cripto.md cripto.md Privacy
Legal

Privacy policy

What personal data we process, why, how long we keep it and what rights you have. A crypto exchange is required by law to know its customers, so we ask for more than an online shop would. We do not sell your data and do not use it for advertising.

Version
1.0
Last updated
26 September 2026

1. Who processes your data

The data controller is December Capital SRL, IDNO 1005600041997, with its registered office at str. M. Sadoveanu 28, Chisinau, Republic of Moldova, which operates the cripto.md service.

For any question about your data, write to support@cripto.md with the subject "Personal data". Your message reaches the person responsible for data protection.

2. What data we process

CategoryExamples
Account dataemail address, phone number, password (kept only in encrypted form), preferred language, two step authentication settings
Identification datafirst and last name, date of birth, IDNP or other personal number, citizenship, details and image of your identity document, verification photo, home address
Financial dataIBAN, last digits of your card, crypto receiving addresses, amounts, rates and order history, blockchain transaction identifiers
Compliance dataoccupation, source of funds and wealth (for large amounts), politically exposed person status, results of sanctions screening and crypto address analysis
Technical dataIP address, browser and device type, date and time of sign-ins, security logs
Communicationsmessages you send us, complaints and our replies

We ask for identification and compliance data only when you go above the limits without verification or when the law requires it. We do not process data about health, religion or political opinions. We check politically exposed person status because the law requires us to.

3. Why we process it and on what basis

PurposeLegal basis
Creating and running your account, executing conversions, sending messages about ordersperformance of our contract with you
Identity verification, transaction monitoring, sanctions screening, reporting to authorities, record keepinglegal obligation (Law No. 308/2017 on preventing and combating money laundering and terrorist financing)
Accounting and tax recordslegal obligation
Protecting your account, preventing fraud, keeping the site secureour legitimate interest, and yours in not being defrauded
Handling complaints and defending legal claimslegitimate interest and legal obligation
News and offersyour consent, which you can withdraw at any time

If you do not give us the data the law requires, we cannot open your account or execute your order.

4. Automated decisions

We use automated tools to check your identity document and photo, to compare names against sanctions lists and to assess the risk of crypto addresses. Where an automated result would lead to an account or an order being refused, the final decision is taken by a person on the compliance team. You can ask for an explanation and for the decision to be reviewed.

5. How long we keep data

  • Identification data, compliance data and transaction records: 5 years from the end of our relationship or from the date of an occasional transaction, as Law No. 308/2017 requires, or longer if an authority asks us in writing to extend it.
  • Accounting documents: the period set by accounting and tax law.
  • Account data with no transactions: until the account is closed.
  • Technical and security logs: up to 12 months.
  • Complaints: 5 years from resolution.
  • Data for promotional messages: until you withdraw consent.

When the period ends, the data is deleted or anonymised.

6. Who we share data with

We do not sell or rent personal data. We share it only as far as necessary with:

  • providers working for us, under a contract that binds them to protect the data: server hosting, email delivery, identity verification, crypto address analysis;
  • banks and payment processors, to carry out your payments, once they are connected;
  • authorities, where the law requires: the Service for Prevention and Combating of Money Laundering, the National Commission for Financial Markets, the State Tax Service, criminal investigation bodies and the courts;
  • other crypto service providers, only the originator and beneficiary information the law requires to travel with a transfer (the travel rule).

7. Transfers outside the Republic of Moldova

Some providers may process data in the European Union or in other countries. We transfer data outside the Republic of Moldova only to countries that ensure an adequate level of protection or with the safeguards provided by Law No. 195/2024, for example standard contractual clauses. On request, we tell you which safeguards apply.

8. Your rights

Under Law No. 195/2024 on personal data protection, you have the right:

  • to find out what data we process about you and to receive a copy;
  • to have wrong or incomplete data corrected;
  • to have data deleted when we no longer have grounds to keep it;
  • to have processing restricted;
  • to receive the data you gave us in a structured format, to pass it to another controller;
  • to object to processing based on legitimate interest;
  • to withdraw your consent at any time, without affecting processing done before;
  • not to be subject to a decision based solely on automated processing.

Write to support@cripto.md. We answer free of charge within one month, which may be extended by two further months for complex requests, in which case we tell you. To protect you, we may ask you to confirm your identity before answering.

Some rights are limited by law. For example, we cannot delete data Law No. 308/2017 requires us to keep, and we cannot tell you about a report made to the authorities.

If you believe we process your data unlawfully, you can complain to the National Center for Personal Data Protection (datepersonale.md) or go to court.

9. How we protect data

  • the connection to the site is encrypted (HTTPS), and passwords are stored only in irreversibly encrypted form;
  • withdrawals and sensitive account changes require two step confirmation;
  • staff access to data is limited to those who need it and is logged;
  • the internal panel can only be reached from authorised networks.

If a data breach puts your rights at risk, we notify you and the supervisory authority within the time limits set by law.

10. Cookies and local storage

We use no advertising cookies, no third-party analytics and no tracking pixels. We use only:

NameTypeWhat it does
cm_sessionessential cookiekeeps you signed in; expires when you sign out or when the session ends
cm.langlocal storagethe language you chose
cm.themelocal storagelight or dark theme
cm.draftlocal storagean order you started, so a page reload does not lose it
cm.noticelocal storageremembers that you have seen the notice about the state of the site, so it does not appear again

These are strictly necessary for the site to work, so they do not require consent. You can clear them at any time in your browser settings.

11. Minors

The service is not intended for anyone under 18. If we learn we have collected a minor's data, we delete it, except what the law requires us to keep.

12. Changes

We may update this policy. The current version is always on this page, with the date of the last update. We email you about material changes before they apply.