Privacy Policy
This Privacy Policy explains how Novolut collects, uses, stores, shares and protects personal data in connection with the Novolut website, request forms, onboarding processes, platform access, product workflows, partnership inquiries and related communications.
This Privacy Policy applies to visitors of the Novolut website, individuals submitting request forms, representatives of companies, beneficial owners, directors, authorized users, platform users, partner representatives, infrastructure partner contacts, suppliers, service providers and other individuals whose personal data may be processed by Novolut.
This Privacy Policy does not create platform access, onboarding approval, service eligibility, infrastructure partner approval or any commercial relationship with Novolut.
1. About Novolut
Novolut provides a financial infrastructure operating layer for international business.
The Novolut platform is designed to help qualified businesses and approved partners coordinate access, workflows, records, routing, reporting and reconciliation across connected financial infrastructure.
Novolut may support workflows involving accounts, payments, FX, liquidity coordination, approved settlement flows, corporate cards, payment acceptance, reporting and operational controls through one controlled platform environment.
Novolut does not provide all underlying regulated financial services directly. The underlying regulated infrastructure may be provided by approved banking, payment, EMI, issuing, acquiring, custody, settlement, liquidity, FX, compliance or other infrastructure partners, depending on the product, jurisdiction, use case and approval status.
2. Personal data we may collect
Novolut may collect and process personal data that you provide directly, that is generated through your use of the website or platform, or that is obtained from approved third parties, service providers, infrastructure partners, compliance providers or public sources.
The personal data we may collect depends on your relationship with Novolut, the nature of the inquiry, the relevant product or workflow, onboarding status, compliance requirements and infrastructure partner requirements.
3. Information submitted through request forms
When you submit a request through the Novolut website, we may collect:
- full name;
- business email address;
- phone number;
- company name;
- job title or role;
- country or jurisdiction;
- company website;
- inquiry type;
- business activity;
- expected use case;
- expected transaction volume;
- expected currencies, corridors or markets;
- partnership type;
- infrastructure or integration requirements;
- message content;
- documents or files submitted by you;
- communication preferences;
- any other information included in the request.
Request form information may be used to evaluate whether Novolut may be able to support the requested business model, platform access, partnership inquiry, infrastructure integration, referral opportunity, flow partnership or dedicated contour discussion.
4. Company, KYB, KYC and UBO information
Where onboarding, compliance review or partnership assessment is required, Novolut may collect and process information about companies and connected individuals.
This may include:
- company registration documents;
- certificate of incorporation or equivalent;
- corporate registry extract;
- constitutional documents;
- ownership structure;
- UBO information;
- director information;
- authorized representative information;
- signatory information;
- proof of address;
- identity documents;
- date of birth;
- nationality;
- country of residence;
- role within the company;
- ownership percentage;
- control relationship;
- board resolutions or authorization documents;
- group structure charts;
- licenses, permits or regulatory registrations;
- expected transaction profile;
- business description;
- source-of-funds or source-of-activity information;
- supplier, customer or counterparty information;
- supporting commercial documents.
Novolut may also process information required to verify directors, beneficial owners, controllers, signatories, administrators, platform users or other individuals connected to a client or partner.
5. Transaction, workflow and platform data
Where a client, partner or authorized user accesses the Novolut platform or related workflows, Novolut may process operational data connected to platform activity.
This may include:
- company profile data;
- user profile data;
- user roles and permissions;
- login and authentication records;
- account or balance records;
- wallet records;
- payment instructions;
- transaction records;
- transaction statuses;
- payment routes;
- currencies and amounts;
- FX workflow data;
- settlement records;
- corporate card records;
- payment acceptance records;
- merchant profile data;
- payout records;
- approval history;
- user actions;
- reporting fields;
- reconciliation records;
- documents linked to transactions;
- provider reference data;
- audit logs;
- support and communication records.
Such data may include personal data where it relates to an identifiable individual, such as an authorized user, representative, cardholder, beneficiary, payer, payee, supplier contact, merchant contact, contractor, employee, director or beneficial owner.
6. Compliance, screening and monitoring data
Novolut may collect and process personal data for compliance, risk, AML, KYC, KYB, sanctions, fraud prevention, onboarding, transaction monitoring and financial crime risk-management purposes.
This may include:
- screening results;
- sanctions, PEP and adverse media indicators;
- risk ratings;
- onboarding decisions;
- compliance notes;
- document verification results;
- transaction monitoring alerts;
- wallet screening results where applicable;
- source-of-funds or source-of-activity materials;
- counterparty information;
- fraud indicators;
- infrastructure partner feedback;
- restriction, rejection or suspension records;
- audit and review records.
Where digital asset or stablecoin-related workflows are relevant, Novolut may process wallet-related information, blockchain transaction references, wallet ownership evidence, transaction source information, destination information, screening results and supporting documentation.
7. Website, device and technical data
When you visit the Novolut website, we may collect technical data such as:
- IP address;
- device type;
- browser type;
- operating system;
- pages visited;
- referral source;
- session data;
- time and date of visit;
- approximate location derived from IP address;
- cookie identifiers;
- analytics data;
- interaction data;
- security logs.
This information may be collected through cookies, analytics tools, server logs or similar technologies. More information is provided in the Novolut Cookie Policy.
8. Communications data
When you communicate with Novolut, we may process:
- email correspondence;
- request form messages;
- meeting notes;
- call notes;
- support inquiries;
- commercial discussions;
- legal or compliance inquiries;
- partnership communications;
- documents exchanged during discussions;
- records of requests and responses.
Novolut may retain communication records for operational, legal, compliance, security, audit, dispute resolution, onboarding, partner-management and business-continuity purposes.
9. How we use personal data
Novolut may use personal data for the following purposes:
- responding to inquiries;
- reviewing request forms;
- evaluating platform access requests;
- evaluating partnership opportunities;
- assessing infrastructure partner fit;
- conducting KYB, KYC and UBO checks;
- conducting sanctions, PEP and adverse media screening;
- reviewing business activity;
- reviewing source of funds or source of activity;
- assessing expected transaction volume and use case;
- onboarding clients, users or partners;
- managing platform access;
- configuring user roles and permissions;
- coordinating workflows, records and reporting;
- supporting payment, settlement, card, payout, payment acceptance or treasury workflows where approved;
- monitoring transactions and platform activity;
- preventing fraud, misuse, sanctions exposure and financial crime;
- supporting compliance and risk-management processes;
- sharing information with infrastructure partners where required or permitted;
- managing contracts and commercial relationships;
- providing support and operational communications;
- securing the website and platform;
- improving website functionality and user experience;
- maintaining records and audit trails;
- complying with legal, regulatory, contractual and infrastructure partner obligations;
- enforcing Novolut’s terms, policies and notices;
- protecting Novolut, clients, partners, infrastructure providers and third parties.
Novolut does not use personal data to create platform access, onboarding approval or service eligibility automatically. Access remains subject to review, approval, provider coverage, contractual terms and compliance requirements.
10. Legal bases for processing
Where applicable data protection laws require a legal basis for processing, Novolut may rely on one or more of the following legal bases:
- performance of a contract or steps taken before entering into a contract;
- compliance with legal or regulatory obligations;
- legitimate interests;
- consent, where required;
- establishment, exercise or defense of legal claims;
- substantial public interest or other permitted grounds where required for compliance or financial crime prevention.
Novolut’s legitimate interests may include operating and improving the website, reviewing business inquiries, conducting client and partner assessments, preventing fraud, managing risk, securing systems, supporting platform operations, maintaining records, communicating with potential clients and partners, and protecting the Novolut platform, users, partners and infrastructure providers.
Where consent is required, you may withdraw consent at any time. Withdrawal of consent does not affect processing carried out before withdrawal and may affect Novolut’s ability to provide certain website functions, communications or services.
11. Sharing personal data
Novolut may share personal data where required or permitted for the purposes described in this Privacy Policy.
Recipients may include:
- Novolut group companies or affiliates;
- approved infrastructure partners;
- banking, payment, EMI, issuing, acquiring, custody, settlement, liquidity, FX or OTC providers;
- compliance, KYB, KYC, AML, sanctions screening and transaction monitoring providers;
- identity verification providers;
- fraud prevention providers;
- technology providers;
- cloud hosting providers;
- analytics providers;
- communication providers;
- legal, audit, accounting, tax and professional advisers;
- regulatory authorities;
- law enforcement agencies;
- courts, tribunals or dispute-resolution bodies;
- prospective partners, counterparties or service providers where relevant to a proposed relationship;
- other third parties where necessary for legal, regulatory, contractual, security, operational or compliance purposes.
Novolut may share onboarding information, compliance documents, risk information, transaction records or supporting materials with infrastructure partners where required or permitted for onboarding, service delivery, monitoring, reporting, compliance or risk-management purposes.
12. Infrastructure partner processing
Where an infrastructure partner provides regulated or operational services, that infrastructure partner may process personal data under its own privacy policy, terms, onboarding requirements and compliance framework.
Infrastructure partners may act as independent controllers, processors or service providers depending on the specific relationship, product, workflow and jurisdiction.
Novolut is not responsible for the privacy practices of infrastructure partners where they process personal data under their own terms and policies.
Clients, partners and users may be required to provide information directly to infrastructure partners as part of onboarding, service delivery, transaction monitoring or compliance review.
13. International transfers
Novolut may process and transfer personal data internationally.
Personal data may be processed in jurisdictions where Novolut, its affiliates, infrastructure partners, service providers, compliance providers, technology providers, professional advisers or other approved recipients operate.
Where required by applicable law, Novolut will use appropriate safeguards for international transfers, which may include contractual safeguards, transfer agreements, standard contractual clauses, adequacy decisions or other lawful transfer mechanisms.
14. Data retention
Novolut retains personal data for as long as necessary for the purposes described in this Privacy Policy.
Retention periods may depend on:
- the nature of the data;
- the purpose of processing;
- onboarding status;
- client or partner relationship;
- legal and regulatory requirements;
- AML, KYC and financial crime recordkeeping requirements;
- infrastructure partner requirements;
- contractual obligations;
- audit requirements;
- dispute resolution needs;
- fraud prevention needs;
- security and operational needs;
- limitation periods;
- whether a request, review, transaction, investigation or dispute is ongoing.
Novolut may retain certain records after a request is declined, a relationship ends, access is terminated or a transaction is completed where retention is necessary for legal, regulatory, compliance, fraud prevention, audit, risk-management, dispute resolution or operational purposes.
15. Security of personal data
Novolut applies technical, organizational and operational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure or destruction.
These measures may include access controls, permissioning, authentication, encryption where appropriate, audit logs, role-based controls, monitoring, secure infrastructure, vendor controls, staff access restrictions and internal policies.
No website, platform, transmission method, storage system or technical environment can be guaranteed to be completely secure. Novolut encourages users and authorized representatives to protect credentials, devices and communications and to report suspected unauthorized access or security incidents promptly.
16. Your rights
Depending on your jurisdiction and applicable data protection law, you may have rights in relation to your personal data.
These may include the right to:
- request access to personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing;
- request portability of personal data;
- withdraw consent where processing is based on consent;
- object to direct marketing;
- lodge a complaint with a data protection authority.
These rights may be subject to limitations, exemptions, identity verification, legal obligations, AML/KYC recordkeeping requirements, infrastructure partner requirements, fraud prevention needs, ongoing investigations, legal claims or other lawful grounds for retention or processing.
Novolut may request information to verify your identity and authority before responding to a privacy request.
17. Automated decision-making
Novolut does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless permitted by applicable law and subject to appropriate safeguards.
Novolut may use automated or semi-automated tools to support screening, fraud prevention, sanctions checks, transaction monitoring, risk indicators, wallet screening, security monitoring or workflow review.
Human review may be applied where required or appropriate, including for onboarding, compliance, risk and infrastructure access decisions.
18. Marketing communications
Novolut may use contact information to send relevant institutional, product, partnership or commercial communications where permitted by applicable law.
You may opt out of marketing communications by using the unsubscribe mechanism where available or by contacting Novolut.
Operational, legal, compliance, onboarding, security, service, relationship or transaction-related communications may still be sent where necessary.
19. Children
The Novolut website, platform and services are not intended for children.
Novolut does not knowingly collect personal data from children.
If Novolut becomes aware that personal data has been collected from a child without appropriate authority, Novolut may delete or restrict that data where required.
20. Third-party websites
The Novolut website may contain links or references to third-party websites, partners, service providers or infrastructure providers.
Novolut is not responsible for their privacy practices, content, security, policies or data processing activities.
You should review the privacy policies of any third-party websites or services you access.
21. Changes to this Privacy Policy
Novolut may update this Privacy Policy from time to time.
The updated version will be posted on this website with a revised “Last updated” date.
Novolut may provide additional notice of material changes where required by applicable law.
22. Contact
Questions about this Privacy Policy or privacy-related requests may be submitted through the Novolut request form.
Novolut reviews privacy-related requests according to the applicable data processing activity and relevant privacy rights.
Submitting a privacy request does not create platform access, onboarding approval, service eligibility or any commercial relationship with Novolut.
For privacy-related matters, contact: [email protected]