Last updated: 1 January 2026
1. Introduction
Nexbit Technologies Ltd. ("Nexbit", "we", "us") is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and applicable EU privacy laws. This Privacy Policy explains how we collect, use, and protect your information.
2. Data Controller
The data controller is Nexbit Technologies Ltd., registered in the European Union. Our Data Protection Officer can be reached at: dpo@nexbit.io
3. Data We Collect
Identity data: Full name, date of birth, nationality, government-issued ID documents (required for KYC under AMLD6).
Contact data: Email address, phone number, residential address.
Financial data: Transaction history, wallet addresses, trading activity, bank account details for fiat withdrawals.
Technical data: IP address, device identifiers, browser type, operating system, cookies, and usage logs.
Communications: Support tickets, chat messages, and email correspondence.
4. Legal Basis for Processing
Contract performance: Processing necessary to provide trading services and manage your account.
Legal obligation: KYC/AML verification required under AMLD6 and MiCA regulation.
Legitimate interests: Fraud prevention, security monitoring, and platform improvement.
Consent: Marketing communications (you may withdraw consent at any time).
5. How We Use Your Data
We use your data to: verify your identity; process transactions; comply with regulatory requirements; detect and prevent fraud; provide customer support; send service notifications; and improve our Platform.
6. Data Sharing
We do not sell your personal data. We may share data with: regulatory authorities and law enforcement when required by law; KYC/AML service providers; payment processors; cloud infrastructure providers (all within the EU/EEA or under Standard Contractual Clauses).
7. International Transfers
Your data is processed primarily within the EU/EEA. Where data is transferred outside the EU, we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Data Retention
We retain your data for as long as your account is active and for 5 years after account closure to comply with AML regulations. Transaction records are retained for 10 years as required by EU financial regulations.
9. Your Rights (GDPR)
Under the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data (subject to legal obligations); restrict processing; data portability; object to processing; and withdraw consent at any time.
To exercise your rights, contact: privacy@nexbit.io. You also have the right to lodge a complaint with your national data protection authority.
10. Cookies
We use essential cookies for platform functionality, analytical cookies to improve user experience, and (with your consent) marketing cookies. You can manage cookie preferences in your browser settings or through our Cookie Consent panel.
11. Security
We implement industry-standard security measures certified under ISO 27001 and ISO 27701, including encryption at rest and in transit, access controls, and regular security audits.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by email. The current version is always available on our Platform.
13. Contact
For privacy inquiries: privacy@nexbit.io
Data Protection Officer: dpo@nexbit.io