Newsletter, product highlights, and trust

Stay ahead of the structure.

Weekly LTO insights, asset updates, and ownership strategies — delivered to your inbox.

Available Capital
$+
Assets Under LTO
+

Everything you need to own, track, and grow.

  • LTO Wallet

    Your assets. Your equity. Live value, tracked in real time.

  • Ownership Page

    Track every installment. See your path to full ownership, one payment at a time.

  • Convert

    Use staking rewards directly toward your balance. Every yield moves you closer.

Non-Recourse. Always.
Institutional MPC Custody.
HyperHedge-secured.
LTO
LTO FrameworkHow it WorksHow to StartYour RightsLTO CalculatorStaking & RewardsEarly Exit & BuyoutConvert AssetTermination
Institutional
Why BitLeaseFor LessorsLessor AgreementSolvency ProofHyperHedge™LTO-as-a-Service
Assets
Bitcoin (BTC) Ethereum (ETH)Solana (SOL)BNB (BNB)Ripple (XRP)
Legal
Terms of ServicePrivacy PolicyLTO AgreementLessor AgreementFee ScheduleRisk DisclosureDisclosuresStaking DisclosureCustody & AssetsExecution & PricingOperational RiskSystem AvailabilityNo Investment Advice
Compliance
AML/CFT PolicySanctions PolicyRegulatory StatusCompliance NoteJurisdiction & LimitsData & PrivacyCookie PolicyData ProcessingIP Notice
Company
AboutNews & InsightsPartnersHelp CenterResourcesMedia KitAnnouncements
Follow BitLease

Risk Warning: Digital assets are highly volatile and subject to market risks. BitLease does not provide investment, financial, tax, or legal advice. The LTO (Lease-to-Own) service may not be suitable for all users. Past performance of any digital asset is not indicative of future results. Platform Reference Prices may differ from real-time exchange prices. BitLease is not a cryptocurrency exchange and does not operate an order book. All LTO Contracts are non-recourse — your maximum loss is limited to payments made. Please ensure you fully understand the risks involved and consult our Risk Disclosure document before proceeding. Our services are not available to residents of restricted jurisdictions, including but not limited to the United States.

BitLease Technologies Ltd. is a subsidiary of 49G Holding, incorporated in Abu Dhabi Global Market (ADGM) (Registration No. 34619)

© 2026 BitLease Technologies Ltd.. All rights reserved.

Data Processing Notice

BitLease Technologies Ltd. A subsidiary of 49G Holding Incorporated in Abu Dhabi Global Market (ADGM) ADGM Registration No.: ​​34619

Last Updated: 21 March 2026

Effective Date: 21 March 2026

Version: 1.0

1. Introduction

1.1 Purpose

This Data Processing Notice (“Notice”) provides a concise, accessible summary of how BitLease Technologies Ltd. (“BitLease,” “we,” “us”) processes your personal data when you access or use the Platform. It is designed to give you a clear understanding of what data we collect, why we collect it, how we use it, who we share it with, and what rights you have, without requiring you to read the full Privacy Policy.

We believe that understanding how your data is handled should not require a legal background. This Notice is written to be read, not filed away.

This Notice supplements but does not replace the Privacy Policy. For comprehensive information about our data processing practices, including detailed legal bases, retention periods, international transfer mechanisms, and security measures, please refer to the full Privacy Policy available on the Platform.

1.2 Data Controller

BitLease Technologies Ltd. is the data controller responsible for your personal data.

Incorporated in: Abu Dhabi Global Market (ADGM), United Arab Emirates Parent company: 49G Holding Data Protection Officer: dpo@bitlease.com

1.3 Platform Context

BitLease is a structured digital asset financing platform operating the Lease-to-Own (LTO) model. BitLease is not a cryptocurrency exchange, broker, lender, or investment service provider. All contracts are denominated in stablecoins. This context determines the scope and nature of data we process. Our data activities relate to structured financing, contract administration, and regulatory compliance, not to trading or exchange operations.

2. Data We Collect

2.1 Overview

We collect only the data necessary for the purposes described in this Notice. The following table summarizes the categories of data, examples of specific data points, and the reason for collection.

CategoryExamplesWhy We Collect It
Identity dataFull legal name, date of birth, nationality, citizenship(s)Account creation, KYC verification, and sanctions screening
Contact dataEmail address, phone number, residential addressAccount management, communications, and proof of address verification
Verification documentsPassport, national ID, driver’s license, proof of address, selfieKYC/KYB identity verification, AML/CTF compliance
Biometric dataFacial geometry (from selfie/liveness check)Identity matching against ID document. Deleted immediately after verification, not retained by BitLease
Financial profile dataSource of funds declaration, employment status, and income informationAffordability assessment, AML source of funds requirements
LTO Contract dataAsset type, Down Payment, installment schedule, contract termsContract execution and administration
Transaction dataPayment history, Buyout records, Full Settlement records, LTO Wallet activityContract management, account statements, and regulatory record-keeping
Staking dataStaking opt-in/out, delegation status, yield recordsLTO Staking Delegation administration
Wallet dataLTO Wallet balances, stablecoin transaction records, and receiving wallet addresses (for ownership transfer)Payment processing, Buyout settlement, ownership transfer
Device and technical dataIP address, device type, browser, operating system, unique device identifiersSecurity, fraud prevention, jurisdictional verification, MFA
Usage dataPages viewed, features accessed, session timestamps, navigation patternsPlatform improvement, performance monitoring
Communications dataSupport tickets, emails, complaint recordsCustomer support, complaint resolution, regulatory record-keeping
Compliance dataSanctions screening results, risk scores, monitoring alerts, PEP statusAML/CFT compliance, sanctions enforcement, regulatory obligations

2.2 Data We Do NOT Collect

We do not collect data from social media profiles or social media activity. We do not purchase data from data brokers or third-party marketing lists. We do not collect health data, genetic data, religious beliefs, political opinions, sexual orientation, or trade union membership. We do not collect biometric data beyond identity verification, and that data is deleted immediately after the verification is complete.

Being clear about what we do not collect is as important as being clear about what we do.

3. Conditional Verification: Risk-Based Approach

3.1 Tiered Access

BitLease applies a risk-based approach to identity verification, consistent with FATF Recommendations and ADGM AML Rules. Access to Platform services is tiered based on verification status:

TierAccess LevelVerification Required
Tier 1, BasicBrowsing, educational content, simulations, calculatorsBasic information: name, email, jurisdiction declaration. Sanctions screening. IP geolocation.
Tier 2, StandardFull Platform access: LTO Contracts, LTO Wallet, Buyout, Full Settlement, stakingFull KYC: government-issued ID, proof of address, selfie/liveness, sanctions/PEP/adverse media screening, source of funds declaration
Tier 3, EnhancedSame as Tier 2, with enhanced monitoringTriggered by risk indicators: Enhanced source of funds/wealth documentation, senior management approval, increased monitoring frequency
Tier 4, InstitutionalLessor access: Investment Contracts, Institutional DashboardFull KYB: corporate documents, beneficial ownership (10%+), authorized signatories, financial statements, AML attestation

3.2 Progressive Data Collection

Data collection is progressive. We collect more data only as needed for the services you choose to access.

At Tier 1, the data we collect is minimal. You can explore the Platform without submitting identification documents. At Tier 2, full verification is required before any financial service (LTO Contract execution, LTO Wallet funding). Tier 3 is triggered by specific risk indicators such as high-value contracts, PEP status, high-risk jurisdiction, unusual transaction patterns, or regulatory requirements. At any time, BitLease may request additional data based on transaction activity, regulatory requirements, or risk triggers identified through ongoing monitoring.

3.3 Why This Matters

This approach has practical consequences for your experience. You are not asked to submit a passport scan just to browse the Platform. Sensitive verification data is collected only when you choose to access financial services. Additional data is requested only when risk factors justify it. The level of data collection is always proportionate to the services accessed and the risk identified.

4. How We Use Your Data

4.1 Processing Purposes and Legal Bases

Every piece of data we process has a defined purpose and a legal basis. The following table maps each purpose to the data activity and the legal ground that permits it.

PurposeDescriptionLegal Basis (GDPR equivalent)
Account managementCreating, maintaining, and administering your accountContract performance
LTO Contract executionProcessing applications, executing contracts, managing installments, facilitating Buyouts and Full SettlementsContract performance
Payment processingProcessing Down Payments, installments, Buyout proceeds, staking rewards, and LTO Wallet operationsContract performance
Ownership transferTransferring Formal On-Chain Ownership upon Full Settlement or final paymentContract performance
Affordability assessmentEvaluating whether the proposed LTO Contract payments are sustainableLegitimate interest (responsible financing)
KYC/KYB verificationVerifying identity, nationality, residence, and beneficial ownershipLegal obligation (AML/CTF law)
AML/CFT monitoringTransaction monitoring, suspicious activity detection, behavioral analysisLegal obligation (AML/CTF law)
Sanctions screeningScreening against OFAC, EU, UN, UK, UAE, and other applicable sanctions listsLegal obligation (sanctions law)
PEP screeningIdentifying Politically Exposed Persons and applying Enhanced Due DiligenceLegal obligation (AML/CTF law)
Tax reportingCRS, FATCA, and jurisdiction-specific tax reportingLegal obligation (tax law)
Fraud preventionDetecting unauthorized access, compromised accounts, bot activity, and jurisdictional circumventionLegitimate interest (security)
Platform securityMonitoring for cyberattacks, intrusion detection, and vulnerability managementLegitimate interest (security)
Customer supportResponding to inquiries, resolving issues, and handling complaintsContract performance / legitimate interest
Platform improvementAnalyzing usage patterns, identifying performance issues, and improving UXLegitimate interest (with consent for analytics cookies)
Legal complianceResponding to regulatory requests, court orders, and legal proceedingsLegal obligation
CommunicationsSending contract-related notifications (payment reminders, status updates, settlement confirmations)Contract performance
MarketingSending promotional communications about new features or servicesConsent only (opt-in required; opt-out available at any time)

4.2 What We Never Use Your Data For

We do not sell your data under any circumstances. We do not share your data with advertisers or ad networks. We do not build marketing profiles from your financial data. We never share Client data with Lessors (this is an absolute firewall enforced at the database architecture level). We do not share data with exchanges or trading platforms, because we are not an exchange and do not participate in trading activity.

5. Who We Share Your Data With

5.1 Categories of Recipients

We share your data only with the parties listed below, only for the purposes specified, and only to the minimum extent necessary.

RecipientPurposeData SharedLegal Basis
FireblocksMPC custody and escrowWallet addresses, asset data, transaction dataContract performance
Identity verification providerKYC/KYB processingID documents, selfie, biometric data (deleted after verification)Legal obligation
AML/CTF screening providerSanctions, PEP, adverse media screeningName, DOB, nationalityLegal obligation
Blockchain analytics providerTransaction monitoring, wallet risk scoringWallet addresses, transaction dataLegal obligation
Payment processorStablecoin payment processingPayment details, amountsContract performance
Cloud infrastructureSecure data hosting and processingAll hosted data (encrypted at rest and in transit)Contract performance
Customer support toolsTicket managementContact info, ticket contentContract performance / legitimate interest
Regulatory authoritiesSupervisory requests, examinations, STR/SAR filings, tax reportingAs required by lawLegal obligation
Law enforcementCourt orders, warrants, criminal investigationsAs required by legal processLegal obligation

5.2 Client-Lessor Data Firewall

This is a fundamental architectural principle, not merely a policy.

Client personal data is never shared with Lessors. Lessor personal data is never shared with Clients. This separation is enforced at the database architecture level, meaning it is built into the infrastructure, not layered on top of it as a rule. Lessors receive only aggregated, anonymized portfolio performance data that cannot be disaggregated to identify individual Clients. No BitLease employee has simultaneous access to both Client-identifying and Lessor-identifying data in connection with the same transaction.

5.3 No Data Sales

BitLease does not sell, rent, lease, or trade personal data to any third party, under any circumstances, for any purpose.

6. International Data Transfers

6.1 Overview

BitLease is incorporated in ADGM (UAE) and may transfer your data to other countries for processing by our service providers. When we transfer data internationally, we ensure appropriate safeguards are in place:

Your LocationTransfer Mechanism
EU/EEAStandard Contractual Clauses (SCCs); Adequacy decisions, and supplementary measures per Schrems II
UKUK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs
ADGMADGM Data Protection Regulations 2021 transfer provisions
SingaporePDPA cross-border transfer provisions (comparable protection standard)
OtherApplicable local mechanisms; explicit consent where no other safeguard is available

6.2 Transfer Impact Assessments

Before transferring data to a new jurisdiction, we conduct a Transfer Impact Assessment. This evaluates the destination country’s legal framework, government access practices, and data subject rights enforceability. Where risks are identified, we implement supplementary technical measures (encryption, pseudonymization) to mitigate them.

7. Data Retention

7.1 Principle

We retain your data only as long as necessary for the purposes it was collected, or as required by law. When retention is no longer justified, data is securely deleted or irreversibly anonymized. We do not keep data “just in case.” Every retention period has a defined reason.

7.2 Key Retention Periods

Data CategoryRetention PeriodReason
Account and identity dataAccount duration + 7 years after closureFinancial services record-keeping
KYC/AML documents7 years after the end of the business relationshipFATF, ADGM AML Rules, EU AMLD, UK MLR
Biometric data (facial geometry)Deleted immediately after verificationData minimized, not retained
LTO Contract and transaction records10 years after contract completion/terminationFinancial record-keeping, tax, statute of limitations
Affordability assessment records7 years after assessmentResponsible financing documentation
Communications and support records5 years after the last interactionCustomer service, dispute resolution
Complaints and resolution records7 years after resolutionRegulatory complaint handling requirements
STR/SAR recordsIndefinite (until authorized by FIU)AML law cannot be deleted without permission
Usage and analytics data24 months (then aggregated/anonymized)Legitimate interest, balanced with privacy
Cookie consent records12 months from consentConsent documentation

8. Your Rights

8.1 Summary of Rights

You have the following rights regarding your personal data. We facilitate these rights promptly and free of charge.

RightDescriptionLimitations
AccessRequest a copy of all personal data we hold about you, and information about how it is processedNone, available to all users
RectificationRequest correction of inaccurate or incomplete dataNone, we correct verified inaccuracies without delay
Erasure (“Right to be Forgotten”)Request deletion of your personal dataCannot delete: KYC/AML records during 7-year retention, transaction records during 10-year retention, STR/SAR records without FIU permission, and data required for active contracts
RestrictionRequest restriction of processing in specific circumstancesAvailable when: contesting accuracy, objecting to processing, processing is unlawful, or data is needed for legal claims
PortabilityReceive your data in a structured, machine-readable format (JSON/CSV)Applies to data you provided, processed by automated means, based on consent or contract
ObjectObject to processing based on legitimate interestsWe cease unless compelling grounds override us. Absolute right to object to direct marketing.
Automated decisionsNot be subject to purely automated decisions with legal/significant effectsWhere automated decisions are used (affordability, risk scoring), human review is available on request
Withdraw consentWithdraw consent for consent-based processing at any timeDoes not affect the lawfulness of prior processing. Withdrawal of marketing consent does not affect platform access.
ComplainLodge complaint with supervisory authorityEU: national DPA. UK: ICO. ADGM: Registration Authority. Singapore: PDPC.

8.2 How to Exercise Your Rights

Contact: privacy@bitlease.com or through Platform settings, Privacy section.

Identity verification: We verify your identity before processing requests to protect against unauthorized access.

Response timeline: Acknowledgment within 5 business days. Substantive response within 30 calendar days (extendable by 60 days for complex requests, with explanation).

Cost: Free, unless requests are manifestly unfounded or excessive.

9. Data Security

9.1 Key Measures

Your data is protected by multiple layers of security, each reinforcing the others:

LayerProtection
EncryptionAES-256 at rest, TLS 1.3 in transit. MPC custody for digital assets (Fireblocks).
Access controlMFA mandatory. Role-based access. Least privilege. Privileged access management.
Monitoring24/7 Security Operations Center. Intrusion detection. Anomaly alerting.
TestingAnnual penetration testing. Continuous vulnerability scanning. SOC 2 Type II program.
OrganizationalEmployee background checks. Mandatory security training. Confidentiality agreements. Segregation of duties.

9.2 Breach Response

If a data breach occurs that poses a risk to your rights, we notify the relevant regulatory authority within 72 hours, notify affected individuals without undue delay where the risk is high, and document all breaches in an internal breach register regardless of risk level.


10. Automated Decision-Making

10.1 Where We Use It

BitLease uses automated processing in several areas. The following table explains where automation is used, how much human oversight exists, and what the impact on you may be.

ProcessAutomation LevelImpactHuman Review Available?
Sanctions screeningFully automated initial screening; human review for potential matchesAccount restriction if match confirmedYes, all potential matches reviewed by a compliance analyst
Transaction monitoringAutomated alert generation; human investigationTransaction holds, enhanced monitoringYes, all alerts investigated by the compliance team
Affordability assessmentPartially automated scoring; human oversightContract approval/denial/modificationYes, on request
Risk scoringAutomated risk rating based on multiple factorsDetermines CDD level (Standard/Enhanced)Yes, on request
IP geolocationAutomated jurisdiction detectionAccess blocking from Restricted JurisdictionsYes, through compliance appeal
Fraud detectionAutomated pattern detection; human investigationAccount restriction pending reviewYes, all flagged accounts reviewed

10.2 Your Right

You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Where such decisions are made, you may request an explanation of the logic involved, request human review of the decision, express your point of view, and contest the decision.

11. Children

The Platform is restricted to individuals aged eighteen (18) or above, or the age of legal majority in their jurisdiction, whichever is greater. We do not knowingly process data from minors. If we discover that data has been collected from a minor, it is deleted promptly and the associated account is terminated.

12. Changes to This Notice

Material changes to this Notice are communicated via email and a prominent Platform notice at least thirty (30) days before the effective date. Where changes affect the legal basis or scope of processing, renewed consent is obtained where required.

Previous versions are available upon request from privacy@bitlease.com.

13. Contact

ContactEmailPurpose
Data Protection Officerdpo@bitlease.comData protection inquiries, rights requests, complaints
Privacy teamprivacy@bitlease.comGeneral privacy questions
Compliancecompliance@bitlease.comAML/CFT data processing inquiries
EU Representativeeu-privacy@bitlease.comEU/EEA data subject inquiries
UK Representativeuk-privacy@bitlease.comUK data subject inquiries
Generalinfo@bitlease.comAll other inquiries

BitLease Technologies Ltd. A subsidiary of 49G Holding Incorporated in Abu Dhabi Global Market (ADGM) Registered Address: Unit PC-1, Level 7, Al Maryah Tower, Abu Dhabi Global Market Square, Abu Dhabi, Al Maryah Island, United Arab Emirates

ADGM Registration No.: 34619

Website: www.bitlease.com