Data Privacy
Collection and Storage of Personal Data
Data Collection
In order to provide foreign exchange and payment services, Vita Capital must collect certain personal and financial information from customers. This includes, but is not limited to:
- Identification Data – name, date of birth, nationality, government-issued ID, passport details, photographs where required
- Contact Data – address, email address, telephone number
- Financial Data – bank account details, payment information, transaction history
- Compliance Data – documents and information required for Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), and Know Your Customer (KYC) purposes
- Technical Data – IP address, device details, online session logs (for security monitoring)
Purpose of Collection
The data we collect is strictly for:
The data we collect is strictly for:
- Processing currency exchange transactions and international payments
- Verifying customer identity and preventing fraud
- Meeting legal and regulatory obligations (AML, KYC, CTF, sanctions checks, tax reporting)
- Providing customer service and communication
- Ensuring security of our systems and services
Data Storage
- All personal data is stored in secure databases located in data centres that meet international security standards.
- Data may be stored in multiple jurisdictions where our services operate, but always under safeguards that comply with relevant data protection laws (e.g., GDPR, UK Data Protection Act, CCPA, GLBA).
- Sensitive data (such as ID documents and financial details) is protected using encryption, access controls, and multi-factor authentication.
- Access to customer data is strictly limited to authorized staff on a “need-to-know” basis.
- Regular backups and security monitoring are in place to prevent loss, unauthorized access, or misuse.
Data Retention
- Personal data will only be kept for as long as necessary to provide services and comply with legal obligations.
- In line with AML/KYC requirements, identification and transaction records are retained for a minimum of 5–7 years after the business relationship ends.
- Once retention periods expire, data is securely deleted or anonymized.