Privacy Policy

Information About the Controller of Personal Data

The website https://spays.io/ is operated under the commercial brand Spays.

Spays is a commercial brand operated by 3-102-966866 Sociedad de Responsabilidad Limitada, a company registered under the laws of Costa Rica with corporate identification number 3-102-966866.

For the purposes of this Privacy Policy, 3-102-966866 Sociedad de Responsabilidad Limitada is the controller of the personal data processed through the website and its services and may also be referred to as “Spays”, “we”, “us”, or “our”.

You may contact us using the contact form or other contact details provided on the website for inquiries related to the processing of your personal data or other requests.

Grounds and Purposes for Data Processing

We are committed to processing personal data in accordance with applicable data protection legislation, including Costa Rica’s Law No. 8968 on the Protection of Individuals with Regard to the Processing of Personal Data, its implementing regulations and, where applicable, the European Union General Data Protection Regulation (“GDPR”) and other relevant privacy laws.

The personal data we process include data that you voluntarily provide to us when interacting with our services, such as when you complete our contact form, sign a contract, create or use an account, undergo identity or compliance verification, initiate a transaction, or otherwise use our services.

This personal data may include, but is not limited to:

  • your full name;
  • email address;
  • telephone number;
  • residential, billing, or correspondence address;
  • date and place of birth;
  • nationality;
  • identification document information;
  • photographs or video recordings used for identity verification;
  • information concerning the source of funds or source of wealth;
  • bank account or payment information;
  • wallet addresses and transaction information;
  • information required for compliance, sanctions screening, fraud prevention, or anti-money laundering purposes; and
  • any other information that you choose or are required to provide for the purpose of engaging with us.

We may also collect additional data depending on the nature of our interactions. This may include preferences, feedback, complaints, inquiries, and communications submitted to us, as well as technical information relating to the use of the website.

Technical information may include:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language settings;
  • login and access information;
  • approximate location derived from technical information;
  • pages visited;
  • actions performed on the website;
  • session information; and
  • other information concerning interactions with the website or platform.

All personal data collected will be processed in accordance with the purposes described in this Privacy Policy.

Depending on the circumstances, we may process personal data on one or more of the following legal grounds:

  • your consent;
  • the performance of a contract with you or steps taken at your request before entering into a contract;
  • compliance with a legal or regulatory obligation;
  • protection of our legitimate interests or those of a third party, provided that these interests do not override your rights and freedoms;
  • prevention of fraud, money laundering, terrorist financing, sanctions violations, or other unlawful activity; and
  • the establishment, exercise, or defence of legal claims.

Where processing is based on consent, you provide your consent by engaging with our forms or services or by otherwise giving a clear affirmative indication of your agreement.

You are not obligated to provide personal data where processing is based exclusively on consent. However, refusing to provide information that is required for contractual, legal, compliance, security, or identity-verification purposes may prevent us from providing some or all of our services to you.

We strive to ensure that the personal data we process are accurate, complete, up to date, and used only for specified and lawful purposes.

Where the purpose of processing materially changes, we will inform you and, where required by applicable law, request your consent before processing your personal data for the new purpose.

Personal data may be processed for purposes including:

  • responding to inquiries or requests;
  • providing and administering our services;
  • creating and managing user accounts;
  • entering into and performing contracts;
  • processing or facilitating transactions;
  • conducting identity and eligibility verification;
  • complying with anti-money laundering and counter-terrorist financing requirements;
  • sanctions, politically exposed person, and adverse-media screening;
  • preventing fraud, abuse, security incidents, and unlawful activity;
  • maintaining the security and functionality of our website and systems;
  • providing customer support;
  • handling complaints and disputes;
  • maintaining accounting, tax, audit, and regulatory records;
  • improving our website, services, and user experience;
  • communicating service-related information;
  • offering product or service information where legally permitted; and
  • establishing, exercising, or defending legal claims.

Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the consent was withdrawn.

Provision of Personal Data to Third Parties

We do not sell your personal data.

We do not share or disclose your personal data to third parties unless this is necessary to provide our services, fulfil our contractual obligations, comply with applicable law, protect our legitimate interests, or respond to a lawful request from a competent authority.

We may share personal data with third-party service providers that assist us in operating and managing our services. These third parties may include:

  • identity-verification and know-your-customer providers;
  • anti-money laundering, sanctions-screening, and fraud-prevention providers;
  • payment service providers;
  • banks and financial institutions;
  • crypto-asset liquidity or execution providers;
  • wallet, blockchain infrastructure, or custody technology providers;
  • cloud-hosting and information-technology providers;
  • cybersecurity providers;
  • analytics and website-support providers;
  • communications and customer-support providers;
  • professional advisers, including lawyers, accountants, auditors, and consultants;
  • insurers;
  • regulators, supervisory authorities, law-enforcement bodies, courts, and other competent authorities; and
  • counterparties involved in a corporate restructuring, merger, acquisition, financing, or sale of assets.

Third-party processors acting on our behalf are required to process personal data only in accordance with our instructions, applicable contracts, and relevant data-protection and information-security requirements.

Where a third party acts as an independent controller, its own privacy policy and legal obligations will apply to the processing it performs.

International Transfers of Personal Data

Because we provide technology-based and crypto-asset-related services and may engage service providers located in different countries, personal data may be transferred to or accessed from jurisdictions outside Costa Rica or outside the country in which you reside.

Where applicable law requires additional safeguards for an international transfer, we will take appropriate steps to ensure that personal data receive an adequate level of protection.

Depending on the circumstances, these safeguards may include:

  • contractual data-protection clauses;
  • standard contractual clauses approved by a competent authority;
  • adequacy decisions;
  • binding legal obligations;
  • security and access-control measures;
  • data minimisation;
  • encryption or pseudonymisation; and
  • other legally recognised transfer mechanisms.
Processing of Personal Data on Blockchain

We do not store personal data directly on a public blockchain unless this is strictly necessary for the provision of a service or completion of a transaction.

As a general principle, identifiable personal data are held off-chain, while only hashes, references, wallet addresses, transaction identifiers, or other technically necessary information may be recorded on a blockchain.

Where on-chain references are used, we may apply cryptographic commitments, hashing, encryption, pseudonymisation, or similar measures to reduce identification risks.

Public blockchain transactions may be permanent and publicly accessible. Due to the technical nature of blockchain networks, certain information recorded on-chain may not be capable of being altered or fully deleted by us.

In such circumstances, we will take reasonable measures to reduce or remove the link between the on-chain information and an identifiable individual. Such measures may include:

  • anonymisation;
  • deletion of corresponding off-chain information;
  • destruction of encryption or access keys;
  • removal of identifying references; or
  • other measures intended to prevent the information from being linked to you.

Where you request erasure or rectification, we will, where applicable:

  1. act on any personal data held in an off-chain system under our control;
  2. take reasonable measures to ensure that any on-chain component no longer allows direct identification through information controlled by us; and
  3. explain any technical limitations that prevent alteration or deletion of blockchain records.

Retention periods are determined according to the purpose of processing and applicable legal requirements. We regularly review whether personal data remain necessary and delete or anonymise information that is no longer required, subject to technical and legal limitations.

Where the GDPR applies to the relevant processing, we take account of applicable European data-protection principles and regulatory guidance concerning the processing of personal data through blockchain technologies.

Withdrawal of Consent

Where personal data are processed on the basis of your consent, you have the right to withdraw that consent at any time.

You may withdraw your consent by using the contact form or other contact information provided on the website.

Once we receive your request, we will stop processing your personal data for the purpose to which the consent related, unless another lawful basis permits or requires continued processing.

Withdrawal of consent will not affect the lawfulness of processing carried out before the consent was withdrawn.

In certain circumstances, we may be unable to stop processing particular personal data following withdrawal of consent. This may apply where processing is necessary for:

  • the performance of a contract;
  • compliance with a legal or regulatory obligation;
  • anti-money laundering, counter-terrorist financing, sanctions, or fraud-prevention requirements;
  • the protection of legal rights;
  • the establishment, exercise, or defence of legal claims;
  • security or crime-prevention purposes; or
  • another legitimate and lawful purpose permitted under applicable law.

Where we cannot fully comply with a withdrawal request, we will inform you, where legally permitted, of the relevant reasons and legal grounds for continuing to process the data.

Data Retention

Your personal data will be retained only for as long as reasonably necessary to fulfil the purposes for which they were collected and to comply with legal, regulatory, contractual, security, accounting, tax, audit, and operational requirements.

In general, we may retain personal data for a period of five years from the date of collection, the completion of the relevant transaction, or the termination of the business relationship, depending on the nature and purpose of the information.

Where applicable anti-money laundering, financial-services, tax, corporate, accounting, sanctions, or other legislation requires a different or longer retention period, the legally required period will apply.

We may also retain personal data for a longer period where this is reasonably necessary for:

  • an ongoing investigation;
  • a regulatory or law-enforcement request;
  • a complaint or dispute;
  • the establishment, exercise, or defence of legal claims;
  • the prevention or detection of fraud or unlawful activity;
  • the enforcement of contractual rights; or
  • the protection of our systems, users, or services.

After the applicable retention period expires, personal data will be securely deleted, anonymised, or otherwise placed beyond use, unless continued retention is required or permitted by law.

Where blockchain records are involved, the technical limitations described in the section on processing personal data on blockchain will apply.

Data Subject Rights

Subject to the conditions, restrictions, and exceptions established under applicable law, you may have the following rights regarding your personal data:

Right to Information

You have the right to receive clear information about how and why your personal data are collected and used.

Right of Access

You may request confirmation as to whether we process your personal data and obtain a copy of the personal data we hold about you.

Right to Rectification

Where your personal data are inaccurate, incomplete, or outdated, you may request that they be corrected or updated.

Right to Erasure

You may request the deletion of your personal data where the applicable legal conditions are met.

This right is not absolute and may not apply where continued processing is required to comply with a legal obligation, complete a transaction, prevent fraud, protect legal rights, or establish, exercise, or defend legal claims.

Right to Restrict Processing

Where applicable, you may request that processing be restricted, including where you contest the accuracy of the data, challenge the lawfulness of processing, or object to the processing while an assessment is being carried out.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may request that relevant personal data be provided in a structured, commonly used, and machine-readable format.

Where technically feasible and legally permitted, you may also request that the information be transmitted directly to another controller.

Right to Object

You may object to processing based on legitimate interests or the performance of a task carried out in the public interest.

You may object at any time to processing for direct-marketing purposes. Where such an objection is made, we will stop using your personal data for direct marketing.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Rights Concerning Automated Decision-Making

Where applicable, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

This right may be subject to exceptions where automated processing is:

  • necessary for entering into or performing a contract;
  • authorised by applicable law; or
  • based on your explicit consent.

Where required, we will implement suitable safeguards, which may include the possibility of obtaining human intervention, expressing your point of view, and contesting the decision.

Right to Complain

You have the right to submit a complaint to the competent data-protection authority if you believe that your personal data have been processed unlawfully or that your data-protection rights have been infringed.

To exercise any of these rights, please contact us through the contact form or contact information available on the website.

We may request reasonable information to verify your identity before responding to a request. This is intended to prevent personal data from being disclosed to an unauthorised person.

Right of Portability

Where the right to data portability applies, you may request a copy of your personal data in a structured, commonly used, and machine-readable format.

Where technically feasible and legally permitted, you may request that we transmit the relevant data directly to another data controller.

The right to portability generally applies to information that you provided to us and that is processed by automated means on the basis of your consent or a contract.

Right to Object

You may object to the processing of your personal data where the processing is based on legitimate interests or another legal basis that permits objection.

Where you object to processing for direct-marketing purposes, we will stop processing your personal data for those purposes.

For other objections, we may continue processing where we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms or where processing is required for the establishment, exercise, or defence of legal claims.

Complaint to the Supervisory Authority

If you believe that your personal data have been processed unlawfully or that your data-protection rights have been violated, you may lodge a complaint with the competent data-protection authority.

In Costa Rica, complaints concerning the misuse or unlawful processing of personal data may be submitted to the Agencia de Protección de Datos de los Habitantes (PRODHAB).

Where the GDPR applies to the processing of your personal data, you may also have the right to complain to the competent supervisory authority in the European Economic Area country in which you reside, work, or believe the alleged infringement occurred.

You may also seek judicial or other remedies available under applicable law.

Use of Artificial Intelligence

We may use artificial-intelligence tools to analyse information, improve our services, detect fraud or suspicious activity, support compliance controls, provide personalised services, or automate certain customer-service and operational functions.

Depending on the circumstances, personal data processed through artificial-intelligence systems may include transaction information, device and technical information, account activity, communications, risk indicators, identity-verification results, and other information relevant to the particular purpose.

Where required by applicable law, we will provide information about the purpose and general functioning of automated processing and the possible consequences for you.

Where processing requires consent, we will obtain that consent before carrying out the relevant processing.

We are committed to ensuring that the use of artificial intelligence respects applicable data-protection rights and does not result in unlawful discrimination or unfair treatment.

Where an automated decision produces legal effects concerning you or similarly significantly affects you, you may have the right to:

  • request human intervention;
  • express your point of view;
  • request an explanation of the decision; and
  • challenge the decision,

subject to applicable legal conditions and exceptions.

Data Security

We implement appropriate technical and organisational measures designed to protect the confidentiality, integrity, availability, and resilience of personal data.

These measures may include:

  • encryption;
  • secure storage;
  • access controls;
  • multi-factor authentication;
  • logging and monitoring;
  • network and system-security controls;
  • vulnerability assessments;
  • incident-response procedures;
  • employee confidentiality obligations;
  • staff training;
  • data minimisation;
  • segregation of access rights;
  • backups and recovery procedures; and
  • periodic reviews of security arrangements.

Access to personal data is limited to personnel, contractors, and service providers who require access for legitimate business, contractual, compliance, security, or legal purposes.

Despite the measures we implement, no internet transmission, electronic storage system, blockchain network, or information-security arrangement can be guaranteed to be completely secure.

You should take appropriate precautions when using online services, including protecting your login details, using strong and unique passwords, securing your devices, and informing us promptly if you suspect unauthorised access to your account.

Personal Data Breaches

Where we become aware of a personal data breach, we will assess the nature and potential consequences of the incident and take reasonable steps to contain, investigate, and remediate it.

Where required by applicable law, we will notify the competent authority and affected individuals within the legally applicable period.

Any notification may include information concerning:

  • the nature of the breach;
  • the categories of information affected;
  • the likely consequences;
  • the measures taken or proposed to address the breach; and
  • steps that affected individuals may take to protect themselves.
Children’s Personal Data

Our services are not intended for children or persons who have not reached the minimum legal age required to enter into the relevant transactions or use the services.

We do not knowingly collect personal data from children in connection with services that are restricted to adults.

Where we become aware that personal data have been collected from a child contrary to applicable law, we will take reasonable steps to delete or otherwise appropriately handle the information.

Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy where necessary to reflect changes in:

  • applicable law or regulatory requirements;
  • our services or business activities;
  • the technologies we use;
  • our processing operations;
  • our service providers; or
  • relevant security or compliance practices.

Any updated version will be published on this page and will become effective from the date stated in the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically.

Where changes materially affect your rights or the way in which we process your personal data, we will provide an appropriate notice through the website, by email, or through another suitable communication channel.

Where required by law, we will obtain your consent before applying a material change to processing that is based on consent.

Contact Us

If you have any questions about this Privacy Policy, the processing of your personal data, or the exercise of your data-protection rights, please contact us through the contact form or contact information available at: hello@spays.io