Data Protection Policy

Data Privacy Policy

Multi-Jurisdictional

Purpose

Vita Capital is committed to protecting the privacy and confidentiality of personal data. This policy explains
how we collect, use, share, and safeguard personal information in compliance with global data protection and
financial regulations, including:

  • EU/UK General Data Protection Regulation (GDPR/UK GDPR)
  • California Consumer Privacy Act (CCPA) and other US privacy laws
  • Gramm-Leach-Bliley Act (GLBA) for financial services in the US
  • Applicable local financial and data protection laws in the jurisdictions where we operate
Data We Collect

We may collect and process the following categories of personal data:

  • Identity Data: full name, date of birth, nationality, government-issued ID, passport details
  • Contact Data: postal address, email address, phone numbers
  • Financial Data: bank account details, payment card information, transaction records
  • Regulatory Data: documents required for AML/KYC/CTF compliance, sanctions screening, and tax reporting
  • Technical Data: IP addresses, cookies, device identifiers, geolocation, and security logs
Legal Basis for Processing

Depending on jurisdiction, we process personal data under the following lawful grounds:

  • GDPR/UK GDPR:
    • Contractual necessity (to provide foreign exchange and payment services)
    • Compliance with legal obligations (AML, CTF, tax, financial regulations)
    • Legitimate interests (fraud prevention, risk management, service improvements)
    • Consent (marketing and optional services)
  • CCPA/GLBA (US):
    • Data processing as required to deliver services, prevent fraud, and comply with financial regulations
    • No sale of customer personal data without explicit opt-out rights
How We Use Data

Customer data may be used for:

  1. Providing foreign exchange, remittance, and related financial services
  2. Verifying customer identity under AML/KYC requirements
  3. Monitoring for suspicious transactions (fraud and financial crime prevention)
  4. Regulatory reporting to competent authorities
  5. Customer support and complaint resolution
  6. Service improvement, analytics, and security monitoring
  7. Marketing (only where consent is given or permitted by law)
Data Sharing & Disclosure

We may share personal data with:

  • Regulators and Law Enforcement (as legally required)
  • Financial Institutions & Payment Providers (to process transactions)
  • Technology & Compliance Vendors (for ID verification, fraud screening, cloud hosting)
  • Affiliates within the [Company Name] group

We do not sell personal information. Under CCPA, customers have the right to opt out of data sharing for marketing purposes.

Cross-Border Transfers

Customer data may be transferred outside the EU/UK/US where services require international payment processing. We ensure adequate safeguards through:

  • Standard Contractual Clauses (SCCs) under GDPR
  • Binding Corporate Rules (BCRs) where applicable
  • Transfers only to jurisdictions with sufficient data protection measures
Data Retention
  • Personal data is kept only as long as required to provide services and comply with legal obligations.
  • Regulatory requirements (e.g., AML/KYC) typically require 5–7 years’ retention after a business relationship ends.
  • Data is securely destroyed or anonymized once no longer required.
Data Security

We apply robust security controls, including:

  • Encryption of data in transit and at rest
  • Role-based access controls and multi-factor authentication
  • Continuous monitoring, intrusion detection, and regular audits
  • Staff training on data handling and regulatory compliance
Customer Rights

Depending on jurisdiction, customers have the following rights:

  • GDPR/UK GDPR Rights: access, rectification, erasure (“right to be forgotten”), restriction of processing, objection, and data portability
  • CCPA Rights: know what data is collected, request deletion, opt-out of data sales, and non-discrimination for exercising rights
  • GLBA Protections: confidentiality and integrity of financial data

Requests can be submitted to compliance@vita-limited.com. We will verify identity before processing any rights request.

Contact & Complaints
  • Data Protection Officer (DPO): Dean Biddulph (dean@vita-capital.com)
  • Complaints may be escalated to the relevant data protection authority (e.g., ICO in the UK, EDPB authority in the EU, or Attorney General in US states with privacy laws).
Policy Review

This policy will be reviewed annually and updated as needed to reflect regulatory changes.

Annual training is provided to all staff annually via KnowBe4 Compliance training modules.