1. Who processes your data
The data controller is December Capital SRL, IDNO 1005600041997, with its registered office at str. M. Sadoveanu 28, Chisinau, Republic of Moldova, which operates the cripto.md service.
For any question about your data, write to support@cripto.md with the subject "Personal data". Your message reaches the person responsible for data protection.
2. What data we process
| Category | Examples |
|---|---|
| Account data | email address, phone number, password (kept only in encrypted form), preferred language, two step authentication settings |
| Identification data | first and last name, date of birth, IDNP or other personal number, citizenship, details and image of your identity document, verification photo, home address |
| Financial data | IBAN, last digits of your card, crypto receiving addresses, amounts, rates and order history, blockchain transaction identifiers |
| Compliance data | occupation, source of funds and wealth (for large amounts), politically exposed person status, results of sanctions screening and crypto address analysis |
| Technical data | IP address, browser and device type, date and time of sign-ins, security logs |
| Communications | messages you send us, complaints and our replies |
We ask for identification and compliance data only when you go above the limits without verification or when the law requires it. We do not process data about health, religion or political opinions. We check politically exposed person status because the law requires us to.
3. Why we process it and on what basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account, executing conversions, sending messages about orders | performance of our contract with you |
| Identity verification, transaction monitoring, sanctions screening, reporting to authorities, record keeping | legal obligation (Law No. 308/2017 on preventing and combating money laundering and terrorist financing) |
| Accounting and tax records | legal obligation |
| Protecting your account, preventing fraud, keeping the site secure | our legitimate interest, and yours in not being defrauded |
| Handling complaints and defending legal claims | legitimate interest and legal obligation |
| News and offers | your consent, which you can withdraw at any time |
If you do not give us the data the law requires, we cannot open your account or execute your order.
4. Automated decisions
We use automated tools to check your identity document and photo, to compare names against sanctions lists and to assess the risk of crypto addresses. Where an automated result would lead to an account or an order being refused, the final decision is taken by a person on the compliance team. You can ask for an explanation and for the decision to be reviewed.
5. How long we keep data
- Identification data, compliance data and transaction records: 5 years from the end of our relationship or from the date of an occasional transaction, as Law No. 308/2017 requires, or longer if an authority asks us in writing to extend it.
- Accounting documents: the period set by accounting and tax law.
- Account data with no transactions: until the account is closed.
- Technical and security logs: up to 12 months.
- Complaints: 5 years from resolution.
- Data for promotional messages: until you withdraw consent.
When the period ends, the data is deleted or anonymised.
6. Who we share data with
We do not sell or rent personal data. We share it only as far as necessary with:
- providers working for us, under a contract that binds them to protect the data: server hosting, email delivery, identity verification, crypto address analysis;
- banks and payment processors, to carry out your payments, once they are connected;
- authorities, where the law requires: the Service for Prevention and Combating of Money Laundering, the National Commission for Financial Markets, the State Tax Service, criminal investigation bodies and the courts;
- other crypto service providers, only the originator and beneficiary information the law requires to travel with a transfer (the travel rule).
7. Transfers outside the Republic of Moldova
Some providers may process data in the European Union or in other countries. We transfer data outside the Republic of Moldova only to countries that ensure an adequate level of protection or with the safeguards provided by Law No. 195/2024, for example standard contractual clauses. On request, we tell you which safeguards apply.
8. Your rights
Under Law No. 195/2024 on personal data protection, you have the right:
- to find out what data we process about you and to receive a copy;
- to have wrong or incomplete data corrected;
- to have data deleted when we no longer have grounds to keep it;
- to have processing restricted;
- to receive the data you gave us in a structured format, to pass it to another controller;
- to object to processing based on legitimate interest;
- to withdraw your consent at any time, without affecting processing done before;
- not to be subject to a decision based solely on automated processing.
Write to support@cripto.md. We answer free of charge within one month, which may be extended by two further months for complex requests, in which case we tell you. To protect you, we may ask you to confirm your identity before answering.
Some rights are limited by law. For example, we cannot delete data Law No. 308/2017 requires us to keep, and we cannot tell you about a report made to the authorities.
If you believe we process your data unlawfully, you can complain to the National Center for Personal Data Protection (datepersonale.md) or go to court.
9. How we protect data
- the connection to the site is encrypted (HTTPS), and passwords are stored only in irreversibly encrypted form;
- withdrawals and sensitive account changes require two step confirmation;
- staff access to data is limited to those who need it and is logged;
- the internal panel can only be reached from authorised networks.
If a data breach puts your rights at risk, we notify you and the supervisory authority within the time limits set by law.
10. Cookies and local storage
We use no advertising cookies, no third-party analytics and no tracking pixels. We use only:
| Name | Type | What it does |
|---|---|---|
cm_session | essential cookie | keeps you signed in; expires when you sign out or when the session ends |
cm.lang | local storage | the language you chose |
cm.theme | local storage | light or dark theme |
cm.draft | local storage | an order you started, so a page reload does not lose it |
cm.notice | local storage | remembers that you have seen the notice about the state of the site, so it does not appear again |
These are strictly necessary for the site to work, so they do not require consent. You can clear them at any time in your browser settings.
11. Minors
The service is not intended for anyone under 18. If we learn we have collected a minor's data, we delete it, except what the law requires us to keep.
12. Changes
We may update this policy. The current version is always on this page, with the date of the last update. We email you about material changes before they apply.