GDPR Compliance Statement
Last Updated: September 1, 2024
This GDPR Compliance Statement complements our Privacy Policy and provides specific regulatory information for residents of the European Economic Area (EEA) and the United Kingdom (UK) regarding how Squaby.com (“we,” “our,” or “us”), collects, uses, and safeguards personal data across squaby.com and all subdomains (including swap.squaby.com and buy.squaby.com) in accordance with the General Data Protection Regulation (GDPR).
Data Controller
For the purposes of the GDPR, the Data Controller for personal data collected directly through our educational and analytical infrastructure is the entity operating the Squaby.com platform.
For third-party financial interfaces integrated into our platform (such as the ChangeNOW liquidity swap widget), the respective third party acts as an independent Data Controller regarding any transactional or identity verification data (KYC/AML) you submit directly within their interface.
Legal Basis for Processing Personal Data
We process personal telemetry exclusively when we have a valid legal basis under Article 6 of the GDPR:
- • Legitimate Interests: To analyze aggregate website telemetry, maintain cross-subdomain security protocols, prevent fraudulent bot activity, and optimize our educational resources (Squaby Academy) and technical market interfaces.
- • Consent: When you explicitly contact us or opt-in to direct communications. You retain the right to withdraw consent at any time.
- • Legal Obligation: When processing is mandatory to comply with applicable statutory or regulatory requirements.
Stateless & Non-Custodial Data Isolation
Squaby is engineered on a strictly non-custodial and stateless architecture. We do not process, store, or log private cryptographic keys, seed phrases, or client-side educational simulation parameters evaluated inside Squaby Academy.
Your Data Protection Rights Under GDPR
Under Articles 15-22 of the GDPR, residents of the EEA and UK possess the following rights regarding their personal data:
• Right of Access (Article 15): Right to request copies of your personal telemetry held by us.
• Right to Rectification (Article 16): Right to request correction of inaccurate or incomplete data.
• Right to Erasure / “Right to be Forgotten” (Article 17): Right to request deletion of your personal data under specific conditions.
• Right to Restrict Processing (Article 18): Right to request restriction of data processing under statutory conditions.
• Right to Data Portability (Article 20): Right to request data transfer to another organization or directly to you in a structured format.
• Right to Object (Article 21): Right to request objection to processing based on legitimate interests or direct communications.
To exercise any of these rights, please submit a request to our support team. We will respond within one calendar month as mandated by GDPR regulations.
International Data Transfers
When data is processed outside the EEA or UK, Squaby ensures appropriate safeguards are applied—including standard contractual clauses (SCCs) approved by the European Commission—to guarantee an equivalent level of data protection.
Data Retention
We retain personal telemetry only for as long as necessary to fulfill the operational purposes outlined in our Privacy Policy or to satisfy legal and accounting requirements. Unnecessary telemetry is routinely deleted or anonymized.
Contact & Supervisory Authority
If you have questions regarding this GDPR Compliance Statement, wish to contact our Data Protection Officer, or want to exercise your data rights, please contact us at:
- Data Controller: Squaby.com
- Email: support@squaby.com
Residents of the EEA or UK also retain the legal right to lodge a complaint with their local supervisory authority for data protection.