Olbra

LEGAL

Privacy Policy

Last reviewed: 22 July 2026 · version 2026-07-22.1

1. Who we are

Olbra ApS (CVR 39729482), Krudtløbsvej 12, 1439 København K, Denmark (“Olbra”, “we”, “our”) is the data controller for the personal data processed through this onboarding platform.

Olbra ApS is an authorised e-money institution supervised by Finanstilsynet, the Danish Financial Supervisory Authority, and is the issuer of the e-money tokens EURY, PLNY and USDY. Further identification details are set out in our imprint.

For any data-protection request, contact [email protected].

2. What data we collect and why

We collect the following categories of personal data for the purposes of onboarding, identity verification, and ongoing anti-money-laundering and counter-terrorist-financing (AML / CTF) monitoring:

  • Identification data — full name, date of birth, nationality, residential address, contact details.
  • Identity document images — passport, national ID, or residence permit.
  • Selfie or liveness image — used to confirm the person presenting the identity document.
  • Employment and income data — status, occupation, employer, income range.
  • Source of funds information and supporting evidence.
  • Politically exposed person (PEP), sanctions and adverse-media screening results.
  • Intended use of e-money tokens, expected counterparties and transaction geographies.
  • Bank account details (IBAN) used to fund your account and to receive redemption payouts.
  • Blockchain wallet addresses you submit, and the on-chain analytics results relating to them.
  • Communications you exchange with our team.
  • Technical data necessary to operate the service securely — IP address and user agent recorded against security-relevant events such as sign-in and acceptance of these terms.

3. Legal bases

We process your personal data on the following GDPR legal bases:

  • Article 6(1)(b) — performance of the contract that governs your onboarding and the issuance and redemption of e-money tokens.
  • Article 6(1)(c) — compliance with our legal obligations, in particular under the Danish Anti-Money Laundering Act (hvidvaskloven), Regulation (EU) 2023/1114 (MiCA), and the Danish Payments Act.
  • Article 6(1)(f) — our legitimate interest in fraud prevention, information security and the integrity of the platform.
  • Article 9(2)(g) and Article 10, where screening reveals data concerning criminal convictions or offences, processed only to the extent AML law requires.

4. Who receives your data

We share personal data with the following categories of recipients, each bound by written data-processing terms under Article 28 GDPR where they act as our processor:

  • Group operating subsidiaries — in the EEA and in the United States, performing day-to-day KYC review, compliance operations and customer support on our behalf as processors.
  • Identity-verification providers — Sumsub (Sum and Substance Ltd), for document authentication, liveness checks and PEP / sanctions screening, where that route is used for your application.
  • Blockchain analytics providers — for sanctions and illicit-finance screening of the wallet addresses you submit.
  • Resend, Inc. — United States. Transactional email delivery; transfers protected by Standard Contractual Clauses and accompanying supplementary measures.
  • Hetzner Online GmbH — Germany (EEA). Hosting of the application, the customer database and identity-document storage.
  • Credit institutions — holding the safeguarded reserve and executing the bank transfers that fund or settle your account.
  • Competent authorities on lawful request — including Finanstilsynet, Datatilsynet, the Danish Money Laundering Secretariat, and tax authorities.

We do not sell personal data, and we do not share it for advertising purposes.

5. International transfers

The platform, its database and all identity-document storage are located in the EEA.

Where personal data is transferred outside the EEA — to our United States operating subsidiary acting as processor, and to Resend as our email processor — the transfer is made under the European Commission’s Standard Contractual Clauses, together with a transfer-impact assessment and supplementary technical measures appropriate to the categories of data involved. You may request a copy of the relevant safeguards from the address in section 12.

6. Automated decision-making

Wallet addresses you submit are screened automatically against sanctions lists and illicit-finance indicators. Where screening returns a sanctions match or a high-risk verdict, the address is rejected automatically, without human involvement. This is a decision within the meaning of Article 22(1) GDPR: it prevents that address from receiving tokens.

It is carried out because it is necessary for entering into or performing our contract with you and to comply with our legal obligations under AML and sanctions law (Article 22(2)(a) and (b)).

You have the right to obtain human intervention, to express your point of view, and to contest the outcome. Contact us at the address in section 12 and a member of our compliance team will re-review the screening result and the decision. Your account, your other addresses and your existing balances are not affected by the rejection of a single address.

Approval of your KYC application itself is not automated: every dossier is decided by a human reviewer.

7. How long we keep your data

We retain personal data for as long as the law requires, and no longer than is necessary for the purposes for which it was collected:

  • KYC records (identity documents, liveness images, source-of-funds evidence, PEP / sanctions screening results) — five years following the end of our customer relationship, as required by the Danish Anti-Money Laundering Act. The retention period is not extended beyond five years unless a specific legal obligation or an ongoing investigation requires it.
  • Accounting and transaction records — five years from the end of the financial year to which they relate, under the Danish Bookkeeping Act.
  • Audit logs (staff actions, status transitions, access to KYC data, acceptance of these terms) — five years, for AML and regulatory-audit purposes.
  • Communications (support email and ticket history) — two years from the last interaction, extended to five years where the communication is relevant to an AML investigation.
  • Session cookies — cleared on sign-out; otherwise a rolling 30-day expiry with sliding renewal on activity.

Account data is deleted on request, subject to the AML retention obligations above and to any ongoing legal, regulatory or investigative hold. Where we cannot delete, we restrict processing so the data is retained only to meet the obligation that requires it.

8. Your rights

Under the GDPR you have the right to access your personal data, to have inaccurate data rectified, to request erasure, to restrict or object to processing, and to receive the data you provided to us in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

The erasure right is limited by the statutory AML retention periods in section 7 — we cannot delete records the law requires us to keep. We will tell you which records are affected and why.

To exercise any of these rights, write to [email protected]. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is Datatilsynet, the Danish Data Protection Agency. You may instead complain to the supervisory authority of the EU member state where you live or work, or where you consider the infringement occurred.

9. Security

We protect personal data with encrypted transport (TLS), encrypted storage of identity documents, role-based access control for staff, four-eyes approval on sensitive operations, and audit logging of every KYC-related staff action. Access to identity documents is limited to personnel who need it to perform a review.

No system is perfectly secure. Where a personal-data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as Article 34 GDPR requires.

10. Cookies

We use strictly necessary cookies only, for session management and request authentication. We use no analytics, advertising or third-party tracking cookies, which is why this application shows no cookie banner — strictly necessary cookies do not require consent. Details are in our cookie policy.

11. Children

This platform is not available to anyone under 18. We do not knowingly collect personal data from children, and age is verified as part of identity verification. If we learn that we hold data relating to a child, we delete it, subject to any overriding legal obligation.

12. Changes and contact

We will notify you by email of material changes to this policy at least 30 days before they take effect, and will ask you to acknowledge the updated version where it changes the basis on which we process your data.

For any privacy request or question about this policy, contact [email protected], or write to Olbra ApS, Krudtløbsvej 12, 1439 København K, Denmark.