Kassio

Privacy Policy

This Privacy Policy describes how we collect and use personal information in connection with the Kassio platform. The data controller for the personal data when accessing Kassio’s platform is Kassio ApS, company registration number (CVR): 42 71 54 09 (hereinafter referred to as “Kassio”, “We”, “Us”, “Our”). This Privacy Policy is an integrated part of the terms of service, which can be found here Terms and Conditions.

We may modify this Privacy Policy from time to time which will be indicated by changing the date on this page. If we make any material changes, we will notify you by email (sent to the email address specified in your account), by means of a notice on our Services prior to the change becoming effective, or as otherwise required by law.

Personal Data Collected

  1. Personal data is data that can be used to identify you directly or indirectly. The Privacy Policy covers all personal data that you voluntarily submit to us and that we obtain from our partners. This privacy policy does not apply to anonymised data as this cannot be used to identify you.
  2. We collect the following types of information:
    1. Full name, date of birth, age, nationality, gender, signature, utility bills, photographs, phone number, home address, and/or email.
    2. Tax/ other ID number, passport number, driver’s license details, national identity card details, photograph identification cards, and/or visa information.
    3. Bank account information, payment card primary account number (PAN), transaction history, trading data, and/or tax identification.
    4. Information on whether you hold a prominent public function (PEP).
    5. Information about the transactions you make on our services, such as the name of the recipient, your name, the amount, and/or timestamp.
    6. Office location, job title, and/or description of role.
  3. Information we collect about you automatically.
    1. Location Information – Information that is automatically collected via analytics systems providers to determine your location, including your IP address and/or domain name and any external page that referred you to us, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system, and platform;
    2. Log Information – Information that is generated by your use of the Services that is automatically collected and stored in our server logs. This may include, but is not limited to, device-specific information, location information, system activity and any internal and external information related to pages that you visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our Website or App (including date and time; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
  4. From time to time, we may obtain information about you from our affiliates or third-party sources as required or permitted by applicable law. These sources may include:
    1. Public Databases and ID Verification Partners: We obtain information about you from public databases and ID verification partners for purposes of verifying your identity in accordance with applicable law. ID verification partners like Onfido use a combination of government records and publicly available information about you to verify your identity. Such information may include your name, address, job role, public employment profile, credit history, status on any sanctions lists maintained by public authorities, and other relevant data. We obtain such information to comply with our legal obligations. In some cases, we may process additional data about you to assess risk and ensure our Services are not used fraudulently or for other illicit activities. In such instances, processing is necessary for us to continue to perform our contractual obligations with you and others.
    2. Blockchain Data: We may analyse public blockchain data to ensure parties utilizing our Services are not engaged in illegal or prohibited activity under our Terms, and to analyse transaction trends for research and development purposes.
    3. Advertising Networks & Analytics Providers: We work with these providers to provide us with de-identified information about how you found our Sites and how you interact with the Sites and Services. This information may be collected prior to account creation.
  5. We only use your personal data where we have a legal basis to do so:
    1. Consent: For some processing activities, we require your prior consent. This applies for example to some of our direct marketing activities which fall under the scope of the GDPR and other Privacy rules. You may withdraw your consent at any time.
    2. Performance of a contract: Some personal data we process about you is for the performance of a contract to which you are a party or to take steps at your request before entering into a contract with us.
    3. Legal obligation: In most cases, we have to process your personal data to comply with legal obligations, including those applicable to financial services institutions, such as the Danish Anti-Money Laundering Act (in Danish: Hvidvaskloven).

How the Personal Data Is Used

  1. Our primary purpose in collecting personal information is to provide you with a secure, smooth, efficient, and customized experience. We generally use personal information to create, develop, operate, deliver, and improve our Services, content and advertising; and for loss prevention and anti-fraud purposes. We may use this information in the following ways:
    1. To maintain legal and regulatory compliance
    2. To enforce our terms in our user agreement and other agreements
    3. To detect and prevent fraud and/or funds loss
    4. To provide the Services
    5. To provide the Service communications
    6. To provide customer service
    7. To ensure quality control
    8. To ensure network and information security
    9. To enhance your experience
    10. For any purpose that you provide your consent.

Disclosure of Your Personal Data

  1. Kassio will not disclose any of its users’ confidential information to a third party, except: (a) to the extent that it is required to do so pursuant to any applicable laws, rules or regulations; (b) if there is a duty to disclose; (c) if our legitimate business interests require disclosure; (d) in line with our Terms; (e) at your request or with your consent or to those described in this Privacy Policy. Kassio will endeavour to make such disclosures on a “need-to-know” basis, unless otherwise instructed by a regulatory authority. Under such circumstances, Kassio will notify the third party regarding the confidential nature of any such information.

Transfer of Personal Data Outside European Economic Area (Eea)

  1. We may transfer your personal information outside the EEA to other Kassio subsidiaries, service providers and business partners (i.e. Data Processors) who are engaged on our behalf. To the extent that we transfer your personal information outside of the EEA, we will ensure that the transfer is lawful and that Data Processors in third countries are obliged to comply with the European Union (EU) General Data Protection Act 2016.

Data Retention

  1. Safeguarding the privacy of your personal information is of utmost importance to us, whether you interact with us personally, by phone, by email, over the internet or any other electronic medium. We will hold personal information, for as long as we have a business relationship with you, in secure computer storage facilities, and we take the necessary measures to protect the personal information we hold from misuse, loss, unauthorised access, modification or disclosure.
  2. When we consider that personal information is no longer necessary for the purpose for which it was collected, we will remove any details that will identify you or we will securely destroy the records. However, we may need to maintain records for a significant period of time (after you cease being our user). For example, we are subject to certain anti-money laundering laws which require us to retain the following, for a period of 5 years after our business relationship with you has ended.
    1. A copy of the records we used in order to comply with our client due diligence obligations;
    2. Supporting evidence and records of transactions with you and your relationship with us.
    3. Also, the personal information we hold in the form of a recorded information, by telephone, electronically or otherwise, will be held in line with regulatory requirements (i.e. 5 years after our business relationship with you has ended or longer if you have legitimate interests (such as handling a dispute with you)).
    4. We may keep your data for longer than 5 years if we cannot delete if for legal, regulatory or technical reasons.

Cookies

  1. When you use our Services, we may make use of the standard practice of placing tiny data files called cookies, flash cookies, pixel tags, or other tracking tools (herein, “Cookies”) on your computer or other devices used when engaging with us. We use Cookies to (i) help us recognize you as a customer, (ii) collect information about your use of our products and services, (iii) to better customize our services and content for you, (iv) and to collect information about your computer or other access devices to ensure our compliance with our anti-money laundering obligations.
  2. You can delete cookies any time you want by using the settings in your web browser. You can also choose to disable cookies from your web browser, but this would mean that our website and other websites that you access may not function properly. If you do this, a potential result is that you may not be able to sign in. Further information on deleting or controlling cookies can be found at www.aboutcookies.org

Your Rights

  1. When we process your personal data, you have several rights under the General Data Protection Regulation.
  2. In general, you have a right of access to Kassio’s processing of your data. This means that you can ask us for information about our processing of your data and a copy of the data. You also have the right to have a copy of your personal data transmitted to another enterprise, where technically feasible.
  3. Also, you have a right to object to our processing of your data. If the situation should occur, we will decide whether we can meet your objection. If that is the case, we will no longer process the data in question.
  4. Finally, you have a right to have erased, blocked or rectified any data that turn out to be inaccurate or misleading or in a similar way have been processed in conflict with legislation.
  5. If you wish to make use of your rights under the Danish Act on Processing of Personal Data, please contact Kassio at support@kassio.com.

If you have questions about our processing of your personal information, you can contact us at support@kassio.com.

Complaints about our processing of your personal data, can be filed at The Danish Data Protection Agency.

You can contact The Danish Data Protection Agency from your digital mail box at borger.dk, by ordinary email to dt@datatilsynet.dk or by ordinary post to The Danish Data Protection Agency, Borgergade 28, 5., 1300 Copenhagen K, Denmark.