Last updated: February 12, 2026
Data Controller: Bank of Bali · Contact: hello@bankofbali.com
Bank of Bali is built on a privacy-first foundation. This Policy explains what personal data we collect, why we collect it, how long we keep it, and the rights you have under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and similar laws. We never sell, rent or share your data with advertisers.
Bank of Bali (the "Service") is operated by Bank of Bali ("we", "us", "our"), acting as the Data Controller for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Our Data Protection contact is: hello@bankofbali.com. Privacy and data-subject requests can be sent to the same address with the subject line "Privacy Request".
We intentionally minimise data collection. The categories we process are:
hello@, support@, press@ bankofbali.com.We do not collect: government IDs (unless you voluntarily complete enhanced due-diligence for OTC volumes over $1,000), biometrics, contact lists, browsing history, or advertising identifiers.
We rely on the following legal grounds:
Bank of Bali operates globally. Personal data may be processed in the EU, the UK, the United States and Indonesia. Where data leaves the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs 2021) or an adequacy decision. You may request a copy of the applicable safeguards by contacting us.
Subject to applicable law, you have the right to:
To exercise any right, email hello@bankofbali.com. We respond within 30 days (extendable by 60 days for complex requests, GDPR Art. 12(3)).
Bank of Bali is not directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us and we will delete it.
We apply industry-standard controls: TLS 1.3 in transit, bcrypt password hashing, encrypted wallet files, JWT httpOnly secure cookies, brute-force lockouts, optional TOTP 2FA, VPN/proxy fingerprinting, and 24/7 automated fraud monitoring. No system is 100% secure — store your 25-word seed phrase offline; we cannot recover it for you.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and inform affected users without undue delay.
We will post any material change here and update the "Last updated" date. For substantive changes, we will email account holders at least 14 days before they take effect.
Privacy questions, requests and complaints: hello@bankofbali.com.
EU/UK users also have the right to lodge a complaint with their national data-protection authority.
We respect your privacy.
Bank of Bali uses strictly-necessary cookies to keep you signed in. Analytics cookies are optional and never used for advertising. See our Cookie Policy and Privacy Policy.