Privacy Notice

Effective Date: 2026-04-20 Last Updated: 2026-04-20

1. Purpose and scope

This Privacy Notice explains how Vitallium Corp (the “Company”, “we”, “us”) collects, uses, discloses, transfers, stores, and protects personal data in connection with:

  • the website(s) at https://app.oria.xyz and related pages (the “Site”);
  • mobile application(s), APIs, and related channels (the “Platform”);
  • the custodial crypto wallet and related services (the “Wallet”);

This Notice is directed to Panamanian clients and is governed by Panama’s personal data protection framework (Law 81 of 2019 and its regulation, Executive Decree 285 of 2021). This Notice should be read together with the Terms of Service, Cookies Policy, Risk Disclosure, and any product-specific notices shown in the Platform.

2. Controller (responsible party) and contact

Controller / Responsable: Vitallium Corp, a Panamanian corporation operating under the “Oria” brand.

Contact details

  • Address: 50th Street, PH Plaza 2000, 17th Floor, Panama City, Panama
  • Privacy email: support@oria.xyz
  • Support channel/web form: https://app.oria.xyz

We may request identity verification to protect you against unauthorized access when responding to privacy requests.

3. Custodial wallet statement (keys controlled by the Company / its providers)

The Wallet is custodial. This means:

  • the Company, directly or through one or more custodians or sub-custodians, controls the wallet environment and the relevant private keys or equivalent access credentials;
  • users do not directly control the private keys associated with the custody environment;
  • users’ rights to assets reflected in the account arise from their contractual relationship with the Company and applicable law.

This custody model is a core risk driver; the Company’s risk disclosures address custody chain risk, omnibus pooling risk, insolvency risk, stablecoin freezing/blacklisting risk, and transaction irreversibility.

4. Definitions

  • Personal data: information that identifies or can reasonably identify an individual.
  • Sensitive data: data that, if misused, could create heightened risk (e.g., biometric data used for identity verification; government ID images; sanctions/PEP screening outcomes; certain financial or vulnerability indicators).
  • Processing: any operation performed on personal data (collection, recording, storage, use, disclosure, deletion).
  • Processors / service providers: vendors processing data on our instructions (e.g., cloud, KYC, sanctions screening, fraud tools, customer support tooling).
  • Custodian / sub-custodian: a wallet custody provider in the custody chain for the Service.

5. Personal data we collect

We apply proportionality (we only process personal data to the extent it is reasonably necessary for a legitimate, defined purpose of the service) and minimization (we collect/process the minimum amount of personal data needed to achieve the purpose, and we don’t keep it longer than needed), but the following categories may be processed depending on how you use the Services.

5.1 Data you provide

Account and contact

  • Full name; gender; email; phone number; username/display name; encrypted password
  • Date of birth / age confirmation (18+); nationality
  • Residence/location declarations for eligibility and restrictions
  • Occupation

Identity verification / KYC (where required)

  • Government ID information and images; proof of address
  • Selfie/liveness outputs and verification metadata (may be sensitive)

Source-of-funds / compliance (where required)

  • Source-of-funds/source-of-wealth information, certifications, supporting documents

Communications

  • Support tickets, chat/email messages, complaints, dispute correspondence

5.2 Data we collect automatically

  • Device identifiers, OS/app version, language/timezone, device model
  • IP address; approximate location derived from IP
  • Security telemetry, login events, system logs, error/crash reports
  • App usage data (e.g., page views, interaction data)
  • Site cookies and similar technologies
  • Cookie identifiers and related usage signals as described in the Cookies Policy

5.3 Wallet, transaction, and platform activity data

  • Account identifiers, wallet identifiers, internal ledger entries, balances
  • Deposit/withdrawal instructions, account balance information
  • Risk flags related to fraud, AML, sanctions compliance, and suspicious activity review

5.4 Sensitive data

We may process sensitive data where necessary, including:

  • biometric/liveness verification outputs (if used),
  • government ID images,
  • sanctions/PEP screening outcomes and certain compliance findings,
  • security-related indicators (account compromise signals).

We apply heightened controls described in Sections 8 and 13–14.

6. Purposes of processing (why we use personal data)

We process personal data to:

6.1 Provide and operate the Services

  • Create and administer accounts; authenticate users; provide customer support
  • Provide custodial wallet services, including maintaining internal books and records and processing deposits/withdrawals

6.2 Security and fraud prevention

  • Prevent unauthorized access, phishing, account takeover
  • Detect, investigate, and remediate fraud, abuse, and cybersecurity threats
  • Maintain logs and audit trails

6.3 Compliance and legal obligations

  • Sanctions screening, AML/KYC verification, and transaction monitoring
  • Respond to lawful requests and legal process
  • Enforce Terms, including restriction and suspension mechanics where applicable

6.4 Product improvement and analytics

  • Debug, maintain, and improve the Platform and Site
  • Analyze performance and usage trends (including via cookies where deployed)

6.5 Communications and marketing (where applicable)

  • Service notices (security alerts, policy updates)
  • Marketing communications where permitted; opt-out controls apply

7. Legal basis / processing conditions (Panama)

We process personal data consistent with Panama Law 81 principles (lawfulness, transparency, purpose limitation, proportionality, security) and Decree 285 operational governance.

Operationally, processing is based on one or more of:

  • Contractual necessity (to provide the Services you request)
  • Legal obligations (compliance, lawful requests)
  • Legitimate interests (security, fraud prevention, platform integrity, service improvement)
  • Consent where required/appropriate (notably certain marketing and certain sensitive data processing)

8. Sensitive data and “related companies of service providers” sharing

8.1 When we share sensitive data

We share sensitive data only where necessary for defined purposes such as:

  • identity verification, liveness/biometric verification (if used),
  • compliance screening (sanctions/PEP),
  • fraud prevention, account security, and incident response,
  • customer support investigations and dispute handling.

8.2 Sharing with “companies related to the service provider”

Where necessary to provide the Services, we may disclose sensitive data to:

  • our affiliates (entities under common control with the Company), and
  • affiliates of our processors/service providers (e.g., corporate group entities of KYC, security, cloud, or support tooling providers)

only to the extent those related entities are involved in delivering the same contracted service (e.g., regional processing, specialized verification, security operations, technical support).

8.3 Mandatory safeguards

We require, contractually and operationally:

  • purpose limitation and confidentiality,
  • access controls and least privilege,
  • sub-processor controls and flow-down obligations,
  • security requirements proportionate to risk,
  • retention and deletion controls, and
  • cooperation with user rights requests (where applicable).

9. How we share personal data (recipient categories)

We may share personal data with:

  • Custodians and sub-custodians used in the custody chain for the Service.
  • Service providers/processors (cloud hosting, security monitoring, KYC/AML, sanctions screening, fraud tooling, communications, analytics, customer support).
  • Affiliates for operations, compliance, security, and support.
  • Authorities / legal recipients where required by law or to protect rights/safety.
  • Business transfer counterparties (M&A, restructuring), subject to confidentiality and legal safeguards.

10. International transfers

Your data may be processed in Panama and may be transferred internationally depending on where our custodians/sub-custodians and vendors operate and on our hosting architecture (cloud regions, redundancy, monitoring). Where international transfers occur, we implement safeguards consistent with Panama’s regime, including contractual protections and security measures.

11. Cookies and similar technologies (site)

Our Site uses cookies and similar technologies as described in our Cookies Policy. That policy describes cookie categories (necessary, functional, analytics, advertising/profiling if deployed) and emphasizes that this Privacy Notice governs the personal data aspects (purposes, rights, retention, transfers).

12. Automated processing, compliance controls, and restrictions

We may use automated and semi-automated systems to detect fraud and account compromise, apply sanctions/compliance screening, and monitor suspicious activity. These controls may lead to transaction delays, additional verification requests, account restrictions/suspension, or refusals where necessary for security, sanctions, AML/CFT, legal process, or platform integrity.

13. Security measures

We use administrative, technical, and physical measures proportionate to risk, including:

  • access controls/least privilege,
  • encryption in transit and, where appropriate, at rest,
  • secure SDLC practices and monitoring,
  • incident response procedures,
  • vendor due diligence and contractual security clauses.

14. Security incidents and breach response (Panama; Decree 285 alignment)

If a security incident affects personal data, we will investigate and mitigate, document the incident, and notify affected individuals and/or the competent authority where required under applicable law and our Decree 285-aligned procedures.

15. Retention (how long we keep data)

We retain personal data only as long as necessary for providing the Services and customer support, compliance/audits/dispute resolution/legal defense, security and fraud prevention, and enforcing Terms and restrictions. Retention periods may vary by data category and legal requirements. We apply deletion/anonymization where feasible once retention is no longer required. However, to comply with the mandatory record-keeping requirements under Panama’s anti-money laundering and tax laws, transaction records and identity verification data (KYC) shall generally be retained for a period of no less than 5 years after the termination of the transaction. The specific retention period shall be subject to applicable laws.

16. Your rights (Panama)

You may have rights under Panama law to request access, correction/rectification, deletion/suppression where applicable, objection/opposition, and other rights recognized by Law 81, subject to identity verification and legal exceptions. How to exercise rights: Contact us using the details in Section 2. We may request additional information to verify identity and locate relevant records.

17. Children

The Services are intended for users 18+ (or the age of majority), consistent with the Terms. We do not knowingly collect personal data from minors.

18. Changes to this Privacy Notice

We may update this Notice to reflect legal, technical, or operational changes. We will update the “Last Updated” date and provide notice through the Platform/Site or other appropriate channel.

19. Contact

For privacy questions, complaints, or rights requests:

  • 50th Street, PH Plaza 2000, 17th Floor, Panama City, Panama
  • support@oria.xyz
  • https://oria.xyz

Annex A — Decree 285 operational compliance artifacts (internal governance)

To align with Decree 285 governance expectations, the Company maintains internally:

  • (protocols/processes/procedures for secure processing and transfers). Transfer register (log of data transfers to third parties and relevant details). Incident documentation + notification workflow. Processor/custodian agreements with minimum privacy/security clauses and sub-processor controls.