Legal
Privacy
Policy
This policy explains how Bitstack Labs Limited collects, uses and protects personal data processed through Entity Desk.
Last updated: August 2026
Overview
Entity Desk is operated by Bitstack Labs Limited ('we', 'us', 'our'). This Privacy Policy explains how we collect, use, disclose and protect personal data when you use the Entity Desk platform, website, and related services (collectively, the 'Service').
By accessing or using the Service you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Service.
Data We Collect
Account data — your name, work email address, company name and role, collected when you register or are invited to an account.
Usage data — log records, IP addresses, browser type, pages visited and feature interactions, collected automatically when you use the Service.
Entity and compliance data — company registration details, shareholder information, KYC/AML documents, and other records you import or create inside the platform. This data belongs to you; we process it only on your instructions.
Billing data — payment card or bank details are processed by our third-party payment processor. We do not store full card numbers on our systems.
Communications — emails, support messages, or demo requests you send to us.
How We Use Your Data
To provide, operate and improve the Service, including diagnosing problems, analysing usage, and developing new features.
To authenticate users and maintain account security.
To send transactional communications such as account verification, password resets, and service notifications.
To respond to support requests and enquiries.
To comply with legal obligations, including AML/KYC obligations applicable to Bitstack Labs Limited.
We do not sell personal data to third parties. We do not use entity or compliance data you upload for any purpose other than delivering the Service to you.
Legal Basis for Processing
Contract — processing necessary to provide the Service under our agreement with you.
Legitimate interests — security monitoring, fraud prevention, product analytics, and improving the Service.
Legal obligation — compliance with applicable laws and regulatory requirements.
Consent — where we have asked for and you have provided consent (e.g. marketing communications, which you may withdraw at any time).
Data Sharing
We share personal data only as described below.
Service providers — cloud infrastructure (AWS), email delivery, payment processing, and customer support tooling. Each provider is bound by a data processing agreement and may only process data on our instructions.
Professional advisers — lawyers, auditors and insurers where necessary for operating our business, under obligations of confidentiality.
Law enforcement or regulators — where we are legally required or permitted to disclose data, or where disclosure is necessary to protect the safety or rights of any person.
Business transfers — in connection with a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity, subject to equivalent privacy protections.
Retention
We retain account data for the duration of your subscription and for a reasonable period thereafter to comply with legal obligations and resolve disputes.
Entity and compliance data is retained for the period specified in your subscription agreement or, where no period is specified, for seven years from account closure — consistent with typical regulatory record-keeping requirements in the jurisdictions we serve.
You may request deletion of your personal data at any time (see Your Rights below). Deletion requests are subject to our legal retention obligations.
Security
We implement technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These include AES-256 encryption at rest, TLS in transit, role-based access controls, multi-factor authentication, and regular security testing.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will notify affected users and relevant authorities of any breach as required by applicable law.
International Transfers
Bitstack Labs Limited is incorporated in Hong Kong. We store and process data on infrastructure located in the United States and, where applicable, other regions depending on your selected data residency option.
Where we transfer personal data outside the jurisdiction in which it was collected, we implement appropriate safeguards — such as standard contractual clauses or reliance on an adequacy decision — to ensure the data receives equivalent protection.
Your Rights
Depending on your jurisdiction, you may have the right to: access personal data we hold about you; correct inaccurate data; request deletion of your data; object to or restrict certain processing; and receive a machine-readable copy of your data (data portability).
To exercise any of these rights, email us at privacy@entitydesk.com. We will respond within 30 days. We may need to verify your identity before actioning your request.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or by a prominent notice within the platform at least 14 days before they take effect. Continued use after the effective date constitutes acceptance of the revised Policy.
Contact
For privacy enquiries or to exercise your rights, contact our Privacy team at privacy@entitydesk.com or by post to Bitstack Labs Limited, Hong Kong.