PRIVACY POLICY AND GDPR COMPLIANCE

Last updated: May 2026

This Privacy Policy describes how FISKL SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ collects, uses, processes, and protects your personal data when you visit our website, use our cryptocurrency exchange services, or interact with us. We are fully committed to protecting your privacy in strict compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Polish Act on the Protection of Personal Data.

1. Data Controller Identity

The data controller responsible for your personal data is:

FISKL SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Registered Office: ul. DAJWÓR, nr 14, lok. 19, 31-052 KRAKÓW, POLSKA
National Court Register Number (KRS): 0001048293
Tax Identification Number (NIP): 6762647430
Statistical Number (REGON): 525932504
Official VASP Registration Number: RDWW-1093

For any questions regarding data protection, you can contact our compliance department via the official corporate communication channels provided on this website.

2. Categories of Personal Data We Collect

To provide our licensed financial intermediation and virtual asset exchange services, and to meet mandatory anti-money laundering (AML) requirements, we collect the following categories of data:

  • Identification Data: Full name, date of birth, nationality, gender, and copy of passport or government-issued identification document.
  • Contact Information: Residential address, corporate email address, and corporate phone number.
  • Financial Data: Bank account details (including Wise account indicators), cryptocurrency wallet addresses, and transaction histories.
  • Verification Data: Know Your Customer (KYC) documentation, proof of address, source of funds declarations, and internal AML screening records.
  • Technical Logs: IP address, device type, operating system, browser data, and website usage statistics collected via infrastructure logs.

3. Legal Basis and Purposes of Data Processing

We process your personal data under the following legal frameworks:

  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): To fulfill strict mandatory duties under the Polish Act on Counteracting Money Laundering and Terrorist Financing, including user identification, transaction monitoring, and regulatory reporting to tax and judicial authorities (KAS/IAS Katowice).
  • Performance of a Contract (Art. 6(1)(b) GDPR): To process, execute, and settle your cryptocurrency exchange requests (crypto-to-fiat and crypto-to-crypto).
  • Legitimate Interests (Art. 6(1)(f) GDPR): To maintain network security, prevent fraudulent activities, manage corporate risks, and optimize the operational features of the website.

4. Data Retention Period

Your personal data will not be kept longer than necessary for the purposes for which it was collected. In accordance with statutory financial and AML regulations in Poland, identification data and financial transaction records must be safely stored for a minimum period of 5 years starting from the end of the corporate relationship or the date of the specific transaction.

5. Disclosure and Third-Party Data Transfers

We do not sell or rent your data to third parties. Your data may be disclosed only to the following trusted categories of recipients:

  • State Authorities: Polish and European financial regulators, tax administrations, courts, and law enforcement bodies when legally requested.
  • Technical Providers: Regulated infrastructure services, hosting entities (site.eu), and operational crypto platforms (Binance, KuCoin) strictly to execute trading activities and secure data processing.
  • Financial Institutions: Partner payment systems (including Wise) for the processing of corporate and C2B transaction settlements.

All personal data is processed and stored within the borders of the European Economic Area (EEA), ensuring complete alignment with GDPR standards.

6. Your Rights Under GDPR

As a data subject, you possess the following legal rights regarding your personal information:

  • Right of Access: You can request a confirmation and a copy of the personal data we hold about you.
  • Right to Rectification: You can request the correction of inaccurate or incomplete corporate or personal details.
  • Right to Erasure (“Right to be Forgotten”): You can request the deletion of your data, provided it is no longer required for statutory compliance or legal processing obligations.
  • Right to Restriction of Processing: You can request that we restrict data usage under certain legal conditions.
  • Right to Data Portability: You can request to receive your data in a structured, commonly used electronic format.

To exercise your rights, please submit a written request to our office. You also have the legal right to lodge an official complaint with the Polish data protection authority: Urząd Ochrony Danych Osobowych (UODO), Warsaw, Poland.