Legal
Data Protection and Privacy Policy
DSM AGENCY LTD (hereinafter referred to as the "Company", "We", "Us", or "Platform") is committed to protecting and respecting the privacy of our users. This Data Protection and Privacy Policy explains how we collect, process, protect, and retain personal data in strict conformity with the United Kingdom General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the supervisory guidance issued by the Information Commissioner's Office (ICO).
1. DATA CONTROLLER IDENTIFICATION
The data controller responsible for your personal data is DSM AGENCY LTD, registered in England and Wales under company number 17395633 (Registered Address: 1st Floor 124 Cleveland Street, London, United Kingdom, W1T 6PG).
- For any data protection inquiries, exercise of data subject rights, or complaints, you can contact our Data Protection Officer at: compliance@dsm-agency.com.
2. CATEGORIES OF DATA PROCESSED
To deliver our digital infrastructure, SaaS analytics, and administrative services, we collect and process the following categories of personal data:
- Primary Identity Data: Full legal name, gender, date of birth, nationality, and high-resolution photographic copies of government-issued identity documents (passports, national ID cards).
- Contact and Residence Data: Residential address, utility bills or bank statements used as proof of address, email address, and telephone number.
- Biometric Security Data: Geometrical facial maps processed via automated identity-matching systems during onboarding to prevent multi-account fraud and identity theft.
- Operational & Analytics Data: Earnings summaries, performance metrics, payment receipts, technical platform logs, and transactional history generated from Supported Digital Platforms.
- Technical Interface Data: IP addresses, geographical location data, browser type, device information, and interaction history on our website.
3. LEGAL GROUNDS FOR DATA PROCESSING
We process your personal data under the following legitimate legal bases:
- Performance of a Contract (Art. 6(1)(b) UK GDPR): Processing is strictly necessary to register your account, set up your Client Ledger Node, and deliver the services described in our Terms of Service.
- Compliance with Legal Obligations (Art. 6(1)(c) UK GDPR): We must collect and retain comprehensive identity and verification records to satisfy UK anti-money laundering (AML), tax reporting, and fraud prevention regulations.
- Legitimate Interests (Art. 6(1)(f) UK GDPR): We process operational and technical data to ensure system security, prevent platform abuse, and mitigate financial and transactional risks.
4. DATA SHARING AND TRANSNATIONAL TRANSFERS
We process all personal data confidentially. We never sell your personal data. To provide our technical infrastructure, data may be shared strictly with authorized B2B partners, including:
- Regulated Payment Partners & Mass Payout Providers: Licensed financial institutions to allocate tracking IDs and process transactions.
- Compliance Verification Vendors: Automated service providers who verify the authenticity of identity documents and perform sanctions/PEP screening.
- Regulatory and Law Enforcement Authorities: When legally requested or required under United Kingdom anti-money laundering, tax, or national security directives.
5. DATA SECURITY, CRYPTOGRAPHY, AND STORAGE
5.1. Cryptographic Protection: We implement robust administrative, physical, and technological security controls. All personal data, identity documents, and operational logs are protected using industry-standard cryptographic protocols, including SSL/TLS in transit and AES-256 encryption at rest.
5.2. Geolocation of Servers: Our primary servers and databases are hosted within highly secure data centers located within the United Kingdom and the European Economic Area (EEA), ensuring maximum regulatory compliance and protection.
6. STATUTORY RETENTION PERIODS
In compliance with the United Kingdom Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 and corporate tax standards, all foundational identity records, KYC documents, and financial transaction communications must be securely retained for a mandatory statutory duration of five (5) years following the formal termination or closure of the Creator's platform account.
7. YOUR DATA SUBJECT RIGHTS
Under the UK GDPR, you possess the following statutory rights regarding your personal data:
- Right of Access: The right to request a complete copy of the personal data we hold about you.
- Right to Rectification: The right to request the immediate correction of inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): The right to request deletion of your data, subject to statutory retention overrides (e.g., AML record-keeping laws).
- Right to Restriction and Objection: The right to restrict processing or object to processing based on legitimate interests.
- Right to Portability: The right to receive your structured personal data in a machine-readable format.
- To exercise any of these rights, please contact our Support Department at support@dsm-agency.com.