cypra.
Terms Privacy AML Open bot
Legal

Privacy Policy

Vela Labs Ltd · Cypra · Last updated 26 July 2026

On this page
1. Who we are 2. Scope 3. Personal data we collect 3.1 Identity and contact data 3.2 Verification and compliance data 3.3 Financial and transaction data 3.4 Technical and usage data 3.5 Communications 4. How we collect data 5. Purposes and legal bases 6. Sharing and processors 7. International transfers 8. Retention 9. Security 10. Your rights 11. Children 12. Automated decision-making 13. Cookies and website 14. Changes 15. Contact

Controller: Vela Labs Ltd (RC 9463024) Product: Cypra Effective date: 26 July 2026 Governing privacy law: Nigeria Data Protection Act 2023 (NDPA) and other applicable law

This Privacy Policy explains how Vela Labs Ltd (“Vela Labs,” “we,” “us”) collects, uses, stores, and shares personal data when you use Cypra (the “Services”).

Related documents: Terms of Use · AML Policy


1. Who we are

Vela Labs Ltd operates Cypra, a crypto on-ramp and off-ramp product delivered primarily through Telegram and related web properties. We act as the data controller for personal data we determine the purposes and means of processing. Where Partners process data on our instructions, they act as processors or independent controllers as described below.

Contact for privacy requests: via Telegram @usecyprabot or the company site velalabs.iamphantasm0.xyz.


2. Scope

This Policy applies to personal data processed through:

  • the Cypra Telegram bot and future messaging channels;
  • the Cypra website (including legal pages and marketing pages we operate);
  • compliance, support, and administrative tools we use to run the Services.

It does not control how Telegram, your bank, or blockchain networks process data as independent operators of their own platforms.


3. Personal data we collect

Depending on how you use Cypra, we may process:

3.1 Identity and contact data

  • Messaging platform identifiers (for example Telegram user ID, username, display name)
  • Full name and other names you provide
  • Date of birth, nationality, residency indicators (where collected)
  • Government identity numbers or documents (for example BVN, NIN, passport, national ID, or other country-specific IDs), including images and metadata
  • Contact details you share in support conversations

3.2 Verification and compliance data

  • KYC tier, verification status, and review outcomes
  • Hashed or tokenised identity attributes (for example HMAC-hashed identifiers used for duplicate detection)
  • Biometric or liveness signals if an identity provider captures them (processed primarily by that provider)
  • Source-of-funds or source-of-wealth information when required
  • Sanctions, PEP, and adverse-media screening results
  • Internal compliance flags, case notes, and audit logs

3.3 Financial and transaction data

  • Bank account details for payouts (account name, number, bank, currency)
  • Wallet addresses, networks, transaction hashes, amounts, tokens
  • Order history, rates displayed, fees, statuses, failure reasons
  • Deposit monitoring records for Settlement Wallets

3.4 Technical and usage data

  • Server logs, IP address (where available), timestamps, error diagnostics
  • Device or client metadata passed by messaging platforms or browsers
  • Security and rate-limiting signals
  • Optional product analytics events if analytics tools are enabled

3.5 Communications

  • Messages you send to the bot or support
  • Notifications we send about Order status

We do not intentionally collect special categories of data beyond what is necessary for identity verification and legal compliance. Please do not submit irrelevant sensitive information.


4. How we collect data

  • Directly from you via bot flows, forms, and support
  • Automatically when you use the Services (logs, Order lifecycle, on-chain monitoring)
  • From Partners (identity verification providers, payment networks, blockchain data providers, wallet infrastructure)
  • From public or official sources used in sanctions and fraud screening

5. Purposes and legal bases

Under the NDPA and related principles, we process personal data for:

PurposeExamplesTypical basis
Provide the ServicesCreate Account, execute Orders, operate Settlement WalletsContract / steps prior to contract
Identity verification & KYCTier limits, document checksLegal obligation / legitimate interests / contract
AML/CFT & fraud preventionMonitoring, SARs, sanctions screeningLegal obligation / public interest / legitimate interests
Customer supportInvestigate failed OrdersContract / legitimate interests
Security & abuse preventionRate limits, intrusion detectionLegitimate interests / legal obligation
Product improvementReliability metrics, feature performanceLegitimate interests
Legal defence & recordsDisputes, auditsLegitimate interests / legal obligation
CommunicationsStatus updates you request or that are necessaryContract / legitimate interests

Where consent is required for a specific optional processing activity, we will request it and you may withdraw it without affecting processing that relies on other bases (for example AML record-keeping).


6. Sharing and processors

We share personal data only as needed to operate Cypra or as required by law. Categories of recipients include:

  • Payment protocol / liquidity / payout Partners — to execute on-ramp and off-ramp Orders
  • Wallet infrastructure providers — to create and operate Settlement Wallets
  • Blockchain monitoring / RPC providers — to detect deposits and confirmations
  • Identity verification providers — to verify government IDs and related checks
  • Cloud hosting and infrastructure — to run application, database, cache, and storage
  • Analytics or error-monitoring tools — if enabled, to maintain reliability (configured to minimise unnecessary personal data where feasible)
  • Professional advisers and auditors — under confidentiality
  • Regulators, NFIU, law enforcement, courts — when legally required or permitted
  • Corporate successors — in a merger, acquisition, or restructuring, subject to appropriate safeguards

We do not sell your personal data.


7. International transfers

Infrastructure and Partners may process data in countries other than Nigeria. Where we transfer personal data internationally, we take steps consistent with the NDPA and good industry practice (for example contractual safeguards, careful vendor selection, and minimisation). Blockchain transactions are public by nature and may be visible globally.


8. Retention

  • AML and transaction records: generally retained for a minimum of five (5) years from the last transaction or account closure (whichever is later), or longer if law requires.
  • KYC documents and verification data: retained for the AML period and any longer period needed for disputes or legal claims.
  • Operational logs: retained for shorter security and debugging windows unless linked to a compliance case.
  • Marketing data (if any): until you opt out or the campaign ends.

When retention ends, we delete or anonymise data where feasible, unless a legal hold applies.


9. Security

We implement technical and organisational measures appropriate to the risk, including access controls, encryption in transit where applicable, hashed storage of certain identity numbers, least-privilege access, and monitoring. No method of transmission or storage is perfectly secure; you also must protect your messaging accounts and devices.


10. Your rights

Subject to the NDPA and exemptions (including AML tipping-off and law-enforcement restrictions), you may have the right to:

  • be informed about processing;
  • access personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion where applicable (note: AML retention may prevent full erasure);
  • restrict or object to certain processing;
  • data portability where applicable; and
  • lodge a complaint with the Nigeria Data Protection Commission (NDPC).

To exercise rights, contact us via Telegram @usecyprabot. We may need to verify your identity before responding. We aim to respond within timeframes required by law.


11. Children

The Services are not directed to individuals under 18. We do not knowingly onboard minors. If you believe a minor has provided data, contact us so we can take appropriate action.


12. Automated decision-making

We use automated monitoring and rules (for example velocity checks, sanctions hits, tier limits) that may affect whether an Order proceeds. Material decisions may be subject to human review in our compliance processes. You may contact us to request an explanation or review where the NDPA provides that right and no legal prohibition applies.


13. Cookies and website

Our marketing website is primarily static. If we introduce analytics cookies or similar technologies, we will update this Policy and, where required, obtain consent. Essential hosting and security logs may still be processed.


14. Changes

We may update this Privacy Policy from time to time. The effective date will change when we do. Material changes will be posted on the website and/or communicated through the Services.


15. Contact

Vela Labs Ltd RC 9463024

Privacy / product contact: Telegram — @usecyprabot Company: https://velalabs.iamphantasm0.xyz/ Website: https://cypra.iamphantasm0.xyz/


This Privacy Policy is a public draft for Users of Cypra. It is not a substitute for personalised legal advice.

cypra. © 2026 Cypra · by Vela Labs LTD
Terms of use Privacy policy AML policy