Privacy Policy

Your data, explained honestly

Last updated: April 2025 · Version 2.0

YandexyWin is committed to handling your personal data with transparency, care, and respect for your rights. This Policy explains what we collect, why we collect it, how we protect it, and the controls you have over it. We comply with the General Data Protection Regulation (GDPR) and equivalent data protection frameworks.

Introduction & Scope

This Privacy Policy applies to all personal data processed by YandexyWin in connection with your use of our platform, website, and services. It covers data collected when you register, make transactions, communicate with us, or interact with Yandexy AI. YandexyWin acts as the data controller for the purposes of GDPR. Where we engage third-party processors, we ensure adequate contractual protections are in place.

Information We Collect

We collect: identity data (name, email address, phone number, government ID for KYC); financial data (wallet addresses, transaction history, investment records); technical data (IP address, browser type, device identifiers, login timestamps); communication data (support messages, AI chat history where stored); and usage data (pages visited, features accessed, error logs). We do not collect payment card data — all transactions are handled via the Tron blockchain.

How We Use Your Information

We process your data to: operate and maintain your account; process deposits and withdrawals; calculate and distribute commissions and bonuses; verify your identity and comply with AML/KYC obligations; detect and prevent fraud and abuse; personalise your experience and deliver platform communications; improve our services through aggregate analytics; and respond to support requests. We do not use your data for automated decision-making that produces legal effects without human review.

Legal Basis for Processing (GDPR)

We rely on the following legal bases: contractual necessity — processing required to deliver the service you have contracted for; legal obligation — KYC, AML, and financial record-keeping requirements; legitimate interests — fraud prevention, security monitoring, and platform improvement, provided these do not override your fundamental rights; and consent — where we send optional marketing communications or process data beyond what is strictly necessary, we will ask for your explicit consent and honour any withdrawal of that consent promptly.

Cookies & Tracking Technologies

We use strictly necessary cookies to maintain your authenticated session and remember your language preference. We do not use third-party advertising or tracking cookies. Analytics data is collected using a self-hosted, privacy-preserving tool that does not share data with third parties. You can control cookie behaviour through your browser settings; disabling session cookies will prevent you from logging in.

Data Sharing & Third Parties

We do not sell your personal data. We share data only with: service providers who assist in operating the platform (cloud infrastructure, email delivery, blockchain node providers) under strict data processing agreements; regulatory authorities and law enforcement where required by law; and — with your explicit consent — any other parties. All third-party providers are assessed for data protection compliance before engagement and are contractually prohibited from using your data for their own purposes.

Blockchain & On-Chain Data

Transactions executed on the Tron blockchain are inherently public and permanent. Your USDT TRC-20 wallet address and associated transaction amounts are visible on-chain to anyone who queries the public ledger. YandexyWin cannot delete or modify on-chain records. We minimise the data linked to your identity on-chain, but you should be aware that blockchain pseudonymity is distinct from full anonymity.

Data Retention

We retain account data for as long as your account is active. Financial records — including transaction history, commission logs, and KYC documents — are retained for a minimum of five years after account closure to comply with financial regulation. Aggregated, anonymised analytics data may be retained indefinitely. You may request deletion of non-mandatory data at any time, subject to our legal retention obligations.

Your Rights (GDPR & Equivalent Frameworks)

Depending on your jurisdiction, you have the right to: access a copy of all personal data we hold about you; rectify inaccurate data; erasure of data we are not legally required to retain ('right to be forgotten'); restriction of processing in certain circumstances; portability of your data in a machine-readable format; object to processing based on legitimate interests; and withdrawal of consent at any time where consent is the legal basis. To exercise these rights, contact [email protected]. We will respond within 30 days.

Security of Your Data

We implement technical and organisational measures proportionate to the risk of processing your data, including TLS 1.3 encryption in transit, AES-256 encryption at rest, bcrypt password hashing, role-based access controls, and audit logging of all administrative actions. In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

International Data Transfers

YandexyWin may transfer personal data to countries outside the European Economic Area in connection with cloud infrastructure or service providers. Where such transfers occur, we ensure adequate safeguards are in place — typically Standard Contractual Clauses approved by the European Commission or equivalent mechanisms. You can request information about the safeguards we apply to specific transfers by contacting [email protected].

Children's Privacy

The YandexyWin platform is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered an account, please contact us immediately at [email protected] and we will take prompt action to close the account and delete any associated data.

Changes to This Policy & Contact

We may update this Privacy Policy as our practices evolve or as required by law. Material changes will be communicated via platform notification at least 14 days before taking effect. The version history is maintained at yandexywin.com/privacy. For data protection queries, to exercise your rights, or to contact our Data Protection Officer, write to [email protected]. We take every inquiry seriously and will respond within the timescales required by applicable law.