Privacy Policy
Qiro ("we," "our," "us") is committed to protecting the privacy of our investors, borrowers, partners, and platform users. This Privacy Policy explains how we collect, use, store, and share information when you interact with our services, including the Qiro platform (https://www.qiro.fi/), our smart contracts, wallets, and related financial services supporting tokenized credit investments.
Effective date: 2 October 2025
Last updated: 23 July 2026
Overview
By accessing or using the Qiro Platform, you acknowledge that you have been provided with this Privacy Policy. Where required by applicable law, we will seek your consent for specific processing activities.
1. Information We may Collect
We may collect the following categories of information:
1.1 Personal Information Provided by Investors
- Full name, date of birth, nationality, and identification documents (passport, ID card, driver's license).
- Contact details (email address, phone number, residential address).
- Financial and professional information required for KYC/AML checks.
- Accredited/qualified investor certifications (where applicable).
1.2 Wallet and Transaction Data
- Blockchain wallet addresses used for investments and repayments.
- Details of subscriptions, token holdings, disbursements, and repayment transactions.
- Vault smart contracts, Facility-related payment flows, Token records, wallet addresses and analogous Programme interactions.
1.4 Platform and Technical Data
- IP addresses, device identifiers, and browser information.
- Usage data from the Qiro platform and dashboards.
- Cookies and similar technologies (if applicable).
2. How We Use Information
Depending on the processing activity, Qiro, Celestia Market Inc. and the relevant Issuer SPV may act as data controller, joint controllers or processor under applicable data protection law (including GDPR, UK GDPR, CCPA and Panama Law 81 of 2019). The default role allocation is: (i) website / platform analytics — Celestia as controller; (ii) KYC / KYB / sanctions onboarding — Issuer and/or Celestia as controller(s), with KYC provider as processor; (iii) Whitelist administration — Issuer and/or Celestia; (iv) Tokenholder records — Issuer; (vi) Partner Vault data — Partner / Partner Issuer and/or Celestia, as agreed per partner vault. Qiro and the relevant Issuer SPV use the collected information for the following purposes:
- Regulatory Compliance: To perform AML/KYC checks and comply with applicable laws.
- Fund Flow Execution: To process subscriptions, issue tokens, disburse loans, and route repayments.
- Risk Management: To verify borrower eligibility, enforce security pledges, and manage investor protections.
- Platform Operations: To provide dashboards, investor reporting, and marketplace services.
- Security: To prevent fraud, unauthorized transactions, and malicious activities.
- Communications: To provide investors and borrowers with reports, notices, and disclosures.
3. Legal Basis for Processing
We process personal data on the following bases:
- Consent: Where you have given explicit consent.
- Contractual Necessity: To perform obligations under the Vault Deed Poll, Onboarding Acknowledgement, Facility Agreement and other applicable Programme Documents.
- Legal Obligations: To comply with AML, KYC, tax, and regulatory requirements.
- Legitimate Interests: To safeguard platform integrity, investor protections, and operational efficiency.
4. Cross-Border Data Transfers and Third Party Services
We may share your personal information with carefully selected third-party service providers to help us operate, provide, and improve our services. These third parties may include:
- Identity verification and compliance providers for Know-Your-Customer (KYC) and Anti-Money Laundering (AML) obligations.
- Cloud hosting, storage, and IT providers to securely manage data.
- Payment processors, custodians, and banking partners to facilitate transactions.
- Analytics, fraud prevention, and security services to maintain the integrity of our platform.
We require all third parties to process your information in accordance with applicable data protection laws and our instructions. They are prohibited from using your information for their own purposes.
Because we operate internationally, your personal information may be transferred to and processed in jurisdictions outside of your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.
Where such cross-border transfers occur, we implement appropriate safeguards to protect your personal information, including:
- Standard Contractual Clauses (SCCs) approved under the General Data Protection Regulation (GDPR).
- Binding contractual obligations requiring recipients to safeguard personal data.
- Technical and organizational measures such as encryption and restricted access.
For residents of the European Economic Area (EEA), United Kingdom, or Switzerland, we will only transfer your personal data to jurisdictions recognized as providing adequate protection or subject to legally valid transfer mechanisms.
For residents of California, we comply with the California Consumer Privacy Act (CCPA), ensuring you have the right to know, access, delete, and opt out of the sale or sharing of your personal data. We do not sell your personal information.
5. Cross-Border Processing by Issuers, Celestia and Programme Participants
Personal Data may be processed by the relevant Issuer SPV, by Celestia in its capacity as platform operator, Curator and/or Whitelist Administrator, and by other Programme participants or service providers where necessary for the Qiro Programme.
The relevant Issuer SPV may include entities such as QuantVault SPV Inc., Straton SPV Inc. or any other Issuer SPV identified in the applicable Programme Documents. Celestia Market Inc. is not described in this Privacy Policy as an Issuer SPV merely because it processes Personal Data in its platform, Curator or service-provider capacity.
Where Personal Data is transferred internationally or processed by Programme participants in different jurisdictions, we use appropriate safeguards where required by applicable law, which may include contractual obligations, Standard Contractual Clauses, access controls, confidentiality obligations, technical and organisational measures, and purpose limitations.
Data shared with the relevant Issuer SPV, Celestia or other Programme participants is limited to what is reasonably necessary for onboarding, KYC / KYB, sanctions screening, Whitelist administration, investor eligibility, Tokenholder records, Redemption, reporting, compliance, dispute handling and analogous Programme purposes.
Requests to access, rectify, delete, restrict or otherwise exercise rights in respect of off-chain Personal Data may be submitted to Qiro / Celestia using the contact details in this Privacy Policy. Qiro / Celestia will coordinate with the relevant Issuer SPV, service provider or Programme participant where necessary.
6. Data Retention
We retain data for as long as necessary to:
- Fulfill the purposes outlined in this policy.
- Comply with legal and regulatory obligations.
- Enforce contractual rights and resolve disputes.
Investor and borrower identity records are typically retained for 7 years post-termination of the business relationship, subject to jurisdictional requirements.
7. Data Security
Qiro employs a comprehensive framework of technical, organizational, and administrative safeguards designed to protect personal data and other confidential information from unauthorized access, disclosure, alteration, or destruction. Our security program is aligned with industry standards and financial services best practices and includes, without limitation:
- Encryption protocols for data in transit and at rest, where applicable.
- Strict access controls and multi-factor authentication to ensure that only authorized personnel may access sensitive information.
- Segregation of duties and role-based permissions to minimize risks of internal misuse.
- Regular monitoring, vulnerability assessments, and audits to identify and address emerging threats.
- Secure infrastructure and storage solutions, including third-party service providers that are contractually bound to adhere to equivalent security measures.
Further to demonstrate our commitment to the highest standards of security and regulatory compliance:
- Independent Audits: We engage reputable third-party firms to perform annual smart-contract and system security audits. Summaries of audit findings will be publicly disclosed to provide transparency and assurance to our users.
- Responsible Disclosure: We maintain a responsible vulnerability disclosure program that allows security researchers to report issues in a safe, coordinated, and legally protected manner.
- Breach Notification: In the unlikely event of a personal data or system security breach, Qiro will notify affected individuals and competent supervisory authorities without undue delay, in accordance with applicable law (e.g., GDPR, CCPA). Notifications will include the nature of the breach, potential impacts, and remedial steps taken.
- Continuous Monitoring: Our systems are subject to ongoing monitoring, penetration testing, and incident-response protocols to identify and address emerging threats in real time.
Blockchain and Decentralized Network Considerations: Certain information, such as wallet addresses and on-chain transaction records, may be publicly recorded on decentralized networks. Such data is by its nature immutable, transparent, and beyond our unilateral control. While we employ rigorous measures to safeguard off-chain data, users should be aware that interactions with smart contracts or decentralized applications carry inherent security risks.
Residual Risk and User Responsibility: While we strive to apply appropriate safeguards in accordance with applicable laws and regulatory obligations, no method of transmission or storage is entirely secure. Accordingly, we cannot guarantee absolute protection of personal data. Users are responsible for maintaining the confidentiality of their access credentials, private keys, and devices used to engage with our services.
8. Your Rights
Depending on your jurisdiction (e.g., GDPR in the EU, PDPA in Singapore), you may have rights to:
- Access, correct, or update your personal data.
- Request deletion, subject to legal retention obligations.
- Restrict or object to processing of personal data.
- Request a copy of your data in portable format.
Requests can be submitted to legal@qiro.fi.
9. Cookies and Web Tracking
The Qiro Platform uses cookies, tracking technologies, and similar tools to enhance functionality, improve user experience, and collect information about how our services are used. These technologies allow us to:
- Recognize and remember users' preferences and settings.
- Facilitate secure login and account management.
- Monitor website traffic, usage patterns, and performance.
- Conduct analytics and market research to improve our services.
- Comply with legal and regulatory obligations, including fraud detection and security monitoring.
Further details on the categories of cookies used, their purposes, retention and your choices are set out in the Cookie Notice.
Third-Party Tracking: We may permit certain trusted third parties (such as analytics providers, compliance vendors, or security monitoring tools) to place cookies or similar technologies on our platforms. These third parties may collect information about your online activities across different services and over time, subject to their own privacy policies.
Product Analytics: With your consent, the Qiro Platform uses Mixpanel to measure explicit interactions such as vault discovery, authentication, verification, wallet connection and investment workflows. Mixpanel is not loaded before consent. You may decline or withdraw analytics consent at any time through the Analytics settings control in the platform footer without affecting essential platform functionality.
Blockchain-Specific Considerations: In addition to cookies, we may track wallet connections, transaction activity, and smart contract interactions to ensure platform integrity and compliance with applicable legal obligations. Such tracking is limited to the extent necessary to provide services and maintain security.
Most web browsers allow you to control or disable cookies through settings. Please note that if you disable or reject certain cookies, some features of our services may not function as intended. Where required by applicable law (e.g., GDPR, ePrivacy Directive, CCPA), we will obtain your consent before placing non-essential cookies or similar tracking technologies on your device.
10. Updates to Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on https://www.qiro.fi/ and the "Last Updated" date will be revised accordingly.
11. Disclaimer
Please note that blockchain data is public and immutable. Wallet addresses, balances, transaction hashes, and smart-contract events are recorded on decentralized ledgers that are publicly visible and cannot be altered or erased. As a result, certain data-subject rights do not apply to on-chain records. We will, however, respect your rights with respect to any off-chain personal data that we process.
12. Complaints
We take very seriously any complaints we receive about our use of Personal Information. If you have any questions, comments, requests or complaints regarding this Privacy Policy, or wish to discuss your data protection rights with us, please contact us using the information below.
13. Contact Us
To exercise any of your rights or if you have any questions or concerns about this Privacy Policy or our privacy practices, please contact us using the following information:
Email: legal@qiro.fi