Vortex Privacy Policy
Last updated: 28 September 2025
Version: 1.0
This Privacy Policy explains how Vortex (a brand operated by SatoshiPay Ltd) collects and processes personal data when you use our websites, apps, widgets, and related services (collectively, the "Services"). It replaces earlier versions and will be updated as our Services evolve.
1. Who we are (Controller)
Controller: SatoshiPay Ltd (trading as "Vortex")
Registered office:
Hill Dickinson Llp
The Broadgate Tower
20 Primrose Street
London, EC2A 2EW United Kingdom
Contact: privacy@vortexfinance.co
SatoshiPay operates Vortex's web/app frontends and determines the purposes and means of processing personal data for the Services described here.
Independent controllers (local partners). For on-/off-ramping, we work with licensed local payment partners who act as independent controllers for their own onboarding (e.g., KYC/KYB), fiat accounts, and payouts. See Section 7 for the current partner list and links to their policies.
Processors. We also use vetted vendors (e.g., cloud hosting, analytics) as processors under data processing agreements. See Section 8.
2. Scope
This policy applies to:
- vortexfinance.co and any sub-domains
- the Vortex Buy & Sell Crypto App and Vortex Widget
- API and backend services that we operate for partners
It does not cover services operated solely by our local partners; they provide their own privacy notices and consents where required.
3. What data we collect
We collect the following categories of personal data, depending on how you use the Services:
- Contact data: e-mail address (for account/security verification and service communications).
- Usage & device data: IP address, device/browser information, language, timestamps, referral URLs, and server logs.
- Transaction metadata: order identifiers, corridor, asset type (e.g., stablecoin, token), amounts, and status. We do not custodially hold your private keys. On-chain transactions are public by design.
- Support data: information you provide in requests (e.g., messages, attachments).
- Cookies/analytics data: only with your consent where required (see Section 11).
4. Why we process data (purposes & legal bases)
We process personal data for the following purposes and legal bases under the GDPR:
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide and operate the Services | initiate and complete conversions; display rates; route transactions | Art. 6(1)(b) GDPR (contract) |
| Service communications & account verification | verification e-mails; status updates; security alerts | Art. 6(1)(b) (contract) |
| Security & abuse prevention | rate-limiting, incident investigation, preventing misuse | Art. 6(1)(f) (legitimate interests) |
| Compliance support | ensuring corridors operate within applicable rules; audit logs (we do not run KYC/KYB) | Art. 6(1)(c) where applicable; otherwise 6(1)(f) |
| Analytics & quality (cookies/analytics) | improving UX and performance | Art. 6(1)(a) (consent) |
| Marketing (optional) | newsletters, product updates | Art. 6(1)(a) (consent). We do not send marketing e-mails without explicit opt-in. |
E-mail addresses for service only. We store e-mail addresses to provide the Service (e.g., verification, transaction notifications, recognizing returning users across rails). This does not require marketing consent. To prevent misuse, we may send a verification e-mail to confirm control of the address.
5. Data sources
- Directly from you (e.g., input fields, support).
- Automatically via your device/browser (IP, logs, cookies subject to consent).
- From local partners, limited to what is necessary to operate a corridor (e.g., transaction status). Partners conduct KYC/KYB on their systems under their policies.
6. Sharing and disclosures (overview)
We share personal data only as needed to run the Services:
- With independent local partners (controllers): to execute on/off-ramp flows (e.g., payout confirmation). Partners use your data under their own policies and legal bases.
- With processors: for hosting, analytics, communications, and support tooling under data processing agreements.
- For legal reasons: if required by law, regulation, or to protect rights, safety, and integrity of the Services.
We do not sell personal data.
7. Local partners (independent controllers)
These partners operate in their own jurisdictions for fiat collection/payout and related compliance. They may collect additional data directly from you. Please review their terms and privacy notices.
- BRLA Digital Ltda (Brazil) – Website: https://avenia.io/ – T/Cs: https://app.avenia.io/Avenia-TC.pdf - Privacy: https://app.avenia.io/Avenia-Privacy-Policy.pdf
- ANCLAP (Argentina) – Website: https://home.anclap.com/
- MYKOBO UAB (EU/Lithuania) – Website: https://mykobo.io/ – Privacy: https://privacy.mykobo.co/ – Terms: https://terms.mykobo.co/
Future partners (blanket clause). To provide the Services, we may add or replace local partners. We will update this list upon material changes and, where legally required, notify users. Even if a partner is not yet listed here, personal data may be shared where necessary to provide the requested on-/off-ramp service.
8. Processors (service providers)
We use reputable vendors under data processing agreements (DPAs):
- Cloud hosting & infrastructure: Amazon Web Services (AWS), Render, Netlify, Supabase.
- Analytics (consent-based): Google Analytics.
- Support/CRM: Pipedrive, Google sheets.
International transfers. Where data is transferred outside the EEA/UK, we use EU Standard Contractual Clauses and/or rely on adequacy decisions (e.g., EU-US Data Privacy Framework) as applicable, plus supplementary safeguards.
9. Retention
We retain personal data only as long as necessary for the purposes above:
- Service & security data: for the lifetime of the account/relationship and for a limited period thereafter (e.g., up to 24 months after last activity) for troubleshooting and compliance support.
- Logs: typically up to 12 months, unless needed longer for security or legal reasons.
- Analytics cookies: per your consent; retention managed by the provider.
We may retain information as required by law (e.g., tax/audit) or to establish, exercise, or defend legal claims.
10. Your rights
Under applicable law (e.g., GDPR/UK-GDPR), you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability. You may withdraw consent at any time (for activities based on consent). To exercise rights, contact privacy@vortexfinance.co. You also have the right to lodge a complaint with your local data protection authority.
11. Cookies & analytics
We use cookies for essential functionality and, with your consent, for analytics. You can manage cookie preferences in your browser or via our cookie banner.
Google Analytics: IP anonymization is enabled. For opt-out tools and details, see https://tools.google.com/dlpage/gaoptout and https://policies.google.com/privacy.
12. Security
We implement appropriate technical and organizational measures, including encryption in transit, access controls, and monitoring. No internet service can be 100% secure; we work to detect and mitigate incidents promptly.
13. Changes to this policy (versioning)
We update this policy when necessary. The "Last updated" date and version appear at the top. For material changes (e.g., new categories of data, new purposes, or new key partners), we will provide a clear notice and, where required, seek consent.
14. Contact
For questions about this policy, data requests, or complaints, contact: privacy@vortexfinance.co
If you prefer, you may also contact SatoshiPay Ltd at its registered address listed above.