The website https://spays.io/ is operated under the commercial brand Spays.
Spays is a commercial brand operated by 3-102-966866 Sociedad de Responsabilidad Limitada, a company registered under the laws of Costa Rica with corporate identification number 3-102-966866.
For the purposes of this Privacy Policy, 3-102-966866 Sociedad de Responsabilidad Limitada is the controller of the personal data processed through the website and its services and may also be referred to as “Spays”, “we”, “us”, or “our”.
You may contact us using the contact form or other contact details provided on the website for inquiries related to the processing of your personal data or other requests.
We are committed to processing personal data in accordance with applicable data protection legislation, including Costa Rica’s Law No. 8968 on the Protection of Individuals with Regard to the Processing of Personal Data, its implementing regulations and, where applicable, the European Union General Data Protection Regulation (“GDPR”) and other relevant privacy laws.
The personal data we process include data that you voluntarily provide to us when interacting with our services, such as when you complete our contact form, sign a contract, create or use an account, undergo identity or compliance verification, initiate a transaction, or otherwise use our services.
This personal data may include, but is not limited to:
We may also collect additional data depending on the nature of our interactions. This may include preferences, feedback, complaints, inquiries, and communications submitted to us, as well as technical information relating to the use of the website.
Technical information may include:
All personal data collected will be processed in accordance with the purposes described in this Privacy Policy.
Depending on the circumstances, we may process personal data on one or more of the following legal grounds:
Where processing is based on consent, you provide your consent by engaging with our forms or services or by otherwise giving a clear affirmative indication of your agreement.
You are not obligated to provide personal data where processing is based exclusively on consent. However, refusing to provide information that is required for contractual, legal, compliance, security, or identity-verification purposes may prevent us from providing some or all of our services to you.
We strive to ensure that the personal data we process are accurate, complete, up to date, and used only for specified and lawful purposes.
Where the purpose of processing materially changes, we will inform you and, where required by applicable law, request your consent before processing your personal data for the new purpose.
Personal data may be processed for purposes including:
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the consent was withdrawn.
We do not sell your personal data.
We do not share or disclose your personal data to third parties unless this is necessary to provide our services, fulfil our contractual obligations, comply with applicable law, protect our legitimate interests, or respond to a lawful request from a competent authority.
We may share personal data with third-party service providers that assist us in operating and managing our services. These third parties may include:
Third-party processors acting on our behalf are required to process personal data only in accordance with our instructions, applicable contracts, and relevant data-protection and information-security requirements.
Where a third party acts as an independent controller, its own privacy policy and legal obligations will apply to the processing it performs.
Because we provide technology-based and crypto-asset-related services and may engage service providers located in different countries, personal data may be transferred to or accessed from jurisdictions outside Costa Rica or outside the country in which you reside.
Where applicable law requires additional safeguards for an international transfer, we will take appropriate steps to ensure that personal data receive an adequate level of protection.
Depending on the circumstances, these safeguards may include:
We do not store personal data directly on a public blockchain unless this is strictly necessary for the provision of a service or completion of a transaction.
As a general principle, identifiable personal data are held off-chain, while only hashes, references, wallet addresses, transaction identifiers, or other technically necessary information may be recorded on a blockchain.
Where on-chain references are used, we may apply cryptographic commitments, hashing, encryption, pseudonymisation, or similar measures to reduce identification risks.
Public blockchain transactions may be permanent and publicly accessible. Due to the technical nature of blockchain networks, certain information recorded on-chain may not be capable of being altered or fully deleted by us.
In such circumstances, we will take reasonable measures to reduce or remove the link between the on-chain information and an identifiable individual. Such measures may include:
Where you request erasure or rectification, we will, where applicable:
Retention periods are determined according to the purpose of processing and applicable legal requirements. We regularly review whether personal data remain necessary and delete or anonymise information that is no longer required, subject to technical and legal limitations.
Where the GDPR applies to the relevant processing, we take account of applicable European data-protection principles and regulatory guidance concerning the processing of personal data through blockchain technologies.
Where personal data are processed on the basis of your consent, you have the right to withdraw that consent at any time.
You may withdraw your consent by using the contact form or other contact information provided on the website.
Once we receive your request, we will stop processing your personal data for the purpose to which the consent related, unless another lawful basis permits or requires continued processing.
Withdrawal of consent will not affect the lawfulness of processing carried out before the consent was withdrawn.
In certain circumstances, we may be unable to stop processing particular personal data following withdrawal of consent. This may apply where processing is necessary for:
Where we cannot fully comply with a withdrawal request, we will inform you, where legally permitted, of the relevant reasons and legal grounds for continuing to process the data.
Your personal data will be retained only for as long as reasonably necessary to fulfil the purposes for which they were collected and to comply with legal, regulatory, contractual, security, accounting, tax, audit, and operational requirements.
In general, we may retain personal data for a period of five years from the date of collection, the completion of the relevant transaction, or the termination of the business relationship, depending on the nature and purpose of the information.
Where applicable anti-money laundering, financial-services, tax, corporate, accounting, sanctions, or other legislation requires a different or longer retention period, the legally required period will apply.
We may also retain personal data for a longer period where this is reasonably necessary for:
After the applicable retention period expires, personal data will be securely deleted, anonymised, or otherwise placed beyond use, unless continued retention is required or permitted by law.
Where blockchain records are involved, the technical limitations described in the section on processing personal data on blockchain will apply.
Subject to the conditions, restrictions, and exceptions established under applicable law, you may have the following rights regarding your personal data:
You have the right to receive clear information about how and why your personal data are collected and used.
You may request confirmation as to whether we process your personal data and obtain a copy of the personal data we hold about you.
Where your personal data are inaccurate, incomplete, or outdated, you may request that they be corrected or updated.
You may request the deletion of your personal data where the applicable legal conditions are met.
This right is not absolute and may not apply where continued processing is required to comply with a legal obligation, complete a transaction, prevent fraud, protect legal rights, or establish, exercise, or defend legal claims.
Where applicable, you may request that processing be restricted, including where you contest the accuracy of the data, challenge the lawfulness of processing, or object to the processing while an assessment is being carried out.
Where processing is based on consent or contract and carried out by automated means, you may request that relevant personal data be provided in a structured, commonly used, and machine-readable format.
Where technically feasible and legally permitted, you may also request that the information be transmitted directly to another controller.
You may object to processing based on legitimate interests or the performance of a task carried out in the public interest.
You may object at any time to processing for direct-marketing purposes. Where such an objection is made, we will stop using your personal data for direct marketing.
Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Where applicable, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
This right may be subject to exceptions where automated processing is:
Where required, we will implement suitable safeguards, which may include the possibility of obtaining human intervention, expressing your point of view, and contesting the decision.
You have the right to submit a complaint to the competent data-protection authority if you believe that your personal data have been processed unlawfully or that your data-protection rights have been infringed.
To exercise any of these rights, please contact us through the contact form or contact information available on the website.
We may request reasonable information to verify your identity before responding to a request. This is intended to prevent personal data from being disclosed to an unauthorised person.
Where the right to data portability applies, you may request a copy of your personal data in a structured, commonly used, and machine-readable format.
Where technically feasible and legally permitted, you may request that we transmit the relevant data directly to another data controller.
The right to portability generally applies to information that you provided to us and that is processed by automated means on the basis of your consent or a contract.
You may object to the processing of your personal data where the processing is based on legitimate interests or another legal basis that permits objection.
Where you object to processing for direct-marketing purposes, we will stop processing your personal data for those purposes.
For other objections, we may continue processing where we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms or where processing is required for the establishment, exercise, or defence of legal claims.
If you believe that your personal data have been processed unlawfully or that your data-protection rights have been violated, you may lodge a complaint with the competent data-protection authority.
In Costa Rica, complaints concerning the misuse or unlawful processing of personal data may be submitted to the Agencia de Protección de Datos de los Habitantes (PRODHAB).
Where the GDPR applies to the processing of your personal data, you may also have the right to complain to the competent supervisory authority in the European Economic Area country in which you reside, work, or believe the alleged infringement occurred.
You may also seek judicial or other remedies available under applicable law.
We may use artificial-intelligence tools to analyse information, improve our services, detect fraud or suspicious activity, support compliance controls, provide personalised services, or automate certain customer-service and operational functions.
Depending on the circumstances, personal data processed through artificial-intelligence systems may include transaction information, device and technical information, account activity, communications, risk indicators, identity-verification results, and other information relevant to the particular purpose.
Where required by applicable law, we will provide information about the purpose and general functioning of automated processing and the possible consequences for you.
Where processing requires consent, we will obtain that consent before carrying out the relevant processing.
We are committed to ensuring that the use of artificial intelligence respects applicable data-protection rights and does not result in unlawful discrimination or unfair treatment.
Where an automated decision produces legal effects concerning you or similarly significantly affects you, you may have the right to:
subject to applicable legal conditions and exceptions.
We implement appropriate technical and organisational measures designed to protect the confidentiality, integrity, availability, and resilience of personal data.
These measures may include:
Access to personal data is limited to personnel, contractors, and service providers who require access for legitimate business, contractual, compliance, security, or legal purposes.
Despite the measures we implement, no internet transmission, electronic storage system, blockchain network, or information-security arrangement can be guaranteed to be completely secure.
You should take appropriate precautions when using online services, including protecting your login details, using strong and unique passwords, securing your devices, and informing us promptly if you suspect unauthorised access to your account.
Where we become aware of a personal data breach, we will assess the nature and potential consequences of the incident and take reasonable steps to contain, investigate, and remediate it.
Where required by applicable law, we will notify the competent authority and affected individuals within the legally applicable period.
Any notification may include information concerning:
Our services are not intended for children or persons who have not reached the minimum legal age required to enter into the relevant transactions or use the services.
We do not knowingly collect personal data from children in connection with services that are restricted to adults.
Where we become aware that personal data have been collected from a child contrary to applicable law, we will take reasonable steps to delete or otherwise appropriately handle the information.
We reserve the right to amend this Privacy Policy where necessary to reflect changes in:
Any updated version will be published on this page and will become effective from the date stated in the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically.
Where changes materially affect your rights or the way in which we process your personal data, we will provide an appropriate notice through the website, by email, or through another suitable communication channel.
Where required by law, we will obtain your consent before applying a material change to processing that is based on consent.
If you have any questions about this Privacy Policy, the processing of your personal data, or the exercise of your data-protection rights, please contact us through the contact form or contact information available at: hello@spays.io