Last Updated: June 2, 2021
CatalX CTS Ltd. (dba. Catalyx Exchange, “CATALYX’, “our”, “we”, or “us”, as context may dictate) recognizes the importance of privacy and the sensitivity of personal information. We are committed to only collecting and storing personal information where absolutely necessary for legitimate business purposes. We are committed to keeping necessary personal information accurate, secure, and confidential.
Your privacy is critically important to us. At CATALYX, we believe in the following fundamental privacy principles:
· We are mindful of the personal information we may ask you to provide and the personal information that we collect about you throughout the operation of our services.
· We retain personal information for only as long as is necessary.
· We strive to make it as simple as possible for the individual to control their personal information that is shared publicly, kept private, or destroyed.
· We aim to be fully transparent as to how we gather, use, and share the individual’s personal information.
B. PRIVACY OFFICER
Personal information is any information that allows an individual, to be identified directly or indirectly including but not limited to: name, date of birth, title, address, telephone number, email address, and banking information. This policy applies to all personal information that is collected, used, or disclosed by CATALYX in any form, whether oral, electronic or written. Our services are not intended for minors. We do not knowingly or intentionally collect information from children under the age of eighteen (18).
CATALYX is accountable for personal information in its possession or control. To ensure accountability, we have informed our users about our policies and practices.
CATALYX will seek assurances regarding the privacy of personal information that may be transferred to third parties for the purpose of providing you with our services, including but not limited to our cloud storage provider, Azure (Microsoft Privacy Statement) for use or processing by requiring that those third parties safeguard all personal information in a way that is consistent with the CATALYX practices and as is required by law. Our third -party partners are required by agreement to respect the confidentiality of personal information.
CATALYX will implement appropriate procedures to safeguard your personal information.
Examples of such safeguards include but are not limited to:
(a) CATALYX will safeguard personal information in its possession or control from loss or theft and from unauthorized access, use, disclosure, copying or modification through appropriate security measures depending on the sensitivity, format and storage of the personal information.
(b) CATALYX will use appropriate care and diligence when destroying or disposing of personal information to prevent unauthorized access, use or disclosure of any personal information.
(c) CATALYX will ensure the use of proper encryption and business practices when transporting personal information internally and to third parties.
(d) CATALYX will have appropriate disaster planning in place and off-site mirrors of personal information and infrastructure to ensure a prompt and appropriate response.
CATALYX employees or agents with access to personal information are required by agreement to respect the confidentiality of such information. As mentioned above, our third-party partners are likewise required by agreement to respect the confidentiality of personal information.
2. Notice and Consent
CATALYX will provide notice and obtain consent as appropriate regarding the collection, use or disclosure of personal information.
CATALYX will outline to users, clients, visitors, and other individuals the purposes for which personal information will be collected, used or disclosed. The purposes may be provided in writing or electronically.
CATALYX collects, uses and discloses personal information that may include but is not limited to the following:
(c) Date of Birth
(d) Email Address
(f) Banking Institution
(g) Bank Account Number
CATALYX collects, uses and discloses personal information for a variety of purposes, including but not limited to the following:
(a) to establish and maintain a secure environment;
(b) to register an account with us and verify your identity as required by applicable legislation;
(c) to provide you with our trading services;
(d) to establish and maintain relations with clients, users, contractors and suppliers including providing further information about CATALYX, its affiliates and subsidiaries and our products and services;
(e) to develop, enhance, market or provide our products or services;
(f) to understand users’ needs and preferences;
(g) to develop, enhance, market or provide products and services to meet users’ needs or expectations;
(h) to manage and develop CATALYX business and operations, including personnel and employment matters.
(i) to meet legal and regulatory requirements such as Financial Transactions and Report Analysis Centre (FINTRAC) and the Canadian Anti-Fraud Centre (CAFC); and
(j) such additional and necessary business purposes as may reasonably be required.
On request, we will either provide appropriate and full reasons on the purpose or object for such collection or refer the individual to the designated person(s) to provide appropriate and full reasons.
Personal information will not be used or disclosed for any new purpose without first identifying the new purpose and providing notice to the user and obtaining the consent of the person, as applicable, unless required by law. Some examples of collection, use or disclosure of personal information without notice or consent may include circumstances where:
(a) in cooperation with or at the request of the appropriate authorities, where seeking the consent of the individual might defeat the purpose of collecting the information, such as in the investigation of a breach of law
(b) it is plain and obvious that it is in the individual’s best interest and reasonable attempts to give notice and obtain consent cannot be done in a timely manner;
(c) in the reasonable judgment of CATALYX, it appears that there is imminent danger to property which could be avoided or minimized by disclosure of the information to a public authority or agent of a public authority; and
(d) it is to an employee or representative representing CATALYX, to comply with a subpoena, warrant or other court order, or as may be otherwise required or authorized by law.
In determining the appropriate form of notice or consent, CATALYX will consider the sensitivity of the personal information and the reasonable expectations of the user, customer, or other individual as the case may be.
3. Limiting Collection, Use, Disclosure, and Retention of Personal Information
CATALYX will take reasonable steps to limit the amount and type of personal information it collects uses and discloses. Personal information will be collected by fair and lawful means and in a fashion that is not unreasonably intrusive. CATALYX will retain personal information for only as long as is reasonably necessary for the identified purposes, or as required by law.
If personal information has been used to make a decision about a user, or another individual, CATALYX will keep the personal information for a reasonably sufficient period to allow the individual to have access to it after such a decision has been made. CATALYX will maintain controls, schedules, practices, and procedures for retention and destruction of personal information.
4. Access, Openness and Compliance
CATALYX will readily make digitally available to all individuals this policy and information about its practices relating to the management of personal information. On request, by email or letter, CATALYX will also advise if and how an individual can access and control their personal information.
On written request by email or letter, CATALYX will inform the requester of the personal information it has in its possession and control relating to the requester. Individuals can seek access to their personal information by contacting the Privacy Officer by email at [email protected]. With the exception of employee personal information, CATALYX may, at its own discretion, charge a minimal fee that represents the cost required to retrieve and provide the requested information. CATALYX may, at its own discretion, provide an estimate of the fee in advance, and in some cases, CATALYX will require a deposit for part or all of the fee.
Upon written request by email or letter, CATALYX will provide a full account of the collection, use, and disclosure of the requester’s personal information. CATALYX will identify from whom the personal information was collected, to whom it has been disclosed, and how and when disclosure took place.
In certain cases, CATALYX may not provide access to personal information that is held. Some examples of this include:
(a) personal information that is work product information and/or disclosing such personal information may reveal confidential commercial or corporate information;
(b) personal information that is protected by solicitor-client privilege;
(c) where the denial of access is authorized by law;
(d) where information relates to existing or anticipated legal proceedings related to or against the individual making the request;
(e) where the information is collected for purposes of an investigation or the information is the result of an arbitration or other formal dispute resolution process;
(f) where the denial of access is necessary to protect CATALYX’s rights and property or the rights and property of associated organizations, affiliates, individuals, agents, employees or shareholders; or
(g) where the request is frivolous or vexatious.
If CATALYX denies an individual’s request for access to personal information, CATALYX will provide brief reasons for refusal to the individual.
Any person will be able to challenge the accuracy and completeness of their personal information and in appropriate circumstances, CATALYX will amend the information. Any unresolved differences as to accuracy or completeness will be noted, where applicable.
CATALYX understands and will address any complaint about these privacy practices with the utmost care and diligence. CATALYX will investigate any complaint and will take all reasonable steps to resolve it.
E. Information We Collect
We only collect information about the person if there is sufficient reason to do so. For example:
· To Provide our automated auction platform for matching individual orders to buy or sell securities with continual price discovery in a central limit order book (CLOB) (the “Services”);
· To Facilitate Communications;
· To Improve our Services.
We will only collect information using three (3) methods:
(a) if and when the person provides information to us,
(b) automatically through operating our Services, and
(c) from outside sources.
F. Information You Provide to Us
We collect information that you provide to us. The amount and type of information depends on the context and how we use the information. Here are some examples:
· Account Information: We ask for basic information from you in order to set up your account. For example, we require individuals who sign up for a CATALYX account to provide a username and email address, as well as all the information required under the applicable AML (anti-money laundering) and KYC (know your customer) regulations and best practices.
· Public Profile Information: If you have an account with us, we collect the information that you provide for your public profile.
· Transaction and Billing Information: You will provide additional personal and payment information that is required to process your transactions and your payments, such as your name, credit card information, bank information and contact information.
· Credentials: Depending on the Services you use, you may also provide us with credentials for your wallets, financial institutions, or other account credentials.
· Communications with Us: You may also provide us information when you respond to surveys, communicate with our employees and representatives, or use our services.
G. Information We Collect Automatically
We also collect some information automatically:
· Log Information: Like most online service providers, we collect information that web browsers, mobile devices, and servers typically make available, such as the browser type, IP address, unique device identifiers, language preference, referring site, the date and time of access, operating system, and mobile network information. We collect log information when you use our Services.
· Usage Information: We may collect information about your usage of our Services. We may also collect information about what happens when you use our Services along with information about your device (e.g., screen size, name of cellular network, and mobile device manufacturer). We use this information to, for example, provide our Services to you, as well as get insights on how people use our Services, so we can make our Services better.
· Location Information: We may determine the approximate location of your device from your IP address. We collect and use this information to, for example, calculate how many people visit our Services from certain geographic regions. We may also collect information about your precise location via our mobile apps (when you give us access to your mobile device’s location information) if you provide informed consent to allow us to do so via your mobile device’s operating system’s permissions.
· Stored Information: We may access information stored on your device through your device’s operating system’s permissions if you provide informed consent to allow us to do so.
· Interactions with Other Users’ Sites: We may also collect some information about the person’s interactions with other users’ sites while they are logged in to their account with us.
H. Information We Collect from Other Sources
We may also get information about you from other sources. The information we receive depends on which services you authorize and any options that are available.
I. Sharing Information
We do not sell our users’ private personal information.
Your personal information may be stored, processed, or otherwise used by us, our affiliates, or our service providers, both inside and outside of Canada. As a result, that country's courts, governments, or law enforcement agencies could obtain disclosure of your information in accordance with that country's laws.
We share personal information in the limited circumstances spelled out below and with appropriate safeguards on your privacy:
· Third Party Vendors: We may share personal information with third party vendors who need to know such personal information in order to provide their services to us, or to provide their services to users. This group includes vendors that help us provide our Services such as:
· Payment providers that process your credit and debit card information,
· Fraud prevention services that allow us to analyze fraudulent payment transactions,
· Postal and email delivery services that help us stay in touch with the user,
· Customer chat and email support services that help us communicate with any person,
· those that assist us with our marketing efforts (e.g., by providing tools for identifying a specific marketing target group or improving our marketing campaigns),
· those that help us understand and enhance our Services, and companies who may need information about you in order to provide technical or other support services to you.
We require vendors to agree to privacy commitments in order to share information with them.
· Legal Requests: We may disclose personal information in response to a subpoena, court order, or other governmental request.
· To Protect Rights, Property, and Others: We may disclose personal information when we believe in good faith that disclosure is reasonably necessary to protect the property or rights of CATALYX, third parties, or the public at large.
· With Consent: We may share and disclose information with the person’s consent. For example, we may share personal information with third parties with which the person has authorized us to do so.
· Aggregated or De-Identified Information: We may share information that has been aggregated or reasonably de-identified, so that the information could not reasonably be used to identify you. For instance, we may publish aggregate statistics about the use of our Services, and we may share a hashed version of your email address to facilitate customized ad campaigns on other platforms.
· Published Support Requests: If you send us a request (for example, via a support email or one of our feedback mechanisms), we reserve the right to publish that request in order to help us clarify or respond to your request or to help us support other users after properly anonymizing and de-identifying the person
J. Information Shared Publicly
Information that you expressly consent to be made public may be disclosed publicly.
How Long We Keep Information
We destroy information about you when we no longer need the information for the purposes for which we collect and use it and we are not legally required to continue to keep it.
We cannot guarantee 100% security, however, we strive, and we work very hard to protect information about you against unauthorized access, use, alteration, or destruction, and take reasonable measures to do so, such as monitoring our Services for potential vulnerabilities and attacks.
You have several choices available when it comes to information you disclose:
· Limit the Information that You Provide: If you have an account with us, you can choose not to provide the optional account information, profile information, and transaction and billing information. Please keep in mind that if you do not provide this information, certain features of our Services, such as for example, paid, premium themes, may not be accessible.
· Limit Access to Information on Your Mobile Device: Your mobile device operating system should provide you with the ability to discontinue our ability to collect stored information or location information via our mobile apps.
· Opt-Out of Electronic Communications: You may opt out of receiving promotional messages from us. Just follow the instructions in those messages. If you opt out of promotional messages, we may still send you other messages, like those about your account and legal notices.
· Close Your Account: We would be very sad to see you go if you no longer want to use our Services. Please keep in mind that we may continue to retain your information after closing your account–for example, when that information is reasonably needed to comply with (or demonstrate our compliance with) legal obligations such as law enforcement requests, or reasonably needed for our legitimate business interests.
K. Your Rights
Canadian privacy laws give you rights with respect to your personal data, subject to any exemptions provided by the law, including the right to:
· Request access to your personal data;
· Request correction or deletion of your personal data;
· Object to our use and processing of your personal data;
· Request that we limit our use and processing of your personal data; and
You can usually access, correct, or delete your personal data using your account settings and tools that we offer, but if you aren’t able to do that, or you would like to contact us about one of the other rights, reach out to us by email to [email protected].
Where applicable, we will seek your express consent to contact you, including by way of commercial electronic messages. This consent is sought by CatalX CTS Ltd. and you can contact us at 604-359-8878 or at 421 7 Ave SW 30th Floor, Calgary, AB T2P 4K9. You can unsubscribe at any time from receiving commercial electronic messages by following the instructions in the message.
Even if you have opted out of receiving marketing communications from us, please be aware that we may still contact you for other purposes. For example, we may contact you to provide communications you have consented to receive, regarding the products or services we provide to you, or if you contact us with an inquiry.
You can also send a letter to CATALYX at the following address: 421 7 Ave SW 30th Floor, Calgary, AB T2P 4K9
Attention: Privacy Officer.
If you have any issues relating to the above, please reach out to us, via email.