Privacy Policy
Article 1 – Data Collection
As part of registration, subscription, and regulatory procedures, Nestra collects strictly necessary personal data:
- Identification data (name, surname, email, phone)
- KYC/AML documents: ID card, proof of address, proof of source of funds
- Payment information (FIAT and crypto)
Article 2 – Purposes of data collection
The data collected is used exclusively to:
- Comply with KYC/AML regulatory obligations
- Manage subscriptions and investments
- Ensure communication with investors (with explicit consent)
Article 3 – Retention and Security
Data is hosted in environments compliant with GDPR (EU), PDPA (Thailand), UAE Data Protection.
Data is retained for a period of 5 years after the end of the contractual relationship.
Security measures implemented:
- Encryption of sensitive data
- Restricted access to authorized personnel only
- Compliance with international standards (ISO/IEC 27001, etc.)
Article 4 – User Rights
In accordance with applicable regulations, users have the following rights:
- Access to their data
- Rectification of inaccurate data
- Deletion of data, subject to legal retention obligations
To exercise these rights, contact: contact@nestra.capital
Article 5 – Data Sharing
Collected data is never sold to third parties.
It is shared only with:
- Authorized partners for KYC/AML procedures (including XSpring – regulated by the Thai SEC)
- Partner law firms
- Competent regulatory authorities (Thailand, UAE, Europe if applicable)
Article 6 – Data Protection Officer (DPO)
The data protection officer role is currently ensured by the founder of Nestra Capital, on a provisional basis.
This role may be transferred to an external certified DPO to strengthen compliance with international investors.