Privacy Policy

Words

1341

Read Time

10 min 19 seconds

Updated

21.08.2026

This Privacy Policy explains how Norwegian Block Exchange AS ("NBX", "we", "us") collects and uses personal data. It is intended to provide the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) in a clear and practical form.

1. Who we are

Norwegian Block Exchange AS is a Norwegian regulated financial services company providing crypto-asset services, electronic money and payment services, and related services offered through NBX.

• Company: Norwegian Block Exchange AS

• Organisation number: 920 245 676

• Business address: Arnstein Arnebergs vei 30, 1366 Lysaker, Norway

• Website: nbx.com

• Privacy / Data Protection Officer contact: privacy@nbx.com

NBX is the data controller for the personal data described in this Policy unless we specifically state otherwise. Where a service is provided together with a partner acting as a separate data controller, that partner's privacy notice may also apply and will be made available where relevant.

2. Who this Policy applies to and what data we process

This Policy applies to personal data relating to customers and prospective customers, representatives and beneficial owners of corporate customers, users of our websites and services, counterparties, persons communicating with NBX, and applicants for employment.

Depending on the relationship and service, NBX may process the following categories of personal data:

• Identity and contact data – for example name, date of birth, national identification number, address, telephone number, email address, nationality, identity documents and identity-verification data.

• Customer and account data – account identifiers, customer profile, service preferences, agreements, communications and support history.

• Financial and transaction data – bank account details, deposits, withdrawals, trades, payments, crypto-asset holdings, wallet addresses, blockchain transaction data and, where relevant, originator/beneficiary information required for crypto-asset transfers.

• Compliance and risk data – customer risk classification, source of funds or wealth information, PEP and sanctions screening results, fraud and transaction-monitoring information, blockchain analytics, and information required for regulatory reporting and investigations.

• Technical and security data – IP address, device and browser information, login and authentication events, system and security logs, and information used to detect or investigate misuse or security incidents.

• Marketing and preference data – communication preferences and information used to provide relevant communications where permitted by law.

• Recruitment data – information provided in applications, CVs and related recruitment correspondence.

NBX does not seek to collect special categories of personal data unless this is necessary and legally permitted. Compliance screening or investigations may incidentally involve sensitive information or information relating to criminal offences; such information is processed only where permitted by applicable law.

3. Why we process personal data and our legal bases

Purpose Main legal basis
Opening and administering accounts; providing trading, custody, e-money, payment and other NBX services; customer support and communications. Necessary to enter into or perform a contract with you (GDPR Art. 6(1)(b)).
KYC/KYB, AML/CTF, sanctions, Travel Rule, regulatory reporting, record keeping and other mandatory compliance activities. Compliance with legal and regulatory obligations (Art. 6(1)(c)), together with applicable Norwegian and EEA financial-services legislation.
Fraud prevention, information security, access control, incident handling, service integrity and protection of NBX, customers and third parties. Legal obligations where applicable (Art. 6(1)(c)) and NBX's legitimate interests in operating secure and reliable services (Art. 6(1)(f)).
Service administration, quality improvement, internal analysis, audit, governance, legal claims and business management. NBX's legitimate interests (Art. 6(1)(f)) and legal obligations where applicable.
Marketing communications. Consent where required (Art. 6(1)(a)); otherwise legitimate interests where permitted by applicable marketing and privacy rules.
Non-essential website technologies. Consent where required by applicable law (Art. 6(1)(a)).
Recruitment and responding to job applications. Steps taken before entering into an employment contract (Art. 6(1)(b)) and legitimate interests in recruitment administration (Art. 6(1)(f)).

Where we rely on legitimate interests, we consider the impact on your rights and interests before processing. Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

Some information is required by law or is necessary for us to provide a service. If required information is not provided, NBX may be unable to establish or continue a customer relationship, execute a transaction, or provide the relevant service.

4. Where we obtain personal data

Most personal data is obtained directly from you. We may also obtain information from:

• identity-verification and KYC/KYB service providers;

• banks, payment service providers, card/service partners and other financial institutions;

• public registers and publicly available sources;

• sanctions, PEP, adverse-media and other compliance databases;

• public blockchains and blockchain analytics providers;

• other regulated crypto-asset service providers and counterparties, including Travel Rule information;

• public authorities and regulators where permitted or required by law; and

• business partners where data has been lawfully transferred to NBX.

5. Who we share personal data with

NBX shares personal data only where this is necessary for the purposes described above, where required by law, or where another valid legal basis applies. Recipients may include:

• service providers acting for NBX, such as cloud, hosting, security, communications, customer-support, identity-verification, screening and analytics providers;

• banks, payment service providers, custodians, card/service partners and other financial or crypto-asset service providers;

• competent authorities, including Finanstilsynet, Økokrim/FIU, tax authorities, police, courts or other public authorities where disclosure is required or permitted;

• auditors, legal advisers and other professional advisers; and

• other parties where necessary to establish, exercise or defend legal claims or protect customers and NBX.

Where a supplier processes personal data on behalf of NBX, we use a data processing agreement as required by GDPR.

6. Transfers outside the EEA

NBX uses service providers and counterparties in an international financial and technology environment. Where personal data is transferred outside the European Economic Area (EEA), NBX uses a lawful transfer mechanism and appropriate safeguards as required by GDPR. Depending on the destination, this may include an EU adequacy decision, the European Commission's Standard Contractual Clauses (SCCs), and supplementary safeguards where required.

You may contact privacy@nbx.com if you want information about the safeguards applicable to a particular transfer.

7. How long we keep personal data

NBX keeps personal data only for as long as necessary for the purpose for which it was collected and to meet legal, regulatory, accounting, security and dispute-resolution requirements.

KYC/AML records and related documentation are generally retained for five years after the customer relationship ends or the relevant transaction is completed. Certain records may be retained for up to ten years where required under Norwegian AML rules. Other information is deleted or anonymised when it is no longer needed, subject to applicable statutory retention requirements and legitimate needs relating to legal claims.

Recruitment data is normally deleted after the recruitment process has ended unless there is a lawful reason or agreement to retain it for longer. Marketing preferences are retained as needed to respect your choices, including opt-outs.

8. Automated tools, risk assessment and publicblockchains

NBX uses automated tools to support identity verification, sanctions and PEP screening, fraud prevention, customer risk classification, transaction monitoring, blockchain analytics and information-security controls. Automated outputs may generate risk indicators or alerts that are used in NBX's control and review processes.

NBX does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for individuals. If this changes, we will provide the information and safeguards required by GDPR.

Crypto-asset transactions may be recorded on public blockchains. Information published to a public blockchain may be publicly visible and, because of the nature of blockchain technology, cannot be altered or deleted by NBX.

9. Your rights

Subject to the conditions and limitations in applicable law, you may have the right to:

• request access to your personal data;

• request correction of inaccurate or incomplete data;

• request deletion of personal data;

• request restriction of processing;

• object to processing based on legitimate interests and object at any time to direct marketing;

• receive certain personal data in a portable format;

• withdraw consent where processing is based on consent; and

• lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

Some rights may be restricted where NBX is required to retain or process information under financial-services, AML/CTF or other legislation, or where disclosure would conflict with statutory confidentiality or investigation requirements.

Requests may be sent to privacy@nbx.com. We may ask for information necessary to verify your identity before responding.

10. Cookies and website technologies

NBX uses cookies and similar technologies for necessary website functionality and security. Analytics, preference or marketing technologies are used only in accordance with applicable consent requirements. You can manage available choices through the cookie controls on nbx.com. Further information is provided in NBX's Cookie Policy.

11. Information security

NBX maintains technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. Measures are risk-based and include access controls, logging and monitoring, security testing, incident handling, continuity measures and employee security requirements.

12. Children

NBX customer services are not intended for persons under 18 years of age, and NBX does not knowingly establish customer relationships with persons under 18.

13. Contact, complaints and changes

Questions about this Policy or NBX's processing of personal data, and requests to exercise privacy rights, can be sent to privacy@nbx.com.

You may also lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority. Information about Datatilsynet and its complaint process is available at datatilsynet.no.

We may update this Privacy Policy when our services, processing activities or legal requirements change. The current version will be published on nbx.com with the date of the latest update.

Cookie Consent

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.