Legal
Privacy Policy
Last updated August 11, 2026
This policy explains how Cosmir Digital Ltd. collects, uses, discloses, and protects personal information in the course of providing institutional digital asset execution and infrastructure services.
01Who we are
Cosmir Digital Ltd. is the organisation responsible for the personal information described in this policy. We are incorporated under the laws of Ontario, Canada, with Ontario Business Registry ID 1001352548 and registered office at 1907 Baseline Road, Unit 104, Ottawa, Ontario, K2C 0C7, Canada.
Privacy enquiries may be directed to our privacy contact at desk@cosmirdigital.com.
Our services are provided to corporate and institutional counterparties. The personal information we handle relates primarily to individuals connected to those entities, such as directors, officers, authorised signatories, beneficial owners, and operational contacts.
02Information we collect
Corporate and representative information: entity name, registration and licensing details, registered and operating addresses, and the names, roles, business contact details, dates of birth, nationalities, and identification documents of representatives and beneficial owners.
Verification and compliance information: identity verification results, sanctions, politically exposed person and adverse media screening results, source-of-funds and source-of-wealth documentation, and records of compliance decisions.
Transaction information: instructions, quotes, confirmations, wallet addresses, blockchain transaction data, counterparty information required for Travel Rule purposes, and associated correspondence.
Technical information: server logs, IP address, browser and device information, and security event records generated when you use our website or systems.
03How we use information
To assess, onboard, and maintain counterparty relationships, including know-your-business and know-your-customer verification.
To provide, operate, and settle the services, including execution, transfer, reconciliation, and reporting.
To meet legal and regulatory obligations, including those under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and related regulations, sanctions legislation, record-keeping and reporting requirements, and applicable payment services requirements.
To manage risk and prevent, detect, and investigate fraud, sanctions evasion, market abuse, and other unlawful activity; to secure our systems; and to establish, exercise, or defend legal claims.
To communicate with authorised representatives about the relationship and the services.
04Our basis for handling information
In Canada we rely on consent, express or implied, where required, and on the exceptions to consent permitted under applicable privacy legislation, including where collection, use, or disclosure is required or authorised by law, is necessary to investigate a breach of an agreement or a contravention of law, or is made for the purposes of a business transaction.
Where the General Data Protection Regulation applies to our handling of personal data, we rely on the performance of a contract, compliance with a legal obligation, our legitimate interests in operating and securing a regulated business, and, where relevant, the establishment or defence of legal claims.
05Disclosure of information
Service providers: identity verification and screening providers, blockchain analytics providers, custody and transfer infrastructure providers, Travel Rule messaging networks, cloud hosting providers, and professional advisers. Providers act on our instructions under contractual confidentiality and security obligations.
Authorities and regulated counterparties: FINTRAC, law enforcement, regulators, tax authorities, and courts where required or authorised by law; and originating or beneficiary institutions where transfer of counterparty information is required by Travel Rule or equivalent obligations.
Corporate transactions: prospective or actual acquirers, investors, or successors in connection with a business transaction, subject to appropriate safeguards.
We do not sell personal information and do not use it for third-party advertising.
06International transfers
Some of our service providers process information outside Canada, including in the United States, the United Kingdom, and the European Economic Area. Where information is processed in another country it may be accessible to the courts, law enforcement, and national security authorities of that country.
We use contractual and organisational safeguards, including standard contractual clauses where applicable, to protect information transferred across borders.
07Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls on a need-to-know basis, encryption of data in transit and at rest, segregation of production environments, logging and monitoring, vendor due diligence, and staff confidentiality and training obligations.
No method of transmission or storage is entirely secure. We maintain incident response procedures and will notify affected individuals and regulators of a breach where required by law.
08Retention
We retain identification, transaction, and compliance records for the periods required by Canadian anti-money laundering legislation, which generally require retention for at least five years after the end of the relationship or the date of the transaction, and longer where another legal obligation, limitation period, or investigation requires it.
Information that is no longer required for a legal or business purpose is deleted or de-identified in accordance with our retention schedule.
09Your rights
Subject to applicable law, you may request access to the personal information we hold about you, request correction of inaccurate or incomplete information, withdraw consent where consent is the basis for our handling, and make a complaint about our handling of your information.
Some information cannot be disclosed or deleted, for example where doing so would reveal a suspicious transaction report, compromise an investigation, breach a legal obligation, or affect the privacy of another person.
To exercise a right, contact desk@cosmirdigital.com. We will respond within the time required by applicable law and may need to verify your identity first. If you are not satisfied with our response you may contact the Office of the Privacy Commissioner of Canada or, where applicable, your local supervisory authority.
10Website, cookies and analytics
Our website is a static informational site. It does not host account access, contact forms, advertising trackers, or third-party analytics or marketing cookies.
Our hosting provider processes standard server logs, including IP address and request metadata, for security, availability, and abuse prevention purposes. Only cookies strictly necessary for delivering and securing the site may be set.
11Changes to this policy
We may update this policy to reflect changes in our services, providers, or legal obligations. The date at the top of this page indicates when it was last revised. Material changes will be notified to onboarded counterparties through the usual channels of communication.
Questions regarding this document may be directed to desk@cosmirdigital.com. See also our Terms of Service.