AG-LEGAL-002 — Alta Group Privacy Policy
1. Overview
This Privacy Policy explains how Alta Group N.V. and its subsidiaries collect, use, store, share, and protect information when users access Alta websites, applications, Discord bots, financial services, marketplace services, and related products.
By using Alta services, the user agrees that Alta may collect and use information as described in this Policy.
2. Alta Services Covered
This Policy applies to services operated by Alta Group and its subsidiaries, including:
- Alta Group;
- Alta Bank;
- Alta Terminal;
- Alta websites;
- Alta Discord bots;
- Alta support systems;
- and any future Alta product or subsidiary.
A specific Alta subsidiary may also publish additional privacy terms for its own services.
3. Information We Collect
Alta may collect information that users provide directly, information generated through use of Alta services, and information received from connected platforms.
This may include:
- Discord user ID;
- Discord username;
- Minecraft username;
- Minecraft UUID, if used;
- a Minecraft verification challenge's world and assigned X/Z block;
- verification status and challenge, check, expiration, and completion timestamps;
- account profile information;
- email address, if provided;
- company or business information;
- account applications;
- verification information;
- support messages;
- forms and uploaded documents;
- transaction records;
- payment records;
- transfer records;
- trading or market activity;
- brokerage applications and order activity;
- Terminal portfolios, holdings, cash-ledger entries, orders, fills, and Bank-to-Terminal funding records;
- legal document identifiers, versions, content hashes, consent scopes, acceptance types, timestamps, and superseded consent history;
- company identity and representative authority when a user accepts terms for a company;
- company memberships, Owner/Member status, primary-owner designation, invitations, removals, company-setting changes, and actions taken in a company context;
- audit logs;
- staff action logs;
- device, browser, or technical information;
- IP address, if collected by hosting or security systems;
- cookies or similar website data, if used.
Alta does not require users to provide more information than is reasonably needed to operate the relevant service.
Minecraft verification
During Minecraft verification, Alta assigns an X/Z block within a fixed verification area and checks the DistrictRP BlueMap live-player feed after the user asks Alta to confirm. Alta compares the claimed Minecraft username and the whole-block X/Z position reported by that feed. Alta does not use the player's Y coordinate for verification and does not intentionally store the Y coordinate, rotation, movement history, or other players returned by the feed.
Alta stores the claimed Minecraft username, verified Minecraft UUID, assigned world and X/Z block, challenge status, and relevant timestamps. Other players may appear transiently in the provider response while the server performs a check, but Alta's verification service is designed not to return or persist that player list. A new challenge does not by itself erase a UUID previously associated with an account, because retaining that association helps prevent account hijacking and duplicate identity claims.
4. How We Use Information
Alta may use information to:
- create and manage accounts;
- verify users, businesses, merchants, customers, or institutions;
- operate banking, payment, brokerage, trading-interface, clearing, and settlement services;
- process transfers, payments, invoices, orders, applications, and support requests;
- maintain transaction and account records;
- verify that a claimed Minecraft identity controls the online player at an assigned block;
- record, prove, and manage platform-wide and product-specific legal acceptance;
- prevent fraud, abuse, bugs, exploits, and unauthorized access;
- enforce rules, agreements, and policies;
- provide customer support;
- send service notifications;
- send Discord bot notifications;
- review disputes;
- investigate suspicious activity;
- administer full-access company memberships, primary-owner protection, invitations, removals, and related security reviews;
- improve Alta products;
- maintain security and platform integrity;
- comply with applicable rules, agreements, or legal obligations;
- protect Alta Group, subsidiaries, users, merchants, customers, institutions, and the platform.
5. Discord and Third-Party Platform Data
Alta services may connect with Discord, Minecraft servers, hosting providers, databases, authentication providers, and other third-party platforms.
When a user connects a Discord account or interacts with an Alta bot, Alta may collect and process Discord-related information such as Discord ID, username, server roles, messages sent to Alta systems, interaction history, and bot command usage.
Alta is not responsible for the privacy practices of Discord, Minecraft, hosting providers, or other third-party platforms.
Users should review the privacy policies of those platforms separately.
6. Financial and Transaction Records
Alta may maintain records of financial-style activity within the Alta ecosystem.
These records may include:
- account balances;
- deposits;
- withdrawals;
- transfers;
- invoices;
- payment links;
- merchant payments;
- lending activity;
- card activity;
- trading activity;
- holdings;
- settlement records;
- routing records;
- fees;
- reversals;
- disputes;
- restrictions;
- account actions.
These records may be kept to operate services, resolve disputes, prevent abuse, maintain audit trails, and protect the integrity of the platform.
Alta Terminal may maintain customer-level portfolio, cash, order, fill, and funding records even when an external execution provider uses a pooled or omnibus Alta account. Alta uses those internal records to allocate provider activity and reconcile each customer's virtual positions and cash.
Unless a specific service states otherwise, Alta services are intended for Minecraft, Discord, roleplay, simulated, or virtual economy environments and do not represent real-world bank accounts or real-world securities accounts.
7. How We Share Information
Alta may share information within the Alta ecosystem, including between Alta Group and its subsidiaries, when needed to operate services.
Alta may share information with:
- Alta Group;
- Alta subsidiaries;
- staff, officers, directors, agents, and contractors;
- service providers;
- hosting providers;
- database providers;
- authentication providers;
- Discord bots or integrations;
- participating institutions, when needed for payment operations;
- merchants, when needed for payments or invoices;
- brokerage, execution, custody, or market-data providers when needed for Alta Terminal services;
- Minecraft server or live-map providers when needed to verify a claimed Minecraft identity;
- law enforcement, legal authorities, or platform administrators if required or reasonably necessary;
- other parties when the user gives permission.
Alta does not sell user personal information to advertisers.
8. Public and Semi-Public Information
Some information may be visible to other users depending on the service.
Examples may include:
- usernames;
- company names;
- public company profiles;
- company disclosures;
- market-data and security profiles;
- public trading or market data;
- leaderboard-style information;
- Discord announcements;
- public support or application information, if submitted in a public channel;
- information users intentionally publish through Alta services.
Users should not submit private information into public or semi-public areas.
9. Data Storage and Security
Alta uses reasonable technical and organizational measures to protect information.
These may include:
- access controls;
- authentication;
- database permissions;
- audit logs;
- staff permission controls;
- private Discord channels;
- secure hosting;
- environment variables;
- limited staff access;
- internal review procedures.
No system is perfectly secure. Alta cannot guarantee that unauthorized access, data loss, downtime, bugs, or security incidents will never occur.
Users are responsible for protecting their own accounts, passwords, Discord accounts, Minecraft accounts, devices, and login sessions.
10. Data Retention
Alta may retain information for as long as needed to operate services, maintain records, resolve disputes, enforce agreements, prevent abuse, comply with obligations, and protect platform integrity.
Alta may retain certain records even after an account is closed, including:
- transaction records;
- audit logs;
- fraud or abuse records;
- support records;
- legal records;
- financial records;
- dispute records;
- banned or restricted user records.
Verification and consent evidence may also be retained after access ends when reasonably needed to prevent duplicate identity claims, prove which document version was accepted, preserve append-only audit history, resolve disputes, or protect platform integrity.
Alta may delete or anonymize information when it is no longer needed.
11. User Choices
Users may stop using Alta services at any time.
Depending on the service, users may request:
- account review;
- correction of inaccurate information;
- deletion of certain account information;
- restriction of certain notifications;
- explanation of certain records;
- export or copy of certain information, if reasonably available.
Alta may deny or limit requests when information must be retained for security, dispute resolution, financial records, fraud prevention, legal reasons, or platform integrity.
12. Cookies and Website Data
Alta websites may use cookies, local storage, sessions, or similar technologies to:
- keep users logged in;
- remember preferences;
- improve website function;
- protect security;
- understand basic usage;
- support authentication.
Users may control cookies through their browser settings, but disabling cookies may break some Alta services.
13. Children and Minors
Alta services may be used in Minecraft, Discord, and roleplay communities where users may be minors. A user must satisfy Discord's and other connected platforms' minimum-age rules. Alta does not intend its services for a child who is below the minimum age permitted for the connected account or who cannot provide any legally required guardian authorization.
Users should not submit sensitive personal information unless it is required for the service.
Parents or guardians may contact Alta through official support channels regarding privacy concerns involving a minor.
Alta may restrict, remove, or delete information if it determines that retaining it creates unnecessary risk. Parents or guardians should not send government identifiers or other sensitive information through public Discord channels.
14. Service Notifications
Alta may send service-related notifications through Discord, email, website alerts, dashboards, or other channels.
These may include:
- account alerts;
- security alerts;
- payment notifications;
- transfer notifications;
- merchant notifications;
- support messages;
- dispute updates;
- brokerage and order-status updates;
- trading or market notices;
- outage notices;
- policy updates.
Some notifications may be required for security, account, payment, or service operation and may not be fully disabled.
15. Staff Access
Alta staff, directors, officers, contractors, agents, or support personnel may access user information only as reasonably needed to operate, support, secure, review, investigate, or enforce Alta services.
Alta may log staff actions for security, audit, and accountability purposes.
16. Data Accuracy
Users are responsible for keeping account, company, merchant, customer, institution, and contact information accurate.
Alta is not responsible for problems caused by inaccurate, outdated, false, or incomplete information provided by users.
17. International and Third-Party Hosting
Alta may use hosting, database, storage, analytics, authentication, or communication providers that store or process information in different locations.
By using Alta services, users understand that information may be processed by third-party service providers as needed to operate the platform.
18. Security Incidents
If Alta becomes aware of a security incident affecting user information, Alta may investigate and take reasonable action.
Alta may notify affected users if it believes notice is appropriate, required, or useful to protect accounts or platform integrity.
Alta may also reset credentials, restrict access, freeze activity, or take emergency measures when needed.
19. Changes to This Policy
Alta may update this Privacy Policy at any time.
Updated versions become effective when posted, published, or otherwise made available.
Alta will make updated versions available through an official channel. Material changes may require renewed affirmative acknowledgment or consent before further use of an affected product. Otherwise, continued use after the stated effective date means the user accepts the updated Policy.
20. Contact
Questions, requests, or concerns about privacy may be sent through official Alta support channels.
21. Approval
This Privacy Policy is adopted by Alta Group N.V. as the platform-wide privacy policy for Alta services.