Skip to content
Sign inCreate accountGo to my account

Menu

Create accountGo to my accountEspañol

Privacy policy

Version 3 ·

This is version 3, which was in force until September 26, 2026. The current one is version 6. Go to the current version

What changes in this version: Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.

In this policy, PITIKLINI SOLUTION SL ("Pitiklini", "we", "us" or "our") explains what personal data we process and what rights you have over it. The policy applies when you visit the pitiklini.com website or use the Pitiklini app (together, the "Platform"), write to us, file a complaint or report an ad. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

The custody, purchase and sale, exchange and transfer of crypto-assets, and the associated payments in euros (the "Crypto-Asset Services") are provided by DEPASIFY S.L. (the "Provider"), an entity subject to Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA). We provide the technology platform: we develop and maintain the website and the app, manage your user account on the Platform (your "Account"), host and moderate P2P ads and provide user support.

Basic information on data protection

The table below summarises the essentials. Each item is explained in detail in the sections that follow.

Who is the controller of your data?

The controller of your Account data and of the Platform is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For any matter relating to your data, you can write to soporte@pitiklini.com.

We have not appointed a data protection officer, because the law does not require us to do so.

Who processes your data in the Crypto-Asset Services?

The Provider verifies your identity and provides you with the Crypto-Asset Services. For these purposes, and to comply with anti-money laundering rules, it processes your personal data on its own account, as a controller, under its own privacy policy. If you cannot find that policy, you can ask us for it at soporte@pitiklini.com and we will send it to you.

  • Identity verification: you provide your documents and the image of your face directly on the verification screen that it shows you. They do not pass through our servers and we do not keep them.
  • Data we send to it: your Account identifier, your email address when it needs to open an account for you, and the instructions for your deposits, withdrawals and payments.
  • Data it sends to us: whether your identity is verified and since when, your name as it appears on your identity document, the identifiers of your account with it, your deposit addresses, your balances and movements (to check that they match ours) and the status of your payments and withdrawals. We inform you of this because we do not obtain this data from you (GDPR, Article 14).
  • Complaints about the Crypto-Asset Services: it resolves them. If you send them to us, we will pass them on to it.

What personal data do we process and how do we obtain it?

If you only visit the website, without an Account: the IP address and the technical details your browser sends with each request (the page requested, the date and time, the browser and system, and the referring page), which our server logs. With those logs, and with the IP address truncated, we produce aggregate statistics of visits. If a page fails, a technical error report is also sent. The website sets no cookies and runs no analytics tool in your browser. What it stores in your browser is set out in the Cookie policy.

If you open an Account:

  • your email address and your password, which is stored as an irreversible summary (a hash) and never in plain text;
  • the code you use to confirm your email address;
  • your display name in P2P and a short identifier of your Account. Unless you change the name in your profile, it is a random alias that we assign when the Account is created (for Accounts created before 25 September 2026, the part of your email address before the @);
  • your language and your preferences;
  • your anti-phishing code, if you choose one, which we include in our emails so that you can recognise them;
  • your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.

To protect your Account: if you use two-step verification, the secret of your authenticator app; your open sessions; and your login history, with the IP address, browser, operating system and approximate country deduced from the IP address. The security alerts we send you include those details.

Before you verify your identity, the app asks you for these basic details: first name, surname, date of birth, nationality, address, city and postcode. We store them in your Account and do not include them in the data we send for the Crypto-Asset Services.

Your activity on the Platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.

In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.

If you write to us or make a complaint: what you tell us and the details we need to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.

If you report an ad: your name, your email address and what you tell us. We store them encrypted.

If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.

Error reports, screen recording and performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, and with which browser and system. The report does not include your name or your email address, and Sentry, which receives the IP address it is sent from, is configured not to store it. In the app, and only if you agree, for a random sample of failures we add a recording of the screen from the minute before the error. The recording masks all text, everything you type and all images before it leaves your device. Also only if you agree, we measure the app's performance: how long screens take to load and respond, and an anonymous count of sessions for each version.

Other people's data you give us: if you complain on someone else's behalf or give us someone else's details in a dispute, you must make sure that you are authorised to do so and that you inform that person.

What data about you do other people see?

  • Your P2P profile is public: your ads show anyone, even without an Account, your display name, your short identifier, how many trades you have made and your rating.
  • In a P2P trade, the other party sees your verified name and, if you are selling, the payment account into which they must pay you. This is what is needed for the payment to reach the right person.
  • If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
  • If you report an ad, the person who posted it does not see your name or your email address, unless this is strictly necessary to explain the decision to them (Digital Services Act, Article 17).

If you want to know how we have balanced our legitimate interest against your rights, you can ask us at soporte@pitiklini.com.

We do not send advertising or build commercial profiles. Before we use your data for any purpose that is not in this policy, we will inform you.

Do we make automated decisions about you?

We do not make decisions about you based solely on automated processing that have legal effects on you or similarly significantly affect you (GDPR, Article 22).

We do, however, apply automatic rules that put an operation on hold for a person to review. A withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the Account is new. In addition, the Account is locked for a period after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends automatically.

Are you required to provide your data?

An email address and a password are required to open an Account. Without identity verification you will not be able to use the Crypto-Asset Services, because the law requires that verification before they are provided. To request a withdrawal you will need two-step verification and, to sell in P2P, a payment account in your name. A mobile number and the anti-phishing code are optional.

To which recipients will your data be disclosed?

  • The entity that provides the Crypto-Asset Services, to the extent explained in "Who processes your data in the Crypto-Asset Services?" above.
  • The other party to each P2P trade, what is needed to pay.
  • Companies that provide services to us (processors): they only process data on our instructions.
  • While the previous app remains in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
  • Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
  • Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).

We do not sell your data or disclose it to anyone for advertising.

Do we transfer your data outside the European Union?

Yes, to the United States and to Israel, with the following safeguards:

  • United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795). We checked this on 25 September 2026 on the official list, and we will check it again whenever it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework ceases to be valid.
  • Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).

You can ask us for a free copy of these safeguards at soporte@pitiklini.com.

How long will we keep your data?

We use each piece of data while it is needed. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that period, we delete it.

What data is recorded on the blockchain?

When you deposit or withdraw crypto, the transaction is recorded on the blockchain of the relevant network, which is public and does not allow records to be changed or deleted. That record does not include your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is the information that links that transaction to you in our systems.

What are your rights and how can you exercise them?

You can exercise the following rights at any time:

  • access to your data and to information about how we process it;
  • rectification, if it is inaccurate or incomplete (you can correct much of it yourself in your profile);
  • erasure, when it is no longer needed or there is no legal basis for processing it;
  • restriction of processing, in the cases provided for by law;
  • portability: receiving the data you gave us in a commonly used format, when we process it under a contract or with your consent;
  • withdrawal of consent, without affecting the processing carried out before the withdrawal;
  • not being subject to automated decisions with legal effects.

Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports, the anti-fraud rules or your visits being counted in the statistics. You can do so by writing to soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need the data to defend ourselves against a claim (GDPR, Article 21). As the statistics do not allow us to identify you, to stop counting your visits we will need you to tell us the IP address you visit the website from (GDPR, Article 11).

How to exercise them: you can write to soporte@pitiklini.com from your Account's email address or tell us how we can verify your identity. You can also do so through a representative. Exercising these rights is free of charge. We will reply within one month; if the request is complex or we receive a large number of requests, we may extend this period by two further months, and we will inform you of this within the first month (GDPR, Article 12).

Limits: we cannot delete data that the law requires us to keep (it stays blocked, as explained above). The entity that provides the Crypto-Asset Services handles requests about the data it processes on its own account; if you send such a request to us, we will pass it on.

How do we protect your data?

All connections between your browser and our servers are encrypted. Passwords are stored as a hash, and payment accounts, verified names and backups are stored encrypted. Two-step verification protects your Account, and our team's access to data is limited according to each person's role and logged. More information, and the measures you can take yourself, is available under Security.

Do we process the data of minors?

The Platform is intended exclusively for people aged 18 or over. If we become aware that an Account belongs to a minor, we will cancel it and delete the minor's data, except the data that the law requires us to keep, which will remain blocked.

How will we inform you of changes to this policy?

We will publish each new version with the date from which it applies and a summary of the changes. Earlier versions will remain available at the bottom of this page. If a change affects you significantly, we will notify you in advance by email or in the app, stating its date and what it means for you.

How can you contact us or make a complaint?

For any matter relating to your data, you can write to soporte@pitiklini.com or, by post, to Calle La Alhondiga, 23, en Los Realejos (Tenerife).

If you consider that we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through its online office, or with the data protection authority of the European Union country where you live, work or where the alleged infringement took place (GDPR, Article 77). We would appreciate it if you contacted us first, so that we can try to resolve the matter.

Versions of this document

Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.

  1. Version 6 · · current

    The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.

  2. Version 5 ·

    It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.

  3. Version 4 ·

    The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.

  4. Version 3 ·

    Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.

  5. Version 2 ·

    Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.

  6. Version 1 ·

    First published version.