EU
MiCA licensed Learn more →

Privacy Policy

Last updated: 22 jun 2026

1. Data controller

The controller of your personal data is AHORACRYPTO, S.L. (hereinafter, “AhoraCrypto”), Spanish tax identification number B10521227, with registered office at Calle Gabriel García Márquez nº 4, 1ª Planta, 28232 Las Rozas (Madrid), Spain.

AhoraCrypto is authorised by the Spanish National Securities Market Commission (Comisión Nacional del Mercado de Valores, “CNMV”) as a crypto-asset service provider under Regulation (EU) 2023/1114 on markets in crypto-assets (hereinafter, “MiCA”), and is an obliged entity for the purposes of Spanish Law 10/2010 of 28 April on the prevention of money laundering and terrorist financing.

The domain ahoracrypto.com (hereinafter, the “Website”) and the AhoraCrypto mobile application (hereinafter, the “App”) are owned by AHORACRYPTO, S.L.

For any matter relating to the processing of your personal data or to the exercise of your rights, you may contact privacidad@ahoracrypto.com. For service-related matters, you may contact soporte@ahoracrypto.com.

2. Scope

This Privacy Policy governs the processing of personal data of users of the Website, of the App and of the crypto-asset services provided by AhoraCrypto (hereinafter, together, the “Services”), as well as of persons who contact AhoraCrypto by any other means.

Accessing or using the Website, the App or the Services makes you a user (hereinafter, the “User”) and implies that you are aware of this Privacy Policy.

AhoraCrypto provides its Services on a non-custodial basis. AhoraCrypto does not hold control of Users’ private keys and does not hold their crypto-assets in custody.

3. Legal bases for processing

AhoraCrypto processes your personal data on one or more of the following legal bases, depending on the specific purpose of each processing activity:

  • Performance of a contract to which you are party, or steps taken at your request prior to entering into a contract (Article 6(1)(b) of Regulation (EU) 2016/679, hereinafter the “GDPR”).
  • Compliance with legal obligations applicable to AhoraCrypto (Article 6(1)(c) GDPR), in particular those arising from MiCA, from Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets (hereinafter, “TFR”), from Law 10/2010 and from Regulation (EU) 2022/2554 (hereinafter, “DORA”).
  • Legitimate interests pursued by AhoraCrypto or by a third party (Article 6(1)(f) GDPR), in particular for the prevention, detection and investigation of fraud, for the security of information and of the Services, and for the establishment and defence of legal claims.
  • Your consent (Article 6(1)(a) GDPR), for processing activities that require it, such as marketing communications or the management of job applications. You may withdraw your consent at any time by writing to privacidad@ahoracrypto.com, without affecting the lawfulness of processing carried out before withdrawal.

Where processing is based on compliance with a legal obligation or on the performance of the contract, a refusal to provide the requested data will prevent AhoraCrypto from providing the Services.

4. Purposes of processing

4.1. Onboarding, registration and provision of the Services

Data processed: name and surname, identity document, nationality, date of birth, country of residence, address, email address, telephone number, details of the payment account used, crypto-asset wallet addresses, transaction history and technical connection data.
Purpose: registration and management of the User, execution of orders for the exchange of crypto-assets for funds and for the transfer of crypto-assets on behalf of clients, and maintenance of the contractual relationship.
Legal basis: performance of the contract (Article 6(1)(b) GDPR).

4.2. Identity verification and video identification

Data processed: image of the identity document, facial image, recording of the video identification process, liveness detection data and the outcome of the verification.
Purpose: to reliably establish the identity of the User prior to onboarding, in accordance with customer due diligence obligations.
Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Articles 3 et seq. of Law 10/2010). To the extent that the video identification process involves the processing of biometric data for the purpose of uniquely identifying a natural person, that processing is based on Article 9(2)(g) GDPR, on grounds of substantial public interest in the prevention of money laundering and terrorist financing.
Verification processes are carried out through a specialised provider acting as a processor on behalf of AhoraCrypto.

4.3. Prevention of money laundering and terrorist financing

Data processed: identification and contact data, information on the source of funds and of wealth, professional activity, purpose and intended nature of the business relationship, politically exposed person status, results of screening against sanctions lists and adverse media, transaction history and the associated risk assessment.
Purpose: formal identification of the client, simplified, standard or enhanced due diligence as applicable, ongoing monitoring of the business relationship, special examination of transactions and, where applicable, the reporting of suspicious activity to the Spanish Financial Intelligence Unit (SEPBLAC).
Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Law 10/2010 and Royal Decree 304/2014).
Please note that, under Article 24 of Law 10/2010, AhoraCrypto may not disclose to the client or to third parties that information has been reported to SEPBLAC or that a transaction is being examined. This prohibition limits the scope of the rights described in clause 13 of this Policy.

4.4. Information accompanying transfers of crypto-assets (TFR)

Data processed: name of the originator and of the beneficiary, wallet address, account number or transaction identifier, address, identity document number, country and date and place of birth, where required.
Purpose: to transmit, receive, retain and verify the information that must accompany transfers of crypto-assets, and to apply the procedures for handling transfers with missing information.
Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Articles 14 to 20 of the TFR).
Disclosure of data: when you instruct a transfer of crypto-assets, AhoraCrypto is legally required to transmit the above data to the beneficiary’s crypto-asset service provider and, where applicable, to any intermediary provider. This disclosure is a mandatory legal requirement for the execution of the transaction and is not subject to your consent.

4.5. Prevention, detection and investigation of fraud

Data processed: identification data, transaction data, wallet addresses and their on-chain analysis, IP address, device identifiers, behavioural data on the Website and the App, usage patterns and associated risk signals.
Purpose: to prevent, detect, investigate and block fraudulent transactions, identity impersonation, unauthorised access, misuse of the Services and fraud schemes directed against Users or against AhoraCrypto. For these purposes, AhoraCrypto uses its own proprietary anti-fraud systems, which analyse transactions carried out through its Services. These systems are used solely for the internal control of AhoraCrypto’s own operations and are neither sold nor licensed to third parties.
Legal basis: the legitimate interest of AhoraCrypto and of its Users in the security of transactions and in the prevention of fraud (Article 6(1)(f) GDPR, in conjunction with Recital 47 GDPR), and compliance with legal obligations where the analysis is carried out under anti-money laundering legislation.

4.6. Information security, continuity and operational resilience

Data processed: access and activity logs, IP addresses, device identifiers, technical traces and incident records.
Purpose: to ensure the security of network and information systems, to detect and respond to incidents, to maintain service continuity and to comply with obligations relating to ICT risk management and incident reporting.
Legal basis: legitimate interest in information security (Article 6(1)(f) GDPR, in conjunction with Recital 49) and compliance with legal obligations arising from DORA and MiCA (Article 6(1)(c) GDPR).

4.7. Client support, enquiries and complaints

Data processed: identification and contact data, content of the communication, supporting documentation provided and details of the transaction concerned.
Purpose: to handle enquiries and requests for information, to process and resolve complaints submitted by Users, and to maintain the complaints register required by applicable legislation.
Legal basis: performance of the contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Article 71 MiCA and Commission Delegated Regulation (EU) 2025/294) and, in the case of enquiries from persons who are not clients, legitimate interest in responding to the request received.

4.8. Record-keeping and responses to requests from authorities

Data processed: all data relating to the Services provided, the orders received and the transactions executed, as well as communications held with the User.
Purpose: to maintain the records of services, activities, orders and transactions required by applicable legislation, and to respond to requests for information from the CNMV, SEPBLAC, the Spanish Tax Agency, judicial authorities and law enforcement bodies, as well as from competent authorities of other Member States.
Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Article 68 MiCA, Law 10/2010 and applicable tax legislation).

4.9. Establishment, exercise and defence of legal claims

Data processed: the data necessary to evidence the contractual relationship, the orders placed, the transactions executed, the communications held and the controls applied.
Purpose: the establishment, exercise and defence of claims in out-of-court, administrative or judicial proceedings, including disputes concerning allegedly fraudulent or unauthorised transactions, chargeback claims, proceedings before the CNMV or before other supervisory authorities, and any proceedings in which AhoraCrypto is a party or is required to evidence compliance with its obligations.
Legal basis: the legitimate interest of AhoraCrypto in defending its rights (Article 6(1)(f) GDPR) and, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR).

4.10. Job applications

Data processed: curriculum vitae containing identification, educational and professional data, cover letter and any other information provided by the candidate.
Purpose: management of the application in open recruitment processes or in future vacancies matching the candidate’s profile.
Legal basis: consent of the data subject (Article 6(1)(a) GDPR) and steps taken prior to entering into a contract.

4.11. Marketing communications

Data processed: name and surname, email address, telephone number, country of residence and interaction data relating to the communications sent.
Purpose: sending news, information about the Services, reminders and promotions.
Legal basis: consent of the data subject (Article 6(1)(a) GDPR) or, in the case of existing clients and in relation to services similar to those already contracted, legitimate interest under Article 21(2) of Spanish Law 34/2002. In either case you may object at any time, free of charge and by simple means, through the link included in each communication or by writing to privacidad@ahoracrypto.com.

5. Legitimate interest balancing

Where AhoraCrypto processes your data on the basis of legitimate interest, it has previously carried out the corresponding balancing exercise between that interest and your fundamental rights and freedoms. The outcome of that assessment is documented and available to you.

In relation to fraud prevention, AhoraCrypto has determined that the processing is necessary to protect both the funds and crypto-assets of Users themselves and the integrity of the Services, that the data processed is limited to what is strictly necessary to identify risk patterns, and that a User may reasonably expect an authorised crypto-asset service provider to apply controls of this nature.

In relation to the defence of legal claims, the processing is limited to the retention and use of information already collected in the course of the contractual relationship, for the applicable limitation periods, and access is restricted to the personnel and advisers involved in the relevant proceedings.

You may request further information about these assessments by writing to privacidad@ahoracrypto.com.

6. Automated decision-making and profiling

AhoraCrypto applies automated risk analysis systems in the context of anti-money laundering and fraud prevention. These systems may result in the assignment of a risk level to the User, in a request for additional documentation, in the delay or blocking of a specific transaction and, where applicable, in the refusal of onboarding or the termination of the business relationship.

The logic involved consists of the evaluation of a set of objective indicators, including the characteristics of the transaction, its amount and frequency, the User’s history, the characteristics of the wallet addresses involved and their on-chain analysis, matches against sanctions lists, and the consistency of the transaction with the declared profile. The envisaged consequence is the application of additional due diligence measures or the non-execution of the transaction.

This processing is based on Article 22(2)(b) GDPR, as it is authorised by Union law and by the Spanish law to which AhoraCrypto is subject, and on Article 22(2)(a) GDPR where it is necessary for entering into or performing the contract.

You have the right to obtain human intervention, to express your point of view and to contest the decision, by writing to privacidad@ahoracrypto.com. This right is exercised without prejudice to the confidentiality duty set out in Article 24 of Law 10/2010, which prevents AhoraCrypto from providing information about the existence of reports to SEPBLAC or about the examination of specific transactions.

7. Processing of data on blockchain networks

The provision of the Services involves the execution of transactions on public distributed ledger networks. Information recorded on those networks, including wallet addresses, amounts and timestamps, is public, is replicated across network participants and, by its own technical nature, cannot be modified or erased by AhoraCrypto or by any other participant.

AhoraCrypto does not control those networks and does not act as controller in respect of the information recorded on them once a transaction has been broadcast. Consequently, the rights to rectification and erasure cannot be exercised over information recorded on the blockchain, without prejudice to the fact that they may be exercised over the data that AhoraCrypto holds in its own systems.

We recommend that you take this into account before instructing any transaction, since the link between a wallet address and an identified person may result from combining public information with other sources.

8. Retention periods

Personal data will be retained for the periods set out below, after which it will be erased or anonymised:

  • Identification and customer due diligence data for anti-money laundering purposes, including video identification: ten years from the termination of the business relationship or from the execution of the occasional transaction, in accordance with Article 25 of Law 10/2010.
  • Records of services, activities, orders and transactions: five years, extendable to up to seven years at the request of the competent authority, in accordance with Article 68 MiCA.
  • Information accompanying transfers of crypto-assets under the TFR: ten years, in accordance with anti-money laundering legislation.
  • Complaints register: five years from resolution, in accordance with Commission Delegated Regulation (EU) 2025/294.
  • Contractual and client relationship data not covered by the paragraphs above: for the duration of the relationship and, after its termination, for the limitation periods applicable to any claims arising from it, up to a maximum of five years under Article 1964 of the Spanish Civil Code.
  • Accounting and tax documentation: six years under Article 30 of the Spanish Commercial Code and four years under Law 58/2003 (General Tax Law), calculated in accordance with the applicable rules in each case.
  • Technical security and access logs: twelve months, unless required for the investigation of an incident or of suspected fraud, in which case they will be retained until the matter is resolved and for the applicable limitation periods.
  • Curricula vitae: one year from receipt, unless the candidate requests erasure earlier.
  • Data processed for marketing communications: until consent is withdrawn or the data subject objects.

Where judicial, administrative or complaint proceedings are ongoing, or where a request from a competent authority is outstanding, the data concerned will be retained until the matter is finally resolved, even if the periods above have elapsed.

Once the applicable periods have elapsed, the data will be blocked and made available exclusively to courts and tribunals, the Public Prosecutor and the competent public authorities, for the limitation period applicable to any liability arising from the processing, in accordance with Article 32 of Spanish Organic Law 3/2018.

9. Recipients of the data

Your personal data may be disclosed to the following recipients:

  • Competent public authorities and bodies, in particular the CNMV, SEPBLAC, the Bank of Spain, the Spanish Tax Agency, judicial authorities and law enforcement bodies, as well as competent authorities of other European Union Member States, where there is a legal obligation or a validly issued request.
  • The beneficiary’s crypto-asset service provider and any intermediary provider, as required by the TFR and described in clause 4.4.
  • Financial institutions and payment service providers involved in the execution of transactions exchanging crypto-assets for funds.
  • Legal advisers, external auditors, external anti-money laundering experts and insurance undertakings, in the context of AhoraCrypto’s regulatory compliance and the defence of its interests.
  • Providers rendering services to AhoraCrypto as processors, in particular providers of identity verification and list screening, cloud infrastructure and hosting providers, managed security service providers, client communication providers and on-chain analytics providers.

AhoraCrypto has entered into the corresponding agreement under Article 28 GDPR with all processors, having verified that they offer sufficient guarantees to implement appropriate technical and organisational measures. You may request information about the current list of processors by writing to privacidad@ahoracrypto.com.

AhoraCrypto does not sell your personal data and does not disclose it to third parties for advertising purposes.

10. International data transfers

As a general rule, personal data is processed and hosted within the European Economic Area.

Where the provision of a service by a provider involves an international transfer of data to a third country, AhoraCrypto ensures that the transfer takes place under an adequacy decision of the European Commission or, failing that, under the standard contractual clauses approved by the European Commission, supplemented where necessary by additional measures resulting from the corresponding transfer impact assessment.

You may request information about existing international transfers and the safeguards applied by writing to privacidad@ahoracrypto.com.

11. Geographical scope of the Services

AhoraCrypto provides its Services to residents of European Union Member States. AhoraCrypto does not direct its Services to residents of third countries and may refuse onboarding or terminate the business relationship where it establishes that a User does not meet this requirement.

12. Accuracy of the data

The User declares and warrants that the personal data provided is true, accurate and up to date, and undertakes to notify AhoraCrypto of any change to it. The obligation to keep information up to date also arises from Article 7 of Law 10/2010.

AhoraCrypto reserves the right to suspend or terminate the provision of the Services to any User who has provided false, incomplete or inaccurate data, without prejudice to any other action available at law.

13. Your rights

You have the right to access your personal data, to request the rectification of inaccurate data, to request its erasure, to request the restriction of processing, to object to processing, to request data portability and not to be subject to decisions based solely on automated processing, on the terms set out in Articles 15 to 22 GDPR.

You may exercise your rights at any time by writing to privacidad@ahoracrypto.com, or by post to AHORACRYPTO, S.L., Calle Gabriel García Márquez nº 4, 1ª Planta, 28232 Las Rozas (Madrid), Spain, expressly stating the right you wish to exercise and enclosing a document evidencing your identity.

The exercise of these rights is subject to the following limitations arising from applicable legislation:

  • Data processed in compliance with anti-money laundering legislation, MiCA or the TFR cannot be erased during the statutory retention periods, nor may you object to its processing.
  • Under Article 24 of Law 10/2010, AhoraCrypto may not provide information about the existence of reports to SEPBLAC or about the examination of specific transactions.
  • Information recorded on public blockchain networks cannot be rectified or erased, as set out in clause 7.
  • The right to object will not apply where AhoraCrypto demonstrates compelling legitimate grounds which override your interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims.

If you consider that the processing of your data does not comply with applicable legislation, or if you are not satisfied with the response to the exercise of your rights, you may lodge a complaint with the Spanish Data Protection Agency (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es) or with the supervisory authority of the Member State of your habitual residence, place of work or place of the alleged infringement, without prejudice to any other administrative remedy or judicial action.

14. Data security

AhoraCrypto has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR and with the ICT risk management framework set out in DORA. These measures include encryption of information, access control on a least-privilege basis, continuous monitoring through a security operations centre, backups, vulnerability and patch management, and periodic security testing.

AhoraCrypto undertakes to comply with its duty of secrecy and confidentiality in respect of personal data, which extends to all of its personnel and to its processors.

Access to the Services requires the use of authentication credentials. The User is responsible for maintaining the confidentiality of those credentials and for all activity carried out from their session, and undertakes to notify AhoraCrypto, as soon as possible, of any unauthorised use or security incident of which they become aware.

Notwithstanding the above, please note that security measures on the internet are not impenetrable. In the event of a personal data breach resulting in a high risk to your rights and freedoms, AhoraCrypto will notify you in accordance with Article 34 GDPR.

15. Minors

The Services are intended exclusively for persons over eighteen years of age. AhoraCrypto does not knowingly collect data from minors. If a User is found to be a minor, the account will be closed and their data erased, without prejudice to applicable statutory retention obligations.

16. Cookies and similar technologies

The use of cookies and similar technologies on the Website and in the App is governed by AhoraCrypto’s Cookie Policy, available on the Website, which supplements this Privacy Policy.

17. Links to third-party sites

The Website and the App may contain links to third-party websites. AhoraCrypto is not responsible for the processing of personal data carried out by those third parties, and we therefore recommend that you review their respective privacy policies, the terms of which may differ from those set out here.

18. Changes to this Privacy Policy

AhoraCrypto may revise this Privacy Policy to reflect changes in legislation, case law, supervisory criteria or in the provision of the Services. The version in force will always be available on the Website and in the App.

Where a change materially affects the processing of your data, AhoraCrypto will notify you in advance, within a reasonable period, through the contact details provided.

19. Contact

For any matter relating to this Privacy Policy or to the processing of your personal data, you may contact AhoraCrypto at privacidad@ahoracrypto.com or at the postal address set out in clause 1.