Introduction
Welcome to Tria Bridge. Tria Bridge Limited is a company incorporated in Cyprus under registration number HE 429492 with its registered office at Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus (“Tria Bridge”, “we”, “us”, or “our”). Tria Bridge is authorised by the Cyprus Securities and Exchange Commission (“CySEC”) as a crypto-asset service provider under Regulation (EU) 2023/1114 on markets in crypto-assets (“MiCAR”). Tria Bridge Limited is the data controller responsible for your personal data. We respect your privacy and are dedicated to safeguarding your personal information.
This Privacy Notice explains how Tria Bridge collects, uses, stores, processes, and shares your personal data when you access our platform, website, or services. It also describes your rights under applicable data protection legislation and how you can exercise them.
This Privacy Notice has been prepared in accordance with:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”); and
- other applicable data protection and privacy laws.
Please read this Privacy Notice carefully. By using Tria Bridge’s services, you acknowledge that you have read and understood how we handle your personal data.
01. Who we are
Tria Bridge Limited is the data controller responsible for your personal data. Tria Bridge determines the purposes and means of processing your personal information and is accountable for ensuring that processing is carried out lawfully, fairly, and transparently.
- Entity
- Tria Bridge Limited
- Registered address
- Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus
- Company registration
- HE429492
- Regulatory status
- Crypto-asset service provider authorised by the Cyprus Securities and Exchange Commission under Regulation (EU) 2023/1114 (MiCAR)
- Privacy contact email
- privacy@triabridge.com
If you have any questions about this Privacy Notice or Tria Bridge’s data practices, please contact us using the details set out in Section 11.
02. Personal data we collect
Tria Bridge may collect, use, store, and process the following categories of personal data, depending on how you interact with our platform and services:
- Identity Data
- First name, last name, username, date of birth, nationality and country of residence, government-issued identification documents.
- Contact Data
- Email address, telephone number, billing address, correspondence address.
- Financial & Transaction Data
- Transaction records, account balances, wallet addresses, source of funds and source of wealth information, bank account details, and instructions and orders you submit in relation to crypto-asset services.
- Technical Data
- IP address, device identifiers, browser type and version, operating system, login timestamps, session identifiers.
- Usage Data
- Pages visited, features accessed, interaction logs, click-stream data, time spent on platform.
- Verification Data
- Know Your Customer (KYC) documents, proof of address, identity verification results, sanctions, politically exposed person and adverse media screening results, and blockchain analytics results relating to wallet addresses.
- Communications Data
- Records of correspondence, support tickets, complaints, and feedback submitted to Tria Bridge.
Special Categories of Personal Data. Tria Bridge does not intentionally collect or process special categories of personal data (such as data concerning health, racial or ethnic origin, religious beliefs, biometric data, or sexual orientation) unless it is strictly required by applicable law or regulation. Where such processing is necessary, Tria Bridge will rely on an appropriate legal basis under Article 9 GDPR and will notify you accordingly.
Where you are onboarded as a corporate client, Tria Bridge also processes personal data relating to your directors, authorised representatives, beneficial owners and other connected natural persons. Where you provide such data to us, you are responsible for ensuring that those individuals have been informed of this Privacy Notice.
03. Lawful basis for processing
Tria Bridge processes your personal data only where a lawful basis exists under Article 6 of the GDPR. The following table sets out the primary purposes for which Tria Bridge processes your data and the corresponding lawful basis applied:
| Processing purpose | Lawful basis | GDPR article |
|---|---|---|
| Account registration, onboarding, and management | Performance of a contract | Art. 6(1)(b) |
| Processing and settling transactions | Performance of a contract | Art. 6(1)(b) |
| Providing crypto-asset services, including custody and administration of crypto-assets on your behalf and the reception and transmission of orders | Performance of a contract | Art. 6(1)(b) |
| Identity verification (KYC) and anti-money laundering (AML) compliance | Legal obligation | Art. 6(1)(c) |
| Complying with regulatory, and reporting obligations | Legal obligation | Art. 6(1)(c) |
| Record-keeping of communications, orders and transactions relating to crypto-asset services | Legal obligation | Art. 6(1)(c) |
| Detecting, investigating, and preventing fraud and security incidents | Legitimate interests | Art. 6(1)(f) |
| Improving and maintaining Tria Bridge’s platform and services | Legitimate interests | Art. 6(1)(f) |
| Sending marketing and promotional communications | Consent | Art. 6(1)(a) |
| Responding to legal or regulatory authority requests | Legal obligation | Art. 6(1)(c) |
| Profiling for personalised service delivery (where applicable) | Consent / Legitimate interests | Art. 6(1)(a)/(f) |
Tria Bridge may process personal data for the purposes of complying with anti-money laundering, counter-terrorist financing, sanctions screening, fraud prevention, and other financial crime prevention obligations imposed under applicable law, including the Cyprus Prevention and Suppression of Money Laundering and Terrorist Financing Law 188(I)/2007, the CySEC Directive on the Prevention and Suppression of Money Laundering and Terrorist Financing, Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, and applicable European Union and United Nations restrictive measures.
Certain personal data is required by law, regulation, or contract in order for Tria Bridge to provide its services, including identity verification and AML/KYC compliance information. Failure to provide such data may prevent Tria Bridge from establishing or maintaining a business relationship with you or providing access to certain services.
Where Tria Bridge relies on legitimate interests as its lawful basis, we have conducted a legitimate interests assessment and are satisfied that our interests are not overridden by your fundamental rights and freedoms. The legitimate interests pursued by Tria Bridge include maintaining platform security, preventing fraud, improving services, protecting business operations, and ensuring the integrity of the platform.
Where Tria Bridge relies on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. See Section 9 for how to exercise this right.
04. How we use your personal data
Tria Bridge uses your personal data to provide, maintain, and improve its platform and services. Specifically, Tria Bridge processes your data to:
- create, verify, and manage your account on the Tria Bridge platform;
- process transactions initiated through Tria Bridge;
- safeguard the crypto-assets and funds we hold on your behalf and keep the records and positions required for that purpose;
- fulfil identity verification and AML/KYC obligations required by applicable law;
- detect, prevent, investigate, and report fraud, financial crime, and other prohibited activities;
- provide customer support and respond to your enquiries or complaints;
- send you service-related communications, security alerts, and account notifications;
- send you marketing communications about Tria Bridge’s products and features, where you have given consent or where otherwise permitted by law;
- analyse platform usage and performance to improve Tria Bridge’s features and user experience;
- comply with applicable laws, regulations, and binding directions from competent authorities, including CySEC; and
- enforce Tria Bridge’s Terms of Service, policies, and legal agreements.
Tria Bridge will not use your personal data for any purpose that is incompatible with the purposes set out in this Privacy Notice without providing you with prior notice and, where required, obtaining your consent.
05. Sharing your personal data
Tria Bridge does not sell, rent, or trade your personal data to third parties for commercial or marketing purposes.
Tria Bridge may share your personal data in the following limited and controlled circumstances:
Service Providers
Tria Bridge engages carefully selected third-party service providers to support its operations. These include providers of IT infrastructure and cloud hosting, identity verification and KYC services, blockchain analytics and sanctions screening, payment processing, cybersecurity, and customer support. All service providers are bound by data processing agreements and are required to process data only on Tria Bridge’s documented instructions and to implement appropriate security measures.
Professional Advisers
Tria Bridge may share data with lawyers, auditors, accountants, compliance consultants, and insurers where necessary for the delivery of professional services, regulatory compliance, or dispute resolution.
Regulatory and Law Enforcement Authorities
Tria Bridge may be required to disclose your personal data to competent regulatory bodies, including CySEC and the Cyprus Unit for Combating Money Laundering (MOKAS), law enforcement agencies, tax authorities, or courts where required by applicable law, a court order, or a binding regulatory directive.
Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of Tria Bridge’s business or assets, your personal data may be transferred to the relevant successor entity. Tria Bridge will provide notice of any such transfer and applicable privacy protections.
06. International data transfers
Tria Bridge may transfer your personal data to countries or territories outside the European Economic Area (EEA) in the course of delivering its services. Where such transfers occur, Tria Bridge ensures that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- transfers to countries that have received an adequacy decision from the European Commission; or
- other legally recognised transfer mechanisms under Chapter V of the GDPR.
Where transfers are carried out using Standard Contractual Clauses, you may request a copy of the relevant safeguards by contacting Tria Bridge using the details set out in Section 11.
07. Data retention
Tria Bridge retains your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, reporting, anti-money laundering, and compliance obligations. Tria Bridge’s retention periods are determined by reference to the nature of the data, the purpose of processing, and applicable legal requirements. Indicative retention periods include:
- identity verification, KYC, AML, sanctions screening, and transaction records: retained for a minimum period of five (5) years following the end of the business relationship or completion of the relevant transaction, in accordance with the Prevention and Suppression of Money Laundering and Terrorist Financing Law 188(I)/2007, or longer where required by applicable law or regulatory obligations;
- account information and contractual records: retained for the duration of the relationship with you and for up to six (6) years thereafter for legal and regulatory purposes;
- customer support correspondence, complaints, and communications data: retained for up to two (2) years following resolution of the relevant matter;
- marketing and promotional data: retained until you withdraw your consent, unsubscribe, or after twenty-four (24) months of inactivity, whichever occurs first;
- technical logs, security records, and platform usage data: generally retained for up to twelve (12) months, unless a longer retention period is necessary for security investigations, fraud prevention, dispute resolution, or legal proceedings.
In certain circumstances, Tria Bridge may retain personal data for longer periods where necessary to establish, exercise, or defend legal claims, comply with ongoing investigations or regulatory requests, or fulfil other legal obligations.
Where retention is no longer required, Tria Bridge will securely delete or irreversibly anonymise your personal data in accordance with its internal data disposal procedures. Anonymised data that can no longer be linked to an identifiable individual may be retained indefinitely for analytical purposes.
Please note that data recorded on a public distributed ledger in connection with a crypto-asset transaction is not controlled by Tria Bridge and cannot be amended or erased by us.
08. Data security
Tria Bridge implements rigorous technical and organisational security measures designed to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure, consistent with its information security and ICT risk management framework. These measures include, but are not limited to:
- encryption of personal data in transit (TLS/SSL) and at rest;
- role-based access controls and least-privilege access principles;
- multi-factor authentication for access to sensitive systems;
- periodic security assessments and testing, and vulnerability assessments;
- incident detection, response, and recovery procedures; and
- ongoing staff training on data protection and information security obligations.
Access to your personal data is restricted to those employees, agents, and contractors of Tria Bridge who have a legitimate business need to access it. All such persons are subject to confidentiality obligations.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Tria Bridge will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, Tria Bridge will also notify you directly without undue delay in accordance with Article 34 GDPR.
09. Your data subject rights
As a data subject under the GDPR, you have the following rights in relation to your personal data held by Tria Bridge. These rights apply subject to applicable exemptions and limitations under data protection law, including limitations arising from our anti-money laundering, record-keeping and regulatory reporting obligations.
- Right of Access (Article 15 GDPR)
- You have the right to request confirmation of whether Tria Bridge processes your personal data and, if so, to obtain a copy of that data together with supplementary information about how it is processed. Tria Bridge will provide this information free of charge.
- Right to Rectification (Article 16 GDPR)
- You have the right to request that Tria Bridge corrects any inaccurate personal data and completes any incomplete data held about you without undue delay.
- Right to Erasure / ‘Right to be Forgotten’ (Article 17 GDPR)
- You have the right to request that Tria Bridge deletes your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent on which processing was based, or where processing is otherwise unlawful. This right is subject to Tria Bridge’s legal retention obligations.
- Right to Restriction of Processing (Article 18 GDPR)
- You have the right to request that Tria Bridge restricts processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where processing is unlawful but you do not want the data erased.
- Right to Data Portability (Article 20 GDPR)
- Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
- Right to Object (Article 21 GDPR)
- You have the right to object to processing of your personal data where Tria Bridge relies on legitimate interests as its lawful basis. You also have an absolute right to object to processing of your personal data for direct marketing purposes at any time.
- Right to Withdraw Consent (Article 7(3) GDPR)
- Where Tria Bridge processes your personal data on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
- Rights in Relation to Automated Decision-Making (Article 22 GDPR)
- Tria Bridge uses automated tools to support identity verification, customer risk scoring, sanctions screening and transaction monitoring. Where a decision producing legal effects concerning you, or similarly significantly affecting you, would be based solely on automated processing, you have the right to obtain human intervention, to express your point of view and to contest the decision, except where the processing is authorised by law to which Tria Bridge is subject.
To exercise any of the rights listed above, please submit a request to Tria Bridge using the contact details in Section 11. Tria Bridge will respond to all valid requests within one calendar month of receipt. Where a request is particularly complex or numerous, this period may be extended by up to two further months, and Tria Bridge will notify you of any such extension within the initial one-month period.
You also have the right to lodge a complaint with the competent data protection supervisory authority. The lead supervisory authority for Tria Bridge is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus:
- Website: www.dataprotection.gov.cy
- Email: commissioner@dataprotection.gov.cy
If you are based in another EU member state, you may also lodge a complaint with your local national data protection supervisory authority.
10. Changes to this Privacy Notice
Tria Bridge may update this Privacy Notice from time to time to reflect changes in applicable law, regulatory guidance, or its business operations and data practices. The updated Privacy Notice will be published on the website.
For material changes that may significantly affect how Tria Bridge processes your personal data, Tria Bridge will provide additional notice, for example by email notification or a prominent notice on our platform, before the changes take effect.
Tria Bridge encourages you to review this Privacy Notice periodically to stay informed of how your personal data is being used and protected.
11. How to contact us
If you have any questions about this Privacy Notice, wish to exercise any of your rights, or want to make a complaint about how we handle your personal data, please contact us:
- Entity
- Tria Bridge Limited
- Address
- Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus
- privacy@thevault.inc
We will acknowledge your request and respond within the timeframes set out in Section 9.