Privacy Policy

Firebit

Last updated on May 26, 2026, Nova Lima, Minas Gerais, Brazil.

FIREBIT DIGITAL ASSETS, a legal entity registered under No. 62.873.133/0001-20 ("Firebit"), respects your privacy and is committed to protecting your personal data. For this reason, this Privacy Policy ("Policy") was prepared to explain, in a clear and transparent manner, how we collect, use, store, protect, and share your Personal Data in the context of our activities.

The protection of Personal Data is a priority for Firebit. We adopt strict data Processing policies and measures, in compliance with applicable legal and regulatory standards, with the objective of ensuring information security, respecting the privacy of data subjects, and ensuring transparency in the processes carried out.

Firebit is a digital platform that operates in the virtual assets market, offering intermediation services for the purchase, sale, and exchange of virtual assets. Certain functionalities, such as fiat currency on-ramp and off-ramp operations, may be made available depending on the product contracted, and the custody of crypto assets traded through Firebit is carried out by a specialized service provider within the same ecosystem, as described in this Policy.

In this context, Firebit reaffirms its institutional commitment to the ethical, secure, and responsible processing of personal data of its users, clients, partners, suppliers, and other data subjects, in strict compliance with current legislation, especially the Brazilian General Data Protection Law (LGPD).

By using (i) our services and/or (ii) our Platform, including our websites, you declare that you are aware of and agree to the terms of this Policy. We recommend careful reading of this document and, in case of questions, contacting us through one of the channels indicated in this Policy.

1. DEFINITIONS

We know that some terms used in this Policy may not be common in your daily life. Therefore, we have prepared a short glossary for reference:

ANPD: the Brazilian National Data Protection Authority, a special-nature autarchy with responsibilities related to the protection of Personal Data and privacy, including oversight for compliance with the LGPD throughout the national territory;

Virtual Asset: a digital representation of value that can be traded or transferred by electronic means and used for payments or investment purposes, excluding national and foreign currencies; electronic currency under Law No. 12,865/2013; instruments that provide the holder with access to specified products or services or benefits arising from such products or services, such as loyalty program points and rewards; and representations of assets whose issuance, bookkeeping, trading, or settlement is provided for by law or regulation, such as securities and financial assets;

Client: means the natural person who enters into or evaluates entering into a contract with Firebit for the use of its digital platform and the enjoyment of the services it provides, including, but not limited to, intermediation for the purchase, sale, exchange, and settlement of Virtual Assets, as well as fiat currency on-ramp and off-ramp operations and, when applicable, services related to the custody of virtual assets.

Consent: a free, informed, and unambiguous expression by which the Data Subject agrees to the Processing of their Personal Data for a specific purpose;

Controller: refers to the natural or legal person responsible for decisions regarding the Processing of Personal Data;

Personal Data: all information that allows the identification of a natural person directly or that may make such person identifiable. Examples of Personal Data include name, address, CPF (Brazilian individual taxpayer registry), ID number, email, identification documents in general, phone number, internet access records (date and time of use of a specific internet application, IP address used for access), among others;

Sensitive Personal Data: Personal Data related to racial or ethnic origin, religious belief, political opinion, membership in a union or organization of a religious, philosophical, or political nature, data concerning health or sexual life, genetic or biometric data when linked to a natural person;

Device:means any electronic device used by Data Subjects to access Firebit's systems, such as desktop computers, laptops, cell phones, tablets, smartphones, and/or other internet-connected devices;

Data Protection Officer (DPO):the person designated by the Processing Agents to act as a communication channel between the Controller, the Data Subjects, and the ANPD, and to ensure that the Processing Agents are in compliance with data protection laws and regulations. The contact information for Firebit's DPO is available in this Policy;

LGPD: means the Brazilian General Data Protection Law, Federal Law No. 13,709, published on August 14, 2018, which regulates Personal Data Processing activities, including in digital media, by natural persons or legal entities under public or private law, with the objective of protecting the fundamental rights of freedom and privacy and the free development of the personality of the natural person. The full content of the LGPD can be consulted at this link;

Processor: the natural or legal person who carries out the Processing of Personal Data on behalf of the Controller, following its instructions;

Partner: the companies that are part of CACTUS FINANCIAL SERVICES LTDA, a limited liability company registered under CNPJ No. 62.578.460/0001-59, and other companies that are part of such economic group, an institution authorized to operate by BACEN (Brazilian Central Bank), of which Firebit is a member;

Virtual Asset Service Provider: a legal entity that carries out, on its own behalf or on behalf of third parties, activities related to virtual assets, such as intermediation, custody, transfer, exchange, or administration, under applicable legislation.

Platform: means the set of digital environments, systems, interfaces, and technological resources made available by Firebit for the provision of its services, including, but not limited to, its website, mobile applications, user panels, APIs, trading systems, payment modules, custody, and other functionalities accessible by electronic means.

Data Subject:the natural person to whom the personal data being processed by Firebit refers, including, among others, platform users, clients, potential clients, legal representatives, job candidates, natural person partners, and any other natural persons whose personal data is processed in the context of Firebit's activities. In this Policy, the terms "you", "your", and "yours" also refer to the Data Subject;

International Data Transfer: transfer of Personal Data to a foreign country or international organization of which the country is a member; and

Processing: any operation performed with Personal Data, whether automated or not. That is, the collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, storage, archiving, deletion, evaluation, or control of information, modification, communication, transfer, dissemination, or extraction of Personal Data.

Any other terms used with initial capital letters shall have the meaning attributed to them in applicable legislation, especially in the LGPD.

2. PURPOSE

The purpose of this Policy is to explain how Firebit processes and protects the Personal Data of its Clients and how these Data Subjects may exercise their rights regarding the Processing of their Personal Data. If you wish to consult how your data is processed, this Policy (in its most recent version) should be consulted.

Certain specific Processing activities may be subject to terms of use, privacy policies, or specific contractual instruments, whether under the responsibility of Firebit or third parties, prepared specifically for certain services, functionalities, or operations. In such cases, and to the extent applicable, this Policy shall not apply to services that have their own terms and/or standards and over which Firebit does not exercise any kind of interference regarding the purposes and means of Personal Data Processing.

What is Firebit's role in the Processing of your Personal Data?

Firebit acts, as a rule, as the Controller of Personal Data processed within the scope of its platform, being responsible for decisions regarding the purposes and means of processing, under applicable legislation.

To enable certain services, Firebit may engage specialized service providers, including other Virtual Asset Service Providers (VASPs), financial institutions, payment providers, custodians, as well as technology, identity verification, and fraud prevention suppliers, who may act as Personal Data Processors, carrying out processing on behalf of and under the instructions of Firebit.

In certain specific situations, depending on the nature of the service and the contractual model adopted, such third parties may act as independent Controllers or joint Controllers, in which case the processing of personal data will be subject to their respective privacy policies and specific contractual instruments, duly informed to data subjects, under current legislation.

3. HOW DOES FIREBIT COLLECT YOUR PERSONAL DATA?

Collection of Personal Data. Your Personal Data may be collected by us in various ways and to fulfill the purposes described in section 6. Below, we explain some of these means that we use:

  • Registration and use of the Platform:at the time of creating the Client's account, as well as during the use of the Firebit Platform, at which time the Personal Data necessary for the use of the Platform is collected, as applicable. Personal Data may also be collected from Partners, within the context of Firebit's economic group;
  • Verification and compliance procedures (KYC/AML): when the Client provides documents, images, and information necessary for identification, identity verification, and compliance with legal and regulatory obligations;
  • Contact and support channels: when the Client provides or updates information through electronic forms, email, phone, messaging apps, or other official Firebit channels; and
  • Exercise of rights and compliance with legal requests: when the Client submits requests related to the exercise of rights provided for in applicable legislation or to compliance with legal obligations.

What Personal Data do we Process?

Firebit will carry out the Processing of the Personal Data indicated below, to the extent necessary to achieve any of the Processing purposes set forth in this Policy:

Registration Data

Collected at the time of account creation and Client registration on the Platform, as well as through updates made by the Data Subject themselves, or through Partners.

Personal Data: Full name, CPF (Brazilian taxpayer ID), ID number or equivalent document, date of birth, address, phone number, email address.

Verification and Compliance Data (KYC / AML)

Collected during identity verification and compliance procedures, carried out directly by Firebit or by specialized contracted service providers.

Personal Data: Identification document (ID card, driver's license, or equivalent), selfie or proof of life.

Financial and Transactional Data

Collected in the context of the execution of financial and crypto asset operations on the Platform.

Personal Data: Banking data (financial institution, account number, branch, Pix key), deposit and withdrawal history (on-ramp and off-ramp), order history, operations, and settlements involving crypto assets.

Contact Data

Collected when the Data Subject provides or updates information through forms, support channels, email, phone, or messaging apps.

Personal Data: Name, CPF, phone number, email address, communication history.

Platform Usage Data

Automatically collected during access to and use of the Platform.

Personal Data: IP address, access date and time, usage logs, cookies, device information, browser, and operating system.

Request Data

Collection occurs if the Data Subject makes requests for the exercise of one or more rights provided for in article 18 of the LGPD or other applicable legislation, by contacting Firebit through the available channels.

Personal Data: Name, Email, CPF, Date of Birth, Parentage, Identification Document Number, Photo, Content of the Request, Supporting Documents Provided by the Data Subject.

We always seek to limit the Processing of Personal Data to the minimum necessary to fulfill its purposes.

Firebit may anonymize your Personal Data whenever necessary to ensure your privacy or when required by applicable legislation. In this regard, Firebit may use anonymized data to obtain, among other things, statistical results useful for Firebit, provided that this is in accordance with applicable legislation.

Furthermore, we are committed to the right to privacy of children and adolescents, the protection of their personal information, and the promotion of good use of technology, so that we do not process Personal Data of minors, except in exceptional situations.

Firebit may collect other Personal Data and/or Sensitive Personal Data from the Data Subject, as necessary to achieve the purposes set forth in the section below and always in accordance with the criteria and procedures provided for in the LGPD.

In the context of providing its services, Firebit may receive Personal Data from third-party partners, such as financial institutions, partner companies, or technology service providers, when such data is necessary to enable the integrated provision of services or the referral of users to the Platform. In such cases, the Processing will observe the legal role played by each party, and the third party may act as an independent Controller, joint Controller, or Processor, depending on the definition of the purposes and means of Processing, under applicable legislation and the contractual instruments entered into between the parties.

You may, at any time, request specific information about which Personal Data is being Processed by Firebit through the support channel indicated in this Policy.

4. PURPOSES

Firebit seeks to carry out the Processing of your Personal Data always based on legitimate, specific, explicit, and informed purposes. In this regard, we detail below the main purposes that underpin the Processing of Personal Data and/or Sensitive Personal Data:

Registration and account creation on the platform

To enable the Client's registration, the creation and management of their account on the Platform, enabling access to the functionalities and services provided.

Data Group: Registration Data

Legal Basis: Performance of a contract or preliminary procedures

Identity verification and regulatory compliance (KYC / AML)

To identify and verify the Client, comply with legal and regulatory obligations, and prevent fraud, money laundering, and terrorism financing.

Data Group: Registration Data and Verification and Compliance Data

Legal Basis: Compliance with Legal or Regulatory Obligation

Execution of purchase, sale, and exchange operations of Virtual Assets

To enable the execution of orders, negotiations, settlement, and registration of operations involving Virtual Assets carried out by the Client.

Data Group: Registration Data, Financial and Transactional Data

Legal Basis: Performance of a contract or preliminary procedures

Sending service communications

To send communications related to the provision of services, such as notices, news, new products, and other information intended to improve the Client's experience.

Data Group: Registration Data

Legal Basis: Legitimate Interest

Communication and Support

To receive, analyze, and respond to questions, requests, complaints, and/or communications sent by Clients through Firebit's official channels.

Data Group: Contact Data

Legal Basis: Performance of a contract

Business Intelligence

To conduct statistical and aggregated analyses to evaluate performance, demand, Platform usage, and continuous improvement of services, whenever possible with anonymized data.

Data Group: Platform Usage Data and Financial and Transactional Data

Legal Basis: Legitimate Interest

Security, protection, and fraud prevention

To ensure the security of the Platform and information technology systems, prevent unauthorized access, security incidents, fraud, and illicit activities.

Data Group: Platform Usage Data, Verification and Compliance Data, and Financial and Transactional Data

Legal Basis: Compliance with Legal or Regulatory Obligation

Corporate Operations

To enable corporate reorganization operations, such as mergers, acquisitions, incorporations, or spin-offs, ensuring the confidentiality and protection of personal data.

Data Group: All Data

Legal Basis: Legitimate Interest

Data Subject Assistance

To analyze, respond, follow up on, and/or fulfill Data Subject requests for the exercise of rights provided for in the LGPD.

Data Group: Request Data

Legal Basis: Compliance with Legal or Regulatory Obligation

Compliance with judicial and/or administrative orders

To disclose to governmental authorities, when the request is made through subpoenas, court orders, or other legal proceedings, to establish or exercise legal rights, or to protect Firebit's property.

Data Group: All Data

Legal Basis: Compliance with Legal or Regulatory Obligation

Defense of Firebit's Rights

To defend Firebit's interests in administrative, arbitration, or judicial proceedings.

Data Group: All Data

Legal Basis: Regular Exercise of Controller Rights

Compliance with Legal Obligations

To comply with legal and/or regulatory obligations, such as those related to Firebit's tax and fiscal obligations, as well as other obligations related to applicable legislation on Virtual Assets.

Data Group: All Data

Legal Basis: Compliance with Legal or Regulatory Obligation

Transaction processing

To process deposits and withdrawals of fiat currency resources, including bank transfers and other payment methods available on the Platform.

Data Group: Registration Data, Financial and Transactional Data

Legal Basis: Performance of a contract or preliminary procedures

You may, at any time, request specific information about the Processing of your Personal Data by Firebit, through the support channel indicated in this Policy.

5. SHARING OF PERSONAL DATA

In some situations, in order to provide our services according to the quality standards you expect, Firebit may share some of your Personal Data with third parties, such as, for example:

  • Service providers and operational partners, such as financial institutions, payment service providers, other Virtual Asset Service Providers and Partners, digital asset custodians, identity verification providers (KYC), fraud prevention and anti-money laundering (AML) providers, as well as technological infrastructure, cloud computing, data storage, backup, information security monitoring, and technical support suppliers, to the extent necessary for the enablement and execution of contracted services;
  • Public bodies, administrative, regulatory, or judicial authorities, including tax and financial authorities, when sharing is necessary for compliance with legal or regulatory obligations, compliance with judicial or administrative orders, or for the regular exercise of Firebit's rights in administrative, arbitration, or judicial proceedings; and
  • Third parties involved in corporate operations, such as mergers, spin-offs, acquisitions, incorporations, or any other corporate reorganization involving Firebit, in which case sharing will occur in a manner compatible with the purposes of this Policy and through the adoption of adequate confidentiality and personal data protection measures.

In the context of providing services, Firebit shares personal data and operational information with a company within the same ecosystem responsible for the custody and infrastructure of crypto assets, exclusively to enable the safekeeping, movement, security, and traceability of users' crypto assets, within the limits necessary for the execution of services.

We emphasize that the sharing of Personal Data by Firebit will be carried out through the adoption of adequate technical, administrative, and organizational measures, designed to ensure the confidentiality, integrity, and availability of information, as well as compliance with security standards required by applicable legislation and market best practices.

In the event of engaging third parties, Firebit will use its best efforts to verify that such third parties have adequate technical, organizational, and legal structures for the processing of personal data, requiring, whenever applicable, compliance with contractual obligations related to information security, confidentiality, and personal data protection.

6. THIRD-PARTY WEBSITES AND APPLICATIONS

We remind you that this Policy applies exclusively to Processing activities carried out by Firebit within the scope of its Platform and its services. This Policy does not apply to websites, applications, platforms, or third-party services accessed through links, technical integrations, or redirects made available on the Platform.

The provision of links, integrations, or references to third-party services does not, by itself, imply any endorsement, sponsorship, or responsibility on the part of Firebit in relation to such third parties, nor regarding the Processing practices they adopt.

7. INTERNATIONAL TRANSFER OF PERSONAL DATA

Within the scope of its activities, Firebit may carry out the international transfer of Personal Data to third parties located outside Brazil, exclusively when such transfer is necessary for the execution of its operations, the use of technological infrastructure, compliance with legal or regulatory obligations, or ensuring the security and continuity of its services.

Such transfers may be carried out for activities such as (i) secure storage and preservation of Personal Data, in order to ensure availability, integrity, and confidentiality of information, (ii) execution of operational and administrative activities, including backup, replication, and data recovery, (iii) use of specialized suppliers located in other countries, and (iv) to ensure compliance with Firebit's legal and/or regulatory obligations. Given the purpose of storage on corporate cloud servers, in addition to compliance with legal and regulatory obligations in the context of operations, all Personal Data under processing may be subject to international transfer.

Personal Data may be transferred and processed in different locations, depending on the needs of Firebit's operations. In this regard, transfers may occur to countries where Firebit's servers, applications, and services are located, as well as countries where other Firebit suppliers are located.

Data Subjects have the right to request more information about the sharing of their Personal Data, and may contact us through the channel indicated in this Policy.

The international transfer of Personal Data may be carried out for the time necessary to fulfill the purposes indicated in this Policy and considering other contracts and/or agreements entered into with third parties and/or clients. The sharing period may vary depending on the nature of the Personal Data transferred, the purposes, and other applicable legal requirements.

International transfers of Personal Data, when they occur to recipients located in countries outside Brazil that do not offer an adequate level of Personal Data protection, will be based on the existence of appropriate safeguards.

8. STORAGE PERIOD

Personal Data will be stored by Firebit for the period necessary and according to the purposes for which it was collected. This data will be retained for a period defined according to:

  • the period required by laws, resolutions, and/or other regulations to which Firebit is subject;
  • the time necessary to achieve the purpose of the Processing of Personal Data, as listed in this Policy;
  • the time necessary to preserve Firebit's legitimate interest, as applicable; or
  • the time necessary to safeguard the regular exercise of Firebit's rights in judicial, administrative, or arbitration proceedings, including in accordance with applicable statute of limitations.

Except in cases where legislation authorizes the retention of your Personal Data by Firebit, they will be deleted when:

  • the purpose of the Processing has been achieved;
  • the Personal Data is no longer necessary or relevant to achieve the specific intended purpose;
  • in applicable cases, you exercise your right to revoke Consent, by means of communication; or
  • there is a determination by the ANPD, in case of violation of the LGPD.

You may, at any time, request the deletion of your Personal Data stored by Firebit, provided that such data (i) is unnecessary, excessive, or processed in non-compliance with the LGPD, or (ii) was provided through the granting of Consent. The deletion request may be made through the support channel indicated in this Policy.

Firebit commits to making its best efforts to fulfill all Personal Data deletion requests as quickly as possible, provided that they are permitted under applicable legislation.

9. WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?

As a Data Subject, you have a series of rights provided for by the LGPD, which are:

  • Confirmation of the existence of Processing: you may request Firebit to confirm that your Personal Data is being processed.
  • Access to Personal Data: you may request Firebit for access to Personal Data under Processing. In this case, Firebit will provide, by electronic or physical means, a copy of your Personal Data stored by us. Firebit cannot provide Personal Data of other Data Subjects.
  • Correction or updating of Personal Data: you may request the correction or updating of your Personal Data when it is inaccurate, incomplete, or outdated. Before updating your Personal Data, Firebit may request documents and/or information that prove the information provided.
  • Request Anonymization, blocking, or deletion of Personal Data: you may request that unnecessary, excessive Personal Data or data processed in non-compliance with the LGPD be anonymized, blocked, or deleted from Firebit's database.
  • Personal Data Portability: you may request the migration of your Personal Data collected by Firebit to another organization after regulation on the subject by the ANPD.
  • Deletion of Personal Data: you may request the deletion of your Personal Data processed by Firebit based on your Consent, at any time, through a free and facilitated expression, and Personal Data will not be deleted in cases where retention is authorized by the LGPD.
  • Information about the sharing of Personal Data: you may request information about the sharing of your Personal Data with third parties.
  • Information about the possibility of not providing Consent: you may request information about the possibility of not providing Consent for the Processing of your Personal Data by Firebit, at which time Firebit will inform you of the consequences of this refusal, which, in some situations, may make it impossible to offer certain products and services.
  • Revocation of Consent: you may revoke the Consent provided to Firebit for the Processing of Personal Data for certain purposes, at any time. However, the withdrawal of Consent (a) will not affect the legitimacy of Processing carried out previously, nor will it prejudice Processing carried out based on other legal bases; and (b) may make it impossible to continue some services.
  • Objection to Processing: you may object to the Processing of Personal Data carried out by Firebit based on one of the legal hypotheses of Consent waiver that is not in line with the provisions of the LGPD.
  • Review of automated decisions and explanation: you may request that Firebit review decisions made solely on the basis of automated Processing of Personal Data that affect your interests, including decisions intended to define your personal, professional, consumer, credit profile, or aspects of your personality, and you may also request clear and adequate information regarding the criteria and procedures used for the automated decision, subject to trade and industrial secrets.

The exercise of Data Subject rights must be carried out exclusively through the contact channels indicated in this Policy, which are available on the Firebit Platform, at which time Firebit will analyze and respond to requests within the periods and terms provided for in applicable legislation, and may, when necessary, request additional information for purposes of confirming the identity of the Data Subject and the legitimacy of the request.

To fulfill the rights exercised under this section and to ensure the security of Personal Data, Firebit may request information and documents for purposes of verifying the identity and authenticity of the requesting Data Subject.

10. SECURITY IN THE PROCESSING OF YOUR PERSONAL DATA

Firebit employs reasonable efforts to ensure the security of systems used in the Processing of Personal Data in an effort to, among other things, prevent incidents that may compromise your privacy and the protection of your Personal Data. Among the initiatives taken by Firebit, we mention:

  • Technical, physical, and administrative measures capable of keeping Personal Data secure and protected from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or any other form of inadequate or unlawful Processing, in compliance with applicable data protection and information security rules, including standard data encryption/encoding in accordance with market best practices;
  • Maintenance of all information in a confidential manner, so that only persons responsible for ensuring the correct use of such information have access to it; and
  • Awareness of Firebit employees on good compliance practices and Personal Data protection, in compliance with the LGPD.

The Platform may contain links that direct you to other pages, including those of partners, that have policies with provisions different from those set forth in this document. Therefore, Firebit is not responsible for the collection, use, sharing, and storage of information and/or Personal Data by those responsible for such pages outside the Firebit Platform domain.

Firebit makes its best efforts to preserve the confidentiality, integrity, and availability of the Personal Data of its Data Subjects. However, no institution can be considered immune to attacks such as unauthorized access perpetrated through methods developed to improperly obtain information. For this reason, we encourage you to take appropriate measures to protect yourself, such as keeping all usernames and passwords confidential, adopting two-factor authentication, among others.

11. HOW TO CONTACT US

If you have any questions or comments related to this Policy and questions related to the topic of Data Protection, please contact us through our Data Protection Officer.

Data Protection Officer: Felipe Fernandes Coelho.

Email: compliance@Firebit.com.

12. GENERAL PROVISIONS

This Policy may be reviewed at any time and without prior notice, taking into consideration, among other points, applicable legislation and organizational changes that may occur at any time, in order to maintain its relevance and effectiveness. The most current version of this policy will always be available at https://www.firebit.pro/privacy-policy .

If we make any significant change to this Policy that, in our judgment, is substantial, you may become aware of the changes to the Policy by accessing our website, where the updated version will be published, with an indication in the appropriate channels about such relevant update.

By continuing to access or use our services after the effective date of such change, you accept and agree to be bound by the revised version of the Policy.

This Policy shall be governed and interpreted in accordance with the laws of the Federative Republic of Brazil and shall take effect on the date of its publication.