1. Introduction
At Mycrytos, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how Mycrytos.site ("Mycrytos," "we," "us," or "our") collects, uses, shares, and protects information when you use our website, mobile applications, and services (collectively, the "Services").
This policy applies to all users worldwide and complies with global privacy laws including GDPR (EU), CCPA/CPRA (California), LGPD (Brazil), and PIPEDA (Canada). By using our Services, you consent to the practices described herein. We process data responsibly, with transparency and user control as core principles.
Key Commitments:
- GDPR compliance with Data Protection Officer oversight
 - CCPA "Do Not Sell My Personal Information" rights
 - End-to-end encryption for sensitive crypto data
 - Zero-knowledge proofs for wallet verification
 - Regular security audits by third-party firms
 
2. Information We Collect
We collect information to provide, improve, and secure our Services. Below is a comprehensive breakdown:
2.1 Personal Information
| Type | Examples | Purpose | Legal Basis | 
|---|---|---|---|
| Account Data | Email, username, password hash | Account creation, authentication | Contract performance | 
| KYC Data | ID documents, selfies, address proof | Regulatory compliance, AML | Legal obligation | 
| Payment Data | Card details (tokenized), crypto addresses | Transaction processing | Contract performance | 
| Communication Data | Support tickets, chat logs | Customer service | Legitimate interest | 
2.2 Usage & Technical Data
Automatically collected when you use our Services:
- Device Information: IP address, browser type, OS version, screen resolution
 - Usage Data: Pages visited, time spent, click patterns, search queries
 - Crypto Data: Wallet addresses, transaction hashes, balance snapshots
 - Location Data: Approximate geolocation (city level) for compliance
 
2.3 Marketing & Analytics Data
- Newsletter subscriptions, webinar attendance
 - Google Analytics, Hotjar heatmaps, Mixpanel events
 - Social media interactions (likes, shares)
 
3. How We Collect Information
We use multiple methods to gather data ethically and transparently:
3.1 Direct Collection
- Forms: Registration, KYC uploads, contact forms
 - Transactions: Crypto deposits/withdrawals, fiat purchases
 - Support: Email tickets, live chat transcripts
 
3.2 Automatic Collection
- Cookies: Session management, preferences
 - Analytics: Google Analytics, server logs
 - Blockchain: Public transaction data, wallet interactions
 
3.3 Third-Party Sources
| Source | Data Type | Purpose | 
|---|---|---|
| KYC Providers (Jumio) | ID verification results | AML compliance | 
| Payment Processors | Transaction confirmations | Fraud prevention | 
| Social Media | Login credentials | Single sign-on | 
4. How We Use Your Information
Your data powers essential Services while respecting privacy:
4.1 Core Services
- Account management and authentication
 - Transaction processing and wallet functionality
 - KYC/AML compliance and regulatory reporting
 - Customer support and issue resolution
 
4.2 Service Improvement
- Analytics for UX optimization
 - Personalized recommendations (crypto alerts)
 - Bug detection and performance monitoring
 
4.3 Marketing (Opt-in)
- Newsletter delivery (unsubscribe anytime)
 - Webinar invitations
 - Targeted ads (with consent)
 
4.4 Legal & Security
- Fraud detection and prevention
 - Law enforcement cooperation
 - Security incident response
 
7. Data Security & Storage
Your data is protected with enterprise-grade measures:
- Encryption: AES-256 at rest, TLS 1.3 in transit
 - Access: Role-based controls, 2FA mandatory
 - Storage: EU/US data centers (AWS, compliant)
 - Audits: Quarterly penetration tests, annual SOC 2
 - Retention: KYC data 7 years, usage 2 years
 
8. Your Privacy Rights
| Right | Description | How to Exercise | 
|---|---|---|
| Access | View your data | Account dashboard | 
| Rectification | Correct inaccuracies | Profile settings | 
| Deletion | Remove data | privacy@mycrytos.site | 
| Portability | Export data | Download request | 
| Objection | Stop processing | Opt-out form | 
9. Children's Privacy
Our Services are not directed to children under 16. We do not knowingly collect data from minors. Parents can request deletion at privacy@mycrytos.site.
10. International Data Transfers
Data may transfer to US/EU. We use Standard Contractual Clauses and adequacy decisions for GDPR compliance. EU users: Data Protection Officer at dpo@mycrytos.site.
11. Changes to This Policy
We may update this policy. Material changes will be notified via email and website banner. Continued use constitutes acceptance.
12. Contact Information
Email: privacy@mycrytos.site
Phone: +1 (809) 377-0077
Address: Mycrytos Inc., 123 Crypto St, Miami, FL 33101, USA
EU DPO: dpo@mycrytos.site