Privacy Policy

Last updated: 1 September 2026

Waveform Services OÜ · Registry code 17205686
MB Wallet Connect is a service operated by Waveform Services OÜ, a private limited company registered in Estonia under the Estonian Commercial Register, registry code 17205686.
Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia
Contact: privacy@mbwalletconnect.com

Contents

  1. Who we are and data controller
  2. Scope of this policy
  3. Personal data we collect
  4. How we use your data and legal bases
  5. Who we share your data with
  6. International transfers
  7. How long we keep your data
  8. Your rights under the GDPR
  9. Automated decision-making
  10. Cookies
  11. How we protect your data
  12. Children
  13. Changes to this policy
  14. Contact

1. Who we are and data controller

MB Wallet Connect is a service operated by Waveform Services OÜ, a private limited company registered in Estonia under the Estonian Commercial Register, registry code 17205686. Our registered address is Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia. In this Privacy Policy, "we", "us", and "our" refer to Waveform Services OÜ, and "the service" refers to MB Wallet Connect, available at https://mbwalletconnect.com.

Waveform Services OÜ is the data controller for the personal data described in this policy, meaning that we determine the purposes and means of processing your personal data. Where our regulated partners process your data as controllers in their own right — for example, when a licensed financial institution opens and administers a euro account in your name — their own privacy notices also apply to that processing.

For any question about this policy or about how we handle your personal data, contact us at privacy@mbwalletconnect.com.

2. Scope of this policy

This policy applies to personal data we process when you visit our website, create an account, use the MB Wallet Connect wallet, complete identity verification, or use the fiat account and conversion services made available through the service. It is written to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Estonian law, including the Estonian Money Laundering and Terrorist Financing Prevention Act ("AML/CFT law").

Two aspects of the service shape what data we process:

This policy does not apply to third-party websites, decentralised applications, or blockchain networks that you interact with through the wallet. Those are operated independently of us.

3. Personal data we collect

3.1 Account data

When you create an account we collect your email address, a display name if you choose to set one, authentication credentials (stored in hashed form), and your account preferences and settings.

3.2 Identity and KYC data

Before regulated fiat services can be provided, applicable AML/CFT law requires us and our partners to verify your identity. For this purpose we collect and process:

3.3 Financial data

When you use the fiat services we process the personal euro account details (IBAN) issued to you by licensed third-party financial institutions, records of your fiat deposits and withdrawals, transaction amounts, dates, references and counterparty details, and records of conversions between euros and digital assets carried out through our regulated partners.

3.4 Blockchain data

We process the public blockchain addresses associated with your wallet and data about on-chain transactions linked to those addresses, including for transaction monitoring required by AML/CFT law. Please note an important limitation: blockchain addresses and on-chain transactions are recorded on public, decentralised ledgers that are, by design, permanent and immutable. This information is publicly visible to anyone, is not held on our systems alone, and cannot be altered or erased by us. Rights such as erasure and rectification cannot be exercised against data recorded on a public blockchain.

3.5 Technical and usage data

When you use the website or the service we automatically collect technical data such as your IP address, device type and identifiers, operating system, browser type, language settings, access timestamps, pages viewed, and diagnostic and security logs, including records of failed login attempts.

3.6 Communications

When you contact us — for example by email to our support address — we keep a record of the correspondence, including your contact details, the content of the messages, and any attachments you send.

4. How we use your data and legal bases

We process personal data only where a legal basis under Article 6 GDPR applies. The table of purposes below maps each purpose to its legal basis.

Providing identity and KYC data is a statutory requirement for the fiat services: if you do not provide it, the law does not permit us or our partners to make those services available to you. The self-custody wallet itself does not require identity verification.

Special categories of data (biometric data)

The liveness check and automated facial comparison performed during identity verification involve biometric data within the meaning of Article 9 GDPR. We process this data only for the purpose of verifying your identity, and only under the conditions of Article 9(2) GDPR: your explicit consent, which we ask for at the start of verification (Article 9(2)(a)), and reasons of substantial public interest laid down in the Estonian Money Laundering and Terrorist Financing Prevention Act and related EU anti-money-laundering rules (Article 9(2)(g)). If you do not consent to the biometric check, we cannot activate the fiat services, because the law requires verified identity before they may be provided. Biometric verification data is handled by our regulated identity verification providers under strict contractual safeguards and is never used for any other purpose.

5. Who we share your data with

We do not sell your personal data. We share it only with the categories of recipients below, and only to the extent necessary for the purposes described in this policy:

6. International transfers

We store and process personal data primarily within the European Economic Area (EEA). Some of our service providers or partners may process data outside the EEA. Where that happens, we ensure an adequate level of protection by transferring data only to countries covered by a European Commission adequacy decision, or by putting in place the European Commission's Standard Contractual Clauses together with any supplementary measures needed, in line with Chapter V of the GDPR. You can request further information about the safeguards applied to a specific transfer by contacting privacy@mbwalletconnect.com.

7. How long we keep your data

We keep personal data only for as long as necessary for the purposes for which it was collected, and then delete or irreversibly anonymise it. The main retention periods are:

8. Your rights under the GDPR

Subject to the conditions and limits set out in the GDPR, you have the following rights in relation to your personal data:

To exercise any of these rights, contact privacy@mbwalletconnect.com. We may need to verify your identity before acting on a request. We respond within one month, which may be extended by two further months for complex or numerous requests; if we extend, we will tell you why.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. You may also complain to the supervisory authority of the EU member state where you live or work.

9. Automated decision-making

Parts of the identity verification process are automated. Document authenticity checks, facial comparison and liveness checks, and screening against PEP and sanctions lists are performed by automated systems operated by us and by our identity verification providers. In some cases an automated result may lead to a decision that significantly affects you — for example, a refusal to activate regulated fiat services because verification could not be completed or a sanctions match was found. This processing is necessary for compliance with AML/CFT law and for entering into the contract with you.

Where an automated decision has a legal or similarly significant effect on you, you have the right to obtain human review of the decision, to express your point of view, and to contest the decision. To request a human review, contact privacy@mbwalletconnect.com.

10. Cookies

This website uses only strictly necessary cookies. These are cookies that are essential for the site to function: maintaining your session, remembering security state, and protecting forms against abuse. Because they are strictly necessary, they do not require consent under EU law. We do not use advertising cookies, cross-site tracking, or third-party marketing trackers of any kind.

You can block or delete cookies through your browser settings. If you block strictly necessary cookies, some parts of the service may not work correctly.

11. How we protect your data

We apply technical and organisational measures appropriate to the risk, including:

No system is completely secure. You are responsible for keeping your device, credentials, and recovery phrase safe; anyone who obtains your recovery phrase can control your assets, and we have no ability to intervene.

12. Children

The service is intended solely for persons aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete it, subject to any statutory retention obligations. If you believe a minor has provided us with personal data, please contact privacy@mbwalletconnect.com.

13. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in the service, in our partners, or in the law. The current version is always published at https://mbwalletconnect.com/privacy.html with its "Last updated" date. If we make material changes, we will give you reasonable advance notice through the service or by email before the changes take effect. Your continued use of the service after the effective date of an updated policy constitutes acceptance of the update, to the extent permitted by law.

14. Contact

Data controller: Waveform Services OÜ, registry code 17205686, Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia.

This Privacy Policy is governed by Estonian law. Any dispute relating to it that cannot be resolved amicably falls under the jurisdiction of the Harju County Court in Tallinn, Estonia, without prejudice to any mandatory consumer protections available to you under the law of your country of residence.