LEGAL
Privacy Policy
How we collect, use, share, and protect personal data, and the rights you have over it.
This Privacy Policy explains how Tokelia LLC ("Tokelia", "we", "us"), a Delaware limited liability company with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States, registered as a Money Services Business with the U.S. Financial Crimes Enforcement Network (MSB registration no. 31000337250402) and with its declared place of business in the State of Montana, processes personal data when you visit our websites, use our dashboards and APIs, or otherwise interact with us. It also describes your rights under laws such as the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA.
1. Who we are
Tokelia LLC is the controller responsible for the personal data described in this policy, except where we act as a processor on behalf of a business customer, in which case that customer is the controller and its own privacy notice applies. For business-customer processing, we handle personal data under a data processing agreement and only on documented instructions.
2. Personal data we collect
Depending on how you interact with us, we may collect: identity and contact data (such as name, company, email, and phone); account and credential data; verification data required for compliance (such as identifiers and documents used for KYC); transaction and usage metadata; device, log, and approximate location data; communications you send us; and information collected through cookies and similar technologies. We do not seek to collect special-category data unless required by law and with an appropriate basis.
3. How we collect it
We collect personal data directly from you when you contact us, request a demo, create an account, or use the Services; automatically through your use of our sites and APIs, using cookies and similar technologies; and from third parties such as identity-verification providers, our financial-institution partners, fraud and sanctions-screening services, and publicly available sources, where permitted by law.
4. How we use personal data and our legal bases
We use personal data to provide, operate, and secure the Services; to verify identity and meet KYC, AML, sanctions, and travel-rule obligations; to prevent fraud and abuse; to communicate with you and provide support; to improve and develop our products; and to comply with legal obligations. Where GDPR applies, our legal bases are performance of a contract, compliance with a legal obligation, our legitimate interests (balanced against your rights), and, where required, your consent.
5. How we share personal data
We may share personal data with service providers and processors acting on our behalf; with financial-institution and payment-network partners that deliver the regulated parts of the Services; with identity-verification, fraud, and compliance vendors; with regulators, law-enforcement, and other authorities where legally required; with professional advisers; and with acquirers or successors in a corporate transaction. We do not sell personal data for money. We require third parties to protect personal data and to use it only for the agreed purposes.
6. International transfers
We may transfer personal data to countries other than where you are located, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or other regions with transfer restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, together with supplementary measures where needed.
7. Data retention
We keep personal data for as long as necessary for the purposes described in this policy, including to provide the Services and to meet legal, accounting, and regulatory requirements. Records tied to financial-crime and recordkeeping obligations are generally retained for the periods required by applicable law. When data is no longer needed, we delete or anonymize it.
8. Security
We maintain technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, least-privilege practices, monitoring, and incident-response procedures. No system is perfectly secure, but we work to protect your data and to notify you and the authorities of significant incidents where required by law.
9. Your rights
Subject to applicable law, you may have the right to access your personal data, to correct or delete it, to restrict or object to certain processing, to data portability, and to withdraw consent where processing is based on consent. Under GDPR you may also lodge a complaint with a supervisory authority. Under the CCPA/CPRA, California residents may request to know, delete, and correct personal information, opt out of sharing for cross-context behavioral advertising, and not be discriminated against for exercising these rights.
10. How to exercise your rights
You can exercise your rights through our contact page, and we will respond within the timeframes required by law. We may need to verify your identity before acting on a request, and in some cases we may be unable to fully comply, for example where retention is legally required. You may use an authorized agent where the law permits.
11. Cookies and similar technologies
We use cookies and similar technologies to run our sites, remember preferences, and understand usage. You can control non-essential cookies through our consent tools and your browser settings. See our Cookie Policy for details on the categories we use and how to manage them.
12. Children's privacy
The Services are intended for businesses and adults. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
13. Third-party links
Our sites and documentation may link to third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we encourage you to review them. We are not responsible for the content or privacy practices of third parties.
14. Changes to this policy
We may update this policy to reflect changes in our practices, technology, or the law. We will post the updated version with a new effective date and, where changes are material, provide additional notice. Your continued use of the Services after the effective date indicates your awareness of the updated policy.
15. Contact us
For privacy questions or to exercise your rights, contact us at [email protected] or through our contact page. Please identify Tokelia LLC, a Delaware limited liability company with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States, registered as a Money Services Business with FinCEN (MSB reg. no. 31000337250402) and with its declared place of business in the State of Montana, and describe your request so we can respond appropriately.
Ready to build with Tokelia?
Tell us your use case and we’ll point you to the right layer: infrastructure, tokenization or Yakopay.