Privacy Policy

Effective Date: 12-12-2024

This Privacy Policy explains how MEDXCHANGE Spółka z ograniczoną odpowiedzialnością (“MedXchange”, “we”, “us”, “our”) collects, uses, discloses, and protects personal information when you visit and use our website, www.mxch.pl.

We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Who We Are

This website is operated by:

MEDXCHANGE Spółka z ograniczoną odpowiedzialnością ul. Wizjonerów 5, lok. 74

31-356 Kraków, Poland

Company Reg. No.: KRS 0001140868 VAT ID: [Insert VAT ID if applicable]

Authorized as a Virtual Asset Service Provider by the Tax Administration Chamber in Katowice.

If you have any questions, you may contact us at:

Email: [Medxchange@mxch.pl]

2. What Information We Collect

We may collect the following categories of personal data from you:

a)  Automatically Collected Data

When you visit our site, we may automatically collect:

  • IP address
  • Browser type and version
  • Device type and OS
  • Pages visited and time spent
  • Referring URL
  • Cookies and tracking data
a)  Information You Provide Voluntarily

When you contact us or interact with the site, you may voluntarily provide:

  • Name and email address (e.g., through a contact form)
  • KYC-related documents (if applicable)
  • Communication content
a)  Transaction-Related Data

If you initiate a crypto transaction with MedXchange through Binance, we may receive or request:

  • Identity verification documents
  • Proof of address
  • Wallet addresses
  • Source of funds documentation

This only occurs in compliance with our AML/KYC obligations (see section 6).

3.  How We Use Your Data

We process your personal data for the following purposes:

  • To provide access to our services
  • To ensure AML/KYC compliance
  • To analyze traffic and improve website functionality
  • To detect and prevent fraud or misuse
  • To respond to inquiries or support requests
  • To comply with legal obligations under Polish and EU law

4.  Legal Bases for Processing

We rely on the following legal grounds under GDPR:

  • Consent – for cookies or marketing (if used)
  • Contractual necessity – to deliver services requested by you
  • Legal obligation – to comply with AML/KYC and tax laws
  • Legitimate interest – to protect and improve our service

5.  How We Share Your Data

We may share your data with:

  • Binance (as a third-party trading platform)
  • Governmental or regulatory authorities (e.g., for AML reporting)
  • Authorized service providers (e.g., hosting, compliance tools)
  • Legal or tax advisors (where necessary for legal obligations)

We do not sell or rent your data to third parties for marketing.

6.  AML/KYC Compliance

As a registered Virtual Asset Service Provider, we are legally required to perform KYC checks on:

  • Any transaction equal to or exceeding €1,000, or
  • Any transaction flagged as suspicious, regardless of amount

We may request and store identification documents and other verification data. This data is stored securely and only used for regulatory compliance.

7.  Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy, including legal, regulatory, and compliance purposes.

For AML/KYC purposes, your data may be retained for up to 5 years after the end of your business relationship with us, in line with EU AML directives.

8.  Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • SSL encryption
  • Access controls
  • Secure data storage
  • Staff confidentiality obligations

While we take reasonable precautions, no method of transmission over the internet is 100% secure.

9.  Your Rights Under GDPR

You have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Restrict or object to data processing
  • Withdraw your consent at any time (for consent-based processing)
  • Lodge a complaint with a data protection authority

To exercise these rights, please contact us at [Medxchange@mxch.pl].

10.  Cookies and Tracking

We may use cookies to improve your experience and analyze site usage. You can manage or disable cookies via your browser settings.

More details are provided in our [Cookie Policy] (coming soon).

11.  International Transfers

Your personal data may be processed outside the European Economic Area (EEA), particularly when interacting with Binance or other global platforms. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent.

12.  Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised “Last Updated” date. You are encouraged to review this policy periodically.

13.  Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or your personal data, please contact:

MEDXCHANGE Sp. z o.o.

Wizjonerów 5, lok. 74

31-356 Kraków, Poland

📧 Email: Medxchange@mxch.pl

🌐 Website: www.mxch.pl