Privacy & Legal Policies
Privacy Policy
This Privacy Policy explains how Fipto PI SAS, trading as Crypto2Cash (“Crypto2Cash”, “we”, “our” or “us”), collects, uses, stores and protects your personal data when you visit our website, use our platform or services, or otherwise interact with us.
Crypto2Cash is a trading name of Fipto PI SAS, a company incorporated in France with Company No. 929 508 893, having its registered office at 65 Rue de la Croix, 92000 Nanterre, France.
This Privacy Policy has been prepared in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection legislation.
Types of data we collect
We may collect:
Personal information such as your name, contact details, date of birth, identification documents, financial information and any information required to establish or maintain a customer relationship.
Technical information, including IP address, browser type, operating system, device information and website usage data.
Information collected through cookies and similar technologies. Some cookies may contain personal data or unique identifiers.
Why we collect your data
We process personal data for purposes including:
responding to enquiries;
onboarding potential customers;
providing our services;
complying with legal and regulatory obligations, including AML/KYC requirements;
preventing fraud and financial crime;
improving our website, platform and services;
communicating with you regarding your account or our services.
Where required by law, we will request your consent before processing your data.
How we collect information
Information you provide directly
We collect information when you:
complete contact forms;
register for an account;
provide identification documents;
communicate with us by email, telephone or through our platform;
become a customer.
Customer information will be retained for the period required by applicable law and our regulatory obligations.
We use Zendesk to provide customer support. Communications with our support team may therefore be stored within Zendesk.
Information collected automatically
When you visit our website or use our platform we may automatically collect technical information including:
IP address;
browser and device information;
operating system;
approximate location (where permitted);
website usage information.
This information helps us improve security and our services.
If we offer login through third-party providers or social media platforms, any information shared with us is governed by the privacy policies of those providers.
Communications
If you contact us, we may communicate with you by email, telephone or through our secure platform.
Where you become a customer, certain service-related communications are mandatory and cannot be opted out of while you maintain an active customer relationship.
Marketing communications will only be sent where permitted by applicable law, and you may unsubscribe at any time.
Updating your information
You may request access to, correction of or deletion of your personal data, subject to our legal and regulatory obligations.
Requests may be sent to:
Protecting your information
We use appropriate technical and organisational security measures to protect your information, including:
encryption;
multi-factor authentication;
access controls;
secure infrastructure;
monitoring and logging;
restricted employee access based upon business need.
Sharing your information
We may disclose information:
to banks, payment providers, liquidity providers or other service providers where necessary to provide our services;
to identity verification providers;
to blockchain analytics providers;
where required by law, regulation or court order;
where necessary to protect our legal rights or prevent fraud or financial crime.
We do not sell your personal data.
Legal Policies
Conflicts of Interest
Crypto2Cash is committed to identifying, preventing and managing conflicts of interest.
The Company operates a Three Lines of Defence (3LoD) governance model to ensure appropriate segregation of duties and independent oversight.
Employees, directors and contractors are required to act honestly, fairly and in the best interests of customers while complying with all applicable laws and internal policies.
Business considerations must never override compliance with AML, sanctions, fraud prevention or other legal and regulatory obligations.
Employees must immediately report any actual, potential or perceived conflict of interest.
Where a conflict cannot be appropriately managed, the Company may refuse to onboard a customer or provide a particular service.
The Board of Directors is responsible for maintaining an effective conflicts of interest framework and ensuring appropriate systems and controls remain in place.
Examples of conflicts include situations where an employee:
could obtain a personal financial benefit;
could avoid a personal financial loss;
has an interest that conflicts with the Company’s regulatory obligations;
receives an inappropriate benefit or inducement from a third party;
has any other personal interest that could impair objective decision-making.
Employees who have a conflict of interest must not participate in decisions relating to the affected customer or transaction.
Legal Policy
This section constitutes the Legal Policies of C2C Solutions sp.z o.o
Conflict of interests:
In order to avoid conflicts of interest within the Company, the Company has established strict separation of functions principles as follows:
- The Company operates on a three lines of defence model, each of them having a separate function and each of them having separate persons fulfilling them. The fulfilment of the functions does not overlap, i.e. conflict of interests is avoided.
- The 3LoD does not assess the functioning of the internal audit (i.e., the internal auditor does not audit itself). Consequently, the internal auditor will not be involved in the development of any internal rules as the internal auditor must subsequently assess the function of the internal control system.
- The especially appointed AML Officer is responsible for putting a framework in place, and implementing necessary systems, controls and procedures to identify, escalate and manage potential conflict of interests effectively.
The Company must also avoid situations where the interests of the owners, directors and the employees of the Company (including contractors etc.) and the interests of the Customers would be in a conflict. This means the following:
- Employees must always fulfil the obligations included in this Policy and/or as stated in applicable law;
- Obligation to fulfil the obligations and rights from the Policy, including the obligation to implement the DD measures fully, must always be more important than the interest of bringing in new business (establishing new Business Relationship(s)) or servicing existing Customers;
- Employees must identify and escalate potential conflict of interests so that they may be appropriately managed and resolved;
The Board of Directors is responsible for putting the framework in place, and implementing necessary systems, controls and procedures to identify, escalate and manage potential conflict of interests effectively;
Seeking to determine potential conflict of interests that might affect the Company detrimentally relating to its fulfilment of the requirements set out in this Policy and applicable AML legislation, the Company appoints dedicated Employees that should observe the following minimum criteria and assess whether any Employees are exposed to any of the situations listed below, when the employee:
- may experience a financial advantage or avoid a financial loss at the potential expense of the compliance with the AML legislation or this Policy;
- has an interest in the result of the rendered service or in the result of a transaction concluded at the potential expense of the Company’s compliance with the AML regulation or this policy;
- receives or will receive from a person (other than the Customer) an inducement in relation to a service provided to the Customer, in the form of monies, goods or services, other than a standard commission or fee for that service;
An example conflict of interests is where an Employee would prefer personal financial gains to properly implementing the Company’s obligations and/or rights from the Policy and/or the applicable law.
In the performance of their functions, each Employee must ascertain whether there is any conflict of interests and avoid conflict of interests. An Employee who is exposed to the conflict of interests must not be responsible for dealing with the relevant Customer and such function should be fulfilled by another Employee who is not in the conflict of interest. If the conflict of interest cannot be avoided by any Employees, then such a Customer will not be onboarded and/or provided services by the Company.