Privacy Policy
Last updated — 2026-07-30
We inform you of our updated Privacy Policy and of the use given to the personal data you provide to us, including data collected simply by browsing this website.
01Identification of the Controller
Controller: BLACKBAU, S.L.U. (“BLACKBAU”). Registered office: Avenida Doctor Mitjavila, no. 5, Bomosa-Alba building, office 2, Andorra la Vella. NRT: 722560G. Public register: Registre de Societats Mercantils del Principat d'Andorra, Book S-529, Folios 111-120, registration number 27462. Email: Hola@blackbau.com
02Information and Consent
Under Regulation (EU) 679/2016 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD), by accepting this Privacy Policy the user gives informed, express, free and unequivocal consent to the processing of personal data collected through this website, whether via its forms or via cookies. All data requested is mandatory, since the services cannot be provided without processing it; browsing the site remains free of charge. The user warrants that the data provided is true and accurate, and where third-party data is provided, that all necessary consents have been obtained.
03Contact via Form, Email or Chat
Source: the user, through the contact form, the chat window or emails sent to the address shown on the site. Legal basis: Art. 6.1.a) GDPR — consent. Purpose: to handle and answer the user's enquiries. Data: name, surname, email and any further data included in the message. Recipients: no transfers are envisaged, save legal obligation or express consent. International transfers: none envisaged. Retention: strictly as long as necessary, with a maximum of 1 year.
04User Registration
Source: the user, during registration. Legal basis: Art. 6.1.a) GDPR — consent. Purpose: creation of the user account and identification of the user for the provision of tokenized-asset investment services. Data: name and surname; type and number of identity document; date of birth; country of residence; postal address; email; mobile number; associated blockchain wallet address. Recipients: Onyze Digital Assets S.L. (provider); Ursus 3 Capital, A.V. (validation of transactions on regulated tokens); Didit Identity Spain, S.L. (KYC provider). International transfers: none envisaged. Retention: strictly as long as necessary for the purpose collected.
05Identity Verification (KYC) and AML Compliance
Source: the user, during identity verification, including identity documentation and biometric data. Legal basis: Art. 6.1.c) GDPR — compliance with a legal obligation. Purpose: verification of identity — level 1 KYC (0–1,000 €); level 2 (1,000–30,000 €) documentary and biometric verification; level 3 (from 30,001 €) recurring screening against international sanctions lists (AML) — and compliance with anti-money-laundering due diligence duties. Data: identity document data, document image, biometric image, verification and AML screening results. Recipients: Onyze Digital Assets S.L.; Didit Identity Spain, S.L.; competent authorities where required by law. International transfers: none envisaged.
06Commercial and Informative Communications
Source: the user, via the optional checkbox in the registration form (“I agree to receive informative emails from the website”). Legal basis: Art. 6.1.a) GDPR — consent. Purpose: sending communications. Data: name, surname and email. Recipients: no transfers for marketing purposes are envisaged. International transfers: none envisaged.
07Referral Programme
Source: the user, through the referral code assigned to their profile. Legal basis: Art. 6.1.b) GDPR — performance of the service contract under the referral programme. Purpose: sending communications. Data: unique referral code, user identifier and referred account data. Recipients: no transfers envisaged, save legal obligation or express consent. Retention: maximum 1 year.
08User Data
The user warrants that the data provided is true, accurate, complete and up to date, and is liable for any direct or indirect damage arising from a breach of this duty, without prejudice to the right of rectification. Where the data belongs to a third party, the user warrants having informed that party and obtained their authorisation. BLACKBAU cannot guarantee the absolute invulnerability of its systems and accepts no liability for damage caused by third-party alterations to IT systems, electronic documents or files.
09Cookie Policy
In accordance with the GDPR and Law 34/2002 on Information Society Services, all personal data obtained through cookies during use of the website is processed as set out in the Cookie Policy.
10Exercise of Rights
You may exercise your rights of access, rectification, erasure, objection, data portability and restriction of processing directly before BLACKBAU. Requests are answered within a maximum of one (1) month from receipt. Send a message stating your name, surname, email and ID or passport number to Hola@blackbau.com. You may also lodge a complaint with the Spanish Data Protection Agency.
11Acceptance of the Privacy Policy
The user acknowledges and accepts having read and understood this Privacy Policy, whose content constitutes the entire agreement between the user and BLACKBAU regarding the use and processing of their personal information, and expressly agrees to be bound by it in full.
BLACKBAU, S.L.U. — Avenida Doctor Mitjavila, no. 5, Bomosa-Alba building, office 2, Andorra la Vella. NRT: 722560G. Email: Hola@blackbau.com
