Controller: Vela Labs Ltd (RC 9463024) Product: Cypra Effective date: 26 July 2026 Governing privacy law: Nigeria Data Protection Act 2023 (NDPA) and other applicable law
This Privacy Policy explains how Vela Labs Ltd (“Vela Labs,” “we,” “us”) collects, uses, stores, and shares personal data when you use Cypra (the “Services”).
Related documents: Terms of Use · AML Policy
1. Who we are
Vela Labs Ltd operates Cypra, a crypto on-ramp and off-ramp product delivered primarily through Telegram and related web properties. We act as the data controller for personal data we determine the purposes and means of processing. Where Partners process data on our instructions, they act as processors or independent controllers as described below.
Contact for privacy requests: via Telegram @usecyprabot or the company site velalabs.iamphantasm0.xyz.
2. Scope
This Policy applies to personal data processed through:
- the Cypra Telegram bot and future messaging channels;
- the Cypra website (including legal pages and marketing pages we operate);
- compliance, support, and administrative tools we use to run the Services.
It does not control how Telegram, your bank, or blockchain networks process data as independent operators of their own platforms.
3. Personal data we collect
Depending on how you use Cypra, we may process:
3.1 Identity and contact data
- Messaging platform identifiers (for example Telegram user ID, username, display name)
- Full name and other names you provide
- Date of birth, nationality, residency indicators (where collected)
- Government identity numbers or documents (for example BVN, NIN, passport, national ID, or other country-specific IDs), including images and metadata
- Contact details you share in support conversations
3.2 Verification and compliance data
- KYC tier, verification status, and review outcomes
- Hashed or tokenised identity attributes (for example HMAC-hashed identifiers used for duplicate detection)
- Biometric or liveness signals if an identity provider captures them (processed primarily by that provider)
- Source-of-funds or source-of-wealth information when required
- Sanctions, PEP, and adverse-media screening results
- Internal compliance flags, case notes, and audit logs
3.3 Financial and transaction data
- Bank account details for payouts (account name, number, bank, currency)
- Wallet addresses, networks, transaction hashes, amounts, tokens
- Order history, rates displayed, fees, statuses, failure reasons
- Deposit monitoring records for Settlement Wallets
3.4 Technical and usage data
- Server logs, IP address (where available), timestamps, error diagnostics
- Device or client metadata passed by messaging platforms or browsers
- Security and rate-limiting signals
- Optional product analytics events if analytics tools are enabled
3.5 Communications
- Messages you send to the bot or support
- Notifications we send about Order status
We do not intentionally collect special categories of data beyond what is necessary for identity verification and legal compliance. Please do not submit irrelevant sensitive information.
4. How we collect data
- Directly from you via bot flows, forms, and support
- Automatically when you use the Services (logs, Order lifecycle, on-chain monitoring)
- From Partners (identity verification providers, payment networks, blockchain data providers, wallet infrastructure)
- From public or official sources used in sanctions and fraud screening
5. Purposes and legal bases
Under the NDPA and related principles, we process personal data for:
| Purpose | Examples | Typical basis |
|---|---|---|
| Provide the Services | Create Account, execute Orders, operate Settlement Wallets | Contract / steps prior to contract |
| Identity verification & KYC | Tier limits, document checks | Legal obligation / legitimate interests / contract |
| AML/CFT & fraud prevention | Monitoring, SARs, sanctions screening | Legal obligation / public interest / legitimate interests |
| Customer support | Investigate failed Orders | Contract / legitimate interests |
| Security & abuse prevention | Rate limits, intrusion detection | Legitimate interests / legal obligation |
| Product improvement | Reliability metrics, feature performance | Legitimate interests |
| Legal defence & records | Disputes, audits | Legitimate interests / legal obligation |
| Communications | Status updates you request or that are necessary | Contract / legitimate interests |
Where consent is required for a specific optional processing activity, we will request it and you may withdraw it without affecting processing that relies on other bases (for example AML record-keeping).
6. Sharing and processors
We share personal data only as needed to operate Cypra or as required by law. Categories of recipients include:
- Payment protocol / liquidity / payout Partners — to execute on-ramp and off-ramp Orders
- Wallet infrastructure providers — to create and operate Settlement Wallets
- Blockchain monitoring / RPC providers — to detect deposits and confirmations
- Identity verification providers — to verify government IDs and related checks
- Cloud hosting and infrastructure — to run application, database, cache, and storage
- Analytics or error-monitoring tools — if enabled, to maintain reliability (configured to minimise unnecessary personal data where feasible)
- Professional advisers and auditors — under confidentiality
- Regulators, NFIU, law enforcement, courts — when legally required or permitted
- Corporate successors — in a merger, acquisition, or restructuring, subject to appropriate safeguards
We do not sell your personal data.
7. International transfers
Infrastructure and Partners may process data in countries other than Nigeria. Where we transfer personal data internationally, we take steps consistent with the NDPA and good industry practice (for example contractual safeguards, careful vendor selection, and minimisation). Blockchain transactions are public by nature and may be visible globally.
8. Retention
- AML and transaction records: generally retained for a minimum of five (5) years from the last transaction or account closure (whichever is later), or longer if law requires.
- KYC documents and verification data: retained for the AML period and any longer period needed for disputes or legal claims.
- Operational logs: retained for shorter security and debugging windows unless linked to a compliance case.
- Marketing data (if any): until you opt out or the campaign ends.
When retention ends, we delete or anonymise data where feasible, unless a legal hold applies.
9. Security
We implement technical and organisational measures appropriate to the risk, including access controls, encryption in transit where applicable, hashed storage of certain identity numbers, least-privilege access, and monitoring. No method of transmission or storage is perfectly secure; you also must protect your messaging accounts and devices.
10. Your rights
Subject to the NDPA and exemptions (including AML tipping-off and law-enforcement restrictions), you may have the right to:
- be informed about processing;
- access personal data we hold about you;
- request correction of inaccurate data;
- request deletion where applicable (note: AML retention may prevent full erasure);
- restrict or object to certain processing;
- data portability where applicable; and
- lodge a complaint with the Nigeria Data Protection Commission (NDPC).
To exercise rights, contact us via Telegram @usecyprabot. We may need to verify your identity before responding. We aim to respond within timeframes required by law.
11. Children
The Services are not directed to individuals under 18. We do not knowingly onboard minors. If you believe a minor has provided data, contact us so we can take appropriate action.
12. Automated decision-making
We use automated monitoring and rules (for example velocity checks, sanctions hits, tier limits) that may affect whether an Order proceeds. Material decisions may be subject to human review in our compliance processes. You may contact us to request an explanation or review where the NDPA provides that right and no legal prohibition applies.
14. Changes
We may update this Privacy Policy from time to time. The effective date will change when we do. Material changes will be posted on the website and/or communicated through the Services.
15. Contact
Vela Labs Ltd RC 9463024
Privacy / product contact: Telegram — @usecyprabot Company: https://velalabs.iamphantasm0.xyz/ Website: https://cypra.iamphantasm0.xyz/
This Privacy Policy is a public draft for Users of Cypra. It is not a substitute for personalised legal advice.