Electronic Money Institution · Lithuania

Security Is Our Highest Investment

We are building a financial institution meant to last, and security sits at the center of that ambition. Sustained investment in security engineering, monitoring, and compliance is what lets businesses rely on us with confidence.

EMI Licence
ACTIVE
Licence number
No. 18
Issuing authority
Bank of Lithuania
Legal entity
UAB Nexpay — reg. code 304708124
View on the Bank of Lithuania register →
01Regulatory framework

Compliance

The regulatory framework Nexpay operates under, grouped by source. Expand any item for detail on how the requirement applies to our services.

European regulation

Nexpay operates in accordance with key European Union regulations that govern data protection, operational resilience, payment services, and financial crime prevention, ensuring a consistent compliance framework across the EU.

National laws

Nexpay complies with applicable national legislation in the jurisdictions where it operates or provides regulated services.

Payment processing standards

Nexpay follows established European payment scheme rules to ensure secure, reliable, and interoperable payment processing.

Sanctions compliance

Nexpay maintains a comprehensive sanctions compliance framework to prevent prohibited transactions and mitigate financial crime risks.

02Data processing partners

Subprocessors

Third parties engaged in the delivery of our services, each governed by contractual data protection and security obligations.

01
Cloud

Provides secure cloud infrastructure and data hosting services for Nexpay’s core systems and applications.

02
Cybersecurity

Delivers network security, web application firewall, and content delivery services to protect and optimise Nexpay’s online platforms.

03
AML

Supports transaction monitoring, AML screening, and risk assessment to help detect and prevent financial crime.

04
Identity verification

Provides digital identity verification and customer due diligence solutions, including document and biometric checks.

05
Strong customer authentication

Enables SCA and secure access to payment and account information services.

06
Sanctions screening

Supplies global sanctions, PEP, and adverse media screening data to support compliance and risk management processes.

07
Travel rule

A provider facilitating secure blockchain transaction messaging and Travel Rule data exchange between VASPs.

08
Security sandbox

Scans files uploaded to Nexpay systems for malicious content before they are processed or stored.

*

Subprocessors are listed by category rather than by name. Contractual confidentiality obligations prevent us from publicly disclosing the identity of individual providers. The full, named list is available to clients, prospective clients, and counterparties on request: write to [email protected].

TLS 1.3+

Encryption in transit

AES-256

Data locking at rest

99.9%

Platform uptime

03Information security statement

Our commitment

Nexpay protects the availability, authenticity, integrity and confidentiality of the information and ICT systems entrusted to it by clients, partners and staff.

We operate an information security management system (ISMS) aligned with the NIST Cybersecurity Framework and designed to meet the Digital Operational Resilience Act (Regulation (EU) 2022/2554), its regulatory technical standards, and the requirements of the Bank of Lithuania.

Framework
NIST Cybersecurity Framework
ISMS design baseline
DORA — Regulation (EU) 2022/2554
Including regulatory technical standards
Bank of Lithuania requirements
Supervisory expectations for EMIs

Governance and accountability

Ownership of ICT risk sits with the Management Board, with independent oversight and audit.

The Management Board bears ultimate responsibility for ICT risk, approves the security policy and digital operational resilience strategy, allocates the resources needed to implement them, and receives an annual security posture report.

A dedicated Chief Information Security Officer oversees the ISMS, and control and audit functions are organised on the three-lines-of-defence model.

The information security policy is binding on all staff, contractors and ICT service providers, and is reviewed at least annually and after any major incident, significant audit finding or supervisory instruction.

How we protect information

Ten control domains make up the ISMS. Each is documented, assigned an owner, and reviewed on a defined cycle.

  • 01
    Risk management
    ICT risk is identified, assessed and treated on a continuous basis. The Management Board sets the Company’s risk and impact tolerance levels and approves the digital operational resilience strategy.
  • 02
    Identity and access control
    Access to systems and information is granted on a need-to-know and least-privilege basis, uses strong authentication, and is reviewed regularly. The same rules apply to third parties.
  • 03
    Encryption
    Sensitive information is encrypted in storage and in transmission, and cryptographic keys are protected throughout their lifecycle.
  • 04
    Secure development and change
    Security requirements are built into projects, system acquisition and software development. All changes to production systems are planned, tested and approved before release.
  • 05
    Monitoring and threat intelligence
    Systems are monitored continuously to detect anomalous activity and performance issues, and threat intelligence is used to keep controls aligned with emerging threats.
  • 06
    Vulnerability management and testing
    Vulnerabilities are identified, prioritised and remediated according to defined timelines. Critical systems are tested at least annually by independent parties; threat-led penetration testing is performed where required by our regulator.
  • 07
    Third-party security
    ICT service providers are assessed before onboarding, bound by contractual security obligations, and monitored throughout the relationship. Providers supporting critical functions are reassessed at least annually.
  • 08
    Business continuity and recovery
    Business continuity and disaster recovery plans cover all critical functions and systems, are supported by regular backups, and are tested at least annually.
  • 09
    People
    Staff undergo background verification proportionate to their role, sign confidentiality and security obligations, and complete mandatory security awareness training every year, including senior management and the Board.
  • 10
    Physical security
    Physical access to offices and data-centre facilities is restricted to authorised persons; environmental protection at hosting facilities is assured through provider due diligence and contractual requirements.

Incident management

Security incidents are handled under a documented incident management plan with defined severity levels and response times. Incidents classified as major under DORA are reported to the competent authority within the regulatory deadlines, and affected clients are informed where required by law or by our agreements with them.

Compliance and assurance

Compliance with DORA, GDPR (overseen by our Data Protection Officer) and applicable Bank of Lithuania requirements is assessed and documented at least annually.

Reporting a security concern

If you believe you have found a security vulnerability or incident affecting Nexpay systems, please contact us at [email protected]. We ask that you do not access, modify or disclose data beyond what is needed to demonstrate the issue.

04Privacy policy

Privacy overview

Read the full privacy policy →
Data privacy is managed through operational principles that limit what we collect, who can reach it, and how long statutory duties require us to keep it.
01
Data minimisation

The company only collects personal details that are strictly necessary to fulfill legal duties and provide its financial services.

02
Least privilege internal access

Employee access to your personal information is strictly restricted to personnel handling compliance, identity verification, fraud prevention, and customer support.

03
Pre-onboarding third-party assessments

External service providers and database partners are evaluated to ensure they maintain compatible data security standards before data sharing occurs.

04
Regulatory overrides

Because the platform operates as a regulated electronic money institution under Lithuanian law, statutory AML and CTF mandates serve as the baseline for data tracking and retention.

Your rights over your data

Under this framework, clients are granted specific rights to manage and audit their personal data, though certain financial compliance laws may restrict their immediate execution.

Right of access

You can request a clear, comprehensive copy of all personal data stored about you by the company.

Right to data portability

You can demand your automated, contract-based data be provided in a structured, machine-readable format to move to another controller.

Right to rectification

You can instantly update basic contact info via your dashboard, or modify restricted records (like legal name or financial details) by contacting [email protected].

Right to object

You can contest data processing justified by “legitimate interests” or completely block the use of your data for direct marketing.

Right to restriction

You can ask the company to temporarily freeze the processing of your data, though doing so may pause your ability to use the services.

Right to erasure (conditional)

You may request the deletion of your data when there is no logical reason for its processing. However, statutory Lithuanian compliance laws supersede this right, legally forcing the company to retain identification/verification data for eight years and transaction histories for five years post-account closure.

05Questions we get asked

FAQ

Frequently asked questions on the personal data we handle, how it is protected, and the rights available to data subjects.