Vortex Privacy Policy

Last updated: 28 September 2025
Version: 1.0

This Privacy Policy explains how Vortex (a brand operated by SatoshiPay Ltd) collects and processes personal data when you use our websites, apps, widgets, and related services (collectively, the "Services"). It replaces earlier versions and will be updated as our Services evolve.

1. Who we are (Controller)

Controller: SatoshiPay Ltd (trading as "Vortex")
Registered office:
Hill Dickinson Llp
The Broadgate Tower
20 Primrose Street
London, EC2A 2EW United Kingdom
Contact: privacy@vortexfinance.co

SatoshiPay operates Vortex's web/app frontends and determines the purposes and means of processing personal data for the Services described here.

Independent controllers (local partners). For on-/off-ramping, we work with licensed local payment partners who act as independent controllers for their own onboarding (e.g., KYC/KYB), fiat accounts, and payouts. See Section 7 for the current partner list and links to their policies.

Processors. We also use vetted vendors (e.g., cloud hosting, analytics) as processors under data processing agreements. See Section 8.

2. Scope

This policy applies to:

  • vortexfinance.co and any sub-domains
  • the Vortex Buy & Sell Crypto App and Vortex Widget
  • API and backend services that we operate for partners

It does not cover services operated solely by our local partners; they provide their own privacy notices and consents where required.

3. What data we collect

We collect the following categories of personal data, depending on how you use the Services:

  • Contact data: e-mail address (for account/security verification and service communications).
  • Usage & device data: IP address, device/browser information, language, timestamps, referral URLs, and server logs.
  • Transaction metadata: order identifiers, corridor, asset type (e.g., stablecoin, token), amounts, and status. We do not custodially hold your private keys. On-chain transactions are public by design.
  • Support data: information you provide in requests (e.g., messages, attachments).
  • Cookies/analytics data: only with your consent where required (see Section 11).

4. Why we process data (purposes & legal bases)

We process personal data for the following purposes and legal bases under the GDPR:

PurposeExamplesLegal basis
Provide and operate the Servicesinitiate and complete conversions; display rates; route transactionsArt. 6(1)(b) GDPR (contract)
Service communications & account verificationverification e-mails; status updates; security alertsArt. 6(1)(b) (contract)
Security & abuse preventionrate-limiting, incident investigation, preventing misuseArt. 6(1)(f) (legitimate interests)
Compliance supportensuring corridors operate within applicable rules; audit logs (we do not run KYC/KYB)Art. 6(1)(c) where applicable; otherwise 6(1)(f)
Analytics & quality (cookies/analytics)improving UX and performanceArt. 6(1)(a) (consent)
Marketing (optional)newsletters, product updatesArt. 6(1)(a) (consent). We do not send marketing e-mails without explicit opt-in.

E-mail addresses for service only. We store e-mail addresses to provide the Service (e.g., verification, transaction notifications, recognizing returning users across rails). This does not require marketing consent. To prevent misuse, we may send a verification e-mail to confirm control of the address.

5. Data sources

  • Directly from you (e.g., input fields, support).
  • Automatically via your device/browser (IP, logs, cookies subject to consent).
  • From local partners, limited to what is necessary to operate a corridor (e.g., transaction status). Partners conduct KYC/KYB on their systems under their policies.

6. Sharing and disclosures (overview)

We share personal data only as needed to run the Services:

  • With independent local partners (controllers): to execute on/off-ramp flows (e.g., payout confirmation). Partners use your data under their own policies and legal bases.
  • With processors: for hosting, analytics, communications, and support tooling under data processing agreements.
  • For legal reasons: if required by law, regulation, or to protect rights, safety, and integrity of the Services.

We do not sell personal data.

7. Local partners (independent controllers)

These partners operate in their own jurisdictions for fiat collection/payout and related compliance. They may collect additional data directly from you. Please review their terms and privacy notices.

Future partners (blanket clause). To provide the Services, we may add or replace local partners. We will update this list upon material changes and, where legally required, notify users. Even if a partner is not yet listed here, personal data may be shared where necessary to provide the requested on-/off-ramp service.

8. Processors (service providers)

We use reputable vendors under data processing agreements (DPAs):

  • Cloud hosting & infrastructure: Amazon Web Services (AWS), Render, Netlify, Supabase.
  • Analytics (consent-based): Google Analytics.
  • Support/CRM: Pipedrive, Google sheets.

International transfers. Where data is transferred outside the EEA/UK, we use EU Standard Contractual Clauses and/or rely on adequacy decisions (e.g., EU-US Data Privacy Framework) as applicable, plus supplementary safeguards.

9. Retention

We retain personal data only as long as necessary for the purposes above:

  • Service & security data: for the lifetime of the account/relationship and for a limited period thereafter (e.g., up to 24 months after last activity) for troubleshooting and compliance support.
  • Logs: typically up to 12 months, unless needed longer for security or legal reasons.
  • Analytics cookies: per your consent; retention managed by the provider.

We may retain information as required by law (e.g., tax/audit) or to establish, exercise, or defend legal claims.

10. Your rights

Under applicable law (e.g., GDPR/UK-GDPR), you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability. You may withdraw consent at any time (for activities based on consent). To exercise rights, contact privacy@vortexfinance.co. You also have the right to lodge a complaint with your local data protection authority.

11. Cookies & analytics

We use cookies for essential functionality and, with your consent, for analytics. You can manage cookie preferences in your browser or via our cookie banner.

Google Analytics: IP anonymization is enabled. For opt-out tools and details, see https://tools.google.com/dlpage/gaoptout and https://policies.google.com/privacy.

12. Security

We implement appropriate technical and organizational measures, including encryption in transit, access controls, and monitoring. No internet service can be 100% secure; we work to detect and mitigate incidents promptly.

13. Changes to this policy (versioning)

We update this policy when necessary. The "Last updated" date and version appear at the top. For material changes (e.g., new categories of data, new purposes, or new key partners), we will provide a clear notice and, where required, seek consent.

14. Contact

For questions about this policy, data requests, or complaints, contact: privacy@vortexfinance.co

If you prefer, you may also contact SatoshiPay Ltd at its registered address listed above.