Last updated: 14 April 2026
Zlatcoin is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your personal information when you use the Zlatcoin platform. This policy is compliant with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable Serbian data protection law.
Data Controller
ALEKSANDAR ZLATKOVIĆ PR AGENCIJA ZA VEB PORTALE SEBN OBRENOVAC
PIB: 108083132 · Matični broj: 63200859
Miloša Obrenovića 135/2, Obrenovac, Beograd-Obrenovac, Republika Srbija
Contact: [email protected]
| Category | Data Points | Purpose |
|---|---|---|
| Account Data | Name, email address, OAuth identifier | Account creation and authentication |
| KYC Data | Government ID document, selfie photograph, date of birth | Identity verification, AML compliance |
| Financial Data | ZLC balance, transaction history, subscription plan | Service provision, billing |
| API Credentials | Encrypted exchange API keys (AES-256-GCM) | Exchange integration (stored encrypted, never transmitted) |
| Usage Data | IP address, browser type, pages visited, timestamps | Security, analytics, fraud prevention |
| Payment Data | Billing address, last 4 digits of card (via Stripe) | Subscription billing (full card data held by Stripe, not us) |
We process your personal data on the following legal bases under GDPR Article 6: (a) Contract performance — processing necessary to provide the Service you have requested; (b) Legal obligation — processing required to comply with AML/KYC regulations; (c) Legitimate interests — processing for fraud prevention, security, and service improvement; and (d) Consent — for optional communications such as newsletters, which you may withdraw at any time.
We retain your personal data for as long as your account is active or as needed to provide the Service. KYC documents are retained for a minimum of 5 years following account closure, as required by AML regulations. Transaction records are retained for 7 years for accounting and tax compliance purposes. You may request deletion of your account and associated data, subject to our legal retention obligations.
We do not sell your personal data. We may share your data with the following categories of third parties:
Under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
We implement appropriate technical and organizational measures to protect your personal data, including AES-256-GCM encryption for sensitive credentials, HTTPS-only communication, rate limiting, and access controls. No system is completely secure, and we cannot guarantee absolute security of your data.
For privacy-related inquiries or to exercise your rights, contact our Data Protection Officer at: [email protected]