Document contents
- 01Who processes your data
- 02The principle that governs the rest: do not collect
- 03Purposes and legal bases
- 04Retention periods and recipients
- 05Processors and partners
- 06Transfers outside the European Union
- 07Your rights, and their real limits
- 08How to exercise your rights
- 09Automated decisions
- 10Data security
- 11Cookies and trackers
- 12Minors
- 13Changes to this policy
Who processes your data
A conversion platform cannot run without identity data: anti-money-laundering rules require it from the first euro converted. The honest question is therefore not “do you collect data”, but which data, why, for how long, and who else sees it.
The controlling entity is being incorporated. Its legal name, legal form and registered address will be published on the legal notice page as soon as they are verifiable. In the meantime, the contact address below is the single entry point for any request about your data, and it is already live.
No data protection officer is appointed to date. Will one be? Yes: large-scale processing of identity data in a regulated setting makes the appointment necessary. Until it is effective we do not pretend otherwise, and requests are handled through the address below.
Privacy contact point
Use this address to exercise your rights, ask about a processing activity, or contest an automated decision. You get an answer within 30 days at most.
[email protected]The principle that governs the rest: do not collect
Every piece of data collected is data to protect, to retain, to delete at the right time and to hand back on request. The product is built to ask for as little as possible, as late as possible.
- Quoting is public: you get a net amount with the fee breakdown, with no account and no email address.
- Identity verification is asked for at the tier where it becomes mandatory, not at sign-up.
- No advertising tracker is set, and no browsing data is sold or shared for commercial purposes.
- Bank details are encrypted and stripped from application logs: they never appear in clear text in a log line.
Purposes and legal bases
Every processing activity rests on an identified legal basis. This is more than a formality: the basis determines which rights you hold. Data processed under a legal obligation cannot be erased on request while the mandated period runs; data processed under our legitimate interest can be objected to on reasoned grounds.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Compute a quote and display the fee breakdown | Chosen asset, amount, country and rail. No identifying data is required at this stage. | Legitimate interest — Article 6(1)(f) — Interest in showing a price before sign-up, which avoids collecting data from a visitor who will not go further. |
| Create and secure your account | Email address, phone number, password hash, second-factor keys, sign-in log and associated IP addresses. | Performance of the contract — Article 6(1)(b) — Without an authenticated account, no order can be tracked and no payout issued. |
| Verify your identity and meet due-diligence obligations | Names, date and place of birth, nationality, address, identity document image, liveness video capture, source-of-funds evidence, results of sanctions and politically exposed person screening. | Legal obligation — Article 6(1)(c) — Customer due-diligence obligations imposed on digital asset service providers. This data cannot be erased on request while the statutory period runs. |
| Execute the order and issue the payout | Assigned deposit address, transaction hashes, amounts, beneficiary details (IBAN, PIX key, mobile money number), status of each step. | Performance of the contract — Article 6(1)(b) — Beneficiary details are the material condition of payment: without them, the money has nowhere to go. |
| Monitor transactions and detect suspicious patterns | Order history, deposit address risk analytics, triggered alerts, analyst notes, reports filed. | Legal obligation — Article 6(1)(c) — Ongoing monitoring is a standalone obligation, separate from initial identity verification. |
| Answer your requests and handle your complaints | Message content, attachments, related order reference, exchange history. | Performance of the contract — Article 6(1)(b) — Handling a complaint is part of the service. The case is tracked to allow escalation. |
| Prevent fraud and technical abuse | IP address, device fingerprint, security events, rate limiting, failed authentication attempts. | Legitimate interest — Article 6(1)(f) — Interest in protecting customer accounts and funds from takeover and malicious automation. |
| Measure site audience | Page views, referrer, device type. No data is collected under this activity today: the category is declared but inactive. | Consent — Article 6(1)(a) — This processing will only start after explicit consent collected through the cookie panel, never before. |
Retention periods and recipients
We keep nothing “by default”. Each category has a period, a deletion trigger and an automatic purge at term.
| Purpose | Retention | Recipients | Transfer outside the EU |
|---|---|---|---|
| Compute a quote and display the fee breakdown | The quote is kept for 30 days in technical form to reconstruct a pricing dispute, then deleted. | Nobody outside the engineering team. | No |
| Create and secure your account | For the life of the account, then 12 months after closure to handle a late dispute. Sign-in logs are kept for 12 months. | Our hosting provider, our transactional email operator and our SMS operator. | No |
| Verify your identity and meet due-diligence obligations | Five years from the end of the business relationship, as required by anti-money-laundering rules. After that period, automatic deletion. | The identity verification provider, sanctions list vendors, and, upon formal request, the competent authorities. | Yes |
| Execute the order and issue the payout | Ten years, the accounting record retention period. Bank details are encrypted and stripped from application logs. | The payment institution executing the transfer on the chosen rail, and it alone. | Yes |
| Monitor transactions and detect suspicious patterns | Five years from the transaction or the closure of the alert. A suspicious activity report is never disclosed to you: the law forbids it. | The competent financial intelligence unit, strictly within the framework provided by law. | No |
| Answer your requests and handle your complaints | Three years after case closure, or five years where the complaint touches compliance. | Our support tool, hosted in the European Union. | No |
| Prevent fraud and technical abuse | Twelve months for security logs, six months for rate-limiting counters. | Our hosting provider and our network protection vendor. | No |
| Measure site audience | Thirteen months maximum from the collection of consent, with no automatic extension. | None to date, the category being inactive. | No |
Processors and partners
We rely on processors for hosting, transactional email and SMS delivery, identity verification, deposit address risk analytics and payment execution. Each acts on documented instructions, under a contract compliant with Article 28 GDPR.
The named list of these processors is not published while the contracts are unsigned. We prefer an accurate category to a vendor name displayed to look established: publishing the name of a partner with whom nothing is contracted would be a false statement, and that is exactly what this site refuses to do.
The list will be published here, name by name, role by role, with the location of processing, as soon as the service goes live. Any later addition will trigger a version update of this document.
Transfers outside the European Union
Two activities structurally involve a transfer outside the Union: identity verification, whose vendors often operate from the United Kingdom or the United States, and payout execution on local rails outside Europe — PIX in Brazil, M-Pesa in Kenya, NIP in Nigeria. Sending money to Kenya means passing the beneficiary’s name and number to a Kenyan institution: that is the material condition of the payment.
What frames those transfers
- An adequacy decision of the European Commission where one exists for the country concerned.
- Failing that, the Commission’s standard contractual clauses, together with a transfer impact assessment taking local government access law into account.
- Additional technical measures: minimising the fields transmitted, encryption in transit and at rest, per-corridor segregation.
- No transfer of convenience: if a purpose can be served from inside the Union, it is.
You may request a copy of the safeguards applying to a specific transfer. We then provide the mechanism used and the destination country, without the commercial clauses of the contract.
Your rights, and their real limits
A privacy policy that lists seven rights without saying which one hits which wall helps nobody. Here are the rights and, for each, the limit that actually applies in our context.
- Right of access
- Obtain confirmation that we process your data, receive a copy of it and the information on purposes, recipients and retention periods.
- Right to rectification
- Have inaccurate data corrected or incomplete data completed. An already verified identity is not corrected by mere declaration: the fix goes through a new document verification.
- Right to erasure
- Request deletion of your data when its retention is no longer justified. Anti-money-laundering and accounting records cannot be erased before the end of their statutory period. We then give you the exact date on which deletion will happen.
- Right to restriction
- Request that a processing activity be frozen while a dispute is resolved.
- Right to portability
- Receive the data you provided in a structured, machine-readable format, or have it transmitted directly to another controller.
- Right to object
- Object to processing based on our legitimate interest, on grounds relating to your particular situation. Objection does not apply to processing imposed by law, notably anti-money-laundering diligence.
- Automated decision-making
- Obtain human intervention, express your point of view and contest a decision taken without human involvement. An automated compliance refusal can always be re-examined by an analyst on request.
- Withdrawal of consent
- Withdraw consent at any time, without affecting the lawfulness of processing already carried out.
How to exercise your rights
- Write to the privacy contact address from the email address linked to your account, or from your account area.
- We verify your identity. Where reasonable doubt exists we ask for one additional verification element — never a fresh copy of an identity document if we already hold a valid one.
- We answer within 30 days. Where the request is complex or multiple, that period may be extended by 2 months, and we tell you with the reason before the initial deadline.
- The answer is free. A manifestly unfounded or repetitive request may lead to a reasoned refusal, never to a silent charge.
If our answer does not satisfy you, you may lodge a complaint with the supervisory authority of your country of residence. That route is open unconditionally and without having to tell us first.
Exercise a right
State the right you invoke and, if possible, the related order reference. That avoids a qualification round trip and shortens handling.
[email protected]Automated decisions
Three checks are automated and can have a direct effect on you: matching your name against sanctions lists, document-based identity verification, and deposit address risk analytics. A match or a failure can suspend an order with no prior human involvement.
You can always ask for a human review. An analyst then reopens the file, you can put your case, and the initial decision can be reversed. The only situation where the detailed reason cannot be shared with you is a reported suspicion: the law then forbids us from discussing it.
Data security
Encryption in transit and at rest, environment segregation, least-privilege access, logging of every access to a verification file, mandatory second factor for internal access. The technical measures are described in detail on the dedicated page.
In the event of a personal data breach likely to create a risk to your rights, we notify the supervisory authority within 72 hours and inform you directly where the risk is high. We also publish a post-incident note, even where individual notification is not required.
Minors
The service is not intended for minors and identity verification checks the date of birth. If we find that an account was opened by a minor, it is closed and the associated data deleted, subject to the records regulation requires us to keep.
Changes to this policy
Any substantive change — a new purpose, a new recipient, a new transfer outside the Union — gets a new version number, an entry in the history at the foot of this page, and direct notice if you hold an account. We do not change a purpose silently.
Version history
| Version | Last updated | Nature of the change |
|---|---|---|
| 1.0.0 | 2 September 2026 | First publication of the document. |
Stable anchors: every section carries an identifier that will not change. You can cite a clause by its direct link.