3REAL

Privacy Policy

Last updated: June 17, 2026

This Privacy Policy explains how 3REAL ("we", "us"), part of the SETAEI ecosystem and operated from Norway, collects, uses, stores, and protects personal data when you use the Platform. We process personal data in accordance with the Norwegian Personal Data Act and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Data We Collect

  • Account data — email address, password hash, display name, referral code, account preferences.
  • KYC data — government-issued ID documents, proof of address, date of birth, and other identity verification information you submit.
  • Transaction data — deposit and withdrawal records, ledger entries, payment references, and on-chain transaction hashes where applicable.
  • Technical data — IP address, browser/device information, session and authentication tokens, and activity logs (e.g. login times, referral link clicks).
  • Communications — support requests and any correspondence with us.

2. How We Use Your Data

  • To create and maintain your account and authenticate your sessions.
  • To verify your identity and comply with KYC/AML legal obligations.
  • To process deposits, withdrawals, and ledger entries accurately.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To send transactional emails (e.g. KYC status, deposit/withdrawal confirmations, security alerts).
  • To comply with legal and regulatory obligations, including reporting to competent authorities where required.

3. KYC Document Handling

Identity documents submitted for KYC are stored in access-restricted storage on infrastructure we control. Access is limited to authorized personnel performing compliance review. KYC documents are retained for as long as your account is active and for the period thereafter required by applicable AML record-keeping obligations, after which they are securely deleted.

4. Cookies and Sessions

We use a single essential, HTTP-only session cookie to keep you signed in. This cookie is required for the Platform to function and is not used for advertising or cross-site tracking. We do not use third-party analytics or advertising cookies. Session cookies are transmitted only over encrypted (HTTPS) connections in production.

5. Security Practices

  • Passwords are hashed using bcrypt; we never store plaintext passwords.
  • Sessions are authenticated via signed, HTTP-only cookies and are invalidated on password change or other sensitive account events.
  • All production traffic is served over HTTPS/TLS.
  • Access to KYC documents, ledger data, and admin functions is restricted by role-based permissions and logged via audit trails.
  • Database backups are encrypted at rest where supported by infrastructure and access-restricted.

No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.

6. Data Retention

We retain account and transaction data for as long as your account is active, and for a reasonable period afterward to meet legal, accounting, and AML record-keeping obligations (which can require retention of several years after account closure). Technical logs are retained for a limited period for security and debugging purposes and are then deleted or anonymized.

7. Your Rights

Subject to applicable law (including GDPR, where it applies to you), you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data, subject to our legal retention obligations (e.g. AML record-keeping cannot be overridden by a deletion request).
  • Object to or request restriction of certain processing.
  • Request a copy of your data in a portable format.
  • Lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.

To exercise any of these rights, contact us using the details below.

8. Data Sharing

We do not sell personal data. We may share data with:

  • Service providers acting on our behalf (e.g. email delivery, hosting), bound by confidentiality obligations.
  • Regulators or law enforcement where required by applicable law or a valid legal request.
  • Successors in the event of a merger, acquisition, or asset transfer, subject to equivalent privacy protections.

9. Contact

For privacy questions or to exercise your rights, contact privacy@3real.no.

Terms of Service · Back to 3REAL