HopFo (the “Company”, “we”, “us”) is the controller of your personal data.
Contact: [email protected]
1. General Provisions
1.1. This Privacy Policy (the “Policy”) explains how HopFo (the “Company”, “we”, “us”) — the data controller — collects, uses, stores, shares and protects personal data of users (the “User”, “you”) of the HopFo service (the “Service”).
1.2. The Service is provided through the Company's website and a Telegram WebApp. By using the Service, you acknowledge that you have read and understood this Policy.
1.3. We process personal data in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the law of the Republic of Cyprus.
1.4. We may update this Policy from time to time. The current version is always available in the Interface. Continued use of the Service after changes constitutes acknowledgement of the updated Policy.
2. Data We Collect
2.1. Contact data: email address and, where provided, phone number.
2.2. Telegram profile data received via the Telegram WebApp: Telegram ID, username, first/last name and profile photo.
2.3. Payment and transaction data: card identifiers, balances, transaction amounts, merchants, dates and statuses. Full card numbers and security codes are handled by our Providers (issuers and processors), not stored by us in plain form.
2.4. Technical data: IP address, browser and device parameters, operating system, language settings, and access timestamps.
2.5. Cookies and similar technologies (see Section 9).
2.6. Communications: information you voluntarily provide when contacting support.
2.7. We do not knowingly collect special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs or health data).
3. How We Use Data
3.1. To operate the Service, authenticate users and maintain accounts.
3.2. To issue and service virtual cards and to process and track transactions.
3.3. To prevent, detect and investigate fraud, abuse and security incidents.
3.4. For internal analytics and to improve the Service.
3.5. To comply with legal, regulatory, accounting and anti-money-laundering obligations.
3.6. To communicate with you, including service notifications and support responses.
4. Legal Basis for Processing
4.1. Performance of a contract — to provide the Service you request (GDPR Art. 6(1)(b)).
4.2. Compliance with a legal obligation — including financial, tax and AML requirements (GDPR Art. 6(1)(c)).
4.3. Consent — for example, for certain cookies and optional communications; you may withdraw consent at any time (GDPR Art. 6(1)(a)).
4.4. Legitimate interests — service administration, security and prevention of abuse, balanced against your rights (GDPR Art. 6(1)(f)).
5. Sharing With Third Parties
5.1. Providers — banks, card issuers, payment systems and processors — to issue cards and execute transactions.
5.2. Telegram — profile data is received and exchanged via the Telegram WebApp API in accordance with Telegram's terms.
5.3. Analytics and technical service providers (including SDK providers and contractors) — generally limited to technical data, in aggregated or anonymized form where possible.
5.4. Government authorities and law enforcement — where required by applicable law or to protect our rights.
5.5. We do not sell personal data to third parties for commercial purposes.
6. International Data Transfers
6.1. Your data may be transferred to and processed in countries outside your own, including outside the European Economic Area, where our Providers or infrastructure operate.
6.2. Where such transfers occur, we take steps to ensure an appropriate level of protection, such as relying on adequacy decisions or standard contractual clauses where applicable.
7. Data Retention
7.1. We retain personal data only for as long as necessary for the purposes set out in this Policy, including to provide the Service and to satisfy legal, accounting and AML retention requirements.
7.2. When data is no longer required, we delete or anonymize it. Certain records may be retained longer where required by law.
8. Your Rights
8.1. Subject to applicable law, you have the right to: access your data; request rectification of inaccurate data; request erasure; restrict or object to processing; data portability; and withdraw consent where processing is based on consent.
8.2. To exercise these rights, contact us at [email protected]. We may need to verify your identity before responding.
8.3. You also have the right to lodge a complaint with a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection.
9. Cookies and Similar Technologies
9.1. We and our service providers use cookies, local storage and SDKs to operate the Service, authenticate sessions, remember preferences and collect technical and analytics data.
9.2. You can manage cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.
10. Security
10.1. We apply reasonable organizational and technical measures to protect personal data, including access controls and protected storage.
10.2. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials and devices secure.
11. Children
11.1. The Service is intended only for adults with full legal capacity. We do not knowingly collect data from minors. If we learn that we have collected such data, we will delete it and may block the account.
12. Changes to This Policy
12.1. We may amend this Policy at any time. The current version is published in the Interface with its effective date. Material changes may be additionally notified where required by law.
13. Contact
For any questions or requests regarding this Policy or your personal data, contact us at: [email protected].