Privacy Policy
Last updated: July 2026
1. Introduction and Data Controller
This Privacy Policy explains how Zevlian collects, uses, stores, and protects your personal data when you use our website, mobile application, and related services (collectively, the “Services”). We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
The data controller responsible for your personal data is:
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Services.
2. What Data We Collect
2.1 Personal Information
When you create an account or use our Services, we may collect the following personal information:
- Full name
- Email address
- Phone number
- Date of birth
- Residential address
- Nationality and country of residence
2.2 Identity Verification Documents
To comply with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations, we collect identity verification data through our third-party provider, Sumsub. This may include:
- Government-issued identity documents (passport, national ID card, driver's license)
- Selfie or biometric facial data for liveness checks
- Proof of address documents
- Verification status and results
Identity documents and biometric data are processed and stored by Sumsub in accordance with their privacy policy and our data processing agreement with them. We receive verification results and may retain limited identity information as required by applicable law.
2.3 Financial and Transaction Data
When you conduct transactions through our Services, we collect:
- Transaction history and details
- Wallet addresses (including XRP Ledger addresses)
- Payment method information
- Transaction amounts, dates, and counterparties
- Account balances
2.4 Device and Technical Data
We automatically collect certain technical information when you access our Services:
- IP address
- Browser type and version
- Device type, model, and operating system
- Unique device identifiers
- Screen resolution and language preferences
- Referring URLs and pages visited
2.5 Usage Data
We collect data about how you interact with our Services, including:
- Features used and actions taken within the application
- Time spent on pages and navigation patterns
- Error logs and performance data
- Search queries within the platform
- Communication preferences and settings
3. How We Use Your Data
3.1 Providing and Improving Our Services
We use your data to operate, maintain, and improve the functionality and performance of our Services. This includes creating and managing your account, enabling transactions, providing customer support, and developing new features based on aggregated usage patterns.
3.2 Identity Verification and KYC/AML Compliance
We process your identity documents and personal information to verify your identity, comply with KYC and AML regulations, and prevent unauthorized or fraudulent use of our Services. This processing is carried out in cooperation with our KYC provider, Sumsub.
3.3 Transaction Processing
We use your financial data to process transactions you initiate, maintain accurate records of your transaction history, and provide you with account statements and notifications related to your activity on the platform.
3.4 Fraud Prevention and Security
We analyze usage patterns, device data, and transaction information to detect and prevent fraudulent activity, protect the security of our platform and users, and enforce our terms of service. This includes monitoring for suspicious transactions, unauthorized access attempts, and other activities that may violate applicable law.
3.5 Communications
We use your contact information to send you service-related notifications (such as transaction confirmations, security alerts, and account updates), respond to your inquiries and support requests, and, where you have opted in, send promotional communications about our products and services. You may opt out of promotional communications at any time.
3.6 Legal Compliance
We process your data as necessary to comply with applicable laws, regulations, and legal processes, including tax reporting, regulatory filings, and responding to lawful requests from public authorities.
4. Legal Basis for Processing
Under Article 6 of the GDPR, we process your personal data based on one or more of the following legal grounds:
Contract Performance (Article 6(1)(b))
Processing is necessary for the performance of the contract between you and Zevlian, including account creation, transaction processing, and the provision of our Services.
Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with legal obligations to which we are subject, including KYC/AML regulations, tax laws, financial reporting requirements, and data retention mandates under applicable EU and Polish law.
Legitimate Interests (Article 6(1)(f))
Processing is necessary for our legitimate interests, including fraud prevention, platform security, service improvement, and analytics. We carefully balance our interests against your rights and freedoms and do not rely on this basis where your interests override ours.
Consent (Article 6(1)(a))
Where none of the above bases apply, we process your data based on your freely given, specific, informed, and unambiguous consent. This includes optional marketing communications and non-essential cookies. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Third Parties
We do not sell your personal data. We share your data only with the following categories of recipients, and only to the extent necessary for the stated purposes:
5.1 Sumsub (Identity Verification / KYC)
We share personal information and identity documents with Sumsub to perform identity verification and KYC checks as required by law. Sumsub processes this data as a data processor on our behalf, subject to a data processing agreement that ensures appropriate safeguards.
5.2 Payment Processors (Transak, Stripe, Flutterwave)
We share transaction data and necessary personal information with our payment processing partners to facilitate fiat currency transactions, on-ramp and off-ramp services, and payment processing. Each of these processors operates under their own privacy policies and applicable data protection regulations.
5.3 XRPL (XRP Ledger Blockchain)
Transactions conducted on the XRP Ledger are recorded on a public, decentralized blockchain. By their nature, blockchain transactions are transparent and immutable. Transaction details such as wallet addresses, amounts, and timestamps are publicly visible and cannot be deleted or modified once recorded. We cannot control or be responsible for the visibility of on-chain data.
5.4 Law Enforcement and Regulatory Authorities
We may disclose your personal data to law enforcement agencies, regulatory authorities, courts, or other public bodies when we are legally obligated to do so, or when disclosure is necessary to protect our rights, your safety, or the safety of others. We will notify you of such disclosure where legally permitted.
5.5 Service Providers
We may engage additional service providers (such as hosting, analytics, and customer support platforms) who process data on our behalf. All such providers are bound by data processing agreements and are required to implement appropriate technical and organizational security measures.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure that appropriate safeguards are in place to protect your data in accordance with the GDPR, including:
- Transfers to countries that the European Commission has determined provide an adequate level of data protection (adequacy decisions)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
- Other legally recognized transfer mechanisms under Chapter V of the GDPR
You may request a copy of the safeguards we use for international transfers by contacting us at [email protected].
7. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our general retention periods are as follows:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account plus 5 years after closure |
| KYC/identity verification data | 5 years after end of business relationship (or longer if required by AML law) |
| Transaction records | 5 years after the transaction (or longer as required by tax or financial regulations) |
| Technical and usage data | Up to 2 years |
| Marketing consent records | Until consent is withdrawn, plus a record of the withdrawal |
| Support correspondence | 3 years after resolution |
When personal data is no longer required, we securely delete or anonymize it. Blockchain data recorded on the XRP Ledger is immutable and cannot be deleted.
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
Right of Access (Article 15)
You have the right to obtain confirmation as to whether we process your personal data, and if so, to request a copy of that data along with information about how it is processed.
Right to Rectification (Article 16)
You have the right to request the correction of inaccurate personal data and, taking into account the purposes of processing, the completion of incomplete personal data.
Right to Erasure (Article 17)
You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent, or where there is no other legal basis for processing. Please note that we may be required to retain certain data under applicable AML, tax, or other legal obligations, and that data recorded on the XRP Ledger cannot be erased.
Right to Restrict Processing (Article 18)
You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where processing is based on consent or contract and is carried out by automated means.
Right to Object (Article 21)
You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose without exception.
Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. In Poland, the relevant authority is the President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, UODO). You may also contact the supervisory authority in the EU/EEA member state of your habitual residence or place of work.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our Services. Cookies are small text files stored on your device that help us recognize you and remember your preferences.
Types of Cookies We Use
- Strictly Necessary Cookies: Essential for the operation of our Services, including authentication, session management, and security. These cannot be disabled.
- Functional Cookies: Enable enhanced functionality and personalization, such as remembering your language or display preferences.
- Analytics Cookies: Help us understand how visitors interact with our Services by collecting information about pages visited, time spent, and errors encountered. This data is aggregated and anonymized where possible.
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our Services. Where non-essential cookies are used, we will obtain your consent before placing them on your device in accordance with applicable law.
10. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect, solicit, or process personal data from anyone under the age of 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as promptly as possible. If you believe that a person under 18 has provided us with personal data, please contact us immediately at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by posting the updated policy on our website with a revised “Last updated” date. For significant changes, we may also provide additional notice through email or an in-app notification.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Your continued use of our Services after any changes constitutes your acceptance of the updated policy.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
We aim to respond to all legitimate requests within 30 days. In certain circumstances, such as particularly complex requests or a high volume of requests, it may take us up to 60 days, in which case we will notify you and keep you informed of progress.