Privacy Policy
VAULTFY AI TRADING CO LTD (hereinafter referred to as "Vaultfy AI Trading," "We," "Us," or "Our"), trading as VAULTFY.AI LIMITED (Company No. 17156633), with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, is unequivocally committed to protecting the privacy and security of your personal data with an institutional-grade framework. This Privacy Policy (the "Policy") outlines how We rigorously collect, utilize, disclose, and safeguard your information when you access and use Our FinTech infrastructure platform and ultra-luxury concierge orchestration service (the "Service").
We operate in strict compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable international data protection laws, adopting a "privacy-by-design" and "privacy-by-default" approach.
1. Our Commitment to Data Minimization and Zero-Knowledge Principles
At VAULTFY.AI, We adhere to a philosophy of aggressive data minimization. We collect and retain only the absolute minimum personal data necessary to provide Our Service, fulfill Our contractual obligations, and comply with stringent legal and regulatory requirements. We strive to implement zero-knowledge principles wherever technically feasible, ensuring that sensitive information is processed without Us ever having direct access to its content.
2. Information We Rigorously Collect
We collect personal data that is strictly essential for the provision and enhancement of Our Service, account management, and robust legal compliance. This includes:
2.1. Core Identity and Contact Data (Strictly for KYC/AML)
- Identity Data: Full legal name, title, date of birth, gender, nationality, government-issued identification details (e.g., passport, national ID).
- Contact Data: Primary billing address, designated delivery address, verified email address, primary telephone numbers.
2.2. Financial Data (Processed via Secure Third Parties)
- Bank Account Details: Encrypted and tokenized via regulated payment processors.
- Payment Card Details: Encrypted and tokenized via PCI-DSS compliant payment gateways.
- Transaction History: Records of payments made through the Service.
- Source of Funds Documentation: Collected and verified by regulated third-party KYC/AML providers.
2.3. Mandatory KYC/AML and Sanctions Screening Data
Information collected for Know Your Customer (KYC), Anti-Money Laundering (AML), and Counter-Terrorist Financing (CTF) compliance, including, where legally required, biometric data (e.g., facial scans for identity verification) processed by certified third-party providers. VAULTFY.AI does not retain raw biometric data.
2.4. Orchestration and Preference Data (Anonymized Where Possible)
- Travel Preferences: Preferred airlines, aircraft types, hotels, destinations, dietary requirements, special requests, travel history (anonymized for analytics).
- Lifestyle Preferences: Interests, hobbies, event preferences, luxury asset specifications (e.g., yacht length, car model).
- Communication Data: Encrypted records of your interactions with ALFRED AI (voice, text, chat) and Our human concierge team, strictly for service fulfillment and quality assurance.
2.5. Technical and Usage Data (Aggregated and Pseudonymized)
Internet protocol (IP) address, login data, browser type and version, time zone setting, location data (generalized), device information, and usage patterns within the Service. This data is primarily collected in an aggregated and pseudonymized form for system optimization and security analytics.
3. Methodologies for Information Collection
We collect information through secure and auditable channels:
- Direct Interactions: Data provided by You during account registration, KYC/AML onboarding (via secure third-party portals), Service usage, and direct communications with Our team.
- Automated Technologies: Technical and Usage Data is automatically collected through encrypted cookies, server logs, and other secure tracking technologies. This data is primarily used for security, performance, and aggregated analytics.
- Secure Third-Party Integrations: We receive strictly necessary personal data from regulated third-party identity verification providers, payment processors, and third-party suppliers (e.g., private jet operators, hotels) to fulfill Service requests and comply with legal obligations. We do not receive or retain data beyond what is essential.
4. Purpose-Limited Use of Your Information
We use your personal data strictly for the following purpose-limited activities, based on the highest applicable legal bases:
4.1. To Provide and Manage the Service (Contractual Necessity)
- Processing your invitation-only registration and managing your highly secure account.
- Orchestrating and facilitating bookings for private aviation, luxury accommodation, and other bespoke services.
- Processing card payments through regulated third-party financial partners.
- Securely communicating with you regarding your bookings and critical Service updates.
4.2. For Mandatory KYC/AML and Regulatory Compliance (Legal Obligation)
- Performing rigorous identity verification, fraud prevention, and sanctions screening through certified third-party providers.
- Strictly complying with all applicable anti-money laundering, counter-terrorist financing, and financial services regulations.
- Responding to legitimate and lawful requests from competent public authorities.
4.3. To Enhance Our Service (Legitimate Interests - with Privacy Safeguards)
- Analyzing aggregated and pseudonymized usage patterns to continuously enhance ALFRED AI and personalize your Service experience.
- Developing and deploying new, secure features and services.
- Conducting internal research and analytics to understand UHNW market trends, always with privacy as a paramount consideration.
4.4. For Essential Communications (Legitimate Interests)
Sending you critical Service-related updates, security alerts, and essential information (non-marketing).
5. Highly Restricted Disclosure of Your Information
We disclose your personal data only when strictly necessary and under robust contractual safeguards, to the following categories of recipients:
- Third-Party Suppliers: Only the minimum necessary data is shared to facilitate your specific bookings (e.g., name for private jet manifest, dietary requirements for hotel).
- Regulated Payment Processors: To securely process card transactions. We do not directly handle or store your full payment credentials.
- Certified Identity Verification Providers: For mandatory KYC/AML compliance. These providers are contractually bound to strict data protection standards.
- Institutional Partners: If you access Our Service through a white-label solution provided by your private bank or family office, We may share strictly relevant, anonymized, or pseudonymized data with them, subject to explicit contractual agreements.
- Legal and Regulatory Authorities: When legally compelled to do so by a court order or binding regulatory request.
- Professional Advisors: Lawyers, accountants, auditors, and insurers, under strict confidentiality obligations.
We mandate that all third parties respect the security and confidentiality of your personal data and treat it in accordance with the highest legal and ethical standards. We strictly prohibit Our third-party service providers from using your personal data for their own purposes and only permit them to process your personal data for specified, purpose-limited activities and in accordance with Our explicit instructions.
6. Secure International Data Transfers
As a global service catering to an international clientele, your data may be transferred to, and stored at, a destination outside the UK and European Economic Area (EEA). Where this occurs, We implement beyond industry-standard safeguards, such as:
- Transferring personal data only to countries that have been deemed to provide an adequate level of protection for personal data by the UK government or European Commission.
- Utilizing specific, enhanced contractual clauses (e.g., UK International Data Transfer Agreement, EU Standard Contractual Clauses) approved by the UK government or European Commission, which impose the same rigorous protection as in the UK/EEA.
- Implementing additional technical and organizational measures (e.g., end-to-end encryption, pseudonymization) to ensure data remains protected during transit and at rest in third countries.
7. Institutional-Grade Data Security
We have implemented and continuously maintain institutional-grade security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. These include, but are not limited to:
- End-to-End Encryption: All sensitive data is encrypted at rest (using AES-256 or stronger) and in transit (using TLS 1.3 or stronger) across all systems and communications.
- Multi-Factor Authentication (MFA): Mandatory MFA for all internal systems, administrative access, and client access to sensitive features.
- Principle of Least Privilege: Access to information systems and data is strictly granted on a "need-to-know" and "least privilege" basis, with regular access reviews.
- Network Segmentation: Robust network segmentation and micro-segmentation to isolate critical systems and data, limiting the blast radius of any potential security incident.
- Regular Security Audits: Continuous security monitoring, regular vulnerability scans, penetration testing, and red team exercises conducted by independent, certified third parties.
- Secure Development Lifecycle (SDLC): Security is embedded into every phase of Our software development lifecycle, from design to deployment, with mandatory code reviews and security testing.
- AI Security Governance: Specific controls for ALFRED AI, including prompt injection protection, model integrity checks, and secure data handling within AI processes.
8. Data Retention: Purpose-Limited and Compliant
We will only retain your personal data for as long as strictly necessary to fulfill the purposes for which We collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, We rigorously consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which We process your personal data, and the applicable legal and regulatory requirements. Data is securely deleted or anonymized once its retention period expires.
9. Your Enhanced Legal Rights
Under applicable data protection laws, you possess enhanced rights in relation to your personal data. These include, but are not limited to, the right to:
- Request access to your personal data.
- Request correction of inaccurate personal data.
- Request erasure of your personal data (the "right to be forgotten").
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data to another party.
- Withdraw consent at any time where We are relying on consent to process your personal data.
If you wish to exercise any of these rights, please contact Our Data Protection Officer using the details below. We will respond to all legitimate requests within one calendar month.
10. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in Our practices, technology, or legal requirements. The latest version will always be prominently posted on Our website with a clear effective date. We encourage you to review this Policy periodically to remain informed about how We are rigorously protecting your information.
11. Contact Information and Data Protection Officer
For any questions regarding this Privacy Policy, your data protection rights, or to report a privacy concern, please contact Our dedicated Data Protection Officer at:
VAULTFY AI TRADING CO LTD
Trading as VAULTFY.AI LIMITED
71-75 Shelton Street, Covent Garden
London, United Kingdom, WC2H 9JQ
Company No.: 17156633
Email: admin@vaultfy.ai