Privacy Policy
Plumex uses a multi-provider model. Different legal entities determine how personal data is used for the Platform, custody, exchange and fiat services. This Notice identifies those entities and their responsibilities. |
|---|
This Privacy Notice explains how personal data is collected, used, disclosed, transferred, protected and retained when you visit plumex.io, create or use a Plumex account, complete identity verification, hold crypto-assets with Capitalista S.A., transact with Innovate Payments Inc. or contact support. It should be read together with the Multi-Party Terms of Use, provider-specific Schedules, the AML/KYC Notice, Cookie Notice and Account Deletion and Retention Policy.
1. Scope
1.1 This Notice applies to the Plumex application, plumex.io and the Ukraine Service Route. It does not govern services excluded from Ukraine v1, including Paybis or an European Union service route.
1.2 The App Store privacy label is a summary of data practices for the submitted App version. This Notice provides the detailed explanation. Where the App, website, software development kits or service providers change, the App Store disclosure and this Notice must be updated accordingly.
1.3 Additional just-in-time notices may be shown before a specific permission, verification step, transaction or optional feature. Those notices supplement this Notice and apply to the relevant processing.
1.4 This Notice does not reduce rights available under mandatory data-protection, consumer, payment or other applicable law.
2. Who controls your personal data
Each entity below acts as an independent controller for the purposes it determines in relation to its own service. The providers do not act as joint controllers merely because their services are integrated in the Plumex Platform. If two entities jointly determine a specific processing purpose and method, the relevant notice will identify that arrangement and the allocation of responsibilities.
Entity | Controller role | Main data domains | Contact |
|---|---|---|---|
Plum Labs s.r.o. | Controller for the Platform Agreement, account administration, App and website operation, platform security, general support and platform communications. | Account and contact data; device, session and usage data; platform support; communication preferences; platform security records. | Company ID 24380792 |
Capitalista S.A. | Controller for the Custody Agreement, custody onboarding, custody records, deposits and withdrawals, custody compliance, security, complaints and service exit. | Identity and verification data required for custody; wallet addresses; blockchain transactions; custody balances and records; source-of-funds and risk information; custody support and complaints. | Mercantile Folio 155759981 |
Innovate Payments Inc. (IPI) | Controller for exchange, fiat and payment services, order execution, payment processing, transaction monitoring, compliance, support and complaints. | Identity and verification data; quotes and orders; bank, payment and vIBAN data; fiat and crypto transaction records; compliance and fraud data; support and complaints. | BC1464778 |
LMLP consulting s.r.o. | Technical service provider supporting identity-verification intake, residence and actual-location checks, jurisdiction routing, technical validation, instruction transmission, logging and support. It generally processes data for the relevant controller. Where law requires LMLP to determine a separate limited purpose, it acts as an independent controller for that purpose. | Verification intake; technical routing; device and session data; system and security logs; technical support records. | Company ID 22380949 |
2.1 You may send a privacy request to support@plumex.io with the subject “Privacy Request”. Plumex support will identify the relevant controller and route the request. You may also contact the relevant controller directly at the address stated above.
2.2 Supporting providers such as PSP (TBD), banks, payment providers, Sumsub, blockchain-screening providers, cloud and support vendors may act as processors or independent controllers depending on their function, legal obligations and contract. Where they act independently, their own privacy notice may also apply.
3. Personal data we collect
Category | Examples |
|---|---|
Account and contact | Name, email, telephone number, date of birth, address, country of residence, nationality, preferred language, username, internal customer and account identifiers, communication preferences. |
Identity and verification | Government-issued identification, document number and validity, proof of address, selfie, video, liveness and biometric verification results, tax or residency information, occupation and information required to verify identity or eligibility. |
Financial and payment | Bank-account and payment-account details, International Bank Account Number or virtual International Bank Account Number, payer and beneficiary information, payment references, currency, amount, bank or payment-provider status, return and chargeback information. |
Crypto-asset and blockchain | Wallet addresses, transaction hashes, asset, network, amount, timestamp, confirmations, custody balance and ledger entries, deposit and withdrawal instructions, wallet ownership evidence and public blockchain information. |
Exchange and transaction | Quote requests, rates, spreads, fees, orders, acceptance or rejection, settlement status, transaction confirmations, counterparty and liquidity references where necessary. |
Compliance and risk | Sanctions and politically exposed person screening results, adverse information, source-of-funds or source-of-wealth information, expected activity, transaction-monitoring alerts, blockchain-risk indicators, fraud signals, risk assessments and investigation records. |
Device, location and technical | Internet Protocol address, device and application identifiers, operating system, App version, browser, language, time zone, login time, session and authentication data, crash and diagnostic information, approximate country or region inferred from device, network, App Store, payment and verification information. |
Communications and support | Support tickets, complaint records, emails, chat messages, attachments, call metadata and records of notices or consents. |
Website and cookie | Cookie identifiers, website visits, consent choices, referring page, browser and interaction data as described in the Cookie Notice. |
Derived data | Eligibility, routing, transaction and fraud indicators, risk scores, account status, service availability and other inferences generated from the data above. |
3.1 Some data, including identification documents, biometric verification data, financial information and compliance records, is sensitive. It is processed only where necessary and subject to enhanced access, security and retention controls.
3.2 Where the App requests access to a device feature such as the camera, photo library, files, notifications or location, the system permission request will identify the access. You may refuse optional permissions, but a required verification or security function may then be unavailable.
4. Where personal data comes from
• Directly from you when you register, verify identity, deposit or withdraw assets, submit an order, make or receive a payment, contact support or exercise a right.
• From the App, website, device, operating system and App Store, including technical, session, security and approximate-location information.
• From Capitalista, IPI, LMLP and supporting providers where necessary to operate an integrated service, reconcile records, route support or meet legal obligations.
• From Sumsub or another identity-verification provider, sanctions and politically exposed person databases, adverse-media and fraud providers, and blockchain analytics services.
• From banks, PSP (TBD) or another payment provider, liquidity and settlement providers, public blockchain networks and public registers.
• From regulators, courts, law-enforcement bodies, advisers, auditors and persons reporting suspected fraud or misuse.
5. Why we process personal data and legal bases
The applicable legal basis depends on the controller, service and jurisdiction. A controller may rely on more than one basis where permitted.
Purpose | Typical data and processing | Legal basis used where applicable |
|---|---|---|
Provide the Platform | Create and administer the account, authenticate access, display provider records, deliver notices, support and account settings. | Performance of the Platform Agreement; steps requested before contract; legitimate interests in operating and supporting the Platform. |
Provide custody | Activate custody, assign or display deposit details, maintain custody records, process withdrawals and manage service exit. | Performance of the Custody Agreement; steps requested before contract; legal obligations; legitimate interests in accurate custody and security. |
Provide exchange and fiat services | Generate quotes, accept or reject orders, process fiat funding and payouts, execute and settle transactions, issue confirmations and reconcile payments. | Performance of the IPI framework and transaction contract; steps requested before contract; payment and financial legal obligations; legitimate interests in settlement and reconciliation. |
Identity, AML and sanctions | Identify and verify users, screen sanctions and politically exposed persons, verify source of funds and wallet control, monitor transactions and respond to authorities. | Legal obligation; substantial public interest where recognised; performance of contract; legitimate interests in preventing financial crime; consent where specifically required for biometric processing. |
Security and fraud prevention | Protect accounts, assets, funds, systems and users; detect account takeover, phishing, malware, unauthorised access, fraud and abuse. | Legal obligations; performance of contract; legitimate interests in security, fraud prevention and defence of users and providers. |
Support and complaints | Respond to enquiries, investigate complaints, preserve evidence and provide redress. | Performance of contract; legal obligation; legitimate interests in resolving issues and establishing or defending claims. |
Service operation and improvement | Diagnostics, capacity, error detection, quality assurance, service metrics and product improvement using proportionate data. | Legitimate interests in reliable, secure and usable services; consent for non-essential cookies, analytics or device access where required. |
Communications and marketing | Service notices, legal updates, security alerts and, where permitted, product information or marketing preferences. | Performance of contract and legal obligation for service notices; consent or legitimate interests for marketing where permitted; right to opt out. |
Corporate, audit and legal matters | Audits, accounting, insurance, professional advice, disputes, restructurings, due diligence and business transfers. | Legal obligation; legitimate interests in governance, business continuity, transactions and legal claims. |
5.1 Where processing relies on consent, you may withdraw consent at any time. Withdrawal does not affect processing already carried out and may make an optional or legally consent-dependent feature unavailable.
5.2 Where processing relies on legitimate interests, the controller balances its interests against your rights and applies data minimisation, access controls and other safeguards. You may object where applicable.
6. Identity verification, biometrics and compliance screening
6.1 Identity verification may require a government document, selfie, video, liveness or biometric comparison. The relevant controller and verification provider use this information to establish that the applicant is a real person, matches the document and is eligible for the requested service.
6.2 Biometric templates or results are processed only where necessary and permitted. Where express consent is required, it will be requested separately. Refusal may prevent completion of remote verification, although an alternative may be offered where operationally and legally available.
6.3 Providers may screen information against sanctions, politically exposed person, fraud, adverse-information and other lawful risk sources and may analyse public blockchain transactions and wallet exposure.
6.4 A provider may be required to retain verification, transaction and investigation records and may be legally prohibited from disclosing a suspicious-activity report or confidential authority request.
7. Automated tools and human review
7.1 Automated tools may be used to verify documents, compare a face with an identification document, detect fraud, score blockchain or transaction risk, identify location inconsistency, route a user or prioritise a case for review.
7.2 An automated result may cause a delay, request for additional information, service limitation or referral to manual review. Where applicable law gives you a right not to be subject to a solely automated decision with significant effect, the relevant controller will provide the required safeguards, including a way to request human review and express your position.
7.3 Providers do not use nationality alone as the basis for Ukraine-route eligibility. Residence, Actual Location, sanctions, verification and service-specific risk factors are considered.
8. Who receives personal data
• The provider responsible for the service you request and other Plumex providers where necessary to operate the integrated flow, reconcile records, route support or meet legal obligations.
• LMLP and other technical, hosting, cloud, authentication, cybersecurity, communications and customer-support providers.
• Sumsub and other identity, document, liveness and biometric-verification providers.
• AMLBot and other sanctions, politically exposed person, fraud, blockchain analytics and transaction-monitoring providers.
• PSP (TBD), banks, payment institutions, correspondent banks, payment processors, liquidity, settlement and wallet providers required for a transaction.
• Apple and other operating-system or App Store providers, which process certain data independently under their own terms and privacy notices.
• Professional advisers, auditors, accountants, insurers, investigators and service-quality reviewers under confidentiality obligations.
• Regulators, courts, law-enforcement, tax, financial-intelligence and other competent authorities where legally required or permitted.
• A buyer, investor, successor or restructuring counterparty where necessary for a proposed or completed transaction, subject to confidentiality and lawful safeguards.
8.1 Processors are required by contract to process personal data only for authorised purposes, maintain confidentiality and security, assist with rights and incidents, and delete or return data when required, subject to lawful retention.
8.2 We do not disclose personal data to an unrelated third party for its own marketing unless this is clearly disclosed and a valid legal basis, including consent where required, has been obtained.
9. International transfers
9.1 The Ukraine Service Route involves controllers and service providers in Ukraine, the Czech Republic, Panama, Canada, the United Kingdom and other countries in which approved providers operate. Personal data may therefore be accessed, stored or processed outside your country of residence.
9.2 Where required, transfers are supported by an adequacy decision, contractual safeguards such as standard data-protection clauses, controller-to-controller or processor terms, confidentiality and security commitments, consent, or another lawful transfer mechanism.
9.3 The level of legal protection and authority access may differ between countries. Controllers assess material transfer risks and apply proportionate contractual, organisational and technical safeguards.
9.4 Public blockchain data is replicated globally and generally cannot be restricted to one country. See section 10.
10. Public blockchains
10.1 Wallet addresses, transaction hashes, asset amounts, network data and timestamps may be recorded on a public blockchain. Public blockchain information may be visible worldwide and analysed by third parties.
10.2 A public blockchain is designed to be durable and may not allow a controller to erase, correct or restrict the underlying entry. A controller may instead correct its internal record, add explanatory information or stop linking the address to your account where lawful and technically possible.
10.3 Do not include names, messages or other unnecessary personal information in blockchain transaction fields.
11. How long personal data is retained
Data is retained only for as long as reasonably necessary for the relevant purpose, mandatory retention, security, dispute and legal-claim needs. Unless a longer or shorter period is required by law or a provider-specific policy, the following periods normally apply:
Data | Typical retention |
|---|---|
Account, contract and core service records | For the life of the account or service and ordinarily five years after closure, termination or the last relevant transaction. |
KYC, AML, sanctions, source-of-funds and transaction records | Ordinarily five years after the end of the relationship or transaction, or longer where required by applicable financial-crime, payment, tax, investigation or legal-hold rules. |
Custody, exchange, fiat and reconciliation records | Ordinarily five years after the transaction or end of the relationship, and longer for unresolved balances, claims, audits or legal requirements. |
Security, authentication and technical logs | Normally up to two years, and longer where linked to an incident, fraud case, dispute or legal requirement. |
Support and complaint records | Normally five years after closure of the matter, or longer if linked to a transaction, legal claim or regulatory requirement. |
Marketing preferences | Until consent is withdrawn or an objection is received; a minimal suppression record may be retained to respect the choice. |
Cookie and website data | For the period stated in the Cookie Notice and consent interface. |
Public blockchain data | Potentially permanent as part of the relevant blockchain. |
11.1 Data may be retained longer where necessary for an investigation, sanctions or legal hold, outstanding balance, complaint, litigation, regulator request, audit, tax or accounting requirement, security incident or defence of legal claims.
11.2 When retention is no longer required, data is deleted, anonymised or placed beyond ordinary use, taking account of backups and technical constraints.
12. Security and personal-data incidents
12.1 Controllers and processors use proportionate technical and organisational measures appropriate to the sensitivity and risk of the data. Measures may include encryption in transit and at rest where appropriate, access controls, multi-factor authentication, logging, segregation of duties, vendor assessment, backups, vulnerability management, incident response and staff confidentiality obligations.
12.2 No system is completely secure. You must also protect your device, email, authentication methods and account credentials and promptly report suspected compromise.
12.3 A controller that becomes aware of a personal-data incident will assess the scope and risk, contain and investigate it, coordinate with affected providers and notify competent authorities and affected individuals where required by law.
12.4 Report a suspected privacy or security incident to support@plumex.io. Do not send passwords, private keys, seed phrases or one-time codes.
13. Your rights
Depending on the controller and applicable law, you may have the following rights:
• to be informed about the processing and the location or identity of the controller;
• to obtain confirmation whether personal data is processed and access a copy;
• to correct, update or complete inaccurate or incomplete data;
• to request deletion, cancellation or anonymisation where data is no longer required and no legal retention ground applies;
• to request restriction of processing in circumstances provided by law;
• to object to processing based on legitimate interests or to direct marketing;
• to receive portable data in a structured, commonly used format where applicable;
• to withdraw consent without affecting prior lawful processing;
• to request human review of a solely automated significant decision where applicable;
• to lodge a complaint with the relevant controller or supervisory authority; and
• to seek another remedy available under applicable law.
13.1 Submit a request to support@plumex.io with the subject “Privacy Request” and identify the relevant account or service. We may request information reasonably necessary to verify identity and authority and to protect the account and other individuals.
13.2 The relevant controller will respond within the period required by applicable law, ordinarily within 30 calendar days. The period may be extended where permitted for complexity, volume or required third-party information, and you will be informed.
13.3 A request may be limited or refused where required or permitted by law, including to protect another person, legal privilege, fraud or security methods, confidential reporting, an investigation, a legal hold or mandatory retention. The controller will explain the lawful basis where permitted.
13.4 Requests are normally free of charge. A reasonable fee or refusal may apply to manifestly unfounded, excessive or repetitive requests where permitted by law.
14. Account deletion
14.1 You may initiate deletion through the in-App account-deletion flow or the method described in the Account Deletion and Retention Policy. Additional verification may be required to protect the account and assets.
14.2 Before deletion, you may need to withdraw available crypto-assets or fiat funds, resolve pending transactions, pay amounts due and address legal or compliance restrictions.
14.3 Account deletion removes or de-identifies personal data that is no longer required. It does not erase public blockchain entries or records that a provider must retain for AML, payment, tax, accounting, fraud, security, complaint, dispute or other legal purposes.
14.4 Closing the Platform account does not automatically terminate an accepted transaction or release an asset or fund subject to a lawful restriction.
15. Marketing, cookies and tracking
15.1 Service, legal, security and transaction communications are necessary for the relevant service and are not marketing messages.
15.2 Marketing communications are sent only where permitted. You may opt out using the message link or account preference, although service communications will continue.
15.3 The website and App may use necessary cookies, local storage, software development kits and similar technologies. Non-essential analytics, personalisation or advertising technologies will be used only where disclosed and where the required consent or other legal basis is in place. See the Cookie Notice.
15.4 The App Store privacy disclosure must include data collected by Plumex and third-party code integrated into the submitted App version. It must be kept accurate and updated when practices change.
16. Children
16.1 The services are intended only for persons aged 18 or older. We do not knowingly open accounts for children.
16.2 If we learn that a child’s personal data was submitted, the relevant controller may restrict the account, verify age or authority and delete or retain the data as required by law, security or fraud-prevention needs.
17. Complaints and supervisory authorities
17.1 Contact support@plumex.io first so the matter can be routed to the responsible controller. You may also complain directly to the controller or the competent authority.
Controller / processing | Relevant authority where applicable |
|---|---|
Ukraine-route processing and rights in Ukraine | Ukrainian Parliament Commissioner for Human Rights. |
Plum Labs or LMLP processing subject to European Union or Czech data-protection law | Office for Personal Data Protection of the Czech Republic or another competent European supervisory authority. |
Capitalista processing in Panama | National Authority for Transparency and Access to Information (ANTAI), Directorate for Personal Data Protection. |
IPI processing in Canada | Office of the Privacy Commissioner of Canada and, where applicable, the Office of the Information and Privacy Commissioner for British Columbia. |
PSP (TBD) or other United Kingdom processing | United Kingdom Information Commissioner’s Office, where applicable. |
17.2 The identity of the competent authority may depend on your location, the controller, the service and the law applying to the processing. Complaining to an authority does not prevent use of other remedies.
18. Changes to this Notice
18.1 This Notice may be updated for changes to providers, services, law, technology, data use or security. The version and date will be shown at the beginning.
18.2 A material change affecting controller identity, purposes, sensitive data, recipients, international transfers or user rights will be notified through the App, email or another durable method where required.
18.3 A provider change does not automatically transfer personal data or responsibility. The applicable provider-succession notice will explain the lawful basis, recipients, effective date, user choices and treatment of existing records.
19. Language and document hierarchy
19.1 This Notice is published in English and Ukrainian. For the Ukraine Service Route, the Ukrainian version prevails in the event of inconsistency, unless mandatory law requires otherwise.
19.2 This Notice governs personal-data processing. The Multi-Party Terms and provider Schedules govern the services. If another document gives more specific information about a particular processing activity, that specific privacy information supplements this Notice.
19.3 Marketing statements, frequently asked questions and App Store descriptions do not amend this Notice.
20. Key definitions
“Actual Location” the country or territory from which you access or use a service, determined using reasonable technical, payment, device and verification information.
“Controller” the entity that determines why and how personal data is processed for the relevant purpose.
“Personal Data” information relating to an identified or identifiable individual, including information that becomes identifiable when combined with other data.
“Processor” an entity processing personal data for a controller under instructions and a data-processing arrangement.
“Sensitive Data” personal data requiring enhanced protection because of its nature or potential impact, including identification documents, biometric verification data, financial information and compliance records.
“Ukraine Service Route” the service configuration intended for eligible users under the Ukraine App Store storefront and the applicable residence and Actual Location controls.
Privacy requests: support@plumex.io