Privacy Policy

Last Updated June 23, 2026

1. General Provisions

This Privacy Policy defines the procedure, conditions, and purposes for the collection, use, storage, disclosure, transfer, and protection of personal data of users, clients, representatives of corporate clients, counterparties, partners, and visitors to the website Heleket.com.

In this Policy, the terms «Heleket», «Company», «we», «us» or «our» refer to HELEKET PLATFORM, which processes personal data in connection with the provision of its products, services, platform solutions, and other related services.

We recognise the confidentiality and protection of personal data as a fundamental obligation of the Company. In this regard, Heleket applies legal, technical, and organisational measures aimed at ensuring the lawfulness, fairness, transparency, security, integrity, and confidentiality of personal data processing.

This Policy applies to all individuals who use our Website, register an account, interact with our services, contact our support team, undergo identity verification procedures, represent corporate clients, or otherwise provide us with personal data.

2. Contact Information

For all matters relating to the processing of personal data, the exercise of your rights, data security, or this Policy, you may contact us by Email: support@heleket.com

3. Key Definitions

For the purposes of this Policy, the following terms apply:

Personal Data — any information that directly or indirectly relates to an identified or identifiable natural person.

Processing — any operation performed on personal data, including collection, recording, organisation, storage, modification, use, transfer, disclosure, restriction, deletion, or destruction.

Data Subject — a natural person to whom the personal data relates.

Sensitive Personal Data — special categories of data, including, where applicable, biometric data, identity document data, information disclosing highly protected personal details, and other data requiring a special protection regime in accordance with applicable law.

KYC/AML/CTF — procedures for client identification, due diligence checks, anti-money laundering, counter-terrorism financing, sanctions evasion prevention, fraud prevention, and other unlawful activities.

4. Principles of Personal Data Processing

Heleket processes personal data in accordance with the following principles:

  • Lawfulness, fairness, and transparency — data is processed only on the basis of a proper legal ground and in a manner that is clear to the user.
  • Purpose limitation — data is collected for specific, legitimate, and pre-defined purposes and is not used in an incompatible manner.
  • Data minimisation — we only request and process data that is necessary to achieve the relevant purposes.
  • Accuracy and relevance — we take reasonable steps to keep personal data accurate and up to date.
  • Storage limitation — data is retained no longer than necessary for the purposes of processing, compliance with the law, protection of rights, and resolution of disputes.
  • Integrity and confidentiality — data is protected against unauthorised access, loss, alteration, disclosure, or destruction.

5. What Personal Data We May Collect

Depending on the nature of your interaction with Heleket, we may collect and process the following categories of personal data:

5.1. Identification Data

  • first name, last name, and other identifiers;
  • date of birth;
  • nationality;
  • identity document data;
  • photograph, facial image, or other data used for identity verification;
  • information required for identity establishment under KYC/AML/CTF procedures.

5.2. Contact Data

  • email address;
  • phone number;
  • residential or registration address;
  • mailing address;
  • other contact details provided by you.

5.3. Financial and Transaction Data

  • payment details;
  • transaction-related data;
  • information on the source of funds, where required;
  • information necessary for financial activity verification;
  • data required for compliance with AML/CTF, sanctions, tax, or other legal obligations.

5.4. Corporate Client and Representative Data

If you act on behalf of a legal entity, we may process:

  • information about your position and authority;
  • corporate email address;
  • documents confirming the right of representation;
  • information about beneficial owners, directors, authorised persons, and other related individuals;
  • information required for corporate client verification.

5.5. Technical and Behavioural Data

When using the Website and services, we may automatically collect:

  • IP address;
  • browser information;
  • device type;
  • operating system;
  • language settings;
  • data on visits, actions, and events on the Website;
  • device identifiers;
  • device fingerprint;
  • security log data;
  • information about login attempts, sessions, and account activity.

5.6. Data from External and Public Sources

We may receive information:

  • from sanctions lists;
  • from politically exposed persons lists;
  • from anti-fraud databases;
  • from KYC, AML, KYB, and transaction monitoring providers;
  • from public registries;
  • from law enforcement, judicial, regulatory, or governmental authorities;
  • from contractors, partners, and identity verification providers.

5.7. Sensitive Data

In limited cases, we may process sensitive personal data, including biometric data contained in documents or used for identity verification.

Such processing is carried out only where an applicable legal basis exists, including your explicit consent, the necessity of complying with legal obligations, fraud prevention, AML/CTF checks, or other grounds provided for under applicable law.

6. Sources of Personal Data

We may receive personal data:

  • directly from you during registration, verification, use of services, or when contacting support;
  • automatically when you use the Website, account, API, technical interfaces, or other Heleket services;
  • from a corporate client, if you are its representative, employee, director, beneficial owner, or authorised person;
  • from identity verification, anti-fraud, AML/CTF, sanctions screening, and transaction monitoring service providers;
  • from publicly available sources, public registries, sanctions lists, and other lawful sources;
  • from financial institutions, payment providers, partners, contractors, or competent authorities, where necessary for the provision of services or compliance with the law.

7. Purposes of Personal Data Processing

Heleket may process personal data for the following purposes:

7.1. Provision of Services

  • account creation and administration;
  • providing access to products and services;
  • processing requests and operations;
  • user support;
  • management of contractual relationships;
  • ensuring platform operation.

7.2. Identification and Verification

  • conducting KYC, KYB, AML, and CTF procedures;
  • identity verification;
  • verification of the authority of corporate client representatives;
  • determination of beneficial owners;
  • sanctions screening;
  • identification of politically exposed persons;
  • verification of the source of funds, where required.

7.3. Security and Abuse Prevention

  • protection of user accounts and assets;
  • prevention of unauthorised access;
  • detection of fraud, abuse, and suspicious activity;
  • transaction monitoring;
  • ensuring cybersecurity;
  • investigation of security incidents;
  • protection of the rights, property, and legitimate interests of Heleket, users, and third parties.

7.4. Legal Compliance

  • fulfilment of AML/CTF requirements;
  • compliance with sanctions legislation;
  • fulfilment of tax, accounting, and reporting obligations;
  • execution of court orders and requests from regulators, law enforcement, and governmental authorities;
  • retention of records for legally established periods;
  • protection of rights in judicial, administrative, or other proceedings.

7.5. Communications

  • sending service notifications;
  • responding to enquiries;
  • informing about changes to services, terms, policies, and security;
  • sending administrative, technical, and legal communications.

7.6. Marketing and Product Development

  • sending news, updates, and product information;
  • improving user experience;
  • analysing the use of the Website and services;
  • development, testing, and optimisation of products;
  • conducting analytics and research.

You may opt out of marketing communications at any time, where such opt-out is provided for under applicable law and does not affect mandatory service or legal notifications.

8. Legal Bases for Processing

Depending on the circumstances, Heleket processes personal data on one or more of the following bases:

  • Performance of a contract — where processing is necessary for the provision of services to you, account management, or the fulfilment of our obligations.
  • Legal obligation — where processing is required to comply with applicable law, including AML/CTF, sanctions, tax, accounting, regulatory, and other obligations.
  • Legitimate interests — where processing is necessary for security protection, fraud prevention, service development, client communications, and protection of the rights and interests of the Company, provided that a fair balance with your rights and freedoms is maintained.
  • Consent — where applicable law requires your consent, including for certain types of marketing, the use of certain cookies, or the processing of sensitive data in cases where consent is the required legal basis.
  • Protection of vital interests — in exceptional cases where processing is necessary to protect the life, safety, or essential interests of a person.
  • Public interest or official requests — where processing is necessary for cooperation with competent authorities, prevention of crime, or the performance of tasks recognised as being in the public interest under applicable law.

If processing is based on consent, you have the right to withdraw it at any time by submitting a request to support@heleket.com. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.

9. Mandatory Data Provision

The provision of certain personal data may be necessary for:

  • account registration;
  • provision of services;
  • conducting KYC/AML/CTF checks;
  • compliance with sanctions and regulatory requirements;
  • ensuring platform security;
  • fulfilment of contractual and legal obligations.

If you refuse to provide the required data or provide incomplete, inaccurate, or outdated information, Heleket may be unable to provide you with services, continue servicing your account, process an operation, or fulfil the relevant request.

In certain cases, we may restrict, suspend, or terminate access to services where this is necessary for legal compliance, risk management, fraud prevention, or the protection of users and the Company.

10. Cookies and Similar Technologies

Heleket may use cookies, pixel tags, web beacons, SDKs, local storage, and similar technologies.

Such technologies may be used for:

  • ensuring Website operation;
  • saving user preferences;
  • authentication and security;
  • fraud prevention;
  • performance analysis;
  • improving functionality;
  • understanding user interaction with services;
  • marketing and analytical purposes, where permitted by law.

You may manage cookies through your browser settings or other available consent mechanisms. Disabling certain cookies may affect the functionality of the Website or certain services.

11. Automated Processing, Profiling, and Monitoring

Heleket may use automated systems, including profiling, for the purposes of:

  • identity verification;
  • risk assessment;
  • AML/CTF monitoring;
  • sanctions screening;
  • fraud detection;
  • analysis of suspicious activity;
  • protection of accounts and transactions;
  • making decisions regarding onboarding, continued servicing, access restriction, or additional verification.

Such processes may involve automated assessment of submitted data, documents, technical parameters, transaction activity, and information from external sources.

If an automated decision produces legal consequences for you or otherwise significantly affects your rights, you may have the right to request human intervention, express your position, and contest the decision, where such right is provided for under applicable law.

12. To Whom We May Disclose Personal Data

Heleket may disclose personal data to the following categories of recipients:

  • Affiliated entities and group companies — for service management, security, execution of internal procedures, and provision of services.
  • Service providers — including hosting, cloud infrastructure, IT support, analytics, communications, KYC/KYB, AML/CTF, document verification, sanctions screening, transaction monitoring, and fraud prevention providers.
  • Financial and payment partners — where necessary for processing operations, payment verification, risk management, or legal compliance.
  • Professional advisors — including lawyers, auditors, accountants, insurance advisors, and other professional consultants.
  • Competent authorities — including courts, regulators, law enforcement, tax, governmental, and supervisory authorities, where disclosure is required by law, a lawful request, or is necessary for the protection of rights and interests.
  • Counterparties in corporate changes — in the event of reorganisation, merger, business sale, asset transfer, financing, due diligence, or a similar transaction.
  • Other persons — if you have given consent to such disclosure or if it is otherwise permitted under applicable law.

We require that recipients of personal data apply appropriate security measures and use the data only for permitted purposes.

13. International Transfer of Personal Data

Heleket may transfer personal data outside the country of your residence, including to countries where the level of data protection may differ from that in your jurisdiction.

Such transfers are carried out only where lawful grounds and appropriate safeguards exist, including, where applicable:

  • an adequacy decision regarding the level of protection;
  • standard contractual clauses;
  • contractual data protection obligations;
  • technical and organisational security measures;
  • necessity for the performance of a contract;
  • fulfilment of legal obligations;
  • cooperation with competent authorities;
  • prevention of crime, fraud, money laundering, terrorism financing, or sanctions evasion.

We take reasonable steps to ensure that recipients of personal data maintain protection standards comparable to the requirements of this Policy and applicable law.

14. Personal Data Retention Periods

We retain personal data only for the period necessary to achieve the processing purposes set out in this Policy, unless a longer period is required or permitted by law.

As a general rule, Heleket may retain personal data for the duration of the relationship with the user and for no less than five years after the termination of such relationship, where this is necessary for compliance with AML/CTF, sanctions, tax, accounting, and regulatory requirements, resolution of disputes, investigation of violations, or protection of legitimate interests.

The actual retention period may depend on:

  • the type of data;
  • the nature of the relationship with you;
  • legal requirements;
  • the existence of pending operations, disputes, investigations, or audits;
  • the need to prevent fraud;
  • requirements of regulators or competent authorities;
  • the legitimate interests of Heleket.

Upon expiry of the applicable retention period, data is deleted, anonymised, or archived in accordance with internal procedures and legal requirements.

15. Personal Data Security

Heleket applies technical, organisational, and administrative measures to protect personal data against accidental or unlawful loss, unauthorised access, disclosure, alteration, destruction, or misuse.

Such measures may include:

  • encryption of data transmission, including SSL/TLS;
  • access controls;
  • differentiation of user and employee permissions;
  • security system monitoring;
  • event and activity logs;
  • incident management procedures;
  • contractor vetting;
  • internal security policies;
  • training and need-to-know data access restrictions;
  • data backup and system resilience measures.

Despite the measures taken, no method of data transmission or storage can be completely secure. We therefore also recommend that users protect their credentials, use strong passwords, refrain from sharing access with third parties, and promptly notify us of any suspicious activity.

16. Your Rights

Depending on applicable law, you may have the following rights with respect to your personal data:

  • Right to information — to receive clear information about how we process your data.
  • Right of access — to request confirmation of processing and a copy of your personal data.
  • Right to rectification — to request the correction of inaccurate or incomplete data.
  • Right to erasure — to request the deletion of personal data where there are no lawful grounds for its further processing.
  • Right to restriction of processing — to request a temporary restriction of processing in cases provided for by law.
  • Right to object — to object to processing based on legitimate interests, including certain types of marketing.
  • Right to data portability — to receive data in a structured, commonly used, and machine-readable format, or to request its transfer to another controller, where applicable.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
  • Rights in relation to automated decisions — in cases provided for by law, you may request human intervention, express your position, and contest the decision.

17. Procedure for Exercising Rights

To exercise your rights, please submit a request to: support@heleket.com

We may request additional information to verify your identity and protect your data from unauthorised disclosure.

We handle requests within the timeframes provided for under applicable law. As a general rule, a response is provided within one month of receipt of the request. In complex cases or where a large number of requests are received, this period may be extended, where permitted by law.

The exercise of rights is generally free of charge. However, we may refuse to fulfil a request or charge a reasonable fee if the request is manifestly unfounded, excessive, repetitive, or constitutes an abuse of rights, where permitted by law.

In certain cases, we may be unable to fulfil your request in full or in part — for example, where retention of data is necessary for compliance with legal obligations, AML/CTF requirements, sanctions controls, tax accounting, protection of rights, investigation of violations, or the fulfilment of lawful requests from competent authorities.

If we are unable to fulfil a request, we will explain the reason for the refusal, where such explanation is not prohibited by law.

18. Data of Minors

Heleket's services are not intended for individuals who have not reached the age required for independent use of the relevant services in their jurisdiction.

We do not intend to knowingly collect personal data of minors without a proper legal basis or the consent of a legal representative, where such consent is required by law.

If we become aware that personal data of a minor has been collected without a proper legal basis, we will take reasonable steps to delete such data or restrict its processing.

19. Third-Party Websites and Services

The Heleket website and services may contain links to third-party websites, applications, services, or resources. This Policy does not apply to the processing of personal data by such third parties.

We do not control and are not responsible for the privacy practices, security, or content of third-party resources. We recommend reviewing their privacy policies before providing data to third parties.

20. Account Confidentiality and User Obligations

You are responsible for the security of your credentials, passwords, authentication methods, and devices used to access Heleket's services.

You agree to:

  • provide accurate and up-to-date information;
  • promptly update your data when changes occur;
  • refrain from sharing account access with third parties;
  • immediately notify us of any suspicious access, loss of credentials, or other security threat;
  • comply with the applicable terms of use and security requirements.

Heleket is not liable for consequences arising from the provision of inaccurate data, breach of security requirements, or sharing of account access with third parties, except where such liability is expressly provided for by law.

21. Changes to this Policy

Heleket reserves the right to periodically update this Policy to reflect changes in legislation, technology, service structure, security procedures, or business practices.

The updated version of the Policy is published on the Website with the date of the last update indicated. Where changes are material, we may notify you by an additional means, such as through the Website, your account, email, or other available channels.

Continued use of the Website or services after the changes take effect constitutes acknowledgement of the updated Policy, unless otherwise provided for under applicable law.

22. Language and Version Priority

This Policy may be available in several languages. In the event of any discrepancy between versions, the English language version shall prevail, unless otherwise expressly provided for under applicable law or the mandatory rules of the relevant jurisdiction.

23. Final Provisions

This Policy forms part of the overall legal documentation framework of Heleket and should be read together with the applicable Terms of Use, AML/KYC policies, and other documents published or provided to the user.

By using the Website, creating an account, undergoing verification, interacting with services, or providing us with personal data, you confirm that you have read this Policy and understand how your personal data is processed in accordance with its terms.