Privacy Policy
How we collect, use, and protect your personal data under the General Data Protection Regulation (GDPR).
01Data Controller
TrustNexus Platform ("TrustNexus", "we", "us", or "our") is the data controller responsible for processing your personal data. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection legislation.
For data protection inquiries, contact our Data Protection Officer at dpo@trustnexus.eu.
02Data We Collect
We collect and process the following categories of personal data depending on the services you use:
- Identity data: Name, date of birth, nationality, country of residence
- Contact data: Email address, phone number, postal address
- Credential data: Encrypted password, multi-factor authentication tokens
- Identity documents: Passport, national ID, or driver license images and data
- Biometric data: Liveness check data (processed by our sub-processor SumSub)
- Business data: Company name, registration number, tax ID, beneficial ownership information
- Verification data: KYC/KYB check results, risk scores, AML screening results
- Technical data: IP address, browser type, login timestamps, session information
- Preference data: Language, timezone, notification settings
03Purposes and Legal Bases
We process your personal data for the following purposes, each supported by a lawful basis under GDPR Article 6:
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| KYC/KYB identity verification and document checks | Legal obligation (AML/KYC regulations) |
| Biometric liveness verification | Explicit consent |
| AML/sanctions screening | Legal obligation |
| Trust score calculation | Performance of contract |
| Transactional email notifications | Performance of contract |
| Security monitoring and fraud prevention | Legitimate interest |
| Platform analytics and improvement | Legitimate interest |
04Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Account data: Duration of service plus 5 years (contractual and regulatory requirements)
- KYC/KYB verification records: 5 years (EU Anti-Money Laundering Directive)
- Identity documents: 5 years from verification date
- Security logs: 90 days (failed login attempts, account lockouts)
- Audit logs: 7 years (financial regulatory compliance)
- Consent records: Duration of consent plus 5 years
After the retention period expires, data is securely deleted or anonymized in accordance with our data lifecycle procedures.
05Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your data where no legal retention requirement applies.
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to restriction (Article 18): Request limitation of processing in certain circumstances.
- Right to object (Article 21): Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, submit a Data Subject Request through your account settings or contact us at dpo@trustnexus.eu. We respond to all requests within 30 days as required by GDPR.
06Sub-Processors
We use a limited number of third-party sub-processors to deliver our services. Each sub-processor is bound by data processing agreements that ensure GDPR compliance. For a complete list of our sub-processors, including their purposes, data categories processed, and safeguards in place, please visit our Sub-Processor Transparency page.
07International Data Transfers
Some of our sub-processors operate outside the European Economic Area (EEA). Where personal data is transferred to countries without an EU adequacy decision, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. Details of each sub-processor's location and safeguards are available on our Sub-Processor Transparency page.
09Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS), role-based access controls, audit logging, and regular security assessments. Access to personal data is restricted to authorized personnel on a need-to-know basis.
11Contact Us
For any questions about this privacy policy or our data processing practices, please contact: