Privacy Policy

NexGen Tech Incorporated trading as Alphapays

Effective Date: June 30, 2026

This Privacy Policy describes the rules by which NexGen Tech Incorporated (trading as Alphapays or "The Company") collects, uses, stores, and protects a Data Subject's Personal Data. Alphapays is committed to protecting your privacy in compliance with the Seychelles Data Protection Act and applicable local corporate regulatory standards.

1. Definitions

In this Policy, the following definitions shall apply:

Term Definition
Alphapays Means NexGen Tech Incorporated, a company incorporated under the laws of the Republic of Seychelles with Registration Number 227642, having its registered office and seat at House of Francis, Room 303, Ile Du Port, Mahe, Seychelles.
Data Controller The entity which determines the purposes and means of the processing of Personal Data. Alphapays is the Data Controller of your personal information.
Data Subject Any natural person whose personal data is collected or processed by the Alphapays Platform and Services.
Personal Data Any information relating to an identified or identifiable individual.
Processing Any operation or set of operations performed on personal data, such as collection, recording, storage, adaptation, transmission, or deletion.
2. Compliance & Governance Structure

Corporate Responsibility

The Board and management of NexGen Tech Incorporated maintain the responsibility for establishing internal compliance procedures aligned with the Seychelles Data Protection Act. Privacy considerations are integrated into our system changes, product development, and software updates as part of our commitment to platform safety.

Compliance Officer

Alphapays has designated individuals internally responsible for supervising data compliance. They ensure the custody and security of data entrusted to the company and act as the main point of contact for personal data inquiries and local regulatory authorities.

3. Personal Data We Collect

Alphapays collects the following categories of data to provide its services effectively:

  • Submitted Information: Data you provide directly when establishing a merchant account or communicating with us, including:
    • Identity Data: Full name, date of birth, username, passport, or government-issued ID details.
    • Contact Data: Corporate or individual physical address, email address, and telephone number.
    • Financial Data: Settlement wallet addresses, source of funds declarations, and platform transaction balances.
  • Automated Data: Information collected automatically when interacting with our gateway or system dashboard, including:
    • Transaction Data: Date, time, amount, crypto asset type, public blockchain wallet addresses, and associated metadata.
    • Technical Data: Internet Protocol (IP) address, operating system, and browser profile information.
  • Verification Data: Information obtained through public sources or third-party databases to fulfill mandatory international Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) protocols.
4. Purposes and Legal Grounds for Processing

We process personal data strictly under valid legal grounds recognized under Seychelles law, primarily:

  1. To Fulfill Contractual Commitments: Managing account registrations, deploying client APIs, executing merchant crypto-to-crypto routing, and providing customer support.
  2. To Meet Legal Obligations: Verifying identities (KYC) and scanning against international sanctions lists to comply with mandatory anti-money laundering regulations.
  3. For Legitimate Business Purposes: Maintaining platform security, monitoring for system fraud, resolving network performance vulnerabilities, and assessing gateway usage statistics.
  4. Based on Consent: Delivering optional promotional newsletters or specific feature updates where a user has explicitly opted in.
5. Security and Confidentiality

Alphapays utilizes technical and organizational security baselines designed to reduce risks of accidental data loss, unauthorized access, or unlawful alteration. Core safeguards include database access restrictions, encrypted data transport channels, regular architecture monitoring, and secure system log controls.

6. Disclosure and Data Sharing

We do not sell or rent user data to third-party marketing entities. Data is only shared with third-party service providers when required to facilitate our core operations, including:

  • External KYC/AML compliance verification platforms.
  • Specialized server hosting, storage, and infrastructure networks.
  • Professional banking partners or liquidity providers necessary to support transaction paths.
  • Competent government, legal, or judicial bodies when strictly required under enforceable statutory laws.

All third-party partners are contracted to handle information responsibly, maintain appropriate data confidentiality, and restrict usage exclusively to the services they perform on our behalf.

7. Cross-Border Data Transfers

As a global payment architecture, data collected by Alphapays may be processed or stored in secure datacenters globally. Cross-border transfers are conducted in accordance with the Seychelles Data Protection Act, ensuring that recipient jurisdictions or contracted entities maintain a comparable and acceptable standard of data handling and security protection.

8. Data Retention and Storage Limitations

Alphapays preserves personal information only for the duration necessary to satisfy the initial purpose of collection, or as explicitly mandated by overriding corporate and financial regulations:

  • Compliance and AML Records: Retained for a minimum of 10 years following the termination of the merchant relationship or single transaction completion to satisfy standard financial crime tracking legislation.
  • Accounting and Operational Records: Held for up to 7 years from the close of the corresponding financial cycle to satisfy corporate bookkeeping frameworks.

Once the maximum legal retention limits expire, Alphapays systematically purges, overwrites, or securely anonymizes the data records within its active systems.

9. Data Subject Rights

Under the framework of the Seychelles Data Protection Act, individuals interacting with our platform possess defined legal privileges regarding their data:

  • Right to be Informed: The right to clear visibility on what data we collect and why.
  • Right of Access: The right to check what data is held about you.
  • Right to Rectification: The right to request the prompt correction of incomplete or outdated personal information.
  • Right to Erasure / Deletion: The right to request data removal, provided the information is no longer needed to satisfy a current contract or overriding regulatory retention law (such as AML records).
  • Right to Object: The right to object to direct marketing or processing driven purely by commercial interests.

Executing Your Rights

To submit a data inquiry or dispute, contact our team using the channels listed below. To ensure data security, we will ask you to verify your identity before processing any details. We aim to review and address all legitimate requests within a reasonable operational timeline.

10. Revisions to this Privacy Policy

Alphapays reserves the right to modify this Privacy Policy at any time to reflect infrastructure changes, new asset integrations, or updated legal frameworks. Any changes will be announced by modifying the "Effective Date" at the top of this page. Continued usage of the platform following updates represents an acknowledgement of the revised practices.

11. Contact Us

For questions, requests, or notices regarding your personal data privacy, please contact our team at:

NexGen Tech Incorporated
Seat at House of Francis, Room 303,
Ile Du Port, Mahe,
Republic of Seychelles
Company Registration Number: 227642
Email: [email protected]