NEOCEX

PRIVACY POLICY

Neocex Platform (neocex.com)

Data Controller: Boulder Tech, S.A.S. de C.V.

Effective date: [DATE]

Version: 1.0

1. Who we are

1.1. This Privacy Policy describes how Boulder Tech, S.A.S. de C.V. (the "Operator", "we") collects, uses, stores and shares personal data of users of the Neocex platform at neocex.com (the "Platform").

1.2. Controller details: Boulder Tech, S.A.S. de C.V., NIT 0528-281024-101-6, registered address 7 Calle Oriente, Poligono 2, Urbanizacion Santa Monica, No. 1, Distrito de Santa Tecla, Municipio de La Libertad Sur, Departamento de La Libertad, Republic of El Salvador. Registered with the National Commission of Digital Assets (CNAD) under registry entry PSAD-0038.

1.3. Contact for privacy matters: [email protected]. [TO CONFIRM: mailbox and the person designated as data protection contact]

1.4. This Policy forms part of the Terms of Use. Capitalised terms have the meaning given in the Terms.

2.1. This Policy applies to all personal data processed in connection with the Platform, including the website, the Account, the API, support channels and marketing communications.

2.2. Processing is carried out under the law of the Republic of El Salvador, including the personal data protection legislation in force, the Digital Asset Issuance Law (LEAD), the anti-money laundering legislation and the regulations of CNAD. Where the law of another jurisdiction grants a user additional rights that apply to us, we honour those rights.

2.3. The Platform is intended for individuals aged 18 and over. We do not knowingly collect data of minors. If we learn that data of a minor has been collected, we delete it and close the Account.

3. Data we collect

3.1. Data you provide

Registration data: email address, password (stored in hashed form), language preference.

Identity verification data: full legal name, date of birth, nationality, residential address, government-issued identity document (type, number, issuing country, expiry date, image), selfie and liveness video, proof of address document, source of funds and source of wealth information, occupation.

Financial and transactional data: deposit and withdrawal addresses, transaction hashes, order and trade history, balances, fees paid, referral relationships.

Communications: support requests, complaints, correspondence, and recordings of chats and calls where permitted by law.

Knowledge test and risk disclosure records for Derivatives access.

3.2. Data collected automatically

Technical data: IP address, device identifiers, browser type and version, operating system, screen parameters, time zone, language settings.

Usage data: pages viewed, features used, session times, click paths, error logs.

Security data: 2FA events, login attempts, active sessions, device fingerprint, geolocation derived from IP address.

Cookies and similar technologies as described in Section 10.

3.3. Data from third parties

Identity verification results and document authenticity checks from our identity verification provider.

Sanctions, politically exposed person and adverse media screening results.

Blockchain analytics: risk scores and exposure data for wallet addresses and transactions, obtained from our blockchain analytics provider and from public blockchains.

Information from competent authorities, courts and other virtual asset service providers, including under Travel Rule obligations.

3.4. We do not collect payment card numbers or bank account details: the Platform does not accept fiat money.

4. Why we process data and on what basis

PurposeDataLegal basis
Creating and operating the Account, executing orders, deposits and withdrawalsRegistration, transactional, technical dataPerformance of the contract (Terms of Use)
Identity verification, sanctions and PEP screening, transaction monitoring, record keeping, suspicious activity reportingIdentity, transactional, security, third-party dataLegal obligation under the LEAD, CNAD regulations and AML/CFT legislation
Fraud prevention, Account security, market surveillanceTechnical, security, transactional dataLegitimate interest of the Operator and of Users in a secure and orderly market; legal obligation
Client support and complaints handlingCommunications, Account dataPerformance of the contract; legal obligation
Compliance with requests of competent authorities and courtsAny categoryLegal obligation
Product analytics and service improvementUsage data, aggregated or pseudonymised where possibleLegitimate interest
Marketing communications about the PlatformEmail, usage dataConsent, which you may withdraw at any time
Referral programmeReferral relationships, fee dataPerformance of the contract
Establishment, exercise or defence of legal claimsAny categoryLegitimate interest; legal obligation

5. Who we share data with

5.1. Service providers acting on our instructions:

5.2. Competent authorities: CNAD, the Financial Investigation Unit of El Salvador (UIF), courts, law enforcement and tax authorities, where required by law or by a lawful request.

5.3. Other virtual asset service providers, to the extent required by Travel Rule obligations for a specific transfer.

5.4. Professional advisers (lawyers, auditors) bound by confidentiality.

5.5. A successor or affiliate in the event of reorganisation, merger or transfer of the business, with notice to you.

5.6. We do not sell personal data and do not share it with third parties for their own marketing.

6. International transfers

6.1. Our providers may process data outside the Republic of El Salvador. Where data is transferred abroad, we rely on contractual safeguards with the recipient requiring a level of protection consistent with this Policy and applicable law.

6.2. Blockchain transactions are public by design. Wallet addresses and transaction hashes are recorded on public networks that are accessible worldwide and cannot be modified or deleted by us.

7. Retention

7.1. Identity verification data, transactional data and compliance records are retained for at least 5 years after the end of the business relationship or the date of the transaction, whichever is later, as required by AML/CFT legislation, and longer where a legal proceeding or a request of a competent authority requires it.

7.2. Account and communication data are retained for the life of the Account and for 5 years after its closure.

7.3. Technical and usage data are retained for up to 24 months unless required for security investigations or legal claims.

7.4. Marketing data are retained until you withdraw consent.

7.5. After the retention period data are deleted or irreversibly anonymised.

8. Security

8.1. We apply technical and organisational measures proportionate to the risk: encryption of data in transit and at rest, mandatory two-factor authentication before the first deposit and the first order, role-based access to systems and client data, logging of access to personal data, segregation of environments, periodic independent security review, and staff training.

8.2. Identity documents and biometric data collected during verification are processed by our identity verification provider and are stored in encrypted form. Access is limited to the compliance function.

8.3. No system is fully secure. You protect your credentials, 2FA device and email account, and notify us immediately of any suspected compromise.

8.4. If a personal data breach is likely to result in a risk to your rights, we notify you and the competent authority in accordance with applicable law.

9. Your rights

9.1. Subject to applicable law you have the right to:

9.2. Requests are sent to [email protected]. We verify your identity before acting on a request and respond within 30 calendar days; the period may be extended once where the request is complex, with notice to you.

9.3. Limits. We cannot delete or restrict data that we are required to retain under AML/CFT legislation, the LEAD or a request of a competent authority, and we cannot alter data recorded on a public blockchain. Where we refuse a request we state the legal ground unless prohibited by law.

9.4. Compliance decisions, including holds and freezes, may be based on automated risk scoring produced by our blockchain analytics provider. A decision to refuse a transaction or close an Account is reviewed by a compliance analyst before it takes effect. You may request human review of such a decision through support, subject to the tipping-off restrictions in AML/CFT legislation.

10. Cookies and similar technologies

10.1. We use strictly necessary cookies for authentication, session management and security. These cannot be switched off without disabling the Platform.

10.2. We use functional cookies to remember your language, theme and interface settings, and analytics cookies to understand how the Platform is used. Analytics cookies are set only with your consent where the law requires consent.

10.3. You can manage cookies in your browser settings and in the cookie banner on the Platform. Disabling functional cookies may affect the interface.

10.4. We do not use third-party advertising cookies.

11. Marketing communications

11.1. We send product and market communications by email only with your consent. Every message contains an unsubscribe link. Service messages required to operate the Account (security alerts, compliance requests, changes to the Terms) are sent regardless of marketing preferences.

11.2. We do not direct marketing at residents of Restricted Jurisdictions.

12. Changes to this Policy

12.1. We may update this Policy. The new version enters into force upon publication on the Platform. Material changes are notified by email or through the interface at least 7 calendar days before they take effect.

13. Contact

Boulder Tech, S.A.S. de C.V.

7 Calle Oriente, Poligono 2, Urbanizacion Santa Monica, No. 1, Distrito de Santa Tecla, Municipio de La Libertad Sur, Departamento de La Libertad, Republic of El Salvador

[email protected]