Privacy policy
Version 2 ·
What changes in this version: Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.
In this policy, PITIKLINI SOLUTION SL ("Pitiklini", "we", "us" or "our") explains what personal data we process and what rights you have over it. The policy applies when you visit the pitiklini.com website or use the Pitiklini app (together, the "Platform"), write to us, file a complaint or report an ad. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
The custody, purchase and sale, exchange and transfer of crypto-assets, and the associated payments in euros (the "Crypto-Asset Services") are provided by DEPASIFY S.L. (the "Provider"), an entity subject to Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA). We provide the technology platform: we develop and maintain the website and the app, manage your user account on the Platform (your "Account"), host and moderate P2P ads and provide user support.
Basic information on data protection
The table below summarises the essentials. Each item is explained in detail in the sections that follow.
| Item | Basic information |
|---|---|
| Controller | PITIKLINI SOLUTION SL (Pitiklini). Contact: soporte@pitiklini.com |
| Purposes | Managing your Account, giving you access to the Platform's features and keeping both secure; handling your questions, complaints and reports; and complying with the law. With your consent, recording the app screen when the app fails and measuring the app's performance. We do not use your data for advertising |
| Legal basis | Performance of the contract you accept when you open your Account, compliance with legal obligations, our legitimate interest in the security and proper functioning of the Platform, and your consent for screen recording and performance measurement |
| Recipients | The Provider; in P2P, the other party to each trade; and the companies that provide technical services to us, with transfers to the United States and Israel |
| Source | You provide almost all of the data. From the Provider we receive the result of your identity verification, your verified name and the details of your account with it |
| Retention | While you keep your Account; after that, blocked for as long as the law requires, and then deleted |
| Rights | Access, rectification, erasure, objection, restriction of processing, portability and withdrawal of consent, by writing to soporte@pitiklini.com. You can also complain to the Spanish Data Protection Agency |
Who is the controller of your data?
The controller of your Account data and of the Platform is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For any matter relating to your data, you can write to soporte@pitiklini.com.
We have not appointed a data protection officer, because the law does not require us to do so.
Who processes your data in the Crypto-Asset Services?
The Provider verifies your identity and provides you with the Crypto-Asset Services. For these purposes, and to comply with anti-money laundering rules, it processes your personal data on its own account, as a controller, under its own privacy policy. If you cannot find that policy, you can ask us for it at soporte@pitiklini.com and we will send it to you.
- Identity verification: you provide your documents and the image of your face directly on the verification screen that it shows you. They do not pass through our servers and we do not keep them.
- Data we send to it: your Account identifier, your email address when it needs to open an account for you, and the instructions for your deposits, withdrawals and payments.
- Data it sends to us: whether your identity is verified and since when, your name as it appears on your identity document, the identifiers of your account with it, your deposit addresses, your balances and movements (to check that they match ours) and the status of your payments and withdrawals. We inform you of this because we do not obtain this data from you (GDPR, Article 14).
- Complaints about the Crypto-Asset Services: it resolves them. If you send them to us, we will pass them on to it.
What personal data do we process and how do we obtain it?
If you only visit the website, without an Account: the IP address and technical details of your browser that the server receives with each request and, if a page fails, a technical error report without your IP address. The website uses no cookies and no analytics. What it stores in your browser is set out in the Cookie policy.
If you open an Account:
- your email address and your password, which is stored as an irreversible summary (a hash) and never in plain text;
- the code you use to confirm your email address;
- your display name in P2P and a short identifier of your Account. Unless you change the name in your profile, it is a random alias that we assign when the Account is created (for Accounts created before 25 September 2026, the part of your email address before the @);
- your language and your preferences;
- your anti-phishing code, if you choose one, which we include in our emails so that you can recognise them;
- your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.
To protect your Account: if you use two-step verification, the secret of your authenticator app; your open sessions; and your login history, with the IP address, browser, operating system and approximate country deduced from the IP address. The security alerts we send you include those details.
Before you verify your identity, the app asks you for these basic details: first name, surname, date of birth, nationality, address, city and postcode. We store them in your Account and do not include them in the data we send for the Crypto-Asset Services.
Your activity on the Platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.
In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.
If you write to us or make a complaint: what you tell us and the details we need to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.
If you report an ad: your name, your email address and what you tell us. We store them encrypted.
If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.
Error reports, screen recording and performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, and with which browser and system. The report does not include your IP address, your name or your email address. In the app, and only if you agree, for a random sample of failures we add a recording of the screen from the minute before the error. The recording masks all text, everything you type and all images before it leaves your device. Also only if you agree, we measure the app's performance: how long screens take to load and respond, and an anonymous count of sessions for each version.
Other people's data you give us: if you complain on someone else's behalf or give us someone else's details in a dispute, you must make sure that you are authorised to do so and that you inform that person.
What data about you do other people see?
- Your P2P profile is public: your ads show anyone, even without an Account, your display name, your short identifier, how many trades you have made and your rating.
- In a P2P trade, the other party sees your verified name and, if you are selling, the payment account into which they must pay you. This is what is needed for the payment to reach the right person.
- If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
- If you report an ad, the person who posted it does not see your name or your email address, unless this is strictly necessary to explain the decision to them (Digital Services Act, Article 17).
For what purposes do we process your data and on what legal basis?
| Purpose | Legal basis (GDPR, Article 6) |
|---|---|
| Opening and running your Account and giving you access to the Platform's features: trading, P2P, and alerts about your trades and your Account | Performance of a contract (6(1)(b)) |
| Keeping your Account secure: two-step verification, alerts about new logins or changes, and closing sessions | Performance of a contract (6(1)(b)) |
| Preventing fraud and abuse: reviewing risky withdrawals, locking the Account after several failed attempts and holding withdrawals after a security change | Legitimate interest in protecting your money, other users' money and the Platform (6(1)(f); Recitals 47 and 49) |
| Sending the data needed for you to use the Crypto-Asset Services, including the opening of your account, and receiving the data we need to show them to you on the Platform | Performance of a contract (6(1)(b)). Spanish Law 10/2010 also requires your identity to be verified before those services are provided to you |
| Showing your profile and your ads in P2P, and showing the other party to each trade what is needed to pay | Performance of a contract (6(1)(b)) |
| Resolving P2P disputes | Performance of a contract (6(1)(b)) |
| Receiving and dealing with reports about ads and explaining our moderation decisions | Compliance with a legal obligation (6(1)(c); Digital Services Act, Articles 16 and 17) |
| Handling your questions and complaints, and passing those concerning the Crypto-Asset Services on to the entity that must resolve them | Performance of a contract (6(1)(b)) and compliance with the legal obligation to deal with complaints (6(1)(c); Spanish General Law for the Protection of Consumers and Users, Article 21) |
| Handling your accessibility reports and giving you the information in another format | Compliance with a legal obligation (6(1)(c); Spanish Law 11/2023 on the accessibility of products and services) |
| Keeping accounts, meeting tax obligations and responding to courts and authorities | Compliance with a legal obligation (6(1)(c)): Spanish Commercial Code (Article 30), Law 58/2003, General Tax Law (Article 29), and the laws that empower each authority |
| Defending ourselves against claims | Legitimate interest in exercising our rights (6(1)(f)) |
| Detecting and fixing faults in the website and the app with error reports | Legitimate interest in the website and the app working properly and being secure (6(1)(f)) |
| Recording the app screen when the app fails | Your consent (6(1)(a)), which you may withdraw at any time |
| Measuring the app's performance | Your consent (6(1)(a)), which you may withdraw at any time |
| Making backups | Legitimate interest in not losing data (6(1)(f)) and the obligation to protect it (GDPR, Article 32) |
If you want to know how we have balanced our legitimate interest against your rights, you can ask us at soporte@pitiklini.com.
We do not send advertising or build commercial profiles. Before we use your data for any purpose that is not in this policy, we will inform you.
Do we make automated decisions about you?
We do not make decisions about you based solely on automated processing that have legal effects on you or similarly significantly affect you (GDPR, Article 22).
We do, however, apply automatic rules that put an operation on hold for a person to review. A withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the Account is new. In addition, the Account is locked for a period after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends automatically.
Are you required to provide your data?
An email address and a password are required to open an Account. Without identity verification you will not be able to use the Crypto-Asset Services, because the law requires that verification before they are provided. To request a withdrawal you will need two-step verification and, to sell in P2P, a payment account in your name. A mobile number and the anti-phishing code are optional.
To which recipients will your data be disclosed?
- The entity that provides the Crypto-Asset Services, to the extent explained in "Who processes your data in the Crypto-Asset Services?" above.
- The other party to each P2P trade, what is needed to pay.
- Companies that provide services to us (processors): they only process data on our instructions.
| Company | Service | Location of the data |
|---|---|---|
| GotoSend Technologies S.L. (Spain) | Develops and maintains the Platform on our behalf, with access to its systems | European Union |
| Hostinger International Ltd. (Cyprus) | The Platform's server and the support email mailbox | European Union |
| MongoDB Limited (Ireland) | The database | European Union (Paris, France) |
| Functional Software, Inc. (Sentry, United States) | Error reports and, if you agree, the recording of the app screen and the measurement of the app's performance | European Union (Frankfurt, Germany); its technical support, from the United States |
| Plus Five Five, Inc. (Resend, United States) | Sending emails | United States |
| Twilio (United States) | Sending security text messages | United States |
| Cloudinary (Israel and United States) | Storing images and dispute files | United States |
- While the previous app remains in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
- Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
- Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).
We do not sell your data or disclose it to anyone for advertising.
Do we transfer your data outside the European Union?
Yes, to the United States and to Israel, with the following safeguards:
- United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795). We checked this on 25 September 2026 on the official list, and we will check it again whenever it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework ceases to be valid.
- Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).
You can ask us for a free copy of these safeguards at soporte@pitiklini.com.
How long will we keep your data?
We use each piece of data while it is needed. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that period, we delete it.
| Data | Retention period |
|---|---|
| Your Account, your profile and your basic details | While you keep your Account. After the Account is cancelled, blocked for five years (Spanish Civil Code, Article 1964) |
| Trades, movements and fees | Six years from the last entry of the financial year (Spanish Commercial Code, Article 30) |
| Login history and security data | One year from each login |
| P2P messages, trades and disputes | Five years from the end of the trade |
| P2P payment accounts | While you keep them saved; if you delete them, only within the trades in which they were used |
| Verified name | While you keep your Account; after it is cancelled, blocked for five years |
| Support requests and accessibility reports | One year after they are closed |
| Complaints | Five years after they are resolved |
| Reports about ads | One year from the decision |
| Error reports, screen recordings and performance measurements | Up to 90 days, in Sentry |
| Server logs (with the IP address) | Fourteen days |
| Backups | Fourteen days: deleted data remains in them for that time |
| What the entity that provides the Crypto-Asset Services keeps | The periods in its privacy policy. The law requires it to keep identity verification data for ten years (Spanish Law 10/2010, Article 25) |
What data is recorded on the blockchain?
When you deposit or withdraw crypto, the transaction is recorded on the blockchain of the relevant network, which is public and does not allow records to be changed or deleted. That record does not include your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is the information that links that transaction to you in our systems.
What are your rights and how can you exercise them?
You can exercise the following rights at any time:
- access to your data and to information about how we process it;
- rectification, if it is inaccurate or incomplete (you can correct much of it yourself in your profile);
- erasure, when it is no longer needed or there is no legal basis for processing it;
- restriction of processing, in the cases provided for by law;
- portability: receiving the data you gave us in a commonly used format, when we process it under a contract or with your consent;
- withdrawal of consent, without affecting the processing carried out before the withdrawal;
- not being subject to automated decisions with legal effects.
Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports or the anti-fraud rules. You can do so by writing to soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need the data to defend ourselves against a claim (GDPR, Article 21).
How to exercise them: you can write to soporte@pitiklini.com from your Account's email address or tell us how we can verify your identity. You can also do so through a representative. Exercising these rights is free of charge. We will reply within one month; if the request is complex or we receive a large number of requests, we may extend this period by two further months, and we will inform you of this within the first month (GDPR, Article 12).
Limits: we cannot delete data that the law requires us to keep (it stays blocked, as explained above). The entity that provides the Crypto-Asset Services handles requests about the data it processes on its own account; if you send such a request to us, we will pass it on.
How do we protect your data?
All connections between your browser and our servers are encrypted. Passwords are stored as a hash, and payment accounts, verified names and backups are stored encrypted. Two-step verification protects your Account, and our team's access to data is limited according to each person's role and logged. More information, and the measures you can take yourself, is available under Security.
Do we process the data of minors?
The Platform is intended exclusively for people aged 18 or over. If we become aware that an Account belongs to a minor, we will cancel it and delete the minor's data, except the data that the law requires us to keep, which will remain blocked.
How will we inform you of changes to this policy?
We will publish each new version with the date from which it applies and a summary of the changes. Earlier versions will remain available at the bottom of this page. If a change affects you significantly, we will notify you in advance by email or in the app, stating its date and what it means for you.
How can you contact us or make a complaint?
For any matter relating to your data, you can write to soporte@pitiklini.com or, by post, to Calle La Alhondiga, 23, en Los Realejos (Tenerife).
If you consider that we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through its online office, or with the data protection authority of the European Union country where you live, work or where the alleged infringement took place (GDPR, Article 77). We would appreciate it if you contacted us first, so that we can try to resolve the matter.
Versions of this document
Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.
Version 6 · · current
The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.
It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.
The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.
Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.
Version 2 ·
Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.
First published version.