LEGAL

Data Storage and Personal Data Protection Policy

COBBY PAY LTD.

Effective Date: 25.11.2025 · Last Updated: 11.04.2026

COBBY PAY LTD. (“CobbyPay”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, security, and integrity of personal information collected, used, disclosed, and retained in connection with our services and business operations.

This Policy has been prepared in accordance with applicable Canadian privacy, anti-money laundering, and payment services legislation, including:

  • The Personal Information Protection and Electronic Documents Act (“PIPEDA”);
  • The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (“PCMLTFA”) and related FINTRAC guidance;
  • The Retail Payment Activities Act (“RPAA”) and applicable Bank of Canada supervisory expectations; and
  • Applicable sanctions, fraud prevention, cybersecurity, and recordkeeping obligations under Canadian law.

As a regulated Canadian money services business and payment service provider, the Company is required to collect, verify, monitor, retain, and in certain circumstances disclose personal information for compliance, operational, legal, and regulatory purposes.

By establishing a relationship with the Company or using our services, you acknowledge and consent to the practices described in this Policy.

1. Collection of Personal Information

The Company collects personal information necessary to provide services, establish and maintain customer relationships, comply with legal and regulatory obligations, manage operational and financial crime risks, and maintain the security and integrity of our systems and services.

The information collected may include personal identifiers such as name, date of birth, nationality, residential address, telephone number, email address, government-issued identification details, residency or immigration information, occupation, business activities, source of funds information, transaction history, account information, and communications records.

Where required for compliance purposes, the Company may also collect information relating to beneficial ownership, politically exposed person (“PEP”) status, sanctions exposure, adverse media findings, wallet addresses, device information, IP addresses, and technical identifiers associated with access to our systems or services.

The Company only collects information reasonably necessary for legitimate business, compliance, operational, or legal purposes.

2. Use of Personal Information

The Company uses personal information for lawful and legitimate purposes connected to the provision of payment services and compliance with applicable Canadian laws and regulatory obligations.

Personal information may be used to verify identity, conduct customer due diligence (“KYC / KYB”), process transactions, provide services, manage accounts, conduct transaction monitoring, identify suspicious activity, prevent fraud, conduct sanctions screening, comply with anti-money laundering and counter-terrorist financing obligations, maintain cybersecurity controls, respond to legal or regulatory requests, and protect the integrity of the Company’s operations.

As a reporting entity under the PCMLTFA and a payment service provider regulated under the RPAA, the Company may also use personal information to comply with FINTRAC reporting obligations, Bank of Canada supervisory requirements, sanctions screening obligations, and internal risk management controls.

The Company does not sell personal information to third parties.

3. Disclosure of Personal Information

The Company may disclose personal information where necessary to provide services, comply with legal or regulatory obligations, protect the Company’s legitimate interests, or manage operational and financial crime risks.

Information may be disclosed to financial institutions, payment processors, banking partners, electronic money institutions, identity verification providers, sanctions screening providers, cloud service providers, auditors, legal advisors, regulators, law enforcement agencies, governmental authorities, or other service providers supporting the Company’s operations.

Where legally required or permitted, the Company may disclose information to FINTRAC, the Bank of Canada, law enforcement authorities, sanctions authorities, or other competent authorities in connection with anti-money laundering, suspicious transaction reporting, sanctions compliance, fraud investigations, or regulatory oversight activities.

Third-party service providers engaged by the Company are expected to maintain appropriate confidentiality, privacy, and security safeguards.

4. Consent and Legal Authority

The Company collects, uses, and discloses personal information with consent where required under applicable law.

Consent may be obtained electronically, in writing, verbally, through account registration, through acceptance of applicable agreements, or implied through the establishment and continuation of a business relationship where permitted by law.

In certain circumstances, the Company may collect, use, retain, or disclose personal information without consent where authorized or required under Canadian law, including obligations arising under the PCMLTFA, sanctions legislation, fraud prevention obligations, law enforcement requests, or regulatory reporting requirements.

5. International Transfers and Service Providers

Due to the international nature of payment services and financial infrastructure, personal information may be processed or stored outside Canada.

Where information is transferred internationally, the Company takes reasonable measures to ensure that appropriate safeguards are maintained and that service providers maintain acceptable confidentiality and security standards.

Information processed in foreign jurisdictions may be subject to lawful access by foreign courts, regulators, law enforcement authorities, or governmental agencies in accordance with applicable local laws.

6. Information Security and Cybersecurity

The Company maintains administrative, technical, organizational, and cybersecurity safeguards designed to protect personal information against unauthorized access, disclosure, misuse, loss, alteration, or destruction.

Security measures may include access controls, multi-factor authentication, encryption, restricted permissions, audit logging, monitoring systems, secure backups, device security controls, cybersecurity monitoring, and incident response procedures appropriate to the nature and sensitivity of the information processed.

Access to personal information is restricted to authorized personnel with a legitimate business or compliance need.

The Company maintains internal procedures relating to cybersecurity incident management, data breach escalation, operational resilience, and information security governance in accordance with applicable Canadian regulatory expectations and operational risk management standards.

7. Retention of Records

The Company retains personal information only for as long as necessary to fulfill legal, regulatory, operational, compliance, and business purposes.

Certain records, including customer due diligence information, transaction records, compliance reviews, suspicious transaction reporting records, and sanctions-related documentation, may be retained for minimum periods required under Canadian law, including retention requirements under the PCMLTFA, FINTRAC guidance, and applicable RPAA obligations.

At the end of the applicable retention period, records are securely deleted, anonymized, or destroyed.

8. Individual Rights

Subject to applicable Canadian law, individuals may request access to personal information held by the Company and may request correction of inaccurate or incomplete information.

Individuals may also inquire about how their personal information is collected, used, retained, disclosed, or protected.

Requests relating to personal information may be submitted using the contact information below. The Company may require verification of identity prior to processing certain requests.

Certain rights may be limited where information must be retained or processed to comply with legal, regulatory, anti-money laundering, fraud prevention, sanctions, or law enforcement obligations.

9. Cookies and Technical Information

The Company may use cookies, analytics tools, and similar technologies to maintain website functionality, improve operational performance, support cybersecurity controls, detect fraud, and analyze usage patterns.

Users may modify browser settings to restrict certain cookies; however, doing so may affect website functionality or service availability.

10. Changes to this Privacy Policy

The Company may amend this Privacy Policy from time to time to reflect changes in legislation, regulatory expectations, operational practices, technology, or business activities.

The most current version of this Policy will be made available through the Company’s website or internal documentation.

Continued use of the Company’s services following any amendment constitutes acknowledgment of the updated Policy where permitted by applicable law.

11. Contact Information

Questions, requests, or concerns relating to this Privacy Policy or the Company’s handling of personal information may be directed to: info@cobbypay.com