Privacy Policy

Effective Date: 28 March 2026

Last Updated: 28 March 2026

This Privacy Policy explains how JamBase LDA ("JamBase", "we", "our", or "us") collects, uses, stores, and protects personal data in connection with SendsHub, our software-as-a-service platform and related website, applications, APIs, and services (collectively, the "Services").

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

1. Company Information

JamBase LDA
Portugal
Product name: SendsHub
For privacy-related inquiries, please contact:
legal@jambase.eu

2. Scope of This Policy

This Privacy Policy applies to:

  • our website
  • web application
  • mobile applications
  • API services
  • customer support communications
  • business onboarding and account management
  • security and audit logs

This Privacy Policy does not govern third-party services, blockchain networks, banks, payment institutions, custodians, or third-party integrations used by our customers.

3. Our Role

JamBase provides technical software infrastructure and SaaS tools for business customers.
We are not:

  • a bank
  • a payment institution
  • an exchange
  • a broker
  • a financial advisor
  • a custodian regulated financial service provider

Customers independently determine how they use the Services and remain solely responsible for ensuring their activities comply with applicable laws, licensing, and regulatory obligations.
In many cases, JamBase acts as a data processor / service provider, while the customer acts as the data controller.

4. Information We Collect

We may collect the following categories of information:

4.1 Account and Identity Data

  • full name
  • company name
  • job title
  • business email address
  • phone number
  • username
  • authentication credentials
  • MFA / 2FA data
  • device identifiers

4.1 Account and Identity Data

  • Information created and stored by customers while using the platform, including:
  • workspaces
  • vaults
  • wallets
  • transaction metadata
  • blockchain addresses
  • user roles and permissions
  • approval workflows
  • access rights
  • audit trails
  • API keys
  • webhook configurations

4.3 Technical and Usage Data

  • IP address
  • browser type
  • device information
  • operating system
  • session identifiers
  • login timestamps
  • access logs
  • crash reports
  • performance metrics
  • error logs

4.4 Support and Communication Data

  • messages sent to support
  • ticket history
  • onboarding communications
  • business correspondence

5. Sensitive Financial Data Disclaimer

SendsHub is designed as a technical infrastructure platform.
Any wallets, transactions, addresses, or blockchain-related data processed within the platform are stored as operational metadata required for service functionality.
Customers remain solely responsible for the legality and compliance of assets, transfers, and transactions initiated through their own use of the Services.

6. How We Use Data

We use personal data to:

  • provide and maintain the Services
  • authenticate users
  • manage permissions and access controls
  • enable workspaces and vault operations
  • process user requests
  • provide technical support
  • improve platform security
  • detect fraud, abuse, and unauthorized access
  • maintain audit and compliance logs
  • communicate service updates
  • enforce our Terms of Use
  • comply with legal obligations

7. Legal Basis (GDPR)

If GDPR applies, we process personal data under one or more of the following legal bases:

  • performance of a contract
  • legitimate interests
  • legal obligation
  • consent, where required
  • protection of security and fraud prevention

8. Data Retention

We retain data only for as long as necessary for:

  • active service provision
  • customer support
  • legal compliance
  • dispute resolution
  • security investigations
  • audit and logging requirements

Security and audit logs may be retained for extended periods where necessary for compliance and incident investigation.

9. Sharing of Data

We may share data only with:

  • cloud hosting providers
  • infrastructure and monitoring providers
  • authentication providers
  • customer-authorized integrations
  • legal and regulatory authorities when required by law

Examples may include services provided by Amazon Web Services, Google, or similar infrastructure providers. We do not sell personal data to advertisers or data brokers.

10. International Transfers

Data may be processed in jurisdictions outside the user's country, including the European Union and other countries where our infrastructure providers operate.
Where required, we use appropriate contractual safeguards, including Standard Contractual Clauses.

11. Security Measures

We implement appropriate technical and organizational safeguards, including:

  • encryption in transit
  • encryption at rest
  • access controls
  • role-based permissions
  • audit logging
  • MFA support
  • network segmentation
  • infrastructure monitoring
  • incident response procedures

However, no system can be guaranteed 100% secure.

12. Customer Responsibilities

Customers are responsible for:

  • managing internal user access
  • assigning roles and permissions
  • securing administrator accounts
  • complying with licensing requirements
  • ensuring lawful use of the Services
  • managing their own regulatory obligations

The initial administrative user designated by the customer may create and manage additional users and permissions.

13. Cookies and Analytics

We may use cookies and similar technologies for:

  • authentication
  • session management
  • security
  • analytics
  • performance monitoring

Where legally required, we will request consent.

14. User Rights

Subject to applicable law, individuals may have the right to:

  • access their data
  • correct inaccurate data
  • request deletion
  • restrict processing
  • object to processing
  • request portability
  • withdraw consent
Requests may be submitted to:
legal@jambase.eu

15. Data Processed on Customer Instructions

Where JamBase processes data on behalf of business customers, such processing is performed strictly under customer instructions and contractual agreements.
Customers are responsible for providing their own privacy notices to their end users where required.

16. Children's Privacy

The Services are intended for business and enterprise use only and are not directed to children.

17. Changes to This Policy

We may update this Privacy Policy from time to time.
Updated versions will be published on the website with a revised effective date.

18. Contact

For privacy or data protection inquiries:
JamBase LDA
legal@jambase.eu