Legal Center

Aditus Labs Inc.

ADITUS LABS INC.

OAccess Gateway — Privacy Notice

Effective Date: September 2026 | Entity: Aditus Labs Inc. (U.S., Texas) | Product: OAccess Gateway

1. About This Notice

This Privacy Notice explains what personal and technical data Aditus Labs Inc. ("Aditus," "we," "us," "our") collects when you use OAccess Gateway (the "Gateway"), why we collect it, who we share it with, and the choices and rights you have.

If you have questions about this Notice, contact us using the details in Section 13.

2. Who We Are

Aditus Labs Inc. is a U.S.-based technology company, incorporated in Texas, and is the developer and operator of OAccess Gateway.

Aditus is a technology provider. We are not a payment processor, custodian, exchange, broker, or bank, and we do not accept your payment or hold your funds or digital assets.

3. Data Roles: Who Controls What

Under data protection law, the entity that decides why and how personal data is processed is the "controller." OAccess Gateway involves more than one controller, each responsible for a different part of your transaction:

  • Aditus Labs Inc. is the controller for platform technical data, session activity, geofencing checks, destination-wallet sanctions screening, and transaction state tracking performed within the Gateway coordination layer.
  • Licensed third-party providers — such as our fiat on-ramp partner(s) (e.g., Bridge) and non-custodial routing providers — are independent controllers for their own payment processing, identity verification/KYC, anti-money-laundering (AML) checks, and fiat banking/settlement.

This means: when you complete identity verification or make a payment through a provider, you are giving that information to the provider directly — not to Aditus.

4. Information We Collect

We practice data minimization: we only collect what Gateway needs to route your request, screen for risk, and support you.

What we do NOT collect or hold:

  • We do not collect or store your government ID, proof of address, or other identity documents submitted for regulated onboarding — those go directly to, and stay with, the licensed provider.
  • We do not collect your full payment card or bank account details.
  • We do not hold your private keys, and we never take custody of your funds or digital assets at any point.

If you sign in with Google or X, that provider shares your name and email with us as part of authentication — we do not receive your password or any other data from that account.

What we DO collect:

Authentication data

What it includes

Your email address, or the name and email associated with your account when you sign in via a third-party identity provider (e.g., Google, X)

Why we collect it

Creating and securing your session

Recipient & refund wallet addresses

What it includes

The self-custodied wallet address you nominate to receive assets, and a separate wallet address used to return funds if a routed transaction fails

Why we collect it

Real-time sanctions screening (OFAC SDN/Consolidated, EU, UK, UN lists) via blockchain analytics tools (e.g., Scorechain), and to coordinate delivery or refund

IP address & location data

What it includes

Your approximate location derived from IP and similar signals

Why we collect it

Enforcing geofencing to block access from restricted or embargoed jurisdictions

Session & technical identifiers

What it includes

Authentication tokens, device/browser characteristics, interaction logs

Why we collect it

Operating and securing the Gateway interface

Transaction state & delivery logs

What it includes

Order status, timestamps, requested assets, settlement transaction hashes, and refund/failure states — including cases where a failed transaction's refund amount is too small to cover network fees and no funds are returned

Why we collect it

Tracking your transaction, audit logging, reconciliation, resolving stuck or failed orders

Transaction volume history linked to your wallet

What it includes

Running totals of transaction value associated with a destination wallet, over time

Why we collect it

Enforcing per-transaction and cumulative volume limits on certain routed transactions

Wallet ownership verification (where applicable)

What it includes

Additional proof of wallet control, required only for certain higher-value routed transactions involving EU/UK self-hosted wallets

Why we collect it

Meeting provider ownership-verification requirements before enabling higher-value routing

Travel Rule passthrough data

What it includes

The beneficiary details and final wallet you provide

Why we collect it

Passed securely to the licensed provider so they can meet their own statutory Travel Rule obligations

Support communications

What it includes

Your email or messaging handle, and your message content

Why we collect it

Responding to support inquiries

5. How We Use Your Information

We use the data above to:

  • Render the Gateway interface and perform eligibility/route checks before any purchase path is shown
  • Screen destination and refund wallet addresses against sanctions lists (direct and indirect exposure), and enforce geofencing
  • Enforce per-transaction and cumulative volume limits on routed transactions, including verifying wallet ownership where a provider requires it for higher-value EU/UK routing
  • Track transaction status, reconcile provider confirmations, and resolve support issues, including failed or refunded transactions
  • Send you essential transaction status alerts and respond to support requests
  • Analyze technical errors and improve Gateway performance
  • Meet our own legal, audit, and recordkeeping obligations

Gateway's eligibility and screening checks are operational risk controls — they are not identity verification, KYC, or AML clearance, and they are not investment advice or an endorsement of any asset.

6. Our Legal Basis for Processing

Depending on your location, we rely on:

  • Contractual necessity — to render the Gateway interface, confirm route eligibility, and act on your transaction request
  • Legitimate interests — enforcing geofencing, screening wallet addresses to prevent sanctions violations and platform misuse, securing our infrastructure, and resolving support issues
  • Legal and regulatory obligations — statutory compliance, corporate recordkeeping, and audit trail requirements
  • Consent — for specific non-essential communications or cookies, where required by law. You may withdraw consent at any time.

7. Cookies and Tracking

We use cookies and similar technologies for essential site function, analytics, and (if applicable) advertising.

  • Essential cookies run automatically and can't be turned off without breaking Gateway's core function.
  • Non-essential cookies (analytics, advertising) will only be set after you provide consent through our cookie banner, if you are located somewhere that requires opt-in consent (for example, the EU/UK).

You can also control cookies through your browser settings.

8. Who We Share Your Information With

We share data only as needed to operate Gateway and as permitted by law. We do not sell your personal information, and we do not present Aditus as the payee or merchant of record in any transaction.

  • Licensed on-ramp and routing providers (e.g., Bridge, and non-custodial routing partners) — we transmit transaction parameters, your recipient and refund wallet addresses, and Travel Rule passthrough details so they can process payment and deliver your assets.
  • Blockchain analytics partners (e.g., Scorechain) — your recipient and refund wallet addresses are transmitted solely for automated sanctions screening.
  • Infrastructure and support vendors — cloud hosting, logging, and customer support tools (e.g., Intercom), bound by confidentiality and data protection agreements.
  • Identity providers — Google or X, if you choose to sign in that way, in order to authenticate you.
  • Legal and regulatory authorities — when required by valid legal process, court order, or law enforcement request.
  • A buyer, if we sell or transfer the business.

9. International Data Transfers

Aditus is headquartered in the United States. Data we collect is processed and stored in the United States. Where you are located in a jurisdiction with data transfer restrictions (such as the EU or UK), we rely on recognized transfer mechanisms, such as Standard Contractual Clauses or applicable adequacy decisions.

10. How Long We Keep Your Data

We retain data only as long as necessary for the purposes described in this Notice:

  • Transaction and technical logs — retained to verify delivery, resolve stuck or failed orders, and support your inquiries
  • Wallet-linked transaction volume history — retained as needed to enforce cumulative volume limits over time
  • Compliance and audit records — sanctions screening evidence, geofencing logs, and wallet ownership verification records are retained to meet audit trail and legal obligations

Once retention requirements expire, data is securely deleted or anonymized.

11. Your Privacy Rights

Depending on where you live, you may have rights under Texas law, other U.S. state privacy laws, or international frameworks. Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), including the right to:

  • Access — request confirmation of, and a copy of, the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request erasure of your data, subject to our legal and audit retention obligations
  • Portability — request a copy of your data in a portable format
  • Opt out of targeted advertising, the sale of personal data, and certain profiling
  • Appeal — if we deny your request, you may appeal our decision; we will respond to your appeal within the statutory timeframe and, if we uphold the denial, provide a way to contact the Texas Attorney General
  • Withdraw consent at any time, for processing based on consent

If you are located outside Texas, you may have similar rights under your own state or country's law.

-

12. How to Exercise Your Rights

To submit a request, contact us at [privacy email] or through our designated support channel. We will verify your request and respond within the timeframe required by applicable law.

13. Contact Us

Questions about this Notice: support@adituslabs.com

14. Children's Privacy

OAccess Gateway is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

15. Data Security

We use technical and organizational security measures to protect your data, including encryption in transit, role-based access controls, data minimization, and regular security reviews. No method of transmission or storage is 100% secure.

16. Data Breach Notification

If a breach affects your personal information, we will notify you and relevant regulators as required by applicable law — including, for Texas residents, notification to the Texas Attorney General within 30 days if the breach affects 250 or more Texas residents.

17. Changes to This Notice

We may update this Notice periodically to reflect product, legal, or regulatory changes. We will post the updated version here with a new effective date, and will provide notice of material changes directly within the Gateway interface.