Legal

Privacy Policy

Website, onboarding, payment and financial-services privacy notice

Legal EntityCyrafa LLC, a Montana domestic limited liability company
Federal StatusFinCEN-registered Money Services Business (MSB), Registration No. 31000307129357
Registered ActivitiesMoney transmission and dealing in foreign exchange, as stated in Cyrafa's FinCEN registration record
Effective DateAugust 18, 2026
Last UpdatedAugust 18, 2026
Contact Email[email protected]

Summary: Cyrafa collects and uses personal data to operate its website and business-finance services, verify customers and beneficial owners, process and monitor fiat and digital-asset transactions, prevent fraud and financial crime, meet legal obligations, and protect its platform. Cyrafa will never ask for a private key or wallet seed phrase.

1. Cyrafa & Cyrafa’s Regulatory Position

Cyrafa LLC ("Cyrafa," "we," "us," or "our") is a Montana limited liability company with its principal office at 1001 S Main St, Suite 600, Kalispell, Montana 59901, United States. Cyrafa is registered with the U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) as a Money Services Business (MSB), registration number 31000307129357. Cyrafa provides or facilitates business-account, payment, IBAN, SWIFT, foreign-exchange, treasury, payout, and digital-asset workflows. Certain banking, account, custody, card, payment, foreign -exchange, settlement, or digital-asset functions may be supplied by independent banks, licensed financial institutions, regulated virtual asset providers, payment institutions, custodians, or other contracted partners. A partner may act as a separate controller of personal data and provide its own privacy notice. Regulatory statement: FinCEN registration is a federal registration under the Bank Secrecy Act. It is not a bank charter, deposit insurance, a state money -transmitter license, an endorsement, or an approval of Cyrafa by FinCEN or another government agency. Product availability depends on the customer's location, the service requested, and the permissions of Cyrafa and its partners.

2. Scope of the Policy

This Policy applies when Cyrafa processes personal data through cyrafa.com; a Cyrafa application, dashboard, portal, or account; account applications and onboarding; KYC, KYB, beneficial -ownership and enhanced -due diligence reviews; payments, transfers, exchange, treasury, settlement, payouts, and digital -asset services; customer support; security and compliance operations; events; and marketing communications. This Policy covers website visitors, applicants, customers, prospective customers, authorized users, directors, officers, beneficial owners, controllers, employees and representatives of business customers, beneficiaries, counterparties, payers, payees, an d other individuals whose information is processed in connection with a transaction or service. This Policy does not ordinarily govern Cyrafa employee or job -applicant data, which may be covered by a separate workforce notice. It also does not govern independent third-party websites, wallets, exchanges, banks, or services that publish their own notices. A more specific notice, including a biome tric notice, cookie notice, product notice, or U.S. financial privacy notice, supplements this Policy and controls for the subject it addresses if there is a conflict.

3. Cyrafa’s Role and Key Definitions

3.1 Controller or business. For most processing described in this Policy, Cyrafa determines why and how personal data is used and acts as a controller or business under applicable privacy law.

3.2 Processor or service provider. When Cyrafa processes personal data only on a business customer's documented instructions, Cyrafa may act as that customer's processor or service provider. In that situation, the business customer normally handles individual privacy requests, and Cyrafa assists it as required by contract and law.

3.3 Personal data or personal information. Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household. The term excludes properly deidentified, aggregated, or publicly ava ilable information to the extent excluded by applicable law.

3.4 Sensitive data. Data treated as sensitive under applicable law, which may include government identifiers, financial-account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health information, sexual orientation, immigration or citizenship sta tus, biometric data used for identification, and personal data of a known child.

3.5 Processing. Any operation performed on personal data, including collection, use, analysis, storage, disclosure, transmission, protection, deletion, or deidentification.

4. Personal Data Collected

The categories collected depend on the relationship, requested service, jurisdiction, risk profile, and legal requirements. Cyrafa may collect:

4.1 Identity and contact information. Full name, former name, alias, date and place of birth, age, nationality, citizenship, residency, postal address, email address, telephone number, signature, photograph, and customer or account identifier.

4.2 Government and tax identifiers. Passport, national identity card, driver's license, residence permit, visa, tax identification number, Social Security number where legally required, document number, issuing authority, issue and expiry dates, and copies or authenticity results.

4.3 Business and beneficial-ownership information. Legal name, trading name, incorporation number, registered and operating addresses, formation and constitutional documents, licenses, tax status, business activities, ownership chain, shareholding, directors, officers, authorized signatories, controllers, ultimate beneficial owners, organizational charts, and corporate registry records.

4.4 Professional and relationship information. Job title, employer, occupation, professional contact details, authority, role, employment or business relationship, and information needed to verify that a person may act for a customer.

4.5 Account and authentication information. Username, password hash, multi -factor authentication data, device enrollment, security questions, access permissions, roles, approval limits, account settings, login history, and suspected compromise indicators.

4.6 Biometric and liveness information. Selfies, video, facial images, facial geometry templates, liveness results, and related signals used to confirm identity or prevent impersonation. Where required, Cyrafa or its provider will give a separate notice and obtain consent before collecting or using biometric identifiers.

4.7 Financial and payment information. Bank-account and routing details, IBAN, SWIFT/BIC, card or token details, beneficiary information, balances, invoices, payment instructions, payment purpose, currency, amount, fees, settlement details, and account statements.

4.8 Transaction and counterparty information. Transaction dates, amounts, currencies, status, source and destination, payer, payee, merchant, beneficiary, counterparty, reference, supporting documents, reconciliation information, and related communications.

4.9 Digital-asset and blockchain information. Wallet addresses, transaction hashes, token and network information, asset amounts, timestamps, public-blockchain activity, exchange or custody account information, source and destination of digital assets, and blockchain-risk indicators.

4.10 Source-of-funds and source-of-wealth information. Income, occupation, business revenue, investments, asset ownership, inheritance, sale proceeds, loan or financing information, tax records, bank statements, contracts, invoices, and supporting explanations or documents.

4.11 Compliance, fraud and risk information. KYC and KYB results, sanctions and watchlist screening, politically exposed person status, adverse media, fraud indicators, device and behavioral risk, blockchain analytics, expected activity, customer risk rating, due -diligence findings, transaction -monitoring alerts, case notes, investigations, and regulatory reporting data.

4.12 Device, usage and network information. IP address, device identifier, browser, operating system, language, time zone, approximate location derived from IP, referral URL, pages and features used, clicks, session information, event logs, crash data, and diagnostic or security logs.

4.13 Approximate or precise location. Approximate location derived from an IP address and, only where a feature requires it and permission is granted, precise device location.

4.14 Communications and sensory information. Emails, messages, support tickets, complaint records, meeting or call details, survey responses, voice recordings where notice is provided, photographs, video, and records of communications with Cyrafa.

4.15 Marketing and preference information. Communication preferences, consent records, event attendance, campaign engagement, service interests, survey answers, and cookie or analytics choices.

4.16 Inferences and derived information. Risk scores, fraud signals, service recommendations, expected -activity profiles, behavioral patterns, and other conclusions derived from the information described above.

5. Information We do not request

Private keys and seed phrases: Cyrafa will never ask for a private key, recovery phrase, or wallet seed phrase. Do not send passwords, one -time authentication codes, private keys, seed phrases, or unrelated sensitive documents by ordinary email or support message. Cyrafa may provide a secure channel when identity or supporting documents are required.

6. How we obtain Personal Data

6.1 Directly from you. When you browse the website, request information, apply for or use an account, complete verification, initiate a transaction, upload a document, attend an event, respond to a survey, or contact Cyrafa.

6.2 From your organization or associated persons. From a customer administrator, employer, company, director, officer, shareholder, beneficial owner, authorized representative, colleague, payer, payee, beneficiary, or counterparty.

6.3 From transaction and financial-service participants. Banks, account and IBAN providers, payment institutions, payment processors, correspondent or settlement institutions, custodians, exchanges, liquidity providers, card issuers or networks, wallets, beneficiaries, and other participants in a requested service.

6.4 From verification, compliance and security providers. Identity and liveness vendors, corporate registries, document-authentication providers, sanctions and PEP databases, adverse -media services, fraud and device-risk providers, blockchain analytics, cybersecurity providers, and other due-diligence sources.

6.5 From public authorities and public sources. Government registries, court records, sanctions lists, law-enforcement or regulatory information, public websites, public blockchains, and other lawfully available sources.

6.6 From commercial and referral sources. Business directories, data providers, professional advisers, referral partners, marketing partners, and lead sources where collection and use are lawful.

6.7 Automatically. Through cookies, local storage, pixels, software development kits, server logs, security systems, and similar technologies when you use the website or services.

7. Why We Process Personal Data

7.1 Evaluate eligibility and onboard customers. Review applications; verify identity, authority, ownership and control; assess service eligibility; conduct KYC, KYB and enhanced due diligence; and establish accounts.

7.2 Provide and administer services. Create and maintain accounts; enable payment, transfer, IBAN, SWIFT, exchange, settlement, treasury, payout and digital -asset workflows; manage permissions and approvals; produce statements and reports; and coordinate partner-delivered services.

7.3 Execute and reconcile transactions. Authenticate instructions; screen parties and wallets; transmit payment information; settle, convert, reconcile, reverse or investigate transactions; calculate fees; and maintain transaction histories.

7.4 Meet legal and regulatory obligations. Comply with the Bank Secrecy Act, USA PATRIOT Act requirements where applicable, FinCEN rules, anti -money-laundering and counter -terrorist-financing duties, OFAC and other sanctions requirements, tax and accounting rules, recordkeeping obligations, court orders, and lawful regulatory or law-enforcement requests.

7.5 Prevent fraud, financial crime and abuse. Detect and investigate impersonation, fraud, account takeover, money laundering, terrorist financing, sanctions evasion, bribery, corruption, cybercrime, prohibited activity, misuse, or attempts to circumvent controls.

7.6 Protect systems, users and transactions. Authenticate users; monitor systems; manage access; investigate incidents; test controls; maintain backups and business continuity; and protect the confidentiality, integrity and availability of information.

7.7 Support customers and resolve disputes. Respond to questions and complaints; troubleshoot services; verify instructions; conduct investigations; handle chargebacks or disputes; and communicate about accounts, security and transactions.

7.8 Operate and improve Cyrafa. Maintain systems; perform quality assurance, analytics, audits and forecasting; improve workflows and products; train staff; manage vendors; document decisions; and develop new features.

7.9 Communicate and market lawfully. Provide requested information; send service updates, educational content, invitations and offers; measure campaign performance; and honor communication preferences and consent.

7.10 Protect legal and business interests. Enforce agreements, establish or defend legal claims, obtain professional advice, conduct corporate transactions, respond to audits, and protect the rights, safety and property of Cyrafa, customers, partners and the public. Cyrafa seeks to collect and process only data that is adequate, relevant and reasonably necessary for the disclosed purposes. We may combine data from different sources where lawful and appropriate for those purposes.

8. Legal Bases for Processing

Where applicable law requires a legal basis, Cyrafa relies on one or more of the following:

8.1 Contract and pre -contract steps. Processing necessary to evaluate an application, open or administer an account, perform a requested transaction, deliver a service, or comply with contractual obligations.

8.2 Legal obligation. Processing required by financial -crime, sanctions, tax, accounting, corporate, consumer-protection, regulatory, recordkeeping, court, or law-enforcement requirements.

8.3 Legitimate interests. Operating and improving the business, preventing fraud and misuse, securing systems and transactions, maintaining records, managing vendors and partners, communicating with business contacts, and establishing or defending legal claims, after balancing those interests against individual rights.

8.4 Consent. Processing based on freely given consent where required, such as certain biometric processing, non-essential cookies, electronic marketing, or precise geolocation. Consent may be withdrawn, but withdrawal does not affect prior lawful processing.

8.5 Vital interests and public interest. Processing necessary in exceptional cases to protect a person's life or safety, or to carry out a substantial public-interest or legal-compliance function recognized by applicable law. If Cyrafa must process particular information to enter into or perform a contract or comply with law, failure to provide it may prevent onboarding, delay a transaction, limit a feature, or require Cyrafa or a partner to decline, restrict, suspend or terminate a service.

9. Financial Crime Screening, Monitoring and Automated Tools

Cyrafa and its providers may use automated and manual tools to authenticate documents and identity, confirm liveness, screen persons and entities against sanctions and watchlists, identify politically exposed persons and adverse media, assess device and behavior al risk, analyze public -blockchain activity, monitor transactions, detect unusual activity, assign risk indicators, and prioritize reviews. These tools may generate alerts, matches, scores, recommendations, or reason codes. Results are evaluated in context and may be reviewed by trained personnel. Cyrafa may request more information, place a transaction on hold, restrict a feature, decline or end a relationship, or make a report when required or permitted by law or a partner's lawful requirements. Where applicable law grants a right relating to profiling or solely automated decisions that produce legal or similarly significant effects, Cyrafa will provide the required information, opt-out mechanism, or human review, subject to exemptions for fraud prevention, security, legal compliance, and regulated financial activity. Cyrafa cannot disclose a Suspicious Activity Report, its existence, or information protected by law -enforcement, sanctions, security, legal privilege, or anti-tipping-off restrictions.

10. When and With whom Personal Data is Disclosed

Cyrafa may disclose relevant categories of personal data to the following recipients when reasonably necessary for the purposes in this Policy:

10.1 Banking, payment and account partners. Banks, payment institutions, account and IBAN providers, money transmitters, payment processors, correspondent and settlement institutions, card issuers and networks, and providers involved in receiving, sending or settling funds.

10.2 Digital-asset and foreign -exchange partners. Custodians, exchanges, wallet infrastructure providers, liquidity and foreign -exchange providers, blockchain networks, on -ramp or off -ramp providers, and transaction counterparties.

10.3 Identity and compliance providers. KYC and KYB vendors, identity and liveness providers, corporate registry services, document-verification providers, sanctions and PEP screening services, adverse-media providers, fraud services, and blockchain analytics.

10.4 Technology and operational providers. Cloud hosting, data storage, communications, customer support, analytics, cybersecurity, software, document management, business continuity, payment operations, and other vendors processing data under contract.

10.5 Transaction participants and account users. Payers, payees, beneficiaries, counterparties, merchants, customer administrators, authorized users, approvers, and others a customer directs Cyrafa to involve.

10.6 Professional advisers, auditors and insurers. Lawyers, accountants, consultants, independent auditors, banking advisers, insurers, and other advisers subject to professional duties or contractual safeguards.

10.7 Government, regulatory and legal recipients. FinCEN, OFAC, tax authorities, courts, law-enforcement agencies, regulators, supervisory authorities, self-regulatory bodies, and other public entities when disclosure is required or permitted by law.

10.8 Corporate transaction participants. Actual or prospective investors, lenders, acquirers, sellers, insolvency practitioners, and advisers in a financing, reorganization, merger, acquisition, sale of assets, or similar transaction, subject to appropriate safeguards.

10.9 Affiliates and authorized recipients. Entities under common control, if any, and other persons where the individual or customer consents, directs disclosure, or the disclosure is otherwise lawful. Depending on the service, a recipient may act as Cyrafa's processor or service provider, a joint participant in a transaction, or an independent controller subject to its own legal obligations and privacy notice.

11. Sale, Sharing, Targeted Advertisings and Opt-Out Signals

Cyrafa does not knowingly sell personal data for money. As of the effective date, Cyrafa does not sell personal data, share personal data for cross -context behavioral advertising, or process personal data for targeted advertising as those terms are defined by the Montana Consumer Data Privacy Act or California Consumer Privacy Act. Cyrafa does not use sensitive personal data to infer characteristics for targeted advertising. Disclosures needed to provide a requested financial service, complete a transaction, prevent fraud, comply with law, or engage contracted processors are not treated as a sale under many privacy laws. Definitions vary, however, and certain advertising or an alytics technologies can be treated as a sale, sharing, or targeted advertising even when no money is paid. If Cyrafa introduces covered sale, sharing, or targeted-advertising activity, it will update this Policy, provide any required conspicuous "Your Privacy Rights" or "Do Not Sell or Share My Personal Information" mechanism outside this Policy, and recognize valid uni versal opt-out preference signals, including Global Privacy Control, where required.

12. Cookie and Similar Technologies

Cyrafa and its providers may use cookies, local storage, pixels, tags, software development kits, APIs, server logs, and similar technologies. These tools may collect device and usage information and may be used for the following purposes:

12.1 Strictly necessary. Operate the website and account, maintain sessions, route network traffic, authenticate users, apply security controls, prevent fraud, and remember privacy choices.

12.2 Functional. Remember language, region, display, accessibility and service preferences, and enable requested features.

12.3 Analytics and performance. Measure traffic, usage, errors, response times, feature performance and aggregate trends so Cyrafa can maintain and improve services.

12.4 Advertising or campaign measurement. Measure outreach or campaign performance only where used and permitted. Where consent or an opt -out is required, Cyrafa will provide the applicable control before or at collection. You may manage non-essential technologies through any cookie banner or settings tool Cyrafa makes available and through browser or device settings. Blocking necessary technologies may prevent the website or account from functioning. Browser "Do Not Track" signals do not have a uniform legal meaning. Cyrafa will recognize legally binding opt-out signals where required. In the EEA, United Kingdom and other consent jurisdictions, non essential cookies will be used only after any required consent.

13. Digital Assets and Public Blockchains

Public blockchains generally record transaction information openly and may retain it permanently. Wallet addresses, transaction hashes, amounts, tokens, networks, timestamps and related information may be visible to anyone and may be copied, combined with other information, or analyzed by third parties. A wallet address may be personal data when linked or reasonably linkable to an individual. Cyrafa does not control a public blockchain and usually cannot edit, delete or erase information recorded on it. A privacy request does not require or enable Cyrafa to alter the blockchain. Where legally permitted, Cyrafa may correct, delete, restrict, or deiden tify off-chain information in systems it controls. Do not place personal data, credentials, private keys, seed phrases, or confidential messages in blockchain metadata or transaction fields.

14. Data Retention and Disposal

Cyrafa retains personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide services, complete transactions, maintain the relationship, comply with legal and regulatory duties, resolve disputes, enforce a greements, prevent fraud, protect security, and respond to audits, investigations or legal claims. Retention is determined by the type and sensitivity of the data, risk, account status, legal limitation periods, contractual commitments, partner requirements, and any legal hold.

14.1 Application, KYC, KYB and beneficial -ownership records. Generally retained during the application or relationship and for the period required by BSA/AML, sanctions, licensing, partner or other rules after rejection, closure, or the relevant event. Many BSA records must be retained for at least five years where the rule applies.

14.2 Account and transaction records. Retained for the relationship and the period required for BSA/AML, tax, accounting, audit, chargeback, dispute, partner, and legal-claim purposes.

14.3 Compliance alerts, investigations and regulatory records. Retained for legally required periods and as needed to document decisions, cooperate with authorities, prevent repeat misuse, or comply with a legal hold. Information protected by SAR confidentiality or anti-tipping-off rules remains restricted.

14.4 Biometric and liveness data. Retained only for the identity-verification, security and legal-compliance purpose and then deleted or destroyed according to applicable law and the provider's legally compliant schedule, unless a longer period is required by law.

14.5 Website, device and security logs. Retained for periods appropriate to security, fraud prevention, diagnostics, system integrity, incident investigation and legal obligations, then deleted, aggregated or deidentified.

14.6 Support and communications records. Retained for account servicing, quality, complaints, disputes, legal compliance and claims, with the period depending on the subject and sensitivity.

14.7 Marketing data. Retained while the relationship or marketing purpose continues, until consent is withdrawn or an objection is honored, and thereafter only as needed to maintain suppression records and demonstrate compliance.

14.8 Privacy-request records. Retained as needed to authenticate the request, demonstrate compliance, prevent fraud and avoid repeating processing contrary to a valid request. When retention is no longer justified, Cyrafa deletes, securely destroys, anonymizes or deidentifies the information. Data may remain temporarily in encrypted backups until overwritten through ordinary cycles. Public-blockchain data may remain permanently outside Cyrafa's control.

15. Information Security

Cyrafa uses administrative, technical and physical safeguards designed to protect personal data and customer information in light of the nature, volume and sensitivity of the data and the risks of processing. Measures may include:

15.1 Governance and risk management. Written policies, assigned responsibility, risk assessments, change management, incident-response planning, business continuity, and periodic review.

15.2 Access and authentication. Role-based access, least -privilege principles, multi -factor authentication where appropriate, access reviews, session controls, and prompt revocation when access is no longer needed.

15.3 Technical safeguards. Encryption or equivalent protections where appropriate, secure configuration, logging, monitoring, vulnerability management, backups, malware protection, and controls against unauthorized access or exfiltration.

15.4 Operational safeguards. Staff confidentiality obligations, security and privacy training, segregation of duties, secure document handling, and review of unusual activity.

15.5 Vendor oversight. Risk-based due diligence, contractual privacy and security terms, access limitations, monitoring, and reassessment of service providers that handle personal data.

15.6 Testing and response. Testing or monitoring of safeguards, investigation of suspected incidents, remediation, documentation, and notification when required. No security measure can guarantee absolute protection. Users are responsible for safeguarding credentials and devices, using strong unique passwords and multi -factor authentication where offered, reviewing transaction instructions, and promptly reporting suspected compromise.

16. Privacy Rights and How to Exercise Them

Depending on location, relationship, applicable thresholds and exemptions, an individual may have one or more of the following rights:

16.1 Confirmation and access. Confirm whether Cyrafa processes personal data and receive access to personal data or specified information about its processing.

16.2 Correction. Correct inaccurate personal data, taking account of the data's nature and the purpose of processing.

16.3 Deletion or erasure. Request deletion of personal data, subject to legal and operational exceptions.

16.4 Portability. Receive qualifying personal data in a portable and, where technically feasible, readily usable format.

16.5 Opt out. Opt out of sale, sharing, targeted advertising, or qualifying profiling where the relevant law provides that right.

16.6 Restriction, objection or limitation. Restrict or object to certain processing, or limit certain uses of sensitive personal information, where applicable.

16.7 Withdraw consent. Withdraw consent for future processing where consent is the legal basis. Withdrawal does not invalidate earlier lawful processing.

16.8 Human review and profiling information. Request human review or information about qualifying automated decisions or profiling where applicable.

16.9 Appeal. Appeal a refusal to act on a request where applicable state law provides an appeal right.

16.10 Complain. Submit a complaint to an applicable privacy, consumer-protection or data-protection authority. To initiate a request, email [email protected] with the subject line "Privacy Request" and identify the right requested and the country or U.S. state of residence. Do not email copies of passports, financial -account credentials, private keys or other highly sensitive documents unless Cyrafa specifically provides an approved secure method. An existing secure account channel may also be used if available. Cyrafa will acknowledge and verify a request using information appropriate to its sensitivity and the risk of unauthorized disclosure. Cyrafa may request additional information, use an existing authenticated account, or decline a request that cannot be reasonabl y authenticated. A person is not required to create a new account solely to exercise a right. An authorized agent may act where permitted, subject to proof of authority and, where allowed, direct verification with the individual. Rights are not absolute. Cyrafa may retain or continue processing data needed to complete a requested transaction; maintain an account requested by the customer; comply with BSA/AML, sanctions, tax, accounting, recordkeeping or other legal obligations; protect security and prevent fraud; exercise or defend legal claims; protect another person's rights; maintain suppression or request records; cooperate with authorities; or process information outside the scope of a particular privacy law. Cyrafa will not unlawfully discriminate or retaliate against an individual for exercising a privacy right.

17. Communications and Marketing Choices

You may unsubscribe from promotional emails by using the unsubscribe link or contacting Cyrafa. Cyrafa may continue sending service, transaction, account, security, compliance, legal and relationship communications that are not promotional. Where consent i s required for electronic marketing, Cyrafa will obtain it and maintain a record of the choice. Withdrawal applies to future marketing and does not prevent communications necessary to provide or secure an account or comply with law.

18. Children and Minors

Cyrafa's services are intended for businesses and adults and are not directed to children or persons under 18. Cyrafa does not knowingly open an account for a minor or intentionally collect personal data from a child through the services. If Cyrafa learns that a minor provided personal data contrary to this restriction, it will investigate and take appropriate action, which may include deletion, restriction, account closure, or obtaining legally valid consent where appropriate. Cyrafa does not knowingly sell, share for cross -context behavioral advertising, use for targeted advertising, or conduct covered profiling using a minor's personal data. Where Cyrafa actually knows or willfully disregards that a user is a minor, it will apply applicable child and teen privacy protections, including COPPA and the enhanced Montana duties described in Section 20, to the extent relevant.

19. Third Party Servers, Links and Partner Notices

The website and services may link to or integrate with independent websites, applications, wallets, exchanges, custodians, banks, payment institutions, card providers, identity vendors or other services. Cyrafa is not responsible for an independent third party's privacy, security, availability or terms. Review the third party's privacy notice before providing information or using its service. Where a partner receives personal data to meet its own regulatory obligations, make an independent eligibility decision, provide an account or execute a transaction, it may act as an independent controller. A privacy request concerning that partner's syste ms may need to be directed to the partner, although Cyrafa will provide reasonable assistance where required.

20. Changes, Accessibility and Contact

Cyrafa may update this Policy to reflect changes in services, partners, technology, law or practices. It will revise the "Last updated" date and post the current version through a conspicuous link containing the word "Privacy." If a change is material, Cyr afa will provide additional notice to affected individuals and, where required, a reasonable opportunity to withdraw consent to materially different future processing. Cyrafa aims to make this Policy reasonably accessible to individuals with disabilities. Contact Cyrafa to request an alternative format. Where required by law, the Policy will be made available in each language in which Cyrafa provides a covered product or service or conducts related activities. Questions, complaints, privacy requests, consent withdrawals and appeals may be directed to: Cyrafa LLC-Privacy & Compliance 1001 S Main St, Suite 600, Kalispell, Montana 59901, United States Email: [email protected] | Website: cyrafa.com