In short, this notice explains what personal data NioX handles, the reasons we handle it, the people we share it with, how long we hold it, and the choices and rights you can use.
01 Who is responsible
For the personal data described in this notice, NioX acts as the controller. The full legal name of the controller, its registered office and its contact details appear on the company page.
If you have a question about this notice, or you wish to exercise one of the rights it describes, please write to our data protection team at the address shown on the contact page.
02 What personal data we collect
The categories of personal data that NioX gathers are set out in the table below.
| Data type | What this includes | Where it comes from |
|---|---|---|
| Identity | Your full legal name, your date of birth, your nationality, the number and image of your identity document, and the photograph captured while you verify | Provided by you and by the verification provider |
| Contact | Your email address, your telephone number and your home address | Provided by you |
| Financial | Your bank account and payment card details, your digital asset addresses, and your balances and transaction history | Provided by you and by payment providers |
| Activity | Orders, trades, deposits, withdrawals, staking subscriptions and card payments | Created as you use the service |
| Screening | Outcomes of sanctions checks, politically exposed person checks, adverse media checks and blockchain analytics | Supplied by screening providers |
| Technical | Your internet protocol address, device identifiers, browser type, operating system, and session and login records | Collected from your device |
| Usage | The pages you view, the features you use, and the time and length of each visit | Collected from your device once you allow cookies |
| Communications | Your messages to support, your complaint records, and recordings of calls where calls are recorded | Provided by you |
03 Why we process data and on what basis
We use personal data for the reasons set out below. Alongside each reason we state the legal basis we rely on.
| Why we use it | Legal basis |
|---|---|
| Setting up and running your account and delivering the exchange service | Performing our contract with you |
| Confirming who you are and checking you against sanctions and politically exposed person lists | Meeting a legal obligation |
| Watching transactions and market activity for financial crime and market abuse | Meeting a legal obligation |
| Reporting suspicious activity to the authority that oversees it | Meeting a legal obligation |
| Keeping records for as long as the law requires | Meeting a legal obligation |
| Keeping the service secure, stopping fraud and looking into incidents | Our legitimate interest in protecting the service and the people who use it |
| Answering your questions and dealing with complaints | Performing our contract with you together with our legitimate interests |
| Understanding how the website is used | Your consent, given through the cookie banner |
| Sending you service messages about your account | Performing our contract with you |
| Sending you marketing about NioX products | Your consent, which you can withdraw whenever you wish |
| Bringing, pursuing or defending legal claims | Our legitimate interest in protecting our legal position |
Whenever we rely on legitimate interests we have completed a balancing assessment, and we will provide a copy if you ask.
04 Biometric data and special categories
As part of identity verification we may match a facial image against the picture on your identity document. When that comparison amounts to processing biometric data in order to identify you uniquely, we carry it out on the ground of substantial public interest in preventing and detecting financial crime, and where the law requires it we obtain your explicit consent before the check runs.
We do not set out to collect any other special category data. Should you include such data in a message, we use it only to reply to you and for no other purpose.
05 Who we share personal data with
We disclose personal data only when a lawful basis allows it, and only to the kinds of recipient listed here.
- Providers of identity verification and screening that we engage to run the checks the law demands.
- Payment providers, banking partners, card issuers and card scheme operators, so far as they need the data to handle a payment or to run the card.
- Custody and blockchain analytics firms we appoint to safeguard client assets and to screen transfers.
- Cloud hosting, communications and support suppliers that act as our processors under contract.
- Competent authorities, law enforcement agencies, regulators and tax authorities when the law or a valid request obliges us to disclose.
- Professional advisers, for example auditors and lawyers, who are bound by a duty of confidence.
- A buyer or successor if the business takes part in a corporate transaction, with the same protections carried over.
We never sell personal data and we never pass it on so that a third party can use it for its own marketing.
06 Transfers across borders
Your personal data may move to a country other than the one where we collected it. If we send it to a country that has not been judged to offer an adequate level of protection, we rely on standard contractual clauses or another lawful transfer mechanism, backed by a transfer risk assessment. We will share a copy of the mechanism we use if you ask.
07 How long we keep data
We hold personal data only for as long as the purpose it was gathered for requires, and never for less than the minimum periods that the law sets.
| What we keep | How long we keep it |
|---|---|
| Identification and verification records | No less than five years after the business relationship ends |
| Transaction records covering orders, trades and funding | No less than five years after the transaction |
| Suspicious activity reports and their supporting records | No less than five years after the report |
| Support messages and complaint records | Six years after the matter closes |
| Technical and security logs | Twelve months, unless kept longer for an investigation |
| Marketing consent records | Until you withdraw consent and then for a further two years |
If a legal obligation, a regulatory request or a live claim calls for a longer period, we keep the records until that need comes to an end.
08 Your rights
So far as the law that applies allows, you hold the rights below.
- The right to be told how your personal data is handled, which is what this notice provides.
- The right to obtain a copy of the personal data we hold about you.
- The right to have any inaccurate personal data put right.
- The right to have data erased once it is no longer needed and no legal obligation requires us to keep it.
- The right to have processing paused while we look at an objection or a correction.
- The right to portability of the data you gave us that we process by automated means under consent or contract.
- The right to object to any processing that we base on legitimate interests.
- The right to withdraw consent at any moment where consent is the basis, which does not undo processing already carried out beforehand.
- The right not to face a decision taken purely by automated processing that carries a legal or similarly significant effect, except where the law permits such a decision.
- The right to lodge a complaint with a supervisory authority.
We reply to a request within one month of receiving it. If a request is complex, or if you make several at once, we may add up to two further months, and we will tell you about the extension and the reason for it within that first month. We charge no fee unless a request is plainly unfounded or excessive.
09 Decisions made by automation
We use automated screening within identity verification, sanctions screening and transaction monitoring. On its own, an alert raised by an automated process settles nothing. Before it takes effect, a decision to turn down an application, to block a transaction or to close an account is reviewed by a member of the compliance team, unless the law calls for an immediate block.
When a decision affects you, you can ask us to review it and you can put forward your point of view. We may hold back some information where sharing it would harm the prevention or detection of financial crime.
10 How we keep data secure
We apply technical and organisational measures to protect personal data. These include encryption while data moves and while it is stored, access granted on a least privilege footing, production environments kept apart, logging and monitoring, and training for our staff.
If a personal data breach is likely to put the rights and freedoms of individuals at risk, we report it to the supervisory authority without undue delay, and where the risk is high we also tell the people affected.
11 Cookies
We explain cookies and similar technologies in the cookie policy. The only cookies we set without your consent are the strictly necessary ones.
12 Updates to this policy
We may revise this notice from time to time. You will find the version number and the date of the latest update at the top of this page. When a change is significant, we give notice before it takes effect.