Privacy Policy
Last updated 28 April 2026
If you have questions about this Policy or want to exercise your rights, contact us at hello@cero.finance.
1. Scope
This Policy applies to the Services, including the waitlist sign-up flow, the beta application via cero.finance and our mobile apps. It does not apply to third-party websites, wallets, exchanges, or services you may interact with separately. Please review the privacy policies of those third parties to understand how they handle your data.
2. What we collect
We collect the following categories of personal data:
Identity and contact data
- Name, email address, country of residence, and (where you provide them) social handles such as Telegram or X usernames.
- Information you submit when applying to the waitlist or the beta programme.
Wallet and onchain data
- Public wallet addresses you connect to the Services.
- Public onchain activity associated with those addresses, including transaction history, balances, protocol interactions, and asset holdings.
- This data is publicly available on the relevant blockchains; we collect and process it to compute and present your Cero Score and related insights.
Centralised exchange (CEX) data
- Where you choose to connect a centralised exchange account (for example, via API key or read-only credentials), we collect transaction history and balance information from that account to inform your Cero Score.
- We only access read-only data. We do not request or store withdrawal or trading permissions.
Cero Score outputs
- The score values, score components, and scoring metadata we generate from the data above. These outputs are personal data when associated with you.
Device and usage data
- Device information (operating system, device model, app version, language, time zone).
- Diagnostic data, including TestFlight crash reports and analytics events.
- Approximate location derived from IP address.
- Information about how you interact with the Services (pages and screens viewed, actions taken, referral source).
Communications
- Messages you send to us via email, Telegram, X, in-app chat, or any support channel.
- Responses to surveys, interviews, or research sessions you participate in.
Cookies and similar technologies
- We and our service providers use cookies, SDKs, and similar technologies to operate the Services, remember your preferences, and measure performance. See Section 11 below.
Information from third parties
- We may receive information about you from public sources, blockchain analytics providers, sanctions screening providers, and other partners as needed to comply with legal obligations and to prevent fraud or sanctions evasion.
3. How we use your data and our legal bases
Under UK and EU data protection law we may only use your personal data where we have a lawful basis to do so. We rely on the following bases:
To provide the Services (contract)
- Creating and managing your waitlist or beta account.
- Computing and displaying your Cero Score and related features.
- Sending you service messages, including confirmations, security alerts, and updates.
To improve and develop the Services (legitimate interests)
- Analysing usage to understand how the Services are used and how to improve them.
- Researching and developing new features, including refining the Cero Score model.
- Diagnosing and fixing bugs, performance issues, and security incidents.
To keep the Services secure (legitimate interests / legal obligation)
- Detecting and preventing fraud, abuse, and unauthorised access.
- Screening against sanctions and prohibited-party lists.
- Enforcing our Terms of Use.
To communicate with you about Cero (consent / legitimate interests)
- Sending you product news, beta invitations, or marketing communications, where you have opted in or where we are otherwise permitted under applicable law.
- You can opt out of marketing at any time by clicking “unsubscribe” in any marketing email or by contacting us at hello@cero.finance.
To comply with legal obligations
- Responding to lawful requests from regulators, law enforcement, or courts.
- Meeting record-keeping, tax, audit, and other statutory requirements.
4. Automated decision-making and profiling
The Cero Score is generated through automated processing of the data described in Section 2, including your wallet activity, onchain history, and (where connected) centralised exchange history. We use this score to determine eligibility for the waitlist, the beta, and (in future) for our credit products and the terms on which they may be offered.
This processing constitutes profiling under Article 22 of the UK and EU GDPR. During the pre-launch and beta phases, the Cero Score is informational only and does not produce legal or similarly significant effects on you. Once we begin issuing credit, an automated score may form part of credit eligibility decisions; in that case, we will provide further information at that time and you will have the right to:
- Request meaningful information about the logic, significance, and consequences of the automated processing.
- Obtain human review of any decision that produces a legal or similarly significant effect on you.
- Express your point of view and contest the decision.
If you have questions about how your Cero Score is calculated or want to request human review, contact us at hello@cero.finance.
5. How we share your data
We share personal data only as described below. We do not sell your personal data.
Service providers
We share data with vendors who help us operate the Services, including cloud hosting (e.g., AWS, Google Cloud), analytics, error reporting, email delivery, customer support, blockchain data providers, sanctions screening providers, and identity verification providers. These vendors are bound by contract to use data only as instructed by us and to keep it secure.
Card and credit partners
If and when you become eligible for a Cero card, we will share necessary data with our card issuing partner, payment processors, and (where applicable) credit reference and fraud prevention agencies. We will provide further details in the relevant product terms before any data is shared for that purpose.
Legal and regulatory
We may share data with regulators, law enforcement, courts, or other authorities where we are required to do so by law, or where we reasonably believe disclosure is necessary to comply with a legal obligation, prevent harm, or enforce our Terms.
Corporate transactions
If Cero is involved in a merger, acquisition, financing, sale of assets, or insolvency, your data may be transferred as part of that transaction. We will require any acquirer to honour the commitments in this Policy, and we will notify you where required by law.
With your consent
We may share your data with other parties where you have given us your consent to do so.
Aggregated and anonymised data
We may share aggregated or anonymised data, which cannot reasonably be used to identify you, for analytics, research, or marketing purposes.
6. International transfers
Cero is based in the United Kingdom, but some of our service providers are located outside the UK and the European Economic Area (EEA), including in the United States. When we transfer personal data outside the UK or EEA, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or transfers to countries the UK or EU has determined provide an adequate level of protection.
You can request more information about these safeguards by contacting us at hello@cero.finance.
7. Data retention
We keep your personal data only for as long as we need it for the purposes set out in this Policy, and as required by law. Indicative retention periods:
- Waitlist applications: until you are admitted to the beta, or for up to 24 months from your last interaction, whichever is earlier.
- Beta accounts: for the duration of your participation in the beta and up to 24 months thereafter, unless we are required to keep it longer for legal or regulatory reasons.
- Wallet, onchain, and CEX-derived data: for the duration of your account and up to 24 months thereafter, except where retained in aggregated or anonymised form.
- Communications and support records: up to 5 years from the date of the communication.
- Records required for legal, tax, audit, or regulatory purposes: for the period required by applicable law (typically 5 to 7 years).
When we no longer need your personal data, we will delete or anonymise it.
8. Security
We use administrative, technical, and physical safeguards designed to protect your personal data against unauthorised access, alteration, disclosure, or destruction. We require our service providers to maintain appropriate safeguards as well.
No system is completely secure. You are responsible for keeping your account credentials, wallets, and private keys secure. If you believe your account has been compromised, contact us immediately at hello@cero.finance.
9. Age limitations
The Services are not intended for anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a person under 18 without appropriate consent, we will delete it. If you believe we may have collected data from a person under 18, contact us at hello@cero.finance.
10. Your rights
Under UK and EU GDPR you have the following rights in relation to your personal data:
- Access — to obtain a copy of the personal data we hold about you and information about how we use it.
- Rectification — to ask us to correct inaccurate or incomplete data.
- Erasure — to ask us to delete your data in certain circumstances (sometimes called the “right to be forgotten”).
- Restriction — to ask us to limit how we use your data in certain circumstances.
- Portability — to receive your data in a structured, commonly used, machine-readable format and to ask us to transmit it to another controller, where technically feasible.
- Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Withdraw consent — where we rely on your consent, to withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
- Automated decisions — to request human review of decisions made solely by automated means that produce legal or similarly significant effects on you (see Section 4).
To exercise any of these rights, contact us at hello@cero.finance. We will respond within one month, unless the request is complex, in which case we may extend this by up to two further months. We will tell you if we need more time.
If you are not satisfied with how we have handled your data, you have the right to complain to a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
If you are in the EU, you may also complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement took place.
11. Cookies and similar technologies
We and our service providers use cookies, SDKs, and similar technologies on cero.finance and in our apps to operate the Services, remember your preferences, measure performance, and improve the user experience.
You can control cookies through your browser settings, or through any cookie banner we display on cero.finance. Some parts of the Services may not function properly if you disable cookies.
12. Changes to this Policy
We may update this Policy from time to time. When we do, we will update the “Last updated” date at the top of the Policy. If we make material changes, we will provide additional notice, for example by email or through the Services.
13. Contact us
Questions, requests, or complaints about this Policy or about how we handle your personal data can be sent to:
Cero Labs Email: hello@cero.finance
