Privacy policy.
This policy explains how Hecto Finance Limited handles personal data in connection with the public HECTX experience, Hecto PMX account access, product workflows, communications and support.
Who we are and when this policy applies
Hecto Finance Limited, a British Virgin Islands company, is the controller of personal data handled through the Hecto PMX interface unless a transaction notice or definitive product document identifies another controller. This policy applies when you browse public HECTX pages, sign in by email or wallet, connect an account, request or confirm a mint, review holdings or activity, configure a withdrawal destination, request support, manage communications or otherwise interact with Hecto PMX. An issuer, administrator, custodian, identity provider, wallet provider, settlement provider or other participant may separately determine how it handles data and may therefore act as an independent or joint controller under its own notice.
Data you provide or authorize
Depending on the feature and your eligibility, we may process your name, email address, country, language, professional or institutional details, account identifier, wallet address, linked-wallet information, support messages, communication preferences, withdrawal destination and label, mint or transfer instructions, and information needed to establish your authority to act for another person or organization. A live product may also require identity, beneficial-owner, source-of-funds, source-of-wealth, investor-classification, tax and compliance information. Do not send Hecto private keys, seed phrases, passwords or information that is not reasonably necessary for the requested purpose.
Data collected through use of the service
We may collect device and browser type, operating system, IP address, approximate IP-derived location, pages and controls used, timestamps, referral information, language, session and consent identifiers, authentication and security events, feature mode, error diagnostics and service-performance data. We may also create account, quote, subscription, deposit, mint, balance, portfolio, withdrawal, activity, support and audit records. Optional analytics is not activated unless the interface requests and receives the permission required by applicable law.
Data from wallets, ledgers and other sources
We may receive data from a wallet or access provider you choose, public or permissioned distributed ledgers, Canton Network participants and query services, Ethereum infrastructure, product issuers and administrators, custodians, settlement counterparties, compliance and identity providers, market and valuation data providers, support vendors, group companies, public records and organizations for which you are authorized to act. We may combine those records with information already associated with your account to reconcile transactions, maintain an accurate product record and protect the service.
Why we process data
We process data to provide and secure the public site and authenticated service; create and administer sessions and accounts; verify identity, authority and eligibility; apply anti-money-laundering, sanctions, fraud and other risk controls; generate, confirm and reconcile product instructions; display portfolio and activity records; administer destinations and support; provide service and security notices; maintain legal, accounting and audit evidence; improve reliability and accessibility; enforce our agreements; establish or defend claims; and comply with law, regulatory requests and lawful process.
Legal bases and your choices
The basis for processing depends on the data, purpose and law that applies. It may include taking steps at your request or performing a contract, complying with a legal obligation, protecting substantial public interests, pursuing legitimate interests such as service security, fraud prevention, record integrity and product improvement, or your consent. Where the British Virgin Islands Data Protection Act applies, we process data in accordance with its notice, choice, disclosure, security, retention, integrity and access principles, including consent where required. Where we rely on consent, you may withdraw it prospectively, but withdrawal does not affect processing already carried out and may prevent us from providing the relevant optional feature.
Identity, compliance and sensitive information
Compliance providers may verify documents, screen names and wallet activity, and return identity, fraud, sanctions, politically exposed person, adverse-media or eligibility results. We seek to receive verification results and the minimum supporting data reasonably needed rather than unnecessary source material. A provider may use document-authentication, facial-comparison or similar technology under a separate notice where permitted by law. We do not intentionally request health, belief, sexual-orientation or other unrelated sensitive information. Compliance decisions may be reviewed, delayed, restricted or reported where required by law or a defensible risk-control process.
Wallet and distributed-ledger transparency
A wallet address and its activity may identify or become linked to you. Transactions may be visible to network participants, analytics providers or the public and may be permanent. Permissioned systems can still distribute records among authorized operators. Hecto cannot ordinarily alter or erase information after it is validly recorded on a blockchain or distributed ledger. Privacy rights relating to Hecto-controlled off-ledger records remain available, but technical immutability and legal recordkeeping duties may limit the remedy that can be provided for ledger data.
Who may receive data
We may disclose data to Hecto group companies and personnel; product issuers, administrators, custodians and auditors; wallet, network, node, query, settlement, banking and payment providers; identity, compliance, fraud and security vendors; cloud, hosting, communications, support and analytics providers; market and valuation data providers; professional advisers and insurers; a buyer or successor in a genuine corporate transaction; and courts, regulators, tax, law-enforcement or other authorities where disclosure is required or lawfully appropriate. Recipients receive only the data reasonably needed for their role and are expected to protect it under applicable law and contractual duties. We do not sell personal data for money or share it for cross-context behavioral advertising.
International data transfers
Hecto and its providers operate internationally, so personal data may be processed outside the country where you live. Where transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, which may include an adequacy decision, approved contractual clauses, additional technical and organizational safeguards, your explicit consent in a permitted case, or another statutory exception. You may contact us for information about safeguards relevant to your data, subject to confidentiality and security limitations.
Retention and deletion
We retain data only for as long as reasonably necessary for the stated purpose, considering the nature and sensitivity of the data, account and product lifecycle, ledger and settlement reconciliation, security and fraud risk, support needs, limitation periods, tax, anti-money-laundering and other recordkeeping duties, and the need to establish or defend claims. We then delete, anonymize or securely archive data unless continued retention is required or permitted. Session and interface records generally have a shorter lifecycle than transaction, compliance, consent and audit evidence. Ledger records may remain indefinitely because Hecto does not control deletion at network level.
Security and incident response
We use administrative, technical and organizational measures designed to protect data in view of the service and risks, including access controls, environment separation, secure transport, logging, data minimization and service-provider controls where appropriate. No internet, wallet, software or ledger system is completely secure. You are responsible for securing your device, email, wallet, authentication factors and recovery material. If a personal-data incident creates a notification duty, we will notify affected individuals and authorities in the manner and timeframe required by applicable law.
Cookies, local storage and communications
Hecto PMX uses necessary cookies or browser storage for session security, legal and cookie-consent evidence, interface preferences and an explicitly selected Demo state. Optional analytics storage is denied by default and may be enabled only after an affirmative choice where required. The current interface does not load an analytics network script. A product-update preference may remain only on your device while marked as local; it is not a mailing-list registration until a communications service confirms it. Marketing messages require the permission required in your jurisdiction and include an appropriate unsubscribe method. You can revise optional cookie choices at any time.
Demo mode, analytics and automated decisions
Demo mode uses simulated product records stored for the current browser origin and does not create a live account, transaction, holding or ledger record. Do not enter real confidential financial information into Demo fields. Aggregated or de-identified information may be used for service measurement and development where permitted by law. Hecto does not currently use the PMX interface to make a decision based solely on automated processing that produces legal or similarly significant effects. If that changes, the relevant notice will describe the logic, significance, available safeguards and any right to request human review.
Your privacy rights
Depending on your location and applicable exemptions, you may request access, correction, deletion, restriction, portability or information about recipients; object to processing based on legitimate interests or direct marketing; withdraw consent; and complain to a competent data-protection authority. Where applicable, California residents may also request information about collection and disclosure and exercise applicable correction, deletion and opt-out rights without unlawful discrimination. Hecto does not currently sell personal information or share it for cross-context behavioral advertising. We may verify identity and authority before acting, and we may retain information required by law, security, fraud prevention, claims or an immutable ledger. To exercise a right, email legal@hecto.inc with enough detail to identify the request but no wallet secret or password.
Children, third-party links and changes
Hecto PMX is intended for adults and is not directed to anyone under 18. We do not knowingly collect a child’s personal data through PMX. Third-party sites, wallets and services have their own privacy practices, for which Hecto is not responsible. We may update this policy to reflect changes in the product, providers, law or processing. We will revise the date and, where required, provide additional notice or request renewed acknowledgement before a material change takes effect.
Contact and complaints
Privacy questions, rights requests and legal correspondence may be sent to legal@hecto.inc. Please identify your country and the Hecto service involved so the request can be routed correctly. You may also lodge a complaint with the data-protection authority that has jurisdiction over you. If you need this policy in an accessible format, contact the same address.
