The categories collected depend on the relationship, requested service, jurisdiction, risk profile, and legal requirements. Cyrafa may collect:
4.1 Identity and contact information. Full name, former name, alias, date and place of birth, age, nationality, citizenship, residency, postal address, email address, telephone number, signature, photograph, and customer or account identifier.
4.2 Government and tax identifiers. Passport, national identity card, driver's license, residence permit, visa, tax identification number, Social Security number where legally required, document number, issuing authority, issue and expiry dates, and copies or authenticity results.
4.3 Business and beneficial-ownership information. Legal name, trading name, incorporation number, registered and operating addresses, formation and constitutional documents, licenses, tax status, business activities, ownership chain, shareholding, directors, officers, authorized signatories, controllers, ultimate beneficial owners, organizational charts, and corporate registry records.
4.4 Professional and relationship information. Job title, employer, occupation, professional contact details, authority, role, employment or business relationship, and information needed to verify that a person may act for a customer.
4.5 Account and authentication information. Username, password hash, multi -factor authentication data, device enrollment, security questions, access permissions, roles, approval limits, account settings, login history, and suspected compromise indicators.
4.6 Biometric and liveness information. Selfies, video, facial images, facial geometry templates, liveness results, and related signals used to confirm identity or prevent impersonation. Where required, Cyrafa or its provider will give a separate notice and obtain consent before collecting or using biometric identifiers.
4.7 Financial and payment information. Bank-account and routing details, IBAN, SWIFT/BIC, card or token details, beneficiary information, balances, invoices, payment instructions, payment purpose, currency, amount, fees, settlement details, and account statements.
4.8 Transaction and counterparty information. Transaction dates, amounts, currencies, status, source and destination, payer, payee, merchant, beneficiary, counterparty, reference, supporting documents, reconciliation information, and related communications.
4.9 Digital-asset and blockchain information. Wallet addresses, transaction hashes, token and network information, asset amounts, timestamps, public-blockchain activity, exchange or custody account information, source and destination of digital assets, and blockchain-risk indicators.
4.10 Source-of-funds and source-of-wealth information. Income, occupation, business revenue, investments, asset ownership, inheritance, sale proceeds, loan or financing information, tax records, bank statements, contracts, invoices, and supporting explanations or documents.
4.11 Compliance, fraud and risk information. KYC and KYB results, sanctions and watchlist screening, politically exposed person status, adverse media, fraud indicators, device and behavioral risk, blockchain analytics, expected activity, customer risk rating, due -diligence findings, transaction -monitoring alerts, case notes, investigations, and regulatory reporting data.
4.12 Device, usage and network information. IP address, device identifier, browser, operating system, language, time zone, approximate location derived from IP, referral URL, pages and features used, clicks, session information, event logs, crash data, and diagnostic or security logs.
4.13 Approximate or precise location. Approximate location derived from an IP address and, only where a feature requires it and permission is granted, precise device location.
4.14 Communications and sensory information. Emails, messages, support tickets, complaint records, meeting or call details, survey responses, voice recordings where notice is provided, photographs, video, and records of communications with Cyrafa.
4.15 Marketing and preference information. Communication preferences, consent records, event attendance, campaign engagement, service interests, survey answers, and cookie or analytics choices.
4.16 Inferences and derived information. Risk scores, fraud signals, service recommendations, expected -activity profiles, behavioral patterns, and other conclusions derived from the information described above.