Last updated: 30 June 2026
Personal Data Processing Notice
1 Introduction
1.1 This Notice describes how WHITE TECH d.o.o., OIB: 22301840862, MBS: 060486036, Petrinjska ulica 6, 10000 Zagreb, Republic of Croatia, as the Controller, processes the personal data of visitors and users of the Website and users of the Platform.
1.2 In operating the Website and providing the Services through the Platform, the Controller processes personal data solely in the manner set out in this Notice.
1.3 We reserve the right to update this Notice from time to time. The version of the Notice in force at the time of use applies to each use of the Website. The date of the last update is stated at the beginning of the Notice.
1.4 The governing language of this Notice is Croatian.
2 Definitions
2.1 In addition to the terms defined in the Controller's General Terms and Conditions and in the Applicable Regulations, which apply mutatis mutandis to this Notice, the following terms apply for the purposes of this Notice:
2.1.1 "Notice" means this personal data processing notice.
2.1.2 "Platform" means the web application and associated technological infrastructure, accessible via the Website, through which the Controller provides crypto-asset related services.
2.1.3 "Controller" means WHITE TECH d.o.o., OIB: 22301840862, MBS: 060486036, Petrinjska ulica 6, 10000 Zagreb, Republic of Croatia.
2.1.4 "Account (or Whitely Account)" has the meaning given to it in the Controller's General Terms and Conditions, namely a virtual interface within the Platform available to the website user following successful registration and verification, through which the website user (as defined in the Website Terms of Use) accesses the Services, views balances, initiates or monitors Transactions, and manages operational settings.
2.1.5 "KYC/KYB Verification" has the meaning given to it in the Controller's General Terms and Conditions, namely the customer due diligence (Know Your Customer) or business due diligence (Know Your Business) procedure carried out by the Company to verify the identity, ownership structure and eligibility of the User of Services prior to granting access to, or continued use of, the Services.
2.1.6 "Services" has the meaning given to it in the Controller's General Terms and Conditions, namely the services provided by the Controller.
2.1.7 "User of Services" has the meaning given to it in the Controller's General Terms and Conditions: a Retail Customer and/or a Business User.
2.1.8 "Authorised User" has the meaning given to it in the Controller's General Terms and Conditions, namely an individual granted access to the Account who is not the customer but a user acting on behalf of a Business User.
2.1.9 "Website" means the Controller's website – https://whitely.hr/ – through which the Services are made available.
2.1.10 "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
2.1.11 "Applicable Regulations" means the GDPR and all other applicable data protection and privacy regulations governing the processing of personal data within these Services, including the Act on the Implementation of the General Data Protection Regulation (OG 42/2018), the regulations on privacy in electronic communications, and all amendments, supplements and regulations adopted thereunder.
3 Who this Notice applies to
3.1 This Notice applies to:
3.1.1 visitors and users of the Website;
3.1.2 Users of Services;
3.1.3 Authorised Users;
3.1.4 persons whose personal data are processed in the KYC/KYB verification procedure.
4 Collection of personal data
4.1 Personal data processed through the Website and the Platform are collected through the following channels:
4.1.1 Registration and opening of an Account: personal data entered when creating an account and during KYC/KYB verification;
4.1.2 Use of the Services and execution of transactions: data generated by use of the Platform;
4.1.3 Contact form on the website: data you enter when contacting us through forms on the Website;
4.1.4 Communication: data from enquiries and other correspondence;
4.1.5 Data collected through cookies and similar technologies;
4.1.6 Third-party sources – data obtained from KYC/AML check providers, public registers and sanctions lists, and other reliable sources.
5 What data we process and for what purposes
5.1 In operating the Website and providing the Services through the Platform, the Controller processes the following categories of personal data for the purposes set out below:
| Purpose of processing | Category of personal data |
|---|---|
| Identification data and contact data | First and last name, date of birth, nationality, country of residence, address, email, telephone number, OIB / tax number |
| Identity verification data (Know Your Customer – KYC) | Data and documents collected in the procedure for verifying the identity of users and business entities; the full list of such data is set out in Annex 1. |
| Financial data | Bank account number, payment card data, tax residency data, source of funds data |
| Transaction data | Amount, currency, date and time, payment method, sender and recipient data, crypto-wallet addresses and related publicly available on-chain data |
| Account data and settings | Username, password (in encrypted form), settings and preferences |
| Communication | Content of enquiries, support messages, call recordings, survey responses |
| Data collected automatically | Device and browser data, device identifiers, IP address, location derived from IP address, language settings, usage logs (log files), and data collected through cookies and similar technologies |
| Data from third-party sources | Data obtained from KYC/AML check providers, public and official registers, sanctions lists and lists of politically exposed persons, blockchain-analytics providers, and financial institutions and business partners |
6 Limitation of the scope of processing
6.1 When processing personal data that you provide on your own initiative (for example in the content of a message, enquiry or other correspondence), we cannot influence the scope and content of the data you choose to include.
6.2 Notwithstanding this, we limit our processing solely to data and information relevant to establishing, performing and maintaining the business relationship and to fulfilling our legal obligations.
6.3 Data not relevant to those purposes are not used and are deleted without undue delay, unless we are required to retain them by law.
7 Purposes of processing and legal bases
7.1 Each processing activity is based on one of the legal bases under the GDPR: performance of a contract, a legal obligation, our legitimate interest, or your consent. The precise basis for each purpose is set out below.
7.2 Performance of a contract
7.2.1 The following data are necessary to open an Account and provide the Services. Without them we cannot open or maintain an Account or provide the Services:
7.2.1.1 Identification data and contact data
7.2.1.2 Financial data
7.2.1.3 Transaction data, account data and settings
7.2.1.4 Communication
7.3 Compliance with legal obligations
7.3.1 As a crypto-asset service provider (CASP), we are subject to a range of regulations requiring us to collect and retain certain data. If you do not provide us with such data, we may not establish or maintain a business relationship with you.
7.3.1.1 Identity verification and customer due diligence (KYC/CDD) and anti-money-laundering / counter-terrorist-financing (AML/CFT)
Personal data are processed to fulfil legal obligations of identity verification, customer due diligence and ongoing monitoring of the business relationship, including screening against sanctions lists and determining politically-exposed-person (PEP) status, in accordance with the Act on the Prevention of Money Laundering and Terrorist Financing (OG 108/17, 39/19, 151/22), Articles 11, 15, 16, 20, 46 and 47, and the applicable crypto-asset market regulations.
7.3.1.2 Exchange of originator and beneficiary information in crypto-asset transfers (Travel Rule)
Personal data on the originator and beneficiary of a crypto-asset transfer (name, distributed-ledger address, crypto-asset account number, address, identification data) are processed and exchanged with other crypto-asset service providers involved in the transfer, in accordance with Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets (the Travel Rule Regulation).
7.3.1.3 Compliance with accounting and tax obligations
Personal data contained in business documentation are processed and retained to fulfil accounting and tax obligations in accordance with the Accounting Act (OG 78/15, 134/15, 120/16, 116/18, 42/20, 47/20, 114/22, 82/23, 150/23), Articles 7, 10 and 13, and the General Tax Act (OG 115/16, 106/18, 121/19, 32/20, 42/20, 114/22, 114/23), Article 66(18).
7.3.1.4 Acting on requests from competent authorities, regulators and courts
Personal data may be processed and provided to competent authorities (HANFA, the Anti-Money-Laundering Office, the Tax Administration, courts and others) on the basis of their requests or orders, in accordance with applicable law, including the Act on the Prevention of Money Laundering and Terrorist Financing.
7.3.1.5 Automatic exchange of tax information on crypto-assets (DAC8)
Clients' personal data (name, address, tax identification number, date and place of birth, transaction and amount data) are processed and reported to the Tax Administration for the automatic exchange of tax information with the competent authorities of other EU Member States, in accordance with Council Directive (EU) 2023/2226 of 17 October 2023 amending Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC8).
7.3.1.6 ICT system security, incident management and ICT incident reporting (DORA)
Personal data contained in ICT incident records, the ICT asset register and risk-management documentation are processed to establish and maintain an ICT risk-management framework, to detect and report major ICT incidents to the competent authority (HANFA), and to ensure digital operational resilience, in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA).
7.4 Our legitimate interest
7.4.1 We process certain data to pursue our legitimate interests, subject to a prior assessment that those interests do not override your rights and freedoms.
| Purpose | Legitimate interest | Categories of data |
|---|---|---|
| Platform security and fraud prevention | Protection of users, funds and system integrity | Device data, IP address, transaction data |
| Improvement and development of the Services, statistics | Understanding and improving the Services | Usage data, transaction data |
| Establishing, protecting and defending legal claims | Protection of our rights | Categories relevant to the specific matter |
7.5 Consent
7.5.1 At present, the Website and the Platform contain no processing for which consent is the legal basis. All processing we carry out is necessary to provide the Services, required by law, or based on our legitimate interests.
7.5.2 We will request consent only if and when we introduce processing that is neither necessary nor required – for example non-essential (analytics or marketing) cookies, marketing communications, or certain additional features you would explicitly activate.
7.5.3 In that case we will request your consent separately and explicitly, before such processing begins.
7.6 Protection of vital interests
7.6.1 Exceptionally, we may process data to protect the vital interests of you or another person (e.g. in emergencies or to prevent serious harm).
8 Identity verification
8.1 In the account-opening procedure, the identity of the person is verified. This is a "one-to-one" (1:1) procedure: the data and image on the identification document the person provides are compared with that person – i.e. with the photograph or video the person presents – to confirm that they are the person named in the document. The sole purpose is to confirm the match between the person and their document.
8.2 This verification must be distinguished from "one-to-many" (1:N) biometric identification, in which a person's biometric data are compared against a database of multiple persons to determine who the person is. We do not carry out such identification.
8.3 Identity verification is carried out to fulfil the legal obligation of customer verification and due diligence, in accordance with the Act on the Prevention of Money Laundering and Terrorist Financing (OG 108/17, 39/19, 151/22) and the Ordinance on Establishing and Verifying Customer Identity Remotely (OG 9/2024). A business relationship cannot be established without successfully completed identity verification.
8.4 Identity verification is carried out by Sumsub as a processor, with which a processing agreement has been concluded in accordance with Article 28 of the GDPR.
8.5 More on their website: https://sumsub.com/
8.6 Sumsub stores and processes personal data on servers within the EEA (Germany), so no transfer of data outside the EEA takes place.
9 Automated decision-making and profiling
9.1 During onboarding and throughout the business relationship, automated tools are used for identity verification, fraud prevention, and compliance with anti-money-laundering, counter-terrorist-financing and sanctions obligations. These tools include:
9.1.1 identity and document verification, including liveness checks and facial comparison (Sumsub);
9.1.2 screening against sanctions lists, lists of politically exposed persons, watchlists and adverse-media sources, with daily re-screening for the duration of the relationship (Sumsub);
9.1.3 transaction monitoring and the screening and risk assessment of crypto-wallet addresses (Chainalysis, Elliptic).
9.2 The automated tools compare data against reference documents, sanctions and other lists, and patterns of risky behaviour, and generate alerts and risk scores. These checks may lead to measures that produce legal effects or similarly significantly affect the person – for example refusal to establish a business relationship or blocking of a particular transaction.
9.3 Final substantive decisions are not made solely by automated processing. Each alert raised is reviewed by an authorised person within the AML/CFT function before a final decision is made. The automated tools support that decision; they do not replace it.
9.4 The legal basis for this processing is performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR).
10 Data from third-party sources
10.1 Where we do not collect personal data directly from the person but from third-party sources, we provide information about such processing through this Notice, which is publicly available on the Website.
10.2 Certain sources from which we obtain data are publicly available sources. This applies in particular to public and official registers, beneficial-ownership registers, sanctions lists and lists of politically exposed persons, and publicly available data recorded on blockchain networks.
10.3 In certain cases we do not carry out additional individual notification of the person regarding the processing of data obtained from third-party sources, namely where:
10.3.1 the collection or disclosure of data is expressly laid down by EU or Croatian law to which we are subject, and which provides appropriate safeguards for the data subject – including, in particular, obligations of customer verification and due diligence, transaction monitoring, sanctions-list screening, and data exchange in crypto-asset transfers (Travel Rule);
10.3.2 individual notification would render impossible or seriously impair the achievement of the purposes of processing, including the prevention of money laundering and terrorist financing, sanctions screening and fraud prevention;
10.3.3 individual notification would place us in conflict with the statutory prohibition on disclosure, under which we may not disclose to the customer or a third party that an analysis, data collection or report relating to the prevention of money laundering and terrorist financing is underway or has been carried out;
10.3.4 individual notification would prove impossible or would require disproportionate effort, in particular in relation to beneficial owners, close family members and close associates of politically exposed persons, and other parties involved in crypto-asset transfers.
11 Who we share data with
11.1 We develop, control and operationally manage the Platform through which we provide the Services independently, as the controller. We use the underlying software solutions under licence, and we obtain certain ICT services and infrastructure support from:
11.1.1 UAB Clear White Technologies (Lithuania, EEA) – licensor of the software solutions and provider of ICT services;
11.1.2 Clear White Technologies Limited (Hong Kong) – provider of ICT services and support.
11.2 To the extent that these providers access personal data processed on the Platform when providing their services, they act as our processors and we apply appropriate safeguards.
11.3 We do not sell your data.
11.4 We share it only with trusted processors, competent authorities and advisers, and only to the minimum extent necessary.
11.5 The manner in which each individual processor collects, processes, stores and uses personal data is governed by its own privacy policy.
| Category of recipient | Purpose of sharing |
|---|---|
| KYC/AML check and fraud-prevention providers | Identity verification, transaction monitoring, risk assessment (Sumsub) |
| IT infrastructure and storage providers (cloud) | Secure hosting and processing of data (see Cloudflare and the next point) |
| Payment service providers and financial institutions | Execution of transactions and payments |
| Customer support and communication-tool providers | Providing support and communicating with users |
| Professional advisers (lawyers, auditors) | Legal and business advice |
| Competent authorities, regulators and courts | Acting on legal obligations and requests |
11.6 We conclude processing agreements with all processors in accordance with Article 28 of the GDPR, binding them to confidentiality and appropriate safeguards.
11.7 In addition to Sumsub, which is used for KYC/KYB verification, identification and related AML checks, the following tools are also used for crypto-transaction monitoring:
11.7.1 Chainalysis: blockchain analytics, transaction monitoring, wallet-address screening, risk assessment and investigations relating to crypto-transactions;
11.7.2 Elliptic: additional blockchain analytics, AML monitoring, wallet-address screening, transaction risk assessment, and detection of exposure to high-risk addresses, entities and typologies. Elliptic (United Kingdom) processes data in a country for which the European Commission has issued an adequacy decision, so the transfer is carried out on the basis of that decision.
11.7.3 Crypto-wallet addresses and transaction data are shared with these providers to the extent necessary for risk assessment, not the entire KYC file.
11.8 As our customer support system we use Zendesk (Zendesk, Inc.). Personal data from your enquiries (name, contact details and the content of the message) are processed through the system. As Zendesk is established in the United States, the data transfer is based on its certification under the EU–U.S. Data Privacy Framework and, where necessary, on the EU Standard Contractual Clauses. The processing is governed by Zendesk's data processing agreement.
12 Transfers of data outside the EEA
12.1 Certain processors are located outside the EEA or may process data outside the EEA. This currently applies to:
12.1.1 Cloudflare, Inc. (USA) – infrastructure, site delivery and protection against malicious traffic;
12.1.2 Google (Google Forms) (USA) – receiving messages via the contact form;
12.1.3 Chainalysis (USA) – blockchain analytics, transaction monitoring and risk assessment of crypto-transactions.
12.2 For these transfers to the USA, the EU Standard Contractual Clauses (SCCs) apply, together with the recipients' participation in the EU–U.S. Data Privacy Framework.
12.3 If we transfer data outside the European Economic Area, we protect it by recognised mechanisms such as the EU Standard Contractual Clauses.
12.4 As a rule, we process your data within the European Economic Area (EEA). If we transfer it outside the EEA, we do so only with appropriate safeguards:
12.4.1 a European Commission adequacy decision for the relevant country; or
12.4.2 the European Commission's Standard Contractual Clauses (SCCs); or
12.4.3 other mechanisms recognised under Chapter V of the GDPR.
13 How long we retain data
13.1 We retain data for as long as necessary for the purpose of processing or as required by law. Due to anti-money-laundering regulations, we retain identity verification and transaction data even after an account is closed.
| Type of data | Retention period |
|---|---|
| Account data | For the duration of the account and a reasonable period after closure to fulfil obligations, and in any event until the expiry of the limitation periods for asserting claims |
| KYC data and transaction data (AML/CFT) | KYC data, transaction data and related documentation (AML/CFT) – ten years after the end of the business relationship, or after the execution of the transaction or collection of the data, in accordance with Article 79(1) of the Act on the Prevention of Money Laundering and Terrorist Financing (OG 108/17, 39/19, 151/22) |
| Accounting and tax data | Within the periods prescribed by accounting and tax regulations |
| Security logs (log files) | The period necessary for security and fraud prevention |
| Support communications | The period necessary to resolve enquiries and any potential legal claims |
13.2 After the retention period expires, we delete or irreversibly anonymise the data.
14 How we protect your data
14.1 We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, loss or destruction. These measures include:
14.1.1 The Platform backend is hosted on our own infrastructure within the European Economic Area and does not constitute an external processor.
14.1.2 Encryption of data in transit and at rest; all communication between users, the interface and the servers takes place over a secured connection (HTTPS/TLS), and we transmit data end-to-end encrypted;
14.1.3 Multi-factor authentication (MFA) on the production system;
14.1.4 Role-based access control, applying the principle of least privilege, so that data are accessed only by authorised persons to the extent necessary for their work;
14.1.5 Pseudonymisation of data where appropriate;
14.1.6 A firewall, protection against malicious traffic and DDoS attacks, and regular security checks;
14.1.7 A confidentiality obligation for all employees and regular training;
14.1.8 Procedures for detecting, reporting and remedying personal data breaches.
14.1.9 As an entity in the financial sector, the Controller is subject to Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). In accordance with that Regulation, we establish and maintain our own information and communications technology (ICT) risk-management system, covering ICT risk management; the detection, handling and reporting of ICT incidents; digital operational resilience testing; and the monitoring of risks relating to third-party ICT service providers.
14.1.10 No system of data transmission or storage is entirely secure. Although we take measures appropriate to the risk, we cannot guarantee absolute data security, but we continuously work to maintain and improve a high level of protection.
15 Cookies and similar technologies
15.1 What cookies are
15.1.1 Cookies are small text files stored on your device when you visit. They allow a website to remember your actions and settings (for example language choice or consent) during a visit and on return visits. Besides cookies, technologies such as browser local storage (localStorage and sessionStorage) can perform similar functions; we do not use these technologies.
15.2 Types of cookies we use
15.2.1 We use only the strictly necessary and functional cookies required for the operation and security of the site. We do not use analytics or marketing cookies, or any tools for tracking, profiling or advertising. We do not track your behaviour on the site beyond what is technically necessary for it to function.
15.3 Legal basis
15.3.1 We set necessary and functional cookies on the basis of their necessity to provide the service you requested, or our legitimate interest in the secure operation of the site (Article 6(1)(f) GDPR). As we do not use non-essential cookies, we do not seek consent for them.
15.4 List of cookies
| Name | Purpose | Category | Duration | Set / sent by |
|---|---|---|---|---|
| cc_cookie | Storing your cookie-consent choice | Necessary | Session | Whitely (EU) |
| i18n_redirected | Storing language preference | Necessary | Session | Whitely (EU) |
| cf_clearance | Protection against DDoS attacks and network optimisation | Functional | 1 year | Cloudflare (USA; SCC + DPF) |
15.5 Third-party cookies and international transfers
15.5.1 The only third-party cookie is cf_clearance, set by Cloudflare, Inc., a company established in the USA, to protect and deliver the site. We protect any transfers of data outside the EEA with the EU Standard Contractual Clauses (SCCs) and the recipient's participation in the EU–U.S. Data Privacy Framework.
15.6 Managing consent and cookies
15.6.1 A consent banner is shown on your first visit. Non-essential categories are not pre-ticked; as we currently use no non-essential cookies, the banner exists for compliance purposes and will be activated only if and when we introduce such cookies. We use the vanilla-cookieconsent solution (v3.1.0) to manage consent.
15.6.2 You can review and change your cookie settings at any time via the settings on the site;
15.6.3 You can also block or delete cookies via your browser settings; disabling necessary cookies may impair part of the site's functionality.
15.7 Changes
15.7.1 If we introduce analytics or marketing cookies in the future, we will seek your consent before setting them and will update this chapter and the cookie list accordingly.
16 Your rights
16.1 In brief: you have the right of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with the supervisory authority. We deal with requests within one month.
16.2 In relation to your personal data, you have the following rights:
16.2.1 Right of access – confirmation of whether we process your data and a copy of that data, together with information about the processing.
16.2.2 Right to rectification – correction of inaccurate data or completion of incomplete data.
16.2.3 Right to erasure – deletion of data when no longer needed; this does not apply to data we are required to retain by law (e.g. KYC/AML).
16.2.4 Right to restriction of processing – temporary restriction of processing in the cases provided for by law.
16.2.5 Right to portability – receipt of the data you provided to us in a structured, machine-readable format, where technically feasible.
16.2.6 Right to object – objection to processing based on legitimate interest.
16.2.7 Right to withdraw consent – at any time, without affecting the lawfulness of prior processing.
16.2.8 Right to be notified of a breach – notification without undue delay if the breach poses a high risk to your rights.
16.2.9 Right to lodge a complaint – lodging a complaint with the Personal Data Protection Agency (see Chapter 20).
16.2.10 Certain rights may be restricted where processing is necessary to prevent money laundering or terrorist financing or to fulfil regulatory obligations.
17 Blockchain and limitations on certain rights
17.1 When using the Services, certain transaction data (for example crypto-wallet addresses, amounts and timestamps) are recorded on a public blockchain network. Due to the technical nature of this technology, such records are immutable, publicly accessible and decentralised.
17.2 This means we cannot alter, delete or restrict data once recorded on the blockchain, nor can we request this of the network. Your rights to rectification, erasure and restriction of processing therefore cannot be applied to such records in a technical sense. Those rights continue to apply in full to personal data we hold in our own systems off-chain (for example account data and KYC data), within the limits of statutory retention obligations.
18 How to exercise your rights
18.1 Send your request to dpo@whitely.hr.
18.2 To protect your privacy, before acting on a request we must unambiguously establish your identity, so we may ask you for additional verification data.
18.3 We respond to requests within one month; for complex or numerous requests we may extend this period by up to two further months, of which we will inform you.
18.4 Exercising rights is generally free of charge; for manifestly unfounded or excessive (in particular repetitive) requests, we may charge a reasonable fee or refuse to act.
18.5 Rights may also be exercised by an authorised representative holding a valid power of attorney.
19 Minors
19.1 The Services are intended solely for persons over 18 years of age.
19.2 We do not knowingly collect data of persons under 18, nor are they permitted to use the Services. If we determine that we have collected data of a minor, we will close such an account and delete the data as soon as possible.
20 Right to complain to the Personal Data Protection Agency
20.1 If you believe we are breaching data protection regulations, you may contact us, and in any event also the supervisory authority – AZOP.
20.2 If you believe that by processing your data we are breaching the regulations, please contact us first so that we can clarify the situation. Regardless, you have the right to lodge a complaint with the supervisory authority:
| Supervisory authority | Personal Data Protection Agency (AZOP) |
|---|---|
| Address | Ulica Metela Ožegovića 16, 10000 Zagreb |
| Tel | +385 1 4609 000 |
| azop@azop.hr | |
| Web | www.azop.hr |
21 Changes to this Notice
21.1 We update this Notice from time to time. We notify you of important changes via the Website or directly.
21.2 We may amend this Notice to align with regulations or changes in processing. We notify you of changes by publication on the website, and for significant changes also directly (e.g. by email).
21.3 The date of the last change is stated at the beginning of the document. We recommend reviewing this Notice from time to time.
22 Contact
22.1 For all data protection queries: dpo@whitely.hr
Annex 1 – Data for KYC/KYB Verification
A. Customer – natural person (user)
| Data category | Specific data | Data subject |
|---|---|---|
| Identification data | First and last name; Date of birth (day, month, year); Address of residence; OIB / personal identification number; Nationality / nationalities; Type, number, issuer and country of identification document (where the OIB of a foreign national cannot be obtained) | User |
| PEP status (politically exposed person) | PEP declaration / status of the user; Data on close family members of the PEP (spouse / partner, children and their partners, parents); Data on close associates of the PEP | User, PEP and related persons |
B. Sole trader / self-employed person (freelancer, consultant)
| Data category | Specific data | Data subject |
|---|---|---|
| Sole-trader / activity data | First and last name; Business address (street, number, place, country); Identification number of the person and their trade/activity; Description of activity and classification under NKD 2007 | User (sole trader) |
C. Representatives and proxies (natural persons)
| Data category | Specific data | Data subject |
|---|---|---|
| Data on legal representative / proxy | Identification data of the representative/proxy (as under A); Data from the certified/apostilled power of attorney; Copy of the principal's ID document | Representative / proxy |
D. Person for whom the transaction is intended
| Data category | Specific data | Data subject |
|---|---|---|
| Data on the recipient / beneficiary of the transaction | First and last name; Address; Personal identification number (if available) | Third natural person |
E. Persons connected to a legal entity (where the customer is a legal entity)
| Data category | Specific data | Data subject |
|---|---|---|
| Data on management members and authorised persons | Names, identification numbers and residency of management members or holders of an equivalent function; Names, identification numbers and residency of persons authorised to represent | Management members / representatives |
F. Beneficial owner (UBO)
| Data category | Specific data | Data subject |
|---|---|---|
| Data on the beneficial owner | First and last name; Nationality; Date of birth (day, month, year); Country of residence; Data on the ownership and control structure (shares, voting rights, control) | Beneficial owner |
| Data on the beneficial owner of a trust / similar foreign arrangement | Identity of the settlors, trustees, protectors; Identity of the beneficiaries or class of beneficiaries; Identity of persons exercising control over the trust | Persons connected to the trust |
G. Purpose and nature of the business relationship
| Data category | Specific data | Data subject |
|---|---|---|
| Data on the purpose of the relationship | Reason for opening the account and intended use (e.g. trading, investment, remittances); Description of business activity (for business entities); Date and time of establishing the business relationship | User |
H. Transaction data
| Data category | Specific data | Data subject |
|---|---|---|
| Data on the transaction | Date and time of transaction; Amount and currency; Method of execution (e.g. SEPA, blockchain, cash); Purpose of the transaction (where higher risk is identified) | User |
I. Source of funds and source of wealth
| Data category | Specific data | Data subject |
|---|---|---|
| Data on source of funds (SoF) and source of wealth (SoW) | Data on the source of funds for the business relationship and individual transactions; Data on the source of wealth (in particular for fiat deposits/withdrawals and for PEPs); Data on source and purpose for transactions above EUR 10,000 | User, UBO |
J. Ongoing monitoring of the business relationship
| Data category | Specific data | Data subject |
|---|---|---|
| Data from ongoing monitoring | Data on the consistency of transactions with the expected nature and purpose of the relationship; Data on deviations in the scope, frequency and type of transactions; Updated data on the customer, beneficial owner and risk profile; Changes in the PEP status of the customer or beneficial owner | User, UBO |
K. Suspicious transactions
| Data category | Specific data | Data subject |
|---|---|---|
| Data on suspicious activities | Indicators of suspicious transactions, funds and persons; All additional data necessary to document and substantiate suspicion of ML/TF | User, related persons |
L. Supporting documents (containing personal data)
| Data category | Specific data | Data subject |
|---|---|---|
| Documents collected for verification | Copy of ID card / passport / driving licence; Extracts from public/court registers, extract from the Beneficial Ownership Register; Founding act, articles of association, list of members/shareholders; Certified/apostilled power of attorney; Proof of address (lease agreement, utility bill, bank statement) | User and related persons |