YouHodler

YHIT Privacy Notice for Clients pursuant to Articles 13-14 GDPR

The contractual documentation, comprising the Terms of Service and the applicable Disclosures, is published on the Website and is available to the Client before and during use of the Services. This Notice must be read together with the Terms of Service and the other applicable Disclosures; in the event of any conflict regarding the protection of personal data, the provisions of this Notice shall prevail. The information published on the Website’s pages is, by contrast, merely descriptive in nature and does not replace what is set out in this Notice and in the Terms of Service.

For notices concerning specific processing activities (such as the website privacy policy and/or the cookie policy), please refer to the relevant notices.

YouHodler Italy S.r.l. (hereinafter, “YouHodler”, the “Company”, “we” or “our”) is committed to protecting your privacy. We have prepared this privacy notice (hereinafter, this “Notice”) to explain to clients how we collect, use and disclose the personal information of individuals who have and/or wish to open an account with YouHodler, accessing through the website or application.

This Notice describes the manner and purposes of the processing of personal data carried out by YouHodler and is drawn up pursuant to Regulation (EU) 2016/679 (hereinafter, the “GDPR”). This Notice also takes into account, where applicable, Regulation (EU) 2023/1114 (hereinafter, “MiCAR”), with particular reference to the information transparency obligations relating to the provision of crypto-asset services.

Any material changes to this Notice or to the processing of personal data will be communicated to data subjects by appropriate means and in compliance with Articles 13 and 14 of the GDPR.

1. DATA CONTROLLER AND DPO

The Data Controller is:

YouHodler Italy S.r.l., Tax Code/VAT No. 12481390966
Registered office: Via del Commercio 32 - 00154 - Rome (RM), Italy
PEC (certified e-mail): [email protected], E-mail [email protected]

The Data Controller has appointed a Data Protection Officer (“DPO”), who can be contacted at the e-mail address [email protected].

2. PURPOSES AND LEGAL BASIS OF PROCESSING

Users’ personal data are processed for the following purposes:

2.1 Provision of the Services and Management of the Contractual Relationship

Personal data are processed in order to enable the User’s registration, the opening and management of the account, access to the Restricted Area, the use of the Services relating to crypto-assets, the execution of transactions and operations, as well as the handling of customer support (including through chatbots based on artificial intelligence systems), of any complaints, and of the contractual relationships connected with the services offered through the Platform.

The Data Controller provides users with a support service through a chatbot based on artificial intelligence systems. The data and information entered by the user during the interaction are processed in order to provide support and respond to the requests made. The user is informed, before or at the time of the interaction, that they are interacting with an artificial intelligence system. Users are advised not to enter information that is not necessary for their support request.

Legal basis: performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR).

2.2 Compliance with Regulatory Obligations, AML/KYC and Fraud Prevention

Personal data are processed in order to comply with the obligations set out in applicable law, including obligations relating to anti-money laundering (“AML”), countering the financing of terrorism (“CTF”), customer due diligence (“KYC”), transaction monitoring, sanctions and PEP screening, record-keeping and compliance with competent authorities. Such processing may include identity verification activities, anti-fraud checks, checks on the source of funds, and the use of providers specialising in blockchain analytics and compliance.

These obligations also include those set out under the “Travel Rule” (Regulation (EU) 2023/1113): as a crypto-asset service provider, the Company is required to transmit and receive — together with crypto-asset transfers — the identification data of the originator and the beneficiary (for example: name, crypto-asset wallet/account address and, where required by law, address, identity document details, date and place of birth). Such data is transmitted to the counterparty’s crypto-asset service provider (CASP) or payment service provider (PSP) involved in the transfer, even if established in a third country, for the purposes of preventing money laundering and terrorist financing

Legal basis: compliance with legal and regulatory obligations (Article 6(1)(c) GDPR).

The verification, analysis and monitoring activities carried out for the purposes of complying with regulatory obligations, including obligations relating to AML, CTF, KYC, fraud prevention and sanctions screening, are not based on the data subject’s consent, but on compliance with legal obligations and, where applicable, on the need to perform the contractual relationship. Automated risk analysis and detection tools may be used for this purpose, including artificial intelligence systems made available by external providers, which generate alerts that are subsequently assessed, where necessary, by authorised personnel

For the purposes of carrying out compliance and verification activities, certain personal data may also be obtained from public sources, official registers, publicly accessible databases, and providers specialising in identity verification services, fraud prevention, blockchain analytics and AML/CTF screening.

2.3 Platform Security, Monitoring of Operational Risks, Service Continuity and Prevention of Abuse

Personal data may be processed to ensure the security of the Platform, prevent unauthorised access, detect fraudulent or abusive use of the Services, manage security incidents, carry out technical checks and protect the integrity of IT systems.

Legal basis: the Data Controller’s legitimate interest in system security and fraud prevention (Article 6(1)(f) GDPR).

2.4 Improvement of Services and Platform Development

Personal data may be used to analyse how the Platform is used, improve the user experience, develop new features, carry out aggregate statistical analyses, monitor operational performance and ensure the proper functioning of the services offered through the Platform.

Legal basis: the Data Controller’s legitimate interest in the improvement and development of the Services (Article 6(1)(f) GDPR).

The provision of personal data for the purposes referred to in paragraphs 2.1, 2.2, 2.3 and 2.4 is necessary for the establishment and performance of the contractual relationship, as well as for compliance with applicable regulatory obligations and/or for the Data Controller’s legitimate interest. Failure to provide the data may make it impossible to activate or continue the contractual relationship and to provide the services offered through the Platform.

2.5 Direct Marketing and Promotional Communications

Subject to the User’s consent, personal data may be processed to send newsletters, commercial communications, service updates, promotional initiatives, events, market research and other marketing activities relating to the services offered through the Platform.

Consent to direct marketing also covers the Data Controller’s possible use of tracking pixels in marketing e-mails, without prejudice to the right to revoke consent, including on a granular basis, exercisable at any time

Legal basis: the data subject’s consent (Article 6(1)(a) GDPR).

2.6 Profiling and Personalisation of Commercial Communications

Subject to the User’s consent, personal data may be processed to analyse preferences, interests, patterns of use of the Platform and interactions with the services offered through the Platform, in order to personalise commercial communications, content and offers relating to the crypto-asset Services.

Legal basis: the data subject’s consent (Article 6(1)(a) GDPR).

The provision of personal data for the purposes referred to in paragraphs 2.5 and 2.6 is optional. Failure to give consent, or its subsequent withdrawal, does not affect the possibility of using the services offered through the Platform or the validity of the contractual relationship. The data subject may withdraw consent at any time, without prejudice to the lawfulness of the processing carried out before the withdrawal.

Even in the absence of consent, but without prejudice to the right to object, which may be exercised at any time, the Company may process personal data to offer, by e-mail, products or services similar to those previously used or purchased (so-called soft spam, pursuant to Article 130(4) of Legislative Decree 196/2003). Legal basis: legitimate interest (Article 6(1)(f) GDPR).

In any case, the Company may process data to protect the Data Controller’s rights in judicial or out-of-court proceedings, as a legitimate interest (Article 6(1)(f) GDPR).

2.7 Interactions via Social Media and Messaging Services

The Company may be present on social media platforms and may make communication channels available to Users through messaging services, including WhatsApp, to enable interaction with the Company, provide information on the Services and, where applicable, handle support or contact requests.

When the User interacts with the Company’s official social media profiles or contacts the Company through messaging services, the identification and contact data associated with the relevant account or profile may be processed, as well as the information and content voluntarily communicated by the User.

Such data is processed to manage and respond to the User’s requests and, depending on the content of the communication, for the performance of the contractual relationship or pre-contractual measures, pursuant to Article 6(1)(b) GDPR, or on the basis of the Company’s legitimate interest in managing its communications and relationships with users, pursuant to Article 6(1)(f) GDPR.

The use of social media platforms and messaging services also involves the processing of personal data by the respective providers, in the manner and for the purposes indicated in their respective privacy notices. Such providers may act, in respect of the processing activities they independently determine, as autonomous data controllers.

Users are advised not to transmit, through social media or messaging services, information that is not necessary for the request made and, in particular, identity documents, access credentials, wallet information, private keys or other confidential information. For communications requiring the transmission of such information, only the secure channels indicated by the Company must be used.

Any use of data collected through social media or messaging services for direct marketing purposes will take place solely where the conditions required by applicable law are met and, where necessary, subject to the data subject’s prior consent. The User may also voluntarily choose to follow the Company’s social profiles or pages, or to join groups or channels managed by the Company, in order to receive updates and information. In such cases, interaction with the User will take place according to the features and methods specific to the platform used, without prejudice to the User’s ability to stop the interaction at any time, by unfollowing the profile or page, leaving the group or channel, or using the other tools made available by the relevant platform.

3. CATEGORIES OF PERSONAL DATA PROCESSED

3.1 Identification and Contact Data

The User’s personal and identification data, including first name, surname, date of birth, nationality, country of residence, address of residence or domicile, e-mail address, telephone number, username, account identifiers and other information provided during registration or use of the Platform, or in a support ticket.

3.2 KYC/AML Data and Verification Data

Data collected for the purposes of customer due diligence (“KYC”), the prevention of money laundering (“AML”) and terrorist financing (“CTF”), including identity documents, images of the document, selfies, video identification, verification of the correspondence between the face and the photograph on the document for the purposes of the data subject’s unique identification in the cases permitted by applicable law, proof of address, information on the source of funds and wealth, data relating to politically exposed person (“PEP”) status, sanctions screening, anti-fraud information and further data required by applicable law or by internal compliance procedures, in compliance with the principle of data minimisation.

3.3 Financial, Wallet and Transactional Data

Data relating to the Services used and the transactions carried out through the Platform, including wallet addresses, public blockchain addresses, balances, transaction history, transactions carried out, data relating to deposits and withdrawals, data relating to fiat currency accounts, payment data, IBAN, bank details, information on the payment methods used, and further information necessary for carrying out transactions and managing the services offered through the Platform.

3.4 Technical, Usage and Browsing Data

Data collected automatically during use of the Platform through the website or Application, including IP address, access logs, device identifiers, browser and operating system information, session data, cookies and similar technologies, browsing data, interactions with the Platform, analytics data, performance information, and data relating to the security and proper functioning of the services offered through the Platform.

3.5 Data Relating to Customer Support and Communications

Data contained in communications exchanged with the Company by e-mail, support ticket, chat, social media, telephone or other official channels, including the content of requests, records of interactions, and information necessary for handling support requests, complaints or disputes.

3.6 Data Collected from Third Parties

Data received from KYC/AML service providers, payment and e-money institution (IMEL) providers, technology partners, blockchain analytics providers, public databases, sanctions registers, PEP lists and other authorised sources, within the limits permitted by applicable law.

3.7 Tracking Pixels

Consistently with the Guidelines on the use of tracking pixels in electronic mail communications issued by the Italian Data Protection Authority (Garante) on 17 April 2026, the following is specified.

Depending on their configuration, such technologies may make it possible to detect information relating to the receipt or opening of the communication, such as the date and time of the interaction and certain technical information associated with the device or connection used. The Data Controller may use tracking pixels in e-mail communications where — in line with Article 122 of the Italian Data Protection Code — this is necessary to ensure the service, irrespective of the data subject’s consent. This may occur: 1) in the case of security measures relating to the user’s authentication process, its completion or its update (e.g., confirmation of account activation, handling of a password-change request, etc.); 2) in the case of non-promotional or non-commercial messages that the Data Controller has a legal obligation to send and in respect of which it needs to establish that the recipient has actually become aware of them (e.g., useful information on how to prevent phishing or fraud in relation to contingent threats; communications relating to contractual changes or to logistical/organisational matters concerning scheduled events, terms of service, or notices on the processing of data subjects’ personal data; notifications relating to security incidents; institutional information campaigns, as well as reminders of contractual or payment deadlines and obligations); 3) whenever the use of tracking pixels is functional to carrying out a statistical count measuring the overall message opening rate, through the use of anonymisation techniques, so as not to allow personalised measurements.

In the case of tracking pixels contained in promotional e-mails, these will only be sent if the user has given consent to direct marketing; the user may subsequently withdraw their previous choices, including on a granular basis, either by withdrawing the single consent given, with the effect of preventing the future receipt of further messages, or by withdrawing it only partially, solely with regard to the tracking associated with the receipt of tracking pixels.

4. METHODS OF DATA COLLECTION AND PROCESSING

Personal data are collected and processed in a manner consistent with the principles of lawfulness, fairness, transparency, minimisation and integrity set out in the GDPR.

4.1 Methods of Data Collection

Personal data are collected:

  • directly from the User, through registration, use of the services offered through the Platform, or communications with the Company;
  • automatically, through the use of the Platform, including logging tools, cookies and technical monitoring systems;
  • through third parties, including KYC/AML service providers, payment providers, blockchain analytics infrastructure, and other technology partners involved in providing the services offered through the Platform.

Certain data relating to transactions carried out on public blockchains may be immutable due to the inherent characteristics of DLT technology; this circumstance may affect the exercise of certain rights under the GDPR, it being understood that the Data Controller processes only the data necessary and adopts appropriate measures to minimise the association between the user’s identity and blockchain addresses.

4.2 Recipients of Personal Data

Personal data may be disclosed to third parties within the limits of the purposes indicated above, including:

  • IT service providers, cloud and hosting infrastructure providers, cybersecurity companies;
  • KYC/AML, anti-fraud and blockchain analytics service providers;
  • payment institutions, financial intermediaries, e-money institutions (IMEL);
  • communication and customer support service providers;
  • legal, tax and professional advisors, auditors;
  • other crypto-asset service providers (CASPs) and payment service providers (PSPs) involved in the execution of crypto-asset transfers, pursuant to Regulation (EU) 2023/1113 (the “Travel Rule”);
  • public authorities and supervisory bodies, in the cases provided for by law.

The parties indicated above act, depending on the case, as data processors pursuant to Article 28 GDPR or as autonomous data controllers. A list of data processors may be requested from the Company at any time.

4.3 Data Security and Technical and Organisational Measures

The Data Controller adopts technical and organisational measures appropriate under Article 32 GDPR, in order to ensure a level of security appropriate to the risk, taking into account the technological nature of the crypto-asset Services and the risks connected with the use of digital infrastructure and DLT systems.

The measures adopted are designed to prevent the loss of personal data, unauthorised access, improper disclosure, and unauthorised alteration or destruction thereof.

The processing of data may take place using electronic tools and, in limited cases, also using paper records.

The Data Controller adopts technical and organisational measures consistent with the applicable regulatory framework, including, where applicable, the measures set out in Regulation (EU) 2022/2554 (DORA) on digital operational resilience.

5. TRANSFERS OF DATA TO THIRD COUNTRIES

Personal data may be transferred outside the European Economic Area.

Such transfers take place in compliance with Article 44 et seq. of the GDPR and on the basis of one of the following appropriate safeguards:

  • adequacy decisions adopted by the European Commission;
  • organisations certified under the EU-US Data Privacy Framework;
  • standard contractual clauses (SCCs) approved by the European Commission, accompanied, where necessary, by a transfer impact assessment (TIA) and by any supplementary measures;

Where necessary in relation to the specific transfer, the Data Controller adopts additional technical, organisational and contractual measures designed to ensure a level of protection for personal data substantially equivalent to that guaranteed within the European Union.

The data subject may obtain a copy of the safeguards adopted for the transfer of personal data by writing to the contact details indicated in this Notice.

6. DATA RETENTION PERIOD

Personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the storage limitation principles set out in Article 5(1)(e) of the GDPR.

In particular:

  • data processed for contractual purposes are retained for the entire duration of the contractual relationship and, subsequently, for the period necessary to comply with applicable statutory obligations, including civil, tax and regulatory obligations, and in any case for a period not exceeding 10 years from the termination of the relationship;
  • data contained in support tickets, support requests and complaints are retained for the time necessary to handle the request and, where relevant for the performance of the contract, the protection of the Data Controller’s rights, or compliance with legal obligations, for up to 10 years from the closure of the contractual relationship;
  • data processed for the purposes of complying with regulatory obligations, including those relating to anti-money laundering and the prevention of terrorist financing, are retained for the period provided for by applicable law and, in any case, for no longer than 10 years from the termination of the contractual relationship, without prejudice to further retention obligations provided for by law or to the need for protection in judicial proceedings. It is specified that data processed for the purposes of the “Travel Rule” (Regulation (EU) 2023/1113) are retained for 5 years from the execution of the transfer, pursuant to Article 26 of that Regulation;
  • data processed for marketing purposes are retained until consent is withdrawn and, in any case, for a period not exceeding 24 months from the collection of consent;
  • data processed for commercial profiling purposes are retained for a period not exceeding 12 months from the collection of consent, unless consent is withdrawn earlier.

At the end of the respective retention periods, personal data are deleted, anonymised or rendered irreversibly non-identifiable.

Personal data are stored on servers located within the European Economic Area, without prejudice to any transfers to third countries carried out in compliance with applicable law and the safeguards referred to in Article 5 of this Notice.

7. RIGHTS OF THE DATA SUBJECT

The data subject may exercise, within the limits and under the conditions set out in Articles 15-22 of the GDPR, the following rights:

  • the right of access to personal data and to information relating to the processing;
  • the right to rectification of inaccurate data and completion of incomplete data;
  • the right to erasure of personal data in the cases provided for by Article 17 GDPR;
  • the right to restriction of processing in the cases provided for by Article 18 GDPR;
  • the right to data portability, in the cases provided for by Article 20 GDPR, in a structured, commonly used and machine-readable format;
  • the right to object to processing in the cases provided for by Article 21 GDPR;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent given before its withdrawal;
  • the right not to be subject to a decision based solely on automated processing, including profiling, in the cases provided for by Article 22 GDPR;
  • the right to lodge a complaint with the Italian Data Protection Authority (Garante) pursuant to Article 77 GDPR.

The exercise of these rights may be limited in the cases provided for by applicable law, including retention or processing obligations arising from anti-money laundering legislation and other statutory obligations. Data subjects may exercise their rights by writing to: [email protected].

The Data Controller will respond to data subjects’ requests without undue delay and, in any event, within one month of receipt of the request, which period may be extended in the cases provided for by Article 12 GDPR.

Last Update 19, August 2026