NAFH - Privacy Policy

Last updated: 1 January 2026

This Privacy Policy explains how NAFH ("NAFH", "we", "us", "our") collects, uses, stores, and protects your personal data when you use our platform, website, and services available at nafhcircles.com (collectively, the "Platform" or "Services").

By creating an account, accessing, or using NAFH, you agree to this Privacy Policy. If you do not agree, you should not use the Platform.

1. Who We Are

NAFH operates an expert-led crypto trading and affiliate platform.

We provide:

  • Non-custodial, API-based trading management on your own exchange accounts
  • An affiliate and compensation plan with internal wallets and reward structures

For any privacy-related questions, you can contact us at:

  • Email: support@nafhcircles.com
  • Website: https://nafhcircles.com

2. What Data We Collect

We collect different types of data to operate the Platform, provide services, improve performance, and comply with legal obligations.

2.1 Information You Provide Directly

When you register or use the Platform, you may provide:

  • Account details
    • Full name
    • Email address
    • Password (hashed, not stored in plain text)
    • Country (if requested)
  • Profile & settings
    • Preferred language
    • Notification preferences
    • 2FA / security settings (e.g. that you enabled Google Authenticator)
  • Referral / affiliate information
    • Who referred you ("Referred By")
    • Your own referral link and related statistics
  • Payment & wallet information (on NAFH)
    • Internal wallet balances (Commission Wallet, Affiliate Wallet, NAFH Trade Wallet, etc.)
    • Deposit and withdrawal requests (amount, token, network, destination address)

We do not see or control your external wallet private keys.

2.2 Trading & API-Related Data

To provide trading management services, we may collect and process:

  • Exchange name
  • API key metadata (API key, masked/hashed storage of secrets depending on our implementation)
  • Technical configuration (e.g. IP-restricted or not)
  • Trading and performance data received via the API:
    • PnL summaries
    • Positions opened/closed
    • Trade pairs and volumes
    • Balance snapshots related to trading

We do not store your Exchange login credentials (email/password); those stay with the Exchange

2.3 Usage & Technical Data

When you access NAFH, we may automatically collect:

  • Device and browser information (e.g. device type, OS, browser type)
  • IP address and approximate location (city/country level)
  • Log data (pages visited, buttons clicked, timestamps, referring pages)
  • Session information and error logs (to debug issues and improve stability)

2.4 Cookies and Similar Technologies

We may use cookies and similar technologies to:

  • Keep you logged in securely
  • Remember preferences and language
  • Analyze site usage and performance
  • Support marketing and referral tracking

You can control cookies through your browser settings, but some features may not work properly if you disable them.

2.5 Optional Communication & Support Data

If you contact us via:

  • Email
  • Support chat
  • Telegram or other official support channels

We may collect:

  • Your message content
  • Email address or username
  • Support ticket history

3. Why We Collect Your Data (Purposes)

We use your data for the following purposes:

3.1 To Provide and Operate the Services

  • Create and manage your account
  • Enable trading management services via your Exchange API
  • Process internal wallet activity and performance fees
  • Manage subscriptions, bonuses, and affiliate rewards

3.2 To Secure the Platform

  • Detect suspicious activity and prevent fraud
  • Monitor for unauthorized access attempts
  • Maintain system integrity and user safety

3.3 To Communicate With You

  • Send service-related notifications
  • Respond to your support requests
  • Provide important updates or security alerts

3.4 To Improve and Develop the Platform

  • Analyze usage trends and performance
  • Fix bugs and improve stability
  • Develop new tools, features, and educational content

3.5 For Legal, Compliance, and Risk Management

  • Comply with legal obligations
  • Enforce our Terms and policies
  • Respond to legal requests or regulatory inquiries

5. How We Share Your Data

NAFH does not sell your personal data.

We may share data in the following limited ways:

5.1 Service Providers

With third-party service providers who help us operate the Platform, such as:

  • Hosting providers and cloud infrastructure
  • Email and notification services
  • Analytics and error tracking tools
  • Payment / blockchain gateway services (where applicable)

These providers only receive the data necessary to perform their services and are expected to handle it securely.

5.2 Exchanges and External Platforms

We communicate with your chosen Exchange via API to:

  • Place and close orders
  • Retrieve trading and balance data

However:

  • We do not share your personal identity information with Exchanges beyond what is needed in the API integration.
  • Your direct relationship with the Exchange is independent, and their own Privacy Policy applies to any data they collect about you.

5.3 Legal and Compliance

We may disclose certain data if:

  • Required by law, regulation, court order, or request from competent authorities, or
  • Necessary to protect rights, safety, or property of NAFH, our users, or the public, or
  • Needed to investigate suspected fraud, security issues, or policy violations.

5.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, user data may be transferred as part of the business, subject to the same or equivalent privacy obligations.

6. International Transfers

Our servers, service providers, or team members may be located in countries other than your own, including Singapore and other jurisdictions.

By using NAFH, you understand and agree that your data may be transferred, stored, and processed in these locations.

We take reasonable steps to ensure that any such transfers comply with applicable data protection laws and that your data remains protected.

7. Data Retention

We retain your personal data for as long as necessary to:

  • Provide the Services and maintain your account
  • Fulfill the purposes set out in this Privacy Policy
  • Comply with legal, accounting, or reporting obligations
  • Resolve disputes and enforce our agreements

In general:

  • Account & profile data: kept while your account is active and for a reasonable period thereafter.
  • Transaction, wallet, referral, and trading records: kept for periods required by law or internal policies.
  • Logs & technical data: kept for shorter periods (unless needed for security or legal reasons).

When data is no longer needed, we aim to delete or anonymize it safely.

8. Data Security

We take security seriously and use reasonable technical and organizational measures to protect your data, including:

  • Encrypted connections (HTTPS) where appropriate
  • Secure storage of passwords (hashed)
  • Measures to protect API keys and sensitive credentials
  • Access controls and internal permissions
  • Monitoring for unusual or suspicious activities

No system can be 100% secure. You also play a key role in security by:

  • Using strong, unique passwords
  • Enabling 2FA
  • Keeping your devices and email secure
  • Not sharing your login details or API keys

9. Your Rights & Choices

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that we correct inaccurate or incomplete data.
  • Deletion: request deletion of your data, subject to legal and operational limitations.
  • Restriction: request that we restrict certain processing in specific circumstances.
  • Objection: object to certain processing based on legitimate interests.
  • Portability: request data in a structured, commonly used format where technically feasible.

To exercise any of these rights, contact us at support@nafhcircles.com with enough information to identify your account.

We may need to verify your identity before fulfilling your request.

Please note:

Some data may be retained to comply with legal obligations or for legitimate business purposes (e.g. transaction logs, fraud prevention, accounting).

10. Children's Privacy

NAFH is not intended for individuals under 18 years of age (or the age of majority in your jurisdiction).

We do not knowingly collect personal data from minors.

If we become aware that a minor has created an account or provided personal data, we may:

  • Delete or restrict the account, and
  • Remove personal data reasonably quickly, unless retention is required by law.

If you believe a minor has used NAFH, please contact us at support@nafhcircles.com

11. KYC and Identity Verification

At this time:

  • NAFH does not require mandatory KYC (Know Your Customer) verification for general use of the Platform.

However, we reserve the right to:

  • Introduce KYC or additional verification processes in the future if required by law, regulation, or internal risk/compliance policies.
  • Request identity documents or additional information in specific cases (e.g. suspected fraud, legal requests, high-risk activity).

If KYC is introduced, we will update this Privacy Policy and our Terms accordingly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes in laws or regulations
  • Changes in our services, features, or business model
  • Feedback and operational needs

When we make material changes, we will:

  • Update the "Last updated" date at the top, and
  • Where appropriate, notify you via email or dashboard notification.

Your continued use of NAFH after such changes means you accept the updated Privacy Policy

14. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or how we handle your data, you can contact us at:

  • Email: support@nafhcircles.com
  • Website: https://nafhcircles.com

We'll do our best to respond within a reasonable timeframe.