Data and privacy
Privacy Policy
This document explains in concrete terms what data re-energy receives through its website, Telegram bot, and API, why it is needed, who receives it, and what you can do with it.
- A user account is linked to a Telegram ID; an ordinary user does not need an email address or a separate password.
- For top-ups and services, we process public TRON addresses, transactions, amounts, orders, and an internal financial ledger.
- A resource supplier receives the address and fulfilment parameters; an AML provider receives only the target and parameters required for the requested check.
- We do not sell personal data, use it for third-party advertising, or receive the seed phrase or private key of a target wallet.
- Marketing messages can be switched off separately; this does not delete financial records or prevent replies to your actions.
- Records on a public blockchain are outside re-energy's control and cannot be erased by us.
1. Scope and controller
This policy applies to the re-energy Telegram bot, re-energy.online, the client API at api.re-energy.online, and related administration infrastructure. It is a notice about data processing, not a request to consent to every form of processing through a single action.
The data controller is the operator of the re-energy service (the “Operator”, “we”), which determines the purposes and means described below. The official contact for requests appears in section 24. Telegram, the public TRON network, and third-party services are separately responsible for the processing they carry out for their own purposes under their own terms.
If you use re-energy through a commercial partner's integration, that partner may also be a separate controller of your data. Its own notice should explain what it collects before passing a request to re-energy.
The policy covers users of the bot, website, and API, partner representatives, administrators, and website visitors. It can also concern people whose public addresses or transactions a user lawfully submitted for an order or check, although a blockchain identifier alone may not tell us who stands behind it.
2. Our principles
- Purpose before data. We collect data for a defined feature, accounting, security, or obligation—not speculatively.
- Minimum disclosure. A supplier does not receive your Telegram profile when it is not required for fulfilment.
- Separate controls. Marketing messages have their own setting and are not mixed with operational bot replies.
- Auditable accounting. Money records are kept so a balance, refund, and dispute can be reconstructed from the ledger.
- No data sales. We do not sell or rent personal data or disclose it to advertising networks.
3. Where data comes from
We receive data from the following sources:
- from you when you send commands, addresses, transaction hashes, settings, support requests, or API requests;
- from the Telegram Bot API—limited profile data and the content of your interaction with the bot;
- from the public TRON network and access services—transactions, balances, resources, statuses, and receipts;
- from order suppliers and AML analytics—fulfilment status, identifiers, cost, transaction, risk factors, and report data;
- from your API partner when it submits a request for you or as part of its own service;
- automatically from our infrastructure—request time, IP address, user agent, path, response status, errors, and security events.
Blockchain data may not concern you personally. It becomes linked to your service account when you use an address as an order target, save it, or top up the deposit address assigned to you.
4. Data we process
- Telegram
- Numeric Telegram ID, username, display name, language, bot-block status, and notification settings.
- Account
- Internal identifier, registration date, referral relationship and code, restrictions, individual pricing, and selected settings.
- Wallets
- Assigned deposit address, TRON addresses you enter, saved labels, balances, and resources needed for the selected feature.
- Top-ups
- Asset, amount, sender and destination addresses, transaction hash, confirmation, crediting rate, and non-credit reason.
- Money and services
- Internal balance, ledger entries, orders, prices, refunds, statuses, fulfilment period, subscriptions, promo codes, and referral accruals.
- AML
- Address or transaction hash, target type, risk score, risk categories, connections and exposure, transaction data, and report metadata.
- API
- API-key hash, safe prefix and label, issue and rotation times, permitted IP list, idempotency keys, and replayable responses.
- Communications
- Support content, current conversation step, message delivery, Telegram errors, and clicks on internal broadcast buttons.
- Administration
- Service-account email, password hash, role, second-factor state, protected recovery secrets, and authorship of administrative actions.
- Security
- IP address, user agent, request time and result, rate-limit events, administrator logins and actions, and diagnostic errors.
5. Why we process data and the legal grounds
The particular legal ground depends on the applicable law and circumstances. Where the law distinguishes between grounds, we rely on one or more of the following:
- Contract and user request
- To create an account, display a price, accept a top-up, fulfil an order, maintain the balance, issue a refund, deliver an AML result, or operate the API.
- Legitimate interests
- To protect users and the service, prevent abuse, route orders, reconcile money, resolve failures, produce internal analytics, and establish or defend claims, after considering user rights.
- Legal obligation
- To preserve or disclose data, respond to a valid request, and meet accounting, tax, sanctions, or other mandatory law where it applies to the Operator.
- Consent or separate choice
- To send marketing and product messages or use optional data where applicable law requires consent. Consent can be withdrawn for the future.
If data is objectively required for an order—for example, the destination address or rental parameters—we cannot quote or supply the service without it. Optional fields do not have to be provided.
Processing is primarily automated using information systems and networks. Depending on the purpose, it includes collection, recording, organisation, storage, correction, retrieval, use, disclosure to the listed recipients, restriction, anonymisation, and erasure or destruction. We do not publish private account data to an unrestricted audience; the public nature of the blockchain is addressed separately in section 7.
6. Telegram account and bot messages
Your Telegram ID is the primary account identifier. The bot also receives a username, display name, and language if Telegram supplies them. We do not automatically receive your telephone number; it reaches us only if you choose to send a contact or type it in a message.
Commands, addresses, and other messages pass through Telegram's infrastructure. Telegram is a separate platform and processes data under its own Privacy Policy. Deleting a chat or Telegram account does not by itself delete records from re-energy's database; a separate request under section 18 is required.
Data about the current conversation step may be stored temporarily so the bot knows which address or parameter it is waiting for. Do not send special-category data, documents, or another person's private information unless it is needed for a specific support matter and agreed with support.
7. Wallets, deposits, and the public blockchain
re-energy assigns each user a separate service-controlled TRON deposit address and links it to the account so top-ups can be detected. It is not a standalone self-custody wallet belonging to the user. Once confirmed, funds are recorded on the internal balance and may be moved to the Operator's service wallets in accordance with the Terms of Service.
To detect, credit, reconcile, and move funds, we read inbound transfers, addresses, amounts, hashes, times, confirmations, balances, resources, and receipts from the TRON network. A public target address is also processed for orders. If you enter another person's address, you must have a lawful basis to use it for the selected feature.
8. Orders, calculations, and automated services
For Energy or Bandwidth rental, address activation, the calculator, Always Charged, and Auto Charging, we process the address, resource, amount, duration, cost calculation, applicable pricing, status, fulfilment identifiers, transaction, and expiry. A label supplied by you may be stored with a saved address.
The financial ledger contains top-ups, debits, refunds, adjustments, referral accruals, and the balance after each operation. It is not merely a display history: it is used to prevent double charges, verify refunds, and investigate discrepancies. Supplier cost and routing are visible to authorised administrators but are not exposed in the client-facing Telegram interface.
Automated services store the thresholds, amounts, service window, status, address, resource, and charge times you configured. After cancellation, part of the history may remain as evidence of services and charges already made.
9. AML checks
When you order an AML check, the selected address or transaction hash and required technical parameters are sent to a specialised analytics provider. We receive and may retain the status, overall risk score, risk categories and factors, connections to service types, exposure structure, transaction context, and technical check identifier.
re-energy transforms that response into its own short assessment and PDF report. Provider categories can be incomplete, can change on re-analysis, and may contain false matches. A check is informational and does not prove the identity of an address owner, a criminal offence, or the legality of a particular transaction.
Processing is based on fulfilling your request, protecting the service, and, where applicable, mandatory compliance. Do not submit an address or transaction together with unnecessary personal explanations.
10. API and commercial partners
For an API account we store a cryptographic hash of the key, its non-secret prefix, rotation details, and, if the partner enables this protection, an exact list of permitted IP addresses. The full live key is shown when issued and is not stored in plaintext. Requests may contain addresses, order parameters, an idempotency key, and other fields in the published contract.
Technical API records help enforce limits, prevent a repeated money action, investigate errors, and protect the key. The IP whitelist is optional, but once enabled, requests from other IP addresses are rejected. Partners are responsible for key secrecy and for the lawfulness of data they submit.
A partner must give its end users its own notice and have a lawful basis to send their addresses and order parameters. Depending on the actual roles and applicable law, the parties may be independent controllers, or re-energy may process data on the partner's instructions. If a data processing agreement is required, it must be executed separately: neither the API documentation nor this policy replaces one.
11. Messages, notifications, and broadcasts
We send replies to your commands, operation confirmations, order and balance updates, security alerts, and, when enabled, product or marketing messages. Marketing messages are separate from ordinary notifications and can be disabled in the bot profile.
Broadcast selection may use language, registration date, balance, whether and when a purchase was made, product type, and recent contact history. We record campaign audience membership, delivery status, rejection reason, and clicks on internal buttons. Telegram does not give us reliable message-open data, so we do not manufacture an open-rate metric.
Marketing opt-out applies to future product and promotional campaigns. Replies to your actions, current-order messages, and other necessary service communications may continue while you use the bot and allow it to message you.
12. Website, local storage, and technical logs
The public website has no advertising trackers or third-party product analytics. Your language choice is kept in browser localStorage so it need not be asked on each visit. This is a technical preference, not an advertising profile.
Like any internet service, our servers and protective infrastructure may process the IP address, date and time, requested path, response status, user agent, and diagnostic details. They are used to deliver the page, restrict attacks, investigate errors, and monitor availability.
Fonts on some public pages are loaded through Google Fonts. This makes the browser contact Google and transmit ordinary HTTP request data, including the IP address and user agent; Google describes this in its Google Fonts privacy explanation.
13. Who may receive data
To the extent needed for the relevant purpose, data may be available to:
- Telegram—to carry messages between you and the bot and to process them as a separate platform;
- resource and automation suppliers—the target address, resource, amount, duration, and technical fulfilment parameters;
- the AML provider—the address or transaction hash and parameters of the requested check;
- an API partner—results and statuses of requests made with that partner's service-account key;
- TRON nodes and data services—public queries used to detect transfers and check resources, balances, and receipts;
- infrastructure providers—hosting, database, backup, traffic delivery, monitoring, and protection;
- authorised personnel and contractors—within their role for support, financial reconciliation, security, or development;
- professional advisers and public authorities—where reasonably needed to protect claims or required by law.
We limit disclosures to their purpose. A rental supplier does not need and is not ordinarily given your Telegram ID, name, username, internal balance, or other-order history. The particular recipients can change with our supplier cascade and infrastructure; information that applicable law requires to be more specific can be requested from support.
14. Processing and transfers in other countries
Telegram, blockchain infrastructure, suppliers, and technical contractors may be located or process data outside your country. Public TRON transactions are inherently available to a global node network; no single operator controls that availability.
Where applicable law requires a specific basis or safeguard for an international transfer, we use an available lawful mechanism appropriate to the recipient and purpose: an adequacy decision, contractual or other recognised safeguards, or a statutory exception for a particular transfer. You may ask support for information about safeguards applying to a particular recipient where the law gives you that right.
15. How long we retain data
We do not apply one number to all data. Retention periods and criteria follow the purpose. Data should not be retained longer than necessary, but a financial record cannot be erased in the same way or at the same time as an optional preference.
- Profile and settings
- While the account is active and then for the period needed to close the relationship, process a request, and prevent repeated abuse.
- Orders and finances
- While needed for balances, fulfilment, refunds, and disputes, and then within mandatory accounting, tax, fraud-prevention, and limitation periods.
- AML
- While the requested result remains available and then as reasonably needed to evidence the service, manage risk, and meet mandatory compliance.
- API and security
- Operational records are kept for a short working period; events linked to a money operation, attack, restriction, or dispute are kept longer while needed for investigation and claims.
- Broadcasts
- Drafts and campaign outcomes are retained while needed to control delivery, frequency, opt-outs, and audit; a marketing opt-out is kept so contact does not restart.
- Backups
- Data removed from an active database may temporarily remain until protected backup rotation and is used only for disaster recovery.
- Blockchain
- Records on the public network are retained under TRON's rules, not our retention schedule.
Exact mandatory periods depend on the Operator's jurisdiction, record type, and whether a dispute or legal hold exists. On request, we will identify the criterion applied to a particular category where required by law.
16. How we protect data
We use organisational and technical safeguards proportionate to risk, including:
- encrypted connections to public interfaces and restricted direct access to internal services;
- controlled administration access, separate accounts, a second factor, and an action log;
- password and API-key hashing, protection of service secrets, and key rotation;
- separate database privileges, input validation, rate limits, and optional API IP whitelisting;
- backups, monitoring, financial invariants, and exclusion of secrets from ordinary logs and alerts.
No system or communication channel is perfectly secure. You are responsible for your Telegram account, device, and API key. If you suspect unauthorised access, immediately revoke or rotate the key, secure Telegram, and contact us through the official channel.
17. Settings you control
- You can separately disable marketing and product messages in the bot profile.
- You can manage low-balance alerts and API-operation notifications in the relevant settings.
- You can avoid saving an address and delete a previously stored label.
- You can enable or clear the IP whitelist and rotate an API key that may have been exposed.
- You can pause or remove an automated service through its interface; records of charges already made are retained separately.
- You can stop using the bot and make a data request under section 18.
Withdrawal of consent or disabling an optional feature operates for the future. It does not make prior processing unlawful or remove another valid ground for retaining a mandatory record.
18. Your rights and how to make a request
To the extent provided by applicable law, you may request:
- confirmation of processing, access, and a copy of data relating to you;
- correction of inaccurate or completion of incomplete data;
- erasure or restriction of processing;
- an objection to processing based on legitimate interests, and an unconditional opt-out from direct marketing;
- portability of data you provided in a machine-readable form where that right applies;
- withdrawal of consent for the future;
- information about recipients and international-transfer safeguards where the law provides it;
- a complaint to a competent supervisory authority or court.
Send a request through the contact in section 24, preferably from the Telegram account concerned. To avoid giving financial history to an impostor, we may reasonably verify control of the Telegram account, API key, deposit address, or another linked record. We respond without undue delay and within the period set by applicable law.
A right may be subject to exceptions: for example, we cannot disclose another person's data or an active security secret, or erase a record the law requires us to keep. In that case we will explain the basis for the refusal or limit to the permitted extent and identify available appeal routes.
19. What happens when an account is deleted
A deletion request does not mean immediate physical erasure of every row. We first review active orders, subscriptions, balances, unresolved top-ups, refunds, and disputes. Optional data is erased or anonymised when no lawful ground remains.
We may retain the minimum necessary data when it is needed:
- for financial, tax, or other mandatory records;
- to complete an unresolved operation or refund;
- to prevent fraud or repeated registration by a blocked abuser and to protect users;
- to establish, exercise, or defend legal claims;
- to preserve audit and balance integrity without further use for incompatible purposes.
We may separate such a record from the active profile and restrict access if full erasure is not yet possible. We cannot erase information from the public blockchain, Telegram systems, or an independent recipient; requests to those recipients follow their policies unless the law requires us to pass a request on for you.
20. Automated processing and segmentation
Prices are calculated, balances checked, available suppliers selected, limits enforced, and statuses and refunds controlled automatically. These rules use service parameters and technical state rather than a hidden evaluation of your personality.
AML scores are produced by a third-party provider's algorithms from blockchain links. They are informational signals, not final legal decisions. Broadcasts may be segmented by language, registration, balance, and usage history, always subject to your message preferences.
We do not use these processes for a solely automated decision that by itself creates legal or similarly significant effects for a user. A technical or risk safeguard may temporarily stop an operation; you can contest it through support and ask for human review.
21. Children
The service is not directed to anyone who cannot independently enter the relevant agreement or use cryptoassets under applicable law. We do not knowingly collect age or children's data for marketing. If you believe a child supplied data without proper permission, contact support: we will restrict the account and handle the data as applicable law requires, retaining only mandatory records.
22. Lawful disclosures and business changes
We may preserve or disclose data where we believe in good faith that this is necessary to comply with a mandatory and legally valid request, protect users, investigate fraud, prevent a security threat, or establish and defend legal claims. We assess authority and scope and, where permitted and reasonable, limit disclosure to what is necessary.
If the service is reorganised, sold, or transferred, data may pass to a successor as part of the operating product, subject to confidentiality and compatible-purpose restrictions. Where required by law, we will give advance notice and an available choice.
23. Changes to this policy
We update this policy when the product, data, recipients, law, or safeguards change. A new version takes effect on the publication date shown above. A material change that noticeably affects rights or use of data will also be communicated through an available channel where possible or required.
We do not use existing data for a new incompatible purpose merely because the wording has changed. If the new purpose requires consent or another separate ground, it will be obtained before that processing begins.
24. Contact and language
For privacy, security, access, correction, or erasure requests, use the official channel below. Do not send a seed phrase, private key, password, 2FA code, or full API key, even to a support representative.
Data controller: operator of the re-energy service
Requests and support: @mark_pm_fintech on Telegram
Website: re-energy.online
Related terms: Terms of Service
The Russian and English versions have the same structure. If they differ, the Russian version prevails unless mandatory law requires otherwise.