Privacy policy
Version 5 ·
What changes in this version: It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.
In this policy, PITIKLINI SOLUTION SL ("Pitiklini", "we", "us" or "our") explains what personal data we process and what rights you have over it. The policy applies when you visit the pitiklini.com website or use the Pitiklini app (together, the "Platform"), write to us, file a complaint or report an ad. It is governed by the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
The custody, purchase and sale, exchange and transfer of crypto-assets, and the associated payments in euros (the "Crypto-Asset Services") are provided by DEPASIFY S.L. (the "Provider"), an entity subject to Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA). We provide the technology platform: we develop and maintain the website and the app, manage your user account on the Platform (your "Account"), host and moderate P2P ads and provide user support.
Basic information on data protection
The table below summarises the essentials. Each item is explained in detail in the sections that follow.
| Item | Basic information |
|---|---|
| Controller | PITIKLINI SOLUTION SL (Pitiklini). Contact: soporte@pitiklini.com |
| Purposes | Managing your Account, giving you access to the Platform's features and keeping both secure; handling your questions, complaints and reports; producing aggregate statistics of visits to the website; and complying with the law. With your consent, recording the app screen when the app fails and measuring the app's performance. We do not use your data for advertising |
| Legal basis | Performance of the contract you accept when you open your Account, compliance with legal obligations, our legitimate interest in the security, proper functioning and improvement of the Platform and in transfers of crypto-assets complying with their rules, and your consent for screen recording and performance measurement |
| Recipients | The Provider; in P2P, the other party to each trade; in a transfer between people on Pitiklini, the other person (your nickname and your Pitiklini ID); and the companies that provide technical services to us, with transfers to the United States and Israel |
| Source | You provide almost all of the data. From the Provider we receive the result of your identity verification, your verified name and the details of your account with it |
| Retention | While you keep your Account; after that, blocked for as long as the law requires, and then deleted |
| Rights | Access, rectification, erasure, objection, restriction of processing, portability and withdrawal of consent, by writing to soporte@pitiklini.com. You can also complain to the Spanish Data Protection Agency |
Who is the controller of your data?
The controller of your Account data and of the Platform is PITIKLINI SOLUTION SL, tax ID B19842756, registered address Calle La Alhondiga, 23, en Los Realejos (Tenerife). For any matter relating to your data, you can write to soporte@pitiklini.com.
We have not appointed a data protection officer, because the law does not require us to do so.
Who processes your data in the Crypto-Asset Services?
The Provider verifies your identity and provides you with the Crypto-Asset Services. For these purposes, and to comply with anti-money laundering rules, it processes your personal data on its own account, as a controller, under its own privacy policy. If you cannot find that policy, you can ask us for it at soporte@pitiklini.com and we will send it to you.
- Identity verification: you provide your documents and the image of your face directly on the verification screen that it shows you. They do not pass through our servers and we do not keep them.
- Data we send to it: your Account identifier, your email address when it needs to open an account for you, and the instructions for your deposits, withdrawals and payments, with your home address when you withdraw euros.
- Data it sends to us: whether your identity is verified and since when, your name as it appears on your identity document and, if it has it, your home address, the identifiers of your account with it, your deposit addresses, your balances and movements (to check that they match ours), the status of your payments and withdrawals and, for each deposit of euros, the source account and its holder. We inform you of this because we do not obtain this data from you (GDPR, Article 14).
- Complaints about the Crypto-Asset Services: it resolves them. If you send them to us, we will pass them on to it.
What personal data do we process and how do we obtain it?
If you only visit the website, without an Account: the IP address and the technical details your browser sends with each request (the page requested, the date and time, the browser and system, and the referring page), which our server logs. With those logs, and with the IP address truncated, we produce aggregate statistics of visits. If a page fails, a technical error report is also sent. The website sets no cookies and runs no analytics tool in your browser. What it stores in your browser is set out in the Cookie policy.
If you open an Account:
- your email address and your password, which is stored as an irreversible summary (a hash) and never in plain text;
- the code you use to confirm your email address;
- your nickname, the name other people see you by in P2P and in transfers, and your Pitiklini ID, a short identifier of your Account. The nickname is random when the Account is created and you can change it in the app; the one you leave is reserved for a time so that nobody else uses it;
- your language and your preferences;
- your anti-phishing code, if you choose one, which we include in our emails so that you can recognise them;
- your mobile phone number, if you give it to us and verify it, to send you security alerts by text message.
To protect your Account:
- if you use two-step verification, the secret of your authenticator app;
- if you register passkeys, the public part of each one, its name, the password manager or service that stores it, whether it is synced across your devices and when it was created and last used. Your fingerprint or your face never leaves your device, which is what checks them;
- your open sessions;
- your login history, with the IP address, browser, operating system and approximate country deduced from the IP address;
- the browsers you have logged in from, to alert you when someone logs in to your Account from a new one: a random identifier stored in a cookie in your browser, of which we only keep a fingerprint, together with the browser and system (for example, "Chrome (Windows 10.0)") and the dates of the first and last login.
The security alerts we send you include those details.
Your activity on the Platform: your balances, deposits, withdrawals (with the destination addresses and the identifier of each transaction), orders, trades and fees. And, to detect fraud, the risk signals of each withdrawal.
If you send crypto-assets to an external address: the address, the network, the name you give it and whose it is: yours or another person's or company's (in that case, their name, which we store encrypted). If it is an account on another platform, the name of that platform. If you prove that a wallet is yours, the signed message and the signature. Regulation (EU) 2023/1113 (Article 14) requires this information to be known for each transfer of crypto-assets, and we keep it in your address book so as not to ask you for it every time.
If you send crypto-assets to another person on Pitiklini: who you send them to, whom you identify by their email address, their nickname, their Pitiklini ID or their deposit address; the amount; the reference, if you write one; and the names of both people, which we store encrypted for the same reason.
If you withdraw euros: your home address (country, postcode, city and street), which the Provider requires to send the payment and which we store encrypted (we take it from your identity verification if the Provider has it, and you confirm or enter it), and the bank accounts in your name from which you have added euros, which are the only ones you can withdraw them to.
In P2P: your ads, your trades, the chat messages, ratings, the payment accounts you save (encrypted) and, if there is a dispute, what the parties provide: messages, receipts and other files.
If you write to us or make a complaint: what you tell us and the details we need to reply to you. For a complaint, also the details the form asks for: yours and, if you complain on someone else's behalf, those of the person you represent and yours as their representative.
If you report an ad: your name, your email address and what you tell us. We store them encrypted.
If you tell us about an accessibility barrier or ask for another format: what you tell us. We will not ask you for health data; if you give it to us, we will only use it to handle your request.
Error reports, screen recording and performance: when the website or the app fails, we send a technical report of the error: what failed, on which screen, and with which browser and system. The report does not include your name or your email address, and Sentry, which receives the IP address it is sent from, is configured not to store it. In the app, and only if you agree, for a random sample of failures we add a recording of the screen from the minute before the error. The recording masks all text, everything you type and all images before it leaves your device. Also only if you agree, we measure the app's performance: how long screens take to load and respond, and an anonymous count of sessions for each version.
Other people's data you give us: if you complain on someone else's behalf, give us someone else's details in a dispute or tell us the name of the holder of an address that is not yours, you must make sure that you are authorised to do so and that you inform that person.
What data about you do other people see?
- Your P2P profile is public: your ads show anyone, even without an Account, your nickname, whether you have verified your identity, the month you joined, how many trades you have completed (in total and in the last 30 days), the percentage you have completed, your average payment and release times and your ratings. Your Pitiklini ID is not shown.
- In a P2P trade, the other party sees your verified name and, if you are selling, the payment account into which they must pay you. This is what is needed for the payment to reach the right person.
- If there is a dispute, the team resolving it sees what both parties provide. The other party sees what you upload to a dispute only if you share it.
- In a transfer between people on Pitiklini, each one sees the other's nickname and the reference of the transfer and, on the receipt, also their Pitiklini ID; never their name or their email address. Anyone who knows your email address, your nickname or your Pitiklini ID can send you crypto-assets and, before confirming, will see your nickname and your Pitiklini ID. If they send to your deposit address, they see nothing about you before confirming; once the transfer is done, they will see your nickname and your ID on the receipt.
- If you report an ad, the person who posted it does not see your name or your email address, unless this is strictly necessary to explain the decision to them (Digital Services Act, Article 17).
For what purposes do we process your data and on what legal basis?
| Purpose | Legal basis (GDPR, Article 6) |
|---|---|
| Opening and running your Account and giving you access to the Platform's features: trading, P2P, and alerts about your trades and your Account | Performance of a contract (6(1)(b)) |
| Keeping your Account secure: two-step verification, passkeys, recognising the browsers you log in from, alerts about new logins or changes, and closing sessions | Performance of a contract (6(1)(b)) |
| Knowing and keeping who sends and who receives each transfer of crypto-assets, in withdrawals to external addresses and in transfers between people on Pitiklini, as required by Regulation (EU) 2023/1113, Article 14 | Legitimate interest in transfers initiated on the Platform complying with that Article, which does not allow them to be made without that information (6(1)(f)) |
| Preventing fraud and abuse: reviewing risky withdrawals, locking the Account after several failed attempts and holding withdrawals after a security change | Legitimate interest in protecting your money, other users' money and the Platform (6(1)(f); Recitals 47 and 49) |
| Sending the data needed for you to use the Crypto-Asset Services, including the opening of your account, and receiving the data we need to show them to you on the Platform | Performance of a contract (6(1)(b)). Spanish Law 10/2010 also requires your identity to be verified before those services are provided to you |
| Showing your profile and your ads in P2P, and showing the other party to each trade what is needed to pay | Performance of a contract (6(1)(b)) |
| Resolving P2P disputes | Performance of a contract (6(1)(b)) |
| Receiving and dealing with reports about ads and explaining our moderation decisions | Compliance with a legal obligation (6(1)(c); Digital Services Act, Articles 16 and 17) |
| Handling your questions and complaints, and passing those concerning the Crypto-Asset Services on to the entity that must resolve them | Performance of a contract (6(1)(b)) and compliance with the legal obligation to deal with complaints (6(1)(c); Spanish General Law for the Protection of Consumers and Users, Article 21) |
| Handling your accessibility reports and giving you the information in another format | Performance of the contract (6(1)(b)), if you have an Account; otherwise, legitimate interest in ensuring that anyone can use the Platform and in replying to those who write to us (6(1)(f)) |
| Keeping accounts, meeting tax obligations and responding to courts and authorities | Compliance with a legal obligation (6(1)(c)): Spanish Commercial Code (Article 30), Law 58/2003, General Tax Law (Article 29), and the laws that empower each authority |
| Defending ourselves against claims | Legitimate interest in exercising our rights (6(1)(f)) |
| Detecting and fixing faults in the website and the app with error reports | Legitimate interest in the website and the app working properly and being secure (6(1)(f)) |
| Logging the requests our server receives (the IP address, the page requested, the date and time, the browser and the referring page) to keep the Platform secure and detect attacks and abuse | Legitimate interest in network and information security (6(1)(f); Recital 49) |
| Producing aggregate statistics of visits to the website from those logs, with the IP address truncated, to know which pages are viewed and improve them | Legitimate interest in knowing how the website is used in order to improve it (6(1)(f)) |
| Recording the app screen when the app fails | Your consent (6(1)(a)), which you may withdraw at any time |
| Measuring the app's performance | Your consent (6(1)(a)), which you may withdraw at any time |
| Making backups | Legitimate interest in not losing data (6(1)(f)) and the obligation to protect it (GDPR, Article 32) |
If you want to know how we have balanced our legitimate interest against your rights, you can ask us at soporte@pitiklini.com.
We do not send advertising or build commercial profiles. Before we use your data for any purpose that is not in this policy, we will inform you.
Do we make automated decisions about you?
We do not make decisions about you based solely on automated processing that have legal effects on you or similarly significantly affect you (GDPR, Article 22).
We do, however, apply automatic rules that put an operation on hold for a person to review. A withdrawal goes to review because of its amount, because it goes to a new address, because it is the first one, because of a recent deposit or because the Account is new. In addition, the Account is locked for a period after several failed password attempts, and withdrawals are held after a security change. In all those cases a person decides, or the hold ends automatically.
Are you required to provide your data?
An email address and a password are required to open an Account. Without identity verification you will not be able to use the Crypto-Asset Services, because the law requires that verification before they are provided. To request a withdrawal you will need two-step verification and, to sell in P2P, a payment account in your name. To withdraw to an external address you must tell us whose it is and, if it belongs to another person or company, their name; above the amount set by the Platform, you must also prove that a wallet of your own is yours. To withdraw euros you will need your home address. Without that information you will not be able to withdraw. A mobile number and the anti-phishing code are optional.
To which recipients will your data be disclosed?
- The entity that provides the Crypto-Asset Services, to the extent explained in "Who processes your data in the Crypto-Asset Services?" above.
- The other party to each P2P trade, what is needed to pay.
- Other users: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your Pitiklini ID, as explained in "What data about you do other people see?".
- Companies that provide services to us (processors): they only process data on our instructions.
| Company | Service | Location of the data |
|---|---|---|
| GotoSend Technologies S.L. (Spain) | Develops and maintains the Platform on our behalf, with access to its systems | European Union |
| Hostinger International Ltd. (Cyprus) | The Platform's server and the support email mailbox | European Union |
| MongoDB Limited (Ireland) | The database | European Union (Paris, France) |
| Functional Software, Inc. (Sentry, United States) | Error reports and, if you agree, the recording of the app screen and the measurement of the app's performance | European Union (Frankfurt, Germany); its technical support, from the United States |
| Plus Five Five, Inc. (Resend, United States) | Sending emails | United States |
| Twilio (United States) | Sending security text messages | United States |
| Cloudinary (Israel and United States) | Storing images and dispute files | United States |
- While the previous app remains in use, when you open it your browser requests typefaces, styles and icons from jsDelivr, cdnfonts and Font Awesome, and prices from CryptoCompare when you post a P2P ad. Those companies receive your IP address and your browser's technical details, as any website you visit does. The new app does not use them.
- Courts, authorities and supervisors, when the law requires it, and the Spanish Tax Agency if a rule requires us to report to it.
- Advisers (lawyers, auditors), bound by confidentiality, and the buyer or successor if the company were sold or merged (LOPDGDD, Article 21).
We do not sell your data or disclose it to anyone for advertising.
Do we transfer your data outside the European Union?
Yes, to the United States and to Israel, with the following safeguards:
- United States: Sentry, Resend, Twilio, Cloudinary and MongoDB are on the EU-US Data Privacy Framework list (Commission Implementing Decision (EU) 2023/1795). We checked this on 25 September 2026 on the official list, and we will check it again whenever it changes. In addition, with each of them we use the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), in case the Framework ceases to be valid.
- Israel has an adequacy decision from the European Commission (Decision 2011/61/EU).
You can ask us for a free copy of these safeguards at soporte@pitiklini.com.
How long will we keep your data?
We use each piece of data while it is needed. When it is no longer needed but the law requires us to keep it, we block it: nobody can use it or see it, and it is only made available to courts, prosecutors or authorities to establish any liability that may exist, for as long as that liability can be claimed (LOPDGDD, Article 32; this restriction of access is required by Spanish law). After that period, we delete it.
| Data | Retention period |
|---|---|
| Your Account and your profile | While you keep your Account. After the Account is cancelled, blocked for five years (Spanish Civil Code, Article 1964) |
| Trades, movements and fees | Six years from the last entry of the financial year (Spanish Commercial Code, Article 30) |
| Login history | One year from each login |
| Two-step verification secret | While you keep it enabled |
| Recognised browsers | They are recognised for one year from the last login from each one; those past that period are deleted the next time you log in |
| Passkeys | Until you delete them; they are deleted when the Account is cancelled |
| Previous nicknames | For the reservation period set by the Platform; then they are deleted automatically |
| Address book, with the holders of the addresses | While you keep them in the address book; the details of each withdrawal, six years from the last entry of the financial year, like the other movements |
| Transfers between people on Pitiklini, with the names of both | Six years from the last entry of the financial year, like the other movements |
| Your home address for withdrawing euros | While you keep your Account; after it is cancelled, blocked for five years |
| P2P messages, trades and disputes | Five years from the end of the trade |
| P2P payment accounts | While you keep them saved; if you delete them, only within the trades in which they were used |
| Verified name | While you keep your Account; after it is cancelled, blocked for five years |
| Support requests and accessibility reports | One year after they are closed |
| Complaints | Five years after they are resolved |
| Reports about ads | One year from the decision |
| Error reports, screen recordings and performance measurements | Up to 90 days, in Sentry |
| Server logs (with the IP address) | Fourteen days |
| Visit statistics (aggregate, with the IP address truncated) | Up to 25 months |
| Backups | Fourteen days: deleted data remains in them for that time |
| What the entity that provides the Crypto-Asset Services keeps | The periods in its privacy policy. The law requires it to keep identity verification data for ten years (Spanish Law 10/2010, Article 25) |
What data is recorded on the blockchain?
When you deposit or withdraw crypto, the transaction is recorded on the blockchain of the relevant network, which is public and does not allow records to be changed or deleted. That record does not include your name, but the address and the amount are visible to anyone. What we do delete, when the time comes, is the information that links that transaction to you in our systems.
What are your rights and how can you exercise them?
You can exercise the following rights at any time:
- access to your data and to information about how we process it;
- rectification, if it is inaccurate or incomplete (you can correct much of it yourself in your profile);
- erasure, when it is no longer needed or there is no legal basis for processing it;
- restriction of processing, in the cases provided for by law;
- portability: receiving the data you gave us in a commonly used format, when we process it under a contract or with your consent;
- withdrawal of consent, without affecting the processing carried out before the withdrawal;
- not being subject to automated decisions with legal effects.
Your right to object. You can object at any time, on grounds relating to your particular situation, to our processing of your data based on our legitimate interest: for example, error reports, the anti-fraud rules or your visits being counted in the statistics. You can do so by writing to soporte@pitiklini.com. We will stop unless we have compelling legitimate grounds that override yours or we need the data to defend ourselves against a claim (GDPR, Article 21). As the statistics do not allow us to identify you, to stop counting your visits we will need you to tell us the IP address you visit the website from (GDPR, Article 11).
How to exercise them: you can write to soporte@pitiklini.com from your Account's email address or tell us how we can verify your identity. You can also do so through a representative. Exercising these rights is free of charge. We will reply within one month; if the request is complex or we receive a large number of requests, we may extend this period by two further months, and we will inform you of this within the first month (GDPR, Article 12).
Limits: we cannot delete data that the law requires us to keep (it stays blocked, as explained above). The entity that provides the Crypto-Asset Services handles requests about the data it processes on its own account; if you send such a request to us, we will pass it on.
How do we protect your data?
All connections between your browser and our servers are encrypted. Passwords are stored as a hash, and payment accounts, verified names, the holders of the addresses in your address book, the names in transfers, your home address and backups are stored encrypted. Of the browsers we recognise we only keep a fingerprint and, of your passkeys, the public part. Two-step verification protects your Account, and our team's access to data is limited according to each person's role and logged. More information, and the measures you can take yourself, is available under Security.
Do we process the data of minors?
The Platform is intended exclusively for people aged 18 or over. If we become aware that an Account belongs to a minor, we will cancel it and delete the minor's data, except the data that the law requires us to keep, which will remain blocked.
How will we inform you of changes to this policy?
We will publish each new version with the date from which it applies and a summary of the changes. Earlier versions will remain available at the bottom of this page. If a change affects you significantly, we will notify you in advance by email or in the app, stating its date and what it means for you.
How can you contact us or make a complaint?
For any matter relating to your data, you can write to soporte@pitiklini.com or, by post, to Calle La Alhondiga, 23, en Los Realejos (Tenerife).
If you consider that we have not handled your data properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), through its online office, or with the data protection authority of the European Union country where you live, work or where the alleged infringement took place (GDPR, Article 77). We would appreciate it if you contacted us first, so that we can try to resolve the matter.
Versions of this document
Each change is published as a new version, with the date it takes effect. Previous versions are kept exactly as they were published.
Version 6 · · current
The app no longer records the screen when it fails or measures its performance, which were the only processing based on your consent: they are removed from the purposes, the legal basis, what Sentry receives and the retention periods, and with them the right to withdraw consent. We also explain what our server sends to Sentry for some of the requests it receives, how long it takes to answer them, without your name, your email address, your IP address or what you send, based on our legitimate interest in the Platform working properly.
Version 5 ·
It covers data that the Platform already processes and that the policy did not mention: your nickname, which you can change, and your Pitiklini ID; your passkeys (only their public part: your fingerprint or your face never leaves your device) and the browsers you log in from, to alert you to a login from a new one; when you send crypto-assets, whose the destination address is or whom you send them to within Pitiklini, as required by Regulation (EU) 2023/1113; and, when you withdraw euros, your home address. With their purpose, legal basis and retention period. It explains what other people see: your P2P profile, which is public, and, in a transfer between people on Pitiklini, your nickname and your ID, never your name or your email address. And the paragraph on the basic details requested before verifying your identity is removed: they are no longer requested and those stored have been deleted.
The legal basis for handling accessibility reports changes: performance of the contract if you have an Account and, otherwise, our legitimate interest in ensuring that anyone can use the Platform. It was previously a legal obligation that does not apply to Pitiklini as a micro-enterprise.
Server logs, kept for fourteen days for the security of the Platform, are added, together with the visit statistics we produce from them, with the IP address truncated and kept for up to 25 months, including their legal basis and how to object. It is clarified that Sentry does not store the IP address.
Drafting review: formal register, defined terms and a clearer presentation of who provides each service. Rights and obligations do not change.
First published version.