RONin EM

RONIN EM Privacy Policy

Last Updated: November 2025


Introduction

This privacy policy (the **"Policy"**) explains how Ronin EM Limited and, where applicable, its affiliated entities (collectively, **"Ronin EM"**, **"we"**, **"us"** or **"our"**) collect, use, store and disclose personal information through our websites (including https://em.ron.in/), web platforms, mobile applications and other online products and services that link to, reference or otherwise apply this Policy (collectively, the **"Services"**), or when you otherwise interact with us.

Ronin EM is a licensed Crypto Asset Services Provider (**"CASP"**) authorised and regulated by the Cyprus Securities and Exchange Commission (**"CySEC"**). We provide, among other things, services relating to exchange between crypto-assets and fiat currency, exchange between crypto-assets, custody and safekeeping of crypto-assets and cryptographic keys, and other crypto-asset related and investment services made available to you from time to time via the Services (collectively, the **"Ronin EM Services"**).

We encourage you to read this Policy carefully as it forms part of the terms and conditions, terms of business, agreement with you and/or terms of use applicable to the Services (collectively, the **"Terms"**). By accessing or using the Services, you acknowledge that you have read and understood this Policy.

If you accept or agree to this Policy on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to this Policy and, in such event, **"you"** and **"your"** will refer and apply to that company or other legal entity.

Application of this Policy

For the purposes of applicable data protection laws (including, where applicable, the EU **General Data Protection Regulation ("GDPR")**), **Ronin EM Limited is the "controller"** of the personal information collected via em.ron.in, any other Ronin EM websites, widgets, mobile applications and other platforms that link to this Policy (together, the **"Site"**). Ronin EM is the entity to contact if you have questions about our use of your personal information (see the "Contact Us" section below).

This Policy also applies to personal data about each **authorised representative** of a client and about other **natural persons** whose personal data we process in the course of providing the Services (for example, directors or beneficial owners of corporate clients, payees, and other connected individuals).

Collection of Information

Information You Provide to Us

We collect information that you provide **directly to us**. For example, we collect information when you create an account with Ronin EM (**"Ronin EM Account"**), subscribe for or use any of the Services, participate in interactive features of the Services, fill out a form, participate in a promotion or campaign, complete a survey, make a transaction, communicate with us via third-party social media sites, request customer support, or otherwise communicate with us.

When You Sign Up or Register for a Ronin EM Account or Services

If you sign up for a Ronin EM Account or otherwise use the Services, we will collect **basic information** about you, which typically includes your name, email address, telephone number, and any other contact details you choose to provide. You may provide this information to us directly, or by signing in to the Services using a third-party authentication provider (for example, where available, via a social network or single-sign-on provider).

We use the information that we collect about you at registration to:

  1. Create and maintain your Ronin EM Account;
  2. Allow you to log in and access the Services; and
  3. Contact you about your Ronin EM Account and/or the Services, which may include service messages, regulatory updates and, where permitted, marketing communications.

When You Provide Information to Complete Onboarding and Build Your Profile

Once you have created a Ronin EM Account, we are required to collect **additional information** in order to comply with anti-money laundering, counter-terrorist financing, sanctions, fraud-prevention, and other regulatory obligations, and to enable you to make full use of the Services.

This may include collecting copies of **identification documents** (such as your passport, national identity card, residence permit, or visa), **proof of address** (such as a recent utility bill or bank statement) and other information or documentation required for our **"know your customer" ("KYC") checks**.

Depending on the Services you use and the jurisdiction in which you are located, we may also ask you to provide additional information such as your gender, date and place of birth, nationality, citizenship and residency status, tax identification number, employment status, occupation, employer, source of funds and source of wealth, approximate annual income, overall financial situation, investment experience and objectives, risk tolerance and any other details that may be required to conduct suitability or appropriateness assessments.

It may be optional for you to provide some of this information; however, for legal and regulatory reasons we will not be able to provide certain features or Services to you unless you provide the information we are required to collect.

We use the information you provide during onboarding and in your profile to, among other things:

  • Verify your identity and conduct checks that we are required to carry out under applicable laws and regulations, including KYC, anti-money laundering, sanctions, fraud, and politically exposed person (**"PEP"**) checks;
  • Contact you on matters related to your Ronin EM Account and the Services, including to request additional information or documentation;
  • Provide you with notices related to your Ronin EM Account, regulatory and security updates, and market or product information;
  • Tailor the Services, content and features presented to you, including performing suitability or appropriateness assessments in relation to certain products;
  • Assess and manage credit, liquidity, and other risks;
  • Set up and maintain security measures to protect your account (including, where enabled, multi-factor authentication); and
  • Maintain administrative records and otherwise provide and manage the Services.

You can review and update certain profile information via your account settings. You should ensure that your information is accurate and up to date and promptly inform us of any material changes. We may rely on the accuracy of the information provided and you are responsible for any loss or damage that may arise from any inaccuracies.

When You Contact Us

If you contact us by telephone, video call, email, post, live chat, ticketing system, or similar communication channel, we will collect information about your communication with us, including the content of the communication and any additional information you choose to provide. We use this information to review, investigate, and respond to your enquiry, to improve our Services, and for training and quality-assurance purposes.

We may record and retain telephone calls, video calls, and other communications with you (where permitted or required by law) and may use such recordings for compliance, dispute-resolution, and fraud-prevention purposes.

Information About Your Use of the Services

Usage and Automatically Collected Information

When you access or use the Services, we automatically collect certain information about you and your activity, which may include:

  • **Financial and Transaction Information:** information relating to your use of the Services, such as details of trades and other transactions you carry out via the Services (for example, the type of asset, amount, price, timestamps, counterparties, wallet addresses and payment methods used), account balances, margin or collateral information (where applicable), and related records.
  • **Log Information:** information about your use of the Services, including access times and dates, pages viewed, IP address and other network identifiers, the web page visited before navigating to our Site, and standard server logs.
  • **Device Information:** information about the computer or mobile device you use to access the Services, such as hardware model, operating system and version, unique device identifiers, and mobile network information.
  • **Activities on the Site:** records of activity on the Site and within your Ronin EM Account, including your account settings, security changes, login attempts, notifications, consents, and preferences, as well as records of deposits, withdrawals, and other transactions.
  • **Location Information:** depending on your device and browser settings, we may collect or derive information about the approximate geo-location of your device. We may use location information for fraud-prevention, security, regulatory and analytics purposes, and, where appropriate, to ensure that certain products are only offered in jurisdictions where they are permitted.
  • **Cookies and Similar Technologies:** we and our service providers use cookies, pixels, web beacons, local storage, and similar technologies to collect and store information when you visit our Site, use our applications or interact with emails. These technologies help us recognise your browser or device, remember your preferences, analyse trends, improve the Services, and tailor content and advertising. For more information, please refer to our Cookie Policy, which forms part of this Policy.

Information We Collect from Other Sources

We may receive personal information about you from third parties, including:

  • Identity-verification providers, credit-reference agencies, fraud-prevention agencies, sanctions-screening providers, and similar bodies, which we use to help verify your identity, detect and prevent fraud and financial crime, and meet our legal and regulatory obligations;
  • Financial institutions, payment service providers, blockchain analytics providers and liquidity providers in connection with payments, transfers, clearing and settlement of your transactions;
  • Public sources, such as public registers, company registries, enforcement databases, sanctions lists and social-media platforms; and
  • Where you choose to connect your Ronin EM Account to a third-party platform or service (such as a wallet, exchange, social-network, or authentication provider), we may receive information from that third party in accordance with your settings and the third party's privacy policy.

We may combine information we receive from third parties with information we collect directly from you or automatically through the Services and treat the combined information as personal data in accordance with this Policy.

Unsolicited Information

If you provide us with personal information that we have not requested, we will handle it in accordance with this Policy. If we reasonably determine that such information is not required for the purposes described in this Policy, we will endeavour to delete it or anonymise it, provided that it is not mixed with information that we are required or entitled to retain. Where such information is mixed, you acknowledge that it may be retained and processed by us in the same manner as the rest of your personal information.

Use of Information

We use the information we collect about you for the following purposes (to the extent permitted by applicable law):

  • To provide, operate, administer, and improve the Services, including to open and maintain your Ronin EM Account, to process and execute your orders and transactions, to facilitate deposits, withdrawals, and transfers, and to provide customer support;
  • To carry out our obligations arising from the Terms and to enforce our rights under those Terms;
  • To comply with applicable laws and regulations, including those relating to anti-money laundering, counter-terrorist financing, sanctions, tax, anti-fraud, and consumer protection;
  • To conduct identity verification, security, and fraud-prevention checks, and to monitor for suspicious activity;
  • To monitor, investigate and manage enquiries, complaints, disputes, and legal proceedings, and to comply with court orders, mandatory dispute-resolution determinations and mandatory orders or directions from government authorities or law-enforcement agencies;
  • To monitor and analyse the performance, usage, security, and stability of the Services, and to develop new products, features and offerings;
  • To compile statistics and analytics for business, risk-management, reporting and marketing purposes;
  • To personalise and tailor your experience with the Services, including by presenting customised content, recommendations, and communications;
  • To send you service, transactional, and administrative messages, including information about changes to our terms, policies, features or technical issues; and
  • Where permitted by law and your preferences, to send you information, updates and marketing communications regarding products and services offered by Ronin EM or our partners, and to measure the effectiveness of such communications; and
  • To facilitate any actual or contemplated reorganisation, merger, acquisition, financing, sale of assets or similar corporate transaction involving Ronin EM.

Sharing of Information

We do not sell your personal information.

We may share your personal information with third parties in the following circumstances and for the purposes described in this Policy:

  • Within Ronin EM Limited and any affiliated companies (collectively, the **"Ronin EM Group"**), for purposes consistent with this Policy;
  • With professional advisers, vendors, consultants, and other service providers who need access to such information to carry out work on our behalf, including IT and hosting providers, payment service providers, blockchain analytics and screening providers, cloud-infrastructure providers, auditors, legal, and analytics providers, and other outsourced service providers;
  • With banks, payment institutions, card schemes, liquidity providers, custodians, wallet providers and other financial institutions as necessary to process payments, settle transactions, provide custody and safekeeping services, and otherwise provide the Services;
  • With counterparties, intermediaries and other third parties involved in or connected to your transactions, to the extent necessary to execute and settle such transactions and to meet our legal and regulatory obligations;
  • With third-party platforms, applications, or services where you choose to connect, link or integrate your Ronin EM Account with such services;
  • In connection with, or during negotiations of, any merger, sale of company assets, financing, acquisition, or other corporate transaction involving Ronin EM, in which personal information may be transferred as part of the transaction, subject to appropriate confidentiality protections;
  • To competent courts, regulators, law-enforcement agencies, and other public authorities where we believe disclosure is necessary or appropriate to comply with applicable laws or regulatory requirements, to respond to legal process, or to protect our rights, property, operations, users, or others; and
  • With your consent or at your direction, for example where you instruct us to share your information with a third party or expressly authorise a third-party integration.

We require all third-party recipients of your personal information (other than public authorities acting in an official capacity) to process your personal information only on our instructions and in accordance with this Policy and applicable law, and to implement appropriate technical and organisational measures to protect your data.

Business Partners

We may maintain relationships with business partners, such as liquidity providers, counterparties, custodians, banking partners, and other financial institutions, to offer or provide you with additional or supplemental services. Where necessary for the provision of such services, we will share your personal data with these partners on a need-to-know basis, subject to appropriate contractual safeguards and in accordance with applicable law.

Your Choices and Rights

Depending on your jurisdiction and subject to applicable law, you may have the following rights in relation to your personal data:

  • The right to request access to, and copies of, the personal data we hold about you;
  • The right to request rectification of inaccurate or incomplete personal data;
  • The right to request erasure of your personal data in certain circumstances;
  • The right to request restriction of processing of your personal data in certain circumstances;
  • The right to object to the processing of your personal data, in particular where we are relying on legitimate interests;
  • The right to receive your personal data in a structured, commonly used and machine-readable format and to transmit that data to another controller (data portability), where technically feasible; and
  • Where processing is based on your consent, the right to withdraw consent at any time.

These rights may be subject to certain limitations and exemptions under applicable law. For example, we may be unable to delete or restrict processing of information that we are required to retain for legal or regulatory purposes.

If you wish to exercise any of these rights, you may contact us using the details provided in the "Contact Us" section below. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).

Right to Lodge a Complaint:

If you are located in the European Economic Area (**"EEA"**) or another jurisdiction that provides for a right to lodge a complaint with a data protection authority, you also have the right to lodge such a complaint with your local supervisory authority if you are concerned about how we process your personal data. We would, however, appreciate the chance to address your concerns before you approach a supervisory authority, so please contact us in the first instance.

Mobile Push Notifications

If you install our mobile applications and enable push notifications, we may send non-promotional push notifications to your device. You can disable these notifications at any time through your device or app settings.

Transfer of Information to Other Countries

We are based in the Republic of Cyprus (“Cyprus”), and your personal data may be processed and stored in Cyprus, in other countries within the EEA, and in other jurisdictions where our service providers, partners or group entities are located. These countries may have data-protection laws that differ from the laws of your country of residence and, in some cases, may not provide the same level of protection.

Where we transfer personal data from the EEA, or other jurisdictions with data-transfer restrictions to countries that are not recognised as providing an adequate level of protection, we implement appropriate safeguards to protect your personal data. These may include entering into data-transfer agreements based on the Standard Contractual Clauses approved by the European Commission or relying on other lawful transfer mechanisms.

You may contact us using our contact details in “Contact Us” section if you would like more information about the specific mechanism used by us when transferring your personal data.

Retention of Personal Information

We retain your personal information for as long as is reasonably necessary to fulfil the purposes for which we collected it, including to provide the Services, to comply with our legal, regulatory, accounting and reporting obligations, to resolve disputes and to enforce our agreements.

The retention period will depend on a number of factors, including the type of data, the nature of our relationship with you, the purposes for which the data is used and applicable legal or regulatory requirements. For example, financial-services and anti-money-laundering regulations may require us to retain certain information for a minimum number of years after the end of our business relationship with you.

When we no longer require your personal information for the purposes described in this Policy, we will take steps to delete it or anonymise it, unless we are required or permitted by law to retain it for a longer period.

Security and Integrity of Information

We use a combination of technical, organisational, and physical safeguards designed to protect your personal information against unauthorised or unlawful access, use, disclosure, alteration, or destruction and against accidental loss or damage. These measures include, among other things, encryption, firewalls, access-controls, segregation of duties and regular monitoring of our systems and infrastructure.

Access to personal information within Ronin EM is limited to those officers, employees, agents, contractors and other third parties who have a business need to know such information. They will only process your personal information on our instructions and are subject to duties of confidentiality.

Your Responsibility:

You are responsible for maintaining the confidentiality and security of your account credentials and for all activities that occur under your Ronin EM Account. You should use a strong, unique password and enable multi-factor authentication (where available), and you must not share your password or authentication codes with anyone else. If you believe your account has been compromised, you should notify us immediately.

Minors

The Services are not directed to, and may not be used by, persons under the age of eighteen or under the age of legal majority in their jurisdiction (whichever is higher) (a **"Minor"**).

We do not knowingly collect personal information from Minors. If we become aware that we have collected personal information from a Minor, we will take steps to delete such information and, where appropriate, close the relevant account.

If you are a parent or guardian and believe that a Minor has provided personal information to us, please contact us using our contact details stated in “Contact Us” section of this Policy.

Changes to this Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal or regulatory requirements, or for other operational reasons. When we make changes, we will revise the **"Last Updated"** date at the top of this Policy and, where required by applicable law, provide you with additional notice or seek your consent to material changes.

We encourage you to review this Policy periodically to stay informed about our information-handling practices. Your continued use of the Services after any changes to this Policy will constitute your acknowledgment of the revised Policy.

Contact Us

If you have any questions or concerns about this Policy or our processing of your personal information, or if you wish to exercise any of your data-protection rights, you can contact us using the following details:

  • **Email:** info@em.ron.in
  • **Postal address:** Ronin EM Limited, Promachon Eleftherias 19, Alpha Business Centre, Mezzanine, Agios Athanasios, 4103 Limassol, Cyprus.

When contacting us, please provide your name, contact details and sufficient information to allow us to identify your account (if applicable) and understand your request. We may request additional information to verify your identity before we respond to certain requests.

Crypto-assets are volatile. Your capital is at risk. You should only invest what you can afford to lose.