Privacy Policy
ByteMax Exchange
This Policy explains which personal data ByteMax Exchange receives, why it uses the data, who it shares the data with, and how you can request information, correction or deletion. It covers the website, your account, Google sign-in, transactions and support. Processing takes account of the service purpose, applicable obligations and rights under the Brazilian General Data Protection Law (LGPD).
- Controller and contact: ByteMax Intermediação de Negócios Ltda., CNPJ 51.091.756/0001-24, based in Januária/MG, Brazil, is the controller of data processed by the platform. For privacy questions and rights requests, use the chat on this website's Support page and ask the team for help with personal data. Visitors can also use the chat without signing in. Do not send passwords, authentication codes or complete identity documents in your initial message; the team will explain how to identify yourself for the request.
- Data collected and its sources: We receive information you provide during registration and use of the service, such as your name, email, phone number, CPF/CNPJ, nationality, address, and company and representative details, depending on the account type. KYC/KYB checks may involve documents, images, identity evidence and review results. We process transaction information, such as amounts, recipients, payment details, receipts, orders, account movements and disputes; support messages and attachments; and technical access, session and security records, such as IP addresses and authentication events. Identity, payment and verification providers also supply confirmations and information needed to deliver the service.
- Sign in with Google: If you choose Google sign-in, we receive your Google account identifier, email address, email verification status and basic profile data made available by Google, such as your name and, when provided, profile image, through the ZITADEL authentication system. Authentication evidence may include the organization domain for Google Workspace accounts. We use this information to authenticate you, create or link your identity to the correct account, maintain access details, securely recover access and support your account. ByteMax does not receive your Google account password. Sign-in is not used to read Gmail messages, Drive files, contacts or calendars.
- Storage and use of Google data: Identity data and authentication links are processed in the authentication systems and databases used by ByteMax, with restricted access. They are retained as needed for access, security, support and the retention obligations described in this Policy. Processing involves Google, the ZITADEL system and infrastructure providers needed for authentication and account operation. Staff access is limited to support, security and compliance needs. ByteMax does not sell data received from Google, use it for personalized advertising or transfer it to train general-purpose AI models. Use and transfer of this data follow the Google API Services User Data Policy, including Limited Use requirements where applicable.
- Purposes of processing: We use necessary data to register and authenticate users, verify identity and eligibility, execute and track payments and orders, maintain records and reconciliation, handle questions and disputes, prevent fraud and unauthorized access, and meet legal and regulatory obligations. Data required for a transaction or KYC/KYB is necessary to provide that feature. When processing relies on consent, its purpose will be explained and consent may be withdrawn through the privacy channels, without overriding other legitimate grounds for retention.
- Sharing and processing abroad: We share necessary data with authentication, hosting, storage, identity verification, fraud prevention and support providers, as well as financial institutions, payment providers and partners carrying out requested transactions. Registration, KYC/KYB and transaction data may be provided to authorities to meet applicable legal obligations or requests. Recipients and providers may be outside Brazil; international processing must observe applicable data protection safeguards and requirements. Sharing is limited to its purpose, with access and confidentiality controls.
- AI-assisted support: The chat uses AI, including OpenAI services, to understand requests, generate replies and assist the team. Messages, support context, attachment references and account or transaction data made available through authorized support queries may be sent to the AI provider for that support interaction. ByteMax stores conversations and support records. Entered content may contain personal data, and automatic removal of that data before processing is not guaranteed. Share only what is needed and ask the team for help with privacy matters.
- Cookies, storage and security: We use cookies and browser storage to maintain sessions, protect requests and remember preferences, such as language and notices already seen. Blocking these resources may prevent sign-in or affect features. Data protection measures include HTTPS connections, authentication and authorization controls, and access restrictions by role. Documents and records are processed in systems subject to security controls; no system eliminates all risk.
- Retention and account closure: Data is retained according to its purpose and the needs of service delivery, security, transaction evidence and legal or regulatory obligations. Closing an account stops its operations but does not immediately erase registration details, history or KYC/KYB records. The applicable minimum retention period is shown during account closure; legal orders and evidence preservation needs may extend retention. The end of the minimum period does not automatically delete or anonymize all data. Deletion requests are assessed according to the data category and grounds requiring its retention.
- Your rights, deletion and Google revocation: Through the Support chat, you can request confirmation of processing, access, correction, sharing information and, where applicable, portability, anonymization, blocking or deletion of data and withdrawal of consent. We may need to verify your identity before fulfilling a request. To close your account, use the deletion option in settings; balances and pending transactions must first be resolved. You can also revoke the ByteMax connection in your Google Account's third-party connections area. Revocation affects Google sign-in but does not automatically close your ByteMax account or erase data already received; request those actions separately through support or settings, as applicable.
© 2026 ByteMax Exchange. All rights reserved.
