BITSA® PRIVACY POLICY
At BITSA®, we want to assure you that your privacy is important to us, which is why we are explaining that we will only use your information for the purposes described, thereby respecting your right to data protection. In any case, whenever we ask you to provide us with your personal data, we will inform you in detail about this.
1. Who is the data controller?
The data controller is BITSA, a simplified joint-stock company (SAS) registered with the Nice Commercial Register under number 885097345, with a share capital of 1,150,000 euros, VAT number FR79885097345, and whose registered office is at 37–41 Boulevard Dubouchage, 06000 Nice, France. Its trading name and registered trade mark is BITSA®, with tax identification number FR79885097345. Contact: Email: soporte@bitsacard.com and telephone: +33 422 530 991.
As we care about your privacy, we have appointed a Data Protection Officer to safeguard your privacy and ensure that we comply with data protection regulations. You can contact them at the email address dpd@bitsacard.com.
2. How do we collect your personal data?
We collect your personal data through various channels, but you will always be informed at the time of collection via information notices regarding the data controller, the purpose and legal basis for processing, the recipients of the data and the retention period for your information, as well as how you can exercise your data protection rights. We may collect your personal data on various occasions, both on the website and via the App:
- When you contact us, for example via the contact or subscription forms on the website, or by telephone.
- When you register by creating a user account.
- When you give permission for your Contacts app to search for contacts in your address book, with whom you can send and receive money.
- When you take part in marketing campaigns, including prize draws or promotions.
- When we are conducting a recruitment process and you send us your CV.
- When, with your authorisation, other legal entities provide us with your data, such as when you verify your identity (KYC) via the online identity verification process.
BITSA® uses social media, and this is another way in which we interact with you. The information collected through the messages and posts you publish may contain personal information that is available online and accessible to the public. These social media platforms have their own privacy policies explaining how they use and share your information; BITSA® therefore recommends that you consult them at before using these platforms, to confirm that you agree with the way in which your information is collected, processed and shared.
Through our website and app, we collect personal information relating to your browsing activity through the use of cookies. For a clear and precise understanding of the cookies we use, their purposes and how you can configure or disable them, please refer to our Cookies Policy.
3. What information can we collect?
We may collect various types of information from you, such as:
- Contact details, name, postal address or proof of residence, telephone number or email address.
- Website and communications usage, as we use cookies which may collect information about you; you can manage these via the relevant cookie manager.
- Account details, such as your National Identity Card number to identify you, including a copy of the document, not just the number.
- Contact list, should you give us permission, so that you can search for your contacts within the app to send and receive money.
- Connection metadata, including your IP address.
- Biometric data from your face to identify you and comply with AML/CFT regulations.
- Your card or bank account details, as well as the source of the funds.
- Any other data we may explicitly request from you during the identification process.
- Curriculum vitae details. Should you provide these to us as part of an unsolicited application or during a recruitment process.
4. What do we use your data for?
At BITSA®, we may use your data for various purposes:
- If you are a customer, we will use your data to manage the services we provide to you, and to do so we must verify your identity as part of our anti-money laundering and counter-terrorist financing measures.
- If you have given permission for us to access your contact list, we can facilitate the sending and receiving of money between BITSA® users.
- To be able to apply for and send you the BITSA® card.
- If you request information, we will use your details to respond to your enquiries.
- To keep you informed about events, offers, products and services that may be of interest to you via various communication channels, provided you have given your consent.
- To manage subscription requests on our channels.
- To manage any competitions or promotions we may run.
- To handle any enquiries, suggestions and complaints you may send to us.
- Recruitment process.
- Managing our business relationships with our suppliers.
- To comply with anti-money laundering regulations.
As data controllers, we are subject to the law and must comply with it. That is why we have a number of legal obligations that we must fulfil, such as, in certain cases, providing specific data that we are required to submit to judicial authorities, regulatory and supervisory bodies, or the state security forces.
We will therefore use your data for the legitimate purposes set out in the regulations, in the following circumstances:
- When you have given your consent to the processing of your personal data for one or more specific purposes;
- Where processing is necessary for the performance of a contract to which you are a party or for the implementation, at your request, of pre-contractual measures;
- Where processing is necessary for compliance with a legal obligation to which the data controller is subject, such as the prevention of money laundering and terrorist financing;
5. How do we protect your personal data?
As we take your personal data very seriously, at BITSA® we have adopted the technical and organisational measures set out in data protection regulations to maintain the security, availability and integrity of your data.
Furthermore, all staff with access to personal data have been trained and are aware of their obligations regarding the processing of your personal data.
In the contracts we enter into with our suppliers, we include clauses requiring them to maintain confidentiality regarding the personal data to which they have had access by virtue of the work commissioned, as well as to implement the necessary technical and organisational security measures to ensure the ongoing confidentiality, integrity, availability and resilience of the systems and services used to process personal data.
All these security measures are reviewed periodically to ensure they remain appropriate and effective.
However, absolute security cannot be guaranteed and no security system is impenetrable; therefore, should any information subject to processing and under our control be compromised as a result of a security breach, we will take the appropriate measures to investigate the incident, notify the Supervisory Authority and, where applicable, those users who may have been affected so that they can take the necessary steps.
6. How long do we keep your data?
At BITSA®, we only retain your information for as long as is necessary to fulfil the purpose for which it was collected, to comply with the legal obligations imposed on us, and to address any potential liabilities that may arise from fulfilling the purpose for which the data was collected. If your data is used for multiple purposes that require us to retain it for different periods, we will apply the longest retention period.
In any event, and as a general rule, we will retain your personal information for as long as a contractual relationship between us exists or until you exercise your right to erasure and/or restriction of processing, in which case the information will be blocked and not used for any purpose other than storage, for as long as it may be necessary for the exercise or defence of legal claims or in the event that any liability arises that needs to be addressed.
7. Do we share your data with other companies?
In order to develop and provide you with the requested service, which requires access to your BITSA® card, we must share your data with the electronic money institution that issues the card, PECUNIA CARDS EDE, S.L.U., with tax identification number (CIF) B86972346, and registered office at Calle Guzmán el Bueno no. 133, Edificio América, Bajo B, 28003, Madrid. Pecunpay, in compliance with current data protection regulations, has appointed a Data Protection Officer, whom you may contact via email at datos@pecuniacards.es, or by post at Calle Guzmán el Bueno nº 133, Edificio América, Bajo B, 28003, Madrid. You may inform us that you object to the transfer of your data; however, in that case, we would be unable to provide you with the requested service.
Furthermore, we rely on Sum and Substance Ltd (UK), primarily for the validation or identification process, as required by Law 10/2010 of 28 April on the prevention of money laundering and the financing of terrorism, or any other applicable related legislation. To this end, you must expressly accept the terms and conditions of service before commencing the identification process.
Crypto-asset transactions provided by BITNOVO®
The processing of users’ personal data in the context of crypto-asset transactions, a service provided by BITNOVO® (PRESSBROKERS, SL), is the sole responsibility of BITNOVO®, which will act as the Data Controller in accordance with the applicable data protection regulations.
You may exercise your data protection rights in relation to transactions carried out within the BITNOVO® platform by emailing dpo@bitnovo.com or by sending a written communication to the following postal address: 46023 Valencia, Calle l’Illa de Sardenya, No. 1, ground floor. For further information on BITNOVO®’s Privacy Policy, click here.
In the context of these operations, BITSA SAS will only process your data to the extent strictly necessary for:
- provide BITNOVO® with your KYC and identification details.
- the management of funds transferred to the IBAN account linked to the user’s card,
BITSA SAS will act as a Data Processor under the instructions of BITNOVO®.
BITSA SAS may disclose your personal data to third-party service providers where this is strictly necessary for the proper provision of the requested service. These third parties will act as Data Processors and will access the information solely in accordance with the instructions of BITSA SAS, pursuant to the relevant data processing agreements entered into for this purpose; they may not use the data for their own purposes or for purposes other than those entrusted to them, and are subject to strict confidentiality and security obligations.
Furthermore, your personal information will be made available to public authorities, judges and courts in order to address any potential liabilities arising from the processing.
Do we process data on behalf of other companies?
We may process personal data obtained by other companies within the framework of a commercial relationship, for which we enter into a data processing agreement with those companies to regulate such situations. In this case, we only process the data on behalf of the party that obtained it and in accordance with the instructions provided to us.
8. Transfer
We may transfer your personal data to service providers based in different parts of the world. Where we intend to transfer personal data to third countries or international organisations outside the EEA, BITSA® puts in place appropriate technical, organisational and contractual measures to ensure that such transfers are carried out in accordance with the applicable data protection regulations.
9. User responsibility
By providing us with your data via electronic channels, you warrant that you are over 18 years of age and that the data provided to BITSA® is true, accurate, complete and up to date. To this end, the user confirms that they are responsible for the accuracy of the data provided and that they will keep this information duly up to date so that it reflects their actual situation, accepting responsibility for any false or inaccurate data they may provide, as well as for any direct or indirect damages that may arise as a result.
10. What rights do you have to protect your personal data?
Data protection legislation allows you to exercise your rights of access, rectification, erasure and data portability, as well as the right to object to and restrict the processing of your data, and the right not to be subject to decisions based solely on the automated processing of your data, where applicable.
These rights are characterised as follows:
- Exercising these rights is free of charge, unless the requests are manifestly unfounded or excessive (e.g. repetitive in nature), in which case BITSA® may charge a fee proportionate to the administrative costs incurred or refuse to act.
- You may exercise these rights directly or through your legal or voluntary representative.
- We must respond to your request within one month; however, taking into account the complexity and number of requests, this period may be extended by a further two months.
- We are obliged to inform you of the means by which you may exercise these rights; these must be accessible, and we may not deny you the right to exercise them solely on the grounds that you have chosen a different method. If the request is submitted electronically, the information will be provided by electronic means where possible, unless you request otherwise.
- If BITSA® does not act on your request, it will inform you, within one month at the latest, of the reasons for its failure to act and of your right to lodge a complaint with a supervisory authority.
In particular, we would like to remind you that you have the following rights:
- You have the right to know whether we are processing your data, the categories of data we process, the purpose of processing, the source from which we obtain it, and whether we transfer or share it. If you believe your data is incorrect or inaccurate, you may contact us to have it corrected; you may also request its erasure if there is a lawful basis for doing so.
- Similarly, you may object to us continuing to process your data or even request that we restrict our use of your data.
- You have the right to be informed if we carry out behavioural profiling and do so entirely by automated means and make decisions in this way; you may request intervention by one of our staff members and challenge any decision we make on that basis.
- You also have the right to data portability; that is, the right to have your data sent to you or to a third party of your choice in a structured, commonly used and machine-readable format.
- Finally, we would like to remind you that you have the right to lodge any claim or complaint with BITSA® or with the Spanish Data Protection Agency (the competent supervisory authority in this matter), by writing to the Agency at C/Jorge Juan, No. 6, 28001 – Madrid, or via the website: https://www.agpd.es/
How can you exercise your rights?
To exercise your rights, BITSA® provides the following means:
- By sending a written and signed request addressed to BITSA SAS, 37 Boulevard DUBOUCHAGE (06000 NICE), with the reference ‘Exercise of LOPD Rights’ written on the letter to ensure it is processed correctly.
- By sending a signed email to dpd@bitsacard.com, stating ‘Exercise of LOPD Rights’ in the subject line.
In both cases, you must prove your identity by enclosing a photocopy or, where applicable, a scanned copy of your national identity card or equivalent document so that we can verify that we are responding only to the data subject or their legal representative; in the latter case, you must also provide a document proving your authority to act on their behalf. You must also complete a form requesting the exercise of rights, which we will send to you upon request.
Version 3, 25 June 2026.