Resources · Legal

Terms of Service & Privacy Policy.

Both documents are effective May 12, 2026. Enterprise clients on a negotiated custody agreement should read these as the baseline that agreement modifies.

Terms of Service

Effective May 12, 2026. These terms are a contract between holdway and the institution named on the account ("you", "the client"). By opening an account you agree to them.

1. The service

holdway provides custody of digital assets: we safekeep assets you deposit into your segregated wallets, execute transfers your authorized users instruct under your configured policy, and report on holdings. Nothing more. In particular, holdway:

  • does not provide investment, legal, accounting, or tax advice, and does not recommend the purchase, sale, or holding of any asset;
  • does not operate an exchange, matching engine, or lending desk, and does not trade for its own account against clients;
  • does not stake, vote, or otherwise deploy client assets unless a separate written addendum says so;
  • is not a consumer product. The service is offered to institutions only, and consumer-protection regimes applicable to retail financial products do not govern it.

"Digital assets" means the assets we list as supported from time to time — currently BTC, ETH, and USDC, with ERC-20 tokens by written arrangement. "Your policy" means the quorum, allow-list, and time-lock configuration active on your account. "Business day" means a weekday other than a U.S. federal holiday.

2. Accounts and authorized users

Accounts are opened in the name of a legal entity after completion of the onboarding described on our Compliance page. On opening, you designate authorized users and assign each a role — administrator, approver, initiator, or viewer. Between us and you:

  • you are responsible for the accuracy of your user list and for keeping it current as people join and leave;
  • every action taken with a valid credential and, where applicable, a valid approval-device signature is attributed to you until you revoke that user's access;
  • you must enforce your own personnel controls — we enforce your policy, not your HR records;
  • you must notify us without undue delay at support@holdway.xyz if you suspect a credential or approval device is compromised. We may suspend affected users while we investigate, and we will not treat that suspension as a service failure.

We may refuse or offboard an account where required by law or by the sanctions and screening obligations described in Section 6.

3. Client instructions and policy configuration

You configure the controls on your account — approval quorums (for example, 3-of-5), withdrawal allow-lists, and time-locks. We enforce that configuration exactly as set. When an instruction satisfies your configured policy — the required quorum has approved, the destination is allow-listed, and any time-lock has elapsed — the instruction is binding: we will execute it, and once broadcast to a blockchain network it cannot be reversed by holdway or by you.

The consequences of that rule cut both ways, and we state them plainly:

  • we are not obliged to second-guess a policy-compliant instruction, and we are not liable for executing one, even if it later proves to have been a mistake on your side;
  • conversely, we will not execute an instruction that fails your policy — not for your CEO, not for your board, not on a phone call — until the policy is satisfied or duly amended;
  • changes to policy configuration (quorums, allow-list entries, time-locks, user roles) are themselves instructions, subject to quorum approval and a time-lock, so a single compromised administrator cannot quietly loosen the controls.

We may delay execution of a policy-compliant instruction only where Section 6 (screening), a legal compulsion, or a genuine operational incident published on our status page requires it, and we will tell you when we do.

4. Fees

Fees are set out in your order form and consist of:

  • a custody fee assessed on the value of assets under custody, billed monthly in arrears;
  • network fees for on-chain transfers, passed through at cost without markup;
  • any one-time fees your order form states, such as key-ceremony fees for bespoke quorum setups.

Fee changes require 30 days' written notice and never apply retroactively. Undisputed invoices are due within 30 days. For non-payment we may suspend new deposits and non-essential features; we will not withhold withdrawals of your existing assets to collect a fee dispute, though our agreed lien for unpaid fees under Section 5 survives.

5. Segregation and title

Your assets remain your property. Assets in custody are held in per-client segregated wallets, are at all times the property of the client, and do not form part of holdway's assets or estate. holdway acquires no title, lien, or security interest in them except as expressly agreed for unpaid fees. Client assets are never lent, staked, pledged, hypothecated, or rehypothecated, and are structured to be bankruptcy-remote: in any insolvency of holdway, they are identifiable, segregated client property to be returned to clients, not distributed to holdway's creditors.

Three consequences follow:

  • we record your holdings wallet-by-wallet in your name, and our books never net one client against another;
  • our agreed lien for unpaid fees extends only to fees actually invoiced and unpaid, never to a general claim over the account;
  • you may verify segregation yourself at any time — the mechanics, per-client wallets and independent proof-of-reserves attestation, are described under Custody and Reporting.

6. Acceptable use

You may not use the service to:

  • hold or move assets that are the proceeds of crime, or facilitate money laundering or terrorist financing;
  • evade sanctions, or transact with sanctioned parties, prohibited jurisdictions, or addresses designated by competent authorities;
  • probe, scan, disrupt, or overload the platform or its API, or attempt to access another client's account or data;
  • resell or intermediate custody for third parties without a written sub-custody agreement with us;
  • misrepresent the identity of beneficial owners, control persons, or the origin of deposited assets during onboarding or thereafter.

We screen transfers as described in our AML program and may decline, delay, or freeze a transaction where law or a screening hit requires it. Where we do, we tell you unless we are legally prohibited from doing so. Material or repeated breach of this section is grounds for immediate termination under Section 9.

7. Warranties and disclaimers

Our undertaking is narrow and real: the service will be operated with the diligence and professional competence described in these terms and our documentation, and we will maintain the control environment described on our Security page, as evidenced by our SOC 2 Type II examinations. Beyond that, the service is provided "as is".

Blockchain networks are third-party systems we do not control. Accordingly, we do not warrant:

  • the operation, availability, or finality of any blockchain network, or the timing of confirmations;
  • the value of any digital asset, which may fall to zero;
  • the consequences of forks, reorganizations, airdrops, or protocol changes — our default handling of forked or airdropped assets is set out in your custody agreement, and unsupported assets sent to your wallets may be unrecoverable;
  • uninterrupted platform availability. Our uptime record is published on the status page; targets and service credits are in your order form.

Supported assets may be added or removed with 30 days' notice; on removal you will have a reasonable window to withdraw before support ends.

8. Limitation of liability

Indirect and consequential losses — including lost profits, lost revenue, and lost opportunity — are excluded for both parties, foreseeable or not. For direct losses, holdway's aggregate liability in any 12-month period is capped at the greater of the fees you paid us in that period and USD 100,000.

The cap does not apply to: loss of client assets caused by holdway's breach of Section 5 (segregation and title); holdway's fraud or willful misconduct; or any liability the law refuses to let a contract cap. Nothing in this section limits your obligation to pay fees. Our insurance program, described under Insurance, sits behind these obligations; it does not replace them, and its policy limits do not define our liability to you.

9. Termination and return of assets

Either of us can walk away without cause by giving 30 days' written notice. We may terminate immediately where you materially breach these terms (including Section 6), become insolvent, or where continuing the relationship would put us in breach of law. On termination, asset return works as follows:

  • we return all client assets to withdrawal addresses on your allow-list, following your quorum-approved instructions, within 10 business days of each instruction — sooner where practicable;
  • your policy controls remain enforced throughout wind-down; termination does not lower the bar for moving your assets;
  • if you give no instruction within 90 days of the termination date, we will transfer remaining assets to your most recently confirmed allow-listed address and close the account;
  • we provide a closing statement and final proof-of-reserves extract for your records, per Reporting.

Fees stop accruing when the account holds no assets. Sections 5, 8, and 10 survive termination.

10. Governing law and general terms

These terms are governed by New York law, disregarding its conflict-of-laws rules. The state and federal courts sitting in the Borough of Manhattan, New York have exclusive jurisdiction, and each party waives objections to that venue and, to the extent permitted, the right to a jury trial.

These terms, your order form, and any negotiated custody agreement are the entire agreement; where they conflict, the negotiated agreement controls, then the order form, then these terms. Assignment needs the other side's written consent; a transfer to an affiliate, or as part of a merger or a sale of substantially the whole business, is permitted with notice. Notices to us go to hello@holdway.xyz; notices to you go to your account administrators. If any provision is unenforceable, the remainder stands. Delay caused by circumstances genuinely outside a party's control is excused — but nothing, ever, excuses holdway from its segregation obligations in Section 5.

Privacy Policy

Effective May 12, 2026. Questions to privacy@holdway.xyz.

1. Who we are and what this covers

holdway is the controller of personal data processed in connection with the custody service and this website. This policy covers data about our clients' personnel — authorized users, beneficial owners, control persons — and about visitors to holdway.xyz and applicants who write to careers@holdway.xyz.

Two boundary notes. First, our clients are institutions; where your employer gives us your details as an authorized user, your employer decides that you are on the account, and we process the data to run it. Second, this policy does not cover on-chain data: blockchain transactions are public by the nature of the networks, and no custodian can delete them. What we control is the mapping between on-chain addresses and identified clients, and that mapping we protect as confidential.

2. Data we collect

  • Account data — names, work contact details, roles, credentials, and approval-device registrations of authorized users.
  • KYC and beneficial-ownership data — identity documents, dates of birth, ownership percentages, source-of-funds information, and screening results for beneficial owners and control persons. We collect this because anti-money-laundering law obliges us to, not by choice; providing it is a condition of the service, and refusing it means we cannot open or keep the account.
  • Usage logs — authentication events, API calls, approval actions, policy changes, and IP addresses, retained as the audit trail of who instructed what and when.
  • Correspondence — support tickets, diligence exchanges, and emails to our @holdway.xyz addresses.

We do not buy data about you, we do not collect data from social media, and we do not run advertising trackers on this site.

3. How we use it

Each use rests on a stated legal basis:

  • to provide, administer, and secure the service — performance of contract;
  • to meet AML, sanctions-screening, travel-rule, and record-keeping obligations — legal obligation;
  • to investigate security incidents, enforce our terms, and establish or defend legal claims — legitimate interest;
  • to send service and security communications to account contacts — performance of contract; these are not marketing and cannot be opted out of while the account is open.

We do not sell personal data, do not use client data to train machine-learning models, and do not use it for third-party marketing.

4. Sharing

We share personal data with three kinds of recipients, and no others:

  • Subprocessors — cloud infrastructure, HSM and facility providers, and screening-data providers. Categories are listed on our Compliance page; the named list is available under NDA; all are bound by data-protection terms and re-vetted annually, and clients get 30 days' notice of changes.
  • Screening providers — to the extent needed to run sanctions, beneficial-ownership, and blockchain-analytics checks required by our AML program.
  • Authorities — where a legally binding request compels disclosure, following the review-and-narrow process described under Compliance. We notify affected clients unless legally prohibited, and when a non-disclosure order expires, we notify then.

Where data moves across borders to a subprocessor, we use recognized transfer mechanisms and keep the documentation available to clients on request.

5. Retention

Personal data stays with us while the account is open, then for whatever period statute demands. Indicative periods:

  • KYC and beneficial-ownership records — minimum five years after the client relationship ends, per AML law;
  • Transaction and instruction logs — minimum five years after the transaction, and longer where they evidence asset ownership;
  • Account and correspondence data — life of the account plus limitation periods for contract claims;
  • Website and applicant data — months, not years; deleted when no longer needed.

AML minimums apply even to deletion requests: where you ask us to delete data we are legally required to keep, we restrict it instead. Restricted data is removed from operational systems, locked to compliance access only, excluded from any other use, and purged when the statutory period expires. That is the honest version of "delete", and it is the one a custodian can actually promise.

6. Security

The controls that guard client assets guard personal data too:

  • everything encrypted on the wire and on disk, with KYC document stores encrypted separately from operational databases;
  • role-based access on a need-to-know basis, with quorum controls on sensitive operations and access reviews on a fixed calendar;
  • full audit logging of access to KYC records;
  • annual SOC 2 Type II examination and independent penetration testing covering these systems.

Details are on our Security page. If we suffer a personal-data breach, we notify affected clients without undue delay, with enough detail for you to act, and notify regulators where required.

7. Your rights

Depending on your jurisdiction, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct inaccurate data — for KYC documents this may require re-verification;
  • request deletion, subject to the retention rules in Section 5;
  • push back on — restrict or object to — any processing we justify by legitimate interest;
  • receive account data you provided in a portable format.

Exercise any of these by writing to privacy@holdway.xyz. Requests are identity-checked and answered inside 30 days, and if a legal obligation prevents us from fulfilling a request we will say so plainly and cite which one. You may also complain to your data-protection authority; we would prefer you write to us first, but that is your right regardless.

8. Changes

We update this policy when practices or law change. Material changes are notified to account administrators by email at least 30 days before they take effect, with the previous version available on request. The effective date at the top of this page always reflects the current version. We never use a policy change to retroactively justify processing that was not permitted when it happened.

Questions on either document — including requests for signable copies, prior versions, or the negotiated custody agreement template — go to compliance@holdway.xyz for terms and diligence matters, or privacy@holdway.xyz for data matters.