1. Data Controller
Nevoxe Pay, Inc. is the data controller responsible for your personal data. Our platform is operated at nevoxepay.com.
For any privacy-related inquiries, please contact our Data Protection Officer at privacy@nevoxepay.com.
2. Data We Collect
2.1 Account & Identity Data
When you register or complete KYC, we collect:
- Full legal name, date of birth, nationality
- Email address and phone number
- Government-issued identity documents (passport, national ID)
- Proof of address documents
- For businesses: company registration documents, UBO declarations, director identification
- Source of funds and source of wealth declarations
2.2 Transaction & Financial Data
- Cryptocurrency wallet addresses (sending and receiving)
- Transaction amounts, timestamps, and blockchain transaction IDs (TxIDs)
- Payment request metadata and merchant references
- Account balances and settlement records
2.3 Technical & Usage Data
- IP addresses and approximate geolocation
- Browser type, operating system, and device identifiers
- API request logs, including endpoints called, timestamps, and HTTP status codes
- Session data and authentication events (logins, OTP verifications, API key usage)
- Error logs and crash reports
2.4 Communication Data
- Support tickets and chat transcripts
- Email correspondence
- Feedback and survey responses
2.5 Data We Do Not Collect
We do not collect private keys or seed phrases. We do not store your payment card data. We do not access your external wallets beyond the on-chain transaction data visible on public blockchains.
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Account creation and authentication | Identity data, email, OTP logs |
| KYC/AML compliance screening | Identity documents, financial data, IP addresses |
| Processing payments and settlements | Wallet addresses, transaction data, account balances |
| Fraud prevention and risk management | Technical data, transaction patterns, behavioral signals |
| Customer support | Communication data, account data, transaction data |
| Regulatory reporting | Identity data, transaction data |
| Platform improvement and analytics | Aggregated, anonymized usage data |
| Marketing (with consent) | Email address, product usage |
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area and United Kingdom, we process your data under the following legal bases:
- Contractual necessity: Processing required to provide the Services you have requested (account management, payment processing, API access).
- Legal obligation: KYC/AML screening, transaction monitoring, sanctions checks, and regulatory reporting required by applicable law.
- Legitimate interests: Fraud prevention, platform security, internal analytics, and improving our services — balanced against your rights and freedoms.
- Consent: Marketing communications, optional analytics cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. International Data Transfers
We operate globally and may transfer your personal data to countries outside your jurisdiction, including countries that may not offer the same level of data protection as your home country.
Where transfers occur from the EEA, UK, or Switzerland, we ensure an adequate level of protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
You may request a copy of the relevant safeguards by contacting privacy@nevoxepay.com.
7. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| KYC documents & identity records | 5 years after account closure | AML regulatory requirement |
| Transaction records | 7 years | Financial reporting & tax law |
| Account data | Duration of relationship + 5 years | Legal obligation |
| API logs | 12 months | Security monitoring |
| Support tickets | 3 years | Dispute resolution |
| Marketing data (with consent) | Until consent withdrawn | Consent-based |
After retention periods expire, data is securely deleted or anonymized.
8. Security
We implement industry-standard technical and organizational security measures, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Database volume encryption (LUKS2)
- Access controls with role-based permissions and MFA enforcement
- Continuous intrusion detection and log monitoring
- Regular vulnerability assessments and penetration testing
- HashiCorp Vault for secrets management
- Segregated network architecture with firewall rules
While we take reasonable precautions, no system is completely secure. If you suspect your account has been compromised, contact us immediately at security@nevoxepay.com.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request deletion of your data where we no longer have a lawful basis to retain it. Note: data subject to legal hold (AML, tax obligations) cannot be deleted until retention periods expire.
- Portability: Receive your data in a machine-readable format and transfer it to another controller.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time.
- Lodge a Complaint: File a complaint with your local data protection authority.
To exercise any of these rights, contact privacy@nevoxepay.com. We will respond within 30 days. We may need to verify your identity before processing your request.
10. Children's Privacy
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data, we will promptly delete it. If you believe a minor has provided us data, contact privacy@nevoxepay.com.
11. Changes to This Policy
We may update this Privacy Policy periodically. For material changes, we will notify you via email or in-platform notice at least 30 days in advance. The updated policy will be effective as of the stated effective date. We encourage you to review this policy regularly.
12. Contact & Data Protection Officer
For privacy-related matters:
- DPO / Privacy Inquiries: privacy@nevoxepay.com
- Security Issues: security@nevoxepay.com
- General Support: support@nevoxepay.com
We aim to acknowledge all privacy requests within 5 business days and resolve them within 30 days.