Privacy Policy
This policy explains, in plain English, what personal data FotifyPay collects, why we collect it, how long we keep it and what rights you have. It is drafted under GDPR Article 13 (EU customers), UK GDPR (UK customers) and PIPEDA (Canadian customers).
1. Who we are (the data controller)
FotifyPay is operated by the legal entity disclosed in our Terms of Service. Where we determine the purpose and means of processing your personal data, we act as data controller within the meaning of Article 4(7) GDPR. For UK customers, the same role applies under the UK GDPR. For Canadian customers, we are the "organization" under PIPEDA.
Contact for privacy queries: privacy@fotifypay.com. Our Data Protection Officer can be reached at dpo@fotifypay.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Identity | Full name, date of birth, nationality, government-ID image | You, during KYC |
| Contact | Email, phone, Telegram handle | You, on sign-up |
| Financial | Pay-in method, last 4 digits of card / masked IBAN, transaction history | You + our payment partners |
| Crypto | Wallet addresses you provide, on-chain transaction hashes | You + the blockchain |
| Technical | IP address, device fingerprint, user-agent, log timestamps | Automated, on every request |
| Compliance | Sanctions screening results, AML risk score, source-of-funds answers | You + Chainalysis, ComplyAdvantage |
3. Why we process it (legal bases — Art. 6 GDPR)
- Performance of a contract (Art. 6(1)(b)): to deliver the crypto you bought.
- Legal obligation (Art. 6(1)(c)): to meet AML/CFT, MiCA, Travel Rule, FCA MLR 2017 and FINTRAC PCMLTFA requirements.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, IT security, debugging — balanced against your rights and disclosed below.
- Consent (Art. 6(1)(a)): only for optional things like marketing newsletters. Withdraw at any time.
4. Who we share it with
- Payment partners — licensed PSPs and Open Banking AISP/PISP providers that move EUR/CAD/GBP for you.
- Compliance vendors — Chainalysis (sanctions screening, on-chain Sanctions Oracle), ComplyAdvantage (PEP / adverse-media lists), Sumsub / Onfido (KYC).
- Authorities — FIUs, the FCA, FINTRAC and the AMLA, on lawful request. We log every such disclosure.
- Counterparty VASPs — only the Travel Rule data required by Regulation (EU) 2023/1113 and equivalent rules.
We do not sell personal data. We do not enable cross-context behavioural advertising.
5. International transfers
Some vendors are outside the EEA. Where so, transfers happen under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) together with documented Transfer Impact Assessments, and — for the UK — the ICO's International Data Transfer Addendum. Canadian customers' data is processed in jurisdictions with comparable protection or under PIPEDA-compliant contractual safeguards.
6. How long we keep it
| Data | Retention | Reason |
|---|---|---|
| KYC documents | 5 years after account closure | Art. 21 AMLR / FCA MLR 2017 reg. 40 |
| Transaction records | 5 years after the transaction | AML rulebook |
| Support correspondence | 3 years | Legitimate interest, dispute defence |
| Marketing consent log | Until you withdraw + 6 months | Accountability |
| Server access logs | 13 months | EDPB guidance on access logs |
7. Your rights
Under GDPR Articles 15–22, UK GDPR and PIPEDA you can: access, rectify, erase, restrict, port and object. Use the dashboard or email privacy@fotifypay.com. We answer within 30 days (extendable by 60 days for complex requests, per Art. 12(3) GDPR).
We may refuse erasure where AML retention law overrides — but we always tell you which article we relied on. See the dedicated GDPR — your rights page for the full walkthrough.
8. Right to lodge a complaint
- EU customers: your national Data Protection Authority — the list is at edpb.europa.eu.
- UK customers: the Information Commissioner's Office (ICO).
- Canadian customers: the Office of the Privacy Commissioner of Canada.
9. Security
Encryption in transit (TLS 1.2+) and at rest (AES-256). Two-factor authentication via Telegram OTP and Google Authenticator. Segregated production database, principle of least privilege, mandatory code review, quarterly penetration tests. We comply with the operational-resilience requirements of Regulation (EU) 2022/2554 (DORA).
10. Changes to this policy
Material changes are announced 30 days in advance by email and on this page. The version number and "Last updated" timestamp at the top of this document are the authoritative record.