Privacy Policy

Bao Trader Effective: March 10, 2026
This Privacy Policy explains how Bao Trader, operated by ORYON TECH LIMITED (the "Company", "we", "us", or "our"), collects, uses, processes, stores, and protects personal data obtained from users of the Bao Trader platform and related services (the "Platform").

The purpose of this Privacy Policy is to ensure transparency regarding the Company's data practices and to inform users of their rights with respect to personal data.

1. Introduction and Scope

1.2 Applicability

This Privacy Policy applies to personal data collected through:

This Privacy Policy applies to the following individuals:

1.3 Regulatory Compliance

The Company is committed to compliance with applicable data protection laws, including:

Where different legal requirements apply depending on the user's jurisdiction, the Company will apply the relevant protections accordingly.

1.4 Acceptance

By accessing or using the Platform, users acknowledge that they have read and understood this Privacy Policy. Where required by applicable law, explicit consent may be requested for specific data processing activities.

1.5 Relationship with Other Documents

This Privacy Policy should be read together with:

In the event of any conflict regarding data processing matters, this Privacy Policy shall prevail.

1.6 Definitions

"Personal Data" means any information relating to an identified or identifiable individual.
"Processing" means any operation or set of operations performed on personal data.
"User" means any individual who accesses or uses the Platform.
"Platform" means the Bao Trader website, simulated trading environment, and associated services.

2. Data Controller and Contact Information

2.1 Data Controller

The data controller responsible for the processing of personal data is:

ORYON TECH LIMITED
Unit 1126, 11/F., Eton Tower
8 Hysan Avenue
Causeway Bay, Hong Kong

The Company acts as the Data Controller for all personal data processed through the Platform.

2.2 Contact for Privacy Matters

For any questions or concerns regarding this Privacy Policy or the processing of personal data, users may contact the Company at: privacy@bao.io

2.3 Data Protection Officer

The Company may designate a Data Protection Officer (DPO). If a DPO is designated, their contact information will be made available on the Platform. Otherwise, privacy matters are handled by the Company's compliance and legal team.

2.4 Representative for European Users

The Company may appoint an EEA representative where required under applicable data protection laws.

2.5 Complaints to Supervisory Authorities

Users have the right to lodge complaints with the relevant supervisory authority:

Users are encouraged to contact the Company first to resolve any concerns before filing a complaint with a supervisory authority.

3. Categories of Personal Data Collected

3.1 Overview

The categories of personal data collected depend on how users interact with the Platform.

3.2 Identification Information

This information is used for account registration and user identification.

3.3 Identity Verification Information

Identity verification may be required before:

3.4 Payment and Transaction Information

Payment processing is conducted through third-party payment service providers.

3.5 Technical and Device Information

This data is used for security, fraud prevention, and Platform optimization.

3.6 Device Fingerprinting and Security Data

This data helps detect suspicious activity, unauthorized access, and potential violations of Platform rules.

3.7 Trading Activity and Platform Usage Data

This data is used for evaluation, monitoring, and fraud detection purposes.

3.8 Communication Data

Communications may be recorded for quality assurance and compliance purposes.

3.9 Marketing and Preference Information

Users may withdraw consent for marketing communications at any time.

3.10 Publicly Available Information

The Company may collect information from publicly accessible databases or sanctions lists. This data is used for compliance, fraud prevention, and risk management purposes.

4. How Personal Data Is Collected

4.1 Direct Collection

Personal data may be collected directly from users through:

4.2 Automated Data Collection

Certain data is collected automatically through:

4.3 Cookies and Tracking Technologies

Cookies and similar technologies may collect:

These technologies are used for functionality, security, analytics, and remembering user preferences.

4.4 Device and Security Monitoring

The Company may monitor the following for security purposes:

This monitoring is used for detecting suspicious activity and fraud prevention.

4.5 Third-Party Identity Verification Providers

The Company may receive data from third-party identity verification providers, including:

4.6 Payment Service Providers

Payment service providers may process:

The Company receives limited confirmation data from payment providers.

4.7 Analytics Providers

Third-party analytics providers may collect:

Analytics data is generally collected in aggregated form.

4.8 Public Sources

The Company may collect data from public sources, including:

This data is used for compliance, fraud prevention, and risk management.

5. Purposes and Legal Bases for Processing

5.1 Overview

The Company processes personal data only where there is a valid legal basis for doing so.

5.2 Performance of a Contract

Processing is necessary for the performance of a contract, including:

5.3 Compliance with Legal Obligations

Processing may be required to comply with:

5.4 Legitimate Business Interests

The Company may process personal data based on legitimate business interests, including:

5.5 Fraud Prevention and Platform Security

The Company processes data for fraud prevention and security purposes, including:

5.6 Marketing Communications

Marketing communications are sent only with user consent or where permitted by law for existing customers. Users can unsubscribe from marketing communications at any time.

5.7 User Consent

Where consent is the legal basis, it applies to:

Users may withdraw consent at any time without affecting the lawfulness of processing based on consent prior to withdrawal.

5.8 Analytics and Service Improvement

The Company may process data for analytics and service improvement, including:

Data used for analytics may be aggregated or anonymized.

5.9 Legal Defense and Enforcement

Processing may be necessary to:

6. Identity Verification and Compliance (KYC)

6.1 Purpose

The Company may require identity verification to:

6.2 Information Used

Identity verification may involve the collection and processing of:

6.3 Third-Party Providers

The Company may use third-party identity verification providers for:

These providers are contractually required to maintain appropriate security and confidentiality standards.

6.4 Anti-Fraud and Abuse Prevention

The Company may conduct:

6.5 Sanctions and Compliance Screening

The Company may screen users against sanctions lists maintained by:

Access to the Platform may be restricted if a user appears on any applicable sanctions list.

6.6 Refusal or Failure to Complete Verification

If a user refuses or fails to complete identity verification, the Company may:

6.7 Data Protection in Verification

Identity verification data is processed in accordance with applicable data protection laws. The Company applies reasonable safeguards, limits access to authorized personnel only, and does not use verification data for unrelated purposes.

7. Cookies and Tracking Technologies

7.1 Use of Cookies

The Platform uses cookies and similar technologies. Cookies are small data files placed on a user's device, which may be set by the Company or by third parties.

7.2 Types of Cookies

Essential Cookies: Required for authentication, session management, and security.

Security Cookies: Used to detect suspicious login attempts, automated abuse, and maintain Platform integrity.

Analytics Cookies: Collect information about pages visited, time spent on the Platform, navigation patterns, and feature interactions.

Preference Cookies: Store language settings, UI preferences, and login preferences.

Marketing Cookies: Used to deliver relevant promotional content and track marketing campaign effectiveness, where permitted by law.

7.3 Similar Technologies

In addition to cookies, the Company may use:

7.4 Managing Preferences

Users can manage cookie preferences through their browser settings, including the ability to:

Disabling certain cookies may affect the functionality of the Platform.

7.5 Third-Party Cookies

Third-party cookies may be set by analytics providers, security monitoring services, and infrastructure providers. The Company does not control the use of cookies by third parties.

7.6 Retention

Session cookies expire when the browser is closed. Persistent cookies remain on the user's device for a defined period or until manually deleted.

8. Sharing of Personal Data with Third Parties

8.1 Overview

The Company does not sell personal data. Personal data may be shared with third parties only in accordance with applicable data protection laws.

8.2 Service Providers

The Company may share personal data with service providers who assist in operating the Platform, including:

8.3 Payment Processing Providers

Payment processing providers may receive:

Payment providers operate under their own privacy policies.

8.4 Identity Verification Providers

Identity verification providers may receive:

8.5 Infrastructure and Cloud Providers

Infrastructure and cloud providers may process technical data necessary for the operation and maintenance of the Platform. These providers are required to maintain appropriate security standards.

8.6 Analytics Providers

Analytics providers may receive:

Analytics data is typically aggregated before sharing.

8.7 Legal and Regulatory Disclosures

The Company may disclose personal data to:

8.8 Business Transfers

In the event of a merger, acquisition, or restructuring, personal data may be transferred as part of the business assets. The Company will take reasonable steps to protect personal data during any such transfer.

8.9 Protection of Rights and Security

Personal data may be shared to:

9. International Data Transfers

9.1 Cross-Border Nature

The Platform is operated from Hong Kong and serves users from various jurisdictions. Personal data may be transferred to, stored in, and processed in countries other than the user's country of residence.

9.2 Transfers for Operations

Data may be transferred to service providers located in multiple jurisdictions for:

9.3 EEA Transfers

For transfers of personal data outside the European Economic Area, the Company relies on:

9.4 Transfers to Service Providers

Service providers receiving personal data are required to:

9.5 Within Corporate Structure

Personal data may be shared with affiliates or related entities for operational and administrative purposes.

9.6 User Acknowledgment

By using the Platform, users acknowledge and accept that their personal data may be transferred internationally as described in this section.

10. Data Retention

10.1 General Principles

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Retention periods may be longer where required by legal obligations, ongoing disputes, contractual agreements, or security requirements.

10.2 Account Information

Account information is retained for the duration of the user's relationship with the Company. After account closure, data may be retained for up to five (5) years unless a longer retention period is required by law.

10.3 Identity Verification Data

Identity verification data is retained for as long as necessary for security, eligibility verification, and fraud prevention purposes. This data may be retained after account closure.

10.4 Trading and Platform Activity

Trading and platform activity data is retained for evaluation, security, performance analysis, and dispute resolution purposes.

10.5 Communications and Support Records

Communication and support records are retained for dispute resolution, service quality monitoring, and documenting user interactions.

10.6 Fraud Prevention and Security Logs

The Company retains security-related data including:

10.7 Deletion or Anonymization

When personal data is no longer needed, the Company will delete or anonymize it. Anonymized data, which can no longer be associated with an individual, may be retained indefinitely.

10.8 Legal Retention Requirements

Where required by applicable law, personal data will be retained for the duration specified by such legal requirements.

11. User Rights (GDPR, CCPA, PDPO)

11.1 Overview

Users have certain rights regarding their personal data, depending on their jurisdiction. These may include the right to access, correct, delete, or restrict the processing of personal data.

11.2 Right of Access

Users may request information about the categories of personal data processed, the purposes of processing, recipients of data, and retention periods. The Company may require identity verification before fulfilling an access request.

11.3 Right to Rectification

Users may request correction of inaccurate or incomplete personal data. Users may also update their information through account settings where available.

11.4 Right to Erasure ("Right to be Forgotten")

Users may request deletion of their personal data where:

The Company may retain certain data where necessary for legal, security, or contractual reasons.

11.5 Right to Restrict Processing

Users may request restriction of processing where:

11.6 Right to Data Portability

Users may request their personal data in a structured, commonly used, and machine-readable format. Where technically feasible, the Company may transfer data directly to another service provider.

11.7 Right to Object

Users may object to the processing of their personal data, particularly where processing is based on legitimate interests. The Company will review and respond to such objections in accordance with applicable law.

11.8 California Residents (CCPA/CPRA)

California residents have additional rights under the CCPA/CPRA, including:

The Company does not sell personal information.

11.9 Hong Kong PDPO

Users in Hong Kong have rights under the Personal Data (Privacy) Ordinance, including:

The Company may charge a reasonable administrative fee for processing access requests.

11.10 Exercising Rights

To exercise any of the above rights, users may submit a request using the contact information provided in this Privacy Policy. Identity verification may be required before processing any request. The Company will respond within the timeframes required by applicable law.

12. Data Security

12.1 Commitment

The Company implements appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, unauthorized disclosure, alteration, or destruction.

12.2 Technical Safeguards

Technical safeguards include:

12.3 Organizational Measures

Access to personal data is limited to authorized personnel only. The Company maintains internal policies, provides employee training, and restricts data access to those with legitimate business purposes.

12.4 Third-Party Standards

Third-party service providers are required to maintain appropriate security safeguards in accordance with applicable laws and industry standards.

12.5 Data Breach Response

In the event of a data breach, the Company will investigate and take steps to mitigate the impact. Where required by applicable law, the Company will notify affected users and relevant regulatory authorities.

12.6 User Responsibilities

Users are responsible for:

The Company is not responsible for security breaches resulting from user failures to protect their credentials or devices.

12.7 No Absolute Security Guarantee

No system can guarantee absolute security. Transmission of data over the internet carries inherent risks, and the Company cannot ensure or warrant the security of any information transmitted to the Platform.

13. Children's Privacy

13.1 Services for Adults

The Platform is intended for individuals who are at least eighteen (18) years of age. The Company does not knowingly collect personal data from individuals under the age of 18.

13.2 No Intentional Collection

The Company does not solicit personal data from minors. If it is discovered that personal data has been collected from an individual under 18, the Company will take steps to delete such data promptly.

13.3 Parental/Guardian Requests

If a parent or guardian believes that a minor has provided personal data to the Company without consent, they should contact the Company. The Company will investigate and take appropriate action.

13.4 Account Termination

If an underage user is identified, the Company may terminate their account and remove their personal data from the Platform.

14. Changes to This Privacy Policy

14.1 Right to Modify

The Company reserves the right to modify this Privacy Policy to reflect changes in Platform operations, legal requirements, or data processing practices.

14.2 Notification

Users will be notified of changes through:

Users are encouraged to review this Privacy Policy periodically.

14.3 Effective Date

Changes to this Privacy Policy are effective upon publication unless otherwise specified. Continued use of the Platform following publication constitutes acknowledgment of the updated Privacy Policy.

14.4 Previous Versions

The Company may retain previous versions of this Privacy Policy. Users may request access to previous versions where required by applicable law.

15. Contact Information and Complaints

15.1 Contacting the Company

For any questions, concerns, or requests regarding this Privacy Policy or the processing of personal data:

ORYON TECH LIMITED
Unit 1126, 11/F., Eton Tower
8 Hysan Avenue
Causeway Bay, Hong Kong

Email: privacy@bao.io

15.2 Submitting Data Protection Requests

Users may submit requests regarding:

Identity verification may be required before processing any data protection request.

15.3 Complaints to Supervisory Authorities

Users have the right to lodge complaints with the relevant supervisory authority:

Users are encouraged to contact the Company first to resolve any concerns.

15.4 Commitment

The Company is committed to protecting user privacy and continually reviews its data processing practices to ensure transparency, accountability, and security.