QGREEN TECHNOLOGY LLC ("QGreenPay", "we", "us", or "our"), a Colorado (USA) limited liability company with its principal office at 999 18th St, Suite 1688, Denver, CO 80202, USA, operates qgreenpay.com and provides on-ramp, off-ramp, multi-currency virtual accounts and pay-in/pay-out services to verified business clients (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit the Site or use the Services, consistent with applicable privacy laws including the EU/UK GDPR and the CCPA/CPRA. If you do not agree with this policy, please do not use the Site or Services.
1. Who We Are
- Legal entity: QGREEN TECHNOLOGY LLC (Colorado limited liability company)
- Principal office: 999 18th St, Suite 1688, Denver, CO 80202, USA
- Telephone: +1 (720) 414-9180
- Privacy & compliance contact: Support@qgreenpay.com
2. Personal Data We Collect
- Identity and Contact Data — full legal name, date of birth, nationality, email address, telephone number, residential address, tax identification number (where applicable).
- Identity Verification (KYC) Data — copies of government-issued identity documents (passport, national identity document, driver's license), selfie images and liveness-check data for facial matching, proof-of-address documents, and where applicable source-of-funds and source-of-wealth documentation.
- Account Data — username, hashed password, account preferences, security settings, two-factor authentication data.
- Transaction and Financial Data — order details, fiat payment details, bank account details for payouts, cryptocurrency wallet addresses, transaction histories, blockchain transaction hashes.
- Technical Data — IP address, browser type and version, device identifiers, operating system and time zone, recorded automatically in our server logs when you access the Site.
- Usage Data — the pages you visit and the page you arrived from, as recorded in our server logs. We do not currently use analytics or behavioural tracking on the Site; see our Cookie Policy for what is stored in your browser.
- Communications Data — records of your communications with our support, compliance, and legal teams.
3. How We Collect Personal Data
- Directly from you — when you register an account, complete KYC verification, submit a transaction, or contact us.
- Automatically — through our server logs and similar technical records when you access the Site.
- From third parties — identity verification providers, payment processors, blockchain analytics providers, sanctions and PEP screening providers, and business partners participating in a transaction.
4. Purposes and Legal Bases of Processing
| Purpose | Legal Basis (GDPR) |
| Providing the Services — account management, fiat-to-crypto conversion, payouts, virtual account issuance, transaction processing | Performance of contract |
| Identity verification (KYC), sanctions screening, transaction monitoring, regulatory reporting (AML/CFT) | Legal obligation and legitimate interests |
| Fraud prevention, risk scoring, dispute handling | Legitimate interests |
| Customer support and communications | Performance of contract / legitimate interests |
| Service improvement, analytics, aggregated statistics | Legitimate interests |
| Marketing communications (where you have opted in) | Consent |
| Meeting tax, accounting, and record-keeping obligations | Legal obligation |
5. Cookies and Tracking Technologies
The Site currently does not set cookies. We use your browser's local storage only to remember the choice you make in the cookie notice. If we introduce non-essential cookies or similar technologies in the future, they will be set only with your consent, and you can manage cookies through your browser settings at any time. See our Cookie Policy for details.
6. Sharing of Personal Data
We may share personal data with:
- Delivery and infrastructure partners — the liquidity, banking and settlement partners involved in delivering a Service. They receive the identity-verification and transaction data needed to open accounts, process payments and settle funds, and act as independent controllers or processors for that activity under their own terms.
- Service providers and processors — identity-verification software and data providers, payment processors and acquiring banks, blockchain-analytics and sanctions-screening tools, fraud-prevention services, cloud hosting and email providers — each acting under data processing agreements.
- Other regulated institutions — where a transaction involves another regulated institution, we share KYC status and transaction-necessary data with that institution under the FATF Travel Rule and applicable law.
- Regulators, financial intelligence units, and law enforcement — where required by law, including suspicious activity reports and sanctions-related disclosures.
- Professional advisers — auditors, legal counsel, and insurers, on a need-to-know basis.
We do not sell your personal information as defined by the CCPA/CPRA.
7. International Data Transfers
Your personal data may be transferred to and processed in the United States and other countries where our service providers operate. Where required, such transfers are protected by appropriate safeguards, including the EU Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.
8. Data Retention
- KYC and AML records: retained for a minimum of five (5) years after the end of the business relationship, as required by applicable AML laws.
- Transaction records: retained for a minimum of five (5) years; tax and accounting records are retained for the periods required by applicable tax law.
- Marketing preferences: retained until you withdraw consent.
Where retention is no longer required, data is securely deleted or anonymized.
9. Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encrypted transmission of your data and protected storage, access controls limited to authorized personnel on a need-to-know basis, and regular security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights
If you are located in the EU/EEA/UK, you have the right to: access your personal data; rectify inaccurate data; erase data (subject to our legal retention obligations); restrict or object to processing; data portability; withdraw consent at any time; and lodge a complaint with your local supervisory authority.
If you are a California resident, you have the right to: know what personal information is collected; request deletion; correct inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell personal information); and not be discriminated against for exercising your rights.
To exercise any right, contact us at Support@qgreenpay.com or +1 (720) 414-9180. We will respond within the timeframe required by applicable law. Certain data (such as KYC and transaction records) may be retained for the periods required by AML and tax law even after a deletion request.
11. Children
The Services are not directed to persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify material changes via the Site and, where appropriate, by email. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
13. Contact
QGREEN TECHNOLOGY LLC · 999 18th St, Suite 1688, Denver, CO 80202, USA · +1 (720) 414-9180 · Support@qgreenpay.com