Privacy Policy

NOX-LGL-P0-002 · v1.0 · Last updated 2026-08-04

Draft — pending legal review. This document is published for transparency while it completes review. Bracketed items are placeholders and will be finalized before the document takes effect.

This Privacy Policy explains how OTSO Fintech Co. LTD collects, uses, discloses, retains and protects personal data when you use the Services. It also explains choices and rights that may apply to you.

2.1 Controller and scope

Unless another notice states otherwise, OTSO Fintech Co. LTD is the controller of personal data covered by this Policy. In enterprise, partner or white-label arrangements, NOX may act as a processor or service provider on behalf of another organization, and that organization's notice may also apply.

This Policy applies to website visitors, registered users, prospective customers, support contacts, business representatives and persons whose data is lawfully provided through connected accounts.

2.2 Personal data we collect

We may collect:

Account and identity data

Name, username, email, telephone number, country, language, date of birth or age confirmation, organization, role, account identifiers, authentication records and verification information.

Subscription and transaction data

Plan, invoices, billing status, payment method metadata, processor tokens, charge and refund records, tax information and, where supported, blockchain transaction identifiers or wallet addresses. We generally do not receive full payment-card numbers from our processors.

Financial profile and decision-support data

Stated objectives, risk tolerance, experience, constraints, preferences, time horizon, portfolio configuration, watchlists, simulations and other information you choose to provide.

Connected-account data

Provider name, account identifier, balances, positions, orders, fills, transaction history, fees, instrument data, performance and risk metrics. Depending on the integration, credentials or access tokens may be processed by us or a specialized provider.

AI interaction data

Prompts, messages, uploaded content, selected settings, generated outputs, feedback and actions taken in response to outputs.

Device and usage data

IP address, device identifiers, browser, operating system, language, approximate location, timestamps, pages, clicks, session events, crash logs and security signals.

Communications and support data

Emails, chat records, call notes, survey responses, complaints and files submitted for support.

Marketing and cookie data

Consent choices, campaign source, referral information, advertising identifiers and interactions with marketing communications.

2.3 Sources

We collect data directly from you, automatically through the Services, from connected third-party providers, payment processors, identity or fraud vendors, business partners, public sources and persons authorized to provide data to us.

2.4 Purposes and legal bases

We use personal data to:

  • provide accounts, subscriptions, analytics, AI features and connected-account functions;
  • authenticate users and secure the Services;
  • process payments and administer refunds;
  • personalize interfaces and decision-support outputs based on user-provided settings;
  • respond to support, complaints and legal requests;
  • detect fraud, abuse, sanctions exposure, cyber threats and violations;
  • maintain logs, audit trails, backups and business records;
  • analyze performance, debug systems and improve products;
  • communicate service notices and, with required consent, marketing;
  • comply with legal, regulatory, tax and contractual obligations; and
  • establish, exercise or defend legal claims.

Depending on location and context, legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations and protection of vital interests. Where we rely on legitimate interests, we balance those interests against affected rights.

2.5 AI, analytics and model improvement

We may use interaction and usage data to evaluate quality, safety, reliability and user experience. This includes reviewing AI assistant conversations (your questions and the generated answers), which are logged with your account for security, quality and support purposes.

[Publication selection required — one of the following will be adopted before this Policy takes effect:]

  • [OPTION A: NO TRAINING] We do not use your private prompts or connected-account data to train general-purpose models, unless you opt in.
  • [OPTION B: LIMITED IMPROVEMENT] We may use selected data to improve NOX systems subject to access controls, minimization and de-identification where reasonably possible. You may opt out at [SETTING/EMAIL].
  • [OPTION C: CONSENT-BASED] We use such data for training only with separate express consent.

We may use aggregated or de-identified information for analytics, benchmarking, research and product improvement, provided we do not reasonably attempt to re-identify it.

2.6 Automated processing

NOX may process objectives, risk settings, account activity and interaction data to generate scores, alerts, portfolio illustrations or other outputs. These systems support user decisions. Unless separately disclosed, they are not intended to make a legally binding decision about you without meaningful human involvement.

You may request information about applicable automated processing and, where law provides, request human review or contest a significant decision.

2.7 Disclosures

We may disclose data to:

  • cloud, hosting, cybersecurity and observability providers;
  • AI-model, data-processing and analytics providers;
  • payment, billing, fraud and identity providers;
  • connected-account platforms and data aggregators at your instruction;
  • support, communications and customer-management vendors;
  • professional advisers, auditors, insurers and corporate affiliates;
  • prospective buyers, investors or transaction participants subject to appropriate safeguards;
  • regulators, courts, law enforcement or other parties where legally required; and
  • other parties with your direction or consent.

We do not sell personal data for money. The use of advertising or cross-context behavioral technologies must be disclosed and controlled as required by applicable law.

2.8 International transfers

We operate globally and may process data in countries other than where you live. Where required, we use recognized transfer mechanisms, such as adequacy decisions, standard contractual clauses, contractual safeguards or consent, together with supplementary security measures where appropriate.

2.9 Retention

We retain personal data only as long as reasonably necessary for the purposes described, including contractual, tax, accounting, security, dispute and regulatory needs. Indicative periods:

  • account records: account life plus [X] years;
  • billing and tax records: [X] years;
  • security and access logs: [X] months;
  • support records: [X] years;
  • connected-account data: while connected plus [X] days/months, unless longer retention is required;
  • consent and policy acceptance evidence: duration of relationship plus applicable limitation period.

Backups may persist for a limited cycle before deletion or overwriting.

2.10 Security

We use administrative, technical and organizational safeguards designed to protect personal data, such as access controls, encryption in transit, secure development practices, monitoring, vendor review and incident response. Credentials for connected trading accounts are encrypted at rest. Authorized personnel may access connected-account credentials where necessary to operate, support or secure the relevant feature; such access is logged and auditable. No method is completely secure. You are responsible for securing your devices and credentials.

2.11 Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing; receive portable data; withdraw consent; opt out of certain advertising or profiling; appeal a refusal; and complain to a supervisory authority.

Submit requests to [PRIVACY EMAIL]. We may verify identity and may refuse or limit requests where permitted by law. Authorized agents must provide proof of authority.

2.12 Marketing choices

You may unsubscribe from promotional emails using the link provided or account settings. We may still send non-promotional service, security, billing and legal notices.

2.13 Cookies

We use cookies and similar technologies as described in the Cookie Policy. Where required, non-essential technologies are used only after consent. You may revise choices through the cookie settings interface.

2.14 Children

The Services are not directed to children under 18, and we do not knowingly permit them to create accounts. Contact us if you believe a child has provided data.

2.15 Third-party links

The Services may link to third parties. Their privacy practices are governed by their own notices, not this Policy.

2.16 Changes

We may update this Policy. Material changes will be notified where required. The date at the top identifies the current version.

2.17 Contact

Privacy contact: [PRIVACY EMAIL]

OTSO Fintech Co. LTD

[REGISTERED OFFICE ADDRESS]