Privacy Policy of futurum bank AG

I. Name and Contact Data of the Controller

The Controller as defined by law is:
futurum bank AG
Hochstraße 35-37
60313 Frankfurt am Main
Germany
Phone: +49.5221.85411-25
E-Mail: info2024 [at] bitcoin [dot] de

II. Contact Data of the Data Protection Officer

The controller's data protection officer may be contacted at: E-Mail: datenschutz [at] bitcoin [dot] de

III. General Information on Data Protection

Whenever a data subject or automated system accesses a website, our system will collect a range of general data and information. This general data and information is stored in the web servers' log files and may include the browser types and versions used, the website from which a system accessing our website has gained access (so-called "referrer"); the subpages accessed by an accessing system on our website, the data and time our website was accessed, an internet protocol address (IP address), the internet service provider of the accessing system and other similar data and information that helps repel threats in the event that our information technology systems are attacked.

We do not use this general data and information to identify the data subject. Rather, this information is required to deliver our website's contents correctly, to optimize our website's content and advertising for it, to ensure the long-term viability of our information technology systems and our website's technology, and to provide the prosecution authorities with any information required in case of a cyber-attack. This data and information, which is collected anonymously, is therefore statistically analyzed and also evaluated with the objective of increasing data protection and data security at the company in order to ultimately ensure the highest possible degree of protection for the personal data we process. The anonymous data in the server log files is stored separately from any personal data provided by the data subject.

a. Scope of Processing Personal Data

Basically, we collect and use personal data of our users only to the extent required for providing a functioning website and our contents and services. We only collect and use personal data of our users after having obtained the user's consent, unless the processing of the data is permitted by applicable legal provisions.

b. Legal Basis for the Processing of Personal Data

Where we obtain the data subject's consent to the processing of their personal data, the legal basis for processing personal data is Art. 6 (1) lit. (a) of the General Data Protection Regulation of the European Union (GDPR).

Where processing personal data is necessary for the performance of a contract to which the data subject is a party, the legal basis for processing personal data is Art. 6 (1) lit. (b) GDPR. The same applies if the processing is necessary in order to take steps prior to entering into a contract.

Where the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, the legal basis for processing personal data is Art. 6 (1) lit. (c) GDPR.

If the processing of personal data is necessary for the purposes of the legitimate interests pursued by us or by a third party, the legal basis for processing personal data is Art. 6 (1) lit. (f) GDPR, unless above interests are overridden by the interests or fundamental rights and freedoms of the data subject.

c. Erasure of Data and Storage Period

The personal data of the data subject will be erased or blocked when the purpose for which they are collected no longer applies. The personal data may also be stored if the controller is required to do so by European or national legislators under EU regulations, laws, or other provisions, to which the controller is subject. The data will also be blocked or erased when the storage period laid down in the mentioned provisions expires, unless continued storage of the data is necessary for concluding or performing a contract.

IV. Data Collection during the Registration and Login to Bitcoin.de

a. Scope of Data Collection

In order to use the offers provided on Bitcoin.de's marketplace, a registration is necessary and the following data will be collected and stored:

  • Sex
  • Given name, family name
  • Name at birth
  • Date of birth
  • Place of birth
  • Address
  • Nationality
  • Bank details
  • Mobile phone number

In addition, the following data will be collected in the login process:

  • IP address of the accessing computer
  • Date and time of the login

b. Purpose of the Data Collection:

The data are collected and processed for the purpose of carrying out and documenting transactions on the marketplace. Within the scope of documentation obligations imposed on us, we are required to collect the above-mentioned data from our users. Where we successfully broker a deal on bitcoin.de, the bank details and the first and family names will be provided to the contracting parties in contracts transmitted by bitcoin.de for the purpose of processing the payment. In the event that contracts are not performed as agreed, the date of birth, place of birth and the address may additionally be transmitted to contracting parties.

c. Legal Basis:

As the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract, the legal basis for the processing of personal data is Art. 6 (1) lit. (b) GDPR.

Where the processing is necessary for compliance with a legal obligation to which the controller is subject, the legal basis for the processing of personal data is Art. 6 (1) lit. (c) GDPR. In all other cases, the processing of personal data is lawful according to Art. 6 (1) lit. (f) GDPR as it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless said interests are overridden by the interests or fundamental right and freedoms of the data subject which require protection of personal data.

d. Storage Period:

The personal data of the data subject will be erased or blocked when the purpose for which they are collected no longer applies. The personal data may also be stored if the controller is required to do so by European or national legislators under EU regulations, laws, or other provisions, to which the controller is subject.

V. Newsletter

As part of the registration process or later as a registered user, we offer the opportunity to subscribe to our newsletter.

In the context of the subscription procedure, we will request your consent and refer to this privacy policy. As the newsletter will be sent to you based on the consent you have given, the legal basis for this is Art. 6 (1) lit. (a) GDPR.

If you purchase goods or services on our website or use the platform for trading and, in this context, enter and store your e-mail address, it may subsequently be used by us for sending you a newsletter. In such case, the newsletter will only contain direct advertising for our own or similar goods or services.

No data will be transmitted to any third party in connection with the data processing carried out for sending newsletters. The newsletter may also be sent by a service provider acting on our behalf, subject to a data processor agreement. The data will only be used for sending the newsletter and be stored until you opt out of the newsletter, unless we are legally required to continue storing the data.

VI. Data Collection during Visits to the Website

a. Visits to the website without logging in as a registered user

When you visit our website without logging in as a registered user, your data will be collected as described in Section III above.

b. Visits to the website and login as a registered user

When you visit our website and log in as a registered user, the IP address, the date and time of the login, and, if possible, how long you are logged in, and whether or not you have logged out will be recorded in log files. These data are available to users in their personal area.

VII. Use of Cookies

Our webpages use cookies. Cookies are text files that are placed and stored on your computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier for a cookie. It comprises a string of characters that allows websites and servers to identify the specific internet browser where the cookie was placed. This enables the websites and servers to distinguish the individual browser used by the data subject from other web browsers containing other cookies. A specific web browser can be recognized and identified by means of the unique cookie ID.

The use of cookies enables us to provide you with more user-friendly services than we could without placing cookies.

a. Description, Scope and Purpose of the Data Processing

The purpose of using cookies necessary for technical reasons is to make the use of the website easier for the user. Some of the website's functions cannot be offered without the use of cookies, as they need to recognize your browser even after switching pages.

We need cookies for the following applications:

  • Provision of a secure log-in area (marketplace access and online wallet)
  • Applying language settings
  • Memorizing search terms

We do not use the personal data collected by cookies that are necessary for technical reasons for creating user profiles.

In addition, our website uses cookies that enable us to analyze the user's surfing habits.

In this way the following data may be transmitted:

  • Search terms entered
  • Access frequency
  • Use of website features

Analytical cookies are used in order to improve the quality of our website and its contents. Analytical cookies provide information on how the website is used and allow us to continuously optimize our services.

We are using analytical cookies to analyze how and to what extent our services are used, which helps us to further optimize our service our – e.g. with respect to our "answer selection system" which we offer our website visitors when they enter a query using the contact form.

User data collected in this way for analytical purposes will be pseudonymized by technical means. It is therefore impossible to relate the data to the accessing user. The data are not stored together with other personal data of the user.

Our legitimate interest in processing the personal data lies in these purposes pursuant to Art. 6 (1) lit. (f) GDPR.

b. Storage Period, Objection and Deletion Options

Cookies are stored on the user's computer and transmitted by it to our website. As a user, you therefore have full control over the use of cookies. By changing the settings of your web browser, you can disable or restrict the transmission of cookies. Cookies previously stored can be deleted at any time. This can even be done automatically. If you deactivate cookies for our website, you may not be able to fully use all the features of our website. This privacy policy informs you about the use of cookies for analytical purposes and refers to this privacy policy. In this context, we also provide information on how to prevent the storage of cookies by changing the browser settings.

VIII. Data Transmission for Protecting Transactions and Security-Relevant Changes by SMS-mTan-Procedure

In the context of protecting transactions and changes to both security-relevant account data and account settings, the transmission of a user's mobile phone number may be necessary for sending an mTan per SMS. These will be transmitted to processors (service providers) who will send you an SMS / mTan.

IX. Data transmission to Fidor Bank for Express Trade Purposes

a. Description, Purpose and Scope of the Data Processing

The transmission of data to Fidor Bank is a prerequisite for using express trade.

The following data are transmitted to Fidor Bank when reserving money amounts:

  • amount to be reserved
  • reservation period
  • IBAN / account holder

In case of an effective express purchase, we additionally notify the bank that and to whom the purchase price will have to be transmitted from the reserved amount.

In case of a successful express sale, the name of the seller, IBAN and BIC as well as the purchase price will also be transmitted to Fidor Bank to allow them to carry out the transfer of the purchase price.

b. Legal Basis for the Data Processing

As the processing and transmission of data to Fidor Bank is necessary for the performance of a contract, the legal basis is Art. 6 (1) lit. (b) GDPR.

c. Storage Period

The data will be erased as soon as they are no longer needed to achieve the purpose for which they were collected. As these data are also collected to comply with accounting requirements under tax law the storage period is 10 years.

X. Contact Form and E-Mail Contact

a. Description and Scope of the Data Processing

On our website, we provide a contact form which can be used for contacting us by electronic means. In the event that a user makes use of this opportunity, the data entered in the input screen will be transmitted to, and stored by, us. These data are:

  • Topic
  • Subject
  • Name
  • User name
  • E-mail address
  • Your message

Alternatively, you can contact us by e-mail at the address provided. In this case, the personal data transmitted with that e-mail will be stored.

In this context, no data are disclosed to any third party. The data are exclusively used for the purposes of the conversation.

b. Legal Basis for the Data Processing

The legal basis for the processing of the data transmitted via contact form or by sending an e-mail is Art. 6 (1) lit. (f) GDPR. If you send an e-mail with the aim of concluding a contract, Art. 6 (1) lit. (b) GDPR is an additional legal basis for the processing of the data.

c. Purpose of the Data Processing

We will use the personal data entered in the input screen exclusively for dealing with your query. In case you contact us via e-mail, the required legitimate interest in processing the personal data also lies in this purpose.

Other personal data processed during the sending process are used to prevent any abuse of the contact form and to ensure the security of our information technology systems.

d. Storage Period

We erase the data as soon as they are no longer needed to achieve the purpose for which they were collected. Any personal data entered in the input screen of the contact form and those transmitted by e-mail, will be erased as soon as the respective conversation with the user is closed. The conversation will be considered closed when it is clear from the circumstances that the matter concerned has been resolved. If the conversation concerns accounting-related matters transmitted by registered users, the retention period is 10 years.

Any data stored in order to comply with legal obligations or administrative orders are subject to other purposes and will not be erased before the expiry of the storage periods required for those purposes.

e. Objection and Deletion Options

Users have the right to withdraw their consent to the processing of their personal data at any time. Users, who contact us by e-mail, can object to the storage of their personal data at any time. In such case the conversation cannot be continued.

If you chose to object, please send your objection to: [at] bitcoin [dot] de.

All personal data stored in the context of this contact will be deleted in such case, unless they are stored for other reasons.

XI. Transmission of Data to Associated Stores

Users, who use the redirect option to our associated independent stores (like Gold-Shop), can use the identification used in their registration, which means that the store will not need to carry out a further identification process. The transmission of data (name and address, no e-mail address) to the stores effected exclusively at your request is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract, pursuant to Art. 6 (1) lit. (b) GDPR. In addition, the transmission of data is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, and said interests are not overridden by your interests or fundamental rights and freedoms, which require the protection of personal data, pursuant to Art. 6 (1) lit. (f).

XII. Data Processing for the Prevention of Abusive Conduct

With a view to defending and preventing abusive and/or fraudulent conduct with respect to our services and to protecting our users, we analyze the data transmitted to us for anomalies.

XIII. Data Protection Provisions on the Deployment and Use of Google Analytics (with Anonymization Function)

The controller responsible for the data processing has integrated the Google Analytics (with anonymization function) component into this website. Google Analytics is a web analytics service. Web analytics refers to the collection, compilation, and analysis of data on the behavior of visitors to websites. A web analytics service captures, inter alia, data about the website from which a data subject has come (so-called referrer), which subpages of the website are accessed or how often and for how long a subpage is viewed. Web analytics is mainly used for optimizing a website and for carrying out cost-benefit analyses of internet advertising.

The operator of the Google Analytics component is Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

The controller responsible for the data processing uses the web analytics service provided by Google Analytics with the extension "gat.anonymizeIp". This extension ensures that the IP address of the data subject's internet connection is abbreviated, and thereby anonymized, by Google if our website is accessed from a member state of the European Union or from another contracting state of the Agreement on the European Economic Area.

The purpose of the Google Analytics component is to analyze visitor flows on our website. Google uses the data and information generated, inter alia, for analyzing the use of our website, compiling online reports on website activity for us and providing other services relating to the usage of our website.

Google places a cookie on the data subject's information technology system. Information on cookies is provided above. The placing of cookies enables Google to analyze the usage of our website. Whenever a data subject accesses an individual page of the website which is operated by the controller and in which a Google-Analytics component has been integrated, the internet browser of the data subject's information technology system automatically transmits data used for the purpose of online analysis to Google. In the context of this technical process, Google obtains information on personal data, like the IP address of the data subject, which will be used by Google, inter alia, to retrace where visitors come from and their clicks, which subsequently allows to invoice commissions.

Cookies are used to store personal information, like the time when a data subject accessed our website, the location from which the data subject accessed our website, and the frequency of visits to our website by a data subject. Every time a data subject visits our website, these personal data, including the IP address of the internet connection used by the data subject, will be transmitted to Google in the United States. Under certain circumstances, Google may transmit the personal data collected in this technical process to third parties.

The data subject may prevent our website from placing cookies, as described above, at any time by changing the respective settings of the web browser used and thereby lastingly object to the placing of cookies. Said setting in the web browser used would also prevent Google from placing a cookie on the information technology system of the data subject. Furthermore, a cookie placed by Google Analytics may be deleted by means of the web browser or other software programs at any time.

In addition, the data subject has the option to object to and prevent the collection and processing of the data generated by Google Analytics in relation to the use of this website. In order to do so, the data subject must download and install a browser add-on available at  https://tools.google.com/dlpage/gaoptout. This browser-add-on tells Google Analytics through JavaScript that no data and information about the website visits may be transmitted to Google Analytics. The installation of the browser add-on is considered an objection by Google. If the data subject's information technology system is later deleted, formatted or newly installed, the data subject must reinstall the browser add-on to disable Google Analytics. If the browser add-on was uninstalled or disabled by the data subject or any other person attributable to their sphere of competence, the browser add-on may be reinstalled or reactivated.

For more details on Google's applicable privacy policy, please refer to  https://www.google.com/intl/en/policies/privacy/ or http://www.google.com/analytics/terms/us.html. More detailed information about Google Analytics is available at https://www.google.com/analytics/.

As an alternative to installing a browser add-on, especially on browsers of mobile devices, you may also prevent the collection of data by Google Analytics by clicking on the following link: Deactivate Google Analytics. When using this link, you place an opt-out cookie that prevents any future collection of your data when you visit this website. An opt-out cookie only applies to one browser and only to our website and will be placed on your device. If you delete the cookies on that browser you will have to place the opt-out cookie again.

XIV. Data Protection Provisions on the Deployment and Use of Web Fonts (Google Fonts)

Our web pages use external fonts, i.e. Google Fonts. Google Fonts is a service provided by Google Inc. ("Google"). The web fonts are embedded by connecting to a server, usually a Google server in the United States. In this way, the server gets information about which of our websites you have visited. Google will also store the IP address of the browser installed on the device of the visitor to these webpages. For more details please refer to Google's privacy policy, which is available at:

https://www.google.com/fonts#AboutPlace:about
https://www.google.com/policies/privacy/