Back to home

Privacy policy

This policy explains what personal data Onyx Bridge Pay Inc. collects, why we process it, who we share it with, how long we keep it, and the rights you have under the EU and UK General Data Protection Regulation, PIPEDA and Quebec Law 25.

Effective
25 August 2026
Version
Draft 1.0 — pre-launch
Applies to
Clients, partners, visitors

Who is responsible for your data

Onyx Bridge Pay Inc., of 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada, is the controller of the personal data described in this policy. We decide why and how your data is processed, and we are accountable for it.

Data protection officer
Our DPO oversees compliance with this policy and can be reached at dpo@onyxbridgepay.com. You may contact the DPO directly about any aspect of how we handle your data.
EU / UK representative (GDPR Article 27)
Because we offer services to individuals in the European Economic Area and the United Kingdom from outside those territories, we have appointed a representative you can contact instead of us at eu-representative@onyxbridgepay.com.
General privacy enquiries
Write to privacy@onyxbridgepay.com for anything relating to your data or your rights.

Where you use a service under a White Label partner brand, that partner is normally the controller for its own client relationship and we act as processor for the platform services we provide to it. In that case the partner privacy notice applies alongside this one, and the partner is your first point of contact.

Scope of this policy

This policy covers personal data we process when you visit our website, apply for an account, use our accounts, payment, exchange or card services, contact our support or compliance teams, apply for a partnership, or otherwise interact with us.

It does not cover the practices of third parties whose own services you choose to use, such as a merchant you pay, a bank that holds your other accounts, or a website we link to. Those organisations have their own privacy notices.

Personal data we collect

Data you give us

  • Identity data: full name, date and place of birth, nationality, gender where shown on an identity document, government identifier such as passport, national ID or driving licence number, and photographs of your documents.
  • Contact data: residential and correspondence address, email address, telephone number.
  • Verification data: selfie or video used for a liveness check, signature, proof of address documents, tax residence and tax identification number.
  • Financial and compliance data: source of funds, source of wealth, employment or business activity, expected transaction volumes, ownership and control structure, politically exposed person status.
  • Account and transaction data: balances, payment instructions, beneficiary details, payment references, currency conversions, card transactions and merchant details.
  • Correspondence: messages, support tickets, complaint records and, where we tell you in advance, call recordings.
  • Partner data: for business applications, information about directors, authorised signatories and beneficial owners.

Data we collect automatically

  • Device and technical data: IP address, device identifiers, operating system, browser type and version, language and time zone settings.
  • Usage data: pages and screens viewed, features used, session duration, referring URLs and interaction events.
  • Security and fraud signals: login times and locations, authentication events, device fingerprint and behavioural indicators used to detect account takeover.

Data we obtain from others

  • Identity verification and document authentication providers.
  • Credit reference and identity database providers, where permitted for verification and fraud prevention.
  • Sanctions, politically exposed person and adverse media screening providers.
  • Blockchain analytics providers, in relation to digital asset addresses involved in your transactions.
  • Company registries, regulators and publicly available sources.
  • Your White Label partner or employer, where they onboarded you to a service we operate.

Our legitimate interests

Where we rely on legitimate interests, we carry out and document a balancing assessment to confirm that our interest does not override your rights and freedoms. Our interests include protecting clients and the platform from fraud and abuse, maintaining security and service continuity, understanding how our products are used so we can improve them, and defending our legal position.

You may object to processing based on legitimate interests at any time by writing to privacy@onyxbridgepay.com. We will stop unless we can show compelling grounds to continue, and we will always stop direct marketing on request.

Automated decision-making and profiling

We use automated systems to make our compliance and fraud controls effective and consistent. These include identity and document matching, sanctions and PEP name screening, risk scoring at onboarding, transaction monitoring rules and fraud models, and blockchain address screening.

Some of these can produce a decision with a significant effect on you, such as declining an application, blocking a transaction or restricting an account. Where that happens, the logic is based on the risk factors described in our AML policy, and the consequence is a delay, refusal or restriction of service.

Who we share your data with

We share personal data only where there is a lawful reason to do so, with:

  • Banking and payment partners, correspondent banks, card issuers, card schemes and acquirers, to execute your transactions.
  • Identity verification, document authentication, sanctions screening and adverse media providers, to meet our verification duties.
  • Fraud prevention and blockchain analytics providers, to protect you and the platform.
  • Cloud hosting, data storage, logging, communications and customer support platforms that operate our infrastructure under contract.
  • Professional advisers, including lawyers, auditors, insurers and independent reviewers, bound by duties of confidentiality.
  • Regulators, financial intelligence units, tax authorities, law enforcement and courts, where we are legally required or permitted to disclose.
  • A White Label partner, where you are its client and the disclosure is necessary to operate its service.
  • An acquirer or successor, if we sell or reorganise part of our business, subject to equivalent protection for your data.

Every processor acts on our documented instructions under a written data processing agreement containing the GDPR Article 28 terms, including confidentiality, security, sub-processor control, assistance with data subject rights and deletion or return of data at the end of the engagement. We do not sell your personal data and we do not share it with advertising networks for their own purposes.

A current list of the categories of processors and the countries they operate from is available on request from privacy@onyxbridgepay.com.

International transfers

We are established in Canada and use service providers in Canada, the European Economic Area, the United Kingdom and the United States. This means your data may be transferred outside your own country.

  • For transfers to Canada, the European Commission adequacy decision covering Canadian commercial organisations subject to PIPEDA applies to much of our processing.
  • Where adequacy does not apply, we use the European Commission Standard Contractual Clauses, and the UK International Data Transfer Addendum for UK transfers.
  • We complete a transfer impact assessment for each such transfer, considering the laws of the destination country and the risk of government access.
  • We apply supplementary safeguards, including encryption in transit and at rest, strict access control, pseudonymisation where practical, and a policy of challenging disproportionate access requests.
  • Transfers may also rely on the GDPR Article 49 derogations where a transfer is necessary to perform your contract or to establish or defend a legal claim.

You may request a copy of the safeguards in place for a specific transfer by contacting dpo@onyxbridgepay.com.

How long we keep your data

We keep personal data only as long as necessary for the purpose it was collected for, plus any period we are legally required to retain it. Financial crime legislation sets the longest of these periods.

Scroll the table sideways to see all columns

CategoryRetention periodReason
Identity and verification records5 years after the end of the relationshipPCMLTFA record-keeping requirement
Transaction records5 years from the date of the transactionAML and accounting obligations
Suspicious activity reports and supporting records5 years from the date of the reportStatutory retention duty
Accounting and tax records6 to 7 years depending on jurisdictionTax and corporate law
Complaint files6 years from resolutionLimitation periods and regulatory review
Card dispute and chargeback records18 months from the transactionCard scheme rules
Support correspondence3 years from last contactService quality and dispute defence
Call recordings, where made12 monthsQuality assurance and dispute resolution
Marketing consent recordsDuration of consent plus 3 yearsEvidence that consent was valid
Website analyticsUp to 14 monthsCookie lifetime limits
Declined applications5 years from the decisionDemonstrating why the decision was made

When a retention period ends we delete or irreversibly anonymise the data. Where deletion is not technically possible in backups, we isolate the data and delete it in the ordinary backup cycle.

Your rights

Subject to the conditions in applicable law, you have the following rights over your personal data:

Access (Article 15)
Obtain confirmation of whether we process your data, a copy of it, and information about the purposes, recipients, retention and safeguards.
Rectification (Article 16)
Have inaccurate data corrected and incomplete data completed.
Erasure (Article 17)
Have your data deleted where it is no longer necessary, where you withdraw consent, or where you successfully object. This right does not apply where we must keep the data by law, which is generally the case for AML and transaction records.
Restriction (Article 18)
Ask us to limit processing while a dispute about accuracy or our legal grounds is resolved.
Portability (Article 20)
Receive the data you provided to us, and that we process by automated means on the basis of consent or contract, in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
Objection (Article 21)
Object to processing based on legitimate interests, and object at any time and without reason to direct marketing.
Withdraw consent (Article 7)
Withdraw consent at any time where we rely on it, including for the biometric liveness check and for non-essential cookies.
Human intervention (Article 22)
Obtain human review of a solely automated decision with a significant effect on you, and contest the outcome.
Complain (Article 77)
Lodge a complaint with a supervisory authority, as described below.

How to exercise your rights

Send your request to privacy@onyxbridgepay.com or to our DPO at dpo@onyxbridgepay.com. We respond within one month, and may extend by up to two further months for complex requests, telling you why within the first month. Exercising your rights is free, though we may charge a reasonable fee for manifestly excessive or repetitive requests. We may ask for information to confirm your identity before we act, so that we do not disclose your data to someone else.

Supervisory authorities

  • In the EEA: the data protection authority of your country of residence, place of work, or where the alleged infringement occurred.
  • In the United Kingdom: the Information Commissioner’s Office (ICO).
  • In Canada: the Office of the Privacy Commissioner of Canada, and the Commission d’accès à l’information du Québec for Quebec residents.

We would always prefer the chance to resolve a concern first, but you are not required to come to us before contacting a regulator.

Cookies and similar technologies

We use cookies and similar technologies on our website and in our applications. Strictly necessary cookies, which support security, authentication, load balancing and your consent choices, are set without consent because the service cannot function without them.

  • Functional cookies remember preferences such as language and layout.
  • Analytics cookies help us understand aggregate usage so we can improve the product.
  • Fraud prevention technologies fingerprint devices to detect account takeover and automated abuse.

Non-essential cookies are set only after you consent through our banner, where accepting and rejecting are presented as equally prominent choices. You can change or withdraw your choice at any time through the cookie settings link in the website footer, and you can also block cookies in your browser, though this may affect functionality.

How we protect your data

We implement technical and organisational measures appropriate to the risk, as required by GDPR Article 32. These include encryption of data in transit and at rest, network segmentation, least-privilege and role-based access control, multi-factor authentication for staff, key management, secure development practices, code review, vulnerability scanning, independent penetration testing, continuous logging and monitoring, tested backups, and mandatory staff confidentiality and security training.

We maintain an incident response plan. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it. Where the risk is high, we also notify affected individuals without undue delay, describing what happened, the likely consequences, the measures taken and what you can do to protect yourself.

You can help by using a strong unique password, enabling all available authentication factors, keeping your devices updated, and never sharing credentials or one-time codes. Report anything suspicious to security@onyxbridgepay.com.

Children

Our services are for adults. We do not knowingly offer accounts to, or collect data from, anyone under 18. If we learn that we hold data about a child, we will delete it promptly unless we are legally required to retain it. If you believe a child has provided us with data, contact us at privacy@onyxbridgepay.com.

Marketing preferences

We send marketing only where you have consented, or where you are an existing client and the message concerns similar products and applicable law permits it. Every marketing message contains a one-click unsubscribe link, and you can also manage preferences in your account settings.

Opting out of marketing does not stop service communications we must send you, such as security alerts, changes to terms, statements and regulatory notices.

Changes to this policy

We review this policy at least annually and whenever we introduce a material change to our processing. The effective date and version are shown at the top of this page, and we keep previous versions available on request.

Where a change materially affects how we use your data, we will notify you by email or through the dashboard before it takes effect, and where the change requires consent we will ask for it.

Contact us about privacy

Data protection officer
dpo@onyxbridgepay.com
Security incidents
security@onyxbridgepay.com
Postal address
Onyx Bridge Pay Inc., 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada