Skip to main content

Draft — not in force

This document is a working draft. It has not been reviewed by counsel and does not yet bind either party. It is published here so that the structure and the substantive restrictions can be reviewed, not so that it can be relied upon.

Privacy notice

Version 0.2-draft · P2P Broker

1. Who is responsible for your data

Paxa Media j.d.o.o., an IT company, of Rijeka, Croatia, develops and maintains this website and is the controller of the personal data described here. You can contact us about data protection — access, correction, erasure or a complaint — at lukar@paxa.media.
Because the controller is established in the European Union, the General Data Protection Regulation applies to this processing in full. That is true regardless of where you live.

two individuals appointed under our AML/CFT policy carry out the identity checks described below and decide whether to make an introduction. They receive your details from the platform for that purpose.

2. What we collect, and when

When you create an account we collect your email address, a password (which we store only as a slow one-way hash and cannot read), your declared country of residence, and your confirmation that you are not resident in the EU or EEA. We record the date and time, your IP address, your browser’s user agent string, and the country our systems observed for your connection.

When you make an exchange request we collect your full name, a telephone number if you give one, the direction, asset, settlement method and indicative amount, your stated purpose in your own words, how you heard about us, and any referrer.

Neither form collects identity documents, and you should not send them to us by email or messaging application. Identity verification happens separately, through our verification provider, over a secure link.

3. Why we collect it, and on what basis

We use this information to assess whether we are able to work with you, to carry out the customer due diligence and screening described in our AML statement, to introduce you to a verified counterparty if we proceed, and to keep the records we are required to keep.

Our bases for processing are: taking steps at your request before entering into a contract; compliance with legal obligations relating to the prevention of money laundering and terrorist financing; and our legitimate interest in operating the business and protecting it and our clients from fraud and financial crime.

4. Who we share it with

  • Our identity verification provider, which processes your identity documents and liveness check on our behalf.
  • Screening and blockchain analytics providers, for sanctions, politically exposed person, adverse media and wallet checks.
  • Supervisory authorities, the financial intelligence unit and law enforcement, where we are required to report or to respond to a lawful request.
  • Our banks and professional advisers, where necessary.

We do not sell your data and we do not use it for advertising.

5. How long we keep it

Five years from the end of our relationship with you, or from your enquiry where no relationship follows. This period is set by anti-money-laundering law and we are not able to shorten it on request. Records are encrypted, access is limited to named individuals, and every access is logged.

6. Your rights

Under the GDPR you have rights to access your data, to have inaccurate data corrected, to have it erased where we are not required to keep it, to object to or restrict certain processing, and to receive it in a portable form. You can complain to the Croatian Personal Data Protection Agency (AZOP), which is our lead supervisory authority, or to the authority where you live.

There are two limits on these rights that we would rather tell you about now than at the moment you exercise them. First, we cannot delete records we are legally required to retain, even if you ask us to and even if we never worked together. Second, where the law prohibits us from disclosing that a report concerning you has been made or is contemplated, we are not permitted to confirm or deny it in response to a request for access, and we may be obliged to withhold information without explaining that we have done so.

7. Where your data is held

Your data is stored in the European Union, in a managed PostgreSQL database hosted in Frankfurt, Germany. The hosting provider processes it on our instructions only and has no other use for it.

Outstanding: name the hosting and application providers explicitly, and confirm the transfer position where a provider is US-controlled even though the data sits in the EU. See compliance/hosting-and-data-residency.md.

8. Cookies

This site sets no advertising or analytics cookies and includes no third-party trackers. The cookies we do set are all necessary for the service to work, and none of them requires consent:

  • your chosen language;
  • the direction, asset and amount you entered on the calculator, so they carry over when you continue;
  • your sign-in session, if you have an account — this one identifies you and is deleted when you sign out;
  • briefly, the reference number of a request you have just made, so it can be shown to you once.

9. Changes

We record which version of this notice was in force when you sent your enquiry, so that we can tell you what you were told at the time.