CORISE CONSULTING CO., LTD. (the “Company”) handles personal information and other information collected in connection with the sales platform it operates at rwa.corise.cc (the “Platform”) in accordance with this Privacy Policy (the “Policy”).
Personal information processed in connection with the MSX Account and wallet, card-payment, transfer, global-transfer, RWA-trading and other services offered through the MSX platform is governed by the privacy policies and other rules established by Mystonks Holding LTD., the Card Issuer, the Card Programme Operator or their designated service provider.
Article 1 (Information We Collect)
The Company may collect the following information in connection with operation of the Platform and sale of the Card:
Information submitted or provided by the Customer: name, email address, telephone number, country, delivery address, and other information provided when applying or making an enquiry.
Order and contract information: Card tier, Card issuance month, expiry date, standard price, discount amount, final purchase price, order date and time, order number, order status, delivery status, referral code and other information relating to the order.
Payment-related information: transaction ID (TXID), originating wallet address, amount sent, blockchain network, payment-confirmation status and other information required to confirm payment, including publicly available blockchain information.
Consent and acknowledgement information: whether and when the Customer accepted or acknowledged the Terms, this Policy, the Card issuance month, expiry date, remaining validity period and discount terms, together with the version of the applicable terms or pricing rule.
Support and communications information: enquiries, Company responses, complaints, cancellation or refund requests, and other support history.
Technical information: IP address, access date and time, access logs, browser, device, operating system, language setting, cookies, local storage, referring URL and other information automatically transmitted through use of the Platform.
The Company does not hold or safeguard the Customer’s fiat currency or digital assets. As a general rule, it does not collect identity documents, facial images or other documents used for identity verification. Where identity verification is required for global transfers or another particular service, it is conducted by the Card Issuer, Card Programme Operator or its designated service provider.
Article 2 (Purposes of Use)
The Company uses collected information for the following purposes:
To accept Card orders, confirm eligibility and order details, and form and perform the sale contract.
To calculate and display the selling price or discount based on the Card tier, issuance month, expiry date and remaining validity period.
To confirm payment to the Designated Payment Address, match payment to an order, and handle overpayments, underpayments, cancellations and refunds.
To prepare, provide, arrange issuance and delivery of, track and reship the Card.
To provide guidance and support required to link an MSX Account to an order.
To record and evidence acceptance or acknowledgement of the Terms, this Policy, expiry information, discount terms and other material matters.
To associate referral codes or referrer information, confirm referral activity and administer the referral programme.
To respond to enquiries, complaints, disputes, misuse and security incidents.
To prevent money laundering, fraud and suspicious transactions, comply with sanctions, and comply with applicable law and internal rules.
To maintain the Platform, respond to failures, improve security, analyse usage and improve services.
To make communications and perform administration incidental to the foregoing purposes.
Article 3 (Disclosure to Third Parties and Service Providers)
1. The Company does not disclose personal data to a third party except with the Customer’s consent or where permitted or required by applicable law.
2. To the extent necessary to sell and provide the Card, the Company may disclose Customer information to:
Partner Service Providers, the Card Issuer and Card Programme Operator: to process orders; prepare, provide and arrange issuance of the Card; link accounts; deliver the Card; process refunds; and provide support.
Payment-related providers: to confirm and reconcile payments and handle overpayments, underpayments and refunds.
Delivery carriers and customs-related providers: to dispatch, clear, deliver, track and reship the Card and investigate delivery incidents.
Government, regulatory, judicial and other public authorities legally entitled to receive the information.
3. The Company may engage external providers for cloud infrastructure, databases, website hosting, email delivery, customer support, security and other operations. The Company will select, contract with and supervise such providers as required by applicable law.
4. If the Company jointly uses personal data, it will first publish the categories of jointly used information, the scope of joint users, the purposes of use and the party responsible for management on the Platform.
Article 4 (External Services and Public Information)
The Company may use external services for cloud infrastructure, databases, hosting, email delivery, analytics, security and customer support. It may also refer to publicly available blockchain information to confirm payments and reconcile transactions. Each provider handles information under its privacy policy and its agreement with the Company.
Article 5 (Cookies and Local Storage)
1. The Platform may use cookies and local storage for language settings, referral codes, input status, security, usage measurement and other necessary functionality.
2. The Customer may delete or restrict cookies and local storage through browser settings. Doing so may prevent use of some Platform functions.
3. If the Company uses analytics, advertising or similar technology, it will provide appropriate information on the service used, information collected and available opt-out method.
Article 6 (Security and Data-Incident Response)
1. The Company implements necessary and appropriate safeguards, having regard to the nature and risks of the information handled, including encryption in transit, access controls, permission management and service-provider oversight, to prevent unauthorised access, leakage, loss, destruction, alteration or damage.
2. If a personal-data incident occurs, the Company will verify the facts, determine the affected scope, limit further harm and take measures to prevent recurrence. It will report to the relevant authority and notify affected Customers where required by applicable law.
Article 7 (Retention)
The Company retains information for the period necessary to fulfil the purposes of use, perform and evidence sale contracts, payments, tax and accounting obligations, and respond to complaints or disputes, and for any period required by applicable law. When retention is no longer required, the Company will securely delete or anonymise the information, unless continued retention is legally required or necessary to protect the Company’s legitimate rights and interests.
Article 8 (Processing Outside the Customer’s Country)
1. The Company is located in the Kingdom of Cambodia. Partner Service Providers, the Card Issuer, Card Programme Operator and service providers may be located outside the Customer’s country of residence. Customer information may therefore be stored or processed in Cambodia or another country or region in which a relevant provider or system is located.
2. Where the Company transfers personal data to a third party outside the relevant jurisdiction, it will obtain any required consent, provide required information, implement contractual safeguards or take other measures required by applicable law. The Customer may request information about overseas recipients where the Customer has that right under applicable law.
Article 9 (Customer Rights and Request Procedure)
1. Subject to applicable law, the Customer may request notification of purposes of use, access to personal information or third-party disclosure records, correction, addition, deletion, suspension of use, erasure or cessation of third-party disclosure.
2. A Customer wishing to make a request should contact the address in Article 12. The Company may request an order number, registered information or the minimum documentation necessary to verify that the requester is the Customer or an authorised representative.
3. Where the Company cannot comply with a request under applicable law, it will notify the requester and, where practicable, explain the reason. If a fee is payable, the Company will provide advance notice of the amount and payment method.
Article 10 (Minors and Optional Provision of Information)
1. The Platform is intended for persons who are at least 18 years old or have reached the legal age of majority in their place of residence.
2. Providing information is voluntary. If information required for ordering, delivery or another necessary procedure is not provided, the Company may be unable to sell or deliver the Card, process a refund, provide support or take other requested action.
Article 11 (Changes to This Policy)
1. The Company may amend this Policy where reasonably necessary due to changes in law, business activities, partnerships, information-handling practices or other circumstances.
2. The amended Policy will be notified by posting it on the Platform or by another appropriate method and applies from the effective date shown with the notice. For a material change, the Company will provide advance notice, obtain required consent or take another appropriate measure, depending on the nature of the change.
Article 12 (Controller Information, Contact and Governing Law)
Entity: CORISE CONSULTING CO., LTD. Representative: SONE KOJI, Chairman Address: #C7 The Fortune Tower, 17F 1702-404, Veal Vong, 7 Makara, Phnom Penh, Kingdom of Cambodia Contact: support@rwa.corise.cc This Policy is governed by and construed in accordance with the laws of the Kingdom of Cambodia. Where mandatory law in the Customer’s country of residence or otherwise applicable to provision of the Platform requires different treatment, that mandatory law applies.
CORISE CONSULTING CO., LTD. | Privacy Policy
