Effective Date: September 2026 | Entity: Aditus Labs Inc. (U.S., Texas) | Product: OAccess Gateway
This Privacy Notice explains what personal and technical data Aditus Labs Inc. ("Aditus," "we," "us," "our") collects when you use OAccess Gateway (the "Gateway"), why we collect it, who we share it with, and the choices and rights you have.
If you have questions about this Notice, contact us using the details in Section 13.
Aditus Labs Inc. is a U.S.-based technology company, incorporated in Texas, and is the developer and operator of OAccess Gateway.
Aditus is a technology provider. We are not a payment processor, custodian, exchange, broker, or bank, and we do not accept your payment or hold your funds or digital assets.
Under data protection law, the entity that decides why and how personal data is processed is the "controller." OAccess Gateway involves more than one controller, each responsible for a different part of your transaction:
This means: when you complete identity verification or make a payment through a provider, you are giving that information to the provider directly — not to Aditus.
We practice data minimization: we only collect what Gateway needs to route your request, screen for risk, and support you.
What we do NOT collect or hold:
If you sign in with Google or X, that provider shares your name and email with us as part of authentication — we do not receive your password or any other data from that account.
What we DO collect:
What it includes
Your email address, or the name and email associated with your account when you sign in via a third-party identity provider (e.g., Google, X)
Why we collect it
Creating and securing your session
What it includes
The self-custodied wallet address you nominate to receive assets, and a separate wallet address used to return funds if a routed transaction fails
Why we collect it
Real-time sanctions screening (OFAC SDN/Consolidated, EU, UK, UN lists) via blockchain analytics tools (e.g., Scorechain), and to coordinate delivery or refund
What it includes
Your approximate location derived from IP and similar signals
Why we collect it
Enforcing geofencing to block access from restricted or embargoed jurisdictions
What it includes
Authentication tokens, device/browser characteristics, interaction logs
Why we collect it
Operating and securing the Gateway interface
What it includes
Order status, timestamps, requested assets, settlement transaction hashes, and refund/failure states — including cases where a failed transaction's refund amount is too small to cover network fees and no funds are returned
Why we collect it
Tracking your transaction, audit logging, reconciliation, resolving stuck or failed orders
What it includes
Running totals of transaction value associated with a destination wallet, over time
Why we collect it
Enforcing per-transaction and cumulative volume limits on certain routed transactions
What it includes
Additional proof of wallet control, required only for certain higher-value routed transactions involving EU/UK self-hosted wallets
Why we collect it
Meeting provider ownership-verification requirements before enabling higher-value routing
What it includes
The beneficiary details and final wallet you provide
Why we collect it
Passed securely to the licensed provider so they can meet their own statutory Travel Rule obligations
What it includes
Your email or messaging handle, and your message content
Why we collect it
Responding to support inquiries
We use the data above to:
Gateway's eligibility and screening checks are operational risk controls — they are not identity verification, KYC, or AML clearance, and they are not investment advice or an endorsement of any asset.
Depending on your location, we rely on:
We use cookies and similar technologies for essential site function, analytics, and (if applicable) advertising.
You can also control cookies through your browser settings.
We share data only as needed to operate Gateway and as permitted by law. We do not sell your personal information, and we do not present Aditus as the payee or merchant of record in any transaction.
Aditus is headquartered in the United States. Data we collect is processed and stored in the United States. Where you are located in a jurisdiction with data transfer restrictions (such as the EU or UK), we rely on recognized transfer mechanisms, such as Standard Contractual Clauses or applicable adequacy decisions.
We retain data only as long as necessary for the purposes described in this Notice:
Once retention requirements expire, data is securely deleted or anonymized.
Depending on where you live, you may have rights under Texas law, other U.S. state privacy laws, or international frameworks. Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), including the right to:
If you are located outside Texas, you may have similar rights under your own state or country's law.
-
To submit a request, contact us at [privacy email] or through our designated support channel. We will verify your request and respond within the timeframe required by applicable law.
Questions about this Notice: support@adituslabs.com
OAccess Gateway is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
We use technical and organizational security measures to protect your data, including encryption in transit, role-based access controls, data minimization, and regular security reviews. No method of transmission or storage is 100% secure.
If a breach affects your personal information, we will notify you and relevant regulators as required by applicable law — including, for Texas residents, notification to the Texas Attorney General within 30 days if the breach affects 250 or more Texas residents.
We may update this Notice periodically to reflect product, legal, or regulatory changes. We will post the updated version here with a new effective date, and will provide notice of material changes directly within the Gateway interface.