The Policy will refer as 'Personal Information to any information related to you as an identified natural person; the 'User' or 'Data Subject' is the person enjoying the service; 'processing' means any step or set of operations performed on your personal information, whether or not by automated means.
This policy will contain the following Chapters:
To use our services, we must collect certain personal information about you to provide our products and services, including our applications and website, allowing you to make purchases, sales, deposits, and withdrawals; they are also transferred between USD and Crypto wallets legally and appropriately and, more importantly, to comply with law enforcement and regulators, especially in regards to anti-money laundering. This chapter will describe the personal information we collect from you and why we do so. For this proposal, we divide the way we collect personal information into two categories:
The data we collect and the data you provide are processed for multiple purposes. The first and most important: is to provide you with our Service: It may sound obvious, but we need your data to provide you with our services. Without your name, bank information, and other details, we simply could not offer our products to you.
As a financial institution, it is critical that we can confirm the true identity of our Clients. We use automated processes to verify the Know-Your-Client (KYC) and Anti-Money Laundering (AML) data you provide to us to assess whether you are located in a prohibited country and, therefore, whether or not we are legally authorized. You can use our services. However, those automated processes support a decision-making process that is, in all cases, performed by humans, who will review any alert issues that arise from the automated processes.
Third-Party Data: If you authorize third-party applications or integrations using our Service, these parties may receive detailed information about your personal information, your profile information, and uploaded documents, some of which may record your visit to our website. Information collected by these third-party applications or integrations is subject to their terms and policies. We also process your personal information to provide customer services, including to fulfill our contractual obligations to you and, based on our legitimate interests, or your legitimate interests, to provide the best customer service we can.
From time to time, we are required to monitor your account activity to verify and protect against fraudulent, unauthorized, or suspicious behavior. For customer support, we strive to ensure that you can use our products efficiently and without headaches, but if you need help. With your consent, our customer support team will occasionally need to access your account details by posing as the service, to solve any problem or answer your questions.
The Internet is known to be an insecure environment and there is no security, but we work very hard to protect Mercury Cash users and information. To that end, we have put security measures in place to prevent your personal information from being accidentally lost, used, altered, or disclosed due to a breach or unauthorized access to any information we store (the 'Unfortunate Events). However, should any of the unfortunate or similar events occur, you agree to release Mercury Cash, its affiliates and service providers, and each of their respective officers, directors, agents, joint ventures, employees, and representatives from any claims, demands, and damages (actual and consequential) of every kind and nature arising out of or in any way related to said activities. These are some risks we encountered; who typically have access to customer information.
Based on our Internal Privacy Policy, access to customer information through the institution's computerized information system is limited to those members with a business reason for knowing such information. Each employee is assigned a login code and password. All Mercury Cash team members must use a Password Generator for all their corporate email addresses, social media platforms, management platforms, and more.
Our members must also share passwords using Keeper, so sensitive information is not saved on any messaging platform. References of new employees are checked. During orientation, each new employee will receive appropriate training on the institution's privacy and client information security policies and the importance of confidentiality. We keep records of each client's personal information and transactions by offline storage. We have a safe deposit box for physical information, and paper documents containing the client's personally identifiable information are shredded after a minimum of 5 years exposed in our Recordkeeping Procedures. Since we have a 'closed system' with our data processor, these procedures minimize risk by limiting physical accessibility to secure customer information, on hacking and Cybersecurity.
As an institution that offers internet services, we have specific virus threats and hacker attacks, which is why we have implemented a Cybersecurity Program and Business Continuity Program.
The measures we take include antivirus software, DDoS firewalling with the help of other artificial intelligence software, and encryption of Mercury Cash website communications with TLS 1.2; This protects us from CSRF attacks, SQL Injection, and any brute force attacks that they want to do to us. Two-factor authentication is also required for all sessions; We have a technological security team working 24/7 to build a safe place, limiting technological risk.
Information requirements
Under Florida's data breach notification law, any entity that acquires, maintains, stores, or uses personal information is required to notify individuals in the state of unauthorized access to personal information in electronic form. Notification to individuals should be done as soon as possible and without undue delay, no later than 30 days after the determination of a security breach. Entities may receive an additional 15 days of good cause if provided to the Legal Department in writing within the original 30-day period. Entities must also notify the Law Department if the breach affects more than 500 people in Florida. If there are more than 1,000 affected individuals, the offending entities must also report to all consumer reporting agencies that compile and maintain nationwide consumer files, as defined in 15 USC Section 1681a(p), without undue delay.
Notification is not required if a proper investigation and consultation with the relevant government agencies determines that the breach has not resulted and is not likely to result in identity theft or any other financial harm to affected individuals. Such determination must be documented in writing and maintained for at least five years. Entities must provide this determination in writing to the Legal Department within 30 days of the determination. Substitute notice is permitted in specific circumstances, and notice may be delayed for law enforcement reasons. Breached third parties must notify relevant data owners or licensees within ten days of discovery of a breach. After receiving notification from a third party, the subject data entity must provide reports to the Department and the Affected Persons.
As a subject, you have the following rights that you can exercise by contacting our Data Protection Officer at [email protected]
Mercury Cash's Privacy Policy, and Internal Privacy Policy is reviewed annually with all employees. Another training is provided to protect against customer information's destruction, loss, or damage due to potential environmental hazards, such as fire and water damage or technological failure. All this training will help minimize risk and safeguard the security of customer information.
fter reviewing, we may make changes to this Privacy Policy. If we make changes, we will notify you by email. If we make material changes, we will do so by applicable legal requirements and notify you before such changes take effect. Please contact us as specified below to keep your personal information accurate, current, and complete. We will take reasonable steps to update or correct the Personal Information in our possession that you previously submitted using our services. Please contact us if you have questions about our Privacy Policy or Mercury Cash's information practices.