Nodu Group Client Privacy Notice

How the Nodu group company that onboards you as a client, or provides services to you, processes personal data.

Last updated 30.09.2026

This notice explains how the Nodu group company that onboards you as a client, or provides services to you, processes personal data. It applies to clients and applicants for onboarding and, where relevant, to their directors, beneficial owners, authorised representatives and users, and the payers, beneficiaries and other counterparties of their transactions. How personal data of website visitors and of people who send an enquiry is handled is explained in the Website and Enquiries Privacy Notice.

Part A applies to all clients. Part B applies where Nodu Digital SIA is responsible for your personal data, and Part C where Nodu Canada, Inc. is responsible for it.

Part A. Provisions that apply to all clients

A1. Which company is responsible for your personal data

Services are provided either by Nodu Digital SIA or by Nodu Canada, Inc. After an enquiry has been reviewed, the Nodu group decides which company can onboard the client, and that company is named in the client’s agreement. The company that onboards you, or with which you apply for onboarding, is the controller of your personal data. Each company is responsible for the personal data it processes for its own clients.

Company Company details Privacy contact
Nodu Digital SIA Limited liability company registered in Latvia, registration number 40203662782, registered office at Aspazijas bulvāris 20, Riga, LV-1050, Latvia. Authorised and regulated by Latvijas Banka as a payment institution and as a crypto-asset service provider under MiCA legal@nodu.fi
Nodu Canada, Inc. Corporation incorporated in Ontario, Canada, Ontario Business Registry ID 1001337843, Business Number 774641831, registered office at 145½ Church Street, Unit 5, Office #180, Toronto, Ontario, M5B 1Y4, Canada. Registered with FINTRAC as a money services business, registration number C100001091 Privacy Officer, canada@nodu.fi

In this notice, “we”, “us” and “our” mean the company responsible for your personal data under this section.

A2. Personal data we collect

  • Identification data: name, date of birth, nationality, identification documents and, where required, a photograph or video taken during identity verification.

  • Contact data: email address, telephone number, address and proof of address.

  • Business and control data: corporate registration details, ownership and control structure, directors, beneficial owners, authorised representatives and users, the purpose and intended nature of the business relationship, expected activity and, where required, source of funds and source of wealth.

  • Due diligence and screening data: results of checks against sanctions lists, politically exposed person lists and adverse media, risk ratings and, where applicable law permits, information about criminal convictions or offences revealed by those checks.

  • Payment, transaction and wallet data: bank account details, payment information, crypto-asset wallet addresses, transaction details, originator and beneficiary information, and the information that must accompany transfers of funds and crypto-assets under applicable law (the “travel rule”).

  • Biometric data used in electronic identity verification, where applicable and with consent.

  • Technical data: IP address, device information and access logs when you use our client interfaces.

  • Communications: correspondence with you and records of your instructions and requests.

We collect this data from you or the client you represent, from public registers and other public sources, from identity verification, screening and blockchain analytics providers, from banks and other payment or crypto-asset service providers involved in a transaction, and from other Nodu group companies, including enquiry information received through the Nodu website.

Much of this information is required by law. If it is not provided, we may be unable to onboard the client, carry out a transaction or continue the relationship.

A3. How we use personal data

We use personal data to:

  • review enquiries and applications, and decide whether and through which Nodu group company services can be provided;

  • carry out customer due diligence, including identity verification, beneficial ownership checks, sanctions and politically exposed person screening, risk assessment and ongoing monitoring;

  • provide our services, execute and record transactions, and manage the client relationship;

  • comply with anti-money laundering, counter-terrorist financing, sanctions, travel rule, tax reporting, record-keeping and regulatory reporting obligations, including reporting suspicious transactions to the competent authorities;

  • prevent and investigate fraud and other misuse, and protect our systems and clients;

  • manage operational, compliance and financial risk, including at Nodu group level;

  • respond to requests from regulators, courts and other public authorities; and

  • establish, exercise or defend legal claims.

A4. Sharing within the Nodu group and with others

  • Nodu group companies. Enquiry information received through the Nodu website is passed by Nodu Group Limited, which operates the website, to the company selected to onboard the client. Customer due diligence information may be shared between Nodu Digital SIA and Nodu Canada, Inc. where a client applies for, or is assessed for, services from the other company, or asks to move from one company to the other, to the extent permitted by applicable anti-money laundering law. Information may also be shared for group-level risk management and compliance oversight, and with Nodu group companies that support our operations, including Nodu Group Limited in the United Kingdom.

  • Service providers: identity verification, screening and blockchain analytics providers, banks, payment institutions, crypto-asset and liquidity providers, cloud and IT providers, customer support providers, auditors and professional advisers. They are bound by contract to protect personal data and to use it only for authorised purposes.

  • Transaction participants: banks, payment and crypto-asset service providers and counterparties, where needed to execute a transaction or to send the information that must accompany it by law.

  • Public authorities: supervisors, financial intelligence units, tax authorities, law enforcement agencies and courts, where required or permitted by law. The authorities for each company are named in Parts B and C.

A5. Automated tools

We use automated tools for identity verification, screening, risk scoring and transaction monitoring. Where a decision based solely on automated processing produces legal effects concerning you or similarly significantly affects you, you may ask for human review of the decision, express your point of view and contest the decision, subject to applicable law.

A6. Security and data breaches

We maintain technical, organisational and contractual safeguards appropriate to the sensitivity of the data, including access controls, authentication, encryption or equivalent protection where appropriate, logging, vendor controls, staff confidentiality obligations, security monitoring and incident response procedures. We notify data breaches to the competent authorities and to affected individuals where required by law.

A7. Changes to this notice

We may update this notice to reflect changes in our practices or legal obligations. The current version is published on the Nodu website, with the date of the last update shown at the top. Where the law requires, or where a change is material, we will give additional notice.

Part B. Nodu Digital SIA

This part applies where Nodu Digital SIA is responsible for your personal data. Nodu Digital SIA processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and Latvian law.

Purpose Legal basis under the GDPR
Customer due diligence, ongoing monitoring, sanctions screening, record-keeping and reporting under Latvian anti-money laundering, counter-terrorism and counter-proliferation financing and sanctions law Compliance with a legal obligation (Article 6(1)(c))
Collecting and sending the information that must accompany transfers of funds and crypto-assets under Regulation (EU) 2023/1113 Compliance with a legal obligation (Article 6(1)(c))
Meeting obligations under Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), Latvian payment services law and tax reporting law, and responding to requests from competent authorities Compliance with a legal obligation (Article 6(1)(c))
Providing services under an agreement with you, or taking steps at your request before entering into one Performance of a contract (Article 6(1)(b))
Processing personal data of representatives, beneficial owners and other individuals connected with a corporate client, where this is not required by law Our legitimate interest in onboarding and serving the client (Article 6(1)(f))
Fraud prevention, security, group-level risk management, and establishing, exercising or defending legal claims Our legitimate interests (Article 6(1)(f))
Biometric data used in identity verification Your explicit consent (Article 9(2)(a))

Information about criminal convictions and offences is processed only to the extent permitted by Latvian anti-money laundering law.

B2. Authorities

Nodu Digital SIA is supervised by Latvijas Banka. It reports to the Financial Intelligence Unit of Latvia and, where required, to the State Revenue Service and other competent authorities.

B3. Retention

Customer due diligence and transaction records are generally kept for five years after the end of the business relationship or the date of an occasional transaction, unless Latvian law or a competent authority requires a longer period. Other personal data is kept only as long as needed for the purposes for which it was collected, including resolving disputes and meeting accounting and tax obligations, and is then deleted or anonymised.

B4. Transfers outside the European Economic Area

Personal data may be transferred to Nodu group companies and service providers outside the European Economic Area (EEA), including Nodu Canada, Inc. in Canada and Nodu Group Limited in the United Kingdom. These transfers are based on adequacy decisions of the European Commission, which include Canada for recipients subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), or on the standard contractual clauses adopted by the European Commission, with supplementary measures where required. Where information must accompany a transfer to a service provider in another country by law, the transfer may rely on another ground permitted by the GDPR. You can request information about these safeguards using the contact details in section B6.

B5. Your rights

Under the GDPR, you have the right to:

  • access your personal data and receive a copy of it;

  • have inaccurate or incomplete personal data corrected;

  • have your personal data erased, where the legal conditions are met;

  • restrict the processing of your personal data, where the legal conditions are met;

  • receive the personal data you provided in a structured, commonly used and machine-readable format and have it transmitted to another controller, where the processing is based on consent or contract and carried out by automated means;

  • withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Right to object: you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests.

Some rights may be limited by law. For example, anti-money laundering law requires us to keep certain records and prohibits us from disclosing whether information has been reported to the authorities.

We respond within one month of receiving your request. Where necessary, this period may be extended by two further months, in which case we will inform you. We may need to verify your identity before responding.

You also have the right to lodge a complaint with a supervisory authority. In Latvia, this is the Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia, www.dvi.gov.lv. You may also complain to the supervisory authority in the EEA country where you live or work or where the alleged infringement took place.

B6. Contact

For questions about this part or to exercise your rights, contact Nodu Digital SIA at legal@nodu.fi, or by post to Aspazijas bulvāris 20, Riga, LV-1050, Latvia, marked “Data protection”.

Part C. Nodu Canada, Inc.

This part applies where Nodu Canada, Inc. (“Nodu Canada”) is responsible for your personal information. Nodu Canada handles personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy laws, including Quebec’s Act respecting the protection of personal information in the private sector and the personal information protection legislation of Alberta and British Columbia.

We collect, use and disclose personal information with your consent, which may be express or implied depending on the sensitivity of the information and the purpose, except where the law permits or requires us to act without consent. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may prevent us from providing some or all of our services, and processing required by law, such as anti-money laundering record-keeping, will continue.

We process personal information to comply with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and FINTRAC requirements, including identity verification, know-your-client checks, sanctions and risk screening, ongoing monitoring, record-keeping and the reporting of suspicious and prescribed transactions. Where we are subject to the Retail Payment Activities Act, we also process personal information to meet the requirements that apply to payment service providers under that Act, including operational risk management, incident response and the safeguarding of end-user funds.

C2. Authorities

We may disclose personal information to FINTRAC and, where applicable, the Bank of Canada, and to law enforcement agencies and the Canada Revenue Agency, where the law requires or permits us to do so.

C3. Retention

We keep personal information only for as long as necessary to provide our services and to meet legal, regulatory, tax, accounting, dispute resolution and audit requirements. Records required under the PCMLTFA are generally kept for at least five years from the applicable triggering date, depending on the type of record. When personal information is no longer required, we securely destroy, erase or anonymise it.

C4. Storage and transfers outside Canada

Some of our service providers and Nodu group companies store or process personal information outside your province or outside Canada. In that case, the information may be subject to the laws of those jurisdictions, and we use contractual and organisational safeguards to protect it. For individuals in Quebec, we assess transfers outside Quebec before they take place, as required by Quebec law.

C5. Your rights

Subject to applicable law, you have the right to:

  • access the personal information we hold about you and receive information about how it has been used and disclosed;

  • have inaccurate or incomplete personal information corrected;

  • withdraw your consent, subject to legal or contractual restrictions;

  • if you are in Quebec, exercise the additional rights available under Quebec law, including data portability, de-indexing in certain circumstances, and rights relating to decisions based exclusively on automated processing.

We may need to verify your identity before responding, and we will respond within the time required by applicable law. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d’accès à l’information du Québec if you are in Quebec, or to the privacy regulator of your province.

Where other data protection laws, such as the EU GDPR or the UK GDPR, apply to our processing, individuals have the rights provided under those laws and may exercise them by contacting our Privacy Officer.

C6. Breaches of security safeguards

We keep records of breaches of security safeguards involving personal information. Where a breach creates a real risk of significant harm to an individual, we report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as required by law.

C7. Contact

Our Privacy Officer is responsible for our compliance with this notice. For privacy questions, requests or complaints, contact the Privacy Officer by email at canada@nodu.fi, or by mail at Nodu Canada, Inc., Attention: Privacy Officer, 145½ Church Street, Unit 5, Office #180, Toronto, Ontario, M5B 1Y4, Canada.