1. Overview and Company-Favorable Interpretation
This Privacy Policy is intended to provide transparent notice of the privacy practices of CHARLESPRO INTERNACIONAL CORP, including its CharlesPRO International brand, websites, forms, investor-facing or participant-facing communications, private access desks, onboarding workflows, information pages, dashboards, analytics, and other digital or offline interactions that link to, display, or incorporate this Policy.
For purposes of this Policy, “Company,” “we,” “us,” “our,” and “CharlesPRO” refer to CHARLESPRO INTERNACIONAL CORP and its authorized representatives, service providers, processors, affiliates, contractors, successors, and permitted assigns, as context permits. “User,” “you,” and “your” refer to any visitor, prospective client, participant, applicant, representative of an entity, investor contact, business contact, or other person who accesses or interacts with our services.
This Policy is drafted to preserve the Company’s operational flexibility, risk-control rights, security practices, compliance rights, and ability to process information as permitted by applicable law, contractual necessity, legitimate business needs, legal obligations, and user consent where consent is required. Nothing in this Policy limits any right, defense, exemption, waiver, lawful processing basis, or other protection available to the Company under applicable law.
This Policy does not create any fiduciary, advisory, financial, brokerage, banking, custodial, investment, employment, partnership, agency, or special relationship. Any separate signed agreement, investor document, onboarding document, risk disclosure, compliance questionnaire, authorization, or service-specific notice may contain additional data terms. In the event of a conflict, the more specific, more recent, or legally required document controls to the maximum extent permitted by law.
2. Scope of this Policy
This Policy applies to personal information processed in connection with:
- our websites, landing pages, request forms, lead forms, login screens, dashboards, and digital interfaces;
- CharlesPRO International materials, CapitalPro, CharlesPRO AppWeb, capital access, smart portfolio tools, secure Web3 functionality, global strategy materials, private app access, investor desk workflows, and related communications;
- business development, onboarding, identity verification, compliance screening, support, risk review, and operational coordination;
- email, WhatsApp, SMS, Telegram, social media, video calls, forms, documents, support requests, and other communications sent to or from us;
- market data displays, analytics, cookies, local storage, device identifiers, log files, and security monitoring;
- offline interactions, signed documentation, forms, questionnaires, compliance files, and due diligence records.
This Policy does not apply to information processed by third-party websites, wallets, exchanges, payment processors, banks, custodians, blockchain networks, social networks, analytics providers, KYC vendors, hosting companies, or other independent third parties, even if their services are linked from or integrated with our services. Their privacy practices are governed by their own policies and terms.
3. Data Controller, Business, and Service Provider Roles
Depending on the context, CHARLESPRO INTERNACIONAL CORP may act as a data controller, business, service provider, processor, joint controller, independent controller, or recipient of information. The applicable role depends on the source of the data, the relationship with the user or entity, the governing contract, and the applicable law.
Where we process information on behalf of an entity customer, partner, counterparty, or service provider, that entity may be responsible for providing required notices, obtaining consents, and responding to certain privacy rights requests. We reserve the right to redirect requests to the appropriate entity, refuse requests where we cannot verify authority, or process requests only as required by applicable law.
4. Categories of Information We May Collect
We may collect, receive, create, infer, or otherwise process the following categories of personal information, subject to applicable law and operational need:
| Category | Examples | Primary Purposes |
|---|---|---|
| Identifiers | Name, alias, business name, email, phone number, WhatsApp contact, mailing address, username, account ID, IP address, device ID. | Account creation, communication, access review, support, compliance, security, fraud prevention. |
| Professional / Business Information | Company name, role, entity documents, business registration, authorized representative details, investment interest, corporate email, professional background. | Due diligence, relationship management, suitability review, entity verification, communications. |
| Contact and Communications Data | Emails, forms, chat messages, support tickets, call notes, meeting notes, attachments, requests, preferences. | Responding to inquiries, documenting communications, operational coordination, dispute prevention. |
| KYC / AML and Compliance Information | Government ID references, verification status, date of birth, nationality, residency, sanctions screening, watchlist checks, beneficial ownership details, source-of-funds or source-of-wealth details, accreditation or suitability materials where applicable. | Legal compliance, risk management, fraud prevention, onboarding approval, regulatory defense. |
| Financial and Transactional Information | Payment references, invoices, wallet addresses, blockchain transaction hashes, bank or processor references, fee records, chargeback history, subscription or access records. | Processing payments, reconciliation, tax/accounting records, fraud control, contractual administration. |
| Device and Technical Data | IP address, browser type, operating system, device model, session IDs, cookies, local storage, language settings, time zone, referral URLs, log files. | Security, analytics, performance, troubleshooting, fraud prevention, personalization. |
| Usage and Interaction Data | Pages viewed, links clicked, forms started or submitted, login attempts, dashboard activity, app access status, market tool interactions. | Service improvement, security monitoring, analytics, operational reporting, user experience. |
| Inferences | Interest area, risk flags, verification status, likely language preference, product interest, engagement level. | Operational prioritization, compliance triage, personalization, fraud detection. |
| Sensitive Information | Government ID data, precise compliance screening data, financial verification materials, biometric or face-match data if provided through a third-party vendor, account credentials if voluntarily submitted in error. | Identity verification, legal compliance, fraud prevention, security, account protection. |
We do not intentionally request more sensitive information than reasonably necessary for the relevant business, legal, security, compliance, or onboarding purpose. However, if you voluntarily submit unsolicited sensitive information, you authorize us to process it to review, store, delete, restrict, return, document, or otherwise handle it as reasonably necessary and permitted by law.
5. Sources of Information
We may collect information from:
- you directly, including when you submit a form, request access, contact us, attend a call, send documents, or communicate through email or messaging channels;
- authorized representatives, entity administrators, business partners, referrers, introducers, advisors, counterparties, and support personnel;
- third-party verification, KYC, AML, fraud prevention, analytics, hosting, payment, blockchain data, compliance, cybersecurity, and communications providers;
- public sources, including corporate registries, court records, sanctions lists, social media, blockchain explorers, public wallet activity, government databases, and public websites;
- automated technologies, including cookies, pixels, server logs, device signals, local storage, and analytics tools;
- records we generate internally, such as risk review notes, verification results, support logs, access decisions, transaction reconciliations, and operational records.
You represent that any information you provide to us is accurate, lawful, and submitted with all necessary authority, consent, and legal rights. If you provide information about another person or entity, you are responsible for ensuring that such person or entity has received any legally required notice and has authorized the disclosure.
6. How We Use Information
We may use personal information for the following business, operational, legal, and compliance purposes:
- to provide, operate, maintain, improve, personalize, secure, and administer our websites, dashboards, app access, onboarding flows, communications, and related services;
- to receive, evaluate, approve, deny, prioritize, suspend, or close access requests, onboarding submissions, private app requests, investor desk requests, or program-related inquiries;
- to perform identity verification, business verification, beneficial ownership checks, sanctions screening, PEP screening, AML review, fraud prevention, risk scoring, and other compliance checks;
- to communicate with you about inquiries, applications, account status, onboarding, documentation, program updates, operational notices, support, security, policy updates, or administrative matters;
- to process payments, invoices, reconciliations, refunds when applicable, chargeback responses, processor communications, tax/accounting records, fee records, and transaction documentation;
- to prevent, detect, investigate, document, and respond to fraud, abuse, unauthorized access, suspicious activity, cybersecurity events, misconduct, breach of terms, or unlawful activity;
- to enforce or defend our Terms and Conditions, risk disclosures, agreements, policies, legal rights, security rights, ownership rights, contractual rights, and business interests;
- to comply with laws, regulations, subpoenas, court orders, law enforcement requests, tax obligations, sanctions requirements, regulatory inquiries, audit obligations, and internal governance requirements;
- to conduct analytics, performance measurement, testing, debugging, service development, content optimization, business forecasting, quality control, and product improvement;
- to create deidentified, aggregated, statistical, or anonymized information that does not reasonably identify you, which we may use and disclose for any lawful business purpose;
- to evaluate corporate transactions, financing, restructuring, mergers, acquisitions, assignments, sale of assets, due diligence, insurance, risk transfer, or business continuity events;
- for any other purpose disclosed at the time of collection, authorized by you, required by contract, or permitted by applicable law.
We reserve the right to refuse, suspend, terminate, restrict, or delay services, access, communications, or transactions where we reasonably believe processing information is necessary to protect the Company, users, counterparties, financial systems, blockchain networks, service providers, or legal compliance.
7. Legal Bases for Processing
Where laws such as the GDPR, UK GDPR, or similar privacy laws require a legal basis, we may rely on one or more of the following:
| Legal Basis | Examples |
|---|---|
| Consent | Marketing subscriptions, optional cookies where required, voluntary submissions, certain communications preferences. |
| Contractual Necessity | Processing needed to provide requested services, evaluate access, administer agreements, respond to service requests, process payments. |
| Legal Obligation | KYC/AML, sanctions screening, accounting, tax, subpoenas, regulatory requests, data retention obligations, security reporting. |
| Legitimate Interests | Security, fraud prevention, risk control, business development, analytics, service improvement, documentation, enforcement of rights, corporate governance. |
| Vital Interests / Public Interest | Rare circumstances involving safety, fraud, emergency response, legal reporting, or protection of persons or systems. |
Where we rely on legitimate interests, we do so only where we believe our interests are not overridden by your legally protected privacy interests, rights, or freedoms. You may have the right to object in certain jurisdictions, subject to verification, exemptions, and our compelling legitimate grounds.
8. KYC, AML, Sanctions, Fraud, and Verification Processing
Because our materials and services may relate to institutional access, capital strategy, financial opportunities, digital asset ecosystems, transaction references, wallets, private access desks, onboarding workflows, and similar high-risk contexts, we may require identity, business, source-of-funds, source-of-wealth, beneficial ownership, accreditation, suitability, residency, nationality, sanctions, and compliance information before providing or continuing access.
We may use internal review, third-party vendors, databases, watchlists, public records, blockchain analytics, fraud tools, device intelligence, email or phone verification, and manual review. We may deny, restrict, or terminate access if information is incomplete, inconsistent, unverifiable, high risk, prohibited, suspicious, or otherwise unacceptable to us in our sole discretion, subject to applicable law.
We may retain compliance records even after a request for deletion where retention is necessary or advisable for legal compliance, regulatory defense, audit, sanctions screening, AML obligations, fraud prevention, dispute resolution, enforcement, accounting, recordkeeping, or other legitimate business purposes.
10. Blockchain, Wallet, and Digital Asset Information
If you connect, disclose, submit, or reference a wallet address, transaction hash, public blockchain address, smart contract, token, payment reference, or digital asset transaction, we may process that information together with other information we hold about you for verification, compliance, support, reconciliation, fraud prevention, analytics, or service administration.
Public blockchains are typically transparent, permanent, distributed, and outside the Company’s control. Information recorded on a blockchain may be publicly visible, indexed by third parties, copied, analyzed, linked to other data, and impossible for us to alter or delete. Your privacy rights may not extend to deletion or correction of immutable public blockchain records, although we may be able to delete or restrict certain off-chain records that we control, subject to legal and operational exceptions.
You are responsible for protecting your wallets, private keys, seed phrases, devices, credentials, and transaction approvals. We will never ask you to disclose a seed phrase or private key. If you voluntarily disclose sensitive wallet credentials to us, we may delete, ignore, secure, or document the disclosure as we deem appropriate, and we disclaim liability for losses arising from your disclosure of such information.
12. Retention of Information
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide services, review requests, administer relationships, maintain records, comply with legal obligations, prevent fraud, resolve disputes, enforce agreements, preserve evidence, support audits, maintain security, and protect the Company’s rights.
Retention periods vary depending on the category of information, relationship, risk level, legal obligations, regulatory expectations, contractual requirements, and operational needs. Compliance, KYC, AML, transaction, tax, accounting, security, dispute, and fraud-related records may be retained for longer periods where required or advisable. When information is no longer reasonably needed, we may delete, deidentify, aggregate, archive, restrict, or securely retain it as permitted by law.
Deletion requests may be denied or limited where retention is necessary for legal compliance, security, fraud prevention, dispute resolution, contractual enforcement, accounting, audit, exercise or defense of legal claims, public blockchain limitations, or other recognized exceptions.
13. Security Measures and Limitations
We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, and destruction. These measures may include access controls, limited personnel access, vendor controls, encryption where appropriate, monitoring, backups, logging, secure hosting, authentication measures, and internal procedures.
No website, application, blockchain interaction, network, system, database, email, messaging platform, transmission, or storage method is completely secure. We cannot and do not guarantee absolute security. You are responsible for maintaining the confidentiality of your devices, wallets, credentials, passwords, private keys, recovery phrases, email accounts, messaging accounts, and access methods.
If we become aware of a data security incident that legally requires notice, we will provide notice in accordance with applicable law. We reserve the right to investigate, remediate, document, and respond to suspected incidents in our discretion and to restrict access when necessary to protect systems, users, or the Company.
14. Your Privacy Rights
Depending on your location and applicable law, you may have the right to request access, confirmation of processing, correction, deletion, portability, restriction, objection, withdrawal of consent, appeal of a decision, opt-out of certain sales/sharing or targeted advertising, limitation of sensitive data use, or other rights. These rights are not absolute and may be subject to verification, exceptions, limitations, fees where permitted, and our legal obligations.
To submit a request, contact us at info@charlesprointernational.com with the subject line “Privacy Request.” We may request information to verify your identity, authority, residency, account relationship, and scope of request. We may decline requests that are unverifiable, excessive, repetitive, fraudulent, unlawful, technically infeasible, or outside the scope of applicable law.
Authorized agents may submit requests where permitted by law, but we may require proof of authorization, identity verification, and direct confirmation from the individual. We will not discriminate against you for exercising rights required by applicable law, but exercising certain rights may affect the availability, functionality, or legality of services.
15. California Privacy Notice
This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to the Company. California residents may have rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, obtain portability, and be free from unlawful discrimination for exercising those rights.
The categories of personal information we may collect are described in Section 4 above. The categories of sources are described in Section 5. The business or commercial purposes are described in Section 6. The categories of recipients are described in Section 11.
| CCPA Category | Collected | Disclosed for Business Purpose |
|---|---|---|
| Identifiers | Yes | Yes, to service providers, compliance vendors, communications providers, and operational parties. |
| Customer Records Information | Yes | Yes, where needed for onboarding, KYC, payment, accounting, legal, or support purposes. |
| Protected Classification Characteristics | Potentially | Only where voluntarily provided or legally required for verification, compliance, or legal obligations. |
| Commercial Information | Yes | Yes, for transaction records, service administration, analytics, and compliance. |
| Internet or Network Activity | Yes | Yes, for security, analytics, hosting, debugging, fraud prevention, and service improvement. |
| Geolocation Data | Potentially | Approximate location may be processed through IP address for security, compliance, and analytics. |
| Professional or Employment Information | Potentially | Yes, for business onboarding, due diligence, relationship management, and verification. |
| Sensitive Personal Information | Potentially | Yes, where required for KYC/AML, identity verification, compliance, fraud prevention, or security. |
| Inferences | Potentially | Yes, for operational prioritization, risk controls, analytics, and personalization. |
We do not knowingly sell or share personal information of individuals under 16. We do not use sensitive personal information to infer characteristics except as permitted by law, or as necessary for security, compliance, fraud prevention, verification, service delivery, or other lawful purposes.
If an activity is considered a “sale” or “sharing” under California law, you may request to opt out by contacting info@charlesprointernational.com with the subject line “Do Not Sell or Share My Personal Information.” We may provide additional opt-out tools if legally required.
16. Florida Digital Bill of Rights Notice
To the extent the Florida Digital Bill of Rights or other Florida privacy and security laws apply to the Company, Florida consumers may have rights regarding confirmation, access, correction, deletion, portability, opt-out of certain processing, targeted advertising, sale of personal data, profiling, and certain sensitive data practices. Applicability may depend on statutory thresholds, exemptions, data types, and business activities.
We provide this notice voluntarily and without conceding that any specific Florida privacy statute applies to every user, product, service, or processing activity. We reserve all statutory exemptions, including exemptions for legal compliance, fraud prevention, security, contractual necessity, financial and regulated information, deidentified data, publicly available information, internal operations, and other permitted uses.
Florida privacy requests may be submitted to info@charlesprointernational.com with the subject line “Florida Privacy Request.” We may verify identity and apply legal exceptions before responding.
17. International Data Transfers
We may process information in the United States and other jurisdictions where we, our service providers, vendors, affiliates, or partners operate. These jurisdictions may have privacy and data protection laws that differ from those in your country or region.
Where legally required, we may use appropriate transfer mechanisms, contractual protections, standard contractual clauses, adequacy decisions, consent, necessity for contract, necessity for legal claims, or other lawful bases for cross-border transfers. By using our services or submitting information, you acknowledge that information may be transferred, stored, and processed outside your country of residence.
18. Children and Minors
Our services are not directed to children or minors. We do not knowingly collect personal information from children under 13, or from minors where a higher age threshold applies, without legally valid consent. If you believe a child has provided personal information to us, contact us and we will take appropriate steps as required by law.
Users must not submit information on behalf of minors unless they have full legal authority and the submission is expressly permitted by our services and applicable law. We reserve the right to delete, restrict, or retain records as necessary to document improper submissions, comply with law, or protect the Company.
19. Third-Party Services, Links, and Integrations
Our services may include links, embeds, scripts, APIs, widgets, analytics, content, app store badges, logos, blockchain explorers, payment links, wallet references, social media pages, messaging links, or other third-party services. We do not control the privacy practices, security, content, availability, legality, or accuracy of third-party services. Your use of third-party services is subject to their own terms and privacy policies.
We are not responsible for third-party failures, breaches, delays, outages, data practices, wallet activity, blockchain network behavior, exchange activity, financial institution requirements, or user disclosures to third parties. You should review third-party policies before submitting information or connecting accounts.
20. Communications, Marketing, and Messaging
We may contact you by email, phone, SMS, WhatsApp, Telegram, social media, push notification, web notification, or other communication methods for administrative, transactional, security, support, onboarding, compliance, marketing, investor desk, app launch, documentation, or relationship-management purposes.
You may opt out of promotional emails by using unsubscribe mechanisms where provided or by contacting us. We may continue to send non-promotional messages, including security alerts, legal notices, account notices, compliance notices, policy updates, service notices, and communications necessary to administer an existing relationship.
Messaging platforms are operated by third parties and may collect or process metadata, message content, phone numbers, identifiers, and usage data under their own terms. Do not send highly sensitive information through insecure channels unless expressly requested through an authorized secure process.
21. Automated Processing, Risk Scoring, and Profiling
We may use automated or semi-automated tools to support fraud detection, security, risk review, KYC/AML screening, sanctions checks, device intelligence, transaction monitoring, prioritization, analytics, and user experience. These tools may produce risk flags, verification results, or recommendations that may be reviewed by human personnel.
Where applicable law grants rights related to automated decision-making or profiling, you may contact us to request review, objection, or additional information. We may deny, limit, or condition requests where exceptions apply, where disclosure would compromise security or fraud prevention, or where we have compelling legitimate grounds.
22. Deidentified, Aggregated, and Anonymous Information
We may create and use deidentified, anonymized, aggregated, statistical, or synthetic information derived from personal information. We may use and disclose such information for analytics, reporting, product development, security, business planning, research, benchmarking, marketing, and any other lawful purpose.
Where required by law, we will maintain deidentified information without attempting to reidentify it except as permitted for testing, validation, compliance, security, or legal purposes. Deidentified or aggregated information is not treated as personal information where it cannot reasonably identify you.
23. Changes to this Privacy Policy
We may update, modify, replace, or revise this Policy at any time. The updated version will be posted with a revised effective date. Changes are effective when posted unless a different date is stated or legally required. Your continued use of our services after changes become effective constitutes acknowledgment of the updated Policy to the maximum extent permitted by law.
Where required, we may provide additional notice or request consent for material changes. It is your responsibility to review this Policy periodically. If you disagree with the Policy, you should discontinue use of our services and contact us regarding any legally available rights.
24. Contact Information
For privacy questions, requests, or concerns, contact:
Company: CHARLESPRO INTERNACIONAL CORP
Brand: CharlesPRO International
Email: info@charlesprointernational.com
Website: charlesprointernational.com
Subject Line: Privacy Request
Please do not submit private keys, seed phrases, wallet recovery phrases, passwords, or highly sensitive documents unless requested through a secure and authorized verification process. Communications sent through email or messaging platforms may not be fully secure.
Company Protective Notice
This Policy should be interpreted to preserve all rights and defenses available to CHARLESPRO INTERNACIONAL CORP. Any statement regarding user rights applies only to the extent required by applicable law and only where the relevant law applies to the Company, the user, the processing activity, and the data involved. We reserve all exceptions, exemptions, limitations, privileges, and lawful grounds for refusal, delay, restriction, retention, disclosure, or continued processing.
Nothing in this Policy waives attorney-client privilege, work-product protection, trade secret protection, cybersecurity confidentiality, anti-fraud protections, regulatory defenses, contractual rights, arbitration rights, limitation of liability clauses, indemnity rights, or any other protection provided by law or contract.