This Privacy Policy explains how Norwegian Block Exchange AS ("NBX", "we", "us") collects and uses personal data. It is intended to provide the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) in a clear and practical form.
Norwegian Block Exchange AS is a Norwegian regulated financial services company providing crypto-asset services, electronic money and payment services, and related services offered through NBX.
• Company: Norwegian Block Exchange AS
• Organisation number: 920 245 676
• Business address: Arnstein Arnebergs vei 30, 1366 Lysaker, Norway
• Website: nbx.com
• Privacy / Data Protection Officer contact: privacy@nbx.com
NBX is the data controller for the personal data described in this Policy unless we specifically state otherwise. Where a service is provided together with a partner acting as a separate data controller, that partner's privacy notice may also apply and will be made available where relevant.
This Policy applies to personal data relating to customers and prospective customers, representatives and beneficial owners of corporate customers, users of our websites and services, counterparties, persons communicating with NBX, and applicants for employment.
Depending on the relationship and service, NBX may process the following categories of personal data:
• Identity and contact data – for example name, date of birth, national identification number, address, telephone number, email address, nationality, identity documents and identity-verification data.
• Customer and account data – account identifiers, customer profile, service preferences, agreements, communications and support history.
• Financial and transaction data – bank account details, deposits, withdrawals, trades, payments, crypto-asset holdings, wallet addresses, blockchain transaction data and, where relevant, originator/beneficiary information required for crypto-asset transfers.
• Compliance and risk data – customer risk classification, source of funds or wealth information, PEP and sanctions screening results, fraud and transaction-monitoring information, blockchain analytics, and information required for regulatory reporting and investigations.
• Technical and security data – IP address, device and browser information, login and authentication events, system and security logs, and information used to detect or investigate misuse or security incidents.
• Marketing and preference data – communication preferences and information used to provide relevant communications where permitted by law.
• Recruitment data – information provided in applications, CVs and related recruitment correspondence.
NBX does not seek to collect special categories of personal data unless this is necessary and legally permitted. Compliance screening or investigations may incidentally involve sensitive information or information relating to criminal offences; such information is processed only where permitted by applicable law.
Where we rely on legitimate interests, we consider the impact on your rights and interests before processing. Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.
Some information is required by law or is necessary for us to provide a service. If required information is not provided, NBX may be unable to establish or continue a customer relationship, execute a transaction, or provide the relevant service.
Most personal data is obtained directly from you. We may also obtain information from:
• identity-verification and KYC/KYB service providers;
• banks, payment service providers, card/service partners and other financial institutions;
• public registers and publicly available sources;
• sanctions, PEP, adverse-media and other compliance databases;
• public blockchains and blockchain analytics providers;
• other regulated crypto-asset service providers and counterparties, including Travel Rule information;
• public authorities and regulators where permitted or required by law; and
• business partners where data has been lawfully transferred to NBX.
NBX shares personal data only where this is necessary for the purposes described above, where required by law, or where another valid legal basis applies. Recipients may include:
• service providers acting for NBX, such as cloud, hosting, security, communications, customer-support, identity-verification, screening and analytics providers;
• banks, payment service providers, custodians, card/service partners and other financial or crypto-asset service providers;
• competent authorities, including Finanstilsynet, Økokrim/FIU, tax authorities, police, courts or other public authorities where disclosure is required or permitted;
• auditors, legal advisers and other professional advisers; and
• other parties where necessary to establish, exercise or defend legal claims or protect customers and NBX.
Where a supplier processes personal data on behalf of NBX, we use a data processing agreement as required by GDPR.
NBX uses service providers and counterparties in an international financial and technology environment. Where personal data is transferred outside the European Economic Area (EEA), NBX uses a lawful transfer mechanism and appropriate safeguards as required by GDPR. Depending on the destination, this may include an EU adequacy decision, the European Commission's Standard Contractual Clauses (SCCs), and supplementary safeguards where required.
You may contact privacy@nbx.com if you want information about the safeguards applicable to a particular transfer.
NBX keeps personal data only for as long as necessary for the purpose for which it was collected and to meet legal, regulatory, accounting, security and dispute-resolution requirements.
KYC/AML records and related documentation are generally retained for five years after the customer relationship ends or the relevant transaction is completed. Certain records may be retained for up to ten years where required under Norwegian AML rules. Other information is deleted or anonymised when it is no longer needed, subject to applicable statutory retention requirements and legitimate needs relating to legal claims.
Recruitment data is normally deleted after the recruitment process has ended unless there is a lawful reason or agreement to retain it for longer. Marketing preferences are retained as needed to respect your choices, including opt-outs.
NBX uses automated tools to support identity verification, sanctions and PEP screening, fraud prevention, customer risk classification, transaction monitoring, blockchain analytics and information-security controls. Automated outputs may generate risk indicators or alerts that are used in NBX's control and review processes.
NBX does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for individuals. If this changes, we will provide the information and safeguards required by GDPR.
Crypto-asset transactions may be recorded on public blockchains. Information published to a public blockchain may be publicly visible and, because of the nature of blockchain technology, cannot be altered or deleted by NBX.
Subject to the conditions and limitations in applicable law, you may have the right to:
• request access to your personal data;
• request correction of inaccurate or incomplete data;
• request deletion of personal data;
• request restriction of processing;
• object to processing based on legitimate interests and object at any time to direct marketing;
• receive certain personal data in a portable format;
• withdraw consent where processing is based on consent; and
• lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
Some rights may be restricted where NBX is required to retain or process information under financial-services, AML/CTF or other legislation, or where disclosure would conflict with statutory confidentiality or investigation requirements.
Requests may be sent to privacy@nbx.com. We may ask for information necessary to verify your identity before responding.
NBX uses cookies and similar technologies for necessary website functionality and security. Analytics, preference or marketing technologies are used only in accordance with applicable consent requirements. You can manage available choices through the cookie controls on nbx.com. Further information is provided in NBX's Cookie Policy.
NBX maintains technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. Measures are risk-based and include access controls, logging and monitoring, security testing, incident handling, continuity measures and employee security requirements.
NBX customer services are not intended for persons under 18 years of age, and NBX does not knowingly establish customer relationships with persons under 18.
Questions about this Policy or NBX's processing of personal data, and requests to exercise privacy rights, can be sent to privacy@nbx.com.
You may also lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority. Information about Datatilsynet and its complaint process is available at datatilsynet.no.
We may update this Privacy Policy when our services, processing activities or legal requirements change. The current version will be published on nbx.com with the date of the latest update.