• LEGAL

Privacy Policy

Effective date: June 26, 2026

Introduction

This Privacy Policy explains how Antier Solutions Pvt Ltd (“Antier,” "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the Flashtle platform and related services (collectively, the "Services"). Antier is the legal entity that operates the Flashtle platform. The Services are provided to business customers ("Customers"). This Privacy Policy applies to: (a) personal information of Customers authorized representatives, employees, and personnel that we collect in connection with account registration, account administration, and ongoing operation of the Services; (b) personal information of visitors to our website; (c) personal information that Customers submit to the Services as part of Customers' business operations, except as otherwise governed by the Data Processing Addendum referenced in Section 11. This Privacy Policy does not apply to: (a) the practices of the independent third-party Know-Your-Business verification provider described in Section 4, which acts as a separate data controller for the personal data Customers submit to it directly; (b) the practices of third-party payment networks, banking partners, or other third parties whose services may be involved in payment processing; (c) the practices of Customers themselves in collecting personal information from their own users or counterparties. If you are a resident of the European Economic Area, the United Kingdom, California, or another jurisdiction with specific privacy rights, additional information about those rights is provided in Section 10.

1. Roles and Responsibilities

The parties' roles under applicable data protection law depend on the personal information involved: (a) Antier as data controller: For personal information of Customers' authorized representatives that Antier collects directly in connection with account registration, account administration, billing, security, support, and operation of the Services, Antier acts as the data controller and determines the purposes and means of processing. (b) Antier as data processor: For personal information that Customers submit to the Services about Customers' own end customers, counterparties, or other data subjects in the course of Customers' business operations, Antier acts as a data processor on behalf of Customer. Antier processes this personal information only in accordance with Customer's documented instructions and the Data Processing Addendum. (c) Third-party KYB provider as data controller: For personal information that Customers submit to the third-party Know-Your-Business verification provider during business verification, that provider acts as an independent data controller. Antier does not receive, store, or have access to those documents. (d) Antier as joint controller (limited circumstances): In limited circumstances where Antier and a third party (such as a banking partner) jointly determine the purposes and means of processing specific categories of personal information, Antier and that third party may act as joint controllers. The terms of any such joint controllership arrangement are documented separately.

2. Personal Information We Collect

2.1 Information Customers Provide to Us.

When a Customer registers for and uses the Services, we collect: (a) Business and account information: legal business name, registered business address, business website, business jurisdiction. (b) Personal information of Customer's authorized representatives: name, business email address, business phone number, job title or role, and the authentication credentials they use to access the Services. (c) Account credentials and authentication data: usernames, passwords (stored as cryptographic hashes, never in plaintext), multi-factor authentication factors, API keys, and session identifiers. (d) Communications: information that authorized representatives share when contacting our support team, submitting feedback, or otherwise communicating with us, including content of messages, support tickets, and call recordings where applicable and notified. (e) Billing and commercial information: payment method details (typically processed by our payment processor without Antier directly storing full card numbers), billing address, tax identification numbers, and commercial agreement details. (f) Verification status: status information received from the KYB provider regarding business verification outcome (approved, declined, pending, or further review required). We do not receive the underlying documents Customer submits to the KYB provider.

2.2 Information We Collect Automatically

When the Services are accessed or used, we automatically collect: (a) Usage data: actions performed within the Flashtle platform, including transactions initiated, API calls made, dashboard interactions, feature usage, configuration changes, and event timestamps. This data is logged on Antier's own infrastructure for the purposes described in Section 3. (b) Device and connection information: Internet Protocol (IP) address, browser type and version, operating system, device identifiers, screen and viewport dimensions, language preferences, referring URL, and timestamps. (c) Cookies and similar technologies: as described in Section 7.

(d) Authentication and security event logs: records of authentication attempts, session activity, security-relevant events, and indicators of fraud or abuse.

2.3 Information from Third Parties

We may receive personal information from third parties in limited circumstances: (a) From the KYB provider: verification status information as described in Section 2.1(f). We do not receive the underlying identification documents Customer submits to the KYB provider. (b) From banking partners and payment networks: limited transaction-related information necessary to process payments, settle funds, and respond to inquiries. (c) From fraud-prevention and sanctions-screening providers: information used to assess fraud risk and screen against applicable sanctions and watchlists. (d) From corporate-information providers: where required to verify or supplement Customer's business information, we may receive information from public registries or commercial business-information providers. We do not purchase, acquire, or rent personal information from data brokers for marketing, advertising, or profiling purposes.

2.4 Sensitive Personal Information

Antier does not intentionally collect or process the following categories of sensitive personal information through the Services: (a) racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, or trade union membership; (b) genetic data or biometric data for identifying a natural person; (c) data concerning health; (d) data concerning a natural person's sex life or sexual orientation; (e) precise geolocation; (f) contents of mail, email, or text messages other than those directly addressed to Antier. To the extent Customers submit such information through the Services for their own business purposes, Antier processes it only as a data processor under Customer's instructions and the Data Processing Addendum.

3. How We Use Personal Information

3.1 Purposes of Processing.Antier processes personal information for the following purposes:

(a) Providing the Services: operating the Flashtle platform, processing transactions, providing dashboards and reports, delivering features requested by Customer, and supporting integrations. (b) Account administration and customer support: authenticating users, managing access, billing, providing support, responding to inquiries, troubleshooting issues, and communicating about account status and service changes. (c) Security and fraud prevention: detecting, preventing, investigating, and responding to unauthorized access, suspicious activity, security threats, abuse, fraud, and misuse of the Services.

(d) Legal and regulatory compliance: complying with applicable laws, regulations, court orders, lawful governmental requests, and our regulatory obligations. (e) Risk management: assessing and managing risks related to Customer's use of the Services, including KYB outcomes, ongoing monitoring, sanctions screening, and risk-related decision-making in connection with banking partner and payment network requirements. (f) Service improvement and analytics: analyzing usage patterns to improve the functionality, performance, reliability, and security of the Services. This analysis is performed using data logged on Antier's own infrastructure; we do not share usage data with third-party analytics providers. (g) Operational communications: sending service-related notices, security alerts, billing communications, and updates about changes to the Services or to these privacy practices. (h) Audit and recordkeeping: maintaining records necessary for internal audit, financial recordkeeping, regulatory reporting, and dispute resolution. (i) Corporate transactions and reorganization: evaluating and undertaking corporate transactions such as mergers, acquisitions, reorganizations, financings, or asset sales, including any spin-out of the Flashtle business into a separate legal entity. We do not use personal information for advertising or marketing by third parties, and we do not sell personal information.

3.2 Legal Bases for Processing (GDPR and UK GDPR)

If you are located in the European Economic Area or the United Kingdom, Antier processes personal information on the following legal bases under the GDPR and UK GDPR: (a) Contract (Article 6(1)(b) GDPR): processing necessary to perform our contract with the Customer or to take steps at the Customer's request before entering into a contract, for example, account registration, billing, and provision of the Services. (b) Legal obligation (Article 6(1)(c) GDPR): processing necessary to comply with our legal obligations, for example, anti-money-laundering recordkeeping, sanctions screening, tax reporting, and responses to lawful requests from authorities. (c) Legitimate interests (Article 6(1)(f) GDPR): processing necessary for our legitimate interests, where those interests are not overridden by the rights and freedoms of data subjects. Our legitimate interests include: (i) operating, securing, and improving the Services; (ii) preventing fraud, abuse, and security incidents; (iii) defending against legal claims and managing our own business; (iv) limited communications to Customers' authorized representatives regarding the Services they use; (v) corporate transactions and business continuity. (d) Consent (Article 6(1)(a) GDPR): where we ask for your specific, informed, freely given consent, for example, for non-essential cookies and for certain optional features.

Where we rely on legitimate interests, you have the right to object as described in Section 10. You may obtain further information about our legitimate interests balancing tests by contacting legal@antiersolutions.com

3.3 Automated Decision-Making

Antier does not subject Customers' authorized representatives to decisions based solely on automated processing that produces legal effects or similarly significantly affects them, except as required by applicable law for fraud prevention, sanctions screening, or risk decisions associated with account access. Where automated decision-making is used, Customers or their representatives have the right to request human review, express their views, and contest the decision in accordance with Section 10.

4. Third-Party Business Verification

To use the Services, Customers must complete business identity verification ("KYB Verification") through an independent third-party verification provider engaged by Antier (the "KYB Provider"). The verification is conducted directly between the Customer and the KYB Provider: (a) Customer submits identification documents and business records directly to the KYB Provider; (b) Antier does not receive, store, or have access to the underlying documents; (c) The KYB Provider acts as a separate data controller for the personal data Customer submits during verification; (d) The Customer's interaction with the KYB Provider is governed by the KYB Provider's separate privacy notice and terms, which the KYB Provider makes available to Customer directly during verification. Antier receives only verification status information (such as approved, declined, pending, or further review required) from the KYB Provider. Antier uses this information to determine whether to grant or maintain Customer's access to the Services.

5. How We Disclose Personal Information

Antier does not sell personal information. We do not share personal information with third parties for their own marketing or advertising purposes. We disclose personal information only in the following circumstances:

5.1 Service Providers and Subprocessors

We use third-party service providers ("Subprocessors") to support the operation of the Services. These Subprocessors process personal information on our behalf under written contracts that:

(a) restrict their processing of personal information to specified purposes; (b) require them to implement appropriate technical and organizational security measures; (c) prohibit further disclosure or use of the personal information without authorization; (d) impose confidentiality obligations and audit rights consistent with applicable law. Categories of Subprocessors we use include: (a) Cloud infrastructure providers: hosting the Flashtle platform and Customer Data. The specific provider and region depend on the data residency configuration the Customer selects. (b) Security and fraud-prevention service providers: assisting with fraud detection, sanctions screening, and security monitoring. (c) Payment processors and banking partners: facilitating payment processing, settlement, and treasury operations. (d) Communications providers: enabling email, notifications, and customer support tools. (e) Professional advisors: legal, accounting, auditing, and other professional advisors bound by confidentiality obligations. We will provide reasonable advance notice of changes to the Subprocessor list to Customers who have engaged the Services under a contract that requires such notice.

5.2 Banking Partners and Payment Networks

To process payment transactions on behalf of Customers, we share transaction-related personal information with banking partners, card networks, payment processors, and other parties involved in the payment flow. The information shared is limited to what is necessary to process, settle, reconcile, and resolve disputes related to transactions.

5.3 Legal Compliance and Protection

We may disclose personal information when: (a) required by law, regulation, court order, subpoena, or other legal process; (b) responding to a valid governmental request or law enforcement inquiry; (c) we reasonably believe disclosure is necessary to: (i) comply with our legal or regulatory obligations; (ii) protect the rights, property, safety, or security of Antier, our customers, our personnel, or others; (iii) investigate, prevent, or address fraud, security incidents, or violations of our terms or policies; (iv) enforce our agreements and policies; (v) establish, exercise, or defend legal claims.

5.4 Corporate Transactions

If Antier is involved in a merger, acquisition, reorganization, financing, sale of all or substantially all assets, bankruptcy, or similar corporate transaction (including a spin-out of the Flashtle business into a separate legal entity), personal information may be transferred to the acquiring or successor entity. We will notify affected data subjects of such transfers consistent with applicable law and will require the recipient to honor the commitments in this Privacy Policy.

5.5 With Consent or at Direction

We may disclose personal information with the data subject's consent or at the direction of the Customer in accordance with the Data Processing Addendum.

6. International Data Transfers

Antier operates internationally and supports multiple regional hosting configurations to accommodate Customers' data residency requirements. As part of providing the Services, personal information may be transferred to, processed in, and stored in jurisdictions other than the jurisdiction where it was originally collected.

6.1 Transfers from the EEA and the UK

For transfers of personal information from the European Economic Area or the United Kingdom to jurisdictions that have not received an adequacy decision from the European Commission or the UK Information Commissioner's Office, we rely on appropriate safeguards including: (a) Standard Contractual Clauses adopted by the European Commission (the "EU SCCs"), as updated from time to time; (b) the UK International Data Transfer Agreement or UK Addendum to the EU SCCs (as applicable); (c) Transfer Impact Assessments completed where required to evaluate the laws and practices of the destination jurisdiction; (d) supplementary measures as appropriate to address specific risks identified in Transfer Impact Assessments.

6.2 Specific Transfer Considerations

(a) Transfers to India: India has not received an adequacy decision from the European Commission as of the effective date of this Privacy Policy. Where Antier processes EEA or UK personal information in India, we rely on EU SCCs and/or the UK International Data Transfer Agreement, supported by Transfer Impact Assessments and supplementary measures.

(b) Transfers to the United States: We rely on EU SCCs and the UK International Data Transfer Agreement (or UK Addendum) for transfers to the United States. Where applicable, we participate in or rely on additional frameworks recognized under applicable law.

7. Cookies and Similar Technologies

7.1 Categories of Cookies

We use cookies and similar technologies on our website and within the Services for the following purposes: (a) Strictly necessary cookies: required for the Services to function properly. These cookies enable core functionality such as authentication, session management, security, fraud prevention, and load balancing. These cookies do not require consent under applicable law. (b) Functional cookies: enabling features such as remembering Customer preferences, language settings, and saved configurations. (c) Analytics cookies: helping us understand how the Services are used so we can improve them. Antier conducts analytics using internal logging only, we do not use third-party analytics providers such as Google Analytics, Mixpanel, Amplitude, Hotjar, or similar services. Data collected by analytics cookies remains within Antier's own infrastructure.

7.2 Cookie Consent and Management

For non-essential cookies (functional and analytics), Customers and website visitors located in jurisdictions requiring consent (such as the EEA and the UK) will be presented with a cookie consent mechanism allowing them to accept, reject, or customize their cookie preferences.

You can manage cookie preferences at any time through: (a) the cookie preferences interface available at the site; (b) your browser settings.

8. Data Retention

We retain personal information for as long as is necessary to provide the Services and to comply with our legal, regulatory, and operational obligations.

8.1 Retention Periods by Category

Retention periods vary by data category: (a) Account information: retained for the duration of the Customer's active account, plus a reasonable period after termination to handle final settlement, support requests, disputes, and to comply with legal retention requirements. (b) Transaction and settlement records: retained for the period required by applicable financial services regulations, which is generally [seven (7) years] from the date of the transaction, but may be longer for specific jurisdictions or specific record types. (c) AML/KYB recordkeeping: retained for the period required by applicable anti-money-laundering laws, typically [five (5) to seven (7) years] from the end of the customer relationship or the date of the relevant transaction, whichever is longer. (d) Support communications: retained for [three (3) years] from the date of the communication. (e) Internal usage logs: retained in identifiable form for up to [thirteen (13) months], after which they are either aggregated (in a form that no longer identifies individuals) or deleted. (f) Authentication and security event logs: retained for [twelve (12) to twenty-four (24) months] for security investigation, fraud-prevention, and compliance purposes, depending on the event type. (g) Cookies: retention periods for specific cookies are disclosed in the Cookie Policy.

8.2 Disposal

When personal information is no longer necessary for the purposes for which it was collected, and when no legal retention obligation applies, we delete it or anonymize it (rendering it no longer attributable to an identified or identifiable individual).

8.3 Legal Hold

Notwithstanding the retention periods above, we may retain personal information for longer periods where required by: (a) applicable law, regulation, or court order; (b) ongoing or anticipated legal proceedings, audits, or investigations; (c) the exercise or defense of legal claims.

9. Security

9.1 Security Program

Antier maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our security program includes: (a) Encryption in transit: Transport Layer Security (TLS) version 1.2 or higher for data transmitted between Customer systems and the Services and between internal components. (b) Encryption at rest: cryptographic algorithms consistent with applicable industry standards (including AES-256 for symmetric encryption) for personal information stored within the Services. (c) Access controls: role-based access controls, principle of least privilege, multi-factor authentication for personnel access to systems processing personal information, and regular access reviews. (d) Network security: network segmentation, intrusion detection systems, web application firewalls, and continuous monitoring. (e) Personnel security: background checks where permitted by law, security training for personnel, written confidentiality agreements, and access governance procedures.

(f) Vendor management: due diligence and contractual safeguards for Subprocessors and other third parties with access to personal information. (g) Incident response: a documented incident response program for identifying, containing, investigating, and remediating security incidents, including escalation, forensics, and post-incident review procedures. (h) Vulnerability management: regular vulnerability scans, penetration testing, secure software development practices, and patch management. (i) Backup and recovery: backup procedures and disaster recovery planning to support continuity of the Services.

9.2 No Absolute Security

While we take commercially reasonable precautions to protect personal information, no security program can guarantee absolute security. We cannot warrant that the Services will be free from unauthorized access, security incidents, or other compromises.

9.3 Security Incident Notification

If Antier becomes aware of a security incident involving the unauthorized access to, acquisition of, disclosure of, or destruction of personal information, Antier will:

(a) notify affected Customers without undue delay, and in any event within the timeframes required by applicable law; (b) provide information about the nature of the incident, the categories and approximate number of data subjects and records affected (to the extent then known), the likely consequences, and the measures taken or proposed to address the incident; (c) cooperate reasonably with affected Customers in connection with their own notification obligations to data subjects and regulators; (d) report the incident to supervisory authorities and other regulators as required by applicable law.

10. Your Rights

Depending on the jurisdiction where you are located, you may have rights regarding your personal information. This Section describes the principal rights available under the GDPR, UK GDPR, and the California Consumer Privacy Act (as amended by the California Privacy Rights Act, the "CCPA"). Residents of other jurisdictions may have similar or different rights under applicable local law.

10.1 Rights Under the GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights: (a) Right of access: request confirmation of whether we process personal information about you, and obtain a copy of that information. (b) Right to rectification: request correction of inaccurate personal information or completion of incomplete personal information. (c) Right to erasure ("right to be forgotten"): request deletion of your personal information in certain circumstances, including where the information is no longer necessary for the purposes for which it was collected, where you have withdrawn consent (and no other legal basis applies), or where the processing is unlawful. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims. (d) Right to restriction of processing: request that we restrict the processing of your personal information in certain circumstances.

(e) Right to data portability: receive personal information you have provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. This right applies where processing is based on consent or contract and is carried out by automated means. (f) Right to object: object, on grounds relating to your particular situation, to processing based on legitimate interests or the performance of a task in the public interest. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

(g) Right to object to direct marketing: object at any time to processing of your personal information for direct marketing purposes. Note: Antier does not use personal information for third-party marketing. (h) Rights related to automated decision-making: not be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you, except where permitted by law. Where applicable, you have the right to obtain human intervention, express your views, and contest the decision. (i) Right to withdraw consent: where processing is based on consent, withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

10.2 Rights Under the CCPA (California Residents)

If you are a California resident, you have the following rights under the CCPA: (a) Right to know: request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we disclose personal information. (b) Right to delete: request that we delete personal information we have collected about you, subject to exceptions including where retention is necessary to complete a transaction, detect security incidents, protect against fraud, comply with legal obligations, or for internal uses reasonably aligned with your expectations. (c) Right to correct: request correction of inaccurate personal information. (d) Right to opt-out of sale or sharing: opt out of any "sale" or "sharing" of personal information. Antier does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA. There is no need to opt out, but you have the right to confirm this. (e) Right to limit use of sensitive personal information: limit the use and disclosure of sensitive personal information to specific permitted purposes. Antier does not use sensitive personal information beyond permitted purposes. (f) Right to non-discrimination: not be discriminated against for exercising your privacy rights. (g) Right to access in a portable format: receive personal information in a portable format where technically feasible.

10.3 Rights in Other Jurisdictions

Residents of other jurisdictions, including (without limitation) Brazil (LGPD), Canada (PIPEDA), Singapore (PDPA), and various U.S. states with comprehensive privacy laws, may have similar or different privacy rights under applicable law. We will respond to rights requests in accordance with the law applicable to you.

10.4 How to Exercise Your Rights

To exercise any of the rights described in this Section 10, contact us at legal@antiersolutions.com. We may need to verify your identity before responding to certain requests to protect against unauthorized requests. The verification we conduct will be proportionate to the sensitivity of the information involved and the nature of the request. We will respond to your request within the timeframes required by applicable law (typically thirty (30) days under GDPR and forty-five (45) days under CCPA), with the possibility of extension in defined circumstances. If we are unable to fully honor a request, for example, because retention is required by law or because the request would adversely affect the rights of others we will explain the reason in our response. There is no fee for exercising your privacy rights, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse to act, as permitted by law).

11. Data Processing Addendum

Where Customer's use of the Services involves Antier processing personal data on Customer's behalf about Customer's own end customers, counterparties, or other data subjects, Antier acts as a data processor under the Data Processing Addendum ("DPA"). The DPA: (a) is incorporated into the Terms of Service by reference upon execution; (b) describes Antier's obligations as data processor under GDPR Article 28 and equivalent provisions of UK GDPR, CCPA, and other applicable data protection laws; (c) includes Standard Contractual Clauses adopted by the European Commission and the UK Addendum where applicable; (d) is available at [DPA URL].

12. Children's Privacy

The Services are designed for business use and are not directed to children. We do not knowingly collect personal information from individuals under the age of 16 (or such other age as required by applicable law in a specific jurisdiction). If we become aware that we have collected personal information from a child without appropriate authorization, we will take steps to delete that information promptly.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, applicable law, or for other operational, legal, or regulatory reasons. When we make material changes, we will: (a) notify Customers by email to the registered contact address or through the Services; (b) update the "Effective date" and "Last updated" dates at the top of this Privacy Policy; (c) where required by applicable law, obtain new consent for changes that materially affect the basis for processing.

Non-material changes (such as clarifications, corrections, and routine updates) take effect on publication. We encourage you to review this Privacy Policy periodically.

____________________________