Legal

Privacy Policy

Last Updated: April, 2026

Introduction

  • This Privacy Policy explains how Byartist Limited (“Bitoshi”, “we”, “us”, or “our”) collects, uses, processes, stores, shares, and protects personal data when users access or use our website, mobile applications, products, and related services (collectively, the “Platform” or “Services”).
  • By accessing, registering on, and using the Platform, you confirm that you have read, understood, and agreed to be legally bound by this Privacy Policy, as may be amended from time to time.
  • This Privacy Policy shall be interpreted in accordance with applicable data protection and privacy laws in jurisdictions where Bitoshi operates or offers services, including but not limited to:
    1. 1. Nigeria Data Protection Act (NDPA);
    2. 2. Ghana Data Protection Act;
    3. 3. Kenya Data Protection Act;
    4. 4. Applicable regulations and regulatory guidance relating to privacy, cybersecurity, and financial crime prevention.

Definitions

  • Agreement, Terms, or Terms of Use: Refers to these Terms and Conditions.
  • Applicable Data Protection Laws: Means all privacy and data protection laws applicable to the Company's operations.
  • Bitoshi Account: This means the account you create on the Bitoshi Platform (mobile application or website) to access or use the Service.
  • Bitoshi, we, us, or our: Refers to Byartist Limited, its subsidiaries, agents, and any person or legal entity to whom the rights or obligations of Byartist Limited have been assigned.
  • Content: This means the platform and any content, materials, graphics, audiovisual files, processes, code, features, functionality, and products available on the Platform.
  • Personal Data: Means any information relating to an identified or identifiable individual.
  • Processing: Means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, or deletion.
  • You, user, or your: This means any person or entity who creates an account on the Platform and accesses any or all of our services.

Personal Data We Collect

  • We may collect and process the following categories of personal data:

    Identity Information: These include:
    1. 1. Full name;
    2. 2. Date of birth;
    3. 3. Nationality;
    4. 4. Government-issued identification documents;
    5. 5. Selfie/liveness verification data;
    6. 6. Bank Verification Number (BVN);
    7. 7. National Identification Number (NIN);
    8. 8. Tax identification information, where applicable.
  • Contact Information: These include:
    1. 1. Email Address;
    2. 2. Phone number;
    3. 3. Residential Address.
  • Financial and Transaction Information: These include:
    1. 1. Bank account information;
    2. 2. Wallet addresses;
    3. 3. Transaction history;
    4. 4. Payment information;
    5. 5. Virtual card activity;
    6. 6. Blockchain transaction information.
  • Technical and Device Information: These include:
    1. 1. IP address;
    2. 2. Device identifiers;
    3. 3. Operating system;
    4. 4. Browser type;
    5. 5. App version;
    6. 6. Device and network information.
  • Usage and Analytics Information: These include:
    1. 1. Navigation activity;
    2. 2. Session activity;
    3. 3. Feature interaction;
    4. 4. Interface engagement;
    5. 5. Diagnostic and performance information.
  • Compliance Information: These include:
    1. 1. Sanctions screening results;
    2. 2. Politically exposed person (PEP) screening results;
    3. 3. Adverse media checks;
    4. 4. Source of funds documentation;
    5. 5. Enhanced due diligence information.

How We Collect Information

  • We may collect information:
    1. 1. Directly from users during onboarding or platform use;
    2. 2. Automatically through the Platform;
    3. 3. From third-party verification providers;
    4. 4. From payment processors and banking partners;
    5. 5. From blockchain analytics providers;
    6. 6. From publicly available databases and watchlists;
    7. 7. From regulators or law enforcement authorities, where legally permitted.

Legal Bases for Processing

  • We process personal data on lawful bases, including:
    1. 1. Compliance with legal and regulatory obligations;
    2. 2. Performance of contractual obligations;
    3. 3. Protection against fraud and financial crime;
    4. 4. Legitimate business interests;
    5. 5. User consent where required by applicable law.

How We Use Personal Data

  • We may use personal data for purposes including, but not limited to:
    1. 1. Customer onboarding and account creation;
    2. 2. Identity verification and KYC compliance;
    3. 3. Fraud prevention and security monitoring;
    4. 4. Sanctions and AML/CFT compliance;
    5. 5. Transaction processing;
    6. 6. Customer support;
    7. 7. Improving platform functionality and performance;
    8. 8. Analytics and operational reporting;
    9. 9. Enforcing our Terms of Use;
    10. 10. Complying with legal or regulatory obligations.

Session Replay and Usage Analytics

  • Session Replay Technology

    We use session replay technology to better understand how users interact with our application, enhance user experience, and improve system performance. Session replay enables us to securely record and analyze user interaction patterns such as navigation flows, scrolling behavior, tapping, and interface engagement to identify usability challenges and technical issues.

  • Data Collection

    When you use our Services, we may automatically collect limited session-related data through third-party analytics service providers, including:

    1. 1. Device information (device type, operating system, app version)
    2. 2. Interaction data (navigation paths, taps, scrolling behavior, form interactions)
    3. 3. Interface engagement metrics
    4. 4. Session timestamps and duration
    5. 5. User identifiers associated with your account
    6. 6. Performance and diagnostic data

    This data is collected solely for analytical, security, and service improvement purposes.

  • Data Use and Retention

    We use session replay data for:

    1. 1. Improving user experience and application performance
    2. 2. Identifying and resolving technical issues
    3. 3. Enhancing platform security and fraud detection
    4. 4. Producing aggregated analytics and operational insights

    Session replay data is retained only for as long as reasonably necessary for the purposes described in this Policy and in accordance with applicable legal, regulatory, security, and operational requirements.

  • Sensitive Information Protection

    We implement reasonable technical and organizational safeguards to prevent the capture and exposure of sensitive personal data. This includes masking or excluding:

    1. 1. Passwords and authentication credentials
    2. 2. Payment and financial instrument details
    3. 3. Government-issued identification numbers
    4. 4. Sensitive biometric templates or unrelated sensitive personal data

    If you believe that sensitive information has been inadvertently captured, please contact us immediately via the contact details below.

  • Third-Party Processors

    Session replay data is processed by our analytics service providers under strict contractual and data protection obligations consistent with applicable data protection laws.

  • Your Privacy Rights and Opt-Out

    Subject to applicable legal, operational, and security requirements, you may request to opt out of certain session replay or analytics processing activities by contacting us through the contact details below. Opting out may limit our ability to diagnose and resolve technical issues associated with your account. You may request deletion of certain session replay data, subject to applicable legal, regulatory, security, audit, fraud prevention, and retention obligations.

  • Changes to Session Replay Practices

    We reserve the right to modify our session replay practices. Where required by applicable law or where changes materially affect user privacy rights, we may provide notice through in-app notifications, website notices, or email communications.

Sharing and Disclosure of Information

  • We may disclose personal data to:
    1. 1. Regulators and competent authorities;
    2. 2. Financial institutions and payment processors;
    3. 3. Identity verification providers;
    4. 4. Sanctions screening providers;
    5. 5. Blockchain analytics providers;
    6. 6. Cloud hosting and infrastructure providers;
    7. 7. Professional advisers and auditors;
    8. 8. Law enforcement agencies where required by law.

    We do not sell personal data.

International Data Transfers

  • Personal data may be transferred to, stored in, or processed in jurisdictions outside a user's country of residence where:
    1. 1. Bitoshi operates;
    2. 2. Service providers are located;
    3. 3. Cross-border processing is necessary for service delivery.
  • Such transfers shall be subject to appropriate safeguards and applicable legal requirements.

Data Retention

  • We retain personal data only for as long as necessary to:
    1. 1. Provide the Services;
    2. 2. Comply with legal and regulatory obligations;
    3. 3. Resolve disputes;
    4. 4. Enforce contractual rights;
    5. 5. Prevent fraud and financial crime.
  • Certain identity verification, transaction, and compliance records may be retained for periods required under applicable AML/CFT, financial services, tax, audit, or regulatory obligations.

Data Security

  • We implement reasonable technical, administrative, and organizational safeguards designed to protect personal data against:
    1. 1. Unauthorized access;
    2. 2. Disclosure;
    3. 3. Destruction;
    4. 4. Alteration;
    5. 5. Misuse;
    6. 6. Accidental loss.
  • Such measures may include:
    1. 1. Encryption;
    2. 2. Access controls;
    3. 3. Monitoring systems;
    4. 4. Authentication procedures;
    5. 5. Secure storage practices.

    However, no system can guarantee absolute security.

User Rights

  • Subject to applicable laws, users may have rights including:
    1. 1. Access to personal data;
    2. 2. Correction of inaccurate information;
    3. 3. Deletion of personal data;
    4. 4. Restriction of processing;
    5. 5. Objection to certain processing activities;
    6. 6. Withdrawal of consent where processing is based on consent;
    7. 7. Complaint rights before applicable data protection authorities.

    Requests may be submitted through the contact details provided below.

Cookies and Tracking Technologies

  • We may use cookies, SDKs, pixels, and similar technologies to:
    1. 1. Authenticate users;
    2. 2. Maintain sessions;
    3. 3. Improve platform functionality;
    4. 4. Analyze traffic and usage;
    5. 5. Enhance security and fraud prevention.
  • Users may control certain cookie settings through browser or device settings, where applicable.

Children's Privacy

  • The Platform is not directed to individuals under the age of 18 or the applicable age of majority in the relevant jurisdiction;
  • We do not knowingly collect personal data from minors without lawful authorization.

Third-Party Links and Services

  • The Platform may contain links to third-party websites or services.
  • Bitoshi is not responsible for the privacy practices, security, or content of third-party services.

Changes to this Privacy Policy

  • We may amend this Privacy Policy from time to time.
  • Material updates may be communicated through:
    1. 1. Email notifications;
    2. 2. In-app notices;
    3. 3. Website publication;
    4. 4. Or other appropriate communication channels.
  • Continued use of the Platform after updates become effective constitutes acknowledgment of the revised Privacy Policy.

Contact Information

  • Questions, complaints, or requests relating to this Privacy Policy or personal data processing may be directed to:

    Support: [email protected]

    DPO: Data Protection Officer

    Byartist Limited [email protected]

Regulatory Complaints

  • Users may also lodge complaints with applicable data protection regulators or supervisory authorities in their jurisdiction where permitted by law.

Get started on Bitoshi in few minutes

Scan the QR code to download the Bitoshi app and start trading.

QR Code to download Bitoshi App

Scan the QR code and join the fastest moving crypto exchange