Privacy Policy UAB Belela

1. INTRODUCTION

1.1. In this document ("Privacy Policy"), you will be informed about who we are, how we process your personal data, the specific purposes for processing, and your rights with regards to your personal data when using the token.com application (referred to as the "Platform").

1.2. This Privacy Policy (together with Terms of Use) applies to your use of the Platform when using the services to exchange fiat and digital assets. Please read it carefully to understand the practices regarding your personal data and how we will treat it.

1.3 Over 18s only. The Platform is intended for all persons over 18 years of age and we do not knowingly collect data relating to under 18s. If you, as a parent or guardian, become aware that your child under the age of 18  has access to the Platform and its resources, you must contact dpo@token.com and request the deletion of your child’s data. 

1.4. Changes to our Privacy Policy and your duty to inform us of changes. From time to time, we may make changes to this Privacy Policy, including to add new features to the Platform or to implement changes as a result of legislative changes. In any case, you will be notified in advance and will have the opportunity to assess whether you wish to continue (or not) to use the services made available through the Platform. If you do not wish to continue using our services, you must terminate your account and uninstall the application, if applicable. 

It is important that the personal data that we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you.

2. WHO WE ARE

2.1. The Platform is offered by Token.com Limited, but services related to fiat and virtual asset exchanges are facilitated by UAB Belela.

2.2. When we mention UAB Belela, we are referring to the company responsible for processing your data as a Joint Controller, together with Token.com Limited. To streamline communication, a Data Protection Officer (DPO) has been appointed for both entities, whom you may contact with questions regarding this Privacy Policy and to facilitate requests in relation to your Personal Data on the Platform. Please contact the DPO using the details provided below:

2.3. Contact Details:
Email address for DPO: dpo@token.com
Registration address: UAB Belela, Architektu g. 56-101 04111, Vilnius, Lithuania

You have the right to make a complaint at any time to your national Data Protection Authority in the EU and the UK.

3. WHAT INFORMATION DO WE COLLECT

We may collect, use, store and transfer different kinds of personal data about you as follows:

  • Identity data

  • Contact data

  • Financial data

  • Transaction data

  • Device data

  • Content data

  • Profile data

  • Usage data

  • Marketing and communications data

  • Location data     

We may also process special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, biometric data, and health and genetic information). We may also be required to collect information about criminal convictions and offences.                  

3.1. HOW IS YOUR PERSONAL DATA COLLECTED

We collect certain information directly from users, such as information entered by the User and information from third-party platforms which the User may use to connect to the Platform. UAB Belela may also automatically collect information about the device used by the User and their interaction with the Platform.

3.1.1. Registration information and information you give to us: In order to access the Platform, it is necessary for the User to provide their personal registration data, such as their name, date of birth, document identification number,  telephone number, email address, as applicable. You consent to giving us this information and also the information you provide to us when you correspond with us, subscribe to any of our services, enter a competition or promotion or survey, when you report a problem with our Platform. If you contact us, we will keep a record of that correspondence.

3.1.2. Information obtained through your device: During the use of the Platform, other information may be obtained by UAB Belela, such as information about: your geographic position, IP address, browser used, cookie information, type and brand of mobile device, identifiers of mobile devices, operating system version, network information, connection provider, Internet used device settings, camera (access to stored images by User on your mobile device and camera for capturing images), software data and permission to send electronic notices, as applicable. We collect this data using cookies and other similar technologies. 

3.1.3. Location Data: We use IP address information to determine your current location. Some of our location enabled- Services require your personal data for the feature to work. If you wish to use the particular feature, you will be asked to consent to your data being used for this purpose. You can withdraw your consent at any time by disabling Location Data in your settings.

3.1.4. User-generated content and User interactions with the Platform: We collect and store information and/or preferences shared by the User while using the Platform. The information stored depends on the degree of User interaction with the resources made available through the Platform.

3.1.5. Banking information: Considering that the Platform allows transfers between the User and the Platform and vice versa, UAB Belela will store the User's bank account data, as applicable. 

3.1.6. Information provided by third parties: If the User chooses to integrate their account on the Platform with social networks or third-party platforms, as available, the Platform may collect and store, among other information, the email address, full name, and profile image, subject to the settings and authorizations given by the User to the third-party platform or integrated social network. 

4. HOW WE USE YOUR INFORMATION

4.1. Your personal data will be stored, in identifiable form in our database, and will only be used when the law allows us to do so for the following purposes. Most commonly, we will use your personal data in the following circumstances:

4.1.1. Where you have consented before the processing;

4.1.2. Where we need to perform a contract we are about to enter or have entered with you;

4.1.3. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;

4.1.4. Where we need to comply with a legal or regulatory obligation.

Purpose for which we will use your personal data

Purpose / Activity: To install the app and register you on the Platform
Type of Data: Identity, Contact details, Financial, Device
Lawful Basis for Processing: Your consent

Purpose / Activity: To process in-app purchases and deliver services offered by the Platform including managing payments, contribution and redemption of values, and collecting money owed to us
Type of Data: Identity, Contact details, Financial, Device, Location, Transaction, Marketing, Communications
Lawful Basis for Processing: Your consent, Performance of a contract with you, Necessary for our legitimate interests (for instance, to recover debts due to us)

Purpose / Activity: To manage our relationship with you including notifying you of any changes to the app or the Platform
Type of Data: Identity, Contact details, Financial, Profile, Marketing, Communications
Lawful Basis for Processing: Your consent, Performance of a contract with you, Necessary for our legitimate interests (for instance, to keep records updated and to analyse how customers use our Platform), Necessary to comply with legal obligations (to inform you of any changes to our terms and conditions)

Purpose / Activity: To enable you to participate in a prize draw, competition, or complete a survey
Type of Data: Identity, Contact details, Device, Profile, Marketing, Communications
Lawful Basis for Processing: Your consent, Performance of a contract with you, Necessary for our legitimate interests (for instance, to analyse how customers use our Platform and to develop them and grow our business)

Purpose / Activity: To administer and protect our business and Platform including troubleshooting, data analysis, system testing, fraud prevention
Type of Data: Identity, Contact details, Device
Lawful Basis for Processing: Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security)

Purpose / Activity: To deliver content and advertisements to you
To personalize customer’s interactive experience with the Platform
To make recommendations to you about products or services which may interest you
To measure and analyse the effectiveness of the advertising we serve you
To monitor trends so we can improve the Platform or to develop new features, products, or services
Type of Data: Identity, Contact details, Device, Content, Profile, Usage, Marketing, Communications, Location
Lawful Basis for Processing: Your consent, Necessary for our legitimate interests (for instance, to develop our products and services, our Platform, and to grow our business)

Purpose / Activity: To comply with legal obligations to collect and share data with public authorities
Type of Data: Identity, Contact details, Financial, Device, Transaction
Lawful Basis for Processing: Necessary to comply with legal obligations

4.2. Some of the information we collect is sensitive personal data, such as Special Categories of Personal Data and criminal convictions and offences. If we use sensitive personal data, we will usually do so on the legal basis that it is in the wider public interest, to establish, take or defend any legal action or, in some cases, that we have your permission. In any case, we will comply with all laws that apply.

Purposes for which we will use Special Categories of / Sensitive Personal Data

Purpose / Activity: To carry out due diligence checks (background checks, such as sanctions checks) which may reveal political opinions or information about criminal convictions or offences
Type of Data: Special categories of personal data, such as political opinions, Criminal convictions or offences
Lawful Basis for Processing: In the wider public interest

Purpose / Activity: To check your identity, to detect and prevent fraud and money laundering
Type of Data: Biometric data
Lawful Basis for Processing: Your consent for optional use of biometrics (such as your vocal pattern in voice recognition systems to identify you), In the wider public interest

Purpose / Activity: To manage and personalize our services, such as needing to receive accessibility assistance for visual or hearing impairments
Type of Data: Medical information, health Information
Lawful Basis for Processing: Your consent, such as placing notes on your accounts which alert us that you need to receive accessibility assistance, In the wider public interest

Purpose / Activity: To comply with laws and regulations that apply to us, and co-operate with regulators and law enforcement organizations
Type of Data: Special categories of personal data, such as biometric data
Lawful Basis for Processing: In the wider public interest

4.3. Disclosures of your personal data

UAB Belela employs service providers to perform certain activities, such as managing and providing databases, verifying identity, collecting payments and cloud hosting. You consent to sharing your personal data with these service providers as set out below for the purposes set out in the table above. Our service providers are aware of and are contractually obliged to comply with the provisions of our Privacy Policy, they cannot use the information made available for other purposes, and only authorized persons are allowed to access the registration information collected     . 

Internal Third Parties: 

  • International Shared Services Limited registered at 101 King's Cross Road, London, England, WC1X 9LP, will receive Identity, Contact details, Financial, Device, Location, Transaction, Marketing, Communications data.

External Third Parties:

  • Acesso Digital Tecnologia da Informação SA, a joint stock company headquartered at Praça General Gentil Falcão, n.º 108, 10º andar, Bairro Cidade Monções, CEP: 04571-150, São Paulo/SP, 05.563.165/0001-95, the company responsible for verifying User data at the time of registration on the Platform, will receive and store your personal and biometric data to promote greater security in the use of your identity and prevent misuse of your data. If you want more information, visit: https://unico.io/privacidade-e-gestao-de-dados/.  

  • SUM AND SUBSTANCE LTD trading as Sumsub registered at 30 St. Mary Axe, London, EC3A 8BF, UNITED KINGDOM, and its affiliates, will receive and store Identity data processed during the onboarding. Sumsub is also used to coordinate verification and screening to authenticate the customer and verify the eligibility to the product. 

  • SEON Technologies Kft. trading as SEON, registered at Rákóczi út 42, 1072 Budapest, Hungary, and its affiliates, will receive and process Contact and Device data from the registration for the fraud prevention service. 

  • Nuvei Limited registered office at 9 Kafkasou, Aglantzia, CY 2112, Nicosia, Cyprus     will receive and process Financial Data as required to make a purchase or sale using the Platform.

  • Intercom R&D Unlimited Company, an Irish company with offices at 2nd Floor, Stephen Court, 18-21 St. Stephen’s Green, Dublin 2, Republic of Ireland, will receive Contact data to provide customer support.

  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Policy.

  • Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.

  • Regulators and other authorities who require reporting of processing activities.

Except for the situations described above and in accordance with applicable law, UAB Belela will not disclose user information without your prior and express consent. However, we reserve the right to provide users' data and information in response to administrative and/or judicial proceedings of any nature, or when required by authorities to comply with applicable law. 

4.4. If the User has agreed, you will receive communications containing promotional materials about the services provided. If the User chooses to stop receiving such communications, you may request to unsubscribe through the link provided in such communications.

4.5. The information and data collected during the User's interaction with the Platform may be used for the preparation of statistics, without any restriction by UAB Belela, as long as it is not possible to identify the User directly or indirectly.

4.6. The User's personal data and information will be stored, in an identifiable way, in our database for the time necessary to comply with the applicable legal obligations and activities provided for in this Privacy Policy, in compliance with applicable law. After carrying out the activities provided for in this Privacy Policy and other legal obligations, the data will be discarded, rendered useless and/or anonymized.

5.REGISTRATION ON THE PLATFORM

5.1. In order to access the restricted content area of ​​the Platform and the functionalities available on our Platform, it is necessary for the User to register and provide the registration information. 

5.2. The basic registration may be carried out in 2 (two) ways: (i) by providing the information contained in item 6.4; or (ii) synchronizing the Platform with your account on a social network, informing login and password, in addition to other necessary registration information, provided for in item 6.4 below (available only for Apple, Google and Facebook). If the User opts for synchronization, the social network will make available to the Platform the User's e-mail address, full name, age, profile picture, telephone number and date of birth . The process of integrating the Platform with the chosen social network will not give UAB Belela access to other information made available by the User on said social network, such as, for example, password to access the social network, publications or friends list. 

5.3. It is the User's responsibility to correctly fill in the data, as well as to keep their registration information updated. UAB Belela is not responsible for errors or mistakes in filling out the User's registration. The User may, at any time, correct and update the data reported to the Platform by sending an email to the address dpo@token.com.

6. USE OF COOKIES

6.1. Cookies (“Cookies”) are simple text files that are transferred to the device used by the User to access the platform and have several functions, such as storing basic information, memorizing the User's preferences and facilitating navigability.

6.2. During the use of the Platform, Cookies may capture information such as geographic location, IP address, operating system version, network information and software data. 

6.3. If the User does not agree with the use of Cookies, he must adjust his settings to not allow the use of Cookies. The User understands and agrees that by disabling Cookies, the Platform functionality may be affected.

6.4. What we use Cookies for:

6.4.1. Improve navigation and features offered by the Platform; 

6.4.2. Collect information about how the User uses the Platform to provide better navigability;

6.4.3. Provide a personalized experience to the User; and

Provide targeted advertising. 

7. YOUR LEGAL RIGHTS

7.1 Under certain circumstances, Users will have the following rights under data protection laws in relation to your personal data:

  • Right to request access to your personal data

  • Right to request correction of your personal data

  • Right to request erasure of your personal data

  • Right to object to processing of your personal data

  • Right to request restriction of processing your personal data

  • Right to request transfer of your personal data

  • Right to withdraw consent

  • Right to ask us not to continue to process your personal data for marketing purposes

Please see the Glossary (see YOUR LEGAL RIGHTS) to find out more about these rights.

You can exercise any of these right at any time by contacting us at dpo@token.com

8. INFORMATION SECURITY

8.1. All the User's personal data is identified in your account and is protected by the password chosen by you at the time when the registration on the Platform was carried out. User is responsible for keeping your password confidential. We ask you not to share your password with anyone.

8.2. Your personal data and information security is reinforced by effective protection mechanisms, such as encryption, security devices, access protocols, firewall and secure web environment. Any payment transactions carried out by UAB Belela or our chosen third-party provider of payment processing services will be encrypted using Secured Sockets Layer technology.

8.3. The custody of the User's information will be maintained by a server chosen by UAB Belela, which must observe the security and reliability aspects required by applicable law. 

8.4. Despite adopting high levels of security for the protection of the data and information collected, it is important that users are aware that, due to the very nature and technical characteristics of the Internet, there is always the risk that unauthorized third parties, in some way, may be able to violate these protection mechanisms and have access to such information, which is why UAB Belela cannot guarantee complete privacy and security in the use of the Platform or in the storage of data.

8.5. The data and information that may be stored or archived on external servers are subject to the same security principles adopted by UAB Belela through contractually binding our suppliers and partners to respect our Privacy Policy.

8.6. UAB Belela has put in place procedures to deal with any suspected personal data breach. In the event of a personal data breach, UAB Belela will notify the User and any applicable regulator when we are legally required to do so.

8.7. The security measures described above apply to your personal data only from the moment UAB Belela receives it and while keeping it in its custody. The functioning and security of the device you use to access the Platform, as well as the network over which your personal data travels, is not the responsibility of UAB Belela. In order to ensure a more secure environment, UAB Belela suggests (without guaranteeing against incidents) that you respect the following basic security precautions:

  • Do not trust strange emails;

  • Do not access suspicious websites;

  • Keep protection mechanisms active and updated, such as antivirus and anti-malware; 

  • Do not install applications or programs from strange or illegal sources; and

  • Do not access “promotional content” from unknown sources.

9. DATA RETENTION

9.1. Details of retention periods for different aspects of your personal data are available in our retention policy which you can request by contacting us. 

9.2. By law, we have to keep basic information about Users (including Contact, Identity, Financial and Transaction Data) for a period of 8 years after the cessation of the business relationship or the last transaction (whichever is the latest). The communication with the client is stored for 5 years after the end of the business relationship or the last contact (whichever is the latest).      

9.3. In some circumstances you can ask us to delete your data: see YOUR LEGAL RIGHTS for further information.

9.4. In some circumstances we will anonymise your personal data so that it can no longer be associated with you for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

9.5. If you do not use the Platform for a period of 8 years then we will treat your account as expired and your personal data may be deleted.

10. SERVICES OFFERED BY THIRD PARTIES

This Privacy Policy is not applicable to other platforms, services or social networks, even if they are directly or indirectly linked to the Platform or UAB Belela. Please note that these third party platforms, services and social networks have their own privacy policies and we do not accept any responsibility for these policies or for any personal data that may be collected by these third parties. UAB Belela recommends that the User carefully read the terms of use and the privacy policy of other platforms, services or social networks they use.

11. INTERNATIONAL TRANSFERS

11.1. Many of our third party service providers are based outside the EU and the UK so their processing of your personal data will involve a transfer of data outside the EU and UK. 

11.2. Whenever we transfer your personal data out of the EU and the UK, we ensure a similar degree of protection is afforded to it by ensuring that the following safeguard is implemented. We use specific contracts approved by the EU and UK which give personal data the same protection it has in the EU and UK.

11.3. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EU and UK.

Glossary

LAWFUL BASIS

Consent means processing your personal data where you have signified your agreement by a statement or clear opt-in to processing for a specific purpose. Consent will only be valid if it is a freely given, specific, informed and unambiguous indication of what you want. You can withdraw your consent at any time by contacting us. 

Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to. 

YOUR LEGAL RIGHTS

You have the right to:

  • Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

    _if you want us to establish the data's accuracy;

    _where our use of the data is unlawful but you do not want us to erase it;

    _where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or

    _you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

DESCRIPTION OF CATEGORIES OF PERSONAL DATA

  • Identity Data: first name, last name, maiden name, username or similar identifier, marital status, title, date of birth, gender, nationality, identity document, selfie      .      

  • Contact Data: billing address, residential address, email address and telephone numbers, proof of address.

  • Financial Data: bank account, payment card details and income tax return (if applicable), documents relevant to sources of funds or sources of wealth verification (if applicable)     

  • Transaction Data: includes details about payments to and from you and details of in-App purchases and purchases on or through our Platform. 

  • Device Data: includes the type of device you use, a unique device identifier (for example, your Device's IMEI number, the MAC address of the Device's wireless network interface, or the mobile phone number used by the Device), mobile network information, your mobile operating system, the type of browser you use, time zone setting, device Manufacturer and Model, Device Language, IP Address, Device Memory, and display configuration.

  • Content Data: includes information stored on your Device, including friends' lists, login information, photos, videos or other digital content, check-ins.

  • Profile Data: includes your username and password, purchase history, your interests, preferences, feedback and survey responses.

  • Usage Data: includes details of your use of any of our services, app or our Platform including, but not limited to, traffic data and other communication data, whether this is required for our own billing purposes or otherwise and the resources that you access.

  • Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences. 

  • Location Data: includes your current location disclosed by IP.     -