> ## Documentation Index
> Fetch the complete documentation index at: https://docs.olympex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy notice

> How Olympex handles data when you use the API.

This notice summarizes Olympex's data handling for API customers. Your Master Services Agreement and Data Processing Addendum govern legally binding obligations.

## What we collect

| Data | Source | Purpose |
| - | - | - |
| Account credentials: the API key ID, the account name, an argon2id hash of the passphrase and an AES-256-GCM-encrypted copy of the secret key | At account creation (`POST /accounts`). | Authentication and account deactivation. |
| Request metadata (endpoint, timestamp, status) | At call time. | Operations, security monitoring, abuse prevention. |
| Swap data (chain, token and wallet addresses, amounts, tx hash) | From `POST /quotes`, `POST /swap` and `POST /tx-status` requests, and on-chain data. | Routing, analytics and support. |

We do not collect end-user email addresses, real names, government IDs, or browsing history through the API. If you transmit personal data through API request fields, you must have a lawful basis under applicable privacy law and you remain the data controller for that data.

## How we use it

* **Operating the service.** Routing, analytics, abuse detection.
* **Customer support.** Diagnosing issues you raise through your support channel.
* **Legal compliance.** Responding to lawful requests, sanctions screening of API customers.

We do not sell data. We do not share data with third parties for advertising.

## Sub-processors

Olympex relies on the following infrastructure providers as sub-processors:

| Sub-processor | Purpose | Region |
| - | - | - |
| Amazon Web Services | Cloud hosting, compute, and storage. | US |
| CoinGecko | Token price reference (read-only). | Global |
| OKX, 1inch, OpenOcean, 0x, Symbiosis, Rango, LiFi | Quotes, swap calldata and cross-chain routing. They receive the chain, token addresses and amounts of a request, and the wallet `account` of a `POST /swap` request. | Global |

A current list with regions and service descriptions is available under your DPA.

## Retention

For the retention periods of request metadata, swap data and account credentials, contact [partners@olympex.io](mailto:partners@olympex.io).

## International transfers

The API runs on Amazon Web Services in the `us-east-1` region, in the United States. For where stored data resides and the terms that cover international transfers, contact [partners@olympex.io](mailto:partners@olympex.io).

## Your rights

If you are an EU/UK customer, you have rights to access, correct, delete, and port your data, subject to operational limits.

Exercise rights by writing to [privacy@olympex.io](mailto:privacy@olympex.io).

## Security

Encryption in transit (TLS 1.2 or higher). Encryption at rest. Passphrases are stored as an argon2id hash and secret keys are encrypted with AES-256-GCM. For questions about audits and penetration testing, contact [partners@olympex.io](mailto:partners@olympex.io). [Security model](/concepts/security-model) covers the technical posture.

## Changes to this notice

Material changes are announced on this page. Continued use after the effective date constitutes acceptance.

## Contact

[privacy@olympex.io](mailto:privacy@olympex.io) for privacy questions.
[legal@olympex.io](mailto:legal@olympex.io) for commercial terms.
[partners@olympex.io](mailto:partners@olympex.io) for security disclosures.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.