Last updated: August 31, 2026
Corridor is a feature of BDRelay, a product of Tech Infrastructure and Technical Services Limited, a company registered in England and Wales. For the personal data described in this policy, that company is the data controller.
This policy covers Corridor specifically. BDRelay’s payment-integration service has its own Privacy Policy.
Some of the most sensitive data in a service like this never reaches us at all, by design:
We do not sell your personal data, and we do not use it for advertising or profiling.
We share the minimum necessary with service providers who process data on our behalf or, where indicated, as controllers in their own right:
Corridor operates on a public blockchain. Transactions you make, including your wallet address, the amounts and the destination addresses, are recorded on that public ledger.
This has a consequence you should understand: we cannot delete, alter or restrict that record. It is public, permanent, visible to anyone, and outside our control. It is not held by us and no request to us can remove it. This limits some of the rights described in section 9 in respect of on-chain data specifically.
Some of our service providers are located outside the United Kingdom. Where personal data is transferred internationally, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement or Addendum, as applicable.
We keep transaction and screening records for as long as required by applicable anti-money-laundering and financial record-keeping law, which is typically at least five years from the end of our relationship with you. Account and contact details are kept for the life of your account and then for the same retention period. Technical logs are kept for a shorter period, ordinarily no more than twelve months.
Under UK data protection law you have the right to:
Two honest limits apply. We must retain certain records to meet anti-money-laundering obligations even if you ask us to erase them, and as explained in section 6 we cannot remove anything recorded on a public blockchain.
To exercise any right, email corridor@bdrelay.com. We will respond within the time limits set by law, ordinarily one month.
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and audit logging.
The most significant security property of Corridor is structural rather than procedural: because we never hold your private key, a compromise of our systems could not be used to move your funds. There is no key material to steal. Correspondingly, the security of your key and your sign-in method is your responsibility, as set out in the Corridor Terms of Service.
We may update this policy. Where a change materially affects how we use your data, we will tell you. The “last updated” date at the top of this page shows when it was last revised.
For any privacy question, email corridor@bdrelay.com.
If you are unhappy with how we have handled your personal data, you can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.