How we operate, protect your data, and secure our platforms. Last updated 10 July 2026.
Effective 10 July 2026
These Terms of Service ("Terms") govern your access to and use of the platforms, APIs and services provided by Bullion Technology Solutions Limited ("Bullion", "we", "us"), including BullionPlus and Bullion Messaging Suite (together, the "Services"). By accessing the Services you agree to these Terms.
You must register an account to use the Services and provide accurate, complete information. You are responsible for safeguarding your credentials and for all activity under your account. You must be legally able to enter into these Terms in your jurisdiction.
You agree not to use the Services to transmit unlawful, fraudulent or unsolicited content, to infringe others' rights, or to circumvent routing, rating or security controls. We may suspend accounts that violate these Terms or applicable law, or that threaten platform integrity.
We target high availability but do not guarantee uninterrupted Service except where a written SLA applies. We may modify or discontinue features with reasonable notice.
The Services, software and brand assets are owned by Bullion. We grant you a limited, non-exclusive, non-transferable licence to use them solely as permitted by these Terms.
To the maximum extent permitted by law, Bullion is not liable for indirect, incidental or consequential damages. Our aggregate liability is limited to the fees you paid in the three months preceding the claim.
We may update these Terms; material changes will be notified in-product or by email. Continued use after changes constitutes acceptance.
Effective 10 July 2026 · GDPR & NDPR compliant
This Privacy Policy explains how Bullion collects, uses and protects personal data when you use our Services or interact with us.
We process data to provide and secure the Services, route and settle transactions, prevent fraud, comply with legal obligations, and improve our products. We do not sell your personal data.
We rely on contract performance, legitimate interests, consent (where required) and legal obligation as lawful bases under GDPR, NDPR and equivalent frameworks.
We share data only with vetted operators, carriers, billers and infrastructure providers necessary to deliver the Services, each bound by data-protection obligations.
We retain data for as long as needed to provide the Services and meet legal, tax and regulatory requirements, then securely delete or anonymise it.
ISO 27001 · PCI-DSS · SOC 2 (in progress)
Security is foundational to everything we build. We protect customer data and funds with layered, independently-audited controls.
All data is encrypted in transit (TLS 1.2+) and at rest. Secrets and keys are managed in a dedicated key-management system with strict access controls.
We run active-active, redundant infrastructure with automated failover, continuous monitoring and a 24/7 network operations centre.
We maintain PCI-DSS and ISO 27001 certification, undergo regular third-party penetration testing, and keep immutable audit logs across the platform.
Found a vulnerability? Report it to customersupport@bullion-plus.com. We investigate all reports and appreciate coordinated disclosure.