PRIVACY POLICY
TABLE OF CONTENTS
- 1. Introduction
- 2. Principles, Data Categories and Purposes of Processing
- 3. Recipients and Transfers
- 4. Retention Periods and Data Subject Rights
- 5. Security Measures and Additional Considerations
- 6. Bit2Me Junior
- 7. Final considerations
1. Introduction
1.1. Objectives
This Privacy Policy describes how Bit2me collects, uses, and protects your personal data when providing the services offered through various channels. Our commitment is to guarantee the privacy and security of your data in accordance with the General Data Protection Regulation (hereinafter GDPR), as well as other applicable privacy regulations, allowing for the secure use of our services.
1.2. About us
Bitcoinforme S.L. is a company authorized by the National Securities Market Commission (CNMV) as a crypto-asset service provider (CASP) in accordance with EU Regulation 2023/1114 (MiCA), by resolution of July 28, 2025, and is the main entity acting as Data Controller for personal data collected through our website and app, without prejudice to the joint controllership agreement signed between some companies of the group (see section 3.3). Bit2me may operate through different companies, so you will be informed at the time of using a specific service which company you are establishing a contractual relationship with, as well as which company will process your personal data.
1.3. Scope of application
This Privacy Policy applies to any person who uses the services and products offered by Bit2me, whether through our web platform (not limited to the domain https://bit2me.com/es) or the mobile application, as well as any other means that involves the processing of personal data. It also applies to all personal data processing operations carried out by the different departments of Bit2me, thus ensuring uniform protection of your personal data.
2. Principles, Data Categories and Purposes of Processing
2.1. Principles of Processing
Bit2me strictly adheres to the following guiding principles established in the GDPR for the processing of your personal data:
- Lawfulness, Fairness and Transparency: Your data will be processed lawfully, fairly, and transparently. This implies clearly informing you about the processing carried out.
- Purpose Limitation: Data will be collected for specified, explicit, and legitimate purposes, and will not be further processed in a manner incompatible with those purposes.
- Data Minimization: Bit2me will ensure that the personal data processed is adequate, relevant, and limited to what is strictly necessary in relation to the purposes for which they are processed.
- Accuracy: Your personal data will be accurate and, where necessary, kept up to date. Bit2me will take all reasonable steps to ensure that inaccurate data is erased or rectified without delay with respect to the purposes for which they are processed.
- Storage Limitation: Data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, subject to legal retention obligations (e.g., Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing).
- Integrity and Confidentiality: Data will be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
2.2. Categories of data collected
Bit2Me obtains and processes your personal data from the following sources:
Directly from the data subject
Most of the data we process is provided directly by the data subject themselves when interacting with Bit2Me and its services.
- Through web forms and registrations: When you request information, contact Bit2Me, sign up for newsletters, register for an event, participate in a contest or sweepstakes, or register for Bit2Me's main services.
- Through the contractual or pre-contractual relationship: When you provide us with data for managing your job application (CV), for providing or contracting services (Clients/Suppliers), or for the execution of specific service Terms and Conditions (Crypto API, Commerce, etc.).
- Through the reporting channel: When you submit a communication or complaint through the Whistleblower Channel, with or without identifying data.
- Through voluntary upload: When you upload a photo or avatar to your Bit2Me user profile.
- Through direct interaction on social media: Personal data you provide when becoming a follower of Bit2Me's corporate social media accounts.
Generated by Activity and Use of Our Services
We collect data generated by the use of the Bit2Me Platform, necessary for service provision and experience improvement. In strict compliance with the principle of data minimization and privacy by design, we will never process more data than necessary for the intended purpose.
- Navigation and technical data: User metadata produced during your navigation (browser, operating system, IP, among others), IP, connection time, and pseudonymized user ID.
- Support and customer service data: User identifiers, traceability data, and history of queries and incidents managed through Customer Service.
From Third Parties
We obtain personal data from external sources, other than the data subject themselves or your activity on the platform, necessary for the fulfillment of legal obligations or for the provision of certain services.
- Bit2Me Group companies (Joint Controllers): Data is processed jointly with other Bit2Me Group companies as Joint Controllers for various purposes such as commercial, fraud prevention, or compliance with Anti-Money Laundering regulations according to the formalized joint controllership agreement.
- Intermediary Entities: For certain services, intermediary entities (configured as Data Controllers) communicate the necessary data for the verification and monitoring of the correct provision of the service.
- Regulatory Compliance (AML/CTF): Data obtained from external or public sources (sanction lists, PEPs databases) for investigations related to the Prevention of Money Laundering and Terrorist Financing.
2.3. Purposes and Legal Bases for Processing
| Purpose of processing | Legal basis | Data processed |
|---|---|---|
| Commercial contact: To respond to information requests made by the data subject through any means about Bit2Me's products and services, and to establish and maintain commercial relationships. | Based on the consent granted, Bit2Me is authorized to process the data subject's data provided through the contact request, and in accordance with legitimate interest for the development and maintenance of commercial relationships (Arts. 6.1.a and 6.1.f GDPR). | Name, phone, email, and query. |
| CV or employment: To manage the data subject's application for published selection processes or other vacant positions that may arise in the future within Bit2Me's activities, in accordance with their professional profile. | The application of pre-contractual measures at the data subject's request or consent in case of reuse for future vacancies (Arts. 6.1.b and 6.1.a GDPR). | Professional area, name, surname, phone, email, CV, cover letter, and any other personal data associated with the CV or professional profile. |
| Promotional or newsletters: Registration for sending information, news, and promotions, and establishing and maintaining commercial relationships. | Consent of the data subject granted to Bit2Me for registration in promotional services and/or legitimate interest in the development of commercial relationships (Arts. 6.1.a and 6.1.f GDPR). | Email address, name, surname, phone number, city or country. As well as user metadata generated during their navigation (browser, operating system, IP, among others). |
| Service provision: Management of registration, execution, and monitoring of services contracted by the user (Loan, Pro, and other Bit2Me services), including technical training (Academy), integration of Application Programming Interfaces (API), and processing, verification, and confirmation of commercial transactions. It also includes the maintenance of the legal and commercial relationship by electronic means. | The existing legal or contractual relationship necessary for the provision of the service (Art. 6.1.b GDPR) and the legitimate interest in the development and maintenance of commercial relationships. | Name, surname, ID, contact address, email, contact phone, user identifiers, transactions and operations carried out on the Platform (pseudonymized), as well as cryptocurrency data and wallet addresses necessary for the proper provision of the service, where applicable. For the BIT2ME Crypto API service, when the identity verification process (KYC) is delegated to the intermediary entity, Bit2Me will additionally process the necessary data for compliance with its AML/CTF obligations. |
| Identity verification: Formal customer identification (KYC), due diligence, and continuous monitoring for compliance with respective regulations. For fraud and money laundering prevention, we inform you that Bit2Me may make decisions supported by AI tools (such as preventive account blocking) in accordance with regulatory thresholds. All these decisions are humanly supervised by experts with decision-making power in the current processing. | The existing legal or contractual relationship necessary for the provision of the service (Art. 6.1.b GDPR), as well as compliance with a legal obligation (Art. 6.1.c GDPR). | Name, surname, ID, contact address, home address, email, contact phone, and other data that may be necessary for formal customer identification and investigation in matters of Anti-Money Laundering and Terrorist Financing, including image and biometric data. |
| Regulatory compliance: Collection, verification, and transmission of the originator's and beneficiary's information to third-party Crypto-Asset Service Providers (CASPs) for each transfer. | Compliance with a legal obligation (Art. 6.1.c GDPR). | Identification and transactional data of the originator and beneficiary. |
| Due diligence and supplier management: Evaluation, selection, and management of the contractual relationship with collaborators, commercial partners, and service providers. Includes the necessary due diligence processes to ensure compliance with the entity's operational, security, and regulatory standards, as well as the administrative and contact management necessary for the execution of current agreements. | The existing legal or contractual relationship necessary for the provision of the service, as well as the legitimate interest in the development of commercial relationships (Arts. 6.1.b and 6.1.f GDPR). | Name, surname, ID, professional contact address, email, contact phone. |
| Infrastructure security and asset protection: To ensure the security, integrity, and resilience of the entity's operational environments, facilities, and systems. This includes managing access controls and monitoring to prevent incidents, protect the physical safety of individuals, and safeguard entrusted assets against threats or unauthorized access. | Compliance with legal obligations regarding security and legitimate interest in protecting critical infrastructure and preventing losses (Art. 6.1.f GDPR). | Identification data, access logs (date/time), images captured by security monitoring systems, and professional contact details of involved parties. |
| Management of promotional activities and events: Organization, management, and development of events, contests, sweepstakes, and commercial promotions, whether carried out independently or in collaboration with third parties. Includes managing the data subject's participation, prize or benefit delivery, and promotion of services through corporate channels and electronic media. | Data subject's consent for participation in the activity or event and for the capture of their image/voice, if applicable; as well as legitimate interest in developing the commercial and promotional relationship. If Terms and Conditions are established for a contest/event, the lawfulness will be based on the existing legal or contractual relationship necessary for the provision of the service (Art. 6.1.b GDPR). | Name, surname, ID, postal address, email, contact phone, and other data necessary for registration or participation. May include image, name, and voice in audiovisual recordings or photographs taken during events. |
| Behavioral analysis and error resolution: Behavioral analysis for improving user experience and resolving technical issues. | Legitimate interest in offering a high-quality service and maintaining the stability of the technological infrastructure (Art. 6.1.f GDPR). | IP, connection time, and user ID, in pseudonymized form. |
| Whistleblower Channel/Reporting Channel: Management of the whistleblower channel and received complaints. | Compliance with a legal obligation (Art. 6.1.c GDPR). | Name, surname, ID, contact address, domicile, email, contact phone, and other data necessary for submitting the complaint, including a detailed description of the reported facts, as well as the identity of potential witnesses. |
| Bot Fraud Prevention via DSPs (S2S): Matching and conversion control with Adtech platforms for detecting advertising fraud and protecting the infrastructure against automated traffic (bots). | Bit2Me's legitimate interest in protecting its infrastructure (Art. 6.1.f GDPR). Where explicit user consent is necessary (Art. 6.1.a GDPR). | ClickIDs, UDIDs, IP address, and other technical conversion identifiers. |
| Web Support and Incident Resolution: Customer service and management of queries and incidents raised through the Customer Service Department to ensure correct service provision and continuity. | Execution of the contract / Terms of Use (Art. 6.1.b GDPR) and Bit2Me's legitimate interest in ensuring service continuity (Art. 6.1.f GDPR). | User identifiers, contact data, and content and history of the query or incident raised. |
We inform you that some data processing operations have as their legal basis the satisfaction of legitimate interests pursued by Bit2Me in joint controllership with the Bit2Me Group companies. These processing operations are carried out after an assessment of your rights and our legitimate interest, in which we have concluded that our interest prevails, as established in Art. 6.1.f) of the General Data Protection Regulation (GDPR).
You can consult the legitimate interest assessment for a specific processing at any time by sending your request to the email address dpd@bit2me.com. We also remind you that you have the right to object to processing based on legitimate interest. You can do so via the email address rgpd@bit2me.com.
Specifically, based on Bit2Me's legitimate interest, the data subject's personal data may be used to protect against possible fraud and try to prevent economic or reputational losses from such fraud, for establishing or maintaining commercial relationships by any means, including electronic means, regarding information of interest about Bit2Me products and services, improving user experience and resolving technical problems, in addition to ensuring security in the facilities by their owner.
The provision of your personal data is, in general, a necessary requirement for the provision of Bit2me's services, particularly in those cases where processing is based on compliance with a legal obligation (for example, identity verification in accordance with Law 10/2010 on the Prevention of Money Laundering) or on the execution of a contract (for example, transaction management). In these cases, refusal to provide the requested data will prevent the provision of the corresponding service.
3. Recipients and Transfers
3.1. Disclosure of Data to Third Parties
At Bit2Me, we are committed to protecting your privacy and only share your personal data when it is strictly necessary to provide you with our services, comply with the law, or protect our legitimate interests.
That is why we may share your personal data with the following recipients:
- Authorities and official bodies: We are obliged to provide identification and transactional information to judicial or administrative authorities, such as SEPBLAC or the Spanish Data Protection Agency (AEPD), to comply with Law 10/2010 on the Prevention of Money Laundering and other tax or legal obligations. Likewise, within the framework of the Internal Information System (Whistleblower Channel), data may be communicated to the Independent Authority for the Protection of Whistleblowers (AAI), the Public Prosecutor's Office, or the competent judicial authority when the reported facts could constitute an infringement or crime, in accordance with Law 2/2023.
- Partners for legal compliance: For each crypto-asset transfer, we transmit the required originator and beneficiary information to other Crypto-Asset Service Providers (CASPs) to comply with EU Regulation 2023/1113.
- Other providers: We use external services for the operation of our App and Website, so for you to enjoy certain functionalities, we share your information with them under strict confidentiality agreements and corresponding data protection contracts.
Furthermore, for certain activities and functions, we use data processors, which can be grouped into the following categories.
| Type of processor | Data involved |
|---|---|
| Technology infrastructure and cloud providers | All data processed in Bit2Me services (including Name, ID, Email, Contact Data and Transactions). |
| Services for AML regulatory compliance | Name, surname, ID, address, image, and other data for formal identification and AML investigation |
| Whistleblower Channel Management | Whistleblower identification data (unless anonymous), data of affected persons and third parties mentioned in the communication, as well as the description of the reported facts. |
| Communication and digital marketing platforms | Email address, name, surname, navigation metadata |
| Behavior analysis and debugging tools | IP, connection time, user ID (pseudonymized) |
| Customer support and contact services | Name, phone, email, user ID (pseudonymized) |
| Training and content platforms | Name, surname, email address |
| Human Resources and recruitment providers | Professional area, name, surname, phone, email, CV, cover letter, and other data associated with the professional profile |
| Commercial partners (KYC/AML) | Identity data and verification evidence (KYC) shared with commercial integration partners (B2B2C models) to ensure coordinated compliance with Law 10/2010, of April 28, on the prevention of money laundering. |
| Cybersecurity providers | Data necessary for infrastructure administration and information security. |
| Payment and fund processing providers | Identification data, bank and payment method data (account/card number, holder), and transaction information, necessary for the provision of financing, card, loan, and payment services offered by Bit2Me. |
3.2. International Data Transfers
The processing of your data is primarily carried out within the European Economic Area (EEA). However, given the global nature of our crypto-asset custody and exchange services, as well as the necessary technological infrastructure, your personal data may be transferred to countries outside the EEA.
Bit2Me is committed to ensuring that any international transfer of personal data maintains an essentially equivalent level of protection to that guaranteed by the GDPR.
At Bit2Me, we may collaborate with partners or providers located outside the European Economic Area. When this occurs, we ensure that your personal data travels with the same level of security and protection as in Spain, always complying with the provisions of the GDPR. To achieve this, we use the following security mechanisms:
- Safe countries (Adequacy Decisions): We send data to countries that the European Commission has officially recognized as safe, having data protection laws equivalent to those in Europe.
- Protection contracts (Appropriate Safeguards): If the country does not have such certification, we sign specific contracts approved by the European Commission (called Standard Contractual Clauses). In addition, we assess whether it is necessary to add extra security layers, such as advanced encryption, so that no one can access your information without authorization.
- Exceptional situations: Only in very specific cases and if the aforementioned safeguards do not exist, we may carry out a transfer based on legal exceptions. This occurs, for example, when you give us your explicit permission after being informed of the risks, or when the transfer is essential for us to fulfill the contract you have with us (such as processing a specific operation).
To request more information about possible international data transfers, you can send an email to rgpd@bit2me.com or contact our Data Protection Officer at dpd@bit2me.com.
3.3. Joint Controllership
The companies Bitcoinforme S.L., Devteam S.L., Deka Software Labs S.L. and Devteam Ireland LTD (hereinafter collectively referred to as the "Bit2Me Group") act as joint controllers for determining jointly the purposes and means of certain activities. This collaboration is based on a joint controllership agreement, in accordance with Art. 26 of the GDPR, through which they coordinate to guarantee information security, the fulfillment of the duty of confidentiality, and centralized data protection management that mitigates operational and reputational risks for the Group.
Processing operations carried out under this joint controllership regime include: (i) the management of the contractual, commercial, and support relationship with customers and suppliers, based on the performance of a contract; (ii) the sending of commercial communications, fraud prevention, and security analysis, covered by the Group's legitimate interest; and (iii) compliance with critical regulations such as Anti-Money Laundering (AML/CTF), tax obligations, and ethical channel management, based on the fulfillment of legal obligations.
Users are informed that they can exercise their data protection rights indistinctly before any of the entities or through the single point of contact at rgpd@bit2me.com. For detailed information on the essential aspects of the joint controllership agreement or the specific breakdown of processing operations, data subjects can request it through the aforementioned email address.
Rewards Program (PayLead): If you register for the Rewards Program, your data will be jointly processed by Bit2Me and PayLead SAS (France) as Joint Controllers, including the analysis of your bank transactions for the generation of personalized offers. For more information, please consult the specific Rewards Program Privacy Policy Here.
4. Retention Periods and Data Subject Rights
4.1. Data Retention Periods
At Bit2Me, we retain your personal data only for the time strictly necessary to offer our services and fulfill the purposes for which they were collected, as long as you maintain your user status and do not request their deletion. Thus, the lifecycle of your personal data is governed by the principle of storage limitation. We do not keep your data indefinitely; its permanence in our systems is divided into three clearly differentiated phases:
1. Active Processing Phase
Your data will be processed as long as you maintain your user status or do not withdraw your consent for specific purposes (such as sending newsletters or selection processes). The moment you request the deletion of your data, it stops being used for commercial, operational (service-specific), or marketing purposes within a maximum period of 48 hours.
2. Legal Hold and Blocking Phase
After the termination of the relationship or the request for deletion, not all your data is physically deleted immediately. By legal imperative, Bit2Me must retain certain data relevant for the fulfillment of legal obligations or the proper exercise of the right to effective judicial protection; in the latter case, duly blocked. Blocking implies adopting technical measures to prevent their ordinary processing and viewing, being reserved solely at the disposal of Judges, Courts, the Public Prosecutor's Office, or the competent Public Administrations (such as the Spanish Data Protection Agency (AEPD) or SEPBLAC).
The indicative periods for legal hold/blocking and their criteria are as follows:
| Purpose of Processing | Retention / Blocking Period | Legal Basis and Justification |
|---|---|---|
| Identity Verification (KYC), AML and Monitoring | 10 years (Legal Hold) | Arts. 25 and 32 of Law 10/2010. Obligation to retain documents and transaction records. |
| Service Provision and Transaction Management | 5 - 6 years (Blocking) | Art. 1964 Civil Code (personal actions) and Art. 30 Commercial Code (commercial documentation). |
| Commercial Contact, Promotional and Newsletters. Behavior and error resolution. User Service Center (CAU) Logs and Incidents | 3 years (Blocking) | Prescription period for serious infringements before the AEPD (Art. 72 Organic Law 3/2018, of December 5) and compliance with the LSSI (Spanish Information Society Services Law). |
| Whistleblower Channel / Reporting Channel | 3 months (Deletion) | Law 2/2023. Maximum retention period in the information system. |
| CV and Selection Processes | 1 year (Deletion) | Minimization principle. Proportional period for future vacancies if consent is given. |
| Account Audit | 5 years (Blocking) | Art. 30 of Law 22/2015 on Account Auditing. |
At Bit2Me, we have a specific personal data retention protocol where retention periods are detailed exhaustively. For more information, you can contact rgpd@bit2me.com.
3. Definitive Deletion Phase
Once the aforementioned legal limitation periods have elapsed, we will proceed with the physical destruction or irreversible anonymization of your information, so that it can no longer be associated with your identity under any circumstances.
4.2. Your Personal Data Rights
In accordance with the GDPR, the data subject has a series of rights that allow them to control and manage their personal data. That is why Bit2me is committed to facilitating the exercise of these rights within the established period.
Right to Access
Right to obtain confirmation as to whether or not we are processing your personal data and, if so, to obtain a copy of the data, in addition to certain information related to its processing.
Right to Rectification
Right to obtain the correction of personal data that is inaccurate or to have incomplete data completed.
Right to Erasure (right to be forgotten)
Right to obtain the erasure of your personal data in accordance with applicable regulations.
Right to Restriction of Processing
This right enables the data subject to obtain from the controller a restriction of the processing of their personal data. The exercise of this right implies that the data subject to restriction may only be stored and, with exceptions, may not be subject to further processing operations.
Right to Data Portability
Right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit them to another controller.
Right to Object
Right to object at any time to our processing of your personal data based on Bit2me's legitimate interest.
Right not to be subject to Automated Individual Decision-Making
Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Requests to exercise your rights must be submitted through our dedicated channel: rgpd@bit2me.com, or to the postal address Calle Germán Bernacer, 69, 03203, Elche, Alicante, Spain.
If you believe that Bit2me has failed to comply with its data protection obligations or has not satisfactorily addressed your request for rights, you have the right to lodge a complaint with the competent supervisory authority. In Spain, this authority is the Spanish Data Protection Agency (AEPD), and you can contact them through the following link https://sedeaepd.gob.es/sede-electronica/home
5. Security Measures and Additional Considerations
5.1. Security Measures
Bit2Me has implemented an Information Security Management System certified under international standards ISO 27001, ISO 37001, and ISO 22301, guaranteeing the resilience and proactive protection of data. These technical measures include data encryption, fragmentation of sensitive information, and the use of advanced custody infrastructures to prevent alteration, loss, or unauthorized access. The effectiveness of these controls is evaluated through periodic reviews, ensuring that the integrity of personal information is maintained under strict logical and physical security standards.
Privacy is reinforced through restricted access control policies and continuous real-time threat monitoring. This Privacy by Design and by Default approach allows the Group to comply with the requirements of applicable privacy regulations, ensuring that personal data processing evolves to address new technological risks. The entity's commitment to continuous improvement ensures a secure environment that protects both the identity and informational assets of all our users.
5.2. Processing of Minors' Data
For certain functionalities or services, Bit2Me may process data of minors. In such cases, this processing will always guarantee compliance with the conditions established in the applicable privacy regulations. Likewise, Bit2me will implement age verification measures and reinforced security protocols for these cases to protect the best interest of the minor and in strict compliance with Privacy by Design and by Default, guaranteeing the principles established in the GDPR.
5.3. Cookies and Tracking Technologies
Bit2me uses cookies and other tracking technologies on its websites and applications to ensure the correct technical functioning of the platform, measure performance, and, when you consent, offer a better experience and personalized advertising. The processing of personal data obtained through these technologies is governed by our Cookie Policy, which you can access via the following link for more information https://legal.bit2me.com/es/support/solutions/articles/35000291056-pol%C3%ADtica-de-cookies.
6. Bit2Me Junior
The provisions of this Privacy Policy will be fully applicable to the Bit2Me Junior service, except for the specifications detailed in this section, which will prevail due to their nature of Privacy by Design (Art. 25 GDPR).
6.1. Information Obligation and Data Origin
Bit2Me Junior is a targeted savings functionality linked to the main Account Holder's account. The Account Holder can create a sub-account and grant viewing access to third parties of their choice. Bit2Me does not collect, process, or store identification data of such third parties, who only access the balance view through the application without holding the status of clients or independent data subjects for GDPR purposes.
In compliance with the duty of transparency, the main account holder (parent/legal guardian) is informed that:
- Principle of Non-Identification: The service has been designed to operate without requiring formal identification data of the minor (ID/NIE, real name, or biometrics). Bit2Me processes technical terminal identifiers and declarative tags, so the minor is not identified as an independent natural person in our systems.
- Data Origin: Bit2Me does not obtain data of minors from external sources.
6.2. Anti-Money Laundering and Financial Security
For the purposes of Law 10/2010, the minor does not hold the status of a client or beneficial owner, with all operational responsibility falling on the verified adult:
- Delegated Monitoring: Bit2Me will apply suspicious transaction control rules to the main Account Holder. In case of unusual movements, the Account Holder will be required to provide proof of Funds Origin (SoF).
- Due Diligence by Exception: Bit2Me reserves the right to request evidence of the family relationship to validate the savings purpose of the product or other relevant information for the purposes of the aforementioned law. This documentation will be processed in accordance with the retention periods required by anti-money laundering regulations, applying restricted access measures and secure deletion (Art. 32 GDPR) once the legally established period has elapsed and in accordance with the principle of personal data minimization.
6.3. Technical Anonymization and Encryption Measures
To ensure that the use of the App does not imply the identification of the minor as an independent data subject or differentiated processing of their personal data, the service has been designed in accordance with the principles of privacy by design and by default, incorporating the following controls:
- Metadata Attribution to the Main Account Holder: Technical identifiers generated by the use of the App (such as the IP address or device ID) are considered, for legal purposes, attributes linked to the main Account Holder who has authenticated the session. Given that the terminal and internet connection are under the legal responsibility of the adult, these metadata are not associated with a minor, but with the technical activity of the verified Account Holder.
- Total Tracking Restriction (Zero-Tracking): By default, the Junior application has all third-party SDKs, marketing cookies, or behavioral analysis tools disabled. No commercial profiling of the terminal user is performed, limiting processing to strictly technical and security functions necessary for the assisted service provision.
6.4. Exercise of Rights
The exercise of the rights set out in Articles 15–22 GDPR concerning the Bit2Me Junior functionality will be carried out by the main Account Holder in accordance with current regulations and the declared legal capacity.
7. Final considerations
7.1. Data Protection Officer Contact
For any questions regarding the processing of your personal data, this Privacy Policy, or the management of a potential security breach, Bit2me has appointed a Data Protection Officer (DPO) in accordance with Article 37 of the GDPR. You can contact our DPO via the following email: dpo@bit2me.com. We ask that you use these channels to ensure that your query is directed to the competent person or team and to facilitate the traceability and proper management of your request.
7.2. Validity and Versions
At Bit2Me, we work every day to evolve and improve our services; therefore, we may update this Privacy Policy periodically to reflect these advances or to adapt to legal changes. You can always check the date of the last update on our website.
If we make significant changes that affect your rights or how we use your information, we will notify you with reasonable notice before they come into effect, either through our platform or through usual contact channels, always complying with the deadlines required by regulations.
In addition to this general document, on occasion, we will show you specific privacy notices or "just-in-time" reminders while you use certain functions of our App or Website. These quick notices serve to give you a clearer and more direct overview of how we process your data in specific services, offering you simpler control over your privacy options.
© Bit2Me 2026
All rights reserved.