Skip to document
NordBalticumSelf-custody wallet
Wallet guidesSign in
Privacy and data

Privacy Policy

A clear account of the data used to provide, protect and support NordBalticum across web and native wallet experiences.

  • Data minimisation
  • No advertising profiles
  • Wallet PIN stays on your device
Official document

Privacy built around user control

See what data is processed, why it is needed, which providers may be involved and how to exercise your rights.

Last updated 31 August 2026
Read the full documentNever share your wallet PIN, private key or recovery information.
Home/Legal/Privacy Policy
Privacy and data

Privacy Policy

Last updated: 31 August 2026

This Privacy Policy explains how Nord Baltic Capital, UAB processes personal data when you use NordBalticum, including our website, web wallet interfaces, native mobile wallet application, support, security, rewards functionality and related software services.

Nord Baltic Capital, UAB is the controller for the personal data that we determine how and why to process. Independent third-party services that you choose to use may act as separate controllers for their own processing under their own privacy notices and legal obligations.

NordBalticum is built around data minimisation, self-custody and user control. We do not sell your personal data, rent personal data to advertisers, use paid advertising trackers, build advertising profiles, or disclose personal data to third parties in exchange for payment for advertising or promotional targeting. We process only the data reasonably necessary for the purposes described below.

1. Our self-custody privacy model

NordBalticum provides self-custody wallet software. We do not take custody of your crypto-assets and cannot authorize blockchain transactions on your behalf without your action through the wallet interface.

Your wallet PIN remains on your device. It is not sent to NordBalticum servers and is not provided by NordBalticum to Stakely, Stripe, Explore services or other third-party providers. We do not use your PIN for analytics, advertising, support or commercial integrations.

We process wallet-related information only as reasonably necessary to provide the features you choose to use, protect the service, comply with applicable law and carry out the other purposes described in this Policy. Public blockchain information is separate from private wallet credentials and may be visible to third parties by the nature of the relevant blockchain.

2. Web wallet and native wallet

NordBalticum is available through supported web interfaces and a native Android application. The data processed depends on the version and features you choose to use.

The native application requests device permissions only when needed for a feature. Camera access may be requested if you choose to scan a wallet QR code. Biometric authentication may be used if you enable a supported biometric access feature. We do not receive your fingerprint, face template or other biometric template.

Network access is required for account functionality, blockchain and market information, third-party integrations and user-authorized blockchain activity. If future features require additional device permissions, the application will request them where required and we will update our disclosures where appropriate.

3. Categories of data we process

Depending on the features you use, we may process account and authentication data; public wallet addresses; public blockchain and transaction information; balances, token and network information; service-fee, rewards, referral and approved-partner records; staking and fiat-onramp integration data; support communications; preferences; and limited device, network, security and error information needed to operate, protect and support the service. For abuse prevention and account security, this may include a pseudonymous first-party device identifier, protected device-key or browser-installation identifiers, IP/network information, platform/browser characteristics, security challenge and attestation results, and security-event or risk records. We do not use this security layer to collect IMEI numbers or biometric templates.

We apply data-minimisation principles and do not intentionally collect personal data merely because it could be useful in the future. The categories actually processed depend on the product version, feature and interaction you choose to use.

4. PIN and private wallet credentials

Your wallet PIN is controlled by you and remains on your device. It is not sent to NordBalticum servers or provided by NordBalticum to Stakely, Stripe, Explore services, blockchain infrastructure providers or other third parties. NordBalticum cannot retrieve a forgotten PIN for you.

NordBalticum does not intentionally receive private wallet credentials as server-side personal data. If you use supported wallet import or recovery functionality, you are responsible for protecting the credentials and backups under your control.

Never send your PIN or private wallet credentials to NordBalticum support or to anyone claiming to represent NordBalticum. Our support team will not ask you to disclose them.

5. Authentication and account data

We process account and authentication information to create and maintain your account, authenticate access and protect the service. Depending on the authentication method, this may include your email address, authentication-provider identifiers and related account and security information.

Authentication to a NordBalticum account is separate from wallet authorization. Account authentication does not give NordBalticum your wallet PIN or an independent ability to sign blockchain transactions from your self-custody wallet.

6. Wallet, transaction and blockchain metadata

We may process public wallet addresses, enabled networks, token selections, public transaction identifiers, operation status, amounts, chain identifiers, token contract addresses, gas and network-fee information, NordBalticum service-fee information, timestamps and related metadata to provide balances, transaction history, rewards, security, support and application state.

Blockchain information can be personal data when it relates or can reasonably be linked to an identifiable person. Processing such information does not give NordBalticum custody or control of the crypto-assets associated with a public wallet address.

7. Public blockchain data

Public blockchains are public by design. Wallet addresses, transactions, balances, token approvals, smart-contract interactions and other on-chain information may be visible to anyone and may be copied, indexed or analysed by independent parties.

Once information is recorded on a public blockchain, NordBalticum generally cannot erase, alter or conceal that blockchain record. Requests concerning personal data held in NordBalticum-controlled systems are therefore different from requests concerning immutable or independently maintained public blockchain data.

Blockchain and related infrastructure providers may receive public blockchain information and ordinary technical request information when the service communicates with them. Their processing is subject to their own roles, systems and applicable legal obligations.

8. Native Explore and dApp browser privacy

The native wallet may provide Explore for optional access to selected independent third-party services. NordBalticum decides which services may be displayed using product, security, legal and operational criteria. Inclusion in Explore is not a guarantee, certification, continuous audit, investment recommendation or assurance that a third-party service will remain safe, solvent, lawful or suitable for you.

Explore is user-directed. You choose whether to open it, which available service to visit, whether to connect your wallet, what information or amount to enter, and whether to approve or reject a requested transaction or signature. NordBalticum does not choose a provider, asset, amount, route or transaction for you.

When you choose to use a third-party service, that provider may receive ordinary device or network information and any public wallet, transaction or other information that you choose to provide or that is necessary for the requested interaction. The provider is responsible for its own privacy practices under its applicable privacy notice.

NordBalticum does not provide Explore services with your PIN, private wallet credentials or biometric authentication data. NordBalticum does not currently receive compensation merely because you browse or use an independent service through Explore, and we do not sell your Explore activity for advertising.

9. Stakely staking integration

NordBalticum provides optional access to staking functionality supported by STAKELY, S.L. (“Stakely”), an independent staking infrastructure provider incorporated in Spain (NIF ESB72551682; registered office C/Ferraz 2, 2º Izq, 28008 Madrid, Spain). Stakely provides the relevant provider-side staking services.

If you choose to use Stakely through NordBalticum, information reasonably necessary for the requested staking interaction may be processed by NordBalticum, Stakely, the relevant blockchain or protocol, and supporting infrastructure. This may include public wallet and transaction information, the staking action you request, status information and related operational records.

NordBalticum does not provide Stakely with your wallet PIN, private wallet credentials or biometric authentication data. Stakely is responsible for personal data processing that it independently determines for its own services. Please review Stakely's Privacy Policy and Terms of Use before using its service.

NordBalticum may retain staking-related records where reasonably necessary for transaction history, service operation, support, security, accounting, legal compliance and administration of the integration. We do not include your wallet PIN or private wallet credentials in those records.

10. Stripe fiat purchase privacy

NordBalticum may provide an optional fiat-to-crypto purchase flow through Stripe. If you choose to use Stripe, Stripe and any service provider identified in its flow may process personal data necessary for the service, including payment, identity verification, sanctions or compliance screening, fraud prevention, wallet-address and transaction information, settlement and customer support, under their applicable terms and privacy notices.

NordBalticum does not intentionally collect or store your full payment card number, bank-login credentials or identity-verification documents merely because you use Stripe. Information you enter directly into Stripe's service is processed by Stripe under its Privacy Policy and applicable service terms, including its Crypto Onramp Terms where applicable.

NordBalticum may process or exchange limited integration and status data reasonably necessary to open, support or display the purchase flow. Your NordBalticum PIN and private wallet credentials are not provided to Stripe.

11. Rewards, referrals and approved partners

If you use NordBalticum rewards, referral or approved-partner functionality, we may process referral codes, referrer and referred user identifiers, relevant account identifiers, public wallet addresses, attribution status, eligible service-fee records, reward calculations, payout status, payout records, timestamps and operational notes.

We use this information to attribute eligible activity, calculate and administer rewards, prevent duplicate attribution or abuse, perform security checks, resolve disputes, maintain financial and operational records and comply with applicable legal obligations.

12. Support and communications

When you contact us, we may process your email address, account identifier, support messages, ticket information, attachments you choose to provide, technical details, public transaction identifiers and other information you voluntarily include so that we can investigate and respond.

Please avoid sending information that is not necessary for your request, particularly wallet secrets or unrelated personal data.

13. Cookies and similar technologies

The web service may use cookies and similar browser technologies that are reasonably necessary for authentication, security, preferences, service continuity and reliable operation.

NordBalticum does not currently use Google Analytics, Meta Pixel, Hotjar, advertising retargeting cookies or paid advertising trackers. We do not use your NordBalticum personal data to build third-party advertising profiles and do not sell or rent your personal data for advertising or promotional targeting.

If we introduce non-essential analytics, advertising or similar tracking technology in the future, we will update this Policy and, where required, obtain consent before activating it.

14. Infrastructure and categories of recipients

We use service providers and infrastructure necessary to operate the product. Depending on the feature, categories of recipients or processors may include hosting and cloud infrastructure, database and authentication providers, transactional email and support providers, security and reliability providers, RPC and blockchain infrastructure, and market or price-data providers.

Independent providers that you choose to use, such as Stakely, a payment provider or a dApp, may receive data necessary for your requested interaction and may process it as independent controllers. We disclose or make available only the data reasonably necessary for the stated purpose, where you direct or initiate the interaction, or where disclosure is required or permitted by law.

NordBalticum does not sell or intentionally disclose your wallet PIN, private wallet credentials or biometric authentication data to Stakely, dApps, RPC providers, payment providers, advertisers or other external service providers. Those credentials are not required for provider-side transaction preparation or blockchain broadcasting.

15. Purposes and legal bases

We process personal data only where we have an applicable legal basis. Depending on the processing activity, this may include processing necessary to perform our agreement with you or take steps at your request; compliance with a legal obligation; our legitimate interests; or your consent where consent is the appropriate basis.

Contract-related processing may include account authentication, requested wallet functionality, transaction-history functionality, support and administration of features you choose to use. Legitimate interests may include protecting accounts and infrastructure, preventing fraud and abuse, maintaining service reliability, troubleshooting, defending legal claims and improving security, provided those interests are not overridden by your rights and freedoms.

Legal-obligation processing may include responding to binding lawful requests and maintaining records where required by applicable law. Where processing relies on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

16. Data minimisation and purpose limitation

We seek to process personal data that is adequate, relevant and limited to what is reasonably necessary for the stated purposes. We do not intentionally repurpose personal data for materially incompatible purposes without an appropriate legal basis and, where required, additional notice or consent.

17. Data retention

We retain personal data for no longer than reasonably necessary for the purpose for which it is processed, taking into account account and service operation, security, fraud prevention, support, rewards and payout administration, legal claims, and applicable accounting, tax, audit or other legal record-keeping requirements.

Different categories therefore have different retention periods. Account-related data may be retained while the account remains active; support and security records may be retained for a reasonable period needed to investigate issues or defend claims; and financial or legally required records may be retained for the period required by applicable law. Data is deleted or anonymised when it is no longer reasonably required, unless continued retention is legally permitted or required.

Public blockchain records are maintained independently of NordBalticum and generally cannot be deleted by us.

18. When we disclose personal data

We do not sell personal data. We may disclose limited personal data to service providers where necessary to operate, secure and support NordBalticum; to independent providers when you request or initiate an interaction with them; to professional advisers where reasonably necessary; or to competent authorities and other recipients where disclosure is required or permitted by applicable law.

NordBalticum does not provide your wallet PIN, private wallet credentials or biometric authentication data to third-party integrations. Where you choose to initiate an external interaction, public wallet, transaction and other information reasonably necessary for that interaction may be processed by the selected provider, blockchain network or supporting infrastructure.

We may also disclose information where reasonably necessary to investigate fraud or abuse, respond to a security incident, establish, exercise or defend legal claims, or protect the rights, security and integrity of NordBalticum and its users, subject to applicable law.

If NordBalticum undergoes a merger, acquisition, financing, reorganisation or transfer of all or part of its business, relevant personal data may be disclosed or transferred as part of that transaction subject to applicable data-protection requirements.

19. International data transfers

Some service providers or independent services may process data outside Lithuania or the European Economic Area. Where NordBalticum is responsible for a transfer of personal data to a country outside the EEA, we use a transfer mechanism or safeguard required by applicable data-protection law, where one is required, such as an adequacy decision or appropriate contractual safeguards.

You may contact us for further information about safeguards applicable to transfers for which NordBalticum is responsible. Independent third-party controllers are responsible for their own international transfers.

20. Security

We use technical and organisational measures designed to protect personal data and the services we operate. Access to personal data is limited according to operational need, and we review security measures in light of the nature of the service and the risks involved.

Your PIN remains on your device and is not provided by NordBalticum to third-party services. Where you enable biometric authentication, the biometric verification is handled by your device and NordBalticum does not receive the biometric template. No online service, device, wallet software, blockchain network or third-party provider can be guaranteed to be completely secure.

21. Automated decision-making

NordBalticum does not currently make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of applicable data-protection law. Automated security controls may detect suspicious activity and may immediately challenge, restrict or suspend hosted functionality where high-confidence security or abuse signals require protective action. Permanent account enforcement is not based on a single weak signal such as an IP address, browser description or one failed request alone. Automated security bans are recorded for administrative review and may be confirmed, removed or marked as a false positive where appropriate.

22. Your data-protection rights

Subject to applicable law and the circumstances of the processing, you may have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time.

These rights are not absolute. A request may be limited where an exemption applies, where retention is legally required, where the request would adversely affect the rights of others, or where the relevant information exists only on a public blockchain or in systems not controlled by NordBalticum.

We may need to verify your identity before acting on a request so that personal data is not disclosed to or deleted at the request of an unauthorized person.

23. Account deletion

You may request or use available functionality to delete your NordBalticum account. We will delete or de-identify personal data associated with the account where required, subject to lawful retention requirements, security needs, fraud prevention, legal claims and technical limitations described in this Policy.

Account deletion does not erase public blockchain records and does not reverse blockchain transactions. Because the wallet is self-custody, deletion of NordBalticum-hosted account data does not give NordBalticum possession or control of crypto-assets recorded on a blockchain.

24. Children

NordBalticum is not intended for children. You must be at least 18 years old, or the age of legal majority in your jurisdiction if higher, and otherwise satisfy the eligibility requirements in our Terms of Service.

25. Complaints and supervisory authority

If you have a privacy concern, we encourage you to contact us first so that we can investigate it. You also have the right, where applicable, to lodge a complaint with the data-protection supervisory authority in your country of habitual residence, place of work or place of the alleged infringement.

As a Lithuanian company, our lead or competent supervisory authority may include the State Data Protection Inspectorate of the Republic of Lithuania, depending on the circumstances and applicable law.

26. Changes to this Privacy Policy

We may update this Policy to reflect changes to NordBalticum, technology, data flows, third-party integrations or legal requirements. We will update the “Last updated” date and provide additional notice where required by applicable law.

27. Contact and controller details

For privacy questions or requests, use the NordBalticum support channel inside the application or email info@nordbalticum.com.

Nord Baltic Capital, UAB
Company code: 307090601
Registered office: Perkūnkiemio g. 13-91, LT-12114 Vilnius, Lithuania
Email: info@nordbalticum.com
Registered with the Register of Legal Entities of the Republic of Lithuania.

Terms of ServiceDelete AccountSign in
NordBalticum
PrivacyTermsDelete account
Self-custody wallet software