BitHash Limited • Licence 07010605
Version 2.3•Last Revised: October 2026

Privacy & Personal Data Protection Policy

This Policy sets out how BitHash Limited collects, verifies, stores, and protects personal data and institutional telemetry across ASIC hardware procurement, cloud hashrate, facility hosting, and automated 00:00 UTC cryptocurrency payout routing in accordance with UAE Federal Decree-Law No. 45 of 2021 (PDPL).

End-to-End Encrypted Telemetry
•
UAE AML/CFT & CBUAE/VARA Compliant
•View Terms & Conditions
Clause 01•Governance

1. Regulatory Framework & Scope

BitHash Limited ("BitHash", "we", "us", or "our"), incorporated under the commercial laws of the United Arab Emirates under Commercial Licence No. 07010605, acts as a Data Controller in respect of personal data processed through our websites (including bithash.ae and associated portals), ASIC procurement channels, customer client dashboards, and datacenter colocation facilities.

This Policy complies strictly with UAE Federal Decree-Law No. 45 of 2021 regarding Personal Data Protection ("UAE PDPL"), cabinet regulations governing electronic transactions, and statutory requirements established by the Central Bank of the UAE (CBUAE) and the Virtual Assets Regulatory Authority (VARA) where applicable to digital asset infrastructure.

Clause 02•Data Types

2. Information We Collect

We process the following categories of data when you interact with BitHash services:

  • Account Identification: Full legal name, institutional entity details, trade licence copies, business registration number, primary email, contact phone number, and physical mailing address.
  • Government KYC Records: Emirates ID, international passport scans, proof of residential address (utility bills or bank statements issued within 90 days), and facial biometrics verified via automated AML screening tools.
  • Cryptocurrency & Mining Telemetry: Public blockchain wallet destination addresses (BTC, USDT, etc.), f2pool subaccount designations, ASIC serial numbers, MAC addresses, realtime stratum hashrate logs, wattage metering readings, and transaction hashes (TXIDs).
  • Technical & Usage Logs: IP addresses, browser user-agents, authentication timestamps, two-factor authentication (2FA) verification state, and access logs from the customer dashboard.
Clause 03•Lawful Grounds

3. Lawful Bases for Processing

We only process personal data where an established lawful ground under Article 4 and Article 5 of the UAE PDPL exists:

  • Performance of a Contract: To procure ASIC hardware, provision turnkey mining container hosting, manage automated 00:00 UTC reward settlements, and grant client dashboard access.
  • Statutory Obligation: To satisfy mandatory UAE Federal AML/CFT laws, Executive Office for Control and Non-Proliferation sanctions screening, and commercial audit requirements.
  • Legitimate Interests: To prevent fraud, protect infrastructure against Distributed Denial of Service (DDoS) attacks, detect account compromises, and enforce our 72-hour anti-drainer security quarantine timers.
  • Explicit Consent: Where you opt in to non-essential communications, product telemetry updates, or specialized institutional marketing.
Clause 04•Compliance

4. AML/CFT & KYC Compliance Verification

In compliance with UAE Federal Decree-Law No. (20) of 2018 on Anti-Money Laundering and Countering the Financing of Terrorism, all BitHash users deploying hardware or receiving automated payouts above statutory thresholds undergo verified Know Your Customer (KYC) onboarding.

Data gathered during KYC verification is segregated in dedicated encrypted datastores with role-based access controls (RBAC) and is accessible exclusively by certified compliance officers.

Clause 05•Telemetry & Mining

5. Mining Telemetry & Payout Wallet Binding

When you configure a Bitcoin or USDT mining wallet, BitHash validates the cryptographic address and binds it to your dedicated f2pool subaccount.

Realtime telemetry metrics (megahash/terahash delivery, chip temperatures, power consumption, rejected shares) are monitored continuously to guarantee contractual uptime and calculate automated daily payouts at 00:00 UTC. Public blockchain transactions are recorded permanently on distributed ledgers outside BitHash's control.

Clause 06•Third Parties

6. Third-Party Disclosures & Mining Pool Partners

BitHash never sells or rents personal data. We disclose information strictly on a need-to-know basis to:

  • Mining Pool Operators: Including f2pool for stratum protocol assignment, worker monitoring, and direct subaccount-level payout routing.
  • Banking & Settlement Partners: Licensed UAE financial institutions and payment gateways for processing fiat invoices, customs clearances, and VAT reporting.
  • Regulatory & Law Enforcement Authorities: When formally compelled by competent judicial orders, CBUAE, or UAE federal police in connection with statutory investigations.
Clause 07•Cross-Border

7. International Data Transfers & Safeguards

Where data is processed across servers located outside the UAE (e.g., globally distributed cloud monitoring or mining pool stratum endpoints), BitHash enforces Standard Contractual Clauses (SCCs) and verifies that recipient jurisdictions maintain adequate data protection levels pursuant to Chapter 5 of the UAE PDPL.

Clause 08•Security

8. Security Protocols & 72-Hour Anti-Drainer Vault

We maintain rigorous technical and organizational security measures to protect your assets:

  • AES-256 Encryption: In-transit TLS 1.3 encryption and at-rest AES-256 encryption across all databases.
  • 72-Hour Anti-Drainer Quarantine: Whenever a payout wallet address or 2FA credential is updated, automated payouts are frozen for 72 hours, with mandatory email and SMS authentication required to override the hold.
  • Cleanroom Facility Access: Physical datacenter facilities feature biometric access, 24/7 CCTV surveillance, and strict escort requirements.
Clause 09•Retention

9. Data Retention & Lawful Disposal

We retain client personal data for the duration of the operational contract and for a statutory period of five (5) to seven (7) years following account termination in compliance with UAE corporate recordkeeping, tax, and AML audit obligations. After expiry of statutory retention periods, records are cryptographically erased or shredded.

Clause 10•Statutory Rights

10. Your Statutory Rights Under UAE PDPL

Subject to statutory AML exceptions, UAE data subjects maintain rights to:

  • Right to Access: Request a copy of personal data and processing summaries maintained by BitHash.
  • Right to Rectification: Request correction of inaccurate, incomplete, or outdated credentials.
  • Right to Erasure: Request deletion of data where processing is no longer necessary or lawful.
  • Right to Restriction & Objection: Object to processing carried out under legitimate interest grounds.
Clause 11•Cookies

11. Cookies & Tracking Technologies

We utilize essential security cookies to preserve authenticated sessions and protect against cross-site request forgery (CSRF). Non-essential analytics cookies require your affirmative consent and can be managed through your browser settings.

Clause 12•Contact

12. Contacting the Data Protection Officer

To exercise any statutory data rights or submit questions regarding this Policy, contact our Compliance Office:

Entity: BitHash Limited (Licence No. 07010605)
Email: compliance@bithash.ae / support@bithash.ae
Phone: +971 52 384 1007
Headquarters: 19th floor, Emirates Tower, Sheikh Zayed Road, Dubai, UAE
BitHash Operations & Legal Documentation