Privacy Policy (GDPR)

Last updated: 2026-01-16
Next scheduled review: 2027-01-16

This Privacy Policy explains how NeFin Solutions, UAB collects, uses, stores and protects personal data, in line with GDPR and AML/CTF rules. It also explains your rights and how to contact us. The English version is legally binding; other languages are provided for convenience only.

Company: NeFin Solutions, UAB  |  Reg. No.: 306289600  |  Address: Savanorių pr. 187-301, LT-02300 Vilnius, Lithuania  |  Status: Applying for CASP authorisation in Lithuania

1. Introduction

What this policy covers and to whom it applies.

This Privacy Policy explains how NeFin Solutions, UAB (“Company”, “we”, “us”, “our”) processes personal data of clients, prospective clients, and website visitors in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Lithuanian AML/CTF framework, MiCA, and other applicable regulations.

2. Data Controller & contact

We are the controller of your personal data.

NeFin Solutions, UAB acts as the data controller. For privacy questions, contact: privacy@nefin.io.

3. Categories of personal data

What data we may process.

  • Identification: name, surname, date of birth, personal ID, nationality, residence address.
  • KYC/AML: ID documents, proof of address, beneficial ownership, PEP/sanctions status, SoF/SoW, adverse media.
  • Biometric & video (for AML/CTF only): liveness checks, facial images, video recordings, signatures.
  • Contact: email, phone, correspondence.
  • Financial: bank details, payment instruments, transaction history, crypto wallet addresses.
  • Technical: IP address, device IDs, browser data, cookies, geolocation (if enabled).
  • Communication: support tickets, chat, email threads.

4. Purposes & legal bases

Why we process data and under which legal ground.

  1. Compliance with legal obligations (e.g., AML/CTF, MiCA, Lithuanian AML law).
  2. Performance of contract (onboarding, transactions, support).
  3. Legitimate interests (fraud prevention, IT security, service improvement).
  4. Consent (optional marketing, non-essential cookies).

5. Data sharing

Who may receive your data and why.

  • Supervisory authorities (e.g., Bank of Lithuania, FIU Lithuania).
  • AML/KYC providers (identity verification, sanctions/PEP screening, transaction monitoring).
  • Financial institutions, liquidity providers, and payment partners.
  • Independent auditors, compliance and legal advisors.
  • IT/security infrastructure providers.
  • Law enforcement or courts where required by law.

We do not sell or rent personal data.

6. International data transfers

How we protect data transferred outside the EEA.

Where personal data is transferred outside the EEA, we rely on EU adequacy decisions or Standard Contractual Clauses (SCCs) with supplementary safeguards.

7. Data retention

How long we keep different data types.

  • KYC/AML data, Travel Rule data, transaction history: 8 years after the end of the business relationship.
  • Client correspondence: 5 years after the end of the business relationship.
  • Investigations/SAR-related records: 5 years.
  • Marketing data: until consent is withdrawn.
  • Technical logs: up to 12 months (longer if required for security or compliance).

Retention may be extended by up to 2 additional years on reasoned request of a competent authority.

8. Data subject rights

Your GDPR rights and how to use them.

  • Access, rectification, erasure (“right to be forgotten” where applicable).
  • Restriction of processing; data portability.
  • Objection to processing based on legitimate interests.
  • Withdraw consent at any time (for consent-based processing).
  • Lodge a complaint with the State Data Protection Inspectorate of Lithuania.

9. Security measures

Technical & organizational security controls.

  • Encryption, pseudonymisation, secure key management.
  • Role-based access, MFA, monitoring and audit logs.
  • Cold storage for crypto assets; BCP/DRP.
  • Continuous sanctions/PEP/adverse media screening.

10. Cookies

Cookie types and your control.

See our Cookie Policy for details on cookie categories and preferences.

11. Data deletion

When and how we delete or anonymise data.

Upon expiry of retention periods, personal data is securely deleted or irreversibly anonymised unless otherwise required by law or competent authority.

12. GDPR compliance statement

We apply the stricter standard where rules conflict.

We process personal data based on clear legal grounds under GDPR. Where conflicts arise between GDPR and other obligations (e.g., AML/CTF), we apply the stricter standard to ensure compliance.

13. Updates

We may update this policy as laws evolve.

The latest version will always be available on this page.

14. How to contact us

Questions about privacy? Contact us.

NeFin Solutions, UAB
Savanorių pr. 187-301, LT-02300 Vilnius, Lithuania
Email: privacy@nefin.io

© 2025 NeFin Solutions, UAB · Legal Documents