Solvexa
Legal

Privacy Policy

How we collect, use, store and share personal data in the course of providing B2B payment services, and what rights you have over that data.

1. Who we are

This policy describes how 3-102-968550 Sociedad de Responsabilidad Limitada ("we", "us") processes personal data. We provide crypto payment processing and related compliance services to business clients. We do not offer services to consumers and do not open accounts for individuals acting outside a business capacity.

For any question about this policy, write to legal@solvexadigital.com.

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on personal data, including collection, storage, use, disclosure and erasure.
  • Client: a business that has entered into or is negotiating an agreement with us.
  • Representative: a natural person acting for a client, such as a director, beneficial owner or technical contact.

3. Principles

We process personal data lawfully, fairly and transparently. We collect only what a defined purpose requires, keep it accurate, retain it no longer than necessary, and protect it with technical and organisational measures proportionate to the risk.

4. Categories of data we process

  • Identification data of client representatives and beneficial owners: name, date of birth, nationality, identity document details.
  • Corporate data: company name, registration details, ownership structure, licensing where applicable.
  • Contact data: business email, phone number, messenger handle, correspondence address.
  • Transaction data: payment amounts, assets, network addresses, timestamps, counterparties, and the screening results attached to them.
  • Compliance data: due diligence records, screening outcomes, sanctions and watchlist check results, alert and case history.
  • Technical data: IP address, browser and device information, and website usage records.
  • Enquiry data: whatever you choose to send through the contact form on this website.

5. Legal bases

Depending on the purpose, we rely on: performance of a contract or steps taken before entering one; compliance with a legal obligation, in particular anti-money-laundering and counter-terrorist-financing duties; our legitimate interests in operating, securing and improving the service; and, where required, consent, which you may withdraw at any time.

6. Purposes

  • Onboarding clients and verifying who we are dealing with.
  • Providing payment processing, payouts, settlement and reporting.
  • Meeting AML, sanctions and record-keeping obligations.
  • Detecting, investigating and preventing fraud and abuse.
  • Responding to enquiries and maintaining the client relationship.
  • Securing our systems and meeting our own audit obligations.

7. Sharing

We share personal data only where there is a basis to do so: with service providers acting on our instructions, including analytics, screening and infrastructure vendors; with banking and settlement partners where a transaction requires it; with competent authorities where the law requires it; and with professional advisers under a duty of confidence. We do not sell personal data.

8. International transfers

Some recipients may be located outside the jurisdiction in which the data was collected. Where that is the case, we put appropriate safeguards in place before the transfer, and we assess each recipient before engaging them. [TBD: the exact mechanism depends on the confirmed jurisdiction of establishment.]

9. Retention

We keep personal data for as long as the relationship lasts and afterwards for the period required by applicable AML and accounting rules. Compliance records are retained for the statutory minimum, which is typically several years after the relationship ends. When a retention period expires, the data is deleted or irreversibly anonymised.

10. Security

Access to personal data is limited to people who need it for their role. Data in transit is encrypted, credentials are scoped and rotatable, environments are separated, and access is logged. No system is perfectly secure, and we do not claim otherwise; we do commit to acting promptly and transparently if an incident affects you.

11. Cookies

This website uses only what it needs to function. We do not run advertising trackers or profile visitors across sites. Where any analytics is added later, this section will be updated before it goes live.

12. Your rights

Subject to applicable law, you may request access to your personal data, its correction or erasure, restriction of processing, portability, or object to processing based on legitimate interests. Some rights are limited where the data is held under a statutory AML obligation, in which case we will explain the limit rather than simply refuse.

To exercise a right, write to legal@solvexadigital.com. We respond within the period the applicable law allows.

13. Automated decision-making

Screening produces a risk score automatically. That score can hold a transaction for review, but a decision with a legal or similarly significant effect on a person is not taken by automated means alone: an accountable person reviews it.

14. Third-party sites

Links from this website to other services are provided for convenience. We are not responsible for their content or their privacy practices, and this policy does not apply to them.

15. Changes

We may update this policy as the service or the law changes. The current version is always the one published on this page.

16. Contact and complaints

Questions and complaints go to legal@solvexadigital.com. If you are not satisfied with our response, you may lodge a complaint with the competent supervisory authority in your jurisdiction.