Privacy Policy
This Privacy Policy explains how Vital Exchange, Inc. collects, uses, and protects your personal information, including rights available to California residents and other state-specific disclosures.
1. Introduction
Vital Exchange, Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and protect information when you use the Mesh Native Exchange platform ("Platform"). This Policy applies to all users including enterprise clients, institutional banking partners, and developers.
2. Information We Collect
We collect the following categories of information: • Identity Information: Full name, job title, employer, government-issued ID (for KYC). • Contact Information: Email address, phone number, mailing address. • Financial Information: Bank account details, settlement references, Vital wallet identifiers, fiat transaction amounts. • Technical Information: IP address, browser type, device identifiers, API key usage logs, access timestamps. • Usage Data: Pages visited, features accessed, API call volumes, error logs. • Communications: Support tickets, email correspondence, compliance submissions. • KYC/AML Data: Identity verification documents, beneficial ownership records, risk scores, sanctions screening results.
3. How We Use Your Information
We use your information to: • Provide and operate the Platform and settlement services. • Verify identity and conduct KYC/AML screening as required by law. • Process and reconcile Vital-to-fiat transactions. • Generate regulatory reports (SARs, CTRs, FinCEN filings). • Detect and prevent fraud, money laundering, and unauthorized access. • Communicate service updates, security alerts, and legal notices. • Improve platform performance, analytics, and user experience. • Comply with applicable laws, regulations, and court orders.
4. Legal Basis for Processing
We process personal data under the following legal bases: • Contract: Processing necessary to provide the services you have contracted for. • Legal Obligation: Processing required to comply with AML, KYC, BSA, FinCEN, OFAC, and other applicable financial regulations. • Legitimate Interest: Fraud prevention, platform security, and service improvement. • Consent: Where we explicitly request consent, such as for marketing communications, which you may withdraw at any time.
5. Sharing & Disclosure
We do not sell your personal information. We may share information with: • Banking Partners & Payment Rails: ACH, SWIFT, SEPA, FedWire, and RTP processors as necessary to execute settlements. • Regulatory & Law Enforcement Authorities: FinCEN, OFAC, SEC, state regulators, and law enforcement when required by law. • KYC/AML Vendors: Identity verification and sanctions screening providers. • Service Providers: Cloud infrastructure, analytics, security, and support vendors under data processing agreements. • Successors: In connection with a merger, acquisition, or asset sale, subject to equivalent privacy protections. • With Your Consent: Any other parties with your explicit written consent.
6. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you. • Right to Delete: Request deletion of personal information, subject to exceptions for legal compliance (e.g., AML record retention). • Right to Correct: Request correction of inaccurate personal information. • Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising. • Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information to purposes necessary to provide services. • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. To submit a request, email support@dosfi.ai or call our toll-free number. We will respond within 45 days. We may require identity verification before processing your request. Authorized agents may submit requests on your behalf with written authorization.
7. Nevada Privacy Rights
Nevada residents have the right to opt out of the sale of their personal information under NRS Chapter 603A. We do not sell personal information as defined under Nevada law. To submit a verified opt-out request, contact support@dosfi.ai.
8. Colorado, Connecticut, Virginia & Other State Rights
Residents of Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), and other states with comprehensive privacy laws may have rights including: • Access, correction, deletion, and portability of personal data. • Opt-out of targeted advertising, sale of personal data, and profiling for significant decisions. We honor these rights to the extent applicable. Requests can be submitted to support@dosfi.ai. We will respond within 45 days (or 90 days where permitted). You may appeal a denial by contacting our Privacy Officer.
9. Data Retention
We retain personal data for as long as necessary to provide our services and comply with legal obligations. Financial transaction and KYC/AML records are retained for a minimum of seven (7) years as required by the Bank Secrecy Act and applicable regulations. Usage logs are retained for 12 months. Marketing preferences are retained until opt-out. Upon request, we will delete data not subject to legal retention requirements within 30 days.
10. Data Security
We implement industry-standard technical and organizational measures to protect your personal information, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, regular penetration testing, SOC 2 Type II compliance measures, and 24/7 security monitoring. Despite these measures, no system is 100% secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
11. Cookies & Tracking Technologies
We use cookies and similar technologies for authentication, security, analytics, and platform functionality. We do not use third-party advertising cookies. You may control cookie preferences through your browser settings. Disabling cookies may limit certain platform features. We honor Global Privacy Control (GPC) signals as opt-out of sale/sharing signals where required by law (including California).
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. Where required, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms approved under applicable data protection law. By using the Platform, you consent to such transfers subject to the protections described in this Policy.
13. Children's Privacy
The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a person under 18, we will promptly delete it. If you believe a minor has provided us personal information, contact support@dosfi.ai.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in law, technology, or our practices. We will notify you of material changes via email or prominent in-platform notice at least 30 days before they take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
15. Contact & Privacy Requests
For privacy inquiries, to exercise your rights, or to reach our Data Protection Officer: Email: support@dosfi.ai Mail: Vital Exchange, Inc., Privacy Officer, 350 Fifth Avenue, New York, NY 10118 Response time: 45 days for verified requests.
Last Updated: July 4, 2026 · Vital Exchange, Inc.