PRIVACY POLICY
Fra: 1.7.2026INTRODUCTION
Digital Assets d.o.o. (hereinafter referred to as the “Company” , “we” , “us” or “our”) places great importance on the privacy and security of its clients (hereinafter referred to as the “client”, “you” or “your”). Safeguarding our clients’ data is our top priority, and we are committed to maintaining transparency regarding how we collect, process, and protect personal data.
This Privacy Policy (hereinafter referred to as the “Policy”) aims to inform clients about the types of data collected by the Company, the reasons for such collection, and the ways in which the Company processes, stores, or shares client data with third parties. It also provides information about clients’ rights in relation to their personal data.
This Policy forms an integral part of the Company’s General Terms and Conditions. This Policy applies to all Services of the Company, including the Platform, the Mobile Application, and the Branch Offices. The Policy applies to all the ways in which clients come into contact with the Company through these channels, regardless of which channel they use.
The Platform and the Mobile Application may contain links directing clients to websites of other service providers. In such cases, this Policy does not apply.
DATA CONTROLLER
The Company recognizes the importance of protecting and handling clients’ personal data with care. We collect and process data in accordance with applicable data protection laws and this Policy. As the data controller, the Company is responsible for the processing of clients’ personal data in connection with the services it provides.
For any questions regarding data processing and to exercise your rights, you may contact us by post or email:
Digital Assets d.o.o.
Hrv. mornarice 1C, 21000 Split, Croatia
Email: zop@bitcoin-store.hr
The Company will respond to the received request within 30 days from the date of receipt. In the case of complex or multiple requests, the response period may be extended, in which case the client will be duly informed. No fee is charged for processing such requests.
If the request is denied, the client will be informed of the reasons for the refusal and of their right to lodge a complaint with the competent data protection authority. In the Republic of Croatia, this is the Croatian Personal Data Protection Agency (AZOP), while in other EU Member States, the competent national data protection authority applies.
COLLECTION OF CLIENT DATA
The Company collects and processes client data depending on the type of Service provided. We may also process data collected within our Company, as well as data obtained from publicly available sources (e.g., court registers, land registries, sanctions lists, and similar).
When using the Platform or the Mobile Application, the following types of data may be processed:
- Contact and general information related to the opening of an Account: data processed when opening an Account may include, for example, full name, residential address, telephone number, email address, date of birth, etc.
- Identity verification data: documents used to verify the client’s identity during the account verification process (e.g., passport, national ID card) and the data contained in those documents; relevant proof of residence documents; information on politically exposed person (PEP) status; video recordings and photographs collected during verification; biometric data; and similar.
- Financial data for transaction execution: such as bank account details (IBAN and BIC), payment service provider information, payment details, transaction IDs, and other sensitive payment-related data.
- Website log data: including location and IP address, transaction data, deposit and withdrawal addresses for crypto-assets, information about the device used to access the Platform or Mobile Application, frequency and duration of visits, operating system, browser type, device type, identification cookies, and third-party cookies.
- Mobile application data: including location and IP address, transaction data, deposit and withdrawal addresses for crypto-assets, mobile device information, frequency and duration of use, operating system, crash reports, data from the camera, storage, etc.
- Corporate client data: in the case of clients that are legal entities and in the case of the use of payment services, the Company may process data obtained from publicly available sources such as court register reports, information on beneficial owners, financial data, or other details necessary to determine the business structure of the corporate client.
- Client sociodemographic data.
- Other publicly available data.
- Client financial data provided by the client.
- Data on contracted Services.
- Data on performed Services.
- Data on communication with the Company.
- Other data based on the use of the Company's Services.
- Other data obtained with the client's consent.
As the data controller, the Company protects clients’ privacy and personal data in accordance with the General Data Protection Regulation – Regulation (EU) 2016/679 (hereinafter: GDPR).
The Company’s services are intended exclusively for adults. The Company does not knowingly collect personal data from minors nor allow the registration of Accounts by individuals under the age of 18. If it is determined that data belonging to a minor has been inadvertently collected, such data will be deleted immediately and the Account will be closed.
PURPOSE OF CLIENT DATA COLLECTION AND PROCESSING
The Company collects and processes data for the purposes of its business operations, as well as in cases where data collection is required or permitted by law. All personal data processing is carried out in accordance with applicable data protection legislation, including the GDPR and applicable laws relating to electronic communications.
The Company reserves the right to collect additional personal data not described in this Policy and will duly inform the client of such instances in a timely manner.
The processing of personal data is lawful when one of the following legal grounds exists:
For the performance of contractual obligations (Article 6(1)(b) of the GDPR) where the processing of personal data is necessary to perform a contract with the client or to take steps at the client's request prior to entering into a contract. Within the use of the Platform and the Mobile Application, such data processing includes:
- registration and verification of the Account, including identity verification procedures and measures for the prevention of money laundering and terrorist financing;
- management of the Account and ongoing updates of client information;
- enabling the use of a digital wallet and trading in crypto-assets (for example, executing buy and sell orders, transferring funds, confirming transactions, etc.);
- processing of payments and withdrawals, including refund processing where applicable;
- providing customer support and responding to client requests (for example, via email, telephone, the Branch Office, or through the Platform);
- maintaining records and fulfilling obligations related to the execution of transactions on the Account;
- improving and optimizing the operation of the Platform and the Mobile Application to ensure a secure and high-quality user experience.
For compliance with legal obligations (Article 6(1)(c) of the GDPR), where the processing of personal data is necessary to meet various legal and regulatory requirements applicable to the Company in connection with the provision of Services. Such processing activities include:
- maintaining business documentation, accounting records, and issuing invoices;
- implementing compliance and risk management measures;
- carrying out “Know Your Customer” (KYC) procedures, including identity verification and collection of information on the source of funds, in accordance with anti-money laundering and counter-terrorist financing regulations;
- providing data to competent tax, regulatory, or judicial authorities when legally required or upon official request from such authorities;
- storing transaction data in accordance with international standards and regulatory requirements;
- keeping records of communication with clients where required by law or necessary to demonstrate compliance with legal obligations.
For the protection of legitimate interests (Article 6(1)(f) of the GDPR), in certain cases where personal data may be processed outside the scope of contractual performance, when such processing is necessary to protect the legitimate interests of the Company, our clients, or third parties. Such processing includes:
- preventing fraud, misuse of the Platform and the Mobile Application, unlawful activities, money laundering, and terrorist financing;
- responding to requests from competent authorities, legal representatives, or debt collection agencies for the purpose of exercising or defending legal claims;
- managing and mitigating risks related to business operations;
- handling general client inquiries and requests outside contractual obligations;
- testing and optimizing procedures and technical solutions, developing new functionalities, and improving the user experience of the Platform and the Mobile Application;
- implementing measures for quality management and the security of business processes;
- conducting data analysis and statistical processing related to the usage of the Platform and the Mobile Application to improve the Company's services;
- performing market research and business planning;
- carrying out marketing activities and direct communication with clients (only to the extent permitted by law and with full respect for the client's right to object);
- processing client preference data (for example, language, region) through cookies and similar technologies, in accordance with the Cookie Policy;
- implementing technical and organizational measures to ensure network and information security, including the prevention of unauthorized access, identity theft, and other forms of misuse;
- protecting clients, partners, employees, and Company assets, which may include the use of security systems where applicable.
Based on the client's consent (Article 6(1)(a) of the GDPR), processing is carried out solely for clearly defined purposes and within the scope specified in the consent statement. The client has the right to withdraw consent at any time, without providing a reason, with future effect. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. Examples of processing based on consent include:
- receiving promotional offers, newsletters, customer satisfaction surveys, participation in prize draws, and other marketing activities;
- the use of cookies and similar technologies for analytical and advertising purposes, in accordance with the Cookie Policy;
- processing of photographs, videos, or other materials for marketing and promotional purposes, where the client has given consent;
- participation in market research or additional services that require consent;
- activation of specific features of the Platform and the Mobile Application (for example, using the camera to scan QR codes to facilitate transactions), where client consent is required;
- processing of personal data for the issuance and use of the Bitstore debit card, including data transfer to financial institutions and partners involved in card issuance and processing, where the client has provided consent.
Protection of the client's vital interests - in exceptional situations, processing may be necessary to protect the client's life, safety, or other fundamental rights (for example, in the event of security incidents or suspected account misuse).
Performance of a task carried out in the public interest - in certain areas, the Company may be required to process personal data for purposes arising from the public interest, for instance, when mandated by law or upon request from competent authorities.
Legitimate interest of the Company or a third party - when processing is necessary to protect the Company's legitimate business interests (for example, ensuring network and information security of the Platform and the Mobile Application, preventing fraud, or improving services), except when such interests are overridden by the client's rights and freedoms requiring the protection of personal data.
IDENTIFICATION OF SUSPICIOUS ACTIVITIES
The Company conducts continuous monitoring of activities on the Account to protect clients and the financial system. This includes the processing of personal and transactional data for the purpose of:
- detecting and preventing suspicious activities related to money laundering, terrorist financing or market abuse;
- conducting risk assessments of clients and their transactions;
- analyzing behavioral and transactional patterns to prevent fraud and unauthorized actions;
- fulfilling regulatory obligations related to reporting and supervision.
Automated data processing tools may be used in these procedures. However, the Company does not make decisions that produce legal or similarly significant effects for the client solely on the basis of automated data processing, without human oversight.
In this way, the Company ensures a proper balance between regulatory requirements and the protection of the client's rights and freedoms.
RETENTION OF CLIENT PERSONAL DATA
Client personal data is stored and processed only for as long as necessary. This means throughout the entire duration of the business relationship (from establishment, through performance, to termination), after which the client’s personal data is retained for as long as the prescribed statutory periods require. Once these periods expire, the client’s personal data may be retained longer solely in accordance with statutory retention and documentation obligations or for the defense of legal claims.
Client personal data is deleted and no longer processed when it is no longer needed for the purposes for which it was collected, and at the latest upon expiration of the statutory retention periods that apply to the Company.
Transactional and financial activity data are retained in accordance with legal and regulatory retention periods, meaning that the client's right to request deletion of such data is legally restricted. These retention periods ensure compliance with accounting, tax reporting, anti-money laundering, and counter-terrorist financing obligations, as well as other regulatory requirements.
Depending on the purpose of the data processing, the Company may retain certain data for shorter or longer periods than those mentioned above, always in compliance with applicable laws and regulations, and with the implementation of appropriate technical and organizational data protection measures.
TRANSFER OF CLIENT DATA TO THIRD PARTIES
The Company does not share clients' personal data with third parties, except in cases where such transfer is necessary to provide contracted services or to comply with legal obligations.
Before establishing cooperation, each service provider and business partner undergoes a detailed assessment and audit. The Company cooperates only with partners that meet strict security and organizational standards and explicitly require them to comply with applicable data protection regulations, including the GDPR.
Client personal data is primarily stored on servers located within the European Union (EU) and the European Economic Area (EEA). In situations where the use of service providers outside the EU and EEA is necessary, the Company ensures that data transfers are carried out only to entities that provide an adequate level of protection in accordance with the GDPR, for example through the use of standard contractual clauses or other recognized transfer mechanisms.
Furthermore, the Company may be required to transfer clients' personal data to competent public authorities or institutions, but only to the extent necessary to comply with legal obligations, submit required reports, or protect the rights and interests of the Company.
CLIENT RIGHTS
Under the GDPR, the client has the following rights:
| Right of Access (Article 15 of the GDPR) | The client has the right to request confirmation from the Company as to whether their personal data is being processed and to obtain a copy of the personal data concerning them that is subject to processing. |
|---|---|
| Right to Rectification (Article 16 of the GDPR) | The client has the right to request, at any time, the correction of inaccurate data or the modification or completion of incomplete data. |
| Right to Erasure (Article 17 of the GDPR) | The client has the right to request the deletion of their personal data stored by the Company at any time. The Company will comply with such a request, except in cases where overriding exceptions apply. We may not be able to fulfill the client’s request if the processing of their personal data is still necessary for the purposes for which it was originally collected (for example, if the client is still in an active business relationship with the Company). A deletion request may also be denied if the processing was originally based on consent and there is another legal basis or an overriding legitimate interest of the Company for continued processing. The most important case in which we cannot delete a client’s personal data is when we are required to retain it in order to fulfill legal or regulatory obligations under the laws of the European Union or the Member State to which we are subject. In all other cases, the Company will act upon the client’s request for data deletion. |
| Right to Restriction of Processing (Article 18 of the GDPR) | The client has the right to request that we restrict the processing of their personal data if at least one of the following conditions is met: the client contests the accuracy of the personal data - the restriction will remain in effect for the period during which the Company verifies the accuracy of the data; the processing of the client's personal data was unlawful, but the client objects to the deletion of the data and instead requests the restriction of its use; the Company no longer needs the client's personal data for processing purposes, but the client requires it for the establishment, exercise, or defense of legal claims; the client has objected to the processing of their data, and it has not yet been determined whether the Company's legitimate grounds override the client's rights and freedoms. |
| Right to Data Portability (Article 20 of the GDPR) | The client has the right to receive the personal data we have collected from them in a structured, commonly used, and machine-readable format. The client also has the right to request that such data be transferred directly to another data controller designated by the client, where technically feasible and where doing so does not adversely affect the rights and freedoms of others. The right to data portability may be exercised only when the legal basis for processing is the client’s consent or (pre-contractual) necessity, and when the processing is carried out by automated means. This right does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller. |
| Right to Object (Article 21 of the GDPR) | The client has the right, at any time and for reasons relating to their particular situation, to object to the processing of their personal data if such processing is based on the Company’s legitimate interests. The processing of the client’s personal data for this purpose shall cease, unless the Company demonstrates compelling legitimate grounds for the processing which override the client’s interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims. When the client’s personal data is processed for direct marketing purposes, the client may object at any time using the contact details provided. The client’s objection does not affect the lawfulness of personal data processing based on legitimate interests prior to the submission of the objection. |
| Right to Withdraw Consent (Article 7(3) of the GDPR) | The client has the right to withdraw their consent to the processing of personal data at any time, after which the Company will cease processing the client’s personal data based on that consent, unless another legal basis applies. The withdrawal of consent does not affect the lawfulness of the processing of the client’s personal data that was carried out based on consent before its withdrawal. |
| Right not to be Subject to automated individual decision-making (Article 22 of the GDPR) | The Company does not use clients’ personal data for automated decision-making, including profiling within the meaning of Article 22 of the GDPR. This means that no decisions producing legal effects concerning the client, or otherwise significantly affecting them, are made based solely on automated processing of the client’s personal data, including profiling. |
DATA PROCESSING SECURITY
The security of clients’ personal data is of utmost importance to the Company, and we are fully committed to protecting all data we collect and process. We implement comprehensive administrative, technical, organizational, and personnel measures designed to prevent the accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use of clients’ personal data.
All security measures are aligned with the highest international standards, and regular audits are conducted to assess their effectiveness, adequacy, and ability to ensure the confidentiality, integrity, and availability of clients’ personal data. In addition, the Company continuously enhances its security protocols to respond to emerging threats and risks in the digital environment, ensuring a high level of data protection for its clients.
The Company applies a comprehensive set of technical, organizational, and personnel measures to ensure that clients’ personal data is encrypted, confidential, and protected in the event of a physical or technical incident. These measures include regular testing, risk assessments, and evaluations of effectiveness to maintain ongoing data security.
Personnel protection measures:
- the processing and accessibility of clients’ personal data are not automated and are limited to an authorized number of employees;
- data is protected against intentional or unauthorized deletion;
- all employees are bound by confidentiality obligations, which remain in force even after the termination of employment;
- regular employee training ensures the proper implementation of security measures and raises awareness of data protection practices.
Technical and organizational measures include, among others:
- SSL encryption on websites and the Platform to ensure secure transmission of clients' personal data;
- two-factor authentication (2FA) for accessing the Platform;
- ensuring confidentiality, integrity, availability, and resilience of systems and Services;
- use of encrypted systems for data storage and transfer;
- pseudonymization and anonymization of personal data where applicable;
- regular assessment and evaluation of the effectiveness of technical and organizational measures
- internal IT security policies and regular employee training;
- incident response management and plans for timely resolution of security incidents.
In the event of a personal data breach involving a client’s data (for example, unauthorized access, loss, or disclosure), the Company will, without undue delay, take all necessary measures to contain and mitigate the consequences of the incident.
If the personal data breach is likely to result in a high risk to the client’s rights and freedoms, the Company will inform the affected clients without undue delay in a clear and transparent manner.
The Company will also comply with its reporting obligations to the competent data protection authority (AZOP) and, where applicable, other regulatory authorities, in accordance with the GDPR and relevant legislation.
AMENDMENTS AND UPDATES TO THE PRIVACY POLICY
The Company is committed to keeping its data protection principles up to date. For this reason, we regularly review and update this Policy to ensure that it:
- is accurately and clearly presented on our Platform, Mobile Application, and Branch Offices;
- contains complete information about clients’ rights and our processing activities, including technical changes or business developments;
- complies with applicable legislation and data protection requirements.
This Policy is periodically updated to reflect current circumstances and changes in business operations or the regulatory framework. If significant changes are made, clients will be notified upon logging into their Account. Where required by applicable law, the Company will obtain the client’s explicit consent for material amendments.
The Company reserves the right to modify any part of this Policy at any time. The amended Policy becomes effective upon its publication on the Platform, the Mobile Application, and the Branch Offices, at which point it is deemed that the client has read, understood, and accepted all provisions of the Policy.
This amended Policy takes effect on 1 July 2026 and replaces the Policy previously in force before that date.