Legal
Privacy Policy
1. Introduction
PazaLabs ("we," "us," or "our") is committed to protecting the privacy of individuals who interact with our platform, website, and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit pazalabs.io, request a demo, or engage with our real-world asset tokenization infrastructure.
By using our services, you agree to the practices described in this policy. If you do not agree, please discontinue use of our platform.
2. Information We Collect
We collect information in the following ways:
- Information you provide directly — name, work email, organisation, role, use case, and any message submitted via contact or demo request forms.
- Account and KYC information — for verified platform participants, we collect identity documents, accreditation status, and jurisdiction information as required by applicable compliance frameworks (including SEC Reg D, ESMA, and AML/KYC regulations).
- Usage information — pages visited, time on site, click events, and referral sources, collected via analytics tools.
- Device and technical data — IP address, browser type, operating system, and device identifiers.
- Communications — emails or messages you send to our team.
3. How We Use Your Information
We use collected information to:
- Respond to demo requests and enquiries
- Provide and improve our tokenization platform and services
- Conduct identity verification and compliance checks as required by law
- Send relevant communications about our products, updates, and market insights (you may opt out at any time)
- Analyse usage patterns to improve our platform and user experience
- Comply with legal and regulatory obligations
- Detect, prevent, and investigate fraud, security incidents, and policy violations
4. Legal Basis for Processing (GDPR / ESMA)
For individuals in the European Economic Area (EEA) or subject to ESMA frameworks, we process personal data on the following legal bases:
- Contractual necessity — to perform obligations under an agreement with you or your institution
- Legal obligation — to comply with AML, KYC, and securities regulations
- Legitimate interests — to operate, improve, and market our platform, where not overridden by your rights
- Consent — for marketing communications and optional analytics, which you may withdraw at any time
5. Information Sharing and Disclosure
We do not sell your personal information. We may share it with:
- Service providers — third-party vendors who assist with analytics, email delivery, CRM, cloud infrastructure, and legal/compliance services, under appropriate data processing agreements
- Regulatory authorities — where required by law, court order, or to protect the rights and safety of PazaLabs or others
- Business transfers — in the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity
- Professional advisers — lawyers, auditors, and compliance consultants bound by confidentiality obligations
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes outlined in this policy, comply with legal obligations, and resolve disputes. KYC/AML records are retained for a minimum of 5 years following the end of a business relationship, as required by applicable regulations. Marketing preferences are retained until you withdraw consent.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data (subject to legal retention obligations)
- Object to or restrict certain processing activities
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority (e.g., your national data protection authority)
To exercise any of these rights, contact us at privacy@pazalabs.io.
8. Security
We implement industry-standard technical and organisational measures to protect your personal data — including encryption in transit and at rest, access controls, and regular security assessments. However, no transmission over the internet is completely secure, and we cannot guarantee absolute security.
9. International Transfers
PazaLabs operates across multiple jurisdictions. Where personal data is transferred outside your home jurisdiction, we apply appropriate safeguards (such as Standard Contractual Clauses) to ensure data receives equivalent protection.
10. Cookies and Tracking
We use cookies and similar technologies to analyse traffic and improve user experience. For full details, see our Cookie Policy.
11. Children's Privacy
Our platform is intended for institutional users and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions, requests, or concerns:
- Email: privacy@pazalabs.io
- General enquiries: hello@pazalabs.io