Effective Date: 24 September 2025
Baltex Privacy Policy
Last Updated: 24 September 2025
1. Who we are & scope
This Privacy Policy explains how Baltex ("Baltex," "we," "us," "our") handles personal information when you use our website, app, widgets, APIs, and related services (the "Services").
- Controller: Baltex (GGWP Limited)
- Contact: [email protected]
2. What we collect
We don’t require account registration to use swaps. Depending on how you use the Services, we may collect:
- You provide: email and message content sent to support; identity and verification details only if KYC/AML is required (e.g., ID, selfie/liveness, proof of address, payment-method ownership, source-of-funds).
- Automatic: IP address, device/browser data, language, basic location (city/region), usage and event logs, error diagnostics, cookie/SDK identifiers.
- On-chain: wallet addresses you submit, transaction IDs, asset/network metadata (note: blockchains are public).
- From partners (where applicable): payment authorization/settlement results, fraud/risk signals, sanctions/PEP screening results.
3. Why we use data
We use information to:
- deliver and operate the Services, process swaps/fiat flows, and provide support;
- meet legal obligations (e.g., KYC/AML, sanctions screening, recordkeeping);
- secure the platform (fraud/abuse prevention, troubleshooting, analytics to improve reliability);
- send service communications (and, with consent where required, optional updates or marketing).
We do not sell personal information and we don’t use it for cross-context behavioral advertising without consent where required.
4. Legal bases (EEA/UK)
We process data when one or more of these applies: contract, legitimate interests (e.g., security, service improvement), legal obligation (e.g., AML/KYC), consent (e.g., certain cookies/marketing).
5. Sharing
We share data only as needed with:
- service providers/processors: hosting, security, analytics, communications, customer support;
- compliance & payments: identity/KYC vendors, sanctions/PEP/fraud screening, card acquirers/processors, banks/e-money institutions, chargeback/refund handlers;
- authorities when legally required or to protect users, our rights, or the public.
Recipients must use data only for our stated purposes and protect it appropriately.
6. Cookies & similar tech
We use cookies/SDKs to run the site, keep sessions secure, and measure performance. You can control non-essential cookies in your browser and (where available) our cookie preferences tool. Some features may not work without certain cookies.
7. Data retention
We keep data only as long as needed for the purposes above and to comply with law. Typical examples:
- KYC/AML & transaction records: 5–10 years (jurisdiction-dependent);
- Support tickets: up to 24 months after resolution;
- Marketing contacts: until you unsubscribe or withdraw consent.
Blockchain records are public and may persist indefinitely.
8. Security
We use technical and organizational measures such as encryption in transit, access controls, logging, and vendor due-diligence. No method is 100% secure, but we work to protect your data.
9. International transfers
Where data moves outside your country, we use appropriate safeguards (e.g., EU Standard Contractual Clauses or UK equivalents) plus technical/organizational measures.
10. Your privacy choices & rights
- Choices: unsubscribe from emails; manage cookie preferences; contact us with questions.
- EEA/UK rights: access, rectify, erase, restrict, portability, object; withdraw consent; complaint to your supervisory authority.
- US (e.g., California, Virginia, Colorado): access/know, delete, correct; opt-out of “sale”/“sharing” for targeted ads; limit use of sensitive data; non-discrimination.
How to exercise: email [email protected]. We may need to verify your request; authorized agents supported where law allows.
11. Children
The Services are not intended for individuals under 18. If you believe a minor provided data, contact us to request deletion.
12. Automated safeguards
We use automated checks (e.g., fraud, sanctions/AML screening). These may affect your ability to complete a transaction. Where required, you may request human review.
13. Third-party sites & blockchains
Links to other sites are governed by their policies. On-chain activity is public and may be analyzed by third parties outside our control.
14. Changes to this Policy
We may update this Policy to reflect changes in law or our Services. We’ll post the updated version with a new Last Updated date.