Legal

Privacy Policy

Effective date: September 25, 2026 · Last updated: September 25, 2026

1.Introduction

XRP Asia Ltd (“we”, “us”, or “our”) is committed to protecting the personal data of our users, customers, and website visitors in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore.

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and how we protect it. It also explains your rights regarding your personal data and how to contact us with questions or concerns.

This policy applies to personal data collected through our website at xrpasia.org, our events registrations, and our offline interactions with you.

2.Personal Data We Collect

We may collect the following types of personal data:

Data you provide directly:

  • Name
  • Email address
  • Phone number
  • Nationality
  • Country of residence
  • Affiliation
  • Job title
  • Social media handles (X, Telegram, Discord, or other platforms)

Data collected automatically:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on our website
  • Referring website or source
  • Cookies
  • Location data

Data from third parties:

  • Data from social media platforms
  • Business partners
  • Public Databases
  • On-chain data including XRP Ledger data

3.Purposes of Data Collection

We collect and use your personal data for the following purposes:

  • Communication: To respond to your enquiries
  • Marketing: To send you promotional materials, newsletters, and updates about our products and services (with your consent)
  • Website improvement: To analyse website usage patterns and improve our website’s functionality
  • Legal compliance: To comply with applicable laws, regulations, and legal obligations
  • Security: To detect, prevent, and address fraud, security issues, and technical problems
  • To better serve the XRP Ledger community and ecosystem: To measure engagement, analyse trends, and gather insights, with the aim of improving our programs and resources

4.Legal Basis for Processing

We process your personal data based on the following legal bases under the PDPA:

  • Consent: Where you have given express consent (e.g., subscribing to our newsletter)
  • Deemed consent: Where you have voluntarily provided personal data for a purpose that is reasonable and apparent (e.g., submitting a contact form)
  • Deemed consent by notification: Where we have notified you of the intended use and you have not opted out within a reasonable period
  • Legal requirement: Where processing is required by Singapore law
  • Contractual necessity: Where processing is necessary to perform a contract with you

5.Disclosure to Third Parties

We may share your personal data with the following types of third parties:

  • Service providers: Companies that provide services on our behalf, such as email delivery, website hosting, error monitoring, and analytics as necessary
  • Professional advisers: Lawyers, accountants, and auditors as necessary
  • Government authorities: Where required by law or in response to valid legal requests
  • Business transfers: In connection with a merger, acquisition, or sale of assets (with notice to you)
  • Partners with a shared interest in growing the XRP Ledger ecosystem: Organisations that offer programs, funding, and resources to XRP Ledger builders and community members.

We require all third-party service providers to process your personal data in accordance with the PDPA and to implement appropriate security measures.

6.Cross-Border Data Transfers

Some of our partners may store or process your data outside Singapore. These include:

  • XRP Ledger Foundation: data stored in France
  • XRPL Commons: data stored in France
  • RippleX: data stored in the US

Where we transfer personal data outside Singapore, we ensure that the recipient provides a standard of protection comparable to the PDPA through contractual arrangements or other appropriate safeguards, in compliance with Section 26 of the PDPA.

7.Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

  • Marketing data: Until you withdraw consent or unsubscribe
  • Website analytics data: 2 years

When personal data is no longer needed, we will securely destroy or anonymise it.

8.Data Security

We implement reasonable security measures to protect your personal data from unauthorised access, disclosure, alteration, and destruction. These measures include:

  • Encryption of sensitive data in transit and at rest
  • Access controls limiting data access to authorised personnel only
  • Regular security assessments and software updates
  • Staff training on data protection practices
  • Secure disposal of physical and digital records

9.Your Rights

Under the PDPA, you have the following rights:

Right to access: You may request access to the personal data we hold about you. We will respond within 30 days of receiving your request. A reasonable fee may apply.

Right to correction: You may request that we correct any inaccurate or incomplete personal data. We will make corrections as soon as practicable.

Right to withdraw consent: You may withdraw your consent for any specific purpose at any time by contacting our DPO. We will process your withdrawal within 10 business days. Please note that withdrawal of consent may affect our ability to provide certain services to you, and we will inform you of the likely consequences.

To exercise any of these rights, please contact us using the details below.

10.Cookies

Our website uses cookies and similar technologies to enhance your browsing experience and collect analytics data.

  • Essential cookies: Required for the website to function properly
  • Analytics cookies: Help us understand how visitors interact with our website (e.g., Google Analytics)
  • Marketing cookies: Used to deliver relevant information

You can manage your cookie preferences through your browser settings. Disabling cookies may affect the functionality of our website.

11.Data Protection Officer

Our Data Protection Officer (DPO) is responsible for overseeing our compliance with the PDPA.

If you have any questions about this privacy policy, wish to exercise your rights, or have concerns about how we handle your personal data, please contact our DPO.

12.Complaints

If you are not satisfied with our response to your data protection concern, you may file a complaint with the Personal Data Protection Commission (PDPC):

13.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by sending an email notification.

We encourage you to review this policy periodically.