Privacy Policy
Last updated: July 4, 2026
⚠️ DRAFT — TEMPLATE ONLY. Not legal advice. This document is a working draft provided for review. It does not constitute legal advice and must be reviewed and approved by qualified legal counsel before it is relied upon. Entity, registration, and contact details are placeholders pending finalisation.
At MPRO Finance, we respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the Digital Operational Resilience Act (DORA), the NIS 2 Directive, and SOC 2 Privacy Criteria.
1. Data Controller
The data controller responsible for your personal data is MPRO Finance. If you have any questions regarding this Privacy Policy, your rights, or data protection practices, please contact us via our official support channels.
2. Personal Data We Collect
We collect and process the following categories of personal data:
- Account Credentials: Name, email address, password hashes, Multi-Factor Authentication (MFA) metadata (public key credentials), and recovery codes.
- KYC Documentation: Identity verification details, country of residence, and related verification statuses.
- System Log Data: IP addresses, browser types, session cookies, and security event logs (such as login attempts or IP changes).
- Activity & Audit Records: Critical operations performed on the Platform (stored in our cryptographic, insert-only audit chain).
3. Legal Bases for Data Processing
Under GDPR, we process your personal data under the following legal bases:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary to provide the platform services, maintain your active account, and support sessions.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Processing necessary to comply with anti-money laundering (AML), know-your-customer (KYC) regulations, tax audit compliance, and operational resilience monitoring under DORA Article 10.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary to secure the platform against fraud, verify system integrity via our cryptographic audit chain, and monitor application performance in alignment with NIS 2 cybersecurity incident handling requirements.
- Consent (Art. 6(1)(a) GDPR): Optional marketing campaigns and analytical cookies.
4. Cryptographic Audit Chain & Log Integrity (SOC 2 & DORA)
- MPRO Finance utilizes a cryptographic, linear, insert-only audit chain (the "Audit Chain") to verify system safety, prevent unauthorized modifications, and verify transaction history.
- Security actions, authorization modifications, access reviews, and ETL data validations are permanently sealed in this cryptographically-chained ledger.
- Because the Audit Chain is linear and mathematically chained to ensure non-repudiation and prevent historical manipulation, security log metadata stored in this chain is preserved under our legitimate interest to defend the platform against cyberattacks and security fraud, in alignment with DORA and SOC 2 Processing Integrity principles.
5. How We Share Your Data
We do not sell your personal data. We share your data only with trusted third-party services necessary for operating the Platform:
- Infrastructure & Database Providers: Hosting services, database nodes, and Redis cache clusters.
- Security & Analytics Services: Error tracking (e.g. Sentry) and consent-based analytic providers.
- KYC Verification Providers: Verified partners who conduct secure AML/KYC background checks.
6. Data Subject Rights Under GDPR
As an EU resident, you possess the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): Obtain copy of your data and information on how we process it.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate personal data.
- Right to Erasure / Right to be Forgotten (Art. 17 GDPR): Request deletion of your personal data when no longer needed or if processing has no valid legal basis. Note: this right is subject to regulatory retention requirements (such as financial AML records) and technical security logging (such as the linear integrity of our Audit Chain) under Art. 17(3)(b) of the GDPR.
- Right to Restriction of Processing (Art. 18 GDPR): Request restriction of data processing in specific circumstances.
- Right to Data Portability (Art. 20 GDPR): Request export of your account data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): Object to processing based on our legitimate interest.
To exercise any of these rights, please contact us.
7. Data Retention & Compliance Periods
- Account Information: Retained for the duration of your active account. Upon request for deletion, account details will be removed within 30 days, subject to overriding statutory requirements.
- Security Event Logs & Audit Trails: Pursuant to DORA Article 10 and financial audit standards, security event logs, authorization history, and corresponding Audit Chain metadata are retained for a minimum of 5 years to guarantee traceability of ICT incidents.
- KYC Records: Retained for a minimum of 5 years following the termination of the business relationship, in accordance with applicable anti-money laundering (AML) legislation.