Privacy policy
Version 1 ·
This policy explains what personal data we process when you visit pitiklini.com, use the Pitiklini app, write to us, file a complaint or report an ad, and what you can do about it. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
The essentials
Basic information on data protection. Each point is explained further down.
| Topic | Summary |
|---|---|
| Controller | PITIKLINI SOLUTION SL (Pitiklini). Contact: soporte@pitiklini.com |
| Purposes | Providing your account and the platform's services, keeping them secure, handling your questions, complaints and reports, and complying with the law. With your permission, recording the app screen when it fails and measuring its performance. We do not use your data for advertising |
| Legal bases | The contract you accept when you open your account, legal obligations, our legitimate interest in security and in things working properly, and your consent for screen recording and performance measurement |
| Recipients | The provider of the crypto-asset services; in P2P, the other person in each trade; and companies that provide technical services to us, some of them in the United States |
| Source | You give us almost everything. From the provider we receive the result of your identity verification, your verified name and the details of your account with it |
| Retention | While you have your account; after that, blocked for as long as the law requires, and then deleted |
| Rights | Access, rectify, erase, object, restrict and port your data, and withdraw your consent, by writing to soporte@pitiklini.com. And complain to the Spanish Data Protection Agency |
Who is responsible for your data?
The controller of your account data, of the website and of the app is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For anything about your data, write to soporte@pitiklini.com.
We have not appointed a data protection officer, because the law does not require us to.
What does the service provider do with your data?
The crypto-asset services are provided to you by the service provider (DEPASIFY S.L., NIF B67823831, calle Álvaro de Bazán 10, 46010 Valencia: custodia, verificación de identidad, pagos y transferencias en euros): verifying your identity, holding your crypto and your money, deposits, withdrawals and euro payments. To provide them and to comply with anti-money laundering rules, the provider processes your data on its own account, as a controller, under its own privacy policy. If you cannot find it, ask us at soporte@pitiklini.com and we will send it to you.
- When you verify your identity, you give your documents and the picture of your face directly on the provider's screen: they do not go through our servers and we do not keep them.
- What we pass to it: your account identifier, your email when your account with it has to be opened, and the instructions for your deposits, withdrawals and payments.
- What it gives us: whether your identity is verified and when, your name as it appears on your document, the identifiers of your account with it, your deposit addresses, your balances and movements (to check they match ours) and the status of your payments and withdrawals. We tell you here because you do not give us this data yourself (GDPR, Article 14).
- Complaints about the crypto-asset services are resolved by the provider: if you send them to us, we pass them on.
What data do we process and where does it come from?
If you only visit the website, without an account: the IP address and technical details of your browser that the server receives with each request and, if a page fails, a technical error report without your IP. The website uses no cookies and no analytics. What it stores in your browser is set out in the Cookie policy.
If you open an account:
- your email address and your password, which is stored as an irreversible summary (a hash), never as it is;
- the code you use to confirm your email;
- your display name in P2P and a short identifier of your account. Unless you change the name in your profile, it is the part of your email before the @;
- your language and your preferences;
- your anti-phishing code, if you choose one, which we include in our emails so you can recognise them;
- your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.
To protect your account: if you use two-step verification, the secret of your authenticator app; your open sessions; and your login history, with the IP address, browser, operating system and approximate country deduced from the IP. The security alerts we send you include those details.
Before you verify your identity, the app asks you for some basic details: first name, surname, date of birth, nationality, address, city and postcode. We store them in your account and do not pass them to the provider.
What you do on the platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.
In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.
If you write to us or complain: what you tell us and how to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.
If you report an ad: your name, your email and what you tell us. We store them encrypted.
If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.
Error reports, screen recording and performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, with which browser and system. It does not include your IP, your name or your email. In the app, and only if you agree, for some failures we add a recording of the screen from the minute before the error, in which all text, everything you type and all images are masked before they leave your device. And, also only if you agree, we measure the app's performance: how long screens take to load and respond, and an anonymous count of sessions for each version.
Other people's data you give us: if you complain on someone else's behalf or give us someone's details in a dispute, make sure you are allowed to and that you tell them.
What can other people see?
- Your P2P profile is public: anyone, even without an account, can see in your ads your display name, your short identifier, how many trades you have made and your rating.
- In a P2P trade, the other person sees your verified name and, if you are selling, the payment account they must pay into. This is what is needed for the payment to reach the right person.
- If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
- If you report an ad, the person who posted it does not see your name or your email, unless it is strictly necessary to explain the decision to them (Digital Services Act, Article 17).
What do we use your data for, and on what legal basis?
| Purpose | Legal basis (GDPR, Article 6) |
|---|---|
| Opening and running your account and providing the platform's services: trading, P2P, alerts about your trades and your account | Contract (6(1)(b)) |
| Keeping your account secure: two-step verification, alerts about new logins or changes, closing sessions | Contract (6(1)(b)) |
| Preventing fraud and abuse: reviewing risky withdrawals, locking the account after several failed attempts, holding withdrawals after a security change | Legitimate interest in protecting your money, other users' money and the platform (6(1)(f); Recitals 47 and 49) |
| Passing to the provider what it needs to open your account and provide its services, and receiving from it what we need to show them to you | Contract (6(1)(b)). Identity verification is also a legal obligation of the provider (Spanish Law 10/2010) |
| Showing your profile and your ads in P2P, and showing the other party to each trade what is needed to pay | Contract (6(1)(b)) |
| Resolving P2P disputes | Contract (6(1)(b)) |
| Receiving and dealing with reports about ads and explaining our moderation decisions | Legal obligation (6(1)(c); Digital Services Act, Articles 16 and 17) |
| Handling your questions and complaints, and passing to the provider those that are for it | Contract (6(1)(b)) and the legal obligation to deal with complaints (6(1)(c); Spanish General Law for the Protection of Consumers and Users, Article 21) |
| Handling your accessibility reports and giving you the information in another format | Legal obligation (6(1)(c); Spanish Law 11/2023 on the accessibility of products and services) |
| Keeping accounts, meeting tax obligations and responding to courts and authorities | Legal obligation (6(1)(c)) |
| Defending ourselves against claims | Legitimate interest in exercising our rights (6(1)(f)) |
| Detecting and fixing faults in the website and the app with error reports | Legitimate interest in the website and the app working properly and being secure (6(1)(f)) |
| Recording the app screen when it fails | Your consent (6(1)(a)), which you can withdraw at any time |
| Measuring the app's performance | Your consent (6(1)(a)), which you can withdraw at any time |
| Making backups | Legitimate interest in not losing data (6(1)(f)) and the obligation to protect it (GDPR, Article 32) |
If you want to know how we weighed our legitimate interest against your rights, ask us at soporte@pitiklini.com.
We do not send advertising or build commercial profiles. Before we start using your data for anything that is not in this policy, we will tell you.
Do we make automated decisions about you?
We do not make decisions about you based solely on automated processing that have legal effects or similarly significant effects on you (GDPR, Article 22).
There are automatic rules that put something on hold for a person to review: a withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the account is new; the account is locked for a while after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends by itself.
Which data must you give us?
Without an email address and a password, an account cannot be opened. Without verifying your identity with the provider, you cannot use the crypto-asset services, because the law requires it of the provider. To withdraw you need two-step verification, and to sell in P2P, a payment account in your name. A mobile number and the anti-phishing code are optional.
Who do we share your data with?
- The service provider, as explained above.
- The other person in each P2P trade, what is needed to pay.
- Companies that provide services to us (processors): they only process data on our instructions.
| Company | What it does | Where the data is |
|---|---|---|
| GotoSend Technologies S.L. (Spain) | Develops and maintains the platform for us, with access to its systems | European Union |
| Hostinger International Ltd. (Cyprus) | The platform's server and the support email mailbox | European Union |
| MongoDB Limited (Ireland) | The database | European Union (Paris, France) |
| Functional Software, Inc. (Sentry, United States) | Error reports and, if you agree, the recording of the app screen and the measurement of its performance | European Union (Frankfurt, Germany); its technical support, from the United States |
| Plus Five Five, Inc. (Resend, United States) | Sending emails | United States |
| Twilio (United States) | Sending security text messages | United States |
| Cloudinary (Israel and United States) | Storing images and dispute files | United States |
- While the previous app is still in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
- Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
- Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).
We do not sell your data or give it to anyone for advertising.
Does your data leave the European Union?
Yes, to the United States and to Israel, with these safeguards:
- United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795); we checked this on 25 September 2026 on the official list, and we check again when it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework stopped being valid.
- Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).
You can ask us for a free copy of these safeguards at soporte@pitiklini.com.
How long do we keep your data?
While a piece of data is needed, we use it. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that, we delete it.
| Data | How long |
|---|---|
| Your account, your profile and your basic details | While you have your account. When you close it, blocked for five years (Spanish Civil Code, Article 1964) |
| Trades, movements and fees | Six years from the last entry of the financial year (Spanish Commercial Code, Article 30) |
| Login history and security data | One year from each login |
| P2P messages, trades and disputes | Five years from the end of the trade |
| P2P payment accounts | While you keep them saved; if you delete them, only within the trades that used them |
| Verified name | While you have your account; when you close it, blocked for five years |
| Support requests and accessibility reports | One year after they are closed |
| Complaints | Five years after they are resolved |
| Reports about ads | One year from the decision |
| Error reports, screen recordings and performance measurements | Up to 90 days, in Sentry |
| Server logs (with the IP address) | Fourteen days |
| Backups | Fourteen days: deleted data remains in them for that time |
| What the provider keeps | The periods in its policy. The law requires it to keep verification data for ten years (Spanish Law 10/2010, Article 25) |
What stays on the blockchain
When you deposit or withdraw crypto, the transaction is recorded on that network's blockchain, which is public and cannot be changed or deleted. That record does not carry your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is what links that transaction to you in our systems.
Your rights and how to exercise them
You can ask us at any time to:
- access your data and find out how we process it;
- rectify it, if it is wrong or incomplete (you can correct much of it yourself in your profile);
- erase it, when it is no longer needed or there is no basis for processing it;
- restrict its use, in the cases provided for by law;
- port it in a commonly used format, for the data you gave us, when we process it under a contract or your consent;
- withdraw your consent, without affecting what we did before;
- not be subject to automated decisions with legal effects.
Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports or the anti-fraud rules. Write to us at soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need it to defend ourselves against a claim (GDPR, Article 21).
How: write to soporte@pitiklini.com from your account's email address, or tell us how to check it is you. You can do so through a representative. It is free. We reply within one month; if the request is complex or there are many, we can extend this by two more months, and we will tell you so within the first month (GDPR, Article 12).
Limits: we cannot delete what the law requires us to keep (it stays blocked, as explained above). Requests about what the provider processes on its own account go to the provider; if you send them to us, we pass them on.
How do we protect your data?
All connections between your browser and our servers are encrypted. Passwords are stored as a hash, payment accounts and verified names are encrypted, and backups are encrypted. Two-step verification protects your account, and our team's access to data is limited by role and logged. More detail, and what you can do yourself, under Security.
Children
The platform is only for people aged 18 or over. If we find out that an account belongs to a minor, we close it and delete their data, except what the law requires us to keep, which stays blocked.
Changes to this policy
We publish each new version with the date it applies from and a summary of what changes; earlier versions remain available at the bottom of this page. If a change affects you significantly, we will tell you in advance by email or in the app, with its date and what it means for you.
Contact and complaints
For anything about your data, write to soporte@pitiklini.com or by post to Calle La Alhondiga, 23, en Los Realejos (Tenerife).
If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (AEPD), through its online office, or to the data protection authority of the European Union country where you live or work. We would appreciate it if you wrote to us first, so we can try to resolve it.
Versions of this document
Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.
Version 6 · · current
The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.
It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.
The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.
Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.
Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.
Version 1 ·
First published version.