Privacy Policy
Please note that this privacy statement will be updated periodically.
Cryptool ("Cryptool", "we", or "us") is committed to protecting the privacy of our customers, and we take our data protection responsibilities with the utmost seriousness.
This Privacy Policy describes how Cryptool collects and processes your personal data through the Cryptool websites and applications that are referenced in this Privacy Policy. Cryptool refers to an ecosystem comprising Cryptool websites (whose domain names include but are not limited to www.cryptool.io, mobile applications, clients, applets and other applications that are developed to offer Cryptool Services, and includes independently-operated platforms, websites and clients within the ecosystem.
This Privacy Policy applies to all Personal data processing activities carried out by us, across platforms, websites, and departments of Cryptool.
To the extent that you are a customer or user of our services, this Privacy Policy applies together with any terms of business and other contractual documents, including but not limited to any agreements we may have with you.
To the extent that you are not a relevant stakeholder, customer, or user of our services, but are using our website, this Privacy Policy also applies to you together with our Cookie Policy.
This Policy should therefore be read together with our Cookie Policy, which provides further details on our use of cookies on the website.
What Personal Data does Cryptool collect and process?
Personal data is data that identifies an individual or relates to an identifiable individual. This includes information you provide to us, information which is collected about you automatically, and information we obtain from third parties.
Information you provide to us. To open an account and access our services, we'll ask you to provide us with some information about yourself. This information is either required by law (e.g., to verify your identity and comply with KYC "Know Your Customer" obligations), necessary to provide the requested services (e.g., you will need to provide your email address in order to open your account), or is relevant for certain specified purposes, described in greater detail below. In some cases, if we add services and features you may be asked to provide us with additional information.
Failure in providing the data required implies that Cryptool will not be able to offer you our services.
We may collect the following types of information from you:
Category of Personal Data | Types of Personal Data |
Personal Identification Data. | Full name, e-mail address, gender, home address, phone number, date of birth, nationality, signature, utility bills, photographs, and a video or voice recording of you |
Sensitive and Biometric Personal Data | Cryptool may also collect sensitive personal data when permitted by local law or with your consent, such as biometric information, for example to verify your identity by comparing the facial scan data extracted from your selfie or video with the photo in your government issued identity document |
Government Identifiers | Government issued identity documents such as passport, national identification number, national identity card details, drivers license numbers |
Online Identifiers | Social media domains/ profiles (such as Telegram, X, etc.) |
Institutional Information | Proof of legal formation, personal identification data for all material beneficial owners, personal data about the board of directors senior persons responsible for the operations of the body corporate |
Financial Information | Bank account information, payment card information, source of funding, source of wealth, Cryptool account information, Cryptool user ID and pay ID |
Wallet Information | Wallet address, wallet ID, and other information related to integrations that you select |
Transaction Information | Information about the transaction you make on our services, such as the name of the recipient, your name and email |
Information from Cookies | See our Cookie Policy for more information. |
Employment Information | Job title, salary wage rate, and company |
Communications | Surveys responses, information contained in the Survey. Communications with us including call recordings with our customer services team. |
Contact Information | E-mail address, country, region, |
Information we collect from you automatically. To the extent permitted under the applicable law, we may collect certain types of information automatically, for example whenever you interact with us or use the services. This information helps us address customer support issues, improve the performance of our sites and services, maintain and or improve your user experience, and protect your account from fraud by detecting unauthorized access.
Information collected automatically includes:
Category of Personal Data | Types of Personal Data |
Browsing Information | Device ID, browsing information such as name and version, Internet Protocol ("IP") address , internet connectivity data, operator and carrier data, login data, browser type and version, device type category and model, time zone setting and location data, language data, application version. browser plug-in types and versions, operating system and platform, other information stored on or available regarding the devices you allow us access to when you visit our Platforms |
Usage Data | Authentication data, security questions, click-stream data, public social networking posts, and other data collected via cookies or similar technologies. Information about how our Services are performing when you use them, e.g., error messages you receive, performance of the site information, other diagnosis data. |
Marketing and Research Information | Identifiers – the IP address, or other online identifiers of a person, e-mail address if used for direct marketing, and name and address Demographic data - (e.g., income, family status, age bracket, gender, interests, etc) Browser/web history data and preferences expressed through selection/viewing/purchase of goods, services and content, information about your mobile device including (where available) type of device, device identification number, mobile operating system. Analytics and profiles of the individuals based on the data collected on them. For more information about this please see our Cookie Policy. Interests or inferred interests and marketing preferences. |
Information we collect from our affiliates and third parties.
From time to time, we may obtain information about you from our affiliates or third parties sources as required or permitted by applicable law.
Category of Personal Data | Type of Personal Data |
Affiliates | In accordance with applicable law, we may obtain information about you from the group of companies related to us by common control or ownership ("Affiliates") as a normal part of conducting business, so that we may offer our Affiliates' Services to you. We may obtain information about you such as Personal Identification Data, Transactional Information, Institutional Information, Usage Information. For example, if you want to convert cryptocurrency into fiat and make withdrawals into your bank account, we might need to exchange information with Cryptool Connect. For more information about how Cryptool Connect processes this information you can check its Privacy Policy here. |
Blockchain Data | We may analyze public blockchain data, such as transaction ID's, transaction amounts, wallet address, timestamps or transactions or events. |
Retail Merchant Information | When conducting a transaction with a third-party merchant, the merchant may provide us with personal data about you such as name, contact information, transaction information. |
2. Why does Cryptool process my personal data? Which legal bases are we relying on for our collection and processing of your personal data?
Our primary purpose in collecting personal data is to provide our services in a secure, efficient, and smooth way. We generally use your personal data to deliver, provide, operate, our services, and for content and advertising, and for loss prevention and anti-fraud purposes. Below you'll find an explanation on how we use Automated individual decision-making, including profiling. Cryptool does not rely solely on automated tools to help determine whether a transaction or a customer account presents a fraud or legal risk.
Why does Cryptool process my Personal Data? | Legal Basis for our use of personal data (EEA and Switzerland EU GDPR) |
Managing our contractual relationship with you. To create and maintain your account. This includes when we use your personal data to take and handle orders and process payments. The Category of Personal Data processed is Personal Identification Data, Institutional Information, Contact Information, Financial Information. The consequences of not processing your personal data for such purposes is the inability to open an account with us or the termination of your account where one is already open. | Processing is necessary for the performance of a contract of which you are a party. |
To maintain legal and regulatory compliance Most of our core services such as the exchange services are subject to strict and specific laws and regulations requiring us to collect, use and store certain personal data and process Personal Identification identity information and in some cases Sensitive Personal Data[(including biometrics) (as detailed in section I) For example to comply with our Know Your Customer ("KYC") obligations under applicable laws and regulations, and in particular to comply with Anti-Money Laundering laws and regulations. The Category of Personal Data is Personal Identification Data , Institutional Information, Sensitive and Biometric information, Government Identifiers, Contact Information, Financial Information. If you do not provide personal information required by law, you may be unable to open an account, or we may have to close your account where it is already opened. | Processing is necessary to comply with our legal obligations under applicable laws and regulations, and Anti-Money Laundering laws and regulations. Processing is necessary for reasons of substantial public interest based on EU or EU Member State law. We are subject to EU Anti-Money Laundering Directives and the relevant EU Member States' law implementing them which require us to process for instance information from your ID documents including a photographic picture of you and a visual image of your face (the so called "liveness check"). |
Communicate with you on service and transaction- related matters. We use your personal data to communicate with you in relation to Cryptool Services on administrative or account-related information. We will communicate with you to keep you updated about our Services for example, to inform you of relevant security issues, updates, or provide other transaction-related information. Without such communications, you may not be aware of important developments relating to your account that may affect how you can use our services. You may not opt-out of receiving critical service communications, such as emails or mobile notifications sent for legal or security purposes. | Processing is necessary for the performance of a contract of which you are a party. |
To provide customer services: We process your personal data when you contact us in order to provide support with respect to questions, disputes, complaints, troubleshoot problems, etc. The Category of Personal Data processed is Personal Identification Data, Institutional Information, Transactional Information, Communications, Contact Information, Financial Information, Browsing Information, Usage Data. Without processing your personal data for this purpose, we can't respond to your requests. | Processing is necessary for the performance of a contract of which you are a party. Processing is necessary for the purpose of the legitimate interest pursued by us to improve our services and enhance our user experience. |
To promote safety, security, and integrity of our platform. We process your personal data in order to enhance security, monitor and verify identity or service access, combat malware or security risks and to comply with applicable security laws and regulations. We process your personal data to verify accounts and related activity, find and address violations of our Terms and Conditions, investigate suspicious activity, detect, prevent and combat unlawful behavior, detect fraud, and maintain the integrity of our Services. The Category of Personal Data processed is Personal Identification Information, Institutional Information, Transactional Information, Contact Information, Financial Information, Browsing Information, Usage Data. Without processing your personal information, we may not be able to ensure the security of our Services. We use your personal data to provide functionality, analyze performance, fix errors, and improve the usability and effectiveness of Cryptool Services. | Processing is necessary for the performance of a contract of which you are a party. |
To promote safety, security, and integrity of our Services. Fraud prevention and detection and credit risks. The Category of Personal Data processed is Personal Identification Data, Institutional Information, Transactional Information, Contact Information, Financial Information, Browsing Information, Usage Data. We process Personal Identification Data to prevent and detect, prevent and mitigate fraud and abuse of our services and in order to protect you against account compromise or funds loss and in order to ensure the security of our users, Cryptool services and others. We may also use scoring methods to assess and manage credit risks. Please note that we may engage in automated decision-making for purposes of risk and fraud detection. When we do, we implement suitable measures to safeguard your rights and freedoms and legitimate interests, including the right to obtain human intervention, to express your point of view and to contest the decision.Please refer below to Section 9 for more information. | Processing is necessary for the purpose of the legitimate interests pursued by us and the interests of our users when, for example, we detect and prevent fraud and abuse in order to protect the security of our users, ourselves, or others; |
To provide Cryptool services. We process your personal data to provide the services to you , process your orders, facilitate transactions and to complete the transactions the Users require. For example, when you want to use the exchange service on our platform, we ask for certain information such as your identification, contact information, and payment information. The Category of Personal Data processed is Personal Identification Data, Institutional Information, Transactional Information, Contact Information, Financial Information, Browsing Information, Usage Data. We cannot provide you with services without such information. | Processing is necessary for the performance of a contract of which you are a party. Processing is necessary for the purpose of our legitimate interest and your interest in providing better documentation for your transactions. |
To use the services of social media platforms or advertising platforms for purposes including marketing The category of personal data processed is Usage Data, Browsing Information. | We rely on your consent to process your personal data to use the services of advertising platforms. When you consent to processing your personal information for a specified purpose, you may withdraw your consent at any time and we will stop processing your personal information for that purpose. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
To improve our services. We process personal data to improve our services and for you to have a better user experience; The Category of Personal Data processed is Personal Identification Data, Institutional Information, Transactional Information, Browsing Information, Usage Data. | Processing is necessary for the purpose of the legitimate interest pursued by us to improve our services and enhance our user experience. |
To provide you with promotions We use your information to provide you with promotions, including offers, rewards, and other incentives for using our Services. This would also enable you to partake in a prize draw, competition or complete a survey. The Category of Personal Data processed is Personal Identification Data, Institutional Information, Transactional Information, Browsing Information, Usage Data and Online Identifiers. | For non-users, processing is necessary for the purpose of our legitimate interest and your interest to reward your customer loyalty. For users, we rely on your consent to process your personal data to provide you with promotions. When you consent to processing your personal information for a specified purpose, you may withdraw your consent at any time and we will stop processing your personal information for that purpose. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
To do research and innovate. We carry out surveys to learn more about your experience using our Services. We also use your information to support research and development and drive innovations of our Services and products. This information will also be used for Marketing purposes. | Processing is necessary for the purpose of our legitimate interest to improve and run our Services through information obtained from these surveys. |
For internal business purposes and record keeping. The Category of Personal Data processed is Personal Identification Data, Financial Information, Transaction Information and Browsing Information. | Processing is necessary for the purpose of the legitimate interest pursued by us to keep records to ensure that you comply with your contractual obligations pursuant to the agreement ("Terms and Conditions") governing our relationship with you. Processing is necessary to comply with our legal obligations to keep certain records for internal business and research purposes as well as for record keeping purposes. |
Recommendations and personalisation. We use your personal information to recommend features and services that might be of interest to you, identify your preferences, and personalize your experience with Cryptool services; | Processing is necessary for the purpose of our legitimate interest to provide a personalized service to our customers. Processing is necessary for the performance of a contract of which you are a party. |
To provide marketing communications to you. We use your information based on your consent to send you targeted marketing communications through email, mobile, in-app, and push notifications. We also use your information to carry out profiling for marketing purposes. The Category of Personal Data processed is Personal Identification Information, Institutional Information, Transactional Information, Browsing Information, Usage Data, Marketing and Research Information, Communications. | Where required by applicable law, we rely on your consent to process your personal information for marketing purposes. When you consent to processing your personal information for a specified purpose, you may withdraw your consent at any time and we will stop processing your personal information for that purpose. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Where we carry out profiling for marketing purposes, for example to establish what Services or promotions you may be interested in, this processing is based on legitimate interest. Transactional account messages and communications regarding our business relationship will not be affected even if you opt-out from marketing communications. |
Cookies: where we use cookies and similar technologies as part of our Service. The Category of Personal Data processed is Information from Cookies. | Where required by applicable law, we rely on your consent to place cookies and similar technologies. When you consent to processing your personal information for a specified purpose, you may withdraw your consent at any time and we will stop processing your personal information for that purpose. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal |
To comply with other legal and regulatory obligations. We may access, read, preserve, and disclose information when we believe it is reasonably necessary to comply with law, legal obligations, regulations, law enforcement, government, and other legal requests, court orders, or disclosure to tax authorities in line with the detailed information set forth under Section 5. The Category of Personal Data processed is Personal Identification Information, Institutional Information, Financial Information, Transactional Information, Browsing Information, Usage Data, Blockchain Data. | Processing is necessary to comply with our legal obligations under applicable laws and regulations We may also rely on legitimate interests in responding to legal requests where we are not compelled by applicable law but have a good faith belief it is required by law in the relevant jurisdiction. |
Can Children Use Cryptool Services?
Cryptool services are exclusively for individuals aged 18 and above. We do not knowingly request or collect information from individuals under the age of 18. If you are under 18, please refrain from providing any personal information to Cryptool. If we suspect that a user is under 18, we will require them to close their account and promptly delete their information.
What About Cookies and Other Identifiers?
We utilize cookies and similar tools to improve user experience, enhance our services, and refine our marketing efforts. Depending on your location, your browser's cookie banner will guide you on accepting or refusing cookies. For detailed information, refer to our cookie policy.
How and Why We Share Your Personal Data?
We may share your personal data with third parties under various circumstances, including compliance with contractual agreements, applicable laws, or legal processes. This may involve sharing data with other Cryptool entities or third-party service providers to facilitate functions such as data analysis, marketing, payment processing, and risk management. We also may disclose information to legal authorities or in business transfers, with your consent, or as described in Policies provided to you.
International Transfers of Personal Information
To support our global operations, we may transfer your personal information outside of the European Economic Area (EEA), UK, and Switzerland. These transfers, also known as "third country transfers," may involve sending data to our affiliates, third-party partners, or service providers worldwide. We implement suitable technical, organizational, and contractual safeguards, including Standard Contractual Clauses, to ensure compliance with applicable data protection regulations. Additionally, we rely on adequacy decisions from the European Commission regarding certain countries or territories outside the EEA that provide an adequate level of protection for personal information.
How Secure is My Information?
At Cryptool, we prioritize the security and privacy of your information. Our systems are designed with robust security measures to prevent unauthorized access, alteration, or disclosure of your data. We employ encryption protocols and software to safeguard your personal data during transmission and storage. Additionally, we maintain physical, electronic, and procedural safeguards to ensure the confidentiality of your information. Access to your data is restricted to authorized personnel only, including employees, agents, contractors, and relevant third parties. To further enhance security, we may request identity verification when accessing your account. We advise using a unique password for your Cryptool account and logging out on shared devices to mitigate potential risks.
What About Advertising?
In order to enhance your user experience, we may share your personal data with our marketing partners for targeted advertising and analytics purposes. However, you have the right to object to the processing of your personal data for direct marketing purposes.
What Rights Do I Have?
You have various rights concerning your privacy and personal data protection. These include the right to access, correct, delete, or request data portability of your personal data. You may also object to our data processing activities or request restrictions under certain circumstances. Furthermore, you have the right to withdraw consent for processing and lodge complaints with relevant data protection authorities. To exercise these rights, please contact us using the provided webform.
Cryptool Permissions
By creating a group, you acknowledge and agree to these terms, granting super admins full access to the group, including its settings and data, for administrative, security, and compliance purposes. Super admins have the authority to access group content and user update/change data as part of their responsibilities, such as platform settings, maintenance, legal compliance, and security oversight. This access is strictly limited to legitimate business purposes and is conducted in accordance with applicable privacy laws and regulations.
How Long Does Cryptool Keep My Personal Data?
We retain your personal data for as long as necessary to provide Cryptool services and fulfill legal obligations. Retention periods may vary depending on jurisdiction and specific purposes. For instance, data collected for compliance with financial laws may be retained for a longer duration. We keep contact information for marketing purposes until unsubscribed or account deletion. Content posted on our platform and voice call recordings may be retained for audit and dispute resolution purposes. Information collected via cookies and analytics tools is typically kept for up to one year from collection.
Policies and Revisions
Privacy practices at Cryptool may change over time, reflecting our evolving business and legal requirements. Any updates to our Privacy Policy will be communicated through our platform or via email. Your continued use of Cryptool implies acceptance of these changes. For inquiries or concerns about privacy, please contact us or your local Data Protection Authority.
Languages
While this Privacy Policy may be available in multiple languages, the English version prevails in case of any discrepancies.
Contact Information
For questions or issues regarding the collection and processing of your personal data, please reach out to our Data Protection Officer using the provided webform or email. For account management and product-related inquiries, contact our Customer Support team through the webform.