Nubio Payments INC: PRIVACY POLICY
Last updated: July 1,2025

1. Introduction
Nubio Payments INC., takes privacy and the security of your personal information seriously. This Privacy Policy (the “Policy”) explains how Nubio Payments INC. and its affiliates and licensors (“NUBIO,” “we,” “us,” or “our”) collect, process, and use your personal information when you interact with our website at https://nubio.io/ (“Website”), access our services (“Services”), or otherwise communicate with us, including through social media or other platforms. By interacting with us through the Website or Services, you (“you,” “your,” “client,” “client representatives,” “data subject”) confirm your acceptance and agreement to this Policy. “Personal Data” refers to any information that identifies or could identify, directly or indirectly, an individual (“Personal Data”). We process your Personal Data in compliance with this Policy and in line with applicable laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA), the Personal Information Protection Act (PIPA), and, where applicable, the General Data Protection Regulation (GDPR) (EU Regulation 2016/679) (collectively, “Data Protection Law”).

2. Scope of the Policy
2.1 This Policy outlines the ways in which we collect and process Personal Data in relation to:
2.1.1. your interactions as a data subject with our services, including submitting information through forms on our Website, browsing the Website, and communicating with us to take pre-contractual steps or perform contractual obligations;
2.1.2. our use of cookies and similar technologies across our Website and in live chat services;
2.1.3. our responsibilities and obligations under the applicable Data Protection Law and any other relevant legal frameworks or regulatory mandates.

3. Principles of Personal Data Processing
3.1. We process Personal Data in accordance with the foundational principles established under Data Protection Law. These principles include:
3.1.1. Processing data fairly, lawfully, and transparently;
3.1.2. Using data only for clear, specified, and lawful purposes and not further processing it in ways incompatible with those purposes;
3.1.3. Collecting only the data that is relevant and limited to what is strictly necessary;
3.1.4. Ensuring that data is accurate and kept current;
3.1.5. Retaining data only for as long as necessary;
3.1.6. Protecting data using appropriate security measures against unauthorized access, loss, or damage.

4. Legal Basis for Processing
We collect and process your Personal Data based on:
your freely given, informed, and specific consent;
our contractual relationships with you or your organization;
legal obligations to which NUBIO is subject; and/or
our legitimate business interests.
We restrict processing to the stated purpose for which the data was collected. If consent is the legal basis, you may withdraw your consent at any time. However, revoking consent may limit our ability to provide certain Services if such data is legally or operationally required.

5. Personal Data Processing Activities
5.1. In connection with our Services, NUBIO may process the following categories of Personal Data:
5.1.1. Consent-Based Processing: Personal Data may be collected and processed based on your consent. Consent must be clear, informed, and documented either in writing, electronically, or via an opt-in checkbox acknowledging the Privacy Policy.
5.1.2. Processing for Business Purposes: Your Personal Data may be processed in the course of initiating, performing, or terminating business agreements. During pre-contract stages, data may be used to prepare offers or respond to service inquiries. Processed data may include: name, surname, email, phone number, government-issued ID (e.g., passport, ID card), IP address, biographical data, and in relation to shareholders or beneficiaries—information on assets or sources of wealth (e.g., tax filings, CVs, real estate documents), payment data, and other required business documentation.
5.1.3. Marketing Use: With your prior consent, NUBIO may use your Personal Data to send you marketing communications, event invitations, newsletters, or relevant updates about our Services. Marketing processing is based on your email or phone details, and data provision for these purposes is voluntary. You may opt out at any time. We may process: name, surname, email, and phone number.
5.1.4. Compliance with Legal Requirements: We may process Personal Data when explicitly required or authorized by local, national, or international legislation. The nature and volume of such data are strictly limited to what the law mandates.
5.1.5. Processing Based on Legitimate Interest: We may process Personal Data if it serves a legitimate interest of NUBIO, including fraud prevention, dispute resolution, legal claims, service optimization, or risk management. Before relying on this basis, we assess whether our interests are balanced with your privacy rights.
5.1.6. Cookies and Tracking Technologies: When you visit our Website, we may use cookies and tracking technologies to collect technical information and improve your user experience. This may include: IP address, login timestamps, browser type/version, time zone, operating system, device identifiers, pages visited, scroll behavior, click activity, and navigation paths. These technologies do not typically identify you personally unless combined with other identifying information.
5.1.7. Automated Decision-Making & Profiling: We may use automated tools to assess behavior, preferences, or performance (e.g., profiling). However, such processing will not be used to make decisions that significantly affect you unless legally permitted and with safeguards. You have the right to receive meaningful information and to request human intervention where applicable.
5.1.8. Special Categories of Data: NUBIO does not seek to collect or process sensitive Personal Data (e.g., relating to health, religion, biometric identifiers) unless legally justified. If needed in the future, such processing will strictly comply with applicable law.
5.1.9. Minors and Restricted Processing: Our Services are not directed to individuals under 18 years of age or the age of majority in their jurisdiction. We do not knowingly collect Personal Data from such individuals. If you believe a minor has submitted data to us, please notify us at info@domuspay.io to arrange deletion.

6. Your Data Protection Rights
You have the following rights concerning your Personal Data:
a) Right of Access: You may request information about what data we hold and how it is processed;
b) Right of Rectification: You may request correction of inaccurate or incomplete data;
c) Right to Object: You may object to processing activities, particularly if based on legitimate interests or used for marketing;
d) Right of Erasure: You may request deletion of your data under certain conditions, such as where it is no longer needed or was processed unlawfully;
e) Right to Data Portability: If processing is based on consent or contract, you may request a copy of your data in a structured, commonly used, machine-readable format and may ask us to transmit it to another controller, if technically feasible;
f) Right to Withdraw Consent: You can revoke your consent at any time, without affecting prior lawful processing;
g) Right to Opt-Out of Marketing: You may opt out of receiving promotional content by following the instructions provided in our messages or by contacting us directly.
If you have any concerns, you may contact us at support@nubio.io or via our registered address. If we cannot resolve your concerns, you may file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/en/, or with the data protection authority in your place of residence or where the incident occurred.

7. Sharing Personal Data
We may disclose your Personal Data to third parties as required to provide Services or comply with applicable law. These include:
Affiliated NUBIO entities;
Service providers for compliance (KYB/KYC);
Banks and financial institutions;
Payment platforms, e-wallets, and card schemes;
Technical service providers, hosting partners, and payment gateways.
We may also share data with law enforcement, regulators, or courts when required by law, or when necessary to protect legal rights or safety. We may share your data if: (1) you authorize it; (2) required in an emergency; or (3) necessary to resolve disputes or enforce agreements. All third parties are bound by agreements limiting data use to specified purposes under our direction.

8. Data Security
We implement appropriate technical and organizational safeguards to protect your data, including encryption, access controls, secure infrastructure, and regular audits. Access to Personal Data is restricted to personnel with a legitimate business need and trained to handle data in accordance with security protocols and legal requirements.

9. Data Retention
We retain Personal Data only for as long as is necessary to fulfill the purposes for which it was collected or as legally required. Retention periods depend on the nature of the data and the context in which it was processed.

10. Updates to This Policy
We reserve the right to modify this Policy to reflect changes in our practices or applicable laws. Updates will be posted on our Website, with a notice prior to becoming effective. Your continued use of our Services after such updates indicates your acceptance of the revised Policy.

11. Contact Details
For questions about this Policy or to exercise your rights, contact us at:
Nubio Payments INC.