exercised against any Group Company in respect of such data. Data you place on a public blockchain is public, permanent and may be analysed by third parties, including to associate a wallet address with your identity.
13. Links to other websites
This website may contain links to other websites. These links are meant for your convenience only. Links to third party websites do not constitute sponsorship or endorsement or approval of these websites. Please be aware that we are not responsible for the content, security or privacy practices of such other websites, and no Group Company accepts liability in respect of any Personal Data you provide to them. We encourage our users to be aware, when they leave our website, to read the privacy statements of each and every website that collects personally identifiable information. This privacy policy applies solely to information collected by this website.
14. Notice for Data Subjects in the European Economic Area and the United Kingdom
Depending on certain factors, amongst them your locality, your Personal Data is protected by certain laws and regulations. For instance, if you are a data subject in the European Economic Area, you have certain rights with respect to your personal data pursuant to the General Data Protection Regulation of the European Union (“GDPR”), and if you are a data subject in the United Kingdom, pursuant to the UK GDPR and the Data Protection Act 2018. This clause applies only to the extent that the GDPR or the UK GDPR applies to the processing of your Personal Data by the relevant Group Company, and is in addition to other clauses of the Privacy Policy.
We process your personal data in reliance on the legal bases below. Where the purpose of processing is: (i) To provide and improve our service, we process your personal data as necessary to perform the contract under which we provide our Services or to take steps that you request prior to signing up for the Services; (ii) To comply with the law, we process your personal data as necessary to comply with applicable laws and our legal obligations; (iii) For compliance, fraud prevention and safety, we have a legitimate interest in processing your personal data, as described in this Privacy Policy, and our reasons for doing so outweigh any prejudice to your data protection rights. We also process your personal data as necessary to comply with our legal obligations; (iv) To send marketing communications; for targeted advertising; or for research and analytics, we have a legitimate interest in processing your personal data, as described in this Privacy Policy, and our reasons for doing so outweigh any prejudice to your data protection rights; and (V) With your consent, we process your personal data in reliance on your consent. You may withdraw it any time in the manner indicated when you provided consent or in the Services. The legal bases in this clause apply only under the GDPR and the UK GDPR. Clause 5 sets out the bases on which Group Companies may rely under other applicable laws.
14.1. Your rights
The rights available to you depend on the data protection law applicable to the processing and on which Group Company is your data controller. You may: (i) ask whether we have any personal data about you and request a copy of such personal data; (ii) request that we update or correct inaccuracies in your personal data; (iii) request that we delete your personal data; (iv) request a portable copy of your personal data; (v) request that we restrict the processing of your personal data if such processing is inappropriate; and (vi) object to our processing of your personal data, for direct marketing or otherwise; (vii) withdraw any consent you have given, without affecting the lawfulness of processing before withdrawal; and (viii) lodge a complaint with your supervisory authority or, in the United Kingdom, the Information Commissioner’s Office.
These rights are subject to applicable law, and to the exemptions and restrictions described in this Privacy Policy and under any other applicable law (including, without limitation, where processing is for the prevention or detection of crime, the apprehension or prosecution of offenders, anti-money laundering and counter-terrorist financing purposes, regulatory functions, tax purposes, legal proceedings, or is subject to legal professional privilege). Where an exemption applies we may decline a request in whole or in part.
If you would like to exercise any of these rights, please contact us via our website through the “Contact” form and specify which right you are seeking to exercise. We may require specific information from you to help us confirm your identity and process your request. Please note that we retain information as necessary to fulfill the purpose for which it was collected and may continue to retain and use information even after a data subject request in accordance with our legitimate interests, including as necessary to comply with our legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
15. Contact Us
If you have any questions, comments or complaints about this Privacy Policy or the use of your Personal Data, please contact us via our website through the “Contact” form.