Riot

Privacy Policy

RiotPay (SDFG CAPITAL PTY LTD) privacy policy. Last updated: June 15, 2026.

SDFG CAPITAL PTY LTD PRIVACY POLICY

LAST UPDATED: 11 June 2026. 

CONTROLLER: SDFG Capital Pty Ltd, a company incorporated under the laws of Australia with company number ACN 678 656 829, whose registered office is at 49 Torrington Drive, Marsfield, NSW 2122, Australia

DPO CONTACT: [e-mail]

This Privacy Policy explains how we process personal data when you visit our website, submit an enquiry, or (if you become a client) use our App. We comply with:

GDPR (EU) 2016/679 and UK GDPR (for individuals in the EEA and UK);

Australian Privacy Act 1988 (APPs) (for all individuals, regardless of location);

Asian data protection laws where applicable, including but not limited to:

– Singapore: Personal Data Protection Act (PDPA)

– Hong Kong: Personal Data (Privacy) Ordinance (PDPO)

– Japan: Act on the Protection of Personal Information (APPI)

– Malaysia: Personal Data Protection Act (PDPA)

– Thailand: Personal Data Protection Act (PDPA)

– South Korea: Personal Information Protection Act (PIPA)

In case of conflict, the stricter protection (generally GDPR) applies to EEA/UK users. Asian users retain all rights granted by their local laws.

1. WHAT PERSONAL DATA WE COLLECT AND WHY 

Data category

Examples

Purpose

Legal basis (GDPR)

Retention

Enquiry form data

Name, company, email, phone, message

Respond to request, provide pricing, begin onboarding

Article 6(1)(b) – steps at request of data subject before contract

6 months after last contact

Technical & analytics

IP address (anonymised in GA), browser, device, referring URL, pages visited

Security, website improvement, analyse usage

Legitimate interest (Article 6(1)(f)) – after consent for non-necessary cookies

2 years (aggregated)

Cookies (non-essential)

Analytics cookies (Google Analytics)

As above

Consent (Article 6(1)(a) + ePrivacy)

Up to 14 months

Client data (if onboarded)

ID, proof of address, UBO, transaction data

KYC/AML, provide banking/OTC services

Legal obligation (Article 6(1)(c) – AML laws) + performance of contract

7 years after account closure

Special categories: We do not process biometric or health data except for liveness checks (which are not stored). Criminal offence data (sanctions, PEP) processed under Art. 6(1)(c) and Art. 10 GDPR.

2. DATA SHARING AND INTERNATIONAL TRANSFERS

We share data with:

  1. Service providers (processors): Google (analytics), [other]. All processors are bound by Data Processing Agreements compliant with GDPR Standard Contractual Clauses (SCCs).
  2. Identity verification partners (for onboarding only): Sumsub, [other].
  3. Australian authorities (AUSTRAC, ASIC, court order).
  4. Banking partners and crypto liquidity providers (for OTC execution).

International transfers outside EEA/UK: we rely on SCCs and UK International Data Transfer Agreement (where applicable) and supplementary measures (encryption, pseudonymisation).

For Australian APP 8: we ensure overseas recipients comply with APPs or we remain liable.

Transfer to Australia: the European Commission has not issued an adequacy decision for Australia. Therefore, we implement SCCs and obtain your explicit consent (by using our website and submitting an enquiry) for such transfers. You may withdraw consent, but then we cannot respond to your enquiry.

For Asian countries users: where required by local law, we obtain your separate consent for cross‑border data transfers to countries without adequacy recognition. You may withdraw such consent at any time.

3. YOUR RIGHTS UNDER GDPR (FOR EEA AND UK USERS)

Under GDPR, you have the right to:

  1. Access (Art. 15): confirmation of processing, copy of data.
  2. Rectification (Art. 16): correct inaccurate data.
  3. Erasure (Art. 17): “right to be forgotten”, unless we have a legal obligation (AML) to retain.
  4. Restriction (Art. 18): pause processing while a complaint is resolved.
  5. Data portability (Art. 20): receive a machine‑readable copy.
  6. Object (Art. 21): to processing based on legitimate interests (e.g., analytics).
  7. Withdraw consent (Art. 7(3)): at any time without detriment.
  8. Lodge a complaint (Art. 77): with your local supervisory authority.

To exercise your rights, email legal@riotpay.com. We will respond within one month (extendable by two months for complex requests). No fee, unless manifestly unfounded.

4. YOUR RIGHTS UNDER ASIAN COUNTRIES DATA PROTECTION LAWS

Depending on your jurisdiction in Asia, you may have the following rights:

Jurisdiction

Key rights (in addition to GDPR rights)

Singapore (PDPA)

Right to access, correct, withdraw consent, and data portability (for certain data). You may complain to the Personal Data Protection Commission (PDPC).

Hong Kong (PDPO)

Right to request access to and correction of your personal data. Direct marketing opt-out. Complaint to the Privacy Commissioner.

Japan (APPI)

Right to be informed of purpose, access, correction, deletion, cessation of use (if violation). Complaint to the PPC.

Malaysia (PDPA)

Right to access, correct, withdraw consent, and prevent processing for direct marketing. Complaint to the Personal Data Protection Department.

Thailand (PDPA)

Rights to access, rectification, erasure, restriction, portability, object. Complaint to the Personal Data Protection Committee.

South Korea (PIPA)

Right to access, correct, delete, suspend processing. Complaint to the Personal Information Protection Commission (PIPC).

We will honour these rights to the extent required by your local law. For any request, contact [e-mail]. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority. 

5. YOUR RIGHTS UNDER AUSTRALIAN PRIVACY ACT (APP)

In addition to GDPR rights, Australian users can also:

  1. Request us to not disclose your data to overseas recipients, but this may prevent us from providing services.
  2. Complain to the Office of the Australian Information Commissioner (OAIC) www.oaic.gov.au.

We will handle privacy complaints internally within 30 days.

6. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies only with your prior consent (except strictly necessary ones). See our Cookie Policy for details and how to withdraw consent.

7. DATA RETENTION AND DELETION

Enquiry data: deleted after 6 months if no further interaction.

Client data: deleted 7 years after account closure (AML requirement).

Analytics data (Google Analytics): 14 months (then automatically deleted).

Backup logs: retained up to 90 days.

Destruction methods: secure electronic deletion (overwriting), shredding of paper records.

8. AUTOMATED DECISION-MAKING AND PROFILING

We do not make solely automated decisions that have legal or significant effects on you based solely on website activity. For clients, the App may use automated scoring for fraud and AML: you will be informed in the App Terms and have the right to human review.

9. CONTACT AND EU REPRESENTATIVE

Data Controller: SDFG Capital Pty Ltd, a company incorporated under the laws of Australia with company number ACN 678 656 829, whose registered office is at 49 Torrington Drive, Marsfield, NSW 2122, Australia

Data Protection Officer (DPO): legal@riotpay.com

10. CHANGES TO THIS PRIVACY POLICY

SDFG Capital Pty Ltd reserves the right to reasonably amend this Privacy Policy from time to time. You should check our website frequently to see recent changes. We will update the “Last Updated” date accordingly at the beginning of this Privacy Policy. We will announce any material changes to this Privacy Policy on our website / platform or by sending an email to the email address that you have provided under your account. Your continued use after the changes to this Privacy Policy means that you understand such changes. Unless stated otherwise, our most recent Privacy Policy  applies to all information that we have about you and your account.