Privacy Policy
How we collect, use, and protect your personal information across our websites, platforms, and products.
Last updated August 2026
Introduction
ARN Fintech (“ARN Fintech,” “we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, mobile applications, and other digital platforms (collectively, the “Services”). By using our Services, you agree to the terms of this Privacy Policy. If you do not agree with this policy, please do not use our Services.
Information we collect
We may collect the following types of information when you use our Services:
- Personal information — name, email address, phone number, date of birth, address, government-issued identification, and other similar information.
- Financial information — bank account details, credit card information, transaction history, and other financial data.
- Technical information — IP address, device information, browser type, operating system, location data, and other technical details.
- Usage information — page views, clickstream data, session duration, and other usage statistics.
How we use your information
We may use the information we collect for the following purposes:
- To provide, operate, and maintain our Services.
- To process transactions and verify your identity.
- To communicate with you, including responding to inquiries and providing customer support.
- To comply with legal and regulatory obligations.
- To improve our Services, develop new features, and conduct research.
- To send you promotional materials and updates, with your consent.
Data security
We implement layered technical and organizational measures to protect your personal information from unauthorized access, use, or disclosure. No method of transmission over the internet or electronic storage is 100% secure, but the following controls are in place across Oracle, Aegis, and Bifrost:
Need a security questionnaire, pen-test summary, or DPA for procurement? Email [email protected] and we will send the current documentation pack.
Encryption in transit & at rest
TLS 1.2+ for all traffic; data at rest encrypted with AES-256, with keys managed separately from application infrastructure.
Multi-factor authentication
2FA enforced for admin, partner, and client-facing logins, with automatic step-up verification on suspicious sign-ins.
Isolated infrastructure
The Risk Management System runs in its own isolated environment, separate from CRM and partner workloads, so incidents in one system never touch execution.
Data centers & backups
Production data is hosted in SOC 2-audited data centers with redundant power and network paths, plus continuous encrypted backups with point-in-time recovery.
Monitoring & audit logging
Every login, configuration change, and payout action is logged, with maker-checker controls on sensitive operations.
Role-based access control
Access follows least-privilege by default, scoped by role and restrictable further per team, desk, or device.
Vulnerability management
Dependencies and infrastructure are patched on a regular cadence, with periodic penetration testing and tracked remediation.
Incident response
A documented process covers detection, containment, and client notification, with defined response-time targets.
Data retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. After this period, your data is deleted or anonymized.
Your rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request access to the personal information we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your personal information under certain conditions.
- Objection — object to the processing of your personal information for specific purposes.
- Data portability — request a copy of your data in a structured, machine-readable format.
To exercise these rights, contact us at [email protected].
International data transfers
Your information may be transferred to and processed in countries outside your jurisdiction, including countries that may not have the same data protection laws as your country. We take steps to ensure your data is treated securely and in accordance with this Privacy Policy.
Children’s privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a minor, we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website or through other communication methods. Continued use of our Services after changes take effect constitutes acceptance of the revised policy.
Contact us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
- Email — [email protected]
- Phone — +90 538 262 00 91
- Address — Levazım District, Vadi Avenue Zorlu Center No: 2 Office: 353, Beşiktaş / İstanbul, Türkiye