Skip to main content
Our full legal disclosure is filed with Malta’s financial regulator under the EU’s MiCA crypto rules: notified to the MFSA on 17 July 2025, published 14 August 2025. Verify the filing (opens in a new tab)

PRIVACY POLICY

What we know about you, and what we do with it.

Last updated: 1 April 2026

In this Privacy Policy, we explain how we process your personal data in the course of providing our services. Please read this Policy carefully. If you have any questions, please contact us at the email address below: info@apraemio.com.

1. General information

Apraemio Ltd., as the data controller, acknowledges the content of this legal notice as binding upon itself. It undertakes to ensure that all data processing related to its activities complies with the requirements set out in this policy, applicable national legislation and the legal acts of the European Union.

You are entitled at any time to object to the Data Controller sending you advertising if the legal basis for the sending of such advertising (as data processing) is the Data Controller’s ‘legitimate interest’.

In matters not covered below, the provisions of the European Union’s General Data Protection Regulation (GDPR) No. 2016/679 and other Hungarian data protection legislation shall apply. The Data Controller reserves the right to amend this Privacy Policy.

Your data is processed by APRAEMIO LTD. (“Data Controller”) (registered office and postal address: Craigmur Chambers, Road Town, Tortola, VG1110, British Virgin Islands; company registration number: 1573637; email address: info@apraemio.com). In the course of our services, we also engage data processors who process your personal data in accordance with our instructions. Our servers are operated by DigitalOcean Holdings, Inc. (contact details: DigitalOcean web hosting, Germany, Frankfurt am Main: digitalocean.com/solutions/web-hosting-germany).

By ‘data processing’ we mean any operation performed on personal data (e.g. recording, storage, analysis, transmission, erasure). By ‘personal data’ we mean data on the basis of which you can be identified either directly (e.g. by your name) or indirectly. All our data processing activities have a purpose, a legal basis and a data retention period. The Data Controller shall not process data if the relevant purpose or legal basis for data processing has ceased to exist, or the relevant data retention period has expired, or the termination of data processing is required by law.

The legal basis for data processing ensures the lawfulness of the data processing.

  • In the case of the legal bases referred to as ‘performance of a contract’ [Article 6(1)(b) of the GDPR] and ‘compliance with a legal obligation’ [Article 6(1)(c) of the GDPR], we definitely require the personal data listed below, as without providing this information you will not be able to use the selected service.
  • In the case of the legal basis known as “consent” [Article 6(1)(a) of the GDPR], you will not suffer any disadvantage if you do not give your consent to the data processing in question and do not provide the personal data requested by the Data Controller.
  • In the case of the legal basis known as “legitimate interest” [Article 6(1)(f) of the GDPR], data processing is necessary for the purposes of the Data Controller’s legitimate interests (e.g. the use of cookies on the website). It is important to note that data processing may also be based on this legal basis if the Data Controller wishes to assert a legal claim against you: the Data Controller will notify you if such data processing takes place.

Please ensure that you only provide the Data Controller with your own personal data (or, where applicable, that of the beneficiary). Please notify the Data Controller immediately if the personal data you have provided changes. The Data Controller accepts no liability for any damage arising from the provision of inaccurate data.

Please use a secure network connection and strong passwords whilst browsing, and please notify the Data Controller immediately if you notice any suspicious activity whilst browsing our website.

Please note that we are not responsible for the data processing practices of other websites or applications accessible via links on our website; therefore, please always check the data processing policies of the sites you visit from our website.

2. Purposes of data processing

The Data Controller processes your personal data as follows.

1. Customer verification

Purpose of data processing: in order to carry out the mandatory customer due diligence measures prior to the purchase of $APRA tokens, the Data Controller processes your personal data as follows.

Personal data processed:

  • natural person identification data (full name, place and date of birth, mother’s maiden name), nationality,
  • address or place of residence (country, postcode, town, street, house number),
  • type and number of identification document, copy of identification document, profile photo appearing on the identification document or taken separately, personal data appearing in the video recording made during customer due diligence,
  • a declaration regarding status as a politically exposed person, customer risk classification level,
  • data confirming the source of funds (or a document certifying this, and any additional personal data contained therein), personal data contained in the customer declaration certifying the source of assets.

Legal basis for data processing: fulfilment of a legal obligation pursuant to Section 6(1)(d) and/or (i) of Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.).

Duration of data processing: for a period of 8 years from the termination of the business relationship or the completion of the transaction, pursuant to Section 56(2) of the Pmt.

2. $APRA token purchase

Purpose of data processing: for the purpose of concluding and performing the contract necessary for the purchase of the $APRA token (including communication during the performance of the contract), the Data Controller processes your personal data as follows.

Personal data processed:

  • full name, address or place of residence, bank account number,
  • the wallet ID associated with the customer (“Purchase ID”),
  • contact details (telephone number, email address, postal address).

Legal basis for data processing: the contract (preparation and) performance.

Details of the bank transfer made for the purpose of the purchase:

  1. Details of the account-holding company: Apraemio Ltd. (registered office: Craigmur Chambers, Road Town, Tortola, VG1110, British Virgin Islands; company registration number: 1573637). Name of the account-holding bank: Column N.A. (registered office: 1 Letterman Drive A-700, San Francisco, CA 94129, USA; SWIFT/BIC code: CLNOUS66).
  2. Details of the account-holding company: Apraemio Ltd. (registered office: Craigmur Chambers, Road Town, Tortola, VG1110, British Virgin Islands; company registration number: 1573637). Name of the account-holding bank: Banking Circle S.A., Denmark (registered office: Lautrupsgade 13-15, 2100 Copenhagen, Denmark; SWIFT/BIC code: SXPYDKKKXXX).

Duration of data processing: until the expiry of the limitation period for obligations arising from the contract, which is typically five years pursuant to Section 6:22(1) of Act V of 2013 on the Civil Code (Ptk.).

3. Contact details

Purpose of data processing: for the purpose of processing and responding to messages sent in connection with our services, the Data Controller processes your personal data as follows.

Personal data processed:

  • full name, email address, telephone number,
  • text of the message (including any additional personal data that may be included in the message).

Legal basis for data processing: preparation (performance) of the contract. ‘Preparation’ of the contract refers to steps taken prior to the potential use of our services (e.g. establishing contact, providing information regarding the selected service, consultation).

Duration of data processing: from the time of contact until the conclusion of the contract; if no contract is concluded, for 6 (six) months from the date of receipt of the message.

4. Newsletter distribution

Purpose of data processing: for the purpose of sending business offers and advertisements relating to our services, and for the purpose of subscribing to our newsletter, the Data Controller processes your personal data as follows.

Personal data processed: name, email address.

Legal basis for data processing: your prior consent.

Duration of data processing: until you unsubscribe from the newsletter (i.e. until you withdraw your consent), or until our newsletter service ceases.

Further information: we use the services of MailerLite, Inc (registered office: 548 Market St, PMB 98174, San Francisco, CA 94104-5401, United States; website: mailerlite.com) to send the newsletter.

3. Principles of data processing

The Data Controller processes personal data in accordance with the law, in a fair and transparent manner (‘lawfulness, fairness and transparency’).

The Data Controller uses personal data exclusively for the purposes set out in this notice, collects it for clearly defined and lawful purposes as specified in this document, and does not process it in a manner contrary to the stated purposes (“purpose limitation”). It is the responsibility and obligation of the data provider that, if they are not providing their own personal data, they must obtain the Data Subject’s prior consent. The data provider is responsible for ensuring that the data is accurate.

The Data Controller shall only request the provision of such personal data from the Data Subject which, in view of the purpose of data processing, is appropriate, relevant and strictly necessary in relation to the specific data processing, and without which the Data Controller would be unable to provide its service or would be unable to provide it in accordance with its undertakings (“data minimisation”).

Data Subjects are responsible for ensuring that the data they provide is true, accurate and up to date. Furthermore, it is the responsibility and obligation of the data provider that, if they are not providing their own personal data, they must obtain the Data Subject’s prior consent. If the Data Subject informs the Data Controller, in accordance with the provisions of this notice, that their data is not accurate, the Data Controller shall ensure that such data is deleted or rectified in accordance with the provisions of this document (“accuracy”).

The Data Controller ensures that personal data is stored in a form that allows the Data Subject to be identified only for as long as is necessary for the processing of the personal data. The Data Controller determines the duration of data storage in accordance with this principle (“limited storage”).

Apraemio Ltd. is committed to protecting the personal data of its customers and partners and considers it of paramount importance to respect its customers’ right to informational self-determination. Apraemio Ltd. treats personal data as confidential and takes all necessary security, information security, technical and organisational measures to guarantee the security of the data. The Data Controller shall take all necessary measures to ensure the secure and intact processing of data and the establishment and operation of the data processing systems required for this purpose, as well as to protect personal data from misuse and loss (“integrity and confidentiality”).

The Data Controller is responsible for compliance with data protection principles and must be able to demonstrate such compliance (“accountability”).

4. Your rights in relation to data processing

You may exercise the following rights at any time by sending a message to the Data Controller’s email address above. In order to filter out unauthorised requests, the Data Controller may ask you for additional information necessary for identification. The Data Controller endeavours to respond to your request within 30 days: this deadline may be extended by up to 2 months in the case of complex requests. The Data Controller will notify you if, for any reason, your request cannot be fulfilled.

  • Access to your personal data: you may request information at any time regarding the details of data processing (e.g. what personal data the Data Controller processes, for what purpose and how).
  • Rectification: you may request that the Data Controller corrects or supplements any personal data it may have processed inaccurately or incompletely.
  • Withdrawal of consent: you may withdraw your previously given consent to the processing of your personal data at any time, unconditionally and free of charge, if ‘consent’ is specified as the legal basis for data processing. However, the withdrawal of consent does not affect the lawfulness of the Data Controller’s data processing prior to the withdrawal.
  • Request for erasure: you may request that we erase some or all of your personal data processed by us. A request for erasure may not be possible, or may only be possible to a limited extent, in cases where the legal basis for data processing is indicated as “compliance with a legal obligation”.
  • Objection to data processing: you may object to the Data Controller sending you advertising, or where the legal basis for data processing is indicated as “legitimate interest”. In the event of an objection, you may also request that the Data Controller restrict the data processing to which the objection relates to data storage only, until the Data Controller has investigated the circumstances of the objection. If the objection is justified, we will no longer process the personal data to which the objection relates.
  • Request to restrict data processing: you may request that the processing of your personal data be restricted if you believe that the processing is unlawful or that the data being processed is inaccurate. You may also request that processing be restricted if the Data Controller would otherwise erase the data, but you still require it (e.g. to assert your legal claims).
  • Data portability: you may request that the Data Controller transfer your personal data – processed on the legal basis of ‘consent’ or ‘performance of a contract’ and automatically – to you or to another data controller designated by you.
  • Lodging a complaint: if you believe that the Data Controller has breached the provisions of the GDPR or other data protection legislation, you may lodge a complaint with the National Authority for Data Protection and Freedom of Information [registered office: 1055 Budapest, Falk Miksa utca 9-11; email address: ugyfelszolgalat@naih.hu; website: naih.hu; telephone: +36 (1) 391-1400; fax: +36 (1) 391-1410].
  • Taking legal action: if you believe that the Data Controller has infringed your rights during data processing, you are entitled to take legal action before the court of your choice – either at your place of residence or your place of stay. Further information regarding court proceedings can be found here: birosag.hu.

5. Use of cookies

We use several cookies that measure and analyse website usage to improve our website. You can find further information on data processing related to cookies via the cookie pop-up window on the website, and in the Cookie Policy.

  • ‘Cookies’ are small files sent by our website and stored in your browser. Each cookie has its own identifier, which allows us to recognise new and returning visitors to the website (including you). Cookies also store information about each visit, which helps us to further improve the website’s functionality.
  • Disabling cookies: you can disable the use of cookies at any time via your browser settings (usually under the ‘Help’ menu). Please note that if you disable cookies, the website may not function properly.
  • Essential cookies: these cookies are necessary for the website to function. The Data Controller uses these cookies on the legal basis of its legitimate interest, pursuant to Section 13/A(3) of Act CVIII of 2001 on certain issues relating to electronic commerce services and information society services (Ekertv.), which means that your consent is not required for the use of such cookies.
  • Statistical or analytical cookies: we use these cookies to measure which subpages you have viewed during a session and which service you use most frequently. (The term ‘session’ here refers to the time you spend on the website between opening and closing it.) We use these statistical and analytical cookies on the basis of your consent, which you can give via the cookie pop-up window that appears when you visit the website.
  • Cookies that facilitate the use of the website (convenience cookies): these cookies make using the website more convenient (e.g. your personal data previously entered in a form is displayed when you return to it). We use these convenience cookies based on your consent, which you can provide via the cookie pop-up that appears when you visit the website.