Privacy Policy

Version 2.0 (draft)Last updated: 29 September 2026

Text to be validated by legal counsel

This is a first draft of the document for Coinbar s. r. o. under Slovak and EU law. It has not yet been reviewed by legal counsel; the items in square brackets are still to be completed.

This policy tells you, as required by Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and by the Slovak Data Protection Act (zákon č. 18/2018 Z. z. o ochrane osobných údajov), how Coinbar s. r. o. processes your personal data.

The Slovak version of this document is the legally binding one. The English and Italian versions are translations provided for information only.

1. Controller and data protection officer

The controller of your personal data is Coinbar s. r. o. ("Coinbar"), a crypto-asset service provider under Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (MiCA), supervised by Národná banka Slovenska (NBS). This policy covers the personal data Coinbar processes when you visit the Coinbar website, use the Coinbar app, open and use an account, or contact Coinbar.

Company name
Coinbar s. r. o.
Legal form
limited liability company (spoločnosť s ručením obmedzeným)
Commercial register entry
IČO 57 695 415 — Mestský súd Bratislava III, Oddiel: Sro, vložka č. 200646/B
Registered office
Krajná 17137/7C, 821 04 Bratislava-Ružinov, Slovakia
Competent authority
Národná banka Slovenska (NBS), Imricha Karvaša 1, 813 25 Bratislava
Data protection e-mail
[email protected]

Data protection officer (Articles 37–39 GDPR)

Name
[TO BE COMPLETED: name of the data protection officer]
Postal address
Coinbar s. r. o., for the attention of the data protection officer, Krajná 17137/7C, 821 04 Bratislava-Ružinov, Slovakia

You can contact the data protection officer with any question about the processing of your personal data and about the exercise of your rights.

2. Personal data we process

Depending on the services you use, Coinbar processes the following categories of personal data:

Identification data and KYC documents

  • first name, surname, date and place of birth, nationality, national identification number and address of permanent residence
  • type, number, issuing country, date of issue and expiry date of your identity document, and images of its front and back
  • answers to the due diligence questionnaire: occupation, source of funds and source of wealth, purpose of the business relationship, expected volume and whether you are a politically exposed person (PEP)

Selfie and biometric data

  • images of your face taken during the identity check while you perform, in front of the camera, a movement chosen at random by the app (liveness check)
  • biometric data derived from those images to compare your face with the photograph in your identity document (face match) and to detect attempts to deceive the check

Contact data

  • e-mail address, telephone number and preferred language

Data on business clients (KYB)

  • name, registration number, registered office and business of the company, purpose of the business relationship and source of funds
  • identification data and identity documents of the beneficial owners and of the persons authorised to act for the company, their ownership or control and PEP status

Financial and transaction data

  • positions in custody, Coinbar Direct exchanges, deposits and withdrawals, with amounts, prices, fees and times
  • data on the SEPA transfers you send to Coinbar through Verifo: name of the payer, IBAN, payment reference and amount
  • crypto-asset addresses used for deposits and withdrawals, and the identifiers of the transactions on the blockchain
  • Travel Rule data: data on the originator and the beneficiary of transfers to or from other crypto-asset service providers and, according to the threshold in force (the app tells you before you confirm), the beneficiary details and your confirmation that you own or control a self-hosted address

Tax data

  • country of tax residence and tax identification number, which Coinbar must collect and report under zákon č. 359/2015 Z. z. o automatickej výmene informácií o finančných účtoch (the Slovak act transposing DAC8)

Screening and risk data

  • results of screening against sanctions lists, lists of politically exposed persons and adverse media (LSEG World-Check One), including ongoing and periodic re-screening
  • results of blockchain analytics on the addresses and transactions linked to your account (Crystal Intelligence)
  • your anti-money-laundering risk profile and your account tier

Device, log and security data

  • IP address, device and browser identifiers, login history and active sessions
  • multi-factor authentication settings and security events on your account
  • records of the actions carried out on your account (audit records)

Communications

  • support requests, complaints and related correspondence
  • your marketing preferences and consents

The identity check (liveness and face match) is performed by Coinbar’s own software. It is not a certified identity verification solution and never leads to an automatic rejection: if the check fails or is inconclusive, your application is reviewed manually by a member of Coinbar’s staff.

3. Purposes and legal bases

Coinbar processes personal data only for specified purposes and on one of the legal bases of Article 6(1) GDPR:

Performance of the contract – Article 6(1)(b) GDPR

Processing necessary to conclude the contract with you and to provide the services:

  • opening and managing your account and signing you in, including multi-factor authentication
  • custody and administration of crypto-assets, exchange through Coinbar Direct and transfer services, including confirmations and statements of positions
  • receiving your EUR transfers through Verifo and exchanging them into EURC on the basis of your prior consent to automatic exchange
  • customer support and service communications

Legal obligations – Article 6(1)(c) GDPR

Processing that the law requires Coinbar to carry out:

  • customer due diligence, enhanced due diligence, monitoring of transactions and reporting of unusual transactions to the Finančná spravodajská jednotka Prezídia Policajného zboru (the Slovak financial intelligence unit) under the Slovak Anti-Money Laundering Act (zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu)
  • obligations of a crypto-asset service provider under MiCA, including record-keeping, custody records and complaints handling
  • transmitting and receiving Travel Rule information under Regulation (EU) 2023/1113 of the European Parliament and of the Council on information accompanying transfers of funds and certain crypto-assets (Transfer of Funds Regulation)
  • collecting and reporting data on crypto-asset users and their transactions to the Slovak Financial Administration (Finančná správa SR) under DAC8
  • keeping accounting records under the Slovak Accounting Act (zákon č. 431/2002 Z. z. o účtovníctve)
  • managing ICT risks and incidents under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • answering requests from NBS, the courts and other public authorities

Legitimate interests – Article 6(1)(f) GDPR

Processing necessary for Coinbar’s legitimate interests, which Coinbar has weighed against your interests and rights (you can object to it, see section 10):

  • security of the platform, of accounts and of the crypto-assets in custody; detection and prevention of fraud and account takeover
  • establishment, exercise and defence of legal claims
  • internal control, audit and the integrity of records

Consent – Article 6(1)(a) GDPR

Processing based on your consent, which you can withdraw at any time without affecting the lawfulness of processing before the withdrawal:

  • marketing communications
  • non-essential cookies (see section 13)

Biometric data – Article 9 GDPR

Biometric data processed to identify a person uniquely belong to the special categories of personal data. Coinbar processes them for the liveness and face-match check only on the basis of your explicit consent (Article 9(2)(a) GDPR), which the app asks for before the check.

You are not obliged to give that consent. If you do not give it, or withdraw it before the check, your identity is verified instead through a manual review carried out by a member of Coinbar’s staff.

Providing identification data, KYC or KYB data, tax residence data and Travel Rule data is a legal requirement: without them Coinbar cannot open an account for you or carry out the transaction concerned. Consent to marketing and to non-essential cookies is voluntary.

4. Sources of personal data

Most personal data come directly from you. Coinbar also obtains personal data from the following sources (Article 14 GDPR):

  • LSEG World-Check One: matches with sanctions lists, lists of politically exposed persons and adverse media, compiled from public sources
  • public blockchains and Crystal Intelligence: the transactions of the addresses linked to your account and the risk analysis of their counterparties
  • other crypto-asset service providers, through the Travel Rule: data on the originator of the transfers you receive
  • Verifo UAB: the data of the SEPA transfers you send with your Coinbar deposit reference (name of the payer, IBAN, payment reference)
  • for business clients, the persons acting for the company: the data of beneficial owners and authorised persons

5. Recipients

Coinbar discloses personal data only to the extent necessary for the purposes above, to the following recipients:

Service providers processing data on Coinbar’s behalf

RecipientServiceData
Amazon Web Services (AWS)hosting of the platform; user authentication (Amazon Cognito)data processed by the platform; sign-in data
Fireblockscustody technology: MPC wallets, signing and monitoring of transactionsaddresses, transactions, internal account identifiers
LSEG (Refinitiv World-Check One)screening against sanctions, PEP lists and adverse mediaidentification data needed for screening, such as name, date of birth and nationality
Crystal Intelligenceblockchain analyticsaddresses and transaction identifiers
NotaBeneexchange of Travel Rule information with other providers (IVMS101 standard)Travel Rule data on originators and beneficiaries

Independent recipients and public authorities

RecipientPurpose
Verifo UAB (electronic money institution, Lithuania)keeps the client-funds account that receives your SEPA transfers
other crypto-asset service providersprovider of the originator or of the beneficiary of your transfers (Travel Rule)
Národná banka Slovenska (NBS)supervision of Coinbar under MiCA
Finančná spravodajská jednotka Prezídia Policajného zborureports of unusual transactions and requests in the field of anti-money laundering
Finančná správa SR (Slovak Financial Administration)reporting of data on crypto-asset users and their transactions (DAC8)
courts, law-enforcement and other public authoritiesonly on a request based on the law

The list of providers and the qualification of each of them as processor or independent controller are to be validated: [TO BE COMPLETED: full register of processors and sub-processors].

Kraken, CoinMarketCap, LiveCoinWatch and CoinGecko are used only as sources of market prices: Coinbar sends them no personal data.

6. Transfers outside the EEA

Coinbar processes personal data primarily in the European Economic Area (EEA). Some service providers, or their sub-processors, may process data in countries outside the EEA.

Such transfers take place only in accordance with Articles 44–49 GDPR:

  • to a country for which the European Commission has adopted an adequacy decision – for recipients in the United States, where applicable, under the EU–US Data Privacy Framework, if the recipient is certified under it
  • or on the basis of appropriate safeguards, in particular the standard contractual clauses adopted by the European Commission, with supplementary measures where needed
  • derogations for specific situations only exceptionally and where the GDPR allows them

Mechanism used for each provider: [TO BE COMPLETED: transfer mechanism per provider (adequacy decision, Data Privacy Framework or standard contractual clauses)]. You can ask for information on the safeguards and for a copy of them at [email protected].

7. Retention periods

Coinbar keeps personal data only for as long as necessary for the purpose for which they were collected, or for as long as the law requires:

DataRetention period
Customer due diligence file: identification data, KYC and KYB documents, selfie, screening results and risk assessment5 years from the end of the business relationship, i.e. from the closure of the account (§ 19 of zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu); longer if the Finančná spravodajská jednotka Prezídia Policajného zboru requests it
Records of individual transactions and Travel Rule data5 years from the date of the transaction (§ 19 of zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu); longer if the Finančná spravodajská jednotka Prezídia Policajného zboru requests it
Biometric data derived for the liveness and face-match check[TO BE COMPLETED: retention period of biometric data]
Records kept under MiCA: contracts, consents, services, transactions, statements, communications and complaints5 years; up to 7 years if NBS requests it before the 5 years have elapsed (Art. 68(9) MiCA)
Accounting records10 years after the year to which they relate (§ 35 of zákon č. 431/2002 Z. z. o účtovníctve)
Tax residence data and DAC8 reports[TO BE COMPLETED: retention period under zákon č. 359/2015 Z. z. o automatickej výmene informácií o finančných účtoch]
Marketing preferencesuntil you withdraw your consent
Device, log and security data[TO BE COMPLETED: retention period of logs]

When the period ends, the data are deleted or anonymised, unless they are needed for the establishment, exercise or defence of legal claims or a public authority has ordered that they be kept.

8. Public blockchains and integrity of records

Transactions on public blockchains (Bitcoin, Ethereum, Solana, XRP Ledger) are public and permanent: the addresses, the amount and the time of a transaction can be seen by anyone and cannot be changed or deleted – neither by Coinbar nor by anyone else. Coinbar does not write your name on a public blockchain, but anyone who knows that an address belongs to you can link its transactions to you.

Your rights to rectification and erasure therefore cannot apply to data recorded on a public blockchain; they apply in full to the data Coinbar keeps in its own systems.

To prove that its audit records have not been altered, Coinbar records cryptographic hashes (digital fingerprints) of those records on a private, permissioned ledger that it operates. Only the hashes are recorded there, not the audit records themselves: no personal data is written to that ledger.

9. Automated decision-making and profiling

Coinbar does not take decisions about you based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

Coinbar uses automated tools that support its staff: screening against sanctions lists, PEP lists and adverse media, blockchain analytics, transaction monitoring, the identity check (liveness and face match) and the assessment of your risk profile – a form of profiling that zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu requires. Their results are reviewed by Coinbar’s staff.

Automated checks may hold a transaction until it is reviewed, or stop a transaction that exceeds the limits of your account. Decisions on your application to open an account, on the rejection of a held transaction and on the closure of your account are taken by a member of Coinbar’s staff.

If you believe that a decision about you was taken without human involvement, you can ask for it to be reviewed by a person, express your point of view and contest the decision by writing to [email protected].

10. Your rights

Under Articles 15–22 GDPR you have the following rights:

  • Right of access

    Art. 15 GDPR

    to obtain confirmation of whether Coinbar processes your personal data, a copy of the data and information on the processing

  • Right to rectification

    Art. 16 GDPR

    to have inaccurate data corrected and incomplete data completed; some identification data can be changed only after a new verification of your identity

  • Right to erasure

    Art. 17 GDPR

    to have your data deleted when there is no longer a reason to keep them; data that Coinbar must keep by law are deleted only when the retention period ends

  • Right to restriction of processing

    Art. 18 GDPR

    to have processing restricted, for example while the accuracy of the data is being checked

  • Notification of recipients

    Art. 19 GDPR

    Coinbar informs the recipients of any rectification, erasure or restriction, unless this proves impossible or involves disproportionate effort, and tells you who they are if you ask

  • Right to data portability

    Art. 20 GDPR

    to receive the data you provided, processed by automated means on the basis of your consent or of the contract, in a structured, commonly used and machine-readable format, and to have them transmitted to another controller

  • Right to object

    Art. 21 GDPR

    to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests, and to object to direct marketing without giving reasons

  • Automated individual decisions

    Art. 22 GDPR

    not to be subject to a decision based solely on automated processing that significantly affects you (see section 9)

  • Withdrawal of consent

    Art. 6(1)(a) and Art. 9(2)(a) GDPR

    to withdraw your consent at any time, as easily as you gave it; withdrawal does not affect the lawfulness of processing before it

To exercise your rights, write to [email protected]. Coinbar may ask you to confirm your identity. It replies without undue delay and at the latest within one month of receiving your request; for complex or numerous requests this period may be extended by two further months, in which case you are informed within the first month. Exercising your rights is free of charge.

Your rights may be limited where the law requires it: data subject to a retention obligation cannot be deleted before the period ends, and zákon č. 297/2008 Z. z. o ochrane pred legalizáciou príjmov z trestnej činnosti a o ochrane pred financovaním terorizmu does not allow Coinbar to inform you of a report of an unusual transaction.

11. Complaint to the supervisory authority and judicial remedy

If you believe that the processing of your personal data infringes the law, you have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The supervisory authority in Slovakia is the ÚOOÚ SR:

Supervisory authority (ÚOOÚ SR)
Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27 (https://dataprotection.gov.sk)

You may also lodge the complaint in the EU Member State of your habitual residence, of your place of work or of the place of the alleged infringement.

Without prejudice to the complaint, you have the right to an effective judicial remedy against Coinbar (Article 79 GDPR).

You can also contact Coinbar’s data protection officer first, at [email protected].

12. Security of personal data

Coinbar protects personal data with technical and organisational measures appropriate to the risk, including:

  • custody of crypto-assets with multi-party computation (MPC) technology: no single person can move clients’ crypto-assets alone
  • encryption of personal data at rest and of connections in transit
  • multi-factor authentication for clients and for Coinbar staff
  • role-based access on a need-to-know basis and dual approval (four-eyes principle) for sensitive operations
  • audit records protected against alteration (see section 8)
  • an ICT risk-management framework, testing and incident management under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)

If a personal data breach is likely to result in a risk to your rights and freedoms, Coinbar notifies the ÚOOÚ SR, where feasible within 72 hours of becoming aware of it (Article 33 GDPR), and, where the risk is high, informs you without undue delay (Article 34 GDPR).

Keep your password and your authentication codes secret and do not share them with anyone.

13. Cookies

The Coinbar website and app use cookies and similar technologies. Strictly necessary cookies are used without consent; all others only with your prior consent, which is not a condition for using the service (§ 109 ods. 8 of zákon č. 452/2021 Z. z. o elektronických komunikáciách, the Slovak Electronic Communications Act).

Cookie Policy →

14. Changes to this policy

Coinbar updates this policy when its processing or the law changes. The version and the date of the last update are shown at the top of the page.

Coinbar informs you of material changes in the app or by e-mail before they take effect.

15. Contact

For any question about this policy or about your personal data, contact:

Data protection officer
[email protected]
Customer support
[email protected]
Postal address
Coinbar s. r. o., Krajná 17137/7C, 821 04 Bratislava-Ružinov, Slovakia

Coinbar s. r. o. — crypto-asset service provider supervised by Národná banka Slovenska (NBS)