1.1 Overall Privacy

Moneybees Forex Corporation (hereinafter “we”, “us”, “our” or “Moneybees”) is committed to respecting and protecting your data privacy rights as a data subject in accordance with Republic Act No. 10173, otherwise known as the “Data Privacy Act of 2012” (the “DPA”), its Implementing Rules and Regulations (“IRR”), the issuances of the National Privacy Commission (“NPC”), and other applicable laws of the Republic of the Philippines.

Moneybees is a virtual asset service provider (“VASP”) registered with the Bangko Sentral ng Pilipinas (“BSP”) that facilitates over-the-counter and online trading desk purchases and sales of virtual assets on a non-custodial basis. For purposes of the DPA, Moneybees acts as a personal information controller with respect to the personal data described in this Policy.

The information you provide when you use the services provided by Moneybees (the “Service” or “Services”) will be collected and used in the manner stated in this Policy.

We process your personal data only when there is a lawful basis to do so under the DPA. Depending on the purpose, that basis may be: (a) compliance with a legal or regulatory obligation, such as our know-your-customer (“KYC”), customer due diligence (“CDD”), transaction monitoring, reporting, and record-keeping obligations under Republic Act No. 9160 (the Anti-Money Laundering Act, as amended, “AMLA”), BSP regulations, and Anti-Money Laundering Council (“AMLC”) issuances; (b) the performance of our contract with you, i.e., delivering the Services you request; (c) our legitimate interests, such as securing our systems, preventing fraud, and improving the Services, where such interests are not overridden by your fundamental rights and freedoms; or (d) your consent, which we rely on only for processing that is genuinely optional — such as direct marketing — and which you may give or withhold freely and withdraw at any time without affecting your access to the Services. Where processing is required by law or regulation, we do not rely on consent, and your consent is not a condition for it.

1.2 What Information We Collect

As mandated by the BSP and the AMLC, in the usual course of our business as a BSP-registered VASP and for purposes of KYC, identity verification, CDD, and transactions monitoring, we collect the following personal information from you and about you, including, but not limited to:

1.2.1. Client Information (Information belonging to our Clients)

i. Name;

ii. Date and place of birth;

iii. Citizenship or nationality;

iv. Complete Address;

v. Mobile Number;

vi. Landline Number;

vii. Email Address;

viii. Virtual Asset Wallet Address;

ix. Specimen signature or biometrics of the Client, including facial images and liveness-check recordings captured during onboarding or verification;

x. For Corporate Account, Information regarding your business entity such as, but not limited to: (a) Certificate of Incorporation; (b) Latest Articles of Incorporation; (c) Latest By-Laws; (d) General Information Sheet; (e) Audited Financial Statement; (f) Secretary’s Certificate; (g) Business Permit; (h) BIR Registration;

xi. Any other information that may be requested to better establish the identity of the Client;

xii. Any other information relevant to the efficient use of our Service;

xiii. Any other information required by existing laws and regulations.

1.2.2. Transactional Information

i. Amount bought, sold, paid, or transferred, together with transaction details such as date, time, location or channel, Virtual Asset type, Exchange Rate applied, and wallet addresses involved;

ii. Any other information that may be requested to better establish the authenticity of the transaction/s involved;

1.2.3. IP addresses, device and browser information, and online identifiers collected through cookies and similar technologies as described in Section 1.6-B (Cookies and Online Tracking);

1.2.4. Any personal information that may be disclosed when you interact with us, including through our chat channels, e-mail, social media pages, and customer support.

1.2.5 Sensitive Personal Information. Some of the data we collect — such as government-issued identification details, biometric data (including facial images and liveness recordings), and, where applicable, information about legal proceedings — constitutes sensitive personal information under the DPA. We process sensitive personal information only where permitted by Section 13 of the DPA, principally because such processing is required by the AMLA, BSP regulations, and other applicable laws, and we apply heightened organizational, physical, and technical security measures to such data.

1.3 Maintenance of Accuracy

To maintain accuracy of personal information, you may access the Services at any time and change any inaccuracies you may find by requesting to update your profile with us. You may also request the deletion or blocking of your personal data as described in Section 1.7 (Data Subject Rights); however, deletion is subject to the mandatory retention periods described in this Section and in Section 1.5 (Data Retention and Disposal), and personal data that we are legally required to retain cannot be deleted until the applicable retention period has lapsed. Upon such change or request from a Client, we shall notify third parties who have previously received or processed such information.

Pursuant to anti-money laundering (“AML”) regulations, if the records relate to ongoing investigations or transactions that have been the subject of a money laundering case, they shall be retained beyond the stipulated retention period until it is confirmed that the case has been closed and terminated.

Pursuant to Bureau of Internal Revenue Revenue Regulations No. 17-2013, documents pertaining to your billing statements, which indicate taxable transactions shall be preserved for ten (10) years. Further, we will keep your personal information as long as it is necessary: a) for the fulfillment of the declared, specified, and legitimate purposes provided above, or when the processing relevant to the purposes has been terminated; b) for the establishment, exercise or defense of legal claims; or c) for legitimate business purposes consistent with these purposes and applicable law.

1.4 How We Use Your Personal Information

Information you provide us may be collected and processed internally, or by authorized third parties acting under contract with us as personal information processors. Each processing purpose below rests on the lawful basis identified in Section 1.1. Where personal data is transferred or stored outside the Philippines, the safeguards described in Section 1.6-A (Cross-Border Transfers) apply. We assure you that our actions concerning your personal information will be guided by this Privacy Policy.

1.4.1. Delivery of Services — to onboard you as a Client, verify your identity, process your Transactions, issue receipts and records, and provide customer support (lawful bases: performance of contract; legal obligation).

1.4.2. Communications

i. To send communication regarding the verification and updating of your personal information and sensitive personal information for purposes of our KYC policies in accordance with law and regulations, which includes email liveness tests, and request for submission of documents and for updating of customer records (lawful bases: legal obligation; performance of contract);

ii. To send email, SMS, and notifications regarding your Transaction/s with us including official receipts (lawful bases: performance of contract; legal obligation);

iii. To send promotions relating to our services or products and services of authorized third parties, only if and for as long as you have given your separate, specific, and informed opt-in consent to receive such marketing communications. Marketing consent is not a condition for using the Services; you may decline or withdraw it at any time, free of charge, through the unsubscribe mechanism in each message or by writing to [email protected], without affecting your Transactions or your access to the Services. We will not share your personal data with third parties for their own marketing purposes without your separate consent; and

iv. To send updates regarding our services and regarding communication from government regulatory and enforcement agencies.

Clients may opt out of these communications, except those which are required by our internal policies and by government regulations to be communicated to you (such as transactional, regulatory, and security notices).

1.4.3. Service Improvement and Market Analysis (lawful basis: legitimate interests)

We constantly strive to improve our Services and user experience. We will use your information to guide us in these efforts, to ensure that our services remain at the cutting edge and to ensure that your user experience remains pleasant and efficient. In addition, we will also use your information for assessment, record-keeping, market analysis, and generation of reports, using aggregated or de-identified data wherever practicable.

We may use the Personal Data we collect for testing, research, analysis and product development. This allows us to understand and analyze your needs and preferences, protect your Personal Data, improve and enhance the safety and security of our Services, develop new features, products and services.

1.4.4. Profiling and Analytics (lawful basis: legitimate interests, subject to your right to object)

i. Connect behavioral data on our Platform (buying and selling actions) with your customer profile and demographics; and

ii. Extract patterns of behavior based on the profiles we can identify from the information you have given us.

iii. You have the right to object to profiling as described in Section 1.7. Profiling under this Section is not used to produce legal effects concerning you or to similarly significantly affect you without human involvement. Where automated screening is used in KYC, sanctions, or fraud checks, adverse results are subject to human review before any final decision to decline, restrict, or terminate the Services.

1.4.5. Information Sharing

Subject to applicable law and, where required, data sharing or outsourcing agreements containing appropriate privacy and security undertakings, we may share, preserve, transfer, and disclose the information we collect, to the following:

i. Companies that form part of our group of companies, to enable them to offer or improve their respective services or products, subject, in the case of offers or marketing, to the consent requirement in Section 1.4.2(iii);

ii. Service providers that help us provide our services, to the extent needed to perform their duties and their functions, including service providers used for the logistics;

iii. To our officers, directors, partners, consultants, employees, agents, auditors, advisors or any other representatives on a need-to-know basis, to the extent needed for the fulfillment of the services;

iv. Government regulators that have regulatory oversight and jurisdiction over Moneybees;

v. Government authorities, in response to a legal request (like a search warrant, court order or subpoena) if we have a good faith belief that we are required to do so under the law;

vi. Government regulatory and/or enforcement agencies in the Philippines and other jurisdictions for reports relating to your account history including, but not limited to limit increase requests, limit breaches, covered and suspicious transactions, and other reports ordered or requested by such regulatory and/or enforcement agencies;

vii. Third-party service providers, partners or the like entities engaged by Moneybees to offer its products and services, and to assist in the administration and/or maintenance of its products, facilities, and services; and

viii. Purchasers or potential purchasers of our rights and obligations relating to the Services we provide, in connection with any acquisitions, sales, mergers, joint ventures, consolidation, restructuring, financing or any other type of business transactions. In any such transaction, personal data will be disclosed or transferred only under obligations of confidentiality and, upon completion, the recipient will be required to continue to protect your personal data in a manner consistent with this Policy and the DPA. You will be notified of any such transfer of your personal data and of any resulting change in the personal information controller, and your rights as a data subject will continue to apply.

1.4.6. Protection of Rights and Legal Interests

The information we collect may also be shared, transferred and disclosed when this is necessary:

i. To protect our rights and interests and those of our business partners, customers or third parties, as may be required and permitted by law;

ii. To detect, prevent and address fraud and other illegal activity;

iii. To establish, exercise, or defend legal claims of the Company and the Related Parties; and

iv. To pursue our legitimate interests or those of a third party, as may be required or permitted by law, where such interests are not overridden by your fundamental rights and freedoms.

1.4.7. AI-Assisted Processing

i. We use automated and artificial intelligence (“AI”)-assisted tools in certain processing activities, consistent with the transparency and accountability principles of BSP Memorandum No. M-2026-031 (Governance Principles for Artificial Intelligence in Financial Services). These currently include, as applicable: (a) facial matching, liveness detection, and document authentication in identity verification and e-KYC (lawful basis: legal obligation); (b) screening and monitoring of transactions for AML/CFT, sanctions, and fraud purposes (lawful bases: legal obligation; legitimate interests); and (c) automated or AI-assisted customer service and chat channels (lawful bases: performance of contract; legitimate interests).

ii. Some of these tools are provided by third-party service providers acting as personal information processors under contract with us. Moneybees remains accountable for personal data processed by such tools, including under the shared-responsibility model for outsourced AI systems under BSP regulations, and requires such providers to implement appropriate security, confidentiality, and data protection measures. Where these tools involve biometric data, the heightened safeguards for sensitive personal information described in Section 1.2 apply.

iii. AI-assisted outputs support, and do not replace, human judgment. No decision that produces legal effects concerning you or that similarly significantly affects you — such as declining your onboarding, restricting your account, or refusing a transaction — is made solely by automated means without human review, except where immediate automated action is required by law or sanctions obligations, in which case the action is promptly reviewed by authorized personnel. You have the right to be informed of automated decision-making and profiling (Section 1.7.5), to object to profiling (Section 1.7.3), and to question or seek review of outcomes you believe resulted from an automated process by contacting our Data Protection Officer (Section 1.8) or through our Financial Consumer Protection Assistance Mechanism, free of charge. We will explain the general basis of the outcome to the extent permitted by law, including laws restricting disclosure of AML/CFT screening information.

iv. Where our chat or customer service channels are operated in whole or in part by automated systems, they will be identified as such where practicable, and you may request a human representative at any time. Personal data disclosed in such channels is processed in accordance with this Policy.

1.5 Data Retention and Disposal

We will retain your personal data for as long as you maintain an account with us and, thereafter, for a period of five (5) years from the date of closure of your account or, for transaction records, from the date of the relevant transaction, in accordance with the AMLA and the guidelines issued by the BSP and the AMLC on the maintenance of records, or for such longer periods required by law (including the ten (10)-year retention of taxable-transaction documents under BIR Revenue Regulations No. 17-2013 and extended retention for records subject of ongoing investigations or cases, as described in Section 1.3). You may request the deletion of your personal data or information by contacting us through our official privacy email address: [email protected], if you no longer wish to keep your account, subject to existing laws, rules and regulations on data retention. Upon expiry of the applicable retention period, personal data will be securely disposed of or anonymized in a manner that prevents further processing, unauthorized access, or disclosure.

1.6 How We Secure Your Personal Information

We will protect your information through the use of secured servers in the cloud, with up-to-date security protocols and technologies in place. Sufficient physical and technical methods and procedures are employed to safeguard and secure the information from unauthorized or unlawful processing. We utilize layered technical security measures, including network segmentation, access controls, and encryption key management, to prevent unauthorized personnel from accessing data from our servers. We authorize access to personal information only for those employees who require it to fulfill their job responsibilities.

Our cloud vendor, Amazon Web Services (AWS), ensures security for the physical hardware, software, networking, and facilities that run their services, as defined in their AWS Security Whitepaper. We may request AWS to provide reports from third-party auditors who have verified compliance with a variety of computer security standards and regulations.

We use TLS / SSL (Transport Layer Security / Secure Sockets Layer) to ensure that data is encrypted while being transferred over the wire. We always use HTTPS (Hypertext Transfer Protocol Secure) for all our websites and web applications, to ensure all of our data to and from browsers are encrypted in transit.

1.6-A Cross-Border Transfers

Some of our service providers, including our cloud hosting provider, may store or process personal data on servers located outside the Philippines (including elsewhere in the Asia-Pacific region). Where personal data is transferred outside the Philippines, Moneybees remains accountable for it under Section 21 of the DPA. We effect such transfers only: (a) under contracts or other reasonable means that require the recipient to provide a comparable level of protection to that required by the DPA, its IRR, and NPC issuances; (b) to the extent necessary for the declared purposes in this Policy; and (c) subject to the same security measures described in Section 1.6. Your rights as a data subject under the DPA continue to apply to personal data transferred abroad.

1.6-B Cookies and Online Tracking

Our Website and Apps use cookies and similar technologies (such as local storage, pixels, and analytics identifiers) to operate and secure the platform, remember your preferences, measure site usage, and improve the Services. Some cookies are strictly necessary for the Website to function; others, such as analytics or marketing cookies, are optional. Where required by law, we will obtain your consent before deploying optional cookies, and you may manage or disable cookies through your browser or device settings, although disabling strictly necessary cookies may affect the functioning of the Website. Our chat channels and embedded social media features may also collect data governed by the privacy policies of the respective providers.

1.6-C Minors

The Services are available only to individuals who are at least eighteen (18) years old. We do not knowingly collect or process the personal data of minors. If we become aware that personal data of a minor has been collected without valid authority, we will delete it, subject to any retention required by law.

1.6-D Personal Data Breach Notification

We maintain a security incident management policy and a data breach response team. In the event of a personal data breach requiring notification under the DPA and NPC Circular No. 16-03, as amended, we will notify the NPC and the affected data subjects within seventy-two (72) hours from knowledge of, or reasonable belief that, a notifiable breach has occurred. The notification will describe the nature of the breach, the personal data possibly involved, and the measures taken to address the breach and mitigate its possible harm, together with the contact details of our Data Protection Officer.

1.7 Data Subject Rights

Please be informed that you have the following rights under the Data Privacy Act of 2012:

1.7.1. Access Personal Data

You may request access to any of the personal data held by the Company, subject to certain restrictions. A request for disclosure of such information is called a subject access request. Any such requests should be addressed to the Data Protection Officer.

1.7.2. Rectification of Personal Data

You have the right to dispute any inaccuracy or error in your personal data and to have it corrected accordingly, unless the request is vexatious or otherwise unreasonable. Upon correction, and if the personal data was previously disclosed to third parties, we will inform those recipients of the correction, upon your reasonable request. Separately, we also ask that you keep the personal data you have supplied to us up to date during the course of your engagement.

1.7.3. Object to the Processing of Personal Data

You have the right to object to the processing of the personal data, including processing for direct marketing, automated processing, or profiling. You shall also be notified and be given an opportunity to withhold consent to the processing in case of changes or any amendment to the information supplied or declared to you in this privacy notice. Where you object to processing based on consent or legitimate interests, we will cease the processing concerned unless it is required by law or is necessary for the purposes described in Sections 1.4.5(iv)–(vi) and 1.4.6.

1.7.4. Erasure or Blocking of Personal Data

You shall have the right to suspend, withdraw or order the blocking, removal or destruction of your personal information from our systems, subject to the mandatory retention periods described in Sections 1.3 and 1.5. Please note that depending on the type of personal information involved, you may be restricted from accessing any of our Services.

1.7.5. Be Informed of the Existence of Processing of Personal Data

You have a right to be informed whether personal data pertaining to you shall be, are being or have been processed, including the existence of automated decision-making and profiling.

1.7.6. Data Portability

Where your personal data is processed by electronic means and in a structured and commonly used format, you have the right to obtain a copy of such data in an electronic or structured format that is commonly used and allows for its further use, subject to the guidelines of the NPC.

1.7.7. Damages

Upon final judgment or award by a court or the NPC, you have the right to be indemnified for any damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal data, taking into account any violation of your rights and freedoms as data subject.

1.7.8. Right to Lodge a Complaint

You have the right to lodge a complaint with the National Privacy Commission if you believe your data privacy rights have been violated. We encourage you to first raise any concern with our Data Protection Officer so we can address it directly, but doing so is not a precondition to your right to complain to the NPC.

1.7.9. Transmissibility of Rights

Your lawful heirs and assigns may invoke your rights as data subject in the event of your death or incapacity, in accordance with the DPA.

1.7.10. How to Exercise Rights.

You may exercise any of these rights, free of charge, by writing to our Data Protection Officer at the contact details in Section 1.8. We may need to verify your identity before acting on a request. We will respond to requests within the periods stated in Section 1.8, or such other periods prescribed by the NPC.

1.8 Data Protection Officer

We have appointed a Data Protection Officer (“DPO”), duly registered with the National Privacy Commission in accordance with NPC Circular No. 2022-04, to be responsible for our privacy program. If you have any questions about how we protect or use your Personal Information or about this Privacy Policy, you may contact us using the information below:

Data Protection Officer

Moneybees Forex Corporation

Address: 4th Floor, Unit C & D Commerce and Industry Plaza Building, 1030 Campus Avenue, McKinley Hill, Taguig City, Philippines

Email: [email protected]

Our DPO will provide an initial response to your questions or complaint within five (5) business days and investigate and attempt to resolve your complaint within fifteen (15) business days. If a longer period is necessary, we will notify you accordingly.

1.9 Questions, Concerns, and Complaints

In case of complaints, concerns, or questions regarding our privacy policy or if you wish to exercise your data subject rights, you may address them to: [email protected].

For more details, or to file a complaint with the National Privacy Commission, please visit the website of the National Privacy Commission at https://privacy.gov.ph.

1.10 Changes to the Privacy Policy

If we modify this Privacy Policy, we will make it available through our Privacy Policy page and indicate the date of the latest revision. For material changes — such as new purposes of processing, new categories of recipients, or changes affecting your rights — we will provide advance notice consistent with the notice standards in our Customer Terms & Conditions (not less than sixty (60) days, unless a shorter period is directed by a regulator or required by law) and, where the change involves processing that requires consent, we will seek your fresh consent before the new processing begins.

Moneybees Logo

Buy and Sell Cryptocurrencies Over-the-Counter

National Privacy Commission DPO/DPS Registered
Beosin Logo
Data Privacy
National Privacy Commission DPO/DPS Registered
Follow us on
  • Twitter
  • Twitter
  • Twitter
  • Twitter
Beosin Logo

© 2026 Moneybees. All rights reserved.