Privacy policy
This policy explains what personal data Onyx Bridge Pay Inc. collects, why we process it, who we share it with, how long we keep it, and the rights you have under the EU and UK General Data Protection Regulation, PIPEDA and Quebec Law 25.
- Effective
- 25 August 2026
- Version
- Draft 1.0 — pre-launch
- Applies to
- Clients, partners, visitors
Who is responsible for your data
Onyx Bridge Pay Inc., of 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada, is the controller of the personal data described in this policy. We decide why and how your data is processed, and we are accountable for it.
- Data protection officer
- Our DPO oversees compliance with this policy and can be reached at dpo@onyxbridgepay.com. You may contact the DPO directly about any aspect of how we handle your data.
- EU / UK representative (GDPR Article 27)
- Because we offer services to individuals in the European Economic Area and the United Kingdom from outside those territories, we have appointed a representative you can contact instead of us at eu-representative@onyxbridgepay.com.
- General privacy enquiries
- Write to privacy@onyxbridgepay.com for anything relating to your data or your rights.
Where you use a service under a White Label partner brand, that partner is normally the controller for its own client relationship and we act as processor for the platform services we provide to it. In that case the partner privacy notice applies alongside this one, and the partner is your first point of contact.
Scope of this policy
This policy covers personal data we process when you visit our website, apply for an account, use our accounts, payment, exchange or card services, contact our support or compliance teams, apply for a partnership, or otherwise interact with us.
It does not cover the practices of third parties whose own services you choose to use, such as a merchant you pay, a bank that holds your other accounts, or a website we link to. Those organisations have their own privacy notices.
Personal data we collect
Data you give us
- Identity data: full name, date and place of birth, nationality, gender where shown on an identity document, government identifier such as passport, national ID or driving licence number, and photographs of your documents.
- Contact data: residential and correspondence address, email address, telephone number.
- Verification data: selfie or video used for a liveness check, signature, proof of address documents, tax residence and tax identification number.
- Financial and compliance data: source of funds, source of wealth, employment or business activity, expected transaction volumes, ownership and control structure, politically exposed person status.
- Account and transaction data: balances, payment instructions, beneficiary details, payment references, currency conversions, card transactions and merchant details.
- Correspondence: messages, support tickets, complaint records and, where we tell you in advance, call recordings.
- Partner data: for business applications, information about directors, authorised signatories and beneficial owners.
Data we collect automatically
- Device and technical data: IP address, device identifiers, operating system, browser type and version, language and time zone settings.
- Usage data: pages and screens viewed, features used, session duration, referring URLs and interaction events.
- Security and fraud signals: login times and locations, authentication events, device fingerprint and behavioural indicators used to detect account takeover.
Data we obtain from others
- Identity verification and document authentication providers.
- Credit reference and identity database providers, where permitted for verification and fraud prevention.
- Sanctions, politically exposed person and adverse media screening providers.
- Blockchain analytics providers, in relation to digital asset addresses involved in your transactions.
- Company registries, regulators and publicly available sources.
- Your White Label partner or employer, where they onboarded you to a service we operate.
Why we process your data and on what legal basis
Under GDPR Article 6 we must have a legal basis for each purpose. The table below sets out each purpose, the data involved and the basis we rely on.
Scroll the table sideways to see all columns
| Purpose | Data used | Legal basis |
|---|---|---|
| Assessing your application and opening your account | Identity, contact, verification, financial | Performance of a contract, and compliance with a legal obligation |
| Verifying your identity, including document and liveness checks | Identity, verification, biometric | Legal obligation for identity verification; explicit consent for the biometric check |
| Screening against sanctions, PEP and adverse media lists | Identity, contact, financial | Compliance with a legal obligation, and substantial public interest |
| Executing payments, conversions and card transactions | Account, transaction, contact | Performance of a contract |
| Monitoring transactions and reporting suspicious activity | Transaction, identity, device | Compliance with a legal obligation |
| Preventing, detecting and investigating fraud | Device, usage, transaction, security signals | Legitimate interests, and legal obligation |
| Providing support and handling complaints | Contact, correspondence, account | Performance of a contract, and legitimate interests |
| Securing our platform and maintaining audit trails | Device, usage, security signals | Legitimate interests, and legal obligation |
| Improving products and analysing aggregate usage | Usage, device (pseudonymised where possible) | Legitimate interests; consent for non-essential cookies |
| Sending service and regulatory notices | Contact, account | Performance of a contract, and legal obligation |
| Sending marketing about our products | Contact, usage | Consent, or legitimate interests for existing clients where permitted |
| Meeting accounting, tax and record-keeping duties | Identity, transaction, financial | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests, and legal obligation |
Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing already carried out. Where we rely on a legal obligation or contract and you decline to provide the data, we may be unable to open or continue your account.
Our legitimate interests
Where we rely on legitimate interests, we carry out and document a balancing assessment to confirm that our interest does not override your rights and freedoms. Our interests include protecting clients and the platform from fraud and abuse, maintaining security and service continuity, understanding how our products are used so we can improve them, and defending our legal position.
You may object to processing based on legitimate interests at any time by writing to privacy@onyxbridgepay.com. We will stop unless we can show compelling grounds to continue, and we will always stop direct marketing on request.
Automated decision-making and profiling
We use automated systems to make our compliance and fraud controls effective and consistent. These include identity and document matching, sanctions and PEP name screening, risk scoring at onboarding, transaction monitoring rules and fraud models, and blockchain address screening.
Some of these can produce a decision with a significant effect on you, such as declining an application, blocking a transaction or restricting an account. Where that happens, the logic is based on the risk factors described in our AML policy, and the consequence is a delay, refusal or restriction of service.
International transfers
We are established in Canada and use service providers in Canada, the European Economic Area, the United Kingdom and the United States. This means your data may be transferred outside your own country.
- For transfers to Canada, the European Commission adequacy decision covering Canadian commercial organisations subject to PIPEDA applies to much of our processing.
- Where adequacy does not apply, we use the European Commission Standard Contractual Clauses, and the UK International Data Transfer Addendum for UK transfers.
- We complete a transfer impact assessment for each such transfer, considering the laws of the destination country and the risk of government access.
- We apply supplementary safeguards, including encryption in transit and at rest, strict access control, pseudonymisation where practical, and a policy of challenging disproportionate access requests.
- Transfers may also rely on the GDPR Article 49 derogations where a transfer is necessary to perform your contract or to establish or defend a legal claim.
You may request a copy of the safeguards in place for a specific transfer by contacting dpo@onyxbridgepay.com.
How long we keep your data
We keep personal data only as long as necessary for the purpose it was collected for, plus any period we are legally required to retain it. Financial crime legislation sets the longest of these periods.
Scroll the table sideways to see all columns
| Category | Retention period | Reason |
|---|---|---|
| Identity and verification records | 5 years after the end of the relationship | PCMLTFA record-keeping requirement |
| Transaction records | 5 years from the date of the transaction | AML and accounting obligations |
| Suspicious activity reports and supporting records | 5 years from the date of the report | Statutory retention duty |
| Accounting and tax records | 6 to 7 years depending on jurisdiction | Tax and corporate law |
| Complaint files | 6 years from resolution | Limitation periods and regulatory review |
| Card dispute and chargeback records | 18 months from the transaction | Card scheme rules |
| Support correspondence | 3 years from last contact | Service quality and dispute defence |
| Call recordings, where made | 12 months | Quality assurance and dispute resolution |
| Marketing consent records | Duration of consent plus 3 years | Evidence that consent was valid |
| Website analytics | Up to 14 months | Cookie lifetime limits |
| Declined applications | 5 years from the decision | Demonstrating why the decision was made |
When a retention period ends we delete or irreversibly anonymise the data. Where deletion is not technically possible in backups, we isolate the data and delete it in the ordinary backup cycle.
Your rights
Subject to the conditions in applicable law, you have the following rights over your personal data:
- Access (Article 15)
- Obtain confirmation of whether we process your data, a copy of it, and information about the purposes, recipients, retention and safeguards.
- Rectification (Article 16)
- Have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17)
- Have your data deleted where it is no longer necessary, where you withdraw consent, or where you successfully object. This right does not apply where we must keep the data by law, which is generally the case for AML and transaction records.
- Restriction (Article 18)
- Ask us to limit processing while a dispute about accuracy or our legal grounds is resolved.
- Portability (Article 20)
- Receive the data you provided to us, and that we process by automated means on the basis of consent or contract, in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection (Article 21)
- Object to processing based on legitimate interests, and object at any time and without reason to direct marketing.
- Withdraw consent (Article 7)
- Withdraw consent at any time where we rely on it, including for the biometric liveness check and for non-essential cookies.
- Human intervention (Article 22)
- Obtain human review of a solely automated decision with a significant effect on you, and contest the outcome.
- Complain (Article 77)
- Lodge a complaint with a supervisory authority, as described below.
How to exercise your rights
Send your request to privacy@onyxbridgepay.com or to our DPO at dpo@onyxbridgepay.com. We respond within one month, and may extend by up to two further months for complex requests, telling you why within the first month. Exercising your rights is free, though we may charge a reasonable fee for manifestly excessive or repetitive requests. We may ask for information to confirm your identity before we act, so that we do not disclose your data to someone else.
Supervisory authorities
- In the EEA: the data protection authority of your country of residence, place of work, or where the alleged infringement occurred.
- In the United Kingdom: the Information Commissioner’s Office (ICO).
- In Canada: the Office of the Privacy Commissioner of Canada, and the Commission d’accès à l’information du Québec for Quebec residents.
We would always prefer the chance to resolve a concern first, but you are not required to come to us before contacting a regulator.
How we protect your data
We implement technical and organisational measures appropriate to the risk, as required by GDPR Article 32. These include encryption of data in transit and at rest, network segmentation, least-privilege and role-based access control, multi-factor authentication for staff, key management, secure development practices, code review, vulnerability scanning, independent penetration testing, continuous logging and monitoring, tested backups, and mandatory staff confidentiality and security training.
We maintain an incident response plan. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it. Where the risk is high, we also notify affected individuals without undue delay, describing what happened, the likely consequences, the measures taken and what you can do to protect yourself.
You can help by using a strong unique password, enabling all available authentication factors, keeping your devices updated, and never sharing credentials or one-time codes. Report anything suspicious to security@onyxbridgepay.com.
Children
Our services are for adults. We do not knowingly offer accounts to, or collect data from, anyone under 18. If we learn that we hold data about a child, we will delete it promptly unless we are legally required to retain it. If you believe a child has provided us with data, contact us at privacy@onyxbridgepay.com.
Marketing preferences
We send marketing only where you have consented, or where you are an existing client and the message concerns similar products and applicable law permits it. Every marketing message contains a one-click unsubscribe link, and you can also manage preferences in your account settings.
Opting out of marketing does not stop service communications we must send you, such as security alerts, changes to terms, statements and regulatory notices.
Changes to this policy
We review this policy at least annually and whenever we introduce a material change to our processing. The effective date and version are shown at the top of this page, and we keep previous versions available on request.
Where a change materially affects how we use your data, we will notify you by email or through the dashboard before it takes effect, and where the change requires consent we will ask for it.
Contact us about privacy
- Privacy team
- privacy@onyxbridgepay.com
- Data protection officer
- dpo@onyxbridgepay.com
- EU / UK representative
- eu-representative@onyxbridgepay.com
- Security incidents
- security@onyxbridgepay.com
- Postal address
- Onyx Bridge Pay Inc., 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada