Privacy Policy
Effective Date: 12-12-2024
This Privacy Policy explains how MEDXCHANGE Spółka z ograniczoną odpowiedzialnością (“MedXchange”, “we”, “us”, “our”) collects, uses, discloses, and protects personal information when you visit and use our website, www.mxch.pl.
We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Who We Are
This website is operated by:
MEDXCHANGE Spółka z ograniczoną odpowiedzialnością ul. Wizjonerów 5, lok. 74
31-356 Kraków, Poland
Company Reg. No.: KRS 0001140868 VAT ID: [Insert VAT ID if applicable]
Authorized as a Virtual Asset Service Provider by the Tax Administration Chamber in Katowice.
If you have any questions, you may contact us at:
Email: [Medxchange@mxch.pl]
2. What Information We Collect
We may collect the following categories of personal data from you:
a) Automatically Collected Data
When you visit our site, we may automatically collect:
- IP address
- Browser type and version
- Device type and OS
- Pages visited and time spent
- Referring URL
- Cookies and tracking data
a) Information You Provide Voluntarily
When you contact us or interact with the site, you may voluntarily provide:
- Name and email address (e.g., through a contact form)
- KYC-related documents (if applicable)
- Communication content
a) Transaction-Related Data
If you initiate a crypto transaction with MedXchange through Binance, we may receive or request:
- Identity verification documents
- Proof of address
- Wallet addresses
- Source of funds documentation
This only occurs in compliance with our AML/KYC obligations (see section 6).
3. How We Use Your Data
We process your personal data for the following purposes:
- To provide access to our services
- To ensure AML/KYC compliance
- To analyze traffic and improve website functionality
- To detect and prevent fraud or misuse
- To respond to inquiries or support requests
- To comply with legal obligations under Polish and EU law
4. Legal Bases for Processing
We rely on the following legal grounds under GDPR:
- Consent – for cookies or marketing (if used)
- Contractual necessity – to deliver services requested by you
- Legal obligation – to comply with AML/KYC and tax laws
- Legitimate interest – to protect and improve our service
5. How We Share Your Data
We may share your data with:
- Binance (as a third-party trading platform)
- Governmental or regulatory authorities (e.g., for AML reporting)
- Authorized service providers (e.g., hosting, compliance tools)
- Legal or tax advisors (where necessary for legal obligations)
We do not sell or rent your data to third parties for marketing.
6. AML/KYC Compliance
As a registered Virtual Asset Service Provider, we are legally required to perform KYC checks on:
- Any transaction equal to or exceeding €1,000, or
- Any transaction flagged as suspicious, regardless of amount
We may request and store identification documents and other verification data. This data is stored securely and only used for regulatory compliance.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy, including legal, regulatory, and compliance purposes.
For AML/KYC purposes, your data may be retained for up to 5 years after the end of your business relationship with us, in line with EU AML directives.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL encryption
- Access controls
- Secure data storage
- Staff confidentiality obligations
While we take reasonable precautions, no method of transmission over the internet is 100% secure.
9. Your Rights Under GDPR
You have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Restrict or object to data processing
- Withdraw your consent at any time (for consent-based processing)
- Lodge a complaint with a data protection authority
To exercise these rights, please contact us at [Medxchange@mxch.pl].
10. Cookies and Tracking
We may use cookies to improve your experience and analyze site usage. You can manage or disable cookies via your browser settings.
More details are provided in our [Cookie Policy] (coming soon).
11. International Transfers
Your personal data may be processed outside the European Economic Area (EEA), particularly when interacting with Binance or other global platforms. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised “Last Updated” date. You are encouraged to review this policy periodically.
13. Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or your personal data, please contact:
MEDXCHANGE Sp. z o.o.
Wizjonerów 5, lok. 74
31-356 Kraków, Poland
📧 Email: Medxchange@mxch.pl
🌐 Website: www.mxch.pl