BDRelay
  • How it works
  • Pricing
  • Corridor
  • Security
  • FAQ
Talk to usSign up
Corridor · Legal

Corridor Privacy Policy

Last updated: August 31, 2026

Template notice. This document is a starting template and not legal advice. It should be reviewed by a qualified solicitor or data-protection adviser, and the list of sub-processors in section 5 confirmed against what is actually deployed, before it is relied upon. Tech Infrastructure and Technical Services Limited’s company number, registered address and ICO registration number should be added once available.

Contents

  1. Who we are
  2. What we collect
  3. What we deliberately do not collect
  4. Why we use it, and our lawful bases
  5. Who we share it with
  6. Public blockchain data
  7. International transfers
  8. How long we keep it
  9. Your rights
  10. Security
  11. Changes to this policy
  12. Contact and complaints

1. Who we are

Corridor is a feature of BDRelay, a product of Tech Infrastructure and Technical Services Limited, a company registered in England and Wales. For the personal data described in this policy, that company is the data controller.

This policy covers Corridor specifically. BDRelay’s payment-integration service has its own Privacy Policy.

2. What we collect

  • Identity and contact details. Your name and email address, provided when you accept an invitation.
  • Your wallet address. The public address of the wallet created on your device. This is a public identifier, not a secret.
  • Transaction records. Amounts, dates, status, the payment partner used, the partner’s order reference, destination addresses you enter, and the resulting blockchain transaction identifiers.
  • Screening results. The outcome of checks against published sanctions lists.
  • Technical data. IP address, browser and device information, and log data generated when you use Corridor.
  • Correspondence. Messages you send us and our replies.

3. What we deliberately do not collect

Some of the most sensitive data in a service like this never reaches us at all, by design:

  • Your private key. It is generated on your device and is never transmitted to us. We hold no key material and could not reconstruct it.
  • Your card or bank details. These are entered on the payment partner’s own surface. They do not pass through Corridor.
  • Your identity documents. Identity verification is carried out by the payment partner under its own programme. We receive the outcome, not the documents.

4. Why we use it, and our lawful bases

  • To provide Corridor — creating your account, showing your balance and history, and processing your instructions. Lawful basis: performance of a contract.
  • To keep the service safe and accurate — reconciling transactions against the blockchain, investigating mismatches, preventing fraud and abuse, and enforcing our limits. Lawful basis: legitimate interests.
  • To meet legal obligations — sanctions screening, record keeping, and responding to lawful requests. Lawful basis: legal obligation.
  • To communicate with you — transactional notifications about your own activity, and answering your questions. Lawful basis: performance of a contract and legitimate interests.

We do not sell your personal data, and we do not use it for advertising or profiling.

5. Who we share it with

We share the minimum necessary with service providers who process data on our behalf or, where indicated, as controllers in their own right:

  • Embedded-wallet provider — to create and secure the wallet on your device.
  • Payment partners (for example MoonPay) — who take your payment and carry out identity verification. They act as independent controllers for the data you give them directly, under their own privacy policies.
  • Hosting and database providers — who store the data described above.
  • Email delivery provider — to send you notifications about your activity.
  • Professional advisers, regulators and law enforcement — where we are legally required to disclose, or to establish or defend legal claims.

6. Public blockchain data

Corridor operates on a public blockchain. Transactions you make, including your wallet address, the amounts and the destination addresses, are recorded on that public ledger.

This has a consequence you should understand: we cannot delete, alter or restrict that record. It is public, permanent, visible to anyone, and outside our control. It is not held by us and no request to us can remove it. This limits some of the rights described in section 9 in respect of on-chain data specifically.

7. International transfers

Some of our service providers are located outside the United Kingdom. Where personal data is transferred internationally, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement or Addendum, as applicable.

8. How long we keep it

We keep transaction and screening records for as long as required by applicable anti-money-laundering and financial record-keeping law, which is typically at least five years from the end of our relationship with you. Account and contact details are kept for the life of your account and then for the same retention period. Technical logs are kept for a shorter period, ordinarily no more than twelve months.

9. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased, where we have no continuing legal basis to keep it;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent, where we relied on consent.

Two honest limits apply. We must retain certain records to meet anti-money-laundering obligations even if you ask us to erase them, and as explained in section 6 we cannot remove anything recorded on a public blockchain.

To exercise any right, email corridor@bdrelay.com. We will respond within the time limits set by law, ordinarily one month.

10. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and audit logging.

The most significant security property of Corridor is structural rather than procedural: because we never hold your private key, a compromise of our systems could not be used to move your funds. There is no key material to steal. Correspondingly, the security of your key and your sign-in method is your responsibility, as set out in the Corridor Terms of Service.

11. Changes to this policy

We may update this policy. Where a change materially affects how we use your data, we will tell you. The “last updated” date at the top of this page shows when it was last revised.

12. Contact and complaints

For any privacy question, email corridor@bdrelay.com.

If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

← Back to home

BDRelay

Payment integration made simple for non-technical businesses. Checkout and payouts powered by Stripe.

Product

  • How it works
  • Pricing
  • Security
  • Corridor

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Acceptable Use
  • Corridor Terms
  • Corridor Privacy
© 2026 Tech Infrastructure and Technical Services Limited. All rights reserved.