Tovanix
Tovanix

Tovanix Privacy Policy

Tovanix Privacy Policy — detailed rules for personal data and on-chain data collection, use, storage and protection across 10 digital businesses. GDPR / CCPA / PIPL compliant.

Tovanix Privacy Policy

Effective Date: May 20, 2026 · Last Updated: October 6, 2026

Tovanix (hereinafter referred to as "we," "us," "our," or "the Platform") is a comprehensive digital infrastructure services platform operated by Astrenix Inc., providing you with multi-chain cryptocurrency payment, multi-chain instant swap, TRON energy rental, virtual credit cards, cloud servers, SMS verification numbers with dedicated mailboxes, SMTP aggregation API, proxy subscriptions, AI API relay, and other services.

We fully understand the importance of your personal information and are committed to keeping it safe and secure. This Policy explains in detail how we collect, use, store, and share your personal information, as well as the rights available to you. Please read this Policy carefully before using our services. By registering an account or using any of our services, you are deemed to have read and agreed to the entire contents of this Policy.

---

1. Data Controller

| Item | Details |

|---|---|

| Data Controller | Astrenix Inc. |

| Company File Number | 20261586266 (Colorado, US) |

| Registered Office Address | 1500 N GRANT ST STE R, Denver, CO 80203, United States |

| Data Protection Contact Email | [email protected] |

| Privacy Contact | Data Protection Officer · Tovanix Legal Team |

If you wish to exercise any of the rights set forth in Section 9 of this Policy, or if you have any questions regarding our personal information processing activities, you may contact us using the contact details above.

---

2. Scope of This Policy

This Policy applies to all scenarios in which you access or use the Tovanix services through the following channels:

The official website (tovanix.com and its subdomains)

The business console / administration portal (https://tovanix.com/m, etc.)

API endpoints (api.nexcore.io) and SDKs

Client applications and desktop tools

The browser extension (Tovanix Workspace)

This Policy does not apply to services provided independently by third parties (for example, exchanges, Cloudflare, or upstream AI / SMS / SMTP providers), which are governed by their respective privacy policies.

3. Information We Collect

We collect personal information only as needed to provide our services. KYC is not required for normal account or business use, and there is no self-service KYC tier. Only when a restricted account appeals to have its restriction lifted may we request identity-verification materials needed to review that appeal. See the AML and Compliance Policy.

3.1 Information You Provide Directly

Account information: email address, username, password (stored in hashed form)

Business configuration: wallet addresses, API callback URLs, domain information, email templates, and other settings you enter in the console

Payment information: cryptocurrency transfer addresses, order amounts, payment methods (USDT / USDC / TRX, etc.)

Customer support communications: content you submit through tickets or the community

3.2 Information Collected Automatically

Device and log data: IP address, User-Agent, operating system, browser version, access timestamps, operation records

Service usage data: API request paths, parameters, response statuses, and call frequency (used for billing, security auditing, and troubleshooting)

Cookies and local storage: login credentials, language preferences, console interface state

3.3 Information from Third-Party Sources

When you make a deposit through a third-party cryptocurrency exchange, we receive on-chain transaction metadata (sending address, amount, transaction hash) for the purpose of confirming receipt of funds

When you use the AI API relay service, we record the upstream provider's request ID (for reconciliation and troubleshooting), but we do not retain the actual content you send to the AI

3.4 Browser Extension (Tovanix Workspace)

Tovanix Workspace is an optional browser extension that shows an overview of your own account in your browser. When you connect it to your account, it handles the following information:

Account identifiers: your account email address and UID, displayed in the extension

Financial information: your account balance, frozen amount and the system notifications of your account, displayed in the extension

Authentication information: a session token issued to the extension. It is separate from your website sign-in, read-only, valid for 24 hours, stored only for the current browser session and deleted when you close the browser or sign out

Device and network information: the browser and operating system name and the IP address observed when the extension connects, and a randomly generated installation identifier. These are shown to you under Account settings → Authorizations so that you can recognize and sign out your own devices; the installation identifier is used to end a device’s previous session when it reconnects

The extension does not read, collect or modify the content of any web page you visit, your browsing history, or your activity on other sites. It does not receive your password, your website session, your API keys or your MCP credentials.

We do not sell this information. We do not transfer it to third parties, except to the infrastructure providers described in Section 5 that process it on our behalf, and we do not use it for any purpose other than providing the extension’s features. Our use of this information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. You can disconnect the extension and end its sessions at any time under Account settings → Authorizations, or by signing out in the extension.

4. Purposes of Use and Legal Bases

| Purpose of Use | Legal Basis (GDPR / CCPA / PIPL equivalents) |

|---|---|

| Service provision: account management, order processing, API usage billing, email delivery, energy delegation, etc. | Performance of a contract (GDPR Art. 6(1)(b)) |

| Security protection: identity verification, fraud detection, risk-control rate limiting, attack mitigation | Legitimate interests (GDPR Art. 6(1)(f)) |

| Compliance and auditing: anti-money laundering, counter-terrorist financing, sanctions compliance, cybersecurity-related laws | Legal obligation (GDPR Art. 6(1)(c)) |

| Service improvement: statistical analysis of usage to optimize product features (in de-identified, aggregated form) | Legitimate interests (GDPR Art. 6(1)(f)) |

| Customer support: ticket handling, issue investigation, support communications | Performance of a contract |

| Important notices: service changes, security alerts, account status | Performance of a contract / legitimate interests |

| Marketing communications (optional; requires your explicit consent) | Consent (GDPR Art. 6(1)(a)) |

We will not use your personal information for:

Sale to third parties (within the meaning of "sale" or "sharing" under the CCPA)

Targeted advertising without your consent

Profiling analysis unrelated to personalized recommendations

5. Information Sharing and Disclosure

We adhere to the principle of data minimization in sharing. We share your personal information with third parties only in the following circumstances:

5.1 Sharing Necessary for Service Operations

Upstream service providers: to fulfill your requests (such as calling the Anthropic / OpenAI APIs, applying for SSL certificates, renting TRON energy, sending SMTP emails, or issuing virtual credit cards), we forward the necessary parameters to the corresponding upstream provider

Payment gateways: USDT on-chain transactions are publicly visible on the blockchain network, and we do not control the dissemination of on-chain data

Infrastructure providers: Cloudflare (CDN / DDoS protection), cloud server vendors, email ESPs, etc.

Data processors: we enter into a Data Processing Agreement with upstream service providers to govern their data processing activities

5.2 Disclosure Required by Law

In response to valid legal process (subpoenas, production orders, notices of assistance in investigations, etc.) lawfully issued by U.S. federal or state judicial, administrative, or regulatory authorities

In response to foreign legal instruments lawfully transmitted through cross-border judicial cooperation mechanisms

As required by laws and regulations relating to anti-money laundering, counter-terrorist financing, and sanctions compliance

5.3 Business Transfers

In the event of a merger, acquisition, asset transfer, or similar transaction, your personal information may be transferred as part of the assets involved. The successor entity will remain bound by this Policy, or you will be notified separately before any change takes effect.

6. Data Storage and Cross-Border Transfers

6.1 Storage Locations

Default storage locations: United States / Singapore / Frankfurt

Storage locations may vary across different business modules; see the "Data Storage" page in the console for details

6.2 Retention Periods

Account information: retained for the duration of your account; deleted or anonymized within 30 days after account closure

Service logs: retained for 90 days to 2 years depending on the type of service (see the "Data Retention" settings in the console)

Cryptocurrency transaction records: retained for no less than 5 years to meet anti-money laundering compliance requirements

Legal archives: content required to be retained by law will be kept until the relevant legal obligation has been fulfilled

6.3 Cross-Border Transfers

When you use products that involve cross-border services (such as AI API relay, overseas SMTP delivery, overseas cloud servers, or virtual credit card issuance), certain portions of your data will unavoidably be transferred outside your jurisdiction. We adopt the following safeguards:

Transmission encrypted via TLS 1.2+

Data processing agreements (SCCs / DPA) executed with overseas service providers, applying the GDPR Standard Contractual Clauses or equivalent protection mechanisms

Transfer of only the data necessary to complete the request

Note: on-chain cryptocurrency transactions are inherently globally visible; this is an intrinsic characteristic of blockchain technology.

7. Data Security

We adopt industry-standard security measures to protect your personal information:

Encryption in transit: HTTPS / TLS 1.2+ enforced site-wide

Encryption at rest: sensitive fields (API keys, private keys, passwords) are stored encrypted with AES-256-GCM

Access control: RBAC-based least-privilege principle, with all admin operations recorded in audit logs

Key management: encryption keys are managed independently and rotated periodically

Network isolation: databases are not directly exposed to the public internet and are accessed via dedicated connections

Intrusion detection: 24×7 monitoring for anomalous logins, brute-force attempts, and scanning activity

Incident response: in the event of a data breach, affected users will be notified within 72 hours, and reports will be made to the competent supervisory authorities (as applicable under GDPR Article 33 / state data breach notification laws)

Although we make every effort to protect your information, no security measure can eliminate risk entirely. You should also safeguard your account credentials and enable strong passwords and two-factor authentication.

8. Cookies and Tracking Technologies

We use essential Cookies and local storage to maintain your login session and save your preferences. We do not use third-party advertising Cookies and do not engage in cross-site tracking.

You may disable Cookies through your browser settings; however, this may prevent certain services from functioning properly (for example, you may be required to log in repeatedly).

9. Your Rights

Under the GDPR, CCPA / CPRA, PIPL, and other applicable laws, you have the following rights with respect to your personal information:

| Right | Description | How to Exercise |

|---|---|---|

| Right of access | Inquire about what information we hold about you | Log in to the console: "Account Center → Data Export" |

| Right to rectification | Correct inaccurate information | Edit directly in the console |

| Right to erasure / right to be forgotten | Request deletion of your personal information | "Account Closure" in the console, or submit a ticket |

| Right to restriction of processing | Request suspension of processing under specific circumstances | Submit a ticket |

| Right to data portability | Obtain your data in a structured format | "Data Export" in the console |

| Right to object | Object to processing based on legitimate interests | Submit a ticket |

| Right to withdraw consent | Withdraw consent previously given | "Privacy Preferences" in the console |

| Right not to be subject to automated decision-making | Object to significant decisions made solely by automated means | Submit a ticket |

| Right to lodge a complaint | Complain to a supervisory authority (see "Contact Us" below) | Contact the supervisory authority directly |

We will respond to your request within 15 business days of receipt (and in any event within the statutory 30-day period). For complex requests, the response period may be extended to 45 days, in which case we will explain the reasons to you.

For California residents (CCPA / CPRA): you also have the right to non-discrimination — we will not provide you with a lower quality of service or charge you higher prices as a result of your exercising your rights.

10. Protection of Minors

The Tovanix services are not directed at minors under the age of 18 (in light of the heightened protection thresholds for children's information under COPPA, GDPR-K, and similar laws, we prohibit registration by minors outright). We do not knowingly collect personal information from minors. If we discover that a minor's information has been collected without guardian consent, we will delete it as soon as possible.

If you are the guardian of a minor and discover that the minor has registered a Tovanix account without your consent, please contact [email protected] to have the account and associated information deleted.

11. Third-Party Services

Our services may integrate with or link to the following third parties:

Cryptocurrency exchanges: Binance, OKX, Coinbase, etc. (for fiat on-ramp guidance)

AI upstream providers: Anthropic, OpenAI, Google, Alibaba Cloud, xAI, etc.

Infrastructure: Cloudflare, various cloud service vendors, email delivery ESPs

We are not responsible for the privacy practices of these third parties; please review their respective privacy policies. Our data sharing with these third parties is governed by the Data Processing Agreement.

12. Changes to This Policy

We reserve the right to amend this Policy at any time. Material changes (for example, new categories of collection, expanded purposes of use, or changes to the parties with whom information is shared) will be communicated to you through the following means:

Publication of an announcement in a prominent position on the website homepage

Notification to all registered users via in-platform messages / email

Public notice at least 7 days before the changes take effect

Your continued use of the services will be deemed acceptance of the amended Policy; if you do not agree, you may close your account.

13. Contact Us

If you have any questions or comments about this Policy, or if you wish to exercise your rights, you may contact us through the following channels:

Ticket system: log in to the console → Ticket Center → Create Ticket (select the "Privacy & Compliance" category)

Community: https://tovanix.com/community

Data protection email: [email protected]

Data protection contact: Data Protection Officer · Tovanix Legal Team

Operating entity: Astrenix Inc. (File #20261586266)

Registered office address: 1500 N GRANT ST STE R, Denver, CO 80203, United States

If you are not satisfied with our response, you may lodge a complaint with the following supervisory authorities:

Users in the European Economic Area (EEA) / United Kingdom: complain to the data protection authority (DPA) in your jurisdiction

California residents: California Privacy Protection Agency (CPPA)

Other regions: the personal information protection supervisory authority in your jurisdiction

Loading…