Version 2.0.2 - 16.02.2022

Introduction

gold-line

This Privacy Policy describes how Vaultoro collects, uses and discloses information, and what choices you have with respect to the information.

Vaultoro takes the protection of your personal data very seriously. We treat your personal details confidentially and in accordance with the statutory data protection regulations and with this data privacy statement. We believe security & privacy should come first.

Responsible Authority/Requesting your data

You are entitled at any time to receive information free of charge about your stored personal data, its origin and recipient and the purpose of the data processing. Furthermore, you are entitled to the correction, blocking or deletion of your personal data.

Please direct all requests for information, queries or revocations regarding data processing via email to the authority responsible for the collection, processing and use of personal data:

Attn. DPO (data protection officer)
Email: [email protected]

Vaultoro Limited
The Loft at The Maltings
East Tyndall Street
Cardiff CF24 5EZ

It is generally possible to use our website without entering personal data. If personal data (e.g. name, address or email address) is collected on our pages, this always takes place on a voluntary basis wherever possible. This data will not be passed on to third parties without your express permission.

Below is some information to let you know what data is collected during your visit to our website and how it is used.

What information does Vaultoro Collect?

gold-line

Data collection when you visit vaultoro.com and Vaultoro blog

If you visit our sites for informational reasons (and do not open an account), we do not collect any personal data. We may gather the data which your browser transmits in order to enable your visit to our Website. This may include: IP address, Date and time of the request, Content of the request (specific page), Access status/http status code, Volume of data transferred, Website from which the request comes), Browser, Operating system, Language and version of the browser software.

This Server logs cannot be matched to specific people and is not merged with other data sources. We reserve the right to subsequently review this data if we become aware of specific indications of unlawful use.

Data collection and processing in case of opening and using a Vaultoro account.

The following data will be collected, used and processed by Vaultoro for the purpose of Sign-up: First name and surname, Date of birth, Email address, Nationality, Registered address, telephone number, Identification document, Type of identification document, Issue date, ID number, ID validity, source of funds, source of wealth. If there is further information collected, it will be processes in the same way as the above.

Verification

All the data collected by Vaultoro is used solely for the purposes of verifying identity documents and/or identifying the user. Vaultoro will not process of your personal data beyond the purpose for which the legal permission is granted.

During the verification process photographs of the identity documents and bills are used to match the user data. The data recorded will vary depending on the type of identity document and the specific situation of the customer.

Vaultoro stores the photographs of the ID documents together that were used to verify the user data. The data can be stored by Vaultoro for the duration of the business relationship and for up to five years after termination, according to the recommended retention periods of the Anti Money Laundering Act.

To a limited extent, we also transmit personal information to processors who perform services for us such as video authentication services( Onfido Limited), IT services (Amazon Web Services Inc.), Client support (Zendesk Inc.), improvement of our website; performance of contracts, account management, accounting, invoicing, examination of defective or suspicious business cases , application management and sending out newsletters. Processors may only use or disclose this data to the extent necessary to perform services for us or to comply with legal rules. Vaultoro contractually obliged these processors to ensure the confidentiality and security of your personal data that they process on our behalf.

If you have given us your consent to process your personal data, processing will only take place in accordance with the defined purposes and to the extent agreed in the declaration of consent. Given consent may be withdrawn at any time without giving reasons and with future effect, if you no longer agree to the processing. For example, with your consent we are processing data for the following purposes:

  • Automated authentication process when you verify yourself using the service ("Onfido") of Onfido Limited (validation of identity);

Trading history

Trading history is collected for the service itself and it is automatically processed to determine the reduction of trading fee.

This data is not shared with any third party and every user has the ability to see this information on their account at any time.

Other data collection

Additional personal data will only be collected if you provide these details voluntarily, for example when making an enquiry. If you provide us with personal data, we will only use it to answer your query and/or process the contract concluded with you. The data will only be stored for us for as long as it takes to implement of the process, e.g. as long as it takes to answer your query. Six weeks at the latest after the termination of the process, all personal data collected will be deleted, unless it is subject to statutory retention periods. Our website uses Uservoice (UserVoice, Inc. 121 2nd Street, 4th Floor, San Francisco, CA 94105) for Customer Support and Enquiries

What information is public on Vaultoro?

Vaultoro makes information public voluntarily for transparency.

Since such public information can be accessed by the public and used by any member of the public, such use by third parties is beyond the control of Vaultoro.

More information can be read in the Publicly visible data section of our terms of services.

What information is shared with Third parties?

We've gone to great lengths to ensure we only use legitimate providers who will also protect your data. Before engaging with any third party Vaultoro performs due diligence to evaluate their privacy, security and confidentiality practices, and executes an agreement implementing its applicable obligations. Your data is only transmitted to third parties when strictly necessary for the performance of the contract or if you have consented to this beforehand.

Email services

As part of the service, we allow data to be synced automatically with third party email services:

MailChimp
MailChimp, 675 Ponce de Leon Ave NE, Suite 5000. Atlanta, GA 30308 USA)

SendGrid
(Sendgrid Inc., 1801 California St, Denver, CO 80202, USA)
If you would like to review SendGrid's privacy policy: https://sendgrid.com/policies/privacy/

Gold Ownership

With the sole purpose of proving Gold ownership your personal data (Name, Surname, Address, Nationality) and Gold balance is shared with ProAurum Switzerland. (pro aurum Schweiz AG - Weinbergstrasse 2. CH-8802 Kilchberg ZH) ProAurum data protection policy: http://proaurum.ch/home/footerbereich/datenschutz.html

Service provider

Vaultoro Clients Limited, as a service provider has access to personal data (Name, Surname, Address, Nationality) and Gold balance. Vaultoro Clients Limited is a 100% subsidiary of Vaultoro Limited. The sole purpose is the provision of service.

What information is collected by Third parties?

Vaultoro uses services that collect data remotely by using "pixel tags", or similar technologies. These technologies can recognise certain types of information on your web browser, whether you have viewed a particular web page or email message, and determine, among other things, the time and date on which you viewed them and the IP address of the computer from which you viewed them.

Google Analytics and Google Tag Manager

This website uses functions of the website analysis service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

Google Analytics uses so-called "cookies". These are text files that are stored on your computer that enable an analysis of your use of the website. The information about your use of this website generated by the cookie is generally sent to a Google server in the USA, where it is stored. Google may also pass on this information to third parties, if this is mandated by law or if third parties process this data on behalf of Google.

Browser plugin to prevent data processing by Google

You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent the logging of the data collected by the cookie and related to your use of the website (incl. your IP address) from being sent to Google, and the processing of this data by Google, by downloading and installing the browser plugin available from the following link:

https://tools.google.com/dlpage/gaoptout?hl=de

Objection to data collection by Google

You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be placed, preventing the collection of your data during future visits to this website: deactivate Google Analytics. You will find more information about the use of user data by Google Analytics in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de

Order data processing by Google

We have concluded an order data processing contract with Google and fully implement the strict requirements of the UK and EU data protection authorities when using Google Analytics.

Demographics feature with Google Analytics

This website uses the "Demographics" feature of Google Analytics. This enables reports to be created that contain information about the age, gender, and interests of visitors to the website.

This data comes from interest-based advertisement by Google and user data from third-party providers. This data cannot be matched with a specific person. You can deactivate this function at any time via the display settings in your Google account, or generally prohibit the collection of your data by Google Analytics as described in the "objection to data collection by Google" section above.

Inclusion of services and content of third parties

If we include content from third parties, e.g. YouTube videos or content from other websites on our website, the ability to consume this content via our website requires that your IP address be sent to the providers of this content (third-party providers). Otherwise, this content cannot be sent to your browser. Your IP address is therefore required to display this content. We endeavour to only use such content when the respective providers will only use the IP address to send the embedded content. If a third-party provider stores your IP address for other purposes, e.g. for statistical purposes, we have no influence on this and cannot give you any information in this respect due to a lack of knowledge.

Infrastructure Subprocessors

We currently use Google Cloud to host customer data. This data is stored in St. Ghislain, Belgium.

Facebook social plugins

Our website uses social plugins ("plugins") from the social network facebook.com, which is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Facebook"). A list of Facebook social plugins and what they look like can be viewed here:

https://developers.facebook.com/docs/plugins/.

If you display a function of our website that contains such a plugin, your device will establish a direct connection to the Facebook servers. The content of the plugin will be sent by Facebook directly to the device of the user, which will include it on the website. User profiles of the users can thus be created using the processed data. We have no influence over the extent of the data that Facebook collects with using this plugin, and we can therefore only inform you based on our level of knowledge.

The inclusion of the plugin enables Facebook to receive the information that a user has accessed a corresponding page of our website. If you are logged into Facebook when doing so, Facebook can match the visit to your Facebook account. If you interact with the plugins, e.g. click the "Like" button or write a comment, the corresponding information will be sent from your device directly to Facebook, where it will be stored. If you are not a member of Facebook, there is still the possibility that Facebook will find out your IP address and store it. According to Facebook, only an anonymised IP address will be stored in Germany.

The scope and purpose of the data collection and further processing and use of data by Facebook, and the corresponding rights and possible settings to protect privacy, can be found in Facebook's data policy at https://www.facebook.com/about/privacy.

If you are a member of Facebook and do not want Facebook to collect data about you via our website and link it to your user data stored on Facebook, you must unregister from/log out of Facebook and delete your cookies before using our webpages.

Additional settings and objections to the use of data for advertising purposes can be found within the Facebook profile settings at https://www.facebook.com/settings?tab-ads, or via the US site http://www.aboutads.info/choices or the EU site http://www.youronlinechoices.com. The settings are independent of the platform: In other words, they are adopted for all devices, such as desktop computers and mobile devices.

Use of Twitter buttons

Our website uses buttons for the service Twitter, Twitter Inc., One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, which can be recognised by the stylised bird. With the aid of this button, it is possible to share a post or a page on our website on Twitter or follow us on Twitter.

If you access a page on our website that contains such a button, your browser will establish a direct connection with the Twitter servers. The content of the Twitter buttons will be sent by Twitter directly to your browser. We have no influence over the scope of the data that Twitter collects with the aid of this plugin and we provide information based on our level of knowledge. Accordingly, only your IP address and the URL of the respective website is shared when using the button, and they are not used for purposes other than to display the button.

You will find further information in Twitter's privacy policy at http://twitter.com/privacy.

Sentry and Error Handling

Vaultoro makes use of Sentry for error logging and alerting.

You will find further information in Sentry's privacy policy at https://sentry.io/privacy/.

Usersnap and Support

Vaultoro makes use of Usersnap for customer bug reporting.

You will find further information in Usersnap privacy policy at https://usersnap.com/privacy-policy.

How does Vaultoro protect my data?

gold-line

Vaultoro takes the protection of your personal data very seriously. We treat your personal details confidentially and in accordance with the statutory data protection regulations and with this data privacy statement. We believe security & privacy should come first.

Data protection and email communication notice

The transfer of information via the internet is not completely secure, so the security of the data sent via the internet to our web server cannot be guaranteed 100%. We store your personal data so that it is not accessible to third parties by taking all necessary technical and organisational measures. In particular, data is encoded and sent encrypted via "SSL" (Secure Sockets Layer). You will notice an encrypted transmission when the address line of the browser changes from http:// to https:// and there is a lock symbol in the browser line. If SSL encryption is activated, the data you send to us using the contact form, for example, cannot be seen by third parties.

When communicating via email, complete data security cannot be guaranteed, so we recommend sending confidential information by post.

How long does Vaultoro hold my information?

The data can be stored by Vaultoro for the duration of the business relationship and for up to five years after termination, according to the recommended retention periods of the Anti Money Laundering Regulations.

Is any information transmitted outside of the EU?

Some of the third party services used by Vaultoro may sit in the USA, in that case Vaultoro may transmit data to only after ensuring that the recipient of the data guarantees an appropriate level of data protection. When transmitting to the USA, Vaultoro will obligate the recipient to observe and comply with the principles of the Privacy Shield and also the GDPR.

What about Cookies?

gold-line

Most websites use so-called "cookies". Cookies do not cause any damage to your computer and they do not contain any viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are deposited on your computer and stored by your browser.

Most of the cookies we use are called "session cookies". They are automatically deleted after the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognise your browser next time you visit.

You can set your browser so that you are informed about the use of cookies and only allow cookies on a case-by-case basis, only accept cookies for certain cases or generally exclude them, and activate the automatic deletion of cookies upon closing the browser. If you deactivate cookies, the functionality of this website may be limited.

In some browsers you can set up rules to manage cookies on a site-by-site basis, giving you more fine-grained control over your privacy. What this means is that you can disallow cookies from all sites except those that you trust.

Browser manufacturers provide help pages relating to cookie management in their products. Please see below for more information.

For other browsers, please consult the documentation that your browser manufacturer provides.

You may opt-out of third party cookies from Google Analytics on its website. You can find comprehensive information about cookies at aboutcookies.org.

Changes to the privacy policy

gold-line

We reserve the right to change our privacy policy in order to adapt it to the changes in the legal situation or in the event of changes to the service or data processing system. However, this only applies with regards to statements about data processing. If your consent is necessary or parts of the privacy policy contain regulations from the contractual relationship with you, changes will only be made with your consent.

We ask that you regularly keep yourself informed about the content of our privacy policy.