In short
- We collect what the law requires to verify your identity, plus what we need to run your account.
- We never sell your data. Analytics and marketing cookies are off until you opt in.
- You can access, correct, export or delete your data at any time — within the limits of our legal retention duties.
1.Data controller
The controller of your personal data is Coin District, [Legal form], registered under [RCS number], whose registered office is at [Registered office address].
Coin District has appointed a Data Protection Officer (DPO), who can be reached at [DPO email address].
2.Data we collect
Identity
Name, date and place of birth, nationality, ID document, selfie for liveness check.
Contact
Email address, phone number, postal address, communication preferences.
Financial
Qualification answers, source of funds, bank details, transactions and holdings.
Technical
Wallet addresses, IP address, device and browser data, login history, cookies.
3.Purposes and legal bases
We only process your data for specific purposes, each based on one of the legal grounds provided by the GDPR.
| Purpose | Legal basis | Retention |
|---|---|---|
| Opening and managing your account | Performance of the contract | Duration of the relationship + 5 years |
| Identity checks, anti-money laundering | Legal obligation | 5 years after account closure |
| Investor qualification | Legal obligation | Duration of the relationship + 5 years |
| Executing investments and trades | Performance of the contract | 10 years (accounting records) |
| Security and fraud prevention | Legitimate interest | 12 months (logs) |
| Newsletter and product news | Consent | Until you unsubscribe |
| CDNT airdrop and referral program (email, wallet address, Zealy username, points, referral link) | Performance of the contract | [Retention period] |
| Audience measurement | Consent | 13 months |
4.Who receives your data
Your data is accessible only to authorized Coin District staff, and to the following categories of recipients, strictly for the purposes above:
- our identity verification provider [KYC provider name];
- our payment service provider and custodian;
- Issuers in which you invest, limited to what is needed to register you as a shareholder;
- founders of companies listed on the Fundraising Board, when you choose to contact them (your name, email, investor profile and message);
- our hosting and IT service providers, bound by data processing agreements;
- public authorities, where required by law.
5.International transfers
Your data is stored within the European Economic Area. If a provider processes data outside it, the transfer is covered by an adequacy decision of the European Commission or by the Commission’s standard contractual clauses, together with additional safeguards where necessary.
6.How long we keep your data
We keep your data only as long as necessary for each purpose (see the table in section 3). At the end of these periods, data is deleted or irreversibly anonymized. Data we must keep for legal reasons is archived with restricted access.
7.Data recorded on a blockchain
Token transactions are recorded on a blockchain. We never write your name or identity documents on-chain: only wallet addresses and token movements are recorded, and the link between an address and your identity is kept off-chain, in our systems.
Because blockchain records cannot be modified, on-chain transaction data cannot be erased. When you exercise your right to erasure, we delete the off-chain link between your identity and your wallet addresses.
8.Your rights
Under the GDPR, you have the following rights. We answer within one month of receiving your request.
Access
Get a copy of your data.
Rectification
Correct inaccurate data.
Erasure
Ask us to delete your data.
Restriction
Limit how we use your data.
Portability
Receive your data in a reusable format.
Objection
Object to processing based on our legitimate interest or to direct marketing.
Where processing is based on your consent, you can withdraw it at any time — for cookies, from the cookie preferences; for emails, from your profile or the link in each email.
9.Security
We protect your data with encryption in transit and at rest, two-factor authentication, strict access controls and regular security audits. If a data breach is likely to put your rights at risk, we will inform you and the competent authority without undue delay.
10.Contact our DPO
To exercise your rights, write to [DPO email address] or by post to Data Protection Officer, Coin District, [Registered office address]. We may ask for proof of identity.
If you believe your rights have not been respected, you can lodge a complaint with the CNIL, the French data protection authority, or with the supervisory authority of your country of residence.
Questions about this document?
Our team answers within 1 business day.