Privacy policy
What we collect, why we collect it, who sees it and how long we keep it — in plain language, with the legal bases named.
01Who we are
Trust Base Technologies AG, Bahnhofstrasse 42, 8001 Zurich, is the controller of the personal data described here. Our Data Protection Officer can be reached at dpo@novex.io.
02What we collect
We collect only what a regulated exchange needs to operate:
- Identity data — name, date of birth, address, and the identity document and selfie you submit for verification.
- Financial data — balances, orders, fills, transfers and the bank or card details used to fund your account.
- Technical data — IP address, device fingerprint, browser and app version, and session logs used for security and fraud detection.
- Communications — support conversations, including chat transcripts and call recordings where local law permits.
We do not buy personal data from brokers, and we do not sell yours. We do not run behavioural advertising on our own properties.
03Why we process it
- To perform our contract with you — operating your account, executing orders, moving money.
- To comply with legal obligations — anti-money-laundering checks, sanctions screening, Travel Rule transfers, tax reporting.
- For our legitimate interests — fraud prevention, security monitoring, and improving the product, balanced against your rights.
- With your consent — marketing email and optional analytics, which you can withdraw at any time.
04Who we share it with
Identity verification providers, blockchain analytics providers, banking partners, cloud infrastructure providers, and regulators or law enforcement where legally compelled.
Every processor is bound by a written agreement, assessed before onboarding, and reassessed annually. The current list of sub-processors is published and versioned.
05International transfers
Data may be processed in Switzerland, the EEA, Singapore and the United States. Transfers outside the EEA rely on adequacy decisions where they exist, and on Standard Contractual Clauses with a transfer impact assessment where they do not.
06How long we keep it
- Identity documents: 90 days after a verification decision, unless retention is legally required.
- Transaction records: ten years from account closure, as required by financial regulation.
- Support conversations: three years.
- Security logs: eighteen months.
07Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or port your data, and to object to processing based on legitimate interests. Email privacy@novex.io and we will respond within 30 days.
Some rights are limited by our regulatory obligations — we generally cannot delete transaction records we are required to retain, even at your request.
08How we protect it
Encryption in transit and at rest, no standing production access, dual approval for privileged actions, and continuous monitoring. Our security model is described in more detail on the security page.