Draft, pending legal review.
This document has been prepared for review by Canadian financial services counsel and is not yet in force. Items in square brackets are unconfirmed and must not be relied upon. It will be published with a version and an effective date before the service accepts customers.
1. Who we are and what this policy covers
[LEGAL ENTITY NAME], trading as Nomos Pay ("Nomos Pay", "we", "us"), is responsible for the personal information described in this policy. Our registered office is [REGISTERED ADDRESS].
This policy applies to the personal information we handle when you visit nomos-pay.com, apply for an account, use our services, or contact us. It applies to individuals, and to the directors, officers, beneficial owners, authorised users and representatives of business customers.
Separate privacy notices may apply to services delivered by our partners. Where that is the case, we will tell you and provide a link.
2. Information you give us
- Identity information: full name, date of birth, nationality, residential address, and government identification documents.
- Verification media: a photograph of your identity document and, where required, a selfie or short video used for liveness checking.
- Contact information: email address, telephone number and postal address.
- Business information: company name, registration number, registered and trading addresses, constitutional documents, ownership and control structure, and details of directors and beneficial owners.
- Financial and risk information: source of funds, and where relevant source of wealth, expected transaction volumes, currencies and counterparties, the nature of your business activity, and tax residence.
- Account information: credentials, security settings, saved recipients, and whitelisted withdrawal addresses.
- Communications: the content of your messages to us, including support tickets, complaints and call notes.
3. Information generated by your use of the services
- Transaction information: amounts, currencies, dates, payment routes, references, counterparties and the status of each instruction.
- Digital asset information: deposit and withdrawal addresses, networks, transaction hashes, and information obtained from analysis of public blockchain records associated with your activity.
- Device and technical information: IP address, device and browser type, operating system, language, time zone and session identifiers.
- Approximate location, derived from your IP address, used to apply geographic restrictions and detect unusual access.
- Usage information: pages viewed, features used, and interactions with our website and applications.
- Cookies and similar technologies, as described in our Cookie Policy.
Blockchain records are public and permanent. Information recorded on a blockchain, including addresses and transaction data, is outside our control, cannot be altered or erased by us, and may be visible to anyone.
4. Information we receive from third parties
- Identity verification providers, who confirm your identity and check the authenticity of your documents.
- Sanctions, politically exposed person and adverse media screening providers.
- Fraud prevention and credit reference providers, where used.
- Blockchain analytics providers, who assess the risk associated with digital asset addresses and transactions.
- Banking, payment and card partners, who provide transaction and status information.
- Public registers, corporate registries and publicly available sources.
- Your representatives, where someone is authorised to act for you.
5. How we use personal information
- To open, operate, secure and administer your account.
- To deliver the services, execute your instructions, and provide statements and records.
- To verify your identity and carry out customer due diligence, including enhanced due diligence where required.
- To meet anti-money laundering, counter-terrorist financing, sanctions, record keeping and reporting obligations.
- To monitor transactions and detect, investigate and prevent fraud, financial crime and misuse of the platform.
- To maintain the security and integrity of our systems.
- To provide customer support and handle complaints.
- To understand how our services are used and to improve them.
- To send service messages, and marketing communications where we are permitted to do so and you have not opted out.
- To comply with legal obligations, respond to lawful requests, and establish, exercise or defend legal claims.
6. Our legal bases for processing
Where a privacy law that requires a legal basis applies to you, we rely on the following: performance of our contract with you, to deliver the services you have asked for; compliance with a legal obligation, in particular anti-money laundering, sanctions, reporting and record-keeping law; our legitimate interests, in operating the platform, preventing fraud and financial crime, and securing our systems; and your consent, where we ask for it, for example for certain cookies or marketing.
Where Canadian privacy law applies, we rely on your knowledge and consent, express or implied, except where the law permits or requires us to collect, use or disclose information without consent, including for the investigation of a breach of an agreement or a contravention of law, and for compliance with our obligations under anti-money laundering legislation.
You can withdraw consent where our processing depends on it, but this may mean we can no longer provide the services, and it does not affect processing we are required by law to continue.
7. Who we share personal information with
We do not sell personal information. Where we engage a service provider, we require it to protect the information and to use it only for the purposes we specify.
| Recipient | Why |
|---|---|
| Identity verification and screening providers | To verify who you are and to screen against sanctions, politically exposed person and adverse media lists |
| Blockchain analytics providers | To assess the risk associated with digital asset addresses and transactions |
| Banking and payment partners, including [APPROVED BANKING PARTNER] and [PAYMENT PARTNER] | To execute payments and hold fiat balances |
| [CARD ISSUER] | To issue and operate any card product, where applicable |
| [CUSTODY PROVIDER] | To hold and transfer digital assets |
| Technology and infrastructure providers | Hosting, communications, analytics and security services |
| Regulators, tax authorities, law enforcement and courts | Where required or permitted by law, including reports we are obliged to file |
| Professional advisers, auditors and insurers | For legal, accounting, audit and insurance purposes |
| A buyer or successor | In connection with a merger, acquisition, financing or transfer of business |
8. International transfers
Personal information may be processed in countries other than the one in which you live, including where our partners and service providers operate. Those countries may have different privacy laws, and information may become accessible to courts, law enforcement and regulators in those countries.
Where we transfer personal information across borders, we take steps required by applicable law to protect it, including contractual protections with the recipient. Details of the jurisdictions involved will be published here once our partner arrangements are confirmed.
9. How long we keep information
We keep personal information for as long as we need it for the purposes described in this policy, and for as long as we are legally required to keep it.
Anti-money laundering law requires us to retain identity records, transaction records and related compliance records for a minimum period after the end of the relationship or the date of the transaction. Where different obligations conflict, we apply the longest applicable retention period. The specific periods that apply to us will be confirmed with counsel and published here.
This means we cannot delete records that we are legally required to keep, even if you ask us to and even after your account is closed. When information is no longer required, we securely delete or anonymise it.
10. Security
We use technical and organisational measures designed to protect personal information, including encryption in transit and at rest, access controls on a least-privilege basis, logging and monitoring, and independent testing of our systems.
No system is completely secure. You play an essential part: keep your credentials confidential, enable two-factor authentication, and tell us immediately if you suspect unauthorised access. We describe our controls in more detail on our security page.
11. Your rights
Depending on where you live and which privacy law applies, you may have some or all of the following rights. Rights are subject to applicable law and to the exceptions in it, and none of them is absolute.
- Access: to ask what personal information we hold about you and to receive a copy.
- Correction: to ask us to correct information that is inaccurate or incomplete.
- Deletion: to ask us to delete information, where we are not required to keep it.
- Restriction and objection: to ask us to limit how we use information, or to object to certain uses.
- Portability: to receive certain information in a portable format, where the right applies.
- Withdrawal of consent: where our processing relies on consent.
- Complaint: to complain to us, and to the privacy regulator in your jurisdiction.
We will not be able to act on a request that would prevent us from meeting a legal obligation. In particular, we cannot delete records we are required to retain under anti-money laundering law, and we cannot disclose information where doing so would reveal that a report has been made to an authority, or would prejudice an investigation.
12. How to exercise a right
Send your request to [PRIVACY EMAIL], or write to us at [REGISTERED ADDRESS]. We will verify your identity before acting on a request, because acting on an unverified request would itself be a security risk.
We will respond within the period required by applicable law. If we cannot do what you have asked, we will explain why, unless the law prevents us from doing so.
If you are not satisfied with our response, you may complain through our Complaints Policy, and you may also complain to the privacy regulator in your jurisdiction.
13. Automated processing and screening
We use automated tools as part of identity verification, sanctions and politically exposed person screening, transaction monitoring, blockchain analytics and fraud detection. These tools may flag an account or a transaction for review, and may cause an instruction to be delayed, refused or reported.
Decisions that significantly affect you, such as declining an application or closing an account, involve human review, except where an automated decision is required or permitted by law. Where you have the right to do so, you may ask us to review such a decision by contacting [COMPLIANCE EMAIL].
14. Children
The services are not directed at children, and we do not knowingly collect personal information from anyone below the minimum age required to hold an account. If you believe a child has provided information to us, contact [PRIVACY EMAIL] and we will delete it, subject to any legal retention obligation.
15. Marketing and communications
We send service messages that are necessary to operate your account, and you cannot opt out of those while your account is open. Where we send marketing, we do so only where permitted by applicable law, including anti-spam law, and you can unsubscribe at any time using the link in the message or by contacting [SUPPORT EMAIL].
16. Third-party links and changes to this policy
Our website may link to third-party sites. We are not responsible for their privacy practices, and you should read their policies.
We may update this policy. Where a change is material we will notify you by email or through the services before it takes effect. The date at the top of this page shows when it was last updated.
Entity and contact details
These details will be completed and confirmed by counsel before publication. Where a placeholder appears below, the information has not yet been confirmed and must not be relied upon.
| Item | Detail |
|---|---|
| Legal entity | [LEGAL ENTITY NAME] |
| Trading name | Nomos Pay |
| Registered office | [REGISTERED ADDRESS] |
| Incorporation number | [INCORPORATION NUMBER] |
| FINTRAC MSB registration | [FINTRAC MSB REGISTRATION NUMBER] |
| Website | nomos-pay.com |
| General support | [SUPPORT EMAIL] |
| Legal | [LEGAL CONTACT EMAIL] |
| Privacy | [PRIVACY EMAIL] |
| Complaints | [COMPLAINTS EMAIL] |
| Compliance | [COMPLIANCE EMAIL] |
| Telephone | [PHONE NUMBER] |
| Effective date | [DATE] |
| Last updated | [DATE] |
Questions about this document, or need it for a diligence process? Contact [LEGAL CONTACT EMAIL] . To raise a formal complaint, see our complaints policy.