Who is responsible for your data
The data controller is the OnyxOne contracting entity ([DATA CONTROLLER ENTITY — TBC]; registered details being finalised, available at hello@onyxone.co). We process personal data in accordance with the UK GDPR and the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO).
Personal data we collect
- Wallet address and on-chain activity you choose to connect (public by nature).
- Account data you provide: email for account and service updates; identity details where KYC is required for a regulated product.
- Technical data: device, session, IP-derived location and security signals needed to protect your account and prevent fraud.
- Communications: messages you send us (e.g. support, security reports).
Lawful bases (UK GDPR)
- Contract — to provide the Service you request.
- Legal obligation — to meet AML/CTF, sanctions, tax and record-keeping duties.
- Legitimate interests — to secure the platform, prevent fraud and improve the Service, balanced against your rights.
- Consent — for non-essential cookies and optional communications, which you can withdraw at any time.
How we use personal data
- To operate, secure and support the Service.
- To meet legal and regulatory obligations (KYC/AML, sanctions screening, record-keeping).
- To communicate service, security and account information.
- To understand aggregate, privacy-respecting usage (only where you have opted in).
What we never do
- We never place personal or sensitive data in URLs.
- We never sell your personal data.
- We never take custody of your keys or funds to display your portfolio.
Sub-processors & sharing
We share personal data only with the infrastructure providers below, with regulators or authorities where legally required, and with a licensed partner if and when a regulated product (e.g. the card) becomes available. Reap is listed as a planned partner and is not yet engaged.
- Vercel Inc. — application hosting & edge delivery (US/EU regions)
- Supabase — database, authentication & storage (EU region)
- Reap — card issuing / BIN-sponsor partner (planned; not yet engaged)
International transfers
Where personal data is transferred outside the UK/EEA, we rely on an appropriate safeguard — an adequacy decision, the UK International Data Transfer Agreement (IDTA), or Standard Contractual Clauses — and apply additional measures where needed.
Retention
We keep personal and compliance records only as long as required by law (for example, AML records for the statutory retention period) or to operate the Service, then delete or anonymise them.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. You can also lodge a complaint with the ICO. To exercise your rights, contact us; we respond within the statutory timeframe.
Security & cookies
We protect personal data with encryption in transit and at rest, strict access controls and server-side secret handling (see our Security page). Our use of cookies is described in the Cookie Policy.
Children
The Service is not directed to children under 18 and we do not knowingly collect their personal data.
Contact
Privacy questions or requests: hello@onyxone.co.