Privacy Policy
Last updated: April 17, 2024
DB ZION ALPHA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (KRS: 0001043322, Virtual Currency Activities Register: RDWW-8221)
This Privacy Policy explains how DB ZION ALPHA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Zion", "we", "us") collects, uses, stores and protects personal data when you use https://zionpayment.com and the Zion app.
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish law. By using our services you accept the practices described below.
1. Data Controller
The data controller is DB ZION ALPHA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, registered in Poland (KRS: 0001043322; Virtual Currency Activities Register: RDWW-8221).
For data protection inquiries contact: privacy@zionpayment.com.
2. Categories of Personal Data We Collect
Identification data
- Full name, date of birth, nationality, residential address
- Government-issued ID details (passport, ID card, driving license)
- Selfie / liveness check imagery
Contact data
- Email address
- Phone number
Financial and transaction data
- Wallet addresses, transaction hashes, transaction amounts and timestamps
- Source of funds declarations
- Bank account or card details when used for fiat settlements
Technical data
- IP address, device identifiers, browser type, operating system
- Cookies and similar tracking technologies
- Logs of pages viewed and actions performed
Compliance data
- Sanctions and PEP screening results
- Risk-scoring outputs
- Records of suspicious activity reports filed with authorities
3. Purposes and Legal Bases of Processing
We process personal data for the following purposes:
- Providing exchange and custodial wallet services (Art. 6(1)(b) GDPR — contract performance)
- Identity verification, KYC and AML obligations (Art. 6(1)(c) GDPR — legal obligation)
- Preventing fraud, sanctions screening, transaction monitoring (Art. 6(1)(c) and Art. 6(1)(f) GDPR — legitimate interest)
- Customer support and communications about service changes (Art. 6(1)(b) and (f) GDPR)
- Security monitoring and incident investigation (Art. 6(1)(f) GDPR)
- Analytics and product improvement using aggregated or pseudonymised data (Art. 6(1)(f) GDPR)
- Marketing communications, where you have consented (Art. 6(1)(a) GDPR — consent)
4. Cookies and Tracking
We use strictly necessary cookies to operate authentication and security features. With your consent we also use analytics cookies (e.g. Plausible) to measure aggregated usage. You can withdraw consent at any time via your browser settings or our cookie banner.
5. Recipients and Disclosures
We share personal data only with parties that need it to deliver the service, comply with the law, or protect our legitimate interests:
- KYC/AML providers and identity verification vendors
- Banking and payment partners processing fiat settlements
- Cloud infrastructure providers hosting our systems
- Legal, accounting and audit advisors
- Public authorities and financial intelligence units when required by law
- Third-party blockchain analytics providers for transaction monitoring
We do not sell personal data. Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
6. Data Retention
We retain personal data only for as long as needed to deliver the service and comply with legal obligations:
- KYC documents and transaction records: 5 years after the end of the business relationship (AML Act)
- Accounting and tax records: at least 5 years per Polish tax law
- Marketing data: until consent is withdrawn
- Technical logs: typically 12 months unless needed for security investigation
7. Your Rights
Under GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request erasure of data, subject to legal retention obligations
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent at any time for processing based on consent
- Lodge a complaint with the Polish Personal Data Protection Office (UODO) or your local supervisory authority
To exercise any right write to privacy@zionpayment.com. We respond within 30 days.
8. Security
We apply technical and organisational measures appropriate to the risk: TLS in transit, encryption at rest for sensitive identifiers, role-based access controls, audit logging, periodic penetration testing and staff training on data protection.
9. Children
Our services are not directed at persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact privacy@zionpayment.com so we can delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on our website with at least 30 days notice before they take effect. The current version is always available at /legal/privacy.
11. Contact
For privacy questions or to exercise your rights: privacy@zionpayment.com
For general support: support@zionpayment.com