Privacy Policy

Last Updated: October 28, 2025 — Effective Date: October 28, 2025

1. Information We Collect

At WowBat, we are committed to safeguarding your privacy while delivering innovative wallet services for users globally. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information when you engage with our Services, including our mobile application and related platforms (collectively, "Services"). By using our Services, you consent to the practices described herein. This policy complies with applicable laws, including the General Data Protection Regulation (GDPR), local regulations in Turkey and other jurisdictions, with a strong emphasis on Know Your Customer (KYC), Anti-Money Laundering (AML), and Countering the Financing of Terrorism (CFT) compliance.

We collect various categories of information to deliver our Services and meet legal obligations:

Personal Identification Information

Full name, email address, phone number, date of birth, nationality, and identity verification documents (e.g., passport, driver's license, or government-issued ID). These are collected during account registration and KYC verification to comply with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations, ensuring we verify your identity and prevent illicit activities. This information is processed by certified identity verification service providers who specialize in compliance and regulatory adherence.

Financial Information

Transaction histories (including timestamps, amounts, cryptocurrency addresses, and recipient details), wallet balances, conversion records, and payment metadata. This data is collected to facilitate cryptocurrency transactions, monitor activity for AML/CFT compliance, and maintain accurate transaction records.

Cryptocurrency Wallet Data

Your wallet addresses, public keys, transaction hashes, and blockchain interactions.

Technical Data

IP addresses, browser type, operating system details, device identifiers, and application usage logs. These help us secure your account, detect suspicious activity, and optimize performance.

Usage Data

Details of your interactions with our Services, such as transaction frequency, conversion history, app navigation patterns, and feature usage, used to enhance user experience and identify potential risks.

Aggregate or Anonymized Data

Non-identifiable data derived from your usage, such as statistical trends, for analytics and service improvements.

We collect this information when you register an account, complete KYC verification, initiate transactions, contact support, or interact with our website or app.

2. How We Use Your Information

We process your information for the following purposes:

Service Delivery

To facilitate cryptocurrency transactions, enable wallet management, provide on-ramp services (fiat-to-crypto conversion), and ensure the security and functionality of our wallet platform.

Legal Compliance, Including KYC/AML/CFT

Know Your Customer (KYC)

We use your personal identification information to verify your identity during onboarding and periodically thereafter, as required by financial regulations in Turkey, the EU, and other applicable jurisdictions. This verification is conducted by certified identity verification service providers. This helps us prevent identity theft, unauthorized account use, and ensure compliance with regulatory requirements.

Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT)

We analyze financial and technical data (e.g., wallet addresses, transaction patterns, cryptocurrency sources) to detect and prevent money laundering, terrorist financing, sanctions evasion, or other illegal activities. This includes monitoring for:

  • Unusual transaction volumes or patterns
  • High-risk jurisdictions
  • Connections to sanctioned entities or individuals
  • Known fraud schemes or illicit activities

This monitoring is conducted in line with guidelines from the Financial Action Task Force (FATF), Turkish financial regulations, and international standards. We may flag, freeze, or report transactions to authorities if suspicious activity is detected, as mandated by law.

Security

To protect your account and our platform from fraud, cyberattacks, or unauthorized access, leveraging technical data and real-time monitoring tools.

Improvement

To analyze usage patterns, troubleshoot issues, and enhance our app's functionality, user interface, and customer support processes.

Communication

To send transactional notifications (e.g., transaction confirmations, security alerts), service updates, and, with your explicit consent, promotional materials about new features or services. We may use anonymized data for statistical analysis, research, or to develop new features without identifying you personally.

3. Disclosure of Your Information

We may share your information with the following entities under strict conditions to operate our Services effectively:

KYC/AML Verification Partners

Your personal identification information and financial data are shared with certified identity verification service providers to perform identity verification, conduct KYC checks, and monitor transactions for AML/CFT compliance. These providers screen your information against compliance databases and monitor for suspicious patterns to ensure regulatory adherence.

Licensed Service Partners for Payment & Exchange Services

To facilitate fiat-to-crypto conversion, merchant payments, and currency exchange services, we partner with licensed financial service providers who hold appropriate regulatory authorizations in their respective jurisdictions. These partners:

  • Process fiat-to-crypto conversions
  • Facilitate merchant payment processing
  • Conduct currency exchange operations
  • Ensure compliance with local and international regulations

Your financial transaction data and wallet information are shared with these partners to the extent necessary to facilitate the requested services.

Third-Party Service Providers

We collaborate with trusted third parties to support our wallet platform:

  • Infrastructure and Cloud Services: To securely store and process your data, maintaining our infrastructure and supporting compliance monitoring systems.
  • Analytics Providers: To analyze usage patterns and improve our Services, typically using anonymized or aggregated data unless required for security or compliance purposes.
  • Security and Fraud Detection Providers: To monitor for suspicious activities, fraud prevention, and security threats.
  • Marketing Partners: With your explicit consent, limited data (e.g., email address) may be shared to deliver personalized promotions.

All third-party providers are carefully vetted, bound by confidentiality agreements, and required to comply with applicable data protection laws. We conduct regular audits to ensure their adherence to these standards.

Regulatory Authorities

We share data when required by law, court orders, or to cooperate with fraud prevention agencies in jurisdictions including Turkey, the EU, and internationally. For AML/CFT purposes, this may include submitting reports to regulators, disclosing personal and financial information to meet tax, AML, or sanctions obligations.

Consent-Based Sharing

With your explicit permission, we may share data with additional third parties or service providers.

International Transfers

Data may be transferred internationally (e.g., to the United States, EU, or other regions) for processing by these third parties. We use Standard Contractual Clauses (SCCs), encryption, and contractual safeguards to ensure equivalent protection, meeting GDPR and other international standards.

Non-Affiliated Third Parties

We do not share your account numbers, wallet addresses, or personal data with non-affiliated third parties for marketing purposes without your explicit consent. You may opt out of non-essential data sharing at any time by contacting privacy@wowbat.asia.

4. Security Measures

We implement robust security practices to protect your data, critical for KYC/AML/CFT compliance and safeguarding your digital assets:

Encryption

All stored data is encrypted using industry-standard encryption protocols (such as AES-256), and data in transit uses Transport Layer Security (TLS) 1.2 or higher to prevent interception.

Authentication

Multi-factor authentication (MFA) is available for account access and high-value transactions, reducing the risk of unauthorized use.

Wallet Security

WowBat provides secure wallet infrastructure and technology. You are responsible for securing your account credentials and maintaining device-level security.

Monitoring

Real-time transaction monitoring systems analyze patterns to detect suspicious activities related to AML/CFT, supported by regular security audits conducted by independent experts.

Physical Security

Our servers and backups are housed in secure facilities with restricted access to prevent physical breaches.

Device Security

We recommend users maintain updated security on their devices, use strong passwords, and enable device-level security features.

Despite these measures, no system is entirely immune to breaches. In case of a significant data incident impacting sensitive information, we will notify you and relevant authorities promptly, as required by law.

5. How We Deal With Suspicious Funds and Transactions

At WowBat, we prioritize the security and integrity of our platform by proactively identifying and managing suspicious funds to protect our users and comply with Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) regulations.

Risk Assessment and Monitoring

We continuously monitor cryptocurrency transactions and wallet addresses for potential risks associated with:

  • Money laundering or terrorist financing
  • Sanctions violations or restricted jurisdictions
  • Known fraud schemes or illicit marketplaces
  • Stolen funds or compromised wallets
  • High-risk transaction patterns

Actions Based on Risk Assessment

Low Risk

Transactions and wallets with low risk profiles proceed normally without interruption, ensuring a seamless experience for legitimate users.

Moderate Risk

Transactions or wallets with moderate risk are flagged for additional monitoring. We observe patterns and activities over time to assess potential risks without imposing immediate restrictions. If patterns escalate or additional verification is needed, we may request voluntary clarification from the user (e.g., additional documentation) or conduct enhanced due diligence.

High Risk

Transactions identified as high risk are subject to immediate action, including:

  • Freezing Funds: We temporarily freeze the associated funds to prevent potential misuse.
  • User Notification: We notify the user via email or app alert, explaining the issue and requesting clarification or additional documentation.
  • Reporting: If the risk is confirmed (e.g., linked to sanctioned entities or known fraud), we file reports with relevant authorities and may permanently lock the user's account and block the wallet from our platform.

User Cooperation and Resolution

If your transaction or wallet is flagged, you will be contacted at support@wowbat.asia with clear instructions to resolve the issue. Funds are released promptly once compliance is verified, ensuring minimal disruption for legitimate users.

Continuous Improvement

We regularly review our risk assessment methodology and adjust our thresholds in response to emerging fraud patterns, regulatory updates, or technological advancements.

6. Retention of Your Information

We retain your personal data only as long as necessary:

Active Use

Data is kept while your account remains active to ensure uninterrupted service and ongoing KYC/AML monitoring.

Post-Termination

After account deactivation, we retain data for up to 5–7 years to comply with legal obligations (e.g., AML/CFT record-keeping requirements under international standards, tax laws, regulatory requirements in Turkey and other jurisdictions) or resolve disputes, unless a longer period is mandated by specific jurisdictions.

Deletion

Post-retention, data is securely deleted or anonymized. You may request earlier deletion where no legal obligation exists, though KYC/AML records may be exempt due to regulatory requirements.

Blockchain Data

Data recorded on blockchain networks is permanent and immutable. We cannot delete or modify blockchain transaction records.

7. Your Rights

You have extensive rights over your personal data, balanced with our legal obligations:

Access

Request a copy of your data, including KYC/AML records, in a machine-readable format.

Rectification

Correct inaccurate or incomplete information, such as outdated personal details or identification information.

Erasure

Request deletion of your data, subject to KYC/AML retention requirements and other legal obligations.

Portability

Obtain your data for transfer to another service, excluding certain compliance-related records.

Objection

Oppose certain types of processing, though AML/CFT monitoring may continue as required by law.

Withdrawal of Consent

Revoke consent at any time, though this may limit service access or require account closure if KYC/AML obligations cannot be met.

To exercise these rights, contact our Privacy Officer at privacy@wowbat.asia. We will respond within 30 days per GDPR standards, unless delayed by legal investigations or compliance requirements.

8. Marketing Communications

We may send you promotional messages about new features, services, or partnerships if you opt in during registration or later. To unsubscribe, email privacy@wowbat.asia or use the "unsubscribe" link in our communications.

9. Legal Compliance

We adhere to a robust framework of laws, with a focus on KYC/AML/CFT:

GDPR (EU)

Ensures lawful processing, transparency, and data rights for European users.

Turkish Data Protection Law (KVKK)

Complies with Turkish privacy and data protection requirements as the company is registered in Turkey.

International Standards

Complies with regulations in countries where our Services are available, including AML/CFT requirements.

FATF Recommendations

Guides our global AML/CFT practices, ensuring we combat money laundering and terrorist financing effectively.

Our legal basis for processing includes your consent, contractual necessity (e.g., providing wallet services), and compliance with legal obligations.

10. International Data Transfers

As a global service, your data may be transferred to jurisdictions outside your residence (e.g., servers in multiple regions) for processing by these third parties. We use Standard Contractual Clauses (SCCs), encryption, and contractual safeguards to ensure equivalent protection, meeting GDPR and other international standards.

11. Cookie Usage

When you access our website or use our Services, we may use cookies and similar technologies to improve your experience and ensure the security of your account. Cookies are small data files that your browser saves on your device when you visit our site. These cookies help us recognize you as a user, understand how you interact with our Services, and provide a more personalized experience. They also assist us in maintaining the security of your account by detecting irregular or suspicious activities.

We use cookies for several purposes, including:

  • Enabling essential functionalities (like logging in and accessing your wallet)
  • Analyzing usage patterns to enhance our platform
  • Detecting fraud and suspicious activity
  • With your consent, delivering personalized content

Some cookies are temporary and expire when you close your browser, while others may remain on your device for a longer period until they expire or you delete them.

You can choose to disable cookies through your browser settings, but please note that doing so may affect the functionality of our Services or your overall user experience. Additionally, some browsers offer a "Do Not Track" (DNT) feature. At this time, our Services do not respond to DNT signals, but you can manage your cookie preferences directly via your browser.

12. Updates to This Policy

We may revise this policy to reflect legal, operational, or technological changes. Updates will be posted at wowbat.asia and, if significant, notified via email or app alerts. Continued use of our Services after updates implies acceptance of the revised terms.

13. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will take steps to delete such information promptly.

14. Third-Party Links

Our Services may contain links to third-party websites and services. WowBat is not responsible for the privacy practices of these third-party sites. We encourage you to review the privacy policies of any third-party services before providing your information.

15. Contact Us

For questions, concerns, or to exercise your rights, reach out to:

General Inquiries:
contact@wowbat.asia

Privacy Requests:
privacy@wowbat.asia

Support:
support@wowbat.asia

Registered Address:
WIN WIN ORGANIZASYON VE DANIŞMANLIK LİMİTED ŞİRKETİ
Aksaray Mah. Koçibey Sk. Özel İşhanı No: 2 İç Kapı No: 11
Fatih, Istanbul, Turkey
Company Registration No. 414233-5

Website:
wowbat.asia

16. Data Protection Officer (DPO)

For data protection matters, you may contact our Data Protection Officer at:

Email:dpo@wowbat.asia

Last Updated: October 28, 2025 — Effective Date: October 28, 2025