Data Controller
Velnix is the controller of the personal data described in this policy. Contact privacy@velnix.app for any privacy request.
Data We Process
Account data (email, display name, avatar), authentication data (hashed credentials, 2FA secrets, recovery codes), device and login metadata (IP, user-agent, timestamps), portfolio and trading data you choose to sync, compliance data (KYC/AML status, residency, date of birth), payment metadata from our payment processors, and support communications.
Legal Bases
We process personal data to (i) perform our contract with you, (ii) comply with legal obligations (including AML/CTF, sanctions and tax reporting), (iii) protect the legitimate interests of Velnix and its users (fraud prevention, security), and (iv) with your consent for marketing communications and analytics cookies.
Retention
Account and transactional records are retained for the duration of the account plus the period required by applicable regulation (typically 5 to 10 years for AML records). Login history and audit logs are retained for at least 12 months. Consent records are retained for the lifetime of the account.
Your Rights
Depending on your jurisdiction you have rights to access, rectify, erase, restrict or port your personal data, and to object to processing. Requests can be made from Settings → Privacy or by emailing privacy@velnix.app. We will respond within 30 days.
Subprocessors
We use a limited set of subprocessors (cloud hosting, database, email delivery, payment processing, AI inference, analytics). A current list is available on request from privacy@velnix.app.
International Transfers
Personal data may be processed outside your country of residence. We rely on Standard Contractual Clauses or equivalent safeguards for transfers out of the EEA / UK.
Security
We apply encryption in transit and at rest, least-privilege access, immutable audit logging, and continuous monitoring. No system is fully immune to breach; incidents affecting you will be notified without undue delay.