This Privacy Policy constitutes part of and should be read in conjunction with the Coin Rivet Terms and Conditions. This policy explains how we may collect, create, process, store, protect, disclose, share and transfer your Personal Data as part of our business operations.
“Personal Data” means any information that identifies or is reasonably capable of identifying an individual, directly or indirectly, and information that is being associated with an identified or reasonably identifiable individual. For more explanation as to what is Personal Data please see the definition in section (S).
Summary – The Summaries |
Any section summary boxes such as this one are provided for your convenience only, we encourage you to read the full sections so that you can fully understand and accept the terms of this Privacy Policy |
Summary – This Notice |
This Notice explains how we Process Personal Data. This Notice may be amended or updated from time to time, so please check it regularly for updates. |
This Notice is issued by Galias Services, UAB (trading as Coin Rivet) a private limited liability company organised and existing under the laws of the Republic of Lithuania, legal entity code: 305705483, registered office address at Lvovo str. 25-104, Vilnius, Republic of Lithuania(“Coin Rivet”, “we”, “us” and “our”) and is addressed to individuals outside our organisation with whom we interact, including customers, visitors to our Sites, users of our Apps, other users of our Services, and visitors to our premises (together, “you”). Defined terms used in this Notice are explained in Section (S) below. For the purposes of this Notice, Coin Rivet is the Controller.
This Notice may be amended or updated from time to time to reflect changes in our practices with respect to the Processing of Personal Data, or changes in Applicable Law. We encourage you to read this Notice carefully, and to regularly check this page to review any changes we might make in accordance with the terms of this Notice. You can always find the latest version of this Privacy Policy here on this page.
Summary – Collection of Personal Data |
We collect or obtain Personal Data: when those data are provided to us (e.g., where you contact us); in the course of our relationship with you (e.g., if you make a purchase); when you make Personal Data public (e.g., if you make a public post about us on social media); when you download, install, or use any of our Apps; when you visit our Sites; when you register to use any of our Sites, Apps, or Services; or when you interact with any third-party content or advertising on our Site or in our App. We may also receive Personal Data about you from third parties (e.g., law enforcement authorities). |
We will only collect Personal Data relevant to the purpose for which it will be used, and which will be limited to what is necessary for that purpose.
Collection of Personal Data: We collect or obtain Personal Data about you from the following sources:
Please note that third parties you interact with may have their own privacy policies, and we are not responsible for their operations or their use of the data they collect. Information collected by third parties is governed by their privacy practices and we are not responsible for unauthorized third-party conduct. We encourage you to learn about the privacy practices of any relevant third parties you engage with.
Summary – Creation of Personal Data |
We create Personal Data about you (e.g., records of your interactions with us). |
We also create Personal Data about you in certain circumstances, such as records of your interactions with us, and details of your past interactions with us. We may also combine Personal Data from any of our Sites, Apps, or Services, including where those data are collected from different devices.
Summary – Categories of Personal Data we Process |
We Process: your personal details (e.g., your name); formal personal details (e.g., government ID); your contact details (e.g., your address); details of your contacts (e.g., the names and contact information in your address book); records of your consents; purchase details; payment details (e.g., your billing address); information about our Sites and Apps (e.g., the type of device you are using); details of your employer (where relevant); information about your interactions with our content or advertising; and any views or opinions you provide to us. |
We Process the following categories of Personal Data about you:
Personal Identity Information: (such as given name(s), preferred name(s), gender, date of birth, age, nationality, title, language)
Formal Identity Information: (such as government-issued identity documents such as identity cards, passports, driving license and/or any other government issued or public information deemed necessary to comply with our legal obligations under financial or anti-money laundering laws.)
Financial Information: (such as bank account details, routing number, blockchain data and addresses, invoices, payment records, transaction history and/or other financial data)
Transaction Information: (details of transactions on our Services, such as details of sender and receiver, amounts, timing and date, blockchain addresses, E wallet addresses)
Employment Information: (such as job title, employer, location, proof of salary and/or earnings)
Correspondence Information: (such as account registration details, email, contact number and home address)
Contacts Information: (such as if you choose to provide us with information about your contacts and your address book by syncing, uploading or importing it to our App)
Sensory Information: (any audio or visual information such as recordings of calls, CCTV videos and selfies for identity verification)
Additional Information (such as where we exercise discretion to collect information required to comply with legal/compliance obligations)
Data relating to our Sites and Apps: (such as device type, operating system, browser type, browser settings, IP address, language settings, dates and times of connecting to a Site, App usage statistics, App settings, QR codes, dates and times of connecting to an App, location data, and other technical communications information (some of which may constitute Personal Data), username; password, security login details, aggregate statistical information.)
Content records: (such as records of any consents you have given, together with the date and time, means of consent and any related information (e.g., the subject matter of the consent)).
Summary – Sensitive Personal Data |
We do not seek to collect or otherwise Process Sensitive Personal Data. Where we need to Process Sensitive Personal Data for a legitimate purpose, we do so in accordance with Applicable Law. |
We do not seek to collect or otherwise Process Sensitive Personal Data in the ordinary course of our business. Where it becomes necessary to Process your Sensitive Personal Data for any reason, we rely on one of the following legal bases:
If you provide Sensitive Personal Data to us, you must ensure that it is lawful for you to disclose such data to us, and you must ensure a valid legal basis applies to the Processing of those Sensitive Personal Data.
Summary – Purposes of Processing and Legal Bases for Processing |
We Process Personal Data for the following purposes: providing our Sites, Apps, and Services to you; compliance checks; operating our business; communicating with you; managing our IT systems; health and safety; financial management; conducting surveys; ensuring the security of our premises and systems; conducting investigations where necessary; compliance with Applicable Law; improving our Sites, Apps, and Services; fraud prevention; and recruitment and job applications. |
The legal basis for the Processing of your Personal Data is dependent on the context in which we collect it and the purposes for which it is used. Subject to Applicable Law, the purposes for which we Process Personal Data, and the most common legal bases on which we perform such Processing, are as follows:
Processing activity | Legal basis for Processing |
Provision of Sites, Apps, and Services:
• Providing our Sites, Apps, or Services; • Providing promotional items upon request; and • Communicating with you in relation to those Sites, Apps, or services. |
• The Processing is necessary for the performance of a contract
• We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, Apps, or Services
• We have obtained your prior consent to the Processing. |
Helping with social interactions:
• Helping with social interactions through our services; • Adding extra functions in order to provide a better customer experience; For example, if you give us permission, we’ll use the contacts list on your phone so you can easily identify other Luxon users and make payments to your contacts using the Luxon Pay App. We will not pass this information to any third parties. |
• We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, Apps, or Services
• We have obtained your prior consent to the Processing. |
Compliance checks:
• Fulfilling our regulatory and/or compliance obligations; • ‘Know Your Client’ checks and confirming and verifying your identity; • Use of credit reference agencies; and; • Screening against government and/or law enforcement agency sanctions lists and other legal restrictions. |
• The Processing is necessary for compliance with a legal obligation;
• The Processing is necessary for the performance of a contract;
• We have a legitimate interest in carrying out the Processing for the purpose of fulfilling our regulatory and compliance obligations;
• We have obtained your prior consent to the Processing. |
Operating our business:
• Operating and managing our Sites, our Apps, and our Services; • Providing content to you; • Displaying advertising and other information to you; • Communicating and interacting with you via our Sites, our Apps, or our Services; and • Notifying you of changes to any of our Sites, our Apps, or our Services. |
• The Processing is necessary for the performance of a contract;
• We have a legitimate interest in carrying out the Processing for the purpose of providing our Sites, our Apps, or our Services or other business operations to you;
• We have obtained your prior consent to the Processing. |
Communications and marketing:
• Communicating with you via any means (including via email, telephone, text message, social media, post or in person) to provide news items and other information in which you may be interested, subject always to obtaining your prior opt-in consent to the extent required under Applicable Law; • Maintaining and updating your contact information where appropriate; and obtaining your prior, opt-in consent where required. |
• The Processing is necessary for the performance of a contract;
• We have a legitimate interest in carrying out the Processing for the purpose of contacting you, subject always to compliance with Applicable Law ;
• We have obtained your prior consent to the Processing
|
Processing activity | Legal basis for Processing |
Management of IT systems:
• Management and operation of our communications, IT and security systems; and audits (including security audits) and monitoring of such systems. |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of managing and maintaining our communications and IT systems. |
Health and safety:
• Health and safety assessments and record keeping; • Providing a safe and secure environment at our premises; • Compliance with related legal obligations. |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of ensuring a safe environment at our premises;
• The Processing is necessary to protect the vital legitimate interests of any individual. |
Financial management:
• Sales; • Finance; • Corporate audit; • Vendor management. |
• We have a legitimate interest in carrying out the Processing for the purpose of managing and operating the financial affairs of our business;
• We have obtained your prior consent to the Processing. |
Security:
• Physical security of our premises (including records of visits to our premises); • CCTV recordings; • Electronic security (including login records and access details). |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of ensuring the physical and electronic security of our business and our premises. |
Investigations:
• Detecting, investigating and preventing breaches of policy, and criminal offences, in accordance with Applicable Law. |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, breaches of our policies and Applicable Laws |
Legal proceedings:
• Establishing, exercising, and/or defending legal rights. |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of establishing, exercising or defending our legal rights. |
Legal compliance:
• Compliance with our legal and regulatory obligations under Applicable Law. |
• The Processing is necessary for compliance with a legal obligation. |
Improving our Sites, Apps, and services:
• Identifying issues with our Sites, our Apps, or our Services; • Planning improvements to our Sites, our Apps, or our Services; • Creating new Sites, Apps, or Services. |
• We have a legitimate interest in carrying out the Processing for the purpose of improving our Sites, our Apps, or our services;
• We have obtained your prior consent to the Processing |
Fraud prevention:
• Detecting, preventing and investigating fraud. |
• The Processing is necessary for compliance with a legal obligation;
• We have a legitimate interest in carrying out the Processing for the purpose of detecting, and protecting against, fraud. |
Recruitment and job applications:
• Recruitment activities; • Advertising of positions; • Interview activities; • Analysis of suitability for the relevant position; • Records of hiring decisions; • Offer details; • Acceptance details. |
• The Processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law);
• We have a legitimate interest in carrying out the Processing for the purpose of recruitment activities and handling job applications;
• We have obtained your prior consent to the Processing |
Where you consent:
• For any other purpose for which you provide your consent |
• We have obtained your prior consent to the Processing |
Summary – Disclosure of Personal Data to Third-Parties |
We disclose Personal Data to: legal and regulatory authorities; our external advisors; our Processors; any party as necessary in connection with legal proceedings; any party as necessary for investigating, detecting or preventing criminal offences; any purchaser of our business; and any third-party providers of advertising, plugins or content used on our Sites or our Apps. |
We disclose Personal Data within Coin Rivet, for legitimate business purposes and the operation of our Sites, Apps, or Services to you, in accordance with Applicable Law. In addition, we disclose Personal Data to:
If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under Applicable Law. Third party processors we use regularly, but which may change from time to time, include but are not limited to:
Summary – Profiling |
Personal Data are subject to automated decision-making and Profiling. |
We Process Personal Data for the purposes of automated decision-making and Profiling, which is defined in Section (19).
We Process Personal Data for the purposes of automated decision-making and Profiling, which is carried out for the following purposes:
Profiling activity | Logic of the Profiling activity | Consequences for you |
Credit Scoring | Where we engage a third party (e.g., a credit reference agency) to provide us with information about your credit score and/or credit history. This information is analysed to determine the most appropriate terms on which to offer you credit, where applicable. | This Profiling activity may affect whether you are able to obtain credit, and the interest rates applicable to any such credit. |
Transaction Monitoring |
We engage a third party to analyse transactions to highlight suspicious behaviour and potentially block suspicious transactions. | This profiling activity may mean that transactions are rejected or delayed if the activity is suspicious we may also report suspicious activity to the relevant regulatory bodies or law enforcement agencies. |
Crypto Transaction Monitoring | We scan all incoming and outgoing wallet addresses, to prevent the use of our platforms for money laundering or other financial crime. This includes send source addresses or destination addresses to third parties to analyse against interaction with known bad actors. | This activity may mean that your wallet is frozen if cryptocurrency associated with known bad actors is sent to the system. This will result in us sending a suspicious activity report to the relevant regulatory bodies or law enforcement agencies. |
KYC Identification | We engage a third party to collect information and analyse it for KYC purposes, this information is then removed from their system and stored on ours. | This profiling activity may mean that sign up is rejected or delayed if we may also need to provide this information relevant regulatory bodies or law enforcement agencies. |
Summary – International Transfer of Personal Data |
We transfer Personal Data to recipients in other countries. Where we transfer Personal Data from the EEA to a recipient outside the EEA that is not in an Adequate Jurisdiction, we do so on the basis of Standard Contractual Clauses. |
Because of the international nature of our business, we transfer Personal Data within Coin Rivet and to third parties as noted in Section (G) above, in connection with the purposes set out in this Notice. For this reason, we transfer Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located.
Where we transfer your Personal Data from the EEA to recipients located outside the EEA who are not in Adequate Jurisdictions, we rely primarily on the European Commission’s Standard Contractual Clauses to facilitate the international and onward transfer of Personal Data. You are entitled to request a copy of our Standard Contractual Clauses using the contact details provided in Section (R) below.
Please note that when you transfer any Personal Data directly to a recipient outside the EEA, we are not responsible for that transfer of your Personal Data. We will nevertheless Process your Personal Data, from the point at which we receive those data, in accordance with the provisions of this Notice.
Summary – Data Security |
We implement appropriate technical and organisational security measures to protect your Personal Data. Please ensure that any Personal Data that you send to us are sent securely. |
We have implemented appropriate technical and organisational security measures designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of Processing, in accordance with Applicable Law.
Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement all reasonable measures to protect your Personal Data, we cannot guarantee the security of your data transmitted to us using the internet – any such transmission is at your own risk and you are responsible for ensuring that any Personal Data that you send to us are sent securely.
Furthermore, we cannot ensure or warrant the security or confidentiality of information you transmit to us or receive from us by Internet or wireless connection, including email, phone, or SMS, since we have no way of protecting that information once it leaves and until it reaches us.
Summary – Data Accuracy |
We take every reasonable step to ensure that your Personal Data are kept accurate and up-to-date and are erased or rectified if we become aware of inaccuracies. |
We take every reasonable step to ensure that:
From time to time we may ask you to confirm the accuracy of your Personal Data.
Summary – Data Minimisation |
We take every reasonable step to limit the volume of your Personal Data that we Process to what is necessary. |
We take every reasonable step to ensure that your Personal Data that we Process are limited to the Personal Data reasonably necessary in connection with the purposes set out in this Notice.
Summary – Data Retention |
We take every reasonable step to ensure that your Personal Data are only retained for as long as they are needed in connection with a lawful purpose. |
We take every reasonable step to ensure that your Personal Data are only Processed for the minimum period necessary for the purposes set out in this Notice. The criteria for determining the duration for which we will retain your Personal Data are as follows:
(1) We will retain Personal Data in a form that permits identification only for as long as:
Plus (2) the duration of:
and:
(3) in addition, if any relevant legal claims are brought, we continue to Process Personal Data for such additional periods as are necessary in connection with that claim.
During the periods noted in paragraphs (2)(a) and (2)(b) above, we will restrict our Processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim, or any obligation under Applicable Law.
Once the periods in paragraphs (1), (2) and (3) above, each to the extent applicable, have concluded, we will either:
Summary – Your Legal Rights |
Subject to Applicable Law, you may have a number of rights, including: the right not to provide your Personal Data to us; the right of access to your Personal Data; the right to request rectification of inaccuracies; the right to request the erasure, or restriction of Processing, of your Personal Data; the right to object to the Processing of your Personal Data; the right to have your Personal Data transferred to another Controller; the right to withdraw consent; and the right to lodge complaints with Data Protection Authorities. In some cases it will be necessary to provide evidence of your identity before we can give effect to these rights. |
Subject to Applicable Law, you may have the following rights regarding the Processing of your Relevant Personal Data:
Subject to Applicable Law, you may also have the following additional rights regarding the Processing of your Relevant Personal Data:
• the right to object, on grounds relating to your particular situation, to the Processing of your Relevant Personal Data by us or on our behalf; and • the right to object to the Processing of your Relevant Personal Data by us or on our behalf for direct marketing purposes. |
This does not affect your statutory rights.
To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Notice, or about our Processing of your Personal Data, please use the contact details provided in Section (R) below. Please note that:
Summary – Cookies and Similar Technologies |
We Process Personal Data by using Cookies and similar technologies. For more information, please see our Cookie Policy. |
When you visit a Site or use an App we will typically place Cookies onto your device, or read Cookies already on your device, subject always to obtaining your consent, where required, in accordance with Applicable Law. We use Cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We Process Personal Data through Cookies and similar technologies, in accordance with our Cookie Policy.
Summary – Terms and Conditions |
Our Terms and Conditions govern all use of our Sites, Apps and our Services. |
All use of our Sites, Apps, or services is subject to our Terms and Conditions. We recommend that you review our Terms and Conditions regularly, in order to review any changes we might make from time to time.
Summary – Direct Marketing |
We Process Personal Data to contact you with information regarding Sites, Apps, or services that may be of interest to you. You may unsubscribe for free at any time. |
We Process Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding Sites, Apps, or services that may be of interest to you. If we provide Sites, Apps, or services to you, we may send information to you regarding our Sites, Apps, or services, upcoming promotions and other information that may be of interest to you, using the contact details that you have provided to us, subject always to obtaining your prior opt-in consent to the extent required under Applicable Law.
You may unsubscribe from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but in some circumstances we will continue to contact you to the extent necessary for the purposes of any Sites, Apps, or services you have requested.
Contact details for Coin Rivet are as follows:
Galias Services, UAB
Lvovo str. 25-104, Vilnius, Republic of Lithuania
Email: support@coinrivet.com