Skip to content
Sign inCreate accountGo to my account

Menu

Create accountGo to my accountEspañol

Privacy policy

Version 6 ·

What changes in this version: The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.

In this policy, PITIKLINI SOLUTION SL ("Pitiklini", "we", "us" or "our") explains what personal data we process and what rights you have over it. The policy applies when you visit the pitiklini.com website or use the Pitiklini app (together, the "Platform"), write to us, file a complaint or report an ad. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

The custody, purchase and sale, exchange and transfer of crypto-assets, and the associated payments in euros (the "Crypto-Asset Services") are provided by DEPASIFY S.L. (the "Provider"), an entity subject to Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA). We provide the technology platform: we develop and maintain the website and the app, manage your user account on the Platform (your "Account"), host and moderate P2P ads and provide user support.

Basic information on data protection

The table below summarises the essentials. Each item is explained in detail in the sections that follow.

Who is the controller of your data?

The controller of your Account data and of the Platform is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For any matter relating to your data, you can write to soporte@pitiklini.com.

We have not appointed a data protection officer, because the law does not require us to do so.

Who processes your data in the Crypto-Asset Services?

The Provider verifies your identity and provides you with the Crypto-Asset Services. For these purposes, and to comply with anti-money laundering rules, it processes your personal data on its own account, as a controller, under its own privacy policy. If you cannot find that policy, you can ask us for it at soporte@pitiklini.com and we will send it to you.

  • Identity verification: you provide your documents and the image of your face directly on the verification screen that it shows you. They do not pass through our servers and we do not keep them.
  • Data we send to it: your Account identifier, your email address when it needs to open an account for you, and the instructions for your deposits, withdrawals and payments, with your home address when you withdraw euros.
  • Data it sends to us: whether your identity is verified and since when, your name as it appears on your identity document and, if it has it, your home address, the identifiers of your account with it, your deposit addresses, your balances and movements (to check that they match ours), the status of your payments and withdrawals and, for each deposit of euros, the source account and its holder. We inform you of this because we do not obtain this data from you (GDPR, Article 14).
  • Complaints about the Crypto-Asset Services: it resolves them. If you send them to us, we will pass them on to it.

What personal data do we process and how do we obtain it?

If you only visit the website, without an Account: the IP address and the technical details your browser sends with each request (the page requested, the date and time, the browser and system, and the referring page), which our server logs. With those logs, and with the IP address truncated, we produce aggregate statistics of visits. If a page fails, a technical error report is also sent. The website sets no cookies and runs no analytics tool in your browser. What it stores in your browser is set out in the Cookie policy.

If you open an Account:

  • your email address and your password, which is stored as an irreversible summary (a hash) and never in plain text;
  • the code you use to confirm your email address;
  • your nickname, the name other people see you by in P2P and in transfers, and your Pitiklini ID, a short identifier of your Account. The nickname is random when the Account is created and you can change it in the app; the one you leave is reserved for a time so that nobody else uses it;
  • your language and your preferences;
  • your anti-phishing code, if you choose one, which we include in our emails so that you can recognise them;
  • your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.

To protect your Account:

  • if you use two-step verification, the secret of your authenticator app;
  • if you register passkeys, the public part of each one, its name, the password manager or service that stores it, whether it is synced across your devices and when it was created and last used. Your fingerprint or your face never leaves your device, which is what checks them;
  • your open sessions;
  • your login history, with the IP address, browser, operating system and approximate country deduced from the IP address;
  • the browsers you have logged in from, to alert you when someone logs in to your Account from a new one: a random identifier stored in a cookie in your browser, of which we only keep a fingerprint, together with the browser and system (for example, "Chrome (Windows 10.0)") and the dates of the first and last login.

The security alerts we send you include those details.

Your activity on the Platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.

If you send crypto-assets to an external address: the address, the network, the name you give it and whose it is: yours or another person's or company's (in that case, their name, which we store encrypted). If it is an account on another platform, the name of that platform. If you prove that a wallet is yours, the signed message and the signature. Regulation (EU) 2023/1113 (Article 14) requires this information to be known for each transfer of crypto-assets, and we keep it in your address book so as not to ask you for it every time.

If you send crypto-assets to another person on Pitiklini: who you send them to, whom you identify by their email address, their nickname, their Pitiklini ID or their deposit address; the amount; the reference, if you write one; and the names of both people, which we store encrypted for the same reason.

If you withdraw euros: your home address (country, postcode, city and street), which the Provider requires to send the payment and which we store encrypted (we take it from your identity verification if the Provider has it, and you confirm or enter it), and the bank accounts in your name from which you have added euros, which are the only ones you can withdraw them to.

In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.

If you write to us or make a complaint: what you tell us and the details we need to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.

If you report an ad: your name, your email address and what you tell us. We store them encrypted.

If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.

Error reports and server performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, and with which browser and system. The report does not include your name or your email address, and Sentry, which receives the IP address it is sent from, is configured not to store it. Our server also sends, for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or the content of what you send. We do not record the screen or measure performance in your browser.

Other people's data you give us: if you complain on someone else's behalf, give us someone else's details in a dispute or tell us the name of the holder of an address that is not yours, you must make sure that you are authorised to do so and that you inform that person.

What data about you do other people see?

  • Your P2P profile is public: your ads show anyone, even without an Account, your nickname, whether you have verified your identity, the month you joined, how many trades you have completed (in total and in the last 30 days), the percentage you have completed, your average payment and release times and your ratings. Your Pitiklini ID is not shown.
  • In a P2P trade, the other party sees your verified name and, if you are selling, the payment account into which they must pay you. This is what is needed for the payment to reach the right person.
  • If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
  • In a transfer between people on Pitiklini, each one sees the other's nickname and the reference of the transfer and, on the receipt, also their Pitiklini ID; never their name or their email address. Anyone who knows your email address, your nickname or your Pitiklini ID can send you crypto-assets and, before confirming, will see your nickname and your Pitiklini ID. If they send to your deposit address, they see nothing about you before confirming; once the transfer is done, they will see your nickname and your ID on the receipt.
  • If you report an ad, the person who posted it does not see your name or your email address, unless this is strictly necessary to explain the decision to them (Digital Services Act, Article 17).

If you want to know how we have balanced our legitimate interest against your rights, you can ask us at soporte@pitiklini.com.

We do not send advertising or build commercial profiles. Before we use your data for any purpose that is not in this policy, we will inform you.

Do we make automated decisions about you?

We do not make decisions about you based solely on automated processing that have legal effects on you or similarly significantly affect you (GDPR, Article 22).

We do, however, apply automatic rules that put an operation on hold for a person to review. A withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the Account is new. In addition, the Account is locked for a period after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends automatically.

Are you required to provide your data?

An email address and a password are required to open an Account. Without identity verification you will not be able to use the Crypto-Asset Services, because the law requires that verification before they are provided. To request a withdrawal you will need two-step verification and, to sell in P2P, a payment account in your name. To withdraw to an external address you must tell us whose it is and, if it belongs to another person or company, their name; above the amount set by the Platform, you must also prove that a wallet of your own is yours. To withdraw euros you will need your home address. Without that information you will not be able to withdraw. A mobile number and the anti-phishing code are optional.

To which recipients will your data be disclosed?

  • The entity that provides the Crypto-Asset Services, to the extent explained in "Who processes your data in the Crypto-Asset Services?" above.
  • The other party to each P2P trade, what is needed to pay.
  • Other users: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your Pitiklini ID, as explained in "What data about you do other people see?".
  • Companies that provide services to us (processors): they only process data on our instructions.
  • While the previous app remains in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
  • Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
  • Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).

We do not sell your data or disclose it to anyone for advertising.

Do we transfer your data outside the European Union?

Yes, to the United States and to Israel, with the following safeguards:

  • United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795). We checked this on 25 September 2026 on the official list, and we will check it again whenever it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework ceases to be valid.
  • Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).

You can ask us for a free copy of these safeguards at soporte@pitiklini.com.

How long will we keep your data?

We use each piece of data while it is needed. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that period, we delete it.

What data is recorded on the blockchain?

When you deposit or withdraw crypto, the transaction is recorded on the blockchain of the relevant network, which is public and does not allow records to be changed or deleted. That record does not include your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is the information that links that transaction to you in our systems.

What are your rights and how can you exercise them?

You can exercise the following rights at any time:

  • access to your data and to information about how we process it;
  • rectification, if it is inaccurate or incomplete (you can correct much of it yourself in your profile);
  • erasure, when it is no longer needed or there is no legal basis for processing it;
  • restriction of processing, in the cases provided for by law;
  • portability: receiving the data you gave us in a commonly used format, when we process it under a contract;
  • not being subject to automated decisions with legal effects.

Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports, the anti-fraud rules or your visits being counted in the statistics. You can do so by writing to soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need the data to defend ourselves against a claim (GDPR, Article 21). As the statistics do not allow us to identify you, to stop counting your visits we will need you to tell us the IP address you visit the website from (GDPR, Article 11).

How to exercise them: you can write to soporte@pitiklini.com from your Account's email address or tell us how we can verify your identity. You can also do so through a representative. Exercising these rights is free of charge. We will reply within one month; if the request is complex or we receive a large number of requests, we may extend this period by two further months, and we will inform you of this within the first month (GDPR, Article 12).

Limits: we cannot delete data that the law requires us to keep (it stays blocked, as explained above). The entity that provides the Crypto-Asset Services handles requests about the data it processes on its own account; if you send such a request to us, we will pass it on.

How do we protect your data?

All connections between your browser and our servers are encrypted. Passwords are stored as a hash, and payment accounts, verified names, the holders of the addresses in your address book, the names in transfers, your home address and backups are stored encrypted. Of the browsers we recognise we only keep a fingerprint and, of your passkeys, the public part. Two-step verification protects your Account, and our team's access to data is limited according to each person's role and logged. More information, and the measures you can take yourself, is available under Security.

Do we process the data of minors?

The Platform is intended exclusively for people aged 18 or over. If we become aware that an Account belongs to a minor, we will cancel it and delete the minor's data, except the data that the law requires us to keep, which will remain blocked.

How will we inform you of changes to this policy?

We will publish each new version with the date from which it applies and a summary of the changes. Earlier versions will remain available at the bottom of this page. If a change affects you significantly, we will notify you in advance by email or in the app, stating its date and what it means for you.

How can you contact us or make a complaint?

For any matter relating to your data, you can write to soporte@pitiklini.com or, by post, to Calle La Alhondiga, 23, en Los Realejos (Tenerife).

If you consider that we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through its online office, or with the data protection authority of the European Union country where you live, work or where the alleged infringement took place (GDPR, Article 77). We would appreciate it if you contacted us first, so that we can try to resolve the matter.

Versions of this document

Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.

  1. Version 6 · · current

    The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.

  2. Version 5 ·

    It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.

  3. Version 4 ·

    The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.

  4. Version 3 ·

    Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.

  5. Version 2 ·

    Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.

  6. Version 1 ·

    First published version.