Privacy Policy
Different legal entities may determine how personal data is used for different Plumex services. Their role depends on the actual processing activity, not merely on technical integration.
1. Scope
1.1 This Privacy Notice applies to plumex.io, the Plumex application and the Ukraine Service Route. A different service, territory or feature may be subject to additional or supplementary privacy information.
1.2 App-store or device-platform disclosures may provide a summary of certain data practices for the relevant App version. This Notice explains the processing connected with the Plumex services in more detail. Just-in-time notices may supplement it for specific permissions, verification steps, transactions or optional features.
1.3 Nothing in this Notice reduces rights available under mandatory data-protection, consumer, payment or other applicable law.
2. Who controls your personal data
2.1 A legal entity acts as a controller only for processing for which it determines the purposes and means. Where an entity processes personal data solely on another controller’s documented instructions, it acts as a processor. Where two entities jointly determine a specific processing purpose and essential means, the required joint-controller allocation and information will apply to that processing.
Entity | Typical data-protection role | Main processing domains / contact |
|---|---|---|
Plum Labs s.r.o. | Controller for Platform purposes it determines. | Platform Agreement, account administration, App/website operation, platform security, general support and platform communications. Company ID 24380792; Křižíkova 703/97a, Karlín, 186 00 Prague 8, Czech Republic. Central privacy channel: support@plumex.io |
Plum Global Inc. | Controller for custody purposes it determines. | Custody Agreement, custody onboarding/records, deposits/withdrawals, custody compliance, security, complaints and service exit. Folio 155788002; Global Bank Tower, 18th Floor, Suite 1801, 50th Street, Panama City, Republic of Panama. Central privacy channel: support@plumex.io |
Innovate Payments Inc. (IPI) | Controller for exchange/fiat/payment purposes it determines. | Quotes/orders, payment processing, execution/settlement, transaction monitoring, compliance, support and complaints. BC1464778; #250 - 997 Seymour St, Vancouver, BC V6B 3M1, Canada. Central privacy channel: support@plumex.io |
LMLP consulting s.r.o. | Usually a processor/service provider when acting on documented instructions; may be a controller for limited purposes required by law or independently determined. | Technical verification intake, residence/location checks, routing, logging, technical validation and support. Company ID 22380949; Spojovací 2604/48, Žižkov, 130 00 Prague 3, Czech Republic. Central privacy channel: support@plumex.io |
2.2 You may submit a privacy request to support@plumex.io with the subject “Privacy Request”. Plumex support will identify and route the request to the relevant controller. You may also contact the relevant controller at the address above.
2.3 Approved banks, payment providers, identity-verification services, blockchain-analytics providers, cloud/security vendors and support providers may act as processors or independent controllers depending on their actual function, legal obligations and contract. Where a provider acts independently, its own privacy information may also apply.
3. Personal data we collect
Category | Examples |
|---|---|
Account and contact | Name, email, telephone, date of birth, address, residence, nationality, language, internal account identifiers and communication preferences. |
Identity and verification | Government identification, document validity, proof of address, selfie/video/liveness, biometric verification results where used, tax/residency and eligibility information. |
Financial and payment | Bank/payment account details, IBAN/vIBAN or routing identifiers, payer/beneficiary information, references, currency, amount, return/chargeback information. |
Crypto-asset and blockchain | Wallet addresses, transaction hashes, asset/network, amount, timestamps, confirmations, custody balances/ledger entries, deposit/withdrawal instructions and wallet-control evidence. |
Exchange and transaction | Quote requests, rates, spreads, fees, orders, acceptance/rejection, settlement status and confirmations. |
Compliance and risk | Sanctions/PEP results, adverse information, source-of-funds/wealth data, expected activity, alerts, blockchain-risk indicators, fraud signals, assessments and investigation records. |
Device, location and technical | IP address, device/App identifiers, OS/App version, browser, language, time zone, session/authentication data, diagnostic information and approximate location indicators. |
Communications and support | Support tickets, complaints, emails/chats, attachments, call metadata and notices/consent records. |
Website and similar technologies | Cookie/local-storage identifiers, website visits, consent choices, referrer and interaction information as described in the Cookie and Similar Technologies Notice. |
Derived data | Eligibility/routing/transaction/fraud indicators, risk scores, account status and service-availability inferences. |
3.1 Identification documents, biometric verification data, financial information and compliance records may require enhanced protection and are processed only where necessary and with proportionate access, security and retention controls.
4. Where data comes from
• Directly from you when you register, verify identity, deposit/withdraw, submit an order, make/receive a payment, contact support or exercise a right.
• From the App, website, device, operating system and app-store environment, including technical/session/security and approximate-location information.
• From Plum Labs, Plum Global, IPI, LMLP and approved providers where necessary to operate the integrated service, reconcile records, route support or meet legal obligations.
• From approved identity-verification, sanctions/PEP, fraud, adverse-information and blockchain-analytics providers.
• From banks/payment providers, liquidity/settlement providers, public blockchains, public registers, regulators, courts, law-enforcement, advisers and persons reporting suspected fraud or misuse.
5. Why we process personal data and legal bases
5.1 The applicable legal basis depends on the controller, processing and law governing that activity. A controller may rely, where applicable, on performance of or steps toward a contract, legal obligation, legitimate interests balanced against individual rights, consent, substantial-public-interest grounds recognised by law, or another lawful basis.
Purpose | Typical processing | Typical basis where applicable |
|---|---|---|
Provide the Platform | Account creation/administration, authentication, notices, support and settings. | Contract / pre-contract steps; legitimate interests in operating and securing the Platform. |
Provide custody | Custody activation, records, deposit/withdrawal handling, reconciliation and service exit. | Custody contract / pre-contract steps; legal obligations; legitimate interests in accurate custody and security. |
Provide exchange and fiat | Quotes/orders, fiat funding/payouts, execution/settlement, confirmation and reconciliation. | Relevant contract / pre-contract steps; applicable payment/financial obligations; legitimate interests in settlement/reconciliation. |
Identity, AML and sanctions | Verification, screening, source checks, monitoring and authority responses. | Applicable legal obligations; recognised public-interest grounds; contract; legitimate interests in preventing financial crime; consent where specifically required. |
Security and fraud prevention | Account/system protection, takeover/fraud detection, incident handling. | Legal obligations; contract; legitimate interests in security and fraud prevention. |
Support and complaints | Responding, investigation, evidence and remediation. | Contract; legal obligation; legitimate interests in resolving issues and claims. |
Service improvement | Diagnostics, capacity, error detection, quality assurance and proportionate analytics. | Legitimate interests; consent for non-essential cookies/analytics/device access where required. |
Communications/marketing | Service/legal/security notices and permitted marketing. | Contract/legal obligation for service notices; consent or legitimate interests for marketing where permitted. |
Corporate/legal matters | Audit, accounting, insurance, professional advice, disputes, restructuring/due diligence. | Legal obligation; legitimate interests in governance, continuity, transactions and legal claims. |
5.2 Where processing relies on consent, it may be withdrawn at any time without affecting prior lawful processing. Where processing relies on legitimate interests, an objection right may apply.
6. Identity verification, biometrics and compliance screening
6.1 Identity verification may require a government document, selfie, video, liveness or biometric comparison using approved verification technology. The relevant controller and verification provider use this information to establish identity and service eligibility.
6.2 Biometric templates/results are processed only where necessary and permitted. Where express consent is required, it will be requested separately; an alternative may be offered where legally and operationally available.
6.3 Providers may screen sanctions, PEP, fraud, adverse-information and blockchain-risk sources and may retain verification/transaction/investigation records where required or permitted.
7. Automated tools and human review
7.1 Automated tools may verify documents, compare identity images, detect fraud, score blockchain/transaction risk, identify location inconsistencies, route users or prioritise cases.
7.2 Where applicable law gives a right not to be subject to a solely automated decision with significant effect, the relevant controller will provide required safeguards, which may include human review and an opportunity to express your position.
8. Who receives personal data
• The provider responsible for the service requested and other Plumex providers where necessary to operate an integrated flow, reconcile records, route support or meet legal obligations.
• LMLP and other approved technical, hosting, cloud, authentication, cybersecurity, communications and support providers.
• Approved identity/document/liveness/biometric verification providers and sanctions, PEP, fraud, blockchain-analytics and transaction-monitoring providers.
• Banks, payment institutions, correspondent banks, payment processors, liquidity, settlement and wallet/infrastructure providers required for a transaction.
• Apple and other device/app-store providers, professional advisers, auditors, insurers and competent authorities where applicable.
8.1 Processors are required by contract to follow authorised instructions, confidentiality and security requirements and to support legally required rights/incident handling, subject to lawful retention.
8.2 Personal data is not disclosed to an unrelated third party for its own marketing unless clearly disclosed and supported by a valid legal basis.
9. International transfers
9.1 Processing for the Ukraine Service Route may involve the Czech Republic, Panama, Canada, Ukraine and other countries in which approved service providers or infrastructure operate. Personal data may therefore be accessed, stored or processed outside your country of residence.
9.2 Where required, international transfers are supported by an adequacy decision, standard contractual clauses or other approved contractual safeguards, controller-to-controller/processor terms, consent or another lawful transfer mechanism.
9.3 Legal protection and authority access differ between countries. Controllers assess material transfer risk and apply proportionate contractual, organisational and technical safeguards where required.
10. Public blockchains
10.1 Wallet addresses, transaction hashes, asset amounts, network data and timestamps may be recorded on public blockchains visible worldwide. A controller generally cannot erase or restrict the underlying public-chain entry and may instead correct its internal record where appropriate.
11. Retention
11.1 Personal data is retained only as long as reasonably necessary for its purpose, mandatory retention, security, dispute and legal-claim needs. Unless a different period is required by law or a provider-specific policy, typical periods are:
Data | Typical retention |
|---|---|
Account, contract and core service records | Life of the account/service and ordinarily five years after closure, termination or the last relevant transaction. |
KYC/AML/sanctions/source and transaction records | Ordinarily five years after the relationship or transaction, or longer where required by applicable financial-crime, payment, investigation or legal-hold rules. |
Custody/exchange/fiat/reconciliation records | Ordinarily five years after the transaction or end of relationship, and longer for unresolved balances, claims, audits or legal requirements. |
Security/authentication/technical logs | Normally up to two years, longer where linked to an incident, fraud case, dispute or legal requirement. |
Support/complaint records | Normally five years after closure of the matter, longer where linked to a transaction, claim or regulatory requirement. |
Marketing preferences | Until consent is withdrawn or an objection is received; a minimal suppression record may be retained. |
Cookie/similar technology data | As stated in the Cookie and Similar Technologies Notice or consent interface. |
Public blockchain data | Potentially permanent as part of the relevant blockchain. |
11.2 When retention is no longer required, data is deleted, anonymised or placed beyond ordinary use, taking account of backup/technical constraints.
12. Security and incidents
12.1 Controllers and processors use proportionate technical and organisational measures appropriate to risk, which may include encryption, access controls, multi-factor authentication, logging, segregation of duties, vendor assessment, backups, vulnerability management, incident response and confidentiality obligations.
12.2 No system is completely secure. A controller that becomes aware of a personal-data incident will assess, contain and investigate it and notify competent authorities/affected individuals where required by law.
13. Your rights
13.1 Depending on the controller and applicable law, you may have rights to information, access, correction, deletion/cancellation, restriction, objection, portability, withdrawal of consent, human review of certain solely automated decisions, complaint to a supervisory authority and other remedies.
13.2 Submit a request to support@plumex.io with the subject “Privacy Request”. Identity/authority verification may be required. The relevant controller responds within the period required by applicable law; where no specific shorter period applies, it aims to respond promptly and ordinarily within 30 calendar days.
13.3 A request may be limited or refused where law permits, including to protect another person, legal privilege, fraud/security methods, confidential reporting, investigations, legal holds or mandatory retention. Requests are normally free of charge except where law permits a fee/refusal for manifestly unfounded, excessive or repetitive requests.
14. Account deletion
14.1 You may initiate deletion through the in-App process or the Account Deletion and Retention Policy. Before deletion, you may need to withdraw assets/funds, resolve pending transactions, pay amounts due and address lawful restrictions.
14.2 Account deletion does not erase public blockchain entries or records that may lawfully be retained for AML, payment, tax, accounting, fraud, security, complaint or dispute purposes.
15. Marketing, cookies and similar technologies
15.1 Service, legal, security and transaction communications are not marketing. Marketing is sent only where permitted and may be opted out of as applicable.
15.2 The website and App may use necessary cookies, local storage, software development kits and similar technologies. Non-essential analytics, personalisation or advertising technologies are used only where disclosed and where the required consent or other lawful basis is in place. See the Cookie and Similar Technologies Notice.
15.3 Separate app-store, operating-system or device-permission disclosures may apply to the relevant App version or device feature.
16. Children
16.1 The services are intended only for persons aged 18 or older. If a child’s data is submitted, the relevant controller may restrict the account, verify age/authority and delete or retain data as required by law, security or fraud-prevention needs.
17. Complaints and supervisory authorities
17.1 Contact support@plumex.io first so the matter can be routed to the relevant controller. You may also complain directly to the controller or competent authority.
Controller / processing | Relevant authority where applicable |
|---|---|
Ukraine-route rights in Ukraine | Ukrainian Parliament Commissioner for Human Rights. |
Plum Labs or LMLP processing subject to Czech/EU data-protection law | Office for Personal Data Protection of the Czech Republic or another competent European supervisory authority. |
Plum Global processing subject to Panama personal-data law | National Authority for Transparency and Access to Information (ANTAI), Directorate for Personal Data Protection. |
IPI processing subject to Canadian privacy law | Office of the Privacy Commissioner of Canada and, where applicable, the Office of the Information and Privacy Commissioner for British Columbia. |
17.2 Competence depends on location, controller, service and applicable law. Use of one complaint route does not remove another remedy available under mandatory law.
18. Changes to this Notice
18.1 This Notice may be updated for changes to providers, services, law, technology, data use or security. Material changes affecting controller identity, purposes, sensitive data, recipients, international transfers or rights will be notified where required.
18.2 A provider change does not automatically transfer personal data or responsibility; any required lawful transfer, notice and user choices will be addressed in the applicable provider-change process.
19. Language and hierarchy
19.1 This Notice may be published in English and Ukrainian. For the Ukraine Service Route, the Ukrainian version prevails in the event of inconsistency unless mandatory law requires otherwise.
19.2 This Notice governs personal-data processing. The Multi-Party Terms and provider Schedules govern services. More specific privacy information for a particular processing activity supplements this Notice.
20. Key definitions
“Controller” means an entity that determines why and how personal data is processed for the relevant purpose. “Processor” means an entity processing personal data on documented instructions for a controller. “Personal Data” means information relating to an identified or identifiable individual. “Sensitive Data” in this Notice refers to information requiring enhanced protection because of its nature or potential impact, including identity documents, biometric verification data, financial information and compliance records. “Ukraine Service Route” means the service configuration intended for eligible users under the Ukraine App Store storefront and residence/actual-location controls.