1. Data Controller
The controller of your personal data is AMADEUS CASTELLUM AG, a company incorporated under the laws of the Federal Republic of Germany (hereinafter "AMADEUS", "we", "us").
Registered office: Thurn-und-Taxis-Platz 6, 60313 Frankfurt am Main, Germany.
Contact for privacy matters: privacy@amadeus-wallet.com
2. Categories of Data Collected
- Identity data: full name, date of birth, nationality, country of residence.
- KYC data: government-issued ID, selfie for liveness check, proof of address.
- Contact data: email address, optional phone number.
- Technical data: IP address, device model, operating system, browser, app version, session timestamps.
- Transactional data: on-chain addresses, amounts, timestamps, transaction hashes, counterparties (public blockchain data).
- Support data: content of communications with our support team.
We never store your Seed Phrase or private keys. They are generated and encrypted locally on your device and never transmitted to our servers.
3. Purposes and Legal Basis (GDPR Art. 6)
- Provision of the Service — contractual performance (Art. 6(1)(b)).
- KYC/AML compliance — legal obligation under German Money Laundering Act (GwG) and EU AMLD (Art. 6(1)(c)).
- Security, fraud prevention, SOC monitoring — legitimate interest (Art. 6(1)(f)).
- Marketing communications — consent (Art. 6(1)(a)), revocable at any time.
- Analytics (aggregated, non-identifying) — legitimate interest (Art. 6(1)(f)).
4. Retention Periods
- KYC records: 10 years after end of the business relationship (GwG § 8).
- Transactional data: 10 years for accounting and AML purposes.
- Technical logs: 24 months, then anonymized.
- Support communications: 3 years.
- Marketing consent records: until consent is withdrawn plus 3 years for evidence.
5. Recipients and Subprocessors
Your data may be shared with the following categories of recipients:
- KYC providers (e.g. Sumsub, Onfido, Veriff).
- Cloud infrastructure providers within the EU or under adequacy decisions.
- Payment and on-ramp providers when you use fiat services.
- Security Operations Center (SOC) and fraud-monitoring providers.
- Auditors, legal counsel, and tax advisors bound by professional secrecy.
- Competent authorities, when required by law.
A current list of subprocessors is available on request.
6. International Transfers
Where personal data is transferred outside the European Economic Area, the transfer is protected by Standard Contractual Clauses ("SCCs") approved by the European Commission, or by adequacy decisions.
7. Your Rights (GDPR Art. 15–22)
- Right of access to your personal data.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent at any time (without affecting past processing).
- Right to lodge a complaint with a supervisory authority — competent authority in Germany: the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI).
Exercise your rights by contacting privacy@amadeus-wallet.com.
8. Automated Decision-Making
We use automated screening (sanctions lists, PEP checks, transaction monitoring) to comply with AML obligations. Adverse decisions can always be reviewed by a human upon request.
9. Security Measures
We implement technical and organizational measures aligned with ISO/IEC 27001, including: AES-256 encryption at rest, TLS 1.3 in transit, Hardware Security Modules (HSM) for key management, 24/7 SIEM monitoring, annual penetration testing, role-based access controls, and a documented incident response plan.
10. Children
The Service is not directed to persons under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.
11. Cookies and Tracking
Our website uses only strictly necessary cookies by default. Optional analytics and marketing cookies are set only after your explicit consent via the cookie banner. See our Cookie Policy for details.
12. Changes to this Policy
We will notify material changes at least 30 days in advance by email or in-app notification.
13. Contact
AMADEUS CASTELLUM AG
Thurn-und-Taxis-Platz 6, 60313 Frankfurt am Main, Germany
Data Protection Officer: dpo@amadeus-wallet.com
Privacy inquiries: privacy@amadeus-wallet.com