Introduction
Welcome to The Vault. The Vault is a software platform operated by Tria Software Limited, a company incorporated in Cyprus under registration number HE422111 with its registered office at Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus and operating under the brand name “The Vault” (“The Vault”, “we”, “us”, or “our”). Tria Software Limited is the data controller responsible for your personal data. We respect your privacy and are dedicated to safeguarding your personal information.
This Privacy Notice explains how The Vault collects, uses, stores, processes, and shares your personal data when you access our website or use The Vault software platform, whether delivered as a hosted software-as-a-service (“SaaS”) web application or deployed in your own environment. It also describes your rights under applicable data protection legislation and how you can exercise them.
Tria Software Limited is a software company and does not provide crypto-asset services. Crypto-asset services are provided by separately regulated entities under The Vault brand, which process your personal data in connection with those services and are the controllers of that data.
This Privacy Notice applies to visitors to our website, to individual clients who subscribe to The Vault platform, and to the employees, officers, contractors and other authorised users of our corporate clients who are given access to the platform.
This Privacy Notice has been prepared in accordance with:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”); and
- other applicable data protection and privacy laws.
Please read this Privacy Notice carefully. By using our website, the platform or The Vault’s services, you acknowledge that you have read and understood how we handle your personal data.
01. Who we are
Tria Software Limited, trading as The Vault, is the data controller responsible for your personal data. The Vault determines the purposes and means of processing your personal information and is accountable for ensuring that processing is carried out lawfully, fairly, and transparently.
- Entity
- Tria Software Limited
- Registered address
- Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus
- Company registration
- HE422111
- Privacy contact email
- privacy@thevault.inc
If you have any questions about this Privacy Notice or The Vault’s data practices, please contact us using the details set out in Section 11.
Our role: controller and processor
Depending on the personal data concerned, The Vault acts either as a controller or as a processor.
The Vault is the controller of personal data relating to: visitors to our website; individual clients who subscribe to the platform in their own name; the authorised users, administrators and contact persons of our corporate clients; and the representatives of our suppliers and partners. This Privacy Notice governs that processing.
The Vault acts as a processor in respect of the content that a corporate client stores or generates within its instance of the platform, including personal data relating to that client’s own customers. In that case the client is the controller, we process the data only on the client’s documented instructions under a written data processing agreement, and we do not use that data for our own purposes. If you are a customer of one of our clients, please address any privacy request to that client, which is responsible for responding to you; if you contact us, we will forward your request to the relevant client.
Where the platform is deployed on-premises in a client’s own infrastructure, The Vault has no access to the personal data held in that deployment except to the limited extent, and for the limited duration, that the client grants us access for support or maintenance purposes.
02. Personal data we collect
The Vault may collect, use, store, and process the following categories of personal data, depending on how you interact with our website, platform and services:
- Identity Data
- First name, last name, username, job title and employer, and, where required for client due diligence or sanctions screening, date of birth and government-issued identification documents.
- Contact Data
- Email address, telephone number, billing address, correspondence address.
- Account and Credential Data
- Account identifiers, hashed passwords, multi-factor authentication enrolment data, API keys and tokens, user roles, permissions and approval rights configured for you within the platform.
- Client and Contract Data
- Where you contract with us, as, or on behalf of a legal entity: company name, registration number, registered address, VAT number, and the names, roles and contact details of directors, authorised signatories, administrators and other representatives, together with the corporate documents supporting them.
- Billing and Payment Data
- Subscription and invoicing records, VAT and tax identifiers, payment references and payment history. We do not collect or store full payment card details; card payments, where offered, are handled by a third-party payment provider.
- Platform Content Data
- Data you or your organisation enter into or generate within the platform, including wallet addresses, transaction records, account balances, counterparty references, approval policies and uploaded documents. We process this data on your or your organisation’s instructions in order to operate the platform, and not for our own purposes.
- Technical Data
- IP address, device identifiers, browser type and version, operating system, login timestamps, session identifiers.
- Usage Data
- Pages visited, features accessed, interaction logs, click-stream data, time spent on the website and the platform.
- Security and Audit Data
- Immutable audit-trail records of actions taken within the platform, including who initiated, approved or rejected an operation and when; authentication and authorisation events; and security event, alert and incident records.
- Due Diligence and Screening Data
- Information and documents collected to verify the identity of our clients and their representatives, proof of address, and the results of screening against applicable sanctions and restrictive-measures lists.
- Communications Data
- Records of correspondence, support tickets, complaints, and feedback submitted to The Vault, including any logs, screenshots or diagnostic files you send us in support of a request.
Special Categories of Personal Data. The Vault does not intentionally collect or process special categories of personal data (such as data concerning health, racial or ethnic origin, religious beliefs, biometric data, or sexual orientation) unless it is strictly required by applicable law or regulation. Where such processing is necessary, The Vault will rely on an appropriate legal basis under Article 9 GDPR and will notify you accordingly. Please do not include special categories of personal data in support requests or upload them to the platform where this is not necessary.
Where you provide us with personal data relating to other individuals, for example your colleagues, directors or beneficial owners, you confirm that you are entitled to do so and that those individuals have been informed of this Privacy Notice.
Our website and the platform are not directed at children, and we do not knowingly collect personal data from persons under the age of 18.
03. Lawful basis for processing
The Vault processes your personal data only where a lawful basis exists under Article 6 of the GDPR. The following table sets out the primary purposes for which The Vault processes your data as a controller and the corresponding lawful basis applied:
| Processing purpose | Lawful basis | GDPR article |
|---|---|---|
| Account registration, onboarding, and management | Performance of a contract | Art. 6(1)(b) |
| Providing, hosting, supporting and maintaining the platform | Performance of a contract | Art. 6(1)(b) |
| Responding to enquiries, demo requests and other messages you send us | Legitimate interests / steps prior to entering into a contract | Art. 6(1)(f) / (b) |
| Billing, invoicing, collection and the keeping of accounting records | Performance of a contract / legal obligation | Art. 6(1)(b) / (c) |
| Client due diligence and screening against sanctions and restrictive measures | Legal obligation | Art. 6(1)(c) |
| Complying with regulatory, and reporting obligations | Legal obligation | Art. 6(1)(c) |
| Detecting, investigating, and preventing fraud and security incidents | Legitimate interests | Art. 6(1)(f) |
| Maintaining authentication, access control and audit-trail records of the platform | Legitimate interests / performance of a contract | Art. 6(1)(f) / (b) |
| Improving and maintaining our website, platform and services | Legitimate interests | Art. 6(1)(f) |
| Sending marketing and promotional communications | Consent | Art. 6(1)(a) |
| Placing non-essential cookies and similar technologies | Consent | Art. 6(1)(a) |
| Responding to legal or regulatory authority requests | Legal obligation | Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Legitimate interests | Art. 6(1)(f) |
Where The Vault acts as a processor, we process personal data solely on the documented instructions of the client that is the controller, as set out in the applicable data processing agreement, and the lawful basis for that processing is determined by that client.
Certain personal data is required by law, regulation, or contract in order for The Vault to provide its services, including identity verification and sanctions screening information. Failure to provide such data may prevent The Vault from establishing or maintaining a business relationship with you or providing access to the platform.
The Vault does not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and does not profile users of the platform. Where the platform applies approval, limit or policy rules to an operation, those rules are configured and controlled by you or by your organisation, not by The Vault.
Where The Vault relies on legitimate interests as its lawful basis, we have conducted a legitimate interests assessment and are satisfied that our interests are not overridden by your fundamental rights and freedoms. The legitimate interests pursued by The Vault include maintaining platform security, preventing fraud, improving services, protecting business operations, and ensuring the integrity of the platform, responding to enquiries about our products, and maintaining a reliable record of who did what within the platform.
Where The Vault relies on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. See Section 9 for how to exercise this right.
04. How we use your personal data
The Vault uses your personal data to provide, maintain, and improve its website, platform and services. Specifically, The Vault processes your data to:
- create, verify, and manage your account and your access rights within the platform;
- host, operate, monitor and support the SaaS web application and provide maintenance, updates and technical support;
- respond to enquiries, demo requests, partnership proposals and job applications submitted through the website;
- carry out client due diligence and screen clients and their representatives against applicable sanctions and restrictive-measures lists;
- issue invoices, collect payment and keep the accounting and tax records required of us;
- detect, prevent, investigate, and report fraud, unauthorised access, misuse of the platform and security incidents, and to maintain audit-trail and security records;
- provide customer support and respond to your enquiries or complaints;
- send you service-related communications, security alerts, and account notifications, including notices of planned maintenance, releases and end-of-support;
- send you marketing communications about The Vault’s products and features, where you have given consent or where otherwise permitted by law;
- analyse platform usage and performance to improve our features and user experience;
- comply with applicable laws, regulations, and binding directions from competent authorities; and
- enforce our terms of service, licence terms, policies, and legal agreements, and establish, exercise or defend legal claims.
The Vault will not use your personal data for any purpose that is incompatible with the purposes set out in this Privacy Notice without providing you with prior notice and, where required, obtaining your consent.
We do not use Platform Content Data, or personal data processed on behalf of a client, to train machine-learning models or to develop products for other clients.
05. Sharing your personal data
The Vault does not sell, rent, or trade your personal data to third parties for commercial or marketing purposes.
The Vault may share your personal data in the following limited and controlled circumstances:
Service Providers
The Vault engages carefully selected third-party service providers to support its operations. These include providers of IT infrastructure and cloud hosting, identity verification and screening services, payment processing, cybersecurity, and customer support, as well as monitoring, logging, ticketing and communication tools. All service providers are bound by data processing agreements and are required to process data only on The Vault’s documented instructions and to implement appropriate security measures.
Sub-processors
Where we act as a processor for a client, we engage sub-processors only as permitted by the applicable data processing agreement, impose the same data protection obligations on them, and remain responsible to the client for their performance. A current list of sub-processors, together with the hosting locations used, is made available to clients and updated in accordance with that agreement.
Professional Advisers
The Vault may share data with lawyers, auditors, accountants, compliance consultants, and insurers where necessary for the delivery of professional services, regulatory compliance, or dispute resolution, and with independent auditors carrying out security or assurance examinations of our services.
Regulatory and Law Enforcement Authorities
The Vault may be required to disclose your personal data to competent regulatory bodies, law enforcement agencies, tax authorities, or courts where required by applicable law, a court order, or a binding regulatory directive. Where we hold the data as a processor and are legally permitted to do so, we will inform the relevant client before disclosing it.
Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of The Vault’s business or assets, your personal data may be transferred to the relevant successor entity. The Vault will provide notice of any such transfer and applicable privacy protections.
06. International data transfers
The Vault may transfer your personal data to countries or territories outside the European Economic Area (EEA) in the course of delivering its services, principally where our service providers or members of our support and engineering teams are located outside the EEA. Where such transfers occur, The Vault ensures that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- transfers to countries that have received an adequacy decision from the European Commission; or
- other legally recognised transfer mechanisms under Chapter V of the GDPR.
Hosting locations for the SaaS platform are agreed with each client and are set out in the applicable service documentation. Where a client requires that its data remain within the EEA, we will host it accordingly.
Where transfers are carried out using Standard Contractual Clauses, you may request a copy of the relevant safeguards by contacting The Vault using the details set out in Section 11.
07. Data retention
The Vault retains your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, reporting, and compliance obligations. The Vault’s retention periods are determined by reference to the nature of the data, the purpose of processing, and applicable legal requirements. Indicative retention periods include:
- client due diligence and sanctions screening records: retained for the duration of the business relationship and for up to five (5) years thereafter, or longer where required by applicable law;
- account information and contractual records: retained for the duration of the relationship with you and for up to six (6) years thereafter for legal and regulatory purposes;
- billing, invoicing and accounting records: retained for six (6) years from the end of the relevant tax year, as required by Cyprus tax and accounting law;
- security and audit-trail records generated within the platform: retained for the term of the client’s subscription and for the period agreed with that client thereafter, and in any event for as long as necessary for security investigations, dispute resolution or legal proceedings;
- customer support correspondence, complaints, and communications data: retained for up to two (2) years following resolution of the relevant matter;
- marketing and promotional data: retained until you withdraw your consent, unsubscribe, or after twenty-four (24) months of inactivity, whichever occurs first;
- technical logs, security records, and platform usage data: generally retained for up to twelve (12) months, unless a longer retention period is necessary for security investigations, fraud prevention, dispute resolution, or legal proceedings.
Personal data that we process as a processor on behalf of a client is retained for as long as that client instructs. On termination or expiry of the relevant agreement we will delete or return it in accordance with that client’s instructions, save where we are required by law to retain a copy.
In certain circumstances, The Vault may retain personal data for longer periods where necessary to establish, exercise, or defend legal claims, comply with ongoing investigations or regulatory requests, or fulfil other legal obligations.
Where retention is no longer required, The Vault will securely delete or irreversibly anonymise your personal data in accordance with its internal data disposal procedures. Anonymised data that can no longer be linked to an identifiable individual may be retained indefinitely for analytical purposes.
Audit-trail entries within the platform are designed to be tamper-evident and cannot be selectively altered without compromising the integrity of the record; where such an entry contains your personal data, we will consider a restriction or erasure request in the light of that constraint and of our and our client’s record-keeping obligations.
08. Data security
The Vault implements rigorous technical and organisational security measures designed to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include, but are not limited to:
- encryption of personal data in transit (TLS/SSL) and at rest;
- role-based access controls and least-privilege access principles;
- multi-factor authentication for access to sensitive systems;
- periodic security assessments and testing, and vulnerability assessments, including independent penetration testing and code review of the platform;
- segregation of client environments and of production from non-production systems;
- tamper-evident audit logging of privileged and client-facing actions;
- incident detection, response, and recovery procedures; and
- ongoing staff training on data protection and information security obligations.
Access to your personal data is restricted to those employees, agents, and contractors of The Vault who have a legitimate business need to access it. All such persons are subject to confidentiality obligations. Access by our personnel to a client’s production environment is granted only where necessary for support or maintenance, is logged, and is revoked when no longer required.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, The Vault will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, The Vault will also notify you directly without undue delay in accordance with Article 34 GDPR. Where we become aware of a breach affecting personal data that we process on behalf of a client, we will notify that client without undue delay so that it can meet its own obligations.
09. Your data subject rights
As a data subject under the GDPR, you have the following rights in relation to your personal data held by The Vault as a controller. These rights apply subject to applicable exemptions and limitations under data protection law.
If your personal data is held in a client’s instance of the platform and we act only as a processor, please address your request to that client. If you send the request to us, we will forward it to the client without undue delay and support the client in responding.
- Right of Access (Article 15 GDPR)
- You have the right to request confirmation of whether The Vault processes your personal data and, if so, to obtain a copy of that data together with supplementary information about how it is processed. The Vault will provide this information free of charge.
- Right to Rectification (Article 16 GDPR)
- You have the right to request that The Vault corrects any inaccurate personal data and completes any incomplete data held about you without undue delay.
- Right to Erasure / ‘Right to be Forgotten’ (Article 17 GDPR)
- You have the right to request that The Vault deletes your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent on which processing was based, or where processing is otherwise unlawful. This right is subject to The Vault’s legal retention obligations and to the integrity of platform audit records.
- Right to Restriction of Processing (Article 18 GDPR)
- You have the right to request that The Vault restricts processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where processing is unlawful but you do not want the data erased.
- Right to Data Portability (Article 20 GDPR)
- Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
- Right to Object (Article 21 GDPR)
- You have the right to object to processing of your personal data where The Vault relies on legitimate interests as its lawful basis. You also have an absolute right to object to processing of your personal data for direct marketing purposes at any time.
- Right to Withdraw Consent (Article 7(3) GDPR)
- Where The Vault processes your personal data on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of the rights listed above, please submit a request to The Vault using the contact details in Section 11. The Vault will respond to all valid requests within one calendar month of receipt. Where a request is particularly complex or numerous, this period may be extended by up to two further months, and The Vault will notify you of any such extension within the initial one-month period. We may ask you for information reasonably necessary to confirm your identity before acting on a request.
You also have the right to lodge a complaint with the competent data protection supervisory authority. The lead supervisory authority for The Vault is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus:
- Website: www.dataprotection.gov.cy
- Email: commissioner@dataprotection.gov.cy
If you are based in another EU member state, you may also lodge a complaint with your local national data protection supervisory authority.
10. Cookies and tracking technologies
The Vault’s website and platform may use cookies and similar tracking technologies to deliver, maintain, and improve its services. Where The Vault uses non-essential cookies (such as analytics or marketing cookies), it will request your consent before placing them. Cookies used inside the platform are limited to those strictly necessary to authenticate you and keep your session secure.
You can manage your cookie preferences at any time through our cookie consent tool or your browser settings. Please note that disabling certain cookies may affect the functionality of the website and the platform.
A full description of the cookies used by The Vault, the purposes for which they are set, and how to manage them is available in our Cookie Policy, which is incorporated into this Privacy Notice by reference.
11. How to contact us
If you have any questions about this Privacy Notice, wish to exercise any of your rights, or want to make a complaint about how we handle your personal data, please contact us:
- Entity
- Tria Software Limited
- Address
- Arch. Makariou III & Markou Drakou, 66-68, Mesa Geitonia, 4003, Limassol, Cyprus
- privacy@thevault.inc
Clients with questions about our role as a processor, our sub-processors or our data processing agreement should contact their account manager or write to the same address.
12. Changes to this Privacy Notice
The Vault may update this Privacy Notice from time to time to reflect changes in applicable law, regulatory guidance, or its business operations and data practices. The updated Privacy Notice will be published on our website.
For material changes that may significantly affect how The Vault processes your personal data, The Vault will provide additional notice, for example by email notification or a prominent notice on our website or the platform, before the changes take effect.
The Vault encourages you to review this Privacy Notice periodically to stay informed of how your personal data is being used and protected.