Skip to content
Sign inCreate accountGo to my account

Menu

Create accountGo to my accountEspañol

Privacy policy

Version 1 ·

This is version 1, which was in force until September 26, 2026. The current one is version 6. Go to the current version

This policy explains what personal data we process when you visit pitiklini.com, use the Pitiklini app, write to us, file a complaint or report an ad, and what you can do about it. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

The essentials

Basic information on data protection. Each point is explained further down.

Who is responsible for your data?

The controller of your account data, of the website and of the app is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For anything about your data, write to soporte@pitiklini.com.

We have not appointed a data protection officer, because the law does not require us to.

What does the service provider do with your data?

The crypto-asset services are provided to you by the service provider (DEPASIFY S.L., NIF B67823831, calle Álvaro de Bazán 10, 46010 Valencia: custodia, verificación de identidad, pagos y transferencias en euros): verifying your identity, holding your crypto and your money, deposits, withdrawals and euro payments. To provide them and to comply with anti-money laundering rules, the provider processes your data on its own account, as a controller, under its own privacy policy. If you cannot find it, ask us at soporte@pitiklini.com and we will send it to you.

  • When you verify your identity, you give your documents and the picture of your face directly on the provider's screen: they do not go through our servers and we do not keep them.
  • What we pass to it: your account identifier, your email when your account with it has to be opened, and the instructions for your deposits, withdrawals and payments.
  • What it gives us: whether your identity is verified and when, your name as it appears on your document, the identifiers of your account with it, your deposit addresses, your balances and movements (to check they match ours) and the status of your payments and withdrawals. We tell you here because you do not give us this data yourself (GDPR, Article 14).
  • Complaints about the crypto-asset services are resolved by the provider: if you send them to us, we pass them on.

What data do we process and where does it come from?

If you only visit the website, without an account: the IP address and technical details of your browser that the server receives with each request and, if a page fails, a technical error report without your IP. The website uses no cookies and no analytics. What it stores in your browser is set out in the Cookie policy.

If you open an account:

  • your email address and your password, which is stored as an irreversible summary (a hash), never as it is;
  • the code you use to confirm your email;
  • your display name in P2P and a short identifier of your account. Unless you change the name in your profile, it is the part of your email before the @;
  • your language and your preferences;
  • your anti-phishing code, if you choose one, which we include in our emails so you can recognise them;
  • your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.

To protect your account: if you use two-step verification, the secret of your authenticator app; your open sessions; and your login history, with the IP address, browser, operating system and approximate country deduced from the IP. The security alerts we send you include those details.

Before you verify your identity, the app asks you for some basic details: first name, surname, date of birth, nationality, address, city and postcode. We store them in your account and do not pass them to the provider.

What you do on the platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.

In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.

If you write to us or complain: what you tell us and how to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.

If you report an ad: your name, your email and what you tell us. We store them encrypted.

If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.

Error reports, screen recording and performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, with which browser and system. It does not include your IP, your name or your email. In the app, and only if you agree, for some failures we add a recording of the screen from the minute before the error, in which all text, everything you type and all images are masked before they leave your device. And, also only if you agree, we measure the app's performance: how long screens take to load and respond, and an anonymous count of sessions for each version.

Other people's data you give us: if you complain on someone else's behalf or give us someone's details in a dispute, make sure you are allowed to and that you tell them.

What can other people see?

  • Your P2P profile is public: anyone, even without an account, can see in your ads your display name, your short identifier, how many trades you have made and your rating.
  • In a P2P trade, the other person sees your verified name and, if you are selling, the payment account they must pay into. This is what is needed for the payment to reach the right person.
  • If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
  • If you report an ad, the person who posted it does not see your name or your email, unless it is strictly necessary to explain the decision to them (Digital Services Act, Article 17).

If you want to know how we weighed our legitimate interest against your rights, ask us at soporte@pitiklini.com.

We do not send advertising or build commercial profiles. Before we start using your data for anything that is not in this policy, we will tell you.

Do we make automated decisions about you?

We do not make decisions about you based solely on automated processing that have legal effects or similarly significant effects on you (GDPR, Article 22).

There are automatic rules that put something on hold for a person to review: a withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the account is new; the account is locked for a while after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends by itself.

Which data must you give us?

Without an email address and a password, an account cannot be opened. Without verifying your identity with the provider, you cannot use the crypto-asset services, because the law requires it of the provider. To withdraw you need two-step verification, and to sell in P2P, a payment account in your name. A mobile number and the anti-phishing code are optional.

Who do we share your data with?

  • The service provider, as explained above.
  • The other person in each P2P trade, what is needed to pay.
  • Companies that provide services to us (processors): they only process data on our instructions.
  • While the previous app is still in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
  • Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
  • Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).

We do not sell your data or give it to anyone for advertising.

Does your data leave the European Union?

Yes, to the United States and to Israel, with these safeguards:

  • United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795); we checked this on 25 September 2026 on the official list, and we check again when it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework stopped being valid.
  • Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).

You can ask us for a free copy of these safeguards at soporte@pitiklini.com.

How long do we keep your data?

While a piece of data is needed, we use it. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that, we delete it.

What stays on the blockchain

When you deposit or withdraw crypto, the transaction is recorded on that network's blockchain, which is public and cannot be changed or deleted. That record does not carry your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is what links that transaction to you in our systems.

Your rights and how to exercise them

You can ask us at any time to:

  • access your data and find out how we process it;
  • rectify it, if it is wrong or incomplete (you can correct much of it yourself in your profile);
  • erase it, when it is no longer needed or there is no basis for processing it;
  • restrict its use, in the cases provided for by law;
  • port it in a commonly used format, for the data you gave us, when we process it under a contract or your consent;
  • withdraw your consent, without affecting what we did before;
  • not be subject to automated decisions with legal effects.

Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports or the anti-fraud rules. Write to us at soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need it to defend ourselves against a claim (GDPR, Article 21).

How: write to soporte@pitiklini.com from your account's email address, or tell us how to check it is you. You can do so through a representative. It is free. We reply within one month; if the request is complex or there are many, we can extend this by two more months, and we will tell you so within the first month (GDPR, Article 12).

Limits: we cannot delete what the law requires us to keep (it stays blocked, as explained above). Requests about what the provider processes on its own account go to the provider; if you send them to us, we pass them on.

How do we protect your data?

All connections between your browser and our servers are encrypted. Passwords are stored as a hash, payment accounts and verified names are encrypted, and backups are encrypted. Two-step verification protects your account, and our team's access to data is limited by role and logged. More detail, and what you can do yourself, under Security.

Children

The platform is only for people aged 18 or over. If we find out that an account belongs to a minor, we close it and delete their data, except what the law requires us to keep, which stays blocked.

Changes to this policy

We publish each new version with the date it applies from and a summary of what changes; earlier versions remain available at the bottom of this page. If a change affects you significantly, we will tell you in advance by email or in the app, with its date and what it means for you.

Contact and complaints

For anything about your data, write to soporte@pitiklini.com or by post to Calle La Alhondiga, 23, en Los Realejos (Tenerife).

If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (AEPD), through its online office, or to the data protection authority of the European Union country where you live or work. We would appreciate it if you wrote to us first, so we can try to resolve it.

Versions of this document

Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.

  1. Version 6 · · current

    The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.

  2. Version 5 ·

    It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.

  3. Version 4 ·

    The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.

  4. Version 3 ·

    Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.

  5. Version 2 ·

    Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.

  6. Version 1 ·

    First published version.