Skip to content

LEGAL

Privacy Policy

How we collect, use, share, and protect personal data, and the rights you have over it.

Effective date: 5 August 2026

This Privacy Policy explains how Tokelia LLC ("Tokelia", "we", "us"), a Delaware limited liability company with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States, registered as a Money Services Business with the U.S. Financial Crimes Enforcement Network (MSB registration no. 31000337250402) and with its declared place of business in the State of Montana, processes personal data when you visit our websites, use our dashboards and APIs, or otherwise interact with us. It also describes your rights under laws such as the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the CPRA.

1. Who we are

Tokelia LLC is the controller responsible for the personal data described in this policy, except where we act as a processor on behalf of a business customer, in which case that customer is the controller and its own privacy notice applies. For business-customer processing, we handle personal data under a data processing agreement and only on documented instructions.

2. Personal data we collect

Depending on how you interact with us, we may collect: identity and contact data (such as name, company, email, and phone); account and credential data; verification data required for compliance (such as identifiers and documents used for KYC); transaction and usage metadata; device, log, and approximate location data; communications you send us; and information collected through cookies and similar technologies. We do not seek to collect special-category data unless required by law and with an appropriate basis.

3. How we collect it

We collect personal data directly from you when you contact us, request a demo, create an account, or use the Services; automatically through your use of our sites and APIs, using cookies and similar technologies; and from third parties such as identity-verification providers, our financial-institution partners, fraud and sanctions-screening services, and publicly available sources, where permitted by law.

4. How we use personal data and our legal bases

We use personal data to provide, operate, and secure the Services; to verify identity and meet KYC, AML, sanctions, and travel-rule obligations; to prevent fraud and abuse; to communicate with you and provide support; to improve and develop our products; and to comply with legal obligations. Where GDPR applies, our legal bases are performance of a contract, compliance with a legal obligation, our legitimate interests (balanced against your rights), and, where required, your consent.

5. Automated decision-making

Tokelia and our licensed financial-institution partners use automated processing, including tools operated by our third-party KYC provider, to verify your identity, meet KYC and AML requirements, screen for fraud and sanctions, and calculate risk scores. Some of these processes may be fully or partly automated. Where required by law, including under Article 22 of the GDPR, you may request human review of, and may contest, a decision based solely on automated processing that produces legal or similarly significant effects concerning you. To make such a request, contact us at [email protected].

6. How we share personal data

We may share personal data with service providers and processors acting on our behalf, including Cloudflare (hosting, security, and content delivery), Google (analytics through Google Analytics 4 and Google Tag Manager, only after you consent), and our third-party KYC provider (identity verification); with financial-institution and payment-network partners that deliver the regulated parts of the Services; with fraud and compliance vendors; with regulators, law-enforcement, and other authorities where legally required; with professional advisers; and with acquirers or successors in a corporate transaction. Tokelia does not sell your personal information, and we do not share it for cross-context behavioral advertising. We require third parties to protect personal data and to use it only for the agreed purposes.

7. International transfers

We may transfer personal data to countries other than where you are located, including the United States, where providers such as Cloudflare, Google, and our KYC provider process data on our behalf. Where we transfer personal data out of the European Economic Area, the United Kingdom, or other regions with transfer restrictions, we rely on Standard Contractual Clauses approved by the European Commission, together with supplementary measures where needed. We do not currently hold a Data Privacy Framework certification for these transfers.

8. Data retention

We keep personal data for as long as necessary for the purposes described in this policy. In particular: we retain KYC/AML and transaction records for at least five (5) years after the end of our relationship with you, or longer where applicable law requires; we retain account data for the life of your account plus any additional period required by applicable legal, accounting, or regulatory obligations; we retain security logs for approximately twelve (12) months; and we retain marketing data until you opt out. When data is no longer needed, we delete or anonymize it.

9. Security

We maintain technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, least-privilege practices, monitoring, and incident-response procedures. No system is perfectly secure, but we work to protect your data and to notify you and the authorities of significant incidents where required by law.

10. Categories of personal information (California)

For purposes of the California Consumer Privacy Act, as amended by the CPRA, the personal information described in this policy generally falls into the following statutory categories: identifiers (such as name, email, and account identifiers); commercial information (such as transaction history); internet or other electronic network activity (such as usage and log data); geolocation data (approximate location); biometric information (collected by our third-party KYC provider during identity verification); professional, employment-related, or financial information (such as company and account details); and inferences drawn from the categories above to reflect preferences or characteristics relevant to providing the Services.

11. Sensitive personal information

During identity verification, our third-party KYC provider may collect biometric information, such as a facial scan or liveness selfie, and compare it against your identity documents. We use this sensitive personal information only to verify your identity and prevent fraud, and not to infer characteristics about you such as race, health, or other protected attributes. Where the law provides this right, you may request that we limit the use of your sensitive personal information to what is necessary to provide the Services.

12. Your rights

Subject to applicable law, you may have the right to access your personal data, to correct or delete it, to restrict or object to certain processing, to data portability, and to withdraw consent where processing is based on consent. If you are located in the EU or UK, you may lodge a complaint with your local data protection supervisory authority. Under the CCPA/CPRA, California residents may request to know, delete, and correct personal information, and not be discriminated against for exercising these rights. As described above, Tokelia does not sell personal information and does not share it for cross-context behavioral advertising, so there is no sale or sharing for you to opt out of.

13. How to exercise your rights

You can exercise your rights through our contact page or by emailing [email protected]. We aim to respond within the timeframes required by applicable law, for example within thirty (30) days under the GDPR and forty-five (45) days under the CCPA/CPRA, in each case subject to extension where the law permits. We may need to verify your identity before acting on a request, and in some cases we may be unable to fully comply, for example where retention is legally required. You may use an authorized agent where the law permits.

14. Cookies and similar technologies

We use cookies and similar technologies to run our sites, remember preferences, and understand usage. You can control non-essential cookies through our consent tools and your browser settings. See our Cookie Policy for details on the categories we use and how to manage them.

15. Children's privacy

The Services are intended for businesses and adults. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

16. Third-party links

Our sites and documentation may link to third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we encourage you to review them. We are not responsible for the content or privacy practices of third parties.

17. EU/UK representative and Data Protection Officer

Tokelia has not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR, nor a Data Protection Officer, at this time. If you have questions about this policy or wish to exercise your rights, you can contact us at [email protected].

18. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or the law. We will post the updated version with a new effective date and, where changes are material, provide additional notice. Your continued use of the Services after the effective date indicates your awareness of the updated policy.

19. Contact us

For privacy questions or to exercise your rights, contact us at [email protected] or through our contact page. Please identify Tokelia LLC, a Delaware limited liability company with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States, registered as a Money Services Business with FinCEN (MSB reg. no. 31000337250402) and with its declared place of business in the State of Montana, and describe your request so we can respond appropriately.

Ready to build with Tokelia?

Tell us your use case and we’ll point you to the right layer: infrastructure, tokenization or Yakopay.