We are building a financial institution meant to last, and security sits at the center of that ambition. Sustained investment in security engineering, monitoring, and compliance is what lets businesses rely on us with confidence.
The regulatory framework Nexpay operates under, grouped by source. Expand any item for detail on how the requirement applies to our services.
Nexpay operates in accordance with key European Union regulations that govern data protection, operational resilience, payment services, and financial crime prevention, ensuring a consistent compliance framework across the EU.
Nexpay complies with applicable national legislation in the jurisdictions where it operates or provides regulated services.
Nexpay follows established European payment scheme rules to ensure secure, reliable, and interoperable payment processing.
Nexpay maintains a comprehensive sanctions compliance framework to prevent prohibited transactions and mitigate financial crime risks.
Third parties engaged in the delivery of our services, each governed by contractual data protection and security obligations.
Provides secure cloud infrastructure and data hosting services for Nexpay’s core systems and applications.
Delivers network security, web application firewall, and content delivery services to protect and optimise Nexpay’s online platforms.
Supports transaction monitoring, AML screening, and risk assessment to help detect and prevent financial crime.
Provides digital identity verification and customer due diligence solutions, including document and biometric checks.
Enables SCA and secure access to payment and account information services.
Supplies global sanctions, PEP, and adverse media screening data to support compliance and risk management processes.
A provider facilitating secure blockchain transaction messaging and Travel Rule data exchange between VASPs.
Scans files uploaded to Nexpay systems for malicious content before they are processed or stored.
Subprocessors are listed by category rather than by name. Contractual confidentiality obligations prevent us from publicly disclosing the identity of individual providers. The full, named list is available to clients, prospective clients, and counterparties on request: write to [email protected].
Encryption in transit
Data locking at rest
Platform uptime
Nexpay protects the availability, authenticity, integrity and confidentiality of the information and ICT systems entrusted to it by clients, partners and staff.
We operate an information security management system (ISMS) aligned with the NIST Cybersecurity Framework and designed to meet the Digital Operational Resilience Act (Regulation (EU) 2022/2554), its regulatory technical standards, and the requirements of the Bank of Lithuania.
Ownership of ICT risk sits with the Management Board, with independent oversight and audit.
The Management Board bears ultimate responsibility for ICT risk, approves the security policy and digital operational resilience strategy, allocates the resources needed to implement them, and receives an annual security posture report.
A dedicated Chief Information Security Officer oversees the ISMS, and control and audit functions are organised on the three-lines-of-defence model.
The information security policy is binding on all staff, contractors and ICT service providers, and is reviewed at least annually and after any major incident, significant audit finding or supervisory instruction.
Ten control domains make up the ISMS. Each is documented, assigned an owner, and reviewed on a defined cycle.
Security incidents are handled under a documented incident management plan with defined severity levels and response times. Incidents classified as major under DORA are reported to the competent authority within the regulatory deadlines, and affected clients are informed where required by law or by our agreements with them.
Compliance with DORA, GDPR (overseen by our Data Protection Officer) and applicable Bank of Lithuania requirements is assessed and documented at least annually.
If you believe you have found a security vulnerability or incident affecting Nexpay systems, please contact us at [email protected]. We ask that you do not access, modify or disclose data beyond what is needed to demonstrate the issue.
The company only collects personal details that are strictly necessary to fulfill legal duties and provide its financial services.
Employee access to your personal information is strictly restricted to personnel handling compliance, identity verification, fraud prevention, and customer support.
External service providers and database partners are evaluated to ensure they maintain compatible data security standards before data sharing occurs.
Because the platform operates as a regulated electronic money institution under Lithuanian law, statutory AML and CTF mandates serve as the baseline for data tracking and retention.
Under this framework, clients are granted specific rights to manage and audit their personal data, though certain financial compliance laws may restrict their immediate execution.
You can request a clear, comprehensive copy of all personal data stored about you by the company.
You can demand your automated, contract-based data be provided in a structured, machine-readable format to move to another controller.
You can instantly update basic contact info via your dashboard, or modify restricted records (like legal name or financial details) by contacting [email protected].
You can contest data processing justified by “legitimate interests” or completely block the use of your data for direct marketing.
You can ask the company to temporarily freeze the processing of your data, though doing so may pause your ability to use the services.
You may request the deletion of your data when there is no logical reason for its processing. However, statutory Lithuanian compliance laws supersede this right, legally forcing the company to retain identification/verification data for eight years and transaction histories for five years post-account closure.
Frequently asked questions on the personal data we handle, how it is protected, and the rights available to data subjects.