Legal
Privacy Policy
Last updated: March 2026
1. Introduction
This Privacy Policy explains how Railr collects, uses, stores, and protects personal data in connection with access to and use of the Railr platform, network, and API.
The Railr network is operated by Railr Inc., a c corporation registered in the State of Wyoming, United States of America. Railr intellectual property is owned by Caradon Enterprises Inc., incorporated in the Republic of Panama, under licence to Railr Inc. References to Railr, we, us, or our in this policy refer to Railr Inc. and its associated entities operating under the Railr brand.
This policy applies to all individuals whose personal data is processed in connection with the Railr network, including applicants, authorised representatives of institutional participants, liquidity providers, API users, and any other individuals who interact with Railr directly.
Railr is committed to processing personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR 2016/679).
2. Data Controller
The data controller responsible for your personal data is:
Railr Inc.
Wyoming, United States
For all data protection enquiries, requests, or complaints, please contact us at legal@railr.io.
As the Railr group structure develops, this policy will be updated to reflect any changes to the data controller or the introduction of additional group entities responsible for processing personal data.
3. What Personal Data We Collect
Railr collects personal data that is necessary for the operation of a permissioned institutional network. The categories of personal data we collect include:
Identity Data
Full legal name, date of birth, nationality, government-issued identification documents, and photographic identification as required for KYC verification purposes.
Contact Data
Email address, telephone number, and professional address.
Professional and Business Data
Company name, company registration details, role and title, beneficial ownership information, and business activity details as required for KYB verification purposes.
Application Data
Information submitted as part of an application for network access, including estimated trading volumes, asset preferences, and participant type.
Regulatory Status Data
Regulatory authorisation, licence, or registration details provided as part of the network access application, including the name of the relevant regulatory authority and licence or registration number.
Verification Data
Results of identity verification checks, regulatory status verification, sanctions screening outcomes, politically exposed person status assessments, and AML screening results.
Communications Data
Records of correspondence and communications between you and Railr, including emails and platform messages.
Technical Data
IP address, browser type, device information, access logs, API request logs, and session data collected through your use of the Railr website, platform, and API.
Usage Data
Information about how you interact with the Railr platform and API, including RFQ activity, quote responses, execution outcomes, features accessed, and session duration.
API Credential Data
API key identifiers, permission scopes, IP whitelist configurations, and API usage logs associated with your account.
4. How We Collect Personal Data
Railr collects personal data:
- Directly from you when you submit an application for network access.
- Through the onboarding and verification process including data collected via our KYC provider.
- Through your ongoing use of the Railr platform, website, and API.
- From publicly available sources including company registries and sanctions databases as part of our compliance obligations.
- From third party verification and screening services as part of our AML and KYB processes.
API usage data and request logs are collected automatically through your API integration. This data is used for security monitoring, rate limit enforcement, audit log generation, and network performance analysis.
5. Lawful Basis for Processing
Railr processes personal data on the following lawful bases under UK GDPR and EU GDPR:
Performance of a Contract
Processing necessary to assess your application, onboard you as a network participant, provide access to the Railr platform and API, and deliver the services you have applied for.
Legal Obligation
Processing necessary to comply with applicable AML, KYC, KYB, and sanctions screening obligations, including the retention of verification and activity records as required by law.
Legitimate Interests
Processing necessary for the operation, security, and improvement of the Railr network, including fraud prevention, API security monitoring, network integrity, audit log maintenance, and communications with participants. We have assessed that our legitimate interests are not overridden by your rights and interests in these cases.
Consent
Where we rely on consent as a lawful basis, such as for the use of non-essential cookies or analytics, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
6. How We Use Your Personal Data
Railr uses personal data to:
- Assess and process applications for network access.
- Conduct identity, business, and compliance verification including KYC, KYB, sanctions screening, and AML checks.
- Onboard and activate verified participants on the Railr network.
- Issue and manage API credentials and access controls.
- Communicate with you regarding your application, participation status, platform updates, and security notices.
- Operate, maintain, and improve the Railr platform, API, and network.
- Monitor network and API activity for security, fraud prevention, and compliance purposes.
- Generate and maintain immutable audit logs of participant activity.
- Meet our legal and regulatory obligations.
- Analyse website usage and platform performance through analytics tools.
- Enforce our Terms of Use and other applicable agreements.
7. Third Party Service Providers
Railr shares personal data with carefully selected third party service providers where necessary for the operation of the platform. These providers act as data processors on our behalf and are contractually required to process personal data only on our instructions and in accordance with applicable data protection law.
Current third party processors include:
Sumsub
Identity verification and KYC/KYB processing provider. Personal data including identity documents and verification results are processed by Sumsub in connection with participant onboarding. Sumsub's privacy policy is available at sumsub.com.
Google Analytics
Website analytics provider operated by Google LLC. Technical and usage data is collected through cookies and similar technologies to analyse website traffic and user behaviour. Google may process this data in the United States. For more information see Google's privacy policy at google.com/privacy.
Vercel
Website and platform hosting infrastructure. Technical data including IP addresses, access logs, and API request logs may be processed by Vercel in connection with platform hosting and delivery.
Railr may engage additional third party processors from time to time, including cloud infrastructure providers, security monitoring services, and compliance tooling providers. Where this involves a material change to how personal data is processed, this policy will be updated accordingly.
8. International Data Transfers
The Railr network is operated by Railr Inc., a c corporation registered in the State of Wyoming, United States of America. Personal data collected from individuals in the United Kingdom or European Union may be transferred to and processed in the United States or other jurisdictions outside the UK and EEA.
Where personal data is transferred internationally, Railr takes appropriate steps to ensure that such transfers are made in accordance with applicable data protection law, including through the use of standard contractual clauses or other appropriate safeguards where required.
Third party processors including Google LLC and Vercel may also process personal data in the United States or other jurisdictions. Where applicable, transfers to these processors are governed by standard contractual clauses or equivalent transfer mechanisms recognised under UK GDPR and EU GDPR.
9. Data Retention
Railr retains personal data only for as long as is necessary for the purposes for which it was collected, subject to any legal or regulatory obligations requiring longer retention periods.
Specific retention periods include:
KYC and KYB verification records
Retained for a minimum of five years from the end of the business relationship, in accordance with AML legislation and applicable regulatory requirements.
Application data
Retained for two years from the date of application, whether or not the application was approved.
Communications records
Retained for three years from the date of the communication, unless a longer period is required for legal or compliance purposes.
API request logs and audit logs
Retained for a minimum of five years to support participant compliance obligations and network integrity monitoring.
Technical and usage data
Retained for up to twelve months from collection, subject to aggregation and anonymisation for analytics purposes.
When personal data is no longer required, it is securely deleted or anonymised in accordance with our data management procedures.
10. API Data and Security
Personal data processed through API access is subject to the same protections as data collected through the platform directly.
API request logs are retained as part of the participant audit log and are accessible to the relevant participant at any time. Logs include request timestamps, endpoint accessed, IP address of the requesting system, and response status. Logs do not include the content of quote responses or pricing data from other participants.
API credentials including key identifiers and permission scope configurations are stored securely. API secrets are hashed and are not recoverable after initial issuance. If an API secret is lost or suspected to be compromised, the participant must revoke the affected key and issue new credentials immediately.
IP whitelist configurations are stored against the participant account and applied to all API requests in real time.
11. Your Rights
Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
Right of Access
You have the right to request a copy of the personal data Railr holds about you.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our legal and regulatory retention obligations. Please note that audit logs and verification records may be exempt from erasure requests where retention is required by law.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format, where processing is based on consent or contract.
Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as the lawful basis.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Liquidity Score calculations are based on objective performance metrics and do not constitute automated decision making of a legal or similarly significant nature.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, please contact us at legal@railr.io. We will respond to all legitimate requests within one month. In complex cases we may extend this period by a further two months, in which case we will notify you.
12. Cookies and Tracking Technologies
Railr uses cookies and similar tracking technologies on its website. For full details of the cookies we use, the purposes for which they are used, and how to manage your cookie preferences, please refer to our Cookie Policy at railr.io/cookies.
13. Data Security
Railr implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These measures include:
- Encryption of data in transit using TLS 1.3 and at rest.
- Access controls limiting data access to authorised personnel only.
- Two-factor authentication on all platform and administrative access.
- API key scoping and IP whitelisting controls.
- Regular security monitoring and review.
- Contractual security obligations imposed on all third party processors.
For full details of Railr's security implementation, please refer to our Security page at railr.io/security.
14. Children
The Railr platform is intended solely for use by institutional participants, professional counterparties, and qualified individuals. Railr does not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data has been collected from a minor, we will take steps to delete it promptly.
15. Changes to This Policy
Railr may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or platform operations. The date at the top of this policy indicates when it was last updated. Where changes are material, we will notify active participants directly.
16. Complaints
If you are not satisfied with how Railr has handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority.
United Kingdom
Information Commissioner's Office (ICO) at ico.org.uk.
European Union
The supervisory authority in your country of residence or the country where the alleged infringement occurred.
We would encourage you to contact us at legal@railr.io in the first instance so that we have the opportunity to address your concern directly.