Privacy Policy
Last Updated: October 22, 2025
This document is prepared in English and shall be interpreted in English. Translations may be provided for convenience only. In the event of any inconsistency, conflict, or ambiguity between any translation and the English version, the English version shall prevail. Translations do not amend, supplement, or replace the English version. To the maximum extent permitted by law, the English version is the binding and controlling text.
This Privacy Policy describes how Zwinner Technology Limited ("DCAUT", "we", "us", or "our") collects, uses, processes, and discloses your personal data when you access and use our website, desktop/mobile applications, and API (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy.
We protect your data under unified global privacy and security standards and will fulfill additional obligations required by the laws applicable to your location.
TL;DR
Note: This summary is for convenience only and is not contractual. In case of inconsistency with the body text, the body prevails.
- We do not store your exchange passwords, and we do not hold your funds; your funds always remain in your own exchange accounts.
- Where necessary to provide core features (read-only queries and trade execution), we process the API keys and related data you provide and apply measures like encryption and least-privilege access.
- We do not sell your personal data. Any advertising or analytics, if used, will be conducted as permitted by law and include opt-out or preference controls where applicable.
- You can disconnect exchange connections at any time and manage account settings.
- If a security incident occurs, we notify and/or report within legally required timeframes, and provide concrete self-help guidance and support channels.
1. Data We Collect
We collect various types of information to provide and improve our Service to you:
1.1. Personal Data
- Main Data: Name, email address, user ID, contact information.
- Billing Data: Payment method details (e.g., credit card information, processed by third-party payment processors), billing address, subscription details.
- Transaction Data: API keys for connecting to cryptocurrency exchanges, exchange account data (e.g., balances, trading history, order information). DCAUT does not store your exchange account passwords. Important: DCAUT does NOT store, hold, or have access to your cryptocurrency funds or fiat currency. We only store encrypted API keys for read-only access and trade execution. Your funds remain in your exchange accounts at all times.
- Communication Data: Records of your communications with us (e.g., support tickets, emails, chat logs).
- Marketing Data: Your preferences in receiving marketing from us and our third parties, and your communication preferences.
1.2. Technical and Usage Data
- Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Service.
- Usage Data: Information about how you use our Service, such as features accessed, pages viewed, time spent on the Service, and interaction patterns.
- Cookie Data: We use cookies and similar tracking technologies to track activity on our Service and retain certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. Where applicable, we provide preference choices or opt-out paths (for example, in-page controls or browser settings).
2. How We Use Your Data
We process your data based on performance of a contract, compliance with legal obligations, your consent, and—where permitted by applicable law—our legitimate interests. We only process your data to the extent necessary to achieve specific, explicit, and reasonable purposes, and we avoid processing that is excessive or incompatible with those purposes. We determine specific legal bases and your exercisable rights in accordance with the laws applicable to your region (e.g., GDPR/UK GDPR, CPRA, PIPL, LGPD). We will not use your data for new purposes that are incompatible with this Policy; if we need to change processing purposes, we will inform you again and, where required by law, obtain your consent.
- To Provide and Maintain the Service: Including managing your account, processing transactions, and enabling trading functionalities.
- To Improve Our Service: Analyzing usage patterns, troubleshooting, and developing new features.
- To Manage Your Subscription: Processing payments, managing billing, and providing customer support.
- To Communicate With You: Sending service-related announcements, updates, security alerts, and marketing communications (where you have consented).
- For Security Purposes: Detecting, preventing, and addressing technical issues, fraud, or unauthorized access.
- To Comply with Legal Obligations: Fulfilling legal, regulatory, and compliance requirements.
For elements that may be considered sensitive in certain jurisdictions (for example, exchange API keys, exchange account balances, trading history, and order information), we process such data to provide the related core features based on performance of the contract with you and other applicable legal bases. Where local law imposes additional requirements for such data, we will fulfill those obligations (for example, providing clear notices and implementing necessary security measures). If you do not provide this information, the corresponding core features cannot be used, but this does not affect your ability to use unrelated parts of the Service.
3. How We Share Your Data
We may share your personal data with the following categories of recipients:
- Service Providers: Third-party companies and individuals who facilitate our Service (e.g., payment processors, cloud hosting providers, analytics providers, customer support platforms).
- Affiliates: With our parent company, subsidiaries, and affiliates.
- Legal and Regulatory Authorities: When required by law, subpoena, or other legal process, or if we believe in good faith that such action is necessary to comply with a legal obligation, protect our rights or property, or ensure the safety of our users or the public.
- Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets.
We do not sell your personal data to third parties.
3.1 Cross-Border Processing and Storage
To provide a global Service, your information may be processed and stored outside your country/region. We will implement appropriate safeguards as required by applicable law (e.g., standard contractual clauses, impact assessments, certifications, or other legally recognized mechanisms) and ensure recipients are subject to appropriate confidentiality and security obligations.
4. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include encryption, firewalls, secure server hosting, and access controls. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
You are responsible for keeping your API keys and account credentials confidential. We strongly recommend the use of IP whitelisting for API keys to enhance your account security. DCAUT cannot enforce exchange-side IP allowlists; configuration and maintenance remain your responsibility. You should not disable this critical security feature when available from your exchange.
4.1 Data Breach Notification
In the event of a personal data breach that may pose risks to your rights and freedoms:
- We will notify affected users within legally required timeframes after becoming aware of the breach, and, where applicable, report to relevant supervisory/data protection authorities.
- The notification will include:
- The nature and scope of the breach
- The types of personal data affected
- Likely consequences and risks
- Measures taken or proposed to address the breach
- We will cooperate with regulatory authorities and take all reasonable steps to mitigate harm.
- Recommended user actions: promptly rotate or revoke related API keys, review accounts and trading activity for anomalies, and contact us via “Contact Us” for support and guidance.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period varies depending on the type of data and the purpose of processing.
For example, billing and invoicing information is retained as required by tax and finance laws. Logs generated for security and audit purposes are deleted or anonymized after the minimum necessary period (unless otherwise required by law or regulation).
6. Your Data Protection Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data under certain conditions.
- Right to Restrict Processing: Request that we restrict the processing of your personal data under certain conditions.
- Right to Object to Processing: Object to our processing of your personal data under certain conditions.
- Right to Data Portability: Request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
We will respond within timelines required by applicable laws (for example, typically 1 month under GDPR/UK GDPR, and typically 45 days under CPRA; extensions may apply with reasons provided). We may need to complete reasonable identity verification before processing your request. Certain requests may not be fully satisfied where restricted by the rights of others, law enforcement, or other legal requirements. In general, we aim to process faster where possible and keep you informed of progress when needed.
To exercise any of these rights, please contact us at [email protected].
6.1 Minors
Our Service is primarily intended for adults. Minors should use the Service only with the consent and guidance of their guardians. We do not knowingly collect children’s personal data, and we implement protections according to the laws applicable in your region (for example, age thresholds for children/minors vary by jurisdiction). If you believe we have collected a minor’s information without necessary consent, please contact us via the “Contact Us” section so that we can delete it or take other necessary measures.
7. AI Technologies
DCAUT may integrate AI technologies for specific purposes, including but not limited to:
- Customer support chatbots for answering common questions
- Strategy recommendation algorithms (if implemented in future)
Regarding AI processing:
- Your input data (e.g., chat messages, strategy parameters) may be processed by AI systems to provide responses or suggestions.
- We do NOT use your trading data, personal information, or API keys to train AI models.
- We do NOT share your data with third-party AI providers for model training.
- Any AI-powered decision-making will be clearly disclosed, and human review will be available for significant actions.
- You may opt out of AI-powered features in your account settings.
We do not engage in decision-making based solely on automated processing that produces legal or similarly significant effects concerning you. If such processing becomes necessary, we will comply with applicable laws and provide corresponding rights to information, explanations, and appeal.
8. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We will also notify you via email and/or a prominent notice on our Service, prior to the change becoming effective.
9. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- By email: [email protected]
- Company: Zwinner Technology Limited