Download our zondacrypto
app and start investing now!
Legal
The data controller is BB Trade Estonia OÜ, with its registered office in Harju maakond, Tallinn, Lasnamäe linnaosa, Tähesaju tee 9, 13917 ESTONIA (office no. 10, 2nd floor), incorporated under Estonian law and registered in the Register of Entrepreneurs of the Ministry of Justice of the Republic of Estonia with the number 14814864; share capital: EUR 350.000.00, fully paid-up, (hereinafter referred to as the ‘Controller’).
The Controller takes care to ensure a high standard of protection of the users, interested parties and visitors to www.zondacrypto.com This Privacy Policy, hereinafter the ‘Policy’, sets forth the rules for the collection, processing and use of the personal data of the website’s users, interested parties and visitors.
The purpose of this Policy is primarily to inform the users, visitors and interested parties about their rights in relation to the processing of their data by the Controller.
In our activities we commit to comply with this Policy and with the requirements of the provisions of the law in force, such as Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter ‘GDPR’) and the Estonian Act on Personal Data Protection of 12 December 2018.
I. Definitions
Whenever this Policy mentions:
II. Categories of data processed
The Controller collects and processes the following categories of personal data:
III. Legal basis and purpose of processing
The legal basis for data processing by the Controller is:
The provision of Personal data by users is voluntary but is required in order to be able to use the Controller’s services provided via https://zondacrypto.com
In the majority of cases, we obtain the data directly from you via our website, which you visit, and by tracing your activity on it, as well as your provision of the data necessary in order to register an account and authenticate your identity on our website.
The personal data of persons visiting the Controller’s website shall be processed starting from your visit to the website. If you do not accept this Policy, please cease any further activity and leave the site.
In remaining cases, we process such personal data as you provide when sending requests via our contact form.
IV. Automated processing decision
Personal data of Users are partially subject to an automated processing decision when verification of the User's account on the site https://zondacrypto.com using the Onfido program (Onfido Limited). The Onfido program, in an automated manner, recommends if the User's verification can be approved, denied or reassigned for manual verification by the Controller. Therefore, the User's verification process is not fully automated, as the final decision about establishing or not establishing a business relationship is made by the Controller. Your submission to the above-mentioned verification process is necessary to use the services of the Controller provided by the website https://zondacrypto.com, including primarily the performance of the contract by the Data Controller which, according to Art. 22 sec. 2, point a of GDPR excludes your right to request the exemption for you from automated processing of Personal Data.
V. Your rights
In the context of the processing of your Personal data, you have the following rights:
If you want to exercise any of the above-described rights or you have any questions concerning the processing of your data, please contact us at
For security reasons, we may require your requests to be made in written form. We have the right to decline your requests if we have reasonable grounds to believe that they are unfair, impossible to comply with or could threaten the privacy of others.
If you believe that we are processing your personal data in violation of the provisions in force, you always have the right to lodge an objection with the supervisory body – the Estonian Data Protection Inspectorate at 39 Tatari, 10134 Tallinn, Estonia.
VI. Data transfer
If necessary, the Controller may transfer your data to the following third parties for processing:
The Controller may enter into written data processing contracts with another entity (processor). The right to enter into such contracts arises from the provisions of the law. Processors may include, without limitation: IT service providers, auditors, accounting firms, outsourced workforce providers, customer service software providers, e-mail operators (Google Inc.), server hosting providers.
Processors shall be contractually required to implement appropriate technical and organizational measures in order to protect the data of interested persons and users and to process such data only in accordance with the Controller’s instructions.
For the purpose of registering an account on https://zondacrypto.com and for verification of your identity, your data shall be transferred for processing to entities providing the authentication of scans of documents as a service (Onfido Limited, LexisNexis Risk Solutions Europe Limited, Fully Verified OU).
In addition, for the purpose of sending you, as Users and Clients, email messages, your Personal Data will be entrusted to the mailing service provider, Insider Services UK Limited.
Taking the above into account, therefore, we inform you that the processors, namely Onfido Limited and Insider Services UK Limited, are based in a third country within the meaning of the GDPR, i.e. the United Kingdom. However, the European Commission has formally confirmed that the United Kingdom of Great Britain and Northern Ireland provides an adequate level of protection of personal data, allowing the free transfer of personal data from the European Economic Area without the need for additional authorisations or the implementation of additional safeguards under Chapter V of the GDPR.
Additionally, please be informed that the data controller transfers your personal data to the business partner - Intercom R&D Unlimited Company (2nd Floor, Stephen Court, 18-21 Saint Stephen's Green, Dublin, Ireland) oraz Intercom, Inc. (55 2nd Street, 4th Fl., San Francisco, CA 94105, USA), as well as other companies from INTERCOM group, while you use the chat on the website https://zondacrypto.com. Currently, the USA does not ensure an adequate level of protection of your data (mainly due to the loss of legal force of the Privacy Shield) due to the lack of a decision by the European Commission regarding the determination of an adequate level of personal data protection, and we do not provide appropriate safeguards specified in art. 46 GDPR, including that we have not concluded standard contractual clauses with the data recipient, and we do not have binding corporate rules. Therefore, we would like to inform you that due to the lack of appropriate safeguards, there is a risk of insufficient protection of your data. In this case, the basis for the transfer of personal data is your voluntary consent in accordance with the art. 49 sec. 1 p. A of GDPR.
Moreover, your personal data may be disclosed to competent public authorities if required by the current provisions of the law.
Your personal data may be disclosed to the Controller’s affiliates (companies with capital or personal ties) – viz. Orion Software sp. z o. o. based in Poland, Expofer Servis House s. r. o. based in Czech Republic, to the extent necessary for business collaboration and the performance of contractual obligations.
To track your activity on our website, we use tools such as Google Analytics, Google Search Console, Google Tag, AHRefs, SEMRush, KW Finder, Screaming From, and SERPRobot. They are, however, tools which are used only to collect statistical data and do not collect any of your Personal data.
VII. Security measures
Your personal data are stored and protected in accordance with the principles set out in the provisions of the law in force. The Controller undertakes appropriate measures to:
Taking into accounting the current state of technology, costs, nature, scope, context and purposes of the Processing operations, as well as the rights and freedoms of individuals, such activities may include, without limitation, Pseudonymization and encryption of personal data, measures ensuring confidentiality, integrity, availability and resilience, restoration measures, as well as procedures for regular testing, evaluation and assessment of the effectiveness of the security measures used.
VIII. Storage period
Having regard to the overriding principles of the GDPR and especially the principles of restricting the purpose, storage and scope of data, we process your data only for a period no longer than necessary to achieve the purposes of processing and no longer than permitted by the provisions of the law. After achieving the purpose of processing, your data shall be erased, as long as the provisions of the law allow this to be done. Depending on the legal basis for processing, different storage periods may apply.
Your data shall be stored until the statute of limitation runs out on any claims or until the legal obligation to store your data expires (especially obligations arising from the AML Directive and the AML Act).
The personal data of interested parties shall be stored until they withdraw their consent or until the Controller’s response (as long as this is possible in the light of the provisions of the law).
Users and Client’s personal data shall be stored for the duration of the contract, until the claims expire and for 5 years after the end of the business relationship/collaboration.
Visitor’s Personal data, who will not be qualified as Users, Clients and Interested parties, will be stored in compliance with applicable Cookies Policy.
IX. Age policy
Our services are not intended for persons younger than eighteen (18) years of age. We have no intention of processing their personal data. If you are younger than 18, do not use the Controller’s services and do not send us any information about yourself. If we become aware that we have been processing the personal data of a person younger than 18, we shall erase such data as soon as possible.
X. Modifications
The Controller is allowed to amend this Privacy Policy at any time. You shall be notified of any amendments by publication of an updated, modified Privacy Policy on the Controller’s website. It is recommended to read through the contents of the Privacy Policy regularly.