Compliance / Data Privacy Policy

Data Privacy Policy

Last updated: 8 September 2026

This policy describes how Blockzo Ltd ("Blockzo", "we") collects, uses, and protects personal data when you use the website at blockzo.io and when you become a client.

We are the data controller for the purposes of UK GDPR and the UK Data Protection Act 2018 in respect of personal data we collect directly from you. Where personal data is processed by our regulated partners in the course of delivering payment or cryptoasset services, those partners act as data controllers in their own right.

1. Personal data we collect

Directly from you (during enquiry and onboarding)

  • Identity and contact data: name, email, phone number, company name, job title
  • Account data: username, preferences, authentication credentials
  • Business data: company registration, beneficial ownership, source of funds documentation
  • Communications: messages, support tickets, feedback

Automatically when you use the Site

  • Device and technical data: device type, operating system, browser
  • Usage data: IP address, approximate location, access times, pages visited
  • Cookies and analytics — see our Cookie Policy

About your end clients or counterparties (where you provide it)

  • Names and contact details
  • Identifiers required for transaction processing
  • Transaction records

2. How we use personal data

  • To provide and operate our introducer service
  • To onboard you with our regulated partners (passing data as required for KYC/KYB/AML checks)
  • To improve our service and conduct analytics
  • To respond to your support requests
  • To receive, triage, and reply to enquiries you submit through the Site
  • To prevent fraud and protect the security of our systems
  • To comply with our legal and regulatory obligations

Automated triage of enquiries. When you submit an enquiry through the Site, we use an automated system — including a large language model provided by Anthropic PBC — to sort it and route it to the right person. This only categorises and prioritises your enquiry; a person reviews every enquiry we receive, and no decision about you is made by automated means alone. Your enquiry is not used to train anyone's models.

3. Legal bases for processing

Performance of a contract; compliance with legal obligations; legitimate interests (operating, securing, and improving our service, and responding to business enquiries you send us); consent (where required, e.g. for non-essential cookies and direct marketing).

4. Who we share personal data with

  • Our regulated partners — your data is shared with the relevant partner to enable them to provide payment or cryptoasset services and to satisfy their own regulatory obligations. Current partners: The Currency Cloud Limited and CurrencyCloud B.V. (collectively, Currencycloud); Universe Money; GC Partner Limited; Equals Connect Limited.
  • Service providers — we use a small number of named processors to run the Site and our operations. Each acts as a data processor on our behalf under written agreement:
    • Hosting, edge delivery, and bot protection: Cloudflare, Inc. (Cloudflare Pages, Workers, R2, Turnstile)
    • Website analytics: Cloudflare Web Analytics (cookieless)
    • Email delivery, calendar, and inbox: Google LLC (Google Workspace) and Wildbit, LLC (Postmark)
    • Customer relationship management: Attio Ltd
    • Internal messaging and enquiry handling: Slack Technologies, LLC
    • Internal documents and records: Notion Labs, Inc.
    • Workflow automation: n8n GmbH
    • Automated enquiry triage: Anthropic PBC (see section 2)
  • Regulators and law enforcement — where we are legally required to disclose information.
  • We do not sell personal data.

5. International transfers

Some of our service providers and regulated partners are based outside the United Kingdom and European Economic Area. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards (such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, with supplementary measures where required).

6. Data retention

We retain personal data for as long as required to provide our service and to comply with our legal and regulatory obligations. Our standard retention period is five years from the end of our relationship with you. We will retain data for longer where required by law (e.g. AML record-keeping). Earlier deletion is possible on request, subject to our legal obligations.

7. Security

We use encryption in transit (TLS / HTTPS), encryption at rest where feasible, and role-based access controls. Despite our measures, no system is completely secure; we cannot guarantee absolute security.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to our legal obligations)
  • Restrict or object to processing
  • Request portability of data you have provided to us
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at privacy@blockzo.io. We will respond within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.

9. Changes

We may update this policy from time to time. Material changes will be communicated by updating the "last updated" date and, where appropriate, by direct notice.

10. Contact

Blockzo Ltd
71–75 Shelton Street, London, England, WC2H 9JQ
Privacy email: privacy@blockzo.io
General email: info@blockzo.io

Questions about this policy? Email us at info@blockzo.io.

Get in touch→