Legal

Privacy policy

What personal data NioX collects, why it is processed, who it is shared with, how long it is kept and the rights available to you.

Version 1.0. Last updated 15 September 2026. This document is published in English and the English version prevails over any translation.

Version 1.0Last updated 15 September 2026Reading time about 6 minutes

In short, this notice explains what personal data NioX handles, the reasons we handle it, the people we share it with, how long we hold it, and the choices and rights you can use.

01 Who is responsible

For the personal data described in this notice, NioX acts as the controller. The full legal name of the controller, its registered office and its contact details appear on the company page.

If you have a question about this notice, or you wish to exercise one of the rights it describes, please write to our data protection team at the address shown on the contact page.

02 What personal data we collect

The categories of personal data that NioX gathers are set out in the table below.

Data typeWhat this includesWhere it comes from
IdentityYour full legal name, your date of birth, your nationality, the number and image of your identity document, and the photograph captured while you verifyProvided by you and by the verification provider
ContactYour email address, your telephone number and your home addressProvided by you
FinancialYour bank account and payment card details, your digital asset addresses, and your balances and transaction historyProvided by you and by payment providers
ActivityOrders, trades, deposits, withdrawals, staking subscriptions and card paymentsCreated as you use the service
ScreeningOutcomes of sanctions checks, politically exposed person checks, adverse media checks and blockchain analyticsSupplied by screening providers
TechnicalYour internet protocol address, device identifiers, browser type, operating system, and session and login recordsCollected from your device
UsageThe pages you view, the features you use, and the time and length of each visitCollected from your device once you allow cookies
CommunicationsYour messages to support, your complaint records, and recordings of calls where calls are recordedProvided by you

03 Why we process data and on what basis

We use personal data for the reasons set out below. Alongside each reason we state the legal basis we rely on.

Why we use itLegal basis
Setting up and running your account and delivering the exchange servicePerforming our contract with you
Confirming who you are and checking you against sanctions and politically exposed person listsMeeting a legal obligation
Watching transactions and market activity for financial crime and market abuseMeeting a legal obligation
Reporting suspicious activity to the authority that oversees itMeeting a legal obligation
Keeping records for as long as the law requiresMeeting a legal obligation
Keeping the service secure, stopping fraud and looking into incidentsOur legitimate interest in protecting the service and the people who use it
Answering your questions and dealing with complaintsPerforming our contract with you together with our legitimate interests
Understanding how the website is usedYour consent, given through the cookie banner
Sending you service messages about your accountPerforming our contract with you
Sending you marketing about NioX productsYour consent, which you can withdraw whenever you wish
Bringing, pursuing or defending legal claimsOur legitimate interest in protecting our legal position

Whenever we rely on legitimate interests we have completed a balancing assessment, and we will provide a copy if you ask.

04 Biometric data and special categories

As part of identity verification we may match a facial image against the picture on your identity document. When that comparison amounts to processing biometric data in order to identify you uniquely, we carry it out on the ground of substantial public interest in preventing and detecting financial crime, and where the law requires it we obtain your explicit consent before the check runs.

We do not set out to collect any other special category data. Should you include such data in a message, we use it only to reply to you and for no other purpose.

05 Who we share personal data with

We disclose personal data only when a lawful basis allows it, and only to the kinds of recipient listed here.

  • Providers of identity verification and screening that we engage to run the checks the law demands.
  • Payment providers, banking partners, card issuers and card scheme operators, so far as they need the data to handle a payment or to run the card.
  • Custody and blockchain analytics firms we appoint to safeguard client assets and to screen transfers.
  • Cloud hosting, communications and support suppliers that act as our processors under contract.
  • Competent authorities, law enforcement agencies, regulators and tax authorities when the law or a valid request obliges us to disclose.
  • Professional advisers, for example auditors and lawyers, who are bound by a duty of confidence.
  • A buyer or successor if the business takes part in a corporate transaction, with the same protections carried over.

We never sell personal data and we never pass it on so that a third party can use it for its own marketing.

06 Transfers across borders

Your personal data may move to a country other than the one where we collected it. If we send it to a country that has not been judged to offer an adequate level of protection, we rely on standard contractual clauses or another lawful transfer mechanism, backed by a transfer risk assessment. We will share a copy of the mechanism we use if you ask.

07 How long we keep data

We hold personal data only for as long as the purpose it was gathered for requires, and never for less than the minimum periods that the law sets.

What we keepHow long we keep it
Identification and verification recordsNo less than five years after the business relationship ends
Transaction records covering orders, trades and fundingNo less than five years after the transaction
Suspicious activity reports and their supporting recordsNo less than five years after the report
Support messages and complaint recordsSix years after the matter closes
Technical and security logsTwelve months, unless kept longer for an investigation
Marketing consent recordsUntil you withdraw consent and then for a further two years

If a legal obligation, a regulatory request or a live claim calls for a longer period, we keep the records until that need comes to an end.

08 Your rights

So far as the law that applies allows, you hold the rights below.

  • The right to be told how your personal data is handled, which is what this notice provides.
  • The right to obtain a copy of the personal data we hold about you.
  • The right to have any inaccurate personal data put right.
  • The right to have data erased once it is no longer needed and no legal obligation requires us to keep it.
  • The right to have processing paused while we look at an objection or a correction.
  • The right to portability of the data you gave us that we process by automated means under consent or contract.
  • The right to object to any processing that we base on legitimate interests.
  • The right to withdraw consent at any moment where consent is the basis, which does not undo processing already carried out beforehand.
  • The right not to face a decision taken purely by automated processing that carries a legal or similarly significant effect, except where the law permits such a decision.
  • The right to lodge a complaint with a supervisory authority.

We reply to a request within one month of receiving it. If a request is complex, or if you make several at once, we may add up to two further months, and we will tell you about the extension and the reason for it within that first month. We charge no fee unless a request is plainly unfounded or excessive.

09 Decisions made by automation

We use automated screening within identity verification, sanctions screening and transaction monitoring. On its own, an alert raised by an automated process settles nothing. Before it takes effect, a decision to turn down an application, to block a transaction or to close an account is reviewed by a member of the compliance team, unless the law calls for an immediate block.

When a decision affects you, you can ask us to review it and you can put forward your point of view. We may hold back some information where sharing it would harm the prevention or detection of financial crime.

10 How we keep data secure

We apply technical and organisational measures to protect personal data. These include encryption while data moves and while it is stored, access granted on a least privilege footing, production environments kept apart, logging and monitoring, and training for our staff.

If a personal data breach is likely to put the rights and freedoms of individuals at risk, we report it to the supervisory authority without undue delay, and where the risk is high we also tell the people affected.

11 Cookies

We explain cookies and similar technologies in the cookie policy. The only cookies we set without your consent are the strictly necessary ones.

12 Updates to this policy

We may revise this notice from time to time. You will find the version number and the date of the latest update at the top of this page. When a change is significant, we give notice before it takes effect.