Privacy Policy

Effective Date 01.08.2026

1. Introduction

This Privacy Policy explains how TERALEX PAY LIMITED, a company incorporated in Canada, registration number BC1536949, office address 5307 Victoria Drive #787, Vancouver, BC V5P 3V6, Canada, collects, uses, discloses, stores, retains and protects personal information in connection with its website, client portal, onboarding, account access, payment services, virtual currency-related services, compliance processes, customer support and related business operations.

In this Policy, "TERALEX", "we", "us" and "our" mean TERALEX PAY LIMITED. "Client", "you" and "your" mean any individual who applies for or uses our services, any representative of a corporate client, and any person whose personal information is provided to us in connection with our services.

This Policy is prepared primarily for a Canadian money services business and payment service provider model. We process personal information in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act, applicable provincial privacy laws where relevant, Canada's Anti-Spam Legislation, anti-money laundering and counter-terrorist financing laws, sanctions laws and other legal and regulatory requirements applicable to our services.

If privacy or data protection laws outside Canada apply to a particular individual, service or processing activity, TERALEX will comply with those requirements to the extent applicable. Nothing in this Policy is intended to voluntarily extend non-Canadian privacy regimes to TERALEX where they do not apply under their own terms.

If you do not agree with this Policy, you should not use our website, apply for an account or use our services.

2. Who This Policy Applies To

This Policy applies to personal information relating to clients, prospective clients, directors, officers, employees, authorised users, authorised representatives, beneficial owners, controlling persons, shareholders, signatories, counterparties, beneficiaries, payees, payors, website visitors, client portal users and other individuals whose information is provided to us or processed in connection with our services.

TERALEX is responsible for personal information under its control. We may use third-party service providers to process information on our behalf or to support regulated services, but TERALEX remains responsible for managing its own legal, privacy, security, AML and recordkeeping obligations.

3. Personal Information We Collect

We collect personal information that is necessary to provide our services, comply with law, prevent fraud, manage risk and operate our business. Depending on the product, service and client type, this may include:

Identification information, including full legal name, date of birth, nationality, citizenship, residential address, business address, occupation, job title and contact details.

Government identification information, including passport, national identity card, driver licence or other government-issued document details, document images, issuing jurisdiction, expiry date and verification results.

Biometric or biometric-related information where identity verification requires a selfie, liveness check, face match, video verification or similar verification method through an identity verification provider.

Corporate and KYB information, including company name, registration number, registered address, operating address, directors, officers, authorised persons, ownership and control structure, beneficial owners, source of funds, source of wealth, business activity and supporting documents.

Account and transaction information, including account identifiers, wallet addresses, payment references, transaction identifiers, transaction hashes, sending and receiving addresses, transaction amounts, assets, currencies, exchange rates, dates, fees, counterparties, beneficiaries, payment instructions, transaction status, balances, safeguarding records, custody records and records supporting a client's entitlement to funds or virtual currency.

Compliance and risk information, including KYC and KYB results, sanctions screening, politically exposed person screening, head of international organisation screening, adverse media, fraud indicators, blockchain analytics, Travel Rule data, transaction monitoring results, risk scores, review notes and decisions.

Technical and usage information, including IP address, device identifiers, browser type, operating system, login data, session data, security logs, cookie identifiers, website usage, error logs and platform activity.

Communications information, including emails, support requests, complaints, notices, delivery records, call notes, chat messages, documents submitted to us and records of communications with our team.

Marketing preference information, including whether you have consented to receive commercial electronic messages and whether you have opted out.

4. Sources of Personal Information

We may collect personal information from the following sources:

  • Directly from you, including through the website, onboarding forms, client portal, customer support, email, chat, calls and documents you provide.
  • From corporate clients, where your information is provided because you are a director, officer, authorised user, beneficial owner, employee, representative, shareholder, controlling person, contact person, payee, payor or beneficiary.
  • From identity verification, KYB, sanctions, PEP, HIO, adverse media, fraud prevention, blockchain analytics, payment, banking and virtual currency service providers.
  • From public sources, including corporate registries, court records, sanctions lists, government lists, public databases and publicly available websites.
  • From payment partners, financial institutions, virtual asset service providers, counterparties, intermediaries and other service providers involved in the transaction chain.
  • From our systems, where we generate records about account activity, transaction activity, risk scoring, monitoring results, alerts, decisions and support interactions.

5. Why We Use Personal Information

We use personal information only for purposes that are reasonably necessary for our services, our legal obligations and our legitimate business operations. Under Canadian privacy law, we rely on meaningful consent, reasonable purposes, accountability, safeguards and statutory exceptions where processing is required or permitted by law.

Where another privacy or data protection law applies to a specific processing activity, we rely on the legal grounds available under that law, which may include performance of a contract, compliance with legal obligations, legitimate business interests, consent where required, or another lawful basis.

Account opening and client onboarding: to assess applications, verify identity, verify legal entities, identify directors and beneficial owners, determine whether we may provide services, assign a client risk rating and create a client file.

Providing services: to provide account access, process payment instructions, support fiat transactions, support virtual currency-related services where available, display balances, manage instructions, process exchanges, maintain transaction history, provide customer support, issue notices, administer fees and limits, and manage returns, holds, safeguarding or custody records where applicable.

AML, sanctions and regulatory compliance: to comply with client identification, beneficial ownership, sanctions screening, PEP and HIO screening, transaction monitoring, Travel Rule, recordkeeping, reporting, law enforcement and regulatory obligations.

Fraud prevention, security and risk management: to detect, prevent and investigate fraud, misuse of services, unauthorised access, account takeover, cyber incidents, financial crime, prohibited activity and other risks.

Communications and support: to respond to requests, provide notices, request documents, communicate about account status, confirm transactions, investigate complaints, resolve errors and provide operational or compliance notices.

Legal claims and corporate administration: to establish, exercise or defend legal claims, enforce our Terms and Conditions, manage disputes, conduct audits, maintain records, obtain professional advice, complete internal reporting and manage our business.

Marketing and service updates: to send permitted product information, invitations, newsletters or marketing communications, subject to applicable consent, opt-out and unsubscribe requirements.

Cookies and operational analytics: to operate the website, maintain sessions, secure the client portal, prevent fraud, remember preferences, understand website performance, collect page views and error logs, and improve services.

You may withdraw consent for optional processing, such as marketing or non-essential cookies, where applicable. Withdrawal of consent does not affect processing that is required to provide services, comply with law, protect against fraud, maintain records, enforce legal rights or meet regulatory obligations.

6. AML, KYC, KYB and Transaction Monitoring

Because we operate in a regulated financial services environment, we are required to collect and retain information that may be more extensive than information collected by ordinary commercial websites. This includes information needed to verify identity, verify corporate clients, identify beneficial owners, understand the purpose and nature of the relationship, assess risk, monitor transactions and comply with reporting obligations.

We may request additional documents or information at onboarding, during the business relationship or before processing a transaction. This may include proof of identity, proof of address, corporate documents, source of funds, source of wealth, beneficiary information, wallet information, payment purpose, supporting invoices, contracts and explanations of transaction activity.

We may screen clients, representatives, directors, beneficial owners, counterparties, beneficiaries, wallet addresses and transactions against sanctions, terrorist, PEP, HIO, adverse media, fraud, blockchain analytics and other risk databases. We may refuse, delay, suspend, block, restrict or terminate services where required by law, by our risk policies or by our partners, and we may not always be permitted to disclose the reasons for such action.

7. Travel Rule and Transaction Data

Where we provide or support virtual currency transfers or electronic funds transfers, we may collect, retain and transmit information about the originator and beneficiary of a transfer. This may include names, addresses, account numbers, reference numbers, wallet addresses, transaction identifiers, transaction hashes, sending and receiving addresses, asset type, amount, date, time, status and related compliance information.

We may share Travel Rule and transaction information with payment partners, virtual asset service providers, financial institutions, intermediaries, compliance providers, regulators, law enforcement and other parties where required or permitted by law or necessary to process the transaction. We may request additional information where a transfer is missing required information and may suspend, reject or delay the transaction pending review.

8. Automated Tools and Human Review

We may use automated tools to support identity verification, document checks, sanctions screening, PEP and HIO screening, fraud checks, blockchain analytics, transaction monitoring, Travel Rule checks, risk scoring and alert generation. These tools help us process information consistently and identify matters requiring review.

Automated tools support our compliance and risk processes, but TERALEX remains responsible for its own material compliance and risk decisions. Where required by law or by our internal procedures, decisions such as client rejection, account restriction, transaction hold, relationship termination or suspicious transaction escalation are reviewed by authorised personnel.

If you believe an automated tool has affected your information or your access to a service, you may contact us using the details in the Contacts section. We will consider the request in accordance with applicable law, AML restrictions, sanctions requirements, fraud prevention, security obligations and our recordkeeping duties.

9. Cookies and Similar Technologies

We may use cookies, pixels, tags, local storage, device identifiers and similar technologies to operate the website and client portal, maintain sessions, secure accounts, prevent fraud, remember preferences, understand website performance, collect page views and error logs, and improve services.

At the current stage, our cookie use is expected to focus on necessary and operational technologies, such as session management, authentication, security, diagnostics, error logging and basic performance measurement. We do not use marketing or behavioural advertising cookies unless they are separately enabled and disclosed.

If we use non-essential analytics, marketing, behavioural advertising or similar technologies in the future, we will provide information and consent or preference controls where required by applicable law. Further information is provided in our Cookie Policy.

10. When We Share Personal Information

We may disclose personal information to the following categories of recipients where necessary for the purposes described in this Policy:

  • Identity verification, KYC, KYB, sanctions, PEP, HIO, adverse media, blockchain analytics and fraud prevention providers.
  • Payment processors, banking partners, safeguarding providers, virtual currency infrastructure providers, virtual asset service providers, liquidity providers, custodial or wallet infrastructure providers and transaction counterparties.
  • Technology, hosting, cloud, email, data storage, cybersecurity, analytics, customer support and communications providers.
  • Professional advisers, auditors, insurers, consultants, legal counsel and accounting providers.
  • Regulators, FINTRAC, Bank of Canada, consumer protection authorities, privacy authorities, law enforcement, courts, tax authorities, sanctions authorities and other competent authorities where required or permitted by law.
  • Business counterparties in connection with a merger, acquisition, financing, restructuring, sale of assets, insolvency process or similar corporate transaction, subject to appropriate confidentiality arrangements.
  • Other parties with your consent or where disclosure is permitted or required by law.

We do not sell personal information in the ordinary meaning of that term. We do not permit service providers to use personal information for their own unrelated purposes unless you have consented or the law permits it.

11. Third-Party Service Providers

We may use third-party service providers to help deliver our services. These providers may process personal information on our behalf or as independent service providers depending on the nature of the service and applicable law. We use contractual and organisational measures designed to require service providers to protect personal information, use it only for authorised purposes, maintain appropriate safeguards, support audits or reviews where applicable and assist with regulatory or individual requests.

Where a service provider is involved in identity verification, transaction processing, virtual currency infrastructure, blockchain analytics, Travel Rule compliance, safeguarding, custody, recordkeeping, security, cloud hosting or operational systems, we may require that provider to make records, reports, logs and supporting evidence available to us in a form that can be used for internal review, audit, complaints, regulatory requests, legal compliance and evidence of client entitlement or transaction history.

12. International Transfers and Processing Outside Canada

Your personal information may be processed, stored or accessed in Canada and in other countries where we, our affiliates, our partners or our service providers operate. These countries may have privacy laws that differ from the laws in your jurisdiction.

When personal information is transferred to a service provider for processing, including outside Canada, we remain responsible for personal information under our control and use contractual or other measures designed to provide a comparable level of protection. Personal information processed in another jurisdiction may be accessible to courts, law enforcement, regulators or national security authorities in that jurisdiction in accordance with local law.

Where privacy or data protection law outside Canada applies to a specific transfer, we will use transfer measures required by that applicable law. These may include contractual, organisational, technical or other safeguards appropriate to the relevant processing activity.

13. Retention of Personal Information

We retain personal information for as long as necessary to provide services, manage the relationship, comply with legal and regulatory obligations, maintain business records, resolve disputes, prevent fraud, conduct audits and enforce our rights.

AML, KYC, KYB, transaction, Travel Rule, screening, monitoring, reporting, risk management, incident, safeguarding and related compliance records may be retained for at least five years or any longer period required by applicable law, regulatory expectation, litigation hold or internal risk requirement. Where information is no longer required, we will delete, destroy, anonymise or archive it in accordance with our retention procedures and applicable law.

Marketing preference information may be retained for as long as necessary to record your consent, opt-out or communication preferences. Security logs, fraud prevention records and system records may be retained for the period required to protect our services, investigate incidents and meet legal or operational requirements.

14. Security

We maintain administrative, technical and physical safeguards designed to protect personal information against loss, theft, unauthorised access, disclosure, copying, use, modification and destruction. These safeguards may include access controls, segregation of duties, encryption, authentication, two-factor authentication, monitoring, logging, backups, confidentiality obligations, vendor controls and incident response procedures.

No system can be guaranteed to be completely secure. You are responsible for keeping your login credentials, devices and authentication factors secure and for notifying us promptly of any suspected unauthorised access or suspicious activity.

15. Privacy Incidents

If we become aware of a breach of security safeguards involving personal information under our control, we will assess the incident and take steps required by applicable law. Where required, we will notify affected individuals, the Office of the Privacy Commissioner of Canada, provincial privacy authorities, the Bank of Canada, FINTRAC, law enforcement, service providers or other competent authorities, and we will keep records of breaches as required by law.

16. Your Privacy Choices and Rights

Subject to legal and regulatory limits, you may request access to personal information we hold about you and request correction of inaccurate or incomplete personal information. You may also ask questions about our privacy practices, challenge our compliance with this Policy or withdraw consent for optional uses.

Depending on your location and the privacy laws or consumer protection laws that apply to a specific processing activity, you may have additional rights in relation to your personal information. These may include rights to request deletion, restriction, portability, objection, withdrawal of consent where processing is based on consent, review of certain automated processing, or other rights that cannot be waived by contract. We will address such requests where required by applicable law.

These rights are not absolute. We may refuse, limit or delay a request where permitted or required by law, including where disclosure or deletion would conflict with AML, sanctions, fraud prevention, Travel Rule, recordkeeping, regulatory reporting, suspicious transaction analysis, tipping-off restrictions, legal privilege, legal claims, tax obligations, audit requirements, security investigations, safeguarding records, custody records or the rights of another person.

We may ask you to verify your identity before responding to a request. We will respond within the timeframe required by applicable law.

17. Marketing Communications and Opt-Out

Where we send commercial electronic messages, we will comply with Canada's Anti-Spam Legislation and other applicable marketing rules. Marketing messages will identify TERALEX, include required contact information and provide a working unsubscribe mechanism. We will process unsubscribe requests within the time required by law.

Even if you opt out of marketing, we may still send service, security, transactional, legal, compliance and account-related communications.

18. Children

Our services are not intended for minors. We do not knowingly provide regulated financial services to individuals who are not legally permitted to use them. If we learn that personal information has been collected from a minor contrary to our requirements, we may delete the information or close the related account, subject to legal and recordkeeping obligations.

19. Third-Party Websites

Our website or platform may contain links to third-party websites, applications or services. We are not responsible for the privacy practices, content or security of third-party websites or services. You should review the privacy policies of those third parties before providing personal information to them.

20. Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, technology, legal requirements, regulatory expectations, vendor arrangements or business practices. The updated version will be posted on our website or made available through another official communication channel with a revised effective date.

Where a change materially affects how we process personal information and applicable law requires notice, consent or another control, we will provide the required notice, consent request or preference mechanism. Operational, security, legal, sanctions, fraud prevention or regulatory changes may take effect sooner where required or appropriate.

We will keep this Policy under review, including in light of future Canadian privacy reform, changes to cookies and tracking rules, and changes to our regulated services.

21. Contacts

TERALEX has designated a Privacy Officer as the individual responsible for overseeing compliance with this Policy and applicable privacy law. If you have questions, requests or complaints about this Policy or our privacy practices, including privacy rights requests, you may contact the Privacy Officer as follows:

  • Company: TERALEX PAY LIMITED
  • Registration number: BC1536949
  • Office address: 5307 Victoria Drive #787, Vancouver, BC V5P 3V6, Canada
  • Website: https://teralex.com/
  • Contact email: support@teralex.com

If you are not satisfied with our response, you may have the right to contact the Office of the Privacy Commissioner of Canada, a provincial privacy authority or another competent authority depending on your location and the applicable law.

22. Legal and Regulatory References

This Policy is prepared with reference to applicable Canadian privacy, anti-spam, AML and payment services requirements, including PIPEDA, applicable provincial privacy laws, Canada's Anti-Spam Legislation, PCMLTFA and FINTRAC guidance, and Bank of Canada guidance where relevant. If other privacy or data protection laws apply to a specific individual, service or processing activity, TERALEX will address those obligations according to their applicable scope.