D0.fi

Legal

Privacy Policy

Last updated 24 August 2026

This policy explains how we handle personal data in connection with d0fi.com and the D0 platform (together, the “Services”).

1. Who we are

D0 (“D0”, “we”, “us”) is operated by D0 Labs Inc., a technology company. We license software that businesses use to build payment experiences for their own users.

We do not receive, hold or transmit funds, and we do not provide regulated financial services. Payments, conversions and custody are performed by banks, payment institutions, acquirers, virtual asset service providers and other regulated entities (each a “Licensed Party”) under their own authorisations and their own terms. This shapes what data reaches us: much of the sensitive material in a payment — identity documents, bank credentials, card details — goes to a Licensed Party, not to us.

Contact: compliance@d0fi.com

2. Our role

Our role depends on whose data it is.

  • For business customers, prospects, website visitors and applicants, we are the controller — we decide why and how the data is used, and this policy governs.
  • For end users of a business customer’s product, we act as a processor on that business’s instructions. The business is the controller, its own privacy policy governs, and you should direct your requests to it. We will pass on any request that reaches us.
  • Where we keep records to meet a legal obligation of our own, we are the controller for those records.

Licensed Parties are separate controllers. Where a Licensed Party verifies an end user’s identity, screens a transaction or keeps a payment record, it does so for its own regulatory purposes and under its own privacy policy. We do not control that, and this policy does not cover it.

3. What we collect

  • Business and contact data — name, work email, company, role, and what you send us through forms or email.
  • Account and integration data — account identifiers, API credentials, configuration, and logs of activity on the platform.
  • Transaction metadata — amounts, currencies, timestamps, payment method, reference identifiers, blockchain addresses and transaction hashes, and status. We receive this so that a business can reconcile and support its own payments.
  • Verification status — where an identity check is required for a service, a Licensed Party or verification vendor carries it out and may return a result or status to us. Identity documents are provided to that party, not to us.
  • Technical data — IP address, device and browser information, and pages viewed.

We do not collect card numbers, bank credentials or private keys. We do not ask for, and ask that you do not send us, special category data such as health, biometric or political data.

4. Why we use it, and on what basis

PurposeBasis
Providing, operating and supporting the ServicesPerformance of a contract
Fraud prevention, platform security and service improvementLegitimate interests
Keeping records we are required to keep, and responding to lawful requestsLegal obligation
Marketing and product communicationsConsent, or legitimate interests in a business context. You can opt out at any time.

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights.

Decisions to delay, decline or report a payment are made by Licensed Parties under their own obligations, not by us. If such a decision affects you, the Licensed Party is the party that can review it, and we will tell you who to contact.

5. Who we share it with

  • Licensed Parties engaged for your market, who deliver the regulated leg of a transaction under their own authorisations and as separate controllers.
  • Verification, screening and fraud vendors.
  • Infrastructure and software providers — hosting, logging, analytics, communications and customer support — acting on our instructions.
  • Regulators, law enforcement and courts, where legally required.
  • Professional advisers, and a counterparty to a financing, merger or acquisition.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

6. Blockchains

Where a transaction is submitted to a public blockchain in connection with the Services, it is recorded on that blockchain permanently. It cannot be edited, deleted, reversed or recalled — by us or by anyone — and a deletion request cannot extend to data already written on-chain. Blockchain addresses and transaction histories are public by design and may be linked to an identity by third parties.

For non-custodial products, including embedded wallets and wallet-connect flows, we do not hold private keys and cannot access, move or recover assets.

7. International transfers

We and the parties we work with operate across multiple countries, so your data may be transferred outside the country where it was collected. Where the law requires a safeguard for such a transfer, we put one in place.

8. How long we keep it

We keep personal data for as long as we need it for the purpose it was collected, and then for the period our legal obligations require. Business contact data is kept until you ask us to remove it.

Anti-money-laundering record-keeping in the markets we serve — generally at least five years — applies to the Licensed Parties who perform the regulated activity. Where a retention obligation applies to us, we meet it.

9. Security

We take reasonable technical and organisational measures to protect personal data against loss, misuse and unauthorised access. No system is completely secure. If a breach affects your data and the law requires notice, we will notify you and the relevant regulator within the required period.

10. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict processing, withdraw consent, and complain to your data protection authority.

To exercise a right, email compliance@d0fi.com. We will respond within the period the applicable law requires. We may need to verify your identity first, and some rights are limited where records must be retained by law or where data sits on a public blockchain (see section 6).

If you are an end user of a business that uses D0, please contact that business first — it is the controller of your data. If your request concerns a payment or an identity check, the Licensed Party that performed it holds that record, and we will tell you who to contact.

11. Cookies

We use cookies that are necessary for the site to work, and may use analytics cookies to understand how it is used. You can control cookies through your browser settings.

12. Children

The Services are for businesses and for people aged 18 or over. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

13. Changes

We may update this policy. The “last updated” date above shows when. If a change is material, we will give notice through the Services or by email.

14. Contact

D0 Labs Inc.
Email: compliance@d0fi.com
Registered office details are available on request.