Privacy Policy
Privacy Notice on the Processing of Personal Data
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This privacy notice explains how Lux Pay Digital Services collects, uses, and protects the personal data of users, customers, potential customers, and individuals interacting with its services, digital platforms, support systems, and technological tools.
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and applies to the processing of personal data carried out by Lux Pay Digital Services in connection with the provision of crypto-asset services and related services within the European Economic Area (EEA).
All personal data are processed in a lawful, fair, and transparent manner, in accordance with the principles of data minimization, purpose limitation, accuracy, integrity, confidentiality, and accountability.
1. Data Controller
Lux Pay Digital Services
The company is registered in the Register of Virtual Currency Service Providers and Digital Wallet Providers (VASP) maintained by the Organismo Agenti e Mediatori (OAM) under number PSV108.
Email contact: support@lux-pay.co
Lux Pay Digital Services operates as part of the Monteris group, responsible for providing crypto-asset services within the European Economic Area.
If appointed, the Data Protection Officer (DPO) can be contacted through the contact details published on the official company website.
2. Purpose and Legal Basis of Data Processing
Personal data are processed for the following purposes.
2.1 Contract Performance and Pre-Contractual Measures
Personal data are processed in order to:
- register users and create accounts
- verify requirements necessary to access services
- conclude and manage contractual relationships
- provide crypto-asset and related services
- manage requests for information and support
- carry out pre-contractual activities requested by users
Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
Providing this data is mandatory. Without it, services cannot be provided.
2.2 Compliance with Legal Obligations
Personal data may be processed to comply with legal obligations, including:
- anti-money laundering (AML) regulations
- counter-terrorism financing requirements
- Know Your Customer (KYC) verification
- tax and accounting obligations
- reporting obligations to regulatory authorities
- compliance obligations applicable to crypto-asset service providers
- internal audit, security, and compliance procedures
Legal basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR).
2.3 Fraud Prevention and Security
Personal data may be processed to:
- prevent fraud and misuse of services
- detect suspicious or anomalous transactions
- protect accounts and digital platforms
- prevent identity theft and unauthorized access
- mitigate operational or reputational risks
- protect the rights of the company in legal proceedings
Legal basis: Legal obligations and legitimate interest (Art. 6(1)(f) GDPR).
2.4 Identity Verification and Remote Identification
The Company may process personal data necessary for identity verification, including information contained in identification documents.
If remote verification methods are used, including video-selfie identification, the Company may process:
- images of identification documents
- photos or videos captured during verification
- data used to confirm identity
If biometric data are processed, explicit consent may be required where applicable.
2.5 Direct Marketing
With user consent, the Company may send promotional communications about services, features, offers, or updates via:
- push notifications
- SMS
- other communication channels
Legal basis: Consent (Art. 6(1)(a) GDPR).
2.6 Soft Spam
Where permitted by law, the Company may send communications related to services similar to those already used by the customer.
Users may unsubscribe at any time through the link provided in communications.
2.7 Commercial Profiling
With consent, personal data may be analyzed to understand:
- preferences
- usage habits
- service interaction patterns
- user interests
This helps improve services and personalize offers.
2.8 Legal Claims and Dispute Management
Personal data may be processed when necessary to establish, exercise, or defend legal claims or manage disputes.
3. Categories of Personal Data Processed
- identification data (name, surname, date and place of birth)
- contact information (email, phone, address)
- identification document details
- tax identifiers
- financial and transaction data
- service usage data
- compliance verification data
- technical data (IP address, browser, device information)
- information voluntarily provided by users
- data from authorized third-party providers
4. Sources of Personal Data
Personal data may be collected:
- directly from users
- through the website or mobile application
- from verification providers
- from compliance databases
- from public registers
- from other companies within the group
5. Nature of Data Provision
Providing personal data for contractual or legal purposes is mandatory.
Failure to provide such data may prevent account registration, access to services, or completion of transactions.
Providing data for marketing or profiling purposes is optional.
6. Data Processing Methods
Personal data are processed using electronic systems, automated tools, and manual procedures where necessary.
Appropriate security measures are implemented to protect data from unauthorized access, loss, or misuse.
7. Recipients of Personal Data
Personal data may be shared with:
- authorized employees
- companies within the corporate group
- IT and cloud providers
- identity verification providers
- AML and fraud prevention services
- legal and financial consultants
- public authorities where required by law
- technical partners supporting service delivery
8. International Data Transfers
Personal data may be transferred outside the European Economic Area when necessary.
Transfers occur in accordance with Articles 44-49 GDPR using approved safeguards such as Standard Contractual Clauses.
9. Data Retention
Personal data are retained only as long as necessary for the purposes described or as required by law.
Once retention periods expire, data will be deleted or anonymized.
10. Browsing Data
The website may automatically collect technical information such as IP addresses, request times, server responses, and system information.
This information helps ensure security and proper system functioning.
11. Cookies and Similar Technologies
The website may use cookies and similar technologies for technical, analytical, or marketing purposes.
Further details are available in the Cookie Policy.
12. Customer Support
Personal data may be processed when users contact support through email, chat, or phone.
Calls may be recorded for quality assurance, security, and compliance purposes.
13. Chatbots and Artificial Intelligence Tools
If AI-based tools or chatbots are used, information may be processed to provide assistance and improve service quality.
Users should avoid sharing sensitive information such as passwords, private keys, or seed phrases.
14. Rights of the Data Subject
Users have the right to:
- access their personal data
- correct inaccurate data
- request deletion of data
- restrict processing
- receive data portability
- object to processing
- withdraw consent
Requests may be sent to support@lux-pay
15. Complaints
Users who believe their data are processed unlawfully may file a complaint with the competent Data Protection Authority.
16. Minors
Services are not intended for minors unless permitted by applicable law.
17. Updates to This Privacy Notice
This privacy notice may be updated due to regulatory, technical, or organizational changes. Updated versions will be published on official company channels.



