🌉 FotifyPay
Home How it works Security Regulation Partners FAQ
Sign in Buy crypto
Home How it works Security Regulation Partners FAQ
Sign in Buy crypto

Legal

  • Privacy policy
  • Terms of service
  • GDPR — your rights
  • AML / KYC policy
  • Cookies
  • Regulatory framework

Questions? legal@fotifypay.com

FotifyPay · Legal

Privacy Policy

Version: v2.0 Last updated: 2026-05-17 Applies to: EU · UK · CA

This policy explains, in plain English, what personal data FotifyPay collects, why we collect it, how long we keep it and what rights you have. It is drafted under GDPR Article 13 (EU customers), UK GDPR (UK customers) and PIPEDA (Canadian customers).

1. Who we are (the data controller)

FotifyPay is operated by the legal entity disclosed in our Terms of Service. Where we determine the purpose and means of processing your personal data, we act as data controller within the meaning of Article 4(7) GDPR. For UK customers, the same role applies under the UK GDPR. For Canadian customers, we are the "organization" under PIPEDA.

Contact for privacy queries: privacy@fotifypay.com. Our Data Protection Officer can be reached at dpo@fotifypay.com.

2. What we collect

CategoryExamplesSource
IdentityFull name, date of birth, nationality, government-ID imageYou, during KYC
ContactEmail, phone, Telegram handleYou, on sign-up
FinancialPay-in method, last 4 digits of card / masked IBAN, transaction historyYou + our payment partners
CryptoWallet addresses you provide, on-chain transaction hashesYou + the blockchain
TechnicalIP address, device fingerprint, user-agent, log timestampsAutomated, on every request
ComplianceSanctions screening results, AML risk score, source-of-funds answersYou + Chainalysis, ComplyAdvantage

3. Why we process it (legal bases — Art. 6 GDPR)

  • Performance of a contract (Art. 6(1)(b)): to deliver the crypto you bought.
  • Legal obligation (Art. 6(1)(c)): to meet AML/CFT, MiCA, Travel Rule, FCA MLR 2017 and FINTRAC PCMLTFA requirements.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, IT security, debugging — balanced against your rights and disclosed below.
  • Consent (Art. 6(1)(a)): only for optional things like marketing newsletters. Withdraw at any time.

4. Who we share it with

  • Payment partners — licensed PSPs and Open Banking AISP/PISP providers that move EUR/CAD/GBP for you.
  • Compliance vendors — Chainalysis (sanctions screening, on-chain Sanctions Oracle), ComplyAdvantage (PEP / adverse-media lists), Sumsub / Onfido (KYC).
  • Authorities — FIUs, the FCA, FINTRAC and the AMLA, on lawful request. We log every such disclosure.
  • Counterparty VASPs — only the Travel Rule data required by Regulation (EU) 2023/1113 and equivalent rules.

We do not sell personal data. We do not enable cross-context behavioural advertising.

5. International transfers

Some vendors are outside the EEA. Where so, transfers happen under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) together with documented Transfer Impact Assessments, and — for the UK — the ICO's International Data Transfer Addendum. Canadian customers' data is processed in jurisdictions with comparable protection or under PIPEDA-compliant contractual safeguards.

6. How long we keep it

DataRetentionReason
KYC documents5 years after account closureArt. 21 AMLR / FCA MLR 2017 reg. 40
Transaction records5 years after the transactionAML rulebook
Support correspondence3 yearsLegitimate interest, dispute defence
Marketing consent logUntil you withdraw + 6 monthsAccountability
Server access logs13 monthsEDPB guidance on access logs

7. Your rights

Under GDPR Articles 15–22, UK GDPR and PIPEDA you can: access, rectify, erase, restrict, port and object. Use the dashboard or email privacy@fotifypay.com. We answer within 30 days (extendable by 60 days for complex requests, per Art. 12(3) GDPR).

We may refuse erasure where AML retention law overrides — but we always tell you which article we relied on. See the dedicated GDPR — your rights page for the full walkthrough.

8. Right to lodge a complaint

  • EU customers: your national Data Protection Authority — the list is at edpb.europa.eu.
  • UK customers: the Information Commissioner's Office (ICO).
  • Canadian customers: the Office of the Privacy Commissioner of Canada.

9. Security

Encryption in transit (TLS 1.2+) and at rest (AES-256). Two-factor authentication via Telegram OTP and Google Authenticator. Segregated production database, principle of least privilege, mandatory code review, quarterly penetration tests. We comply with the operational-resilience requirements of Regulation (EU) 2022/2554 (DORA).

10. Changes to this policy

Material changes are announced 30 days in advance by email and on this page. The version number and "Last updated" timestamp at the top of this document are the authoritative record.

This document is part of FotifyPay's binding legal framework. If a translated version differs from the English original, the English text prevails. For complaints, contact legal@fotifypay.com — or escalate to the regulator listed on our Regulatory framework page.

🌉 FotifyPay

A calmer on-ramp to crypto

Buy Bitcoin, Ethereum and USDT with EUR, CAD or GBP — through Open Banking or card. Built for the EU, UK and Canada.

Product

  • Home
  • How it works
  • Security
  • Loyalty
  • Rates
  • FAQ

Partner

  • Affiliate program
  • APM partnerships
  • Open Banking providers
  • Large-client pricing

Legal

  • Privacy policy
  • Terms of service
  • GDPR — your rights
  • AML / KYC policy
  • Cookies
  • Regulatory framework

Contact

  • support@fotifypay.com
  • legal@fotifypay.com
  • partners@fotifypay.com
  • Telegram support

FotifyPay © 2026 — FCA reg. №928910 · FINTRAC MSB · MiCA CASP · GDPR compliant

Not investment advice. Crypto assets are volatile and not covered by deposit-protection schemes. Past performance is no guarantee of future results.