The cultural exchange layer for participation-driven momentum.
Cursic Exchange Inc. is dedicated to safeguarding the privacy, identity integrity, and cryptographic assets of our global participants. This Privacy Policy details the categories of information we collect, the rigorous security protocols we implement, and your privacy rights under global regulatory frameworks including GDPR and CCPA.
Our philosophy on cryptographic privacy and data minimization.
Wherever feasible, sensitive identity markers are converted into irreversible cryptographic hashes to prevent identity leakage across operational microservices.
This Privacy Policy applies to all personal data collected, stored, processed, and transmitted through the Cursic Exchange web portal, mobile interfaces, API endpoints, and associated financial services.
We follow a strict 'Privacy by Design' methodology. We only collect the minimal personal information necessary to deliver high-performance exchange services, maintain regulatory compliance, and safeguard market participants.
Data categories gathered for compliance and exchange operations.
We collect personal information across three primary operational categories:
1. Account Credentials: Email address, cryptographic wallet public keys, encrypted password hashes, and multi-factor authentication (MFA/TOTP) metadata.
2. Customer Due Diligence (KYC) Data: Full legal name, date of birth, residential address, nationality, government-issued photo ID documents, biometric liveness selfie verification, and corporate registry filings for institutional entities.
3. Financial & Trading Telemetry: Order history, trade execution records, transaction notional amounts, deposit/withdrawal logs, IP addresses, device identifiers, and browser telemetry for fraud prevention.
Privacy-preserving sybil resistance and cap enforcement.
Your identity hash guarantees that platform rules are enforced equitably across all participants without exposing your personal documents to public ledgers.
To enforce critical anti-sybil protections (such as the 2,000 CN drop allocation cap) without disseminating raw identity records across the matching engine, Cursic computes a deterministic SHA-256 identity fingerprint (`VerifiedIdentityId`).
This mathematical fingerprint is derived from normalized combination of legal name, date of birth, and identity document number.
Internal orderbook workers, ledger validators, and rate limiters interact exclusively with the irreversible `VerifiedIdentityId` hash, shielding your sensitive personal identification information from day-to-day transaction processing.
Why we process your data under international legal standards.
We process your personal information under the following lawful legal bases:
• Contractual Performance: Executing order matching, maintaining account balances, processing deposits/withdrawals, and crediting Creator Respect Allocations.
• Legal & Regulatory Obligations: Complying with mandatory Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), Know Your Customer (KYC), and tax reporting directives.
• Legitimate Business Interests: Detecting wash trading, preventing DDoS attacks, profiling system performance, and defending against fraud.
• User Consent: When you opt into non-essential marketing notifications or analytics tracking.
Storage protocols and statutory financial retention periods.
All uploaded identity documents (passports, national IDs, utility bills, corporate registries) are encrypted in transit via TLS 1.3 and stored in an isolated, access-controlled Document Vault encrypted with AES-256.
Document access is restricted to credentialed compliance officers with mandatory multi-party authorization and immutable audit logging.
Statutory Retention Period: Under international financial AML regulations, customer verification records and transaction ledgers must be retained for a minimum statutory period (typically 5 to 7 years following account closure) before permanent cryptographic erasure.
Strict limits on disclosures and international data transfers.
Cursic DOES NOT sell, rent, monetize, or trade your personal data to advertisers, data brokers, or unauthorized third parties.
Information is shared strictly with trusted, audited sub-processors bound by stringent Data Protection Agreements (DPAs):
• Regulated Identity Verification Providers for document scanning and biometric liveness checks.
• Cloud Infrastructure Providers with SOC 2 Type II and ISO 27001 certifications.
• Law Enforcement & Regulatory Authorities only upon receipt of a legally binding subpoena, court order, or formal regulatory mandate.
Access, correction, export, and deletion rights.
Submit privacy requests directly to privacy@cursic.com. We respond to all verified data requests within 30 calendar days.
Depending on your jurisdiction, you are entitled to exercise the following fundamental privacy rights:
• Right of Access: Request a full copy of the personal data we hold about you.
• Right to Rectification: Correct inaccurate or incomplete personal records.
• Right to Data Portability: Export your transaction and profile data in a structured, machine-readable format (JSON/CSV).
• Right to Erasure ('Right to be Forgotten'): Request deletion of your data, subject to statutory AML compliance retention requirements.
• Right to Restrict Processing: Object to or restrict specific processing activities.
To exercise any of these rights, contact our Data Protection Officer at privacy@cursic.com.
Zero-trust architecture, encryption standards, and threat monitoring.
Cursic employs military-grade security controls to protect user data from unauthorized access, alteration, disclosure, or destruction:
• Zero-Trust Network Architecture with strict least-privilege role-based access control (RBAC).
• Automated intrusion detection, DDoS mitigation, and continuous vulnerability scanning.
• End-to-end encryption for sensitive data streams and hardware security modules (HSM) for cryptographic key isolation.
Direct contact channels for privacy inquiries and regulatory matters.
If you have questions, feedback, or concerns regarding this Privacy Policy, our data practices, or wish to file a formal privacy inquiry, please reach out to our dedicated compliance team:
• Email: privacy@cursic.com
• Compliance Department: compliance@cursic.com
• Corporate Entity: Cursic Exchange Inc.