Privacy Policy
In plain language
A quick, non-binding overview. The full Policy below is what legally applies.
- Who we are. The Service is operated by VaultX Inc., a company incorporated in the Republic of Panama (the “Operator”).
- What we collect for a swap. The exchange direction and amount, your receiving wallet address, and your contact details (for example, email or a Telegram username). Email is optional and not required to use the Service.
- What we collect for verification. To meet AML law we (or a provider such as Sumsub) verify you using an identity document, a selfie with the document, source-of-funds documents, citizenship, and your address.
- Why we use it. To verify you, screen against sanctions / PEP / restricted-jurisdiction lists, check the origin of funds, prevent fraud, and comply with the law.
- How you reach us. Onboarding, verification and requests are handled by email, on the website, and via our official Telegram channel (@noctraswap). Verification runs through our KYC/KYB partner (e.g. Sumsub).
- Who we share with. Verification and sanctions-screening providers, hosting/IT providers, and professional advisors under confidentiality — only as needed.
- How long we keep it. AML records for at least 5 years after the relationship ends; other data only as long as needed.
- 18+ only, and your rights. The Service is for adults. You can ask what data we hold, correct it, or request deletion (subject to mandatory AML retention).
1. Introduction
1.1. This Privacy Policy (the “Policy”) sets forth the personal data collected, processed, and stored by the operator of the service hosted at https://noctra.io (the “Service”).
1.2. Use of the Service constitutes the User’s unconditional agreement to this Policy and to the terms regarding data collection and processing set forth herein. If the User does not agree to these terms, they must refrain from using the Service.
1.3. The processing of personal data is carried out in accordance with Law No. 81 of the Republic of Panama of 26 March 2019 on Personal Data Protection, and Executive Decree No. 285 of 28 May 2021.
1.4. By using the Service, the User confirms that they have familiarized themselves with this Policy.
2. Terms and definitions
2.1. Personal Data — any information relating directly or indirectly to a specific or identifiable natural person (the “Personal Data Subject”), including data automatically obtained by the HTTP server upon access to the Service and during the User’s subsequent actions (host IP address, type of operating system, and pages visited).
2.2. Terms of Use — the agreement between the User and the Operator governing the use of the Service, of which this Policy forms an integral part.
2.3. User (Personal Data Subject) — an individual who visits, accesses, or otherwise uses the Service, regardless of whether they actually use its functions.
2.4. Operator — VaultX Inc., a company incorporated in the Republic of Panama.
2.5. Destruction of personal data — actions resulting in the impossibility of determining the attribution of personal data to a specific Personal Data Subject without excessive financial and organizational cost.
2.6. Processing of personal data — any action or set of actions performed on personal data, whether or not by automated means, including collection, recording, systematization, accumulation, storage, updating, retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction.
3. General provisions
3.1. This Policy governs the processing of personal data when the Operator interacts with the User in connection with the User’s use of the Service.
3.2. The Policy was developed in accordance with: (a) the agreements concluded with the Operator; (b) applicable legislation, namely Law No. 81 of the Republic of Panama of 26 March 2019 and Executive Decree No. 285 of 28 May 2021; and (c) other regulatory documents reflecting modern requirements on personal data protection.
3.3. This Policy is published on the Service to ensure continuous access for Users.
4. Categories of personal data processed
4.1. Data voluntarily provided by the User
The email address is collected on a voluntary basis. The absence of an email address does not affect access to the Service.
4.2. Data required to carry out the exchange
- the exchange direction and amount;
- your Noctra ID and the registered sending wallet address used for the exchange;
- the cryptocurrency wallet address for receiving funds;
- contact email.
4.3. Data required for verification
To comply with AML legislation, the Operator performs user verification, carried out either by the Operator directly or through a third-party provider, using the following data:
- identity document;
- selfie with the identity document;
- documents confirming the source of funds;
- citizenship;
- registered address / actual residential address;
- for businesses (KYB): company registration documents, beneficial owners (UBO) and authorized signatory identification;
- the wallet address(es) you register for sending, which we pre-screen.
5. Purposes of personal data processing
5.1. Users’ personal data are processed for the following purposes:
- identification and verification of Users;
- screening against sanctions, PEP, and prohibited-jurisdiction lists;
- analysis of the origin of funds;
- prevention of fraud and misuse of the Service;
- compliance with the requirements of applicable legislation;
- preparation of reporting documents serving as the basis for financial transactions;
- fulfilling obligations under legislation on combating the legalization of proceeds obtained through criminal activity, and legislation on the prevention of corruption, fraud, terrorism, and other offenses.
5.2. The processing of personal data is limited to the achievement of specific, predetermined, and legitimate purposes. Processing incompatible with the purposes of collection is not permitted.
6. Processing methods
6.1. Onboarding, verification and exchange requests are handled through the website and by email. To exchange, the User submits a request containing their Noctra ID, a registered sending wallet and the transaction details; the desk confirms the locked rate and deposit instructions by email or via the official Telegram channel (@noctraswap).
6.2. Verification may be carried out through a third-party KYC/KYB provider (for example, Sumsub). Documents should be submitted only through the secure channels indicated by the Operator.
7. Transfer of data to third parties
7.1. The Operator may transfer data to the following categories of recipients, strictly to the extent necessary for the specified purposes:
- identity verification providers;
- sanctions screening providers;
- hosting and IT infrastructure providers;
- professional advisors (lawyers, auditors) subject to confidentiality obligations.
8. Personal data retention periods
8.1. Records of transactions and anti-money-laundering information are retained for at least five (5) years following the termination of the relationship with the User. Other data are retained no longer than necessary for the purposes of processing, after which they are deleted.
9. Destruction of personal data
9.1. The User’s personal data shall be destroyed in the following cases:
- upon achievement of the purposes of processing, or if the need to achieve them ceases — within 30 days of the date the purpose is achieved, unless otherwise provided by an agreement with the User;
- in the event of unlawful processing or lawful withdrawal of personal data — within 10 working days of discovery;
- upon expiry of the retention period determined under applicable legislation and the Operator’s internal documents, including withdrawal of consent to processing.
10. Personal information of minors
10.1. The Service is intended for individuals over the age of 18. The Operator does not knowingly collect data on individuals under the age of 18. If such data is identified, it is deleted.
11. User rights
The User has the right to:
- obtain information about the data held by the Operator and the purposes and recipients of its use;
- correct the data in the event of inaccuracies;
- request deletion of data if it is no longer needed (subject to mandatory AML retention periods);
- receive information about third parties to whom the Operator has transferred personal data.
12. Changes to this Policy
12.1. The Operator reserves the right to update this Policy.
12.2. The current version is published on the website, indicating the date of modification.
12.3. Material changes are communicated via available means. Continued use of the Service constitutes acceptance of the updated version.
13. Final provisions
13.1. The period for processing personal data corresponds to the duration of the Operator’s obligations, or continues until the User withdraws consent or the Operator ceases operations.
13.2. Consent may be withdrawn by the User or their representative by submitting a free-form written statement to the Operator, using a method that allows reliable identification of the person who signed and submitted the statement and, where applicable, verification of the representative’s authority.