Data Privacy Policy
Multi-Jurisdictional
Purpose
Vita Capital is committed to protecting the privacy and confidentiality of personal data. This policy explains
how we collect, use, share, and safeguard personal information in compliance with global data protection and
financial regulations, including:
- EU/UK General Data Protection Regulation (GDPR/UK GDPR)
- California Consumer Privacy Act (CCPA) and other US privacy laws
- Gramm-Leach-Bliley Act (GLBA) for financial services in the US
- Applicable local financial and data protection laws in the jurisdictions where we operate
We may collect and process the following categories of personal data:
- Identity Data: full name, date of birth, nationality, government-issued ID, passport details
- Contact Data: postal address, email address, phone numbers
- Financial Data: bank account details, payment card information, transaction records
- Regulatory Data: documents required for AML/KYC/CTF compliance, sanctions screening, and tax reporting
- Technical Data: IP addresses, cookies, device identifiers, geolocation, and security logs
Depending on jurisdiction, we process personal data under the following lawful grounds:
-
GDPR/UK GDPR:
- Contractual necessity (to provide foreign exchange and payment services)
- Compliance with legal obligations (AML, CTF, tax, financial regulations)
- Legitimate interests (fraud prevention, risk management, service improvements)
- Consent (marketing and optional services)
-
CCPA/GLBA (US):
- Data processing as required to deliver services, prevent fraud, and comply with financial regulations
- No sale of customer personal data without explicit opt-out rights
Customer data may be used for:
- Providing foreign exchange, remittance, and related financial services
- Verifying customer identity under AML/KYC requirements
- Monitoring for suspicious transactions (fraud and financial crime prevention)
- Regulatory reporting to competent authorities
- Customer support and complaint resolution
- Service improvement, analytics, and security monitoring
- Marketing (only where consent is given or permitted by law)
We may share personal data with:
- Regulators and Law Enforcement (as legally required)
- Financial Institutions & Payment Providers (to process transactions)
- Technology & Compliance Vendors (for ID verification, fraud screening, cloud hosting)
- Affiliates within the [Company Name] group
We do not sell personal information. Under CCPA, customers have the right to opt out of data sharing for marketing purposes.
Customer data may be transferred outside the EU/UK/US where services require international payment processing. We ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) under GDPR
- Binding Corporate Rules (BCRs) where applicable
- Transfers only to jurisdictions with sufficient data protection measures
- Personal data is kept only as long as required to provide services and comply with legal obligations.
- Regulatory requirements (e.g., AML/KYC) typically require 5–7 years’ retention after a business relationship ends.
- Data is securely destroyed or anonymized once no longer required.
We apply robust security controls, including:
- Encryption of data in transit and at rest
- Role-based access controls and multi-factor authentication
- Continuous monitoring, intrusion detection, and regular audits
- Staff training on data handling and regulatory compliance
Depending on jurisdiction, customers have the following rights:
- GDPR/UK GDPR Rights: access, rectification, erasure (“right to be forgotten”), restriction of processing, objection, and data portability
- CCPA Rights: know what data is collected, request deletion, opt-out of data sales, and non-discrimination for exercising rights
- GLBA Protections: confidentiality and integrity of financial data
Requests can be submitted to compliance@vita-limited.com. We will verify identity before processing any rights request.
- Data Protection Officer (DPO): Dean Biddulph (dean@vita-capital.com)
- Complaints may be escalated to the relevant data protection authority (e.g., ICO in the UK, EDPB authority in the EU, or Attorney General in US states with privacy laws).
This policy will be reviewed annually and updated as needed to reflect regulatory changes.
Annual training is provided to all staff annually via KnowBe4 Compliance training modules.