STABLEX

Privacy Policy

Effective Date: 01 June 2026 | Version 2.0

Preamble

This Privacy Policy (“Policy”) is published by Alpha Street Technologies Private Limited, a company incorporated under the Companies Act, 2013, having its registered office in India (“Stablex”, “the Company”, “we”, “us”, or “our”), and explains how we collect, use, process, store, disclose, and protect personal information of users (“you”, “your”, or “User”) who access or use our website (), our trading platform (account.stablex.in), and all related applications, features, and services (collectively, the “Services”).

This Policy is framed with reference to, and is intended to be read consistently with, applicable Indian law including the Information Technology Act, 2000 and the rules made thereunder (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011), the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules issued or to be issued thereunder, the Prevention of Money Laundering Act, 2002 (“PMLA”) and rules framed by the Financial Intelligence Unit – India (“FIU-IND”), and other applicable regulatory guidance issued from time to time.

BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS POLICY. IF YOU DO NOT AGREE WITH ANY PART OF THIS POLICY, YOU MUST DISCONTINUE USE OF THE SERVICES IMMEDIATELY.

1. Definitions and Interpretation

  • “Account” means the registered user account created by you on the Platform for the purpose of accessing the Services.
  • “Personal Information” or “Personal Data” means any data about an individual who is identifiable by or in relation to such data, including Sensitive Personal Data as defined below.
  • “Sensitive Personal Data” includes, without limitation, government identity numbers (such as Aadhaar and PAN), financial information (bank account and payment details), and biometric information (such as photographs used for liveness verification), consistent with the meaning ascribed under applicable Indian law.
  • “Platform” means collectively the website at stablex.in and the trading application at account.stablex.in.
  • “Processing” means any operation performed on Personal Information, including collection, recording, storage, use, disclosure, transmission, and erasure.
  • “VASP” means Virtual Asset Service Provider, being the classification applicable to Stablex under the Prevention of Money Laundering Act, 2002, as registered with FIU-IND.
  • Words importing the singular include the plural and vice versa. Section headings are for convenience only and do not affect interpretation.

2. Scope and Applicability

This Policy applies to all Personal Information collected by Stablex through the Platform, customer support channels, KYC/onboarding processes, and any other interaction between you and Stablex in connection with the Services. This Policy does not apply to information collected by third-party websites, applications, or services that may be linked to or integrated with the Platform, which are governed by their own respective privacy policies.

This Policy is designed for users accessing the Services from within India. If you access the Services from outside India, you do so on your own initiative and are responsible for compliance with local laws, to the extent applicable.

3. Information We Collect

We collect the following categories of Personal Information in the course of providing the Services:

3.1 Account & Identity Data

  • Full legal name, date of birth, and photograph
  • Permanent Account Number (PAN) and government-issued photo identification
  • Aadhaar details, collected and verified exclusively through UIDAI-sanctioned offline e-KYC / masked-Aadhaar or Aadhaar-based e-KYC mechanisms; Stablex does not collect, store, or retain your full/unmasked Aadhaar number except where explicitly permitted and required for regulatory verification through an authorised KYC User Agency (KUA), and only for the minimum duration necessary
  • Residential address and proof-of-address documentation
  • Email address, mobile number, and account login credentials
  • Biometric data, including facial images and liveness-detection data, collected solely for identity verification purposes during onboarding and periodic re-verification. This data is classified as Sensitive Personal Data and is processed only with your explicit, informed consent obtained at the point of collection

3.2 Bank & Payment Data

  • Verified bank account number, IFSC code, and account holder name
  • UPI identifiers and payment reference numbers
  • INR deposit and withdrawal transaction records

Stablex does not accept card-based payments and does not collect or store card numbers, card expiry dates, or card CVV information.

3.3 Crypto Activity Data

  • Wallet deposit and withdrawal addresses
  • Network type (including ERC-20, TRC-20, BEP-20) and associated transaction hashes
  • Trade history, order records, and settlement confirmations

3.4 Device & Usage Data

  • IP address, device identifiers, browser type, and operating system
  • Log data, including pages visited, timestamps, and session duration
  • Cookies, pixel tags, software development kit (SDK) identifiers, and analytics event data

3.5 Support & Communication Data

  • Support tickets, chat transcripts, and email correspondence
  • Call recordings, where applicable, subject to a verbal disclosure at the commencement of the call
  • Feedback, survey responses, and internal verification notes

4. Legal Basis for Processing

We process your Personal Information on one or more of the following legal bases:

  • Your explicit consent, provided at the time of registration, KYC verification, or opt-in to specific features
  • Performance of the contract for Services between you and Stablex, including account management and transaction execution
  • Compliance with a legal obligation, including obligations under the PMLA, FIU-IND directions, and directions of the Reserve Bank of India (RBI) concerning payment and settlement systems
  • Our legitimate interest in preventing fraud, ensuring platform security, and improving the Services, provided such interest does not override your fundamental rights

5. Why We Collect Your Information (Purpose of Processing)

  • To create, verify, and administer your Account
  • To conduct Know Your Customer (KYC) and Anti-Money Laundering (AML) checks required under the PMLA, 2002 and FIU-IND guidelines
  • To process INR deposits, virtual digital asset purchases, and withdrawals
  • To detect, investigate, and prevent fraudulent transactions, unauthorised access, and other security incidents
  • To maintain accurate transaction and audit records and to provide customer support
  • To comply with directions, orders, and reporting obligations of FIU-IND, the Reserve Bank of India, and other competent authorities
  • To improve platform performance, develop new features, and personalise your experience
  • To send transactional alerts and security notifications, and, where you have separately opted in, promotional communications

6. How We Share Your Information

We do not sell your Personal Information to any third party for monetary or other consideration. We disclose Personal Information only where necessary, and only to the following categories of recipients, each of whom is contractually bound by data protection and confidentiality obligations no less protective than those set out in this Policy:

  • KYC and identity verification service providers, including for liveness-check purposes
  • Banking and payment partners for INR settlement and fund transfers
  • Custody and wallet infrastructure providers engaged for secure storage of digital assets
  • Over-the-counter (OTC) liquidity partners for sourcing and settlement of virtual digital assets
  • Fraud detection, cybersecurity, and analytics vendors
  • Cloud hosting, information technology infrastructure, and customer support tool providers
  • Law enforcement agencies, regulators, and governmental authorities, where required by applicable law, a valid court order, or a lawful regulatory direction
  • A successor entity in the event of a merger, acquisition, or corporate restructuring, provided that you are given prior written notice (by email and/or prominent notice on the Platform) of any such transfer

Where any recipient described above is located outside India, the cross-border transfer provisions in Section 11 shall apply.

7. Data Retention

We retain categories of Personal Information for differentiated periods based on the purpose of collection, as summarised below:

Category of DataRetention PeriodBasis
KYC records, identity documents, transaction recordsMinimum 5 years from the date of termination of the business relationship / account closurePMLA, 2002 and FIU-IND Master Directions
Bank and payment records5 years from the date of the relevant transactionPMLA record-keeping obligations
Device, usage, and log data12 to 24 months from the date of collection, unless required for an active security investigationLegitimate interest in security and fraud prevention
Support tickets and correspondence3 years from the date of resolution of the queryDispute resolution and audit trail
Marketing consent and preference recordsUntil consent is withdrawn, plus 12 months thereafter for compliance record-keepingConsent management

On expiry of the applicable retention period, Personal Information is securely deleted, destroyed, or irreversibly anonymised in accordance with our internal data-retention and disposal procedures, save where continued retention is required to comply with a legal obligation, resolve an ongoing dispute, or enforce our agreements with you.

8. Data Security

We implement administrative, technical, and physical safeguards that are designed to be reasonable and appropriate to the sensitivity of the Personal Information processed, including:

  • Multi-Party Computation (MPC) wallet architecture and segregated hot/cold wallet storage for digital assets
  • Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using AES-256
  • Role-based access controls, the principle of least privilege, and internal access logging
  • Periodic security audits, penetration testing, and vulnerability assessments
  • Employee confidentiality obligations and access restricted on a need-to-know basis

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security of your Personal Information. In the event that we become aware of a personal data breach that is likely to compromise the confidentiality, integrity, or availability of your Personal Information, we will:

  • Assess the scope and severity of the breach without undue delay
  • Notify the relevant supervisory or regulatory authority within the timeframe prescribed under applicable law
  • Notify affected Users without undue delay, and in any event within seventy-two (72) hours of becoming aware of a breach that is likely to result in a risk to their rights, through email and/or a prominent notice on the Platform
  • Take reasonable remedial measures to contain and mitigate the impact of the breach

9. Cookies & Tracking Technologies

We use cookies, local storage, software development kit identifiers, and similar tracking technologies for the purposes described in the table below:

CategoryPurposeDuration
Strictly NecessaryMaintain login session, load balancing, and platform security (including CSRF protection)Session / up to 30 days
FunctionalRemember user preferences and settingsUp to 12 months
AnalyticsUnderstand platform usage patterns and improve performanceUp to 24 months
Performance / Advertising (if enabled)Measure the effectiveness of marketing communications, where applicableUp to 12 months

You may control or disable cookies through your browser or device settings. Disabling strictly necessary cookies may impair core functionality of the Platform, including login and security features. Where Stablex uses any third-party advertising or measurement pixels, such use will be separately identified and will be subject to your consent, where required by applicable law.

10. Your Rights & Choices

Subject to applicable law and the exceptions set out in this Policy, you have the following rights in respect of your Personal Information:

  • Right to Access: to obtain confirmation of, and access to, the Personal Information we hold about you
  • Right to Correction: to request correction of inaccurate, incomplete, or outdated Personal Information
  • Right to Erasure: to request deletion of your Account and associated Personal Information, subject to legal and regulatory retention obligations described in Section 7
  • Right to Data Portability: to request your Personal Information in a structured, commonly used, machine-readable format, to the extent technically feasible and required under applicable law
  • Right to Withdraw Consent: to withdraw consent previously provided for a specific processing activity at any time, without affecting the lawfulness of processing carried out prior to such withdrawal, and without affecting our ability to continue processing where required for legal or regulatory compliance
  • Right to Opt Out: to opt out of promotional and marketing communications at any time, without affecting transactional or security communications
  • Right to Nominate: to nominate another individual to exercise your rights under this Policy in the event of your death or incapacity, in accordance with applicable law
  • Right to Grievance Redressal: to lodge a grievance with our Grievance Officer as set out in Section 13, and thereafter, if unresolved, with the relevant data protection authority or the Data Protection Board of India (once constituted)

To exercise any of the above rights, please submit a request through the contact details in Section 16 or directly to our Grievance Officer. We will acknowledge your request within seven (7) days and will endeavour to respond substantively within thirty (30) days, or such shorter period as may be prescribed under applicable law. We may request additional information to verify your identity before processing your request.

11. Cross-Border Data Transfers

Certain of our service providers and liquidity partners, described in Section 6, may be located, or may process data, outside India. Where such cross-border transfer occurs, we take reasonable measures designed to ensure that your Personal Information continues to receive a level of protection consistent with this Policy, including through the use of contractual data-protection commitments with the relevant recipient.

We will not knowingly transfer Personal Information to any country or territory that is restricted or blacklisted by the Central Government under the Digital Personal Data Protection Act, 2023 or any successor legislation, once such restrictions are notified.

12. Children's Privacy

The Services are intended solely for individuals who are eighteen (18) years of age or older and who are legally capable of entering into binding contracts under the Indian Contract Act, 1872. We do not knowingly collect Personal Information from any individual under the age of 18. If we become aware that we have inadvertently collected Personal Information from a person under the age of 18, we will promptly delete such information and close the associated Account.

13. Grievance Redressal

In accordance with the Information Technology Act, 2000, the rules made thereunder, and the Digital Personal Data Protection Act, 2023, Stablex has appointed a Grievance Officer to address any complaints, queries, or concerns regarding this Policy or the processing of your Personal Information.

Grievance OfficerMr. Anil Singh
DesignationGrievance Officer, Alpha Street Technologies Private Limited
Email
Response TimelineAcknowledgement within 7 days; substantive resolution within 30 days of receipt of a valid complaint

Should you remain dissatisfied with the resolution provided by the Grievance Officer, you may escalate your grievance to the Data Protection Board of India (once constituted under the Digital Personal Data Protection Act, 2023) or to any other competent authority or forum having jurisdiction.

14. Changes to This Policy

We may amend or update this Policy from time to time to reflect changes in our practices, technology, legal, or regulatory requirements. The revised Policy will be posted on the Platform together with an updated “Effective Date”. Where a change is material, we will provide additional notice, such as an email communication or a prominent in-app notification, in advance of the change taking effect. Your continued use of the Services following such notice constitutes your acceptance of the revised Policy.

VersionEffective DateSummary of Changes
1.020 March 2026Initial publication of the Privacy Policy
2.001 June 2026Addition of Grievance Officer details; clarified Aadhaar/biometric handling; corrected regulatory references; added data portability and consent-withdrawal rights; added breach-notification timeline, cookie table, and retention schedule; expanded to formal legal drafting format

15. Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India. Subject to any mandatory regulatory or statutory forum having jurisdiction, the courts at Fatehabad, Haryana shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

16. Contact Us

For any questions, concerns, or requests regarding this Policy or the processing of your Personal Information, please contact us at:

Alpha Street Technologies Private Limited

Email (General Support):

Email (Grievance Officer):

Website:

Platform: