blackdaycardNon-custodial

Black Day Card Privacy Policy

Last updated: August 2026

Introduction

This Privacy Policy (the “Policy”) describes how IRGA LLP, a company incorporated under the laws of the Republic of Kazakhstan, with its registered office at 65 Karelskaya Street, Turksib District, Almaty, Kazakhstan (hereinafter referred to as the “Company”), collects, uses, stores, discloses, and protects personal information obtained from users (hereinafter referred to as “Users” or “you”) of its website, application, Telegram bot, and related digital platforms (collectively, the “Platform”), operated under the brand Black Day Card.

The Company is committed to protecting your privacy and handling your personal data in accordance with applicable privacy and data protection laws. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the terms of this Policy. This Policy forms an integral part of the Terms of Use.

Article 1. Purpose and Basis

In order to provide its digital-asset and card services to Users, IRGA LLP, operating under the brand Black Day Card, collects certain personal information from you when you register, log in, or use the website, application, Telegram bot, or related interfaces (collectively, the “Platform”). This Policy, together with other applicable policies and notices of the Company, sets out the rules governing the collection, use, and protection of such information to prevent misuse or unauthorized access.

Black Day Card is built on a non-custodial architecture and collects only the amount of data necessary for the technical operation of the Platform, the provision of the Services (including card services), and compliance with applicable regulatory requirements.

Black Day Card never collects, stores, or has access to Users’ private keys or seed phrases.

Article 2. Designation

For the purposes of this Policy:

  • “Company,” “we,” “us,” or “our” mean IRGA LLP, a company incorporated under the laws of the Republic of Kazakhstan, with its registered office at 65 Karelskaya Street, Turksib District, Almaty, Kazakhstan, operating under the brand Black Day Card.
  • “Platform” means the website, application, Telegram bot, and any other digital interface operated under the brand Black Day Card.
  • “User,” “you,” or “your” mean any natural or legal person accessing or using the Platform.

The Company and the User are collectively referred to as the “Parties”, and individually as a “Party.”

Article 3. Definition and Interpretation

The following terms shall have the meanings ascribed to them below, unless the context requires otherwise:

  • Personal information: all information that is recorded electronically or otherwise and can be used, whether independently or in combination with other information, to identify a particular natural person or reflect that person’s pattern of behavior, including sensitive personal information.
  • Sensitive personal information: including, without limitation, identity-document details, biometric information, payment-account details, registered address, transaction information, and similar data.
  • Deletion of personal information: the deletion of personal information from systems used for routine business functions so that such information cannot be accessed or retrieved, subject to mandatory retention under applicable law.

Article 4. Scope of Application

This Policy applies to all Users who access or use the Black Day Card website, application, Telegram bot, and related Platforms. Users shall comply with this Policy, subject to and as permitted by the laws relating to the protection of personal information in the country or region where they are based.

Article 5. Invocation

Any statute, decree, or administrative regulation referred to in this Policy shall refer to the latest amended version thereof, whether such amendment is made before or after the date of this Policy.

Article 6. Headings

The headings used in this Policy are for convenience only and shall not be used to interpret its terms.

Article 7. Use of the term “include”

The term “include” used herein shall always mean “include but not limited to”, unless this Policy specifies otherwise.

Article 8. User Consent and Authorization

By accessing or using the Platform, the User is deemed to have expressed acceptance, consent, undertaking, and confirmation of the following:

  • the User agrees, on a voluntary basis, to disclose personal information to us where required for the Services;
  • the User will abide by all terms of this Policy;
  • the User agrees and authorizes the Company to collect the User’s personal information when the User registers, logs in, and/or uses the Services;
  • the User agrees to this Policy and to subsequent amendments made in accordance with Article 23;
  • the User agrees that the Company may contact the User in connection with products and services that may be of interest, unless the User has indicated that they do not wish to receive such communications.

Article 9. Information Collected

Users agree that the Company may use cookies and similar technologies to track actions in connection with use of the Platform and may collect and record technical information, including IP address, approximate geographical location, and other data.

Personal data which we may collect include:

  • Web3 authorization: the wallet’s public address and a cryptographic message signature.
  • Personal identification information: full name, date of birth, nationality, contact details (email and/or Telegram ID), country of residence, and, where required for light KYC or card issuance, photographs and address information.
  • Formal identification information: government-issued identity documents and related data deemed necessary to comply with legal obligations under financial or anti-money laundering laws, processed through authorized third-party KYC providers where applicable.
  • Transaction information: information about operations you make on the Services, such as amounts, assets, timestamps, statuses, and public blockchain addresses used to interact with the Platform.
  • Card-related data: card status, limits, and transaction history, as serviced by the card issuer.
  • Message content: feedback, support correspondence, and similar communications.
  • Device and usage data: device type, operating system, browser, language, crash logs, session metadata, and how you interact with the Platform.

We may also collect and store certain information automatically when you visit the Platform, including:

  • how you came to and use the Services;
  • device type and unique device identification numbers;
  • device event information (such as crashes, browser type, language, date and time of the request, and referral URL);
  • pages accessed and links clicked;
  • broad geographic location (country or city level);
  • technical data collected through cookies, pixel tags, and similar technologies.

This information helps us address support issues, improve performance, provide a streamlined experience, and protect accounts from fraud.

Article 10. Device Permissions

Where the application requests device permissions (for example camera, notifications, or network access), those permissions are requested only when needed for a specific function, such as identity verification or service delivery. Granting a permission is not implied by agreeing to this Policy. You may revoke permissions in your device settings. Refusing a permission will not affect unrelated functions.

Article 11. Supply of Information

If Users voluntarily use the Services, they may be required to provide:

  • Identity information: information that helps the Platform verify whether the User is eligible to use the Services, including name, address, official proof of identity, and other information that may assist in verification.
  • Service information: information that helps the Company contact the User and provide the Services, including telephone number, valid email address, Telegram ID, and payment or card-related account information as required.

Article 12. Changes in the Method of Information Collection

When a User uses the Platform, the Company may collect additional necessary information through official contact channels published on the Platform, or by any other method that complies with applicable law, in order to improve functionality, enhance security, or as required by a court order, applicable law, or a competent authority.

Article 13. Third-Party Websites and Sources

If a User follows a link on the Platform to a third-party website or partner, the User agrees to comply with that third party’s separate privacy policy. The Company is not responsible for the content or activities of such third-party websites or partners.

Sources of information may include:

  • Public databases and ID verification partners: used to verify identity and screen against sanctions lists in accordance with applicable law.
  • Blockchain data: public blockchain data may be analyzed to ensure parties using the Services are not engaged in illegal or prohibited activity, and to assess transaction trends.
  • The card issuer and payment partners: data necessary for issuance and servicing of cards.
  • Infrastructure, advertising, and analytics providers: de-identified or technical information about how you found and use the Platform.

Article 14. Installation of Cookies

When a User visits the Platform, the Company may use cookies and similar technologies (including analytics tools) to record performance and, where applicable, the effectiveness of communications. Cookies are a small amount of data sent to the User’s browser and stored on the User’s device.

Article 15. Function of Cookies

Cookies are used to remember settings, enable core functionality, compile anonymous usage statistics, and secure sessions. Cookies collect aggregate statistics and are not used to obtain unrelated data from the User’s device, email, or files. They enable the Platform to recognize the User’s browser and remember information.

Article 16. Disabling Cookies

Most browsers are preset to accept cookies. Users may set their browsers to reject cookies or to notify them when cookies are installed. Certain features of the Platform may be unavailable if cookies are disabled. Non-essential cookies are used with the User’s consent where required by law.

Article 17. Use of Information

Information collected by the Company is used to:

  • provide the Services via the Platform, including the wallet interface, swaps, and card issuance and servicing;
  • identify and confirm Users’ identities where required;
  • improve and upgrade the Services and respond to support requests;
  • keep statistics relating to use of the Platform and carry out analysis required for security, compliance, or cooperation with competent authorities;
  • personalize the User experience;
  • facilitate transactions requested by the User;
  • send service notices, updates, and, where permitted, product information (with the ability to unsubscribe);
  • fulfill other purposes specified in the Terms of Use and applicable law.

The User’s personal information will not be sold, exchanged, or otherwise provided to any third party for that party’s own marketing without the User’s consent, except where doing so is necessary to complete the transactions the User requires or as otherwise permitted by this Policy.

Article 18. Information Disclosure to Third Parties

The Company does not sell, trade, or otherwise transfer personal information for unrelated commercial purposes. Disclosure may be made, to the extent necessary, to:

  • affiliates and trusted third parties who help operate the Platform, manage the business, or provide services to Users, provided they keep such information confidential;
  • KYC/AML providers, the card issuer, payment partners, and blockchain-analytics providers;
  • infrastructure providers (hosting, security, analytics);
  • competent authorities upon a lawful request.

Any such disclosure shall be in accordance with applicable law, necessary to execute the Company’s policies and ensure proper functioning of the Platform, or necessary to protect the rights, property, or safety of the Company or others. Recipients may not use the information for marketing or any other purpose that has not been agreed.

Article 19. Protection of Personal Data

The Company adopts appropriate physical, electronic, management, and technical measures to protect Users’ personal data, including:

  • Physical measures: records stored in an appropriately secure location.
  • Electronic measures: data stored in systems and storage media subject to strict access restrictions.
  • Management measures: only duly authorized staff may access personal data, on a need-to-know basis, and must comply with internal confidentiality rules.
  • Technical measures: encryption in transit (such as TLS) and, where appropriate, at rest.
  • Other measures: network servers protected by firewalls and monitoring.

Article 20. Deletion of Personal Information

After account deletion, the User will no longer be able to log in to or use the Platform. Personal data that is not subject to mandatory retention is deleted or irreversibly anonymized. Data that must be retained under AML/CFT, sanctions, tax, or other legal requirements, or for an investigation by a competent authority, is retained for the statutory period and then deleted.

Article 21. Reporting of Flaws

If any User becomes aware of a security flaw in the Platform, the User should contact the Company through official support channels promptly so that appropriate measures can be taken.

Article 22. Exemption

Despite the measures described above, the Company cannot guarantee that information transmitted via the internet is absolutely secure. The Company does not warrant the absolute security of personal information provided by Users and is not liable for loss or damage arising from unauthorized access resulting from events beyond its reasonable control, including vulnerabilities of third-party platforms and the User’s own devices.

Article 23. Amendment of this Policy

The Company reserves the right to modify this Policy at any time. Users will be informed of material amendments by publishing an updated version on the Platform, with the effective date indicated. Users should review this Policy regularly. If a User does not agree to an amendment, the User must stop accessing the Platform. Continued access to and use of the Platform after an updated version is released constitutes agreement to the updated Policy.

Article 24. Communication with Us

Comments, feedback, and data-subject requests should be sent through the official support channels indicated on the Platform (including the application and Telegram bot), or to the following official contacts:

Those channels are the valid means by which the Company communicates with Users for privacy matters. The Company is not obliged to reply to communications sent through unofficial means.

Article 25. Publication of Announcements

The Company publishes announcements and information exclusively via official contact details provided on the Platform or by posting announcements on the Platform. The Company is not liable for any loss arising from a User’s reliance on information obtained by any other means.

Article 26. Users’ Rights

Depending on applicable law (including, where applicable, the GDPR for Users in the EEA), the User may have the right to:

  • request access to their personal data;
  • request rectification of inaccurate data;
  • request erasure of data (subject to mandatory AML retention periods);
  • restrict or object to processing;
  • receive data in a portable format;
  • withdraw consent (for processing based on consent);
  • lodge a complaint with a data protection supervisory authority.

Requests should be submitted through official channels on the Platform. We respond within the timeframes established by applicable law (as a rule, within 30 days) and may request identity confirmation. The rights to erasure and objection do not apply to data that the Company is required to retain under AML/CFT legislation, sanctions requirements, or requests from competent authorities.

Article 27. Minors

The Services are intended only for persons over 18 years of age. The Company does not knowingly collect data of minors. If such data is identified, it is deleted and access is closed.