Privacy Policy
MB Wallet Connect is a service operated by Waveform Services OÜ, a private limited company registered in Estonia under the Estonian Commercial Register, registry code 17205686.
Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia
Contact: privacy@mbwalletconnect.com
Contents
- Who we are and data controller
- Scope of this policy
- Personal data we collect
- How we use your data and legal bases
- Who we share your data with
- International transfers
- How long we keep your data
- Your rights under the GDPR
- Automated decision-making
- Cookies
- How we protect your data
- Children
- Changes to this policy
- Contact
1. Who we are and data controller
MB Wallet Connect is a service operated by Waveform Services OÜ, a private limited company registered in Estonia under the Estonian Commercial Register, registry code 17205686. Our registered address is Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia. In this Privacy Policy, "we", "us", and "our" refer to Waveform Services OÜ, and "the service" refers to MB Wallet Connect, available at https://mbwalletconnect.com.
Waveform Services OÜ is the data controller for the personal data described in this policy, meaning that we determine the purposes and means of processing your personal data. Where our regulated partners process your data as controllers in their own right — for example, when a licensed financial institution opens and administers a euro account in your name — their own privacy notices also apply to that processing.
For any question about this policy or about how we handle your personal data, contact us at privacy@mbwalletconnect.com.
2. Scope of this policy
This policy applies to personal data we process when you visit our website, create an account, use the MB Wallet Connect wallet, complete identity verification, or use the fiat account and conversion services made available through the service. It is written to comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Estonian law, including the Estonian Money Laundering and Terrorist Financing Prevention Act ("AML/CFT law").
Two aspects of the service shape what data we process:
- Self-custody wallet. MB Wallet Connect is a non-custodial wallet. Your private keys are generated and stored on your own device. We never hold, control, transmit, or back up your private keys or recovery phrases, and we cannot access or recover your digital assets. As a result, using the wallet on its own requires very little personal data.
- Regulated fiat services. If you choose to use euro account details (IBAN), fiat deposits and withdrawals, or conversion between euros and digital assets, these services are provided through licensed third-party financial institutions and regulated payment infrastructure partners. Anti-money-laundering law requires identity verification ("KYC") before these services can be activated, and this is where most of the personal data described below is collected.
This policy does not apply to third-party websites, decentralised applications, or blockchain networks that you interact with through the wallet. Those are operated independently of us.
3. Personal data we collect
3.1 Account data
When you create an account we collect your email address, a display name if you choose to set one, authentication credentials (stored in hashed form), and your account preferences and settings.
3.2 Identity and KYC data
Before regulated fiat services can be provided, applicable AML/CFT law requires us and our partners to verify your identity. For this purpose we collect and process:
- your full name, date of birth, nationality, and residential address;
- identity documents such as a passport, national identity card, or residence permit, including the images and machine-readable data they contain;
- photographs and liveness data captured during verification, including a selfie and short video or motion capture used to confirm that the document belongs to you and that a live person is present;
- the results of screening against politically exposed person ("PEP") lists, international and national sanctions lists, and adverse media sources;
- where required by law or by our partners' risk assessment, information on your occupation, the origin of your funds, and the intended nature of your use of the service.
3.3 Financial data
When you use the fiat services we process the personal euro account details (IBAN) issued to you by licensed third-party financial institutions, records of your fiat deposits and withdrawals, transaction amounts, dates, references and counterparty details, and records of conversions between euros and digital assets carried out through our regulated partners.
3.4 Blockchain data
We process the public blockchain addresses associated with your wallet and data about on-chain transactions linked to those addresses, including for transaction monitoring required by AML/CFT law. Please note an important limitation: blockchain addresses and on-chain transactions are recorded on public, decentralised ledgers that are, by design, permanent and immutable. This information is publicly visible to anyone, is not held on our systems alone, and cannot be altered or erased by us. Rights such as erasure and rectification cannot be exercised against data recorded on a public blockchain.
3.5 Technical and usage data
When you use the website or the service we automatically collect technical data such as your IP address, device type and identifiers, operating system, browser type, language settings, access timestamps, pages viewed, and diagnostic and security logs, including records of failed login attempts.
3.6 Communications
When you contact us — for example by email to our support address — we keep a record of the correspondence, including your contact details, the content of the messages, and any attachments you send.
4. How we use your data and legal bases
We process personal data only where a legal basis under Article 6 GDPR applies. The table of purposes below maps each purpose to its legal basis.
- Providing the service (performance of a contract, Article 6(1)(b)). Creating and administering your account, operating the wallet interface, activating and supporting fiat account details, executing deposits, withdrawals and conversions through our regulated partners, and providing customer support.
- Complying with the law (legal obligation, Article 6(1)(c)). Performing identity verification, PEP and sanctions screening, and ongoing transaction monitoring as required by the Estonian Money Laundering and Terrorist Financing Prevention Act and related EU rules; keeping statutory records; and responding to lawful requests from supervisory, tax, and law-enforcement authorities, including reporting to the Estonian Financial Intelligence Unit where the law requires it.
- Protecting the service and our business (legitimate interests, Article 6(1)(f)). Securing our systems, preventing and investigating fraud and abuse, monitoring performance, improving and developing the service, keeping internal records, and establishing, exercising, or defending legal claims. Where we rely on legitimate interests we balance them against your rights and freedoms, and you may object as described in section 8.
- Marketing (consent, Article 6(1)(a)). Sending you newsletters or promotional messages about the service, only if you have opted in. You can withdraw consent at any time, and withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Providing identity and KYC data is a statutory requirement for the fiat services: if you do not provide it, the law does not permit us or our partners to make those services available to you. The self-custody wallet itself does not require identity verification.
Special categories of data (biometric data)
The liveness check and automated facial comparison performed during identity verification involve biometric data within the meaning of Article 9 GDPR. We process this data only for the purpose of verifying your identity, and only under the conditions of Article 9(2) GDPR: your explicit consent, which we ask for at the start of verification (Article 9(2)(a)), and reasons of substantial public interest laid down in the Estonian Money Laundering and Terrorist Financing Prevention Act and related EU anti-money-laundering rules (Article 9(2)(g)). If you do not consent to the biometric check, we cannot activate the fiat services, because the law requires verified identity before they may be provided. Biometric verification data is handled by our regulated identity verification providers under strict contractual safeguards and is never used for any other purpose.
5. Who we share your data with
We do not sell your personal data. We share it only with the categories of recipients below, and only to the extent necessary for the purposes described in this policy:
- Identity verification providers. Regulated providers that carry out document verification, liveness checks, and PEP and sanctions screening on our behalf and on behalf of our financial partners. Your KYC data is transmitted to them via secure API.
- Licensed financial institutions and payment infrastructure partners. The licensed third-party financial institutions that issue your euro account details and the regulated payment infrastructure partners that execute fiat deposits, withdrawals, and conversions between euros and digital assets. These partners are themselves subject to AML/CFT law and process your data under their own regulatory obligations.
- IT service providers. Hosting, cloud infrastructure, security, analytics, and communications providers that process data on our behalf under data processing agreements meeting the requirements of Article 28 GDPR.
- Authorities. The Estonian Financial Intelligence Unit, supervisory authorities, courts, tax authorities, and law-enforcement bodies, where disclosure is required by law or by a binding order. AML/CFT law may prohibit us from informing you that such a disclosure has been made.
- Professional advisers and corporate transactions. Auditors, lawyers, and insurers under confidentiality obligations, and prospective acquirers or successors in the context of a merger, acquisition, or reorganisation, subject to appropriate safeguards.
6. International transfers
We store and process personal data primarily within the European Economic Area (EEA). Some of our service providers or partners may process data outside the EEA. Where that happens, we ensure an adequate level of protection by transferring data only to countries covered by a European Commission adequacy decision, or by putting in place the European Commission's Standard Contractual Clauses together with any supplementary measures needed, in line with Chapter V of the GDPR. You can request further information about the safeguards applied to a specific transfer by contacting privacy@mbwalletconnect.com.
7. How long we keep your data
We keep personal data only for as long as necessary for the purposes for which it was collected, and then delete or irreversibly anonymise it. The main retention periods are:
- Identity, KYC, and financial data. Under the Estonian Money Laundering and Terrorist Financing Prevention Act, we must retain identity verification data and transaction records for at least five years after the end of the business relationship or the completion of the relevant transaction. This period may be extended where the law requires it or where a competent authority orders an extension.
- Account data. For the life of your account, and afterwards for the period needed to comply with statutory obligations and limitation periods for legal claims.
- Technical and security logs. Generally up to twelve months, unless a longer period is needed to investigate a security incident or suspected abuse.
- Communications. Generally up to three years from the closure of the matter, unless a longer period is needed for legal claims.
- Marketing data. Until you withdraw consent or object, after which we retain only the minimum needed to honour your opt-out.
- Blockchain data. Data recorded on public blockchains is retained indefinitely by the networks themselves and is outside our control, as explained in section 3.4.
8. Your rights under the GDPR
Subject to the conditions and limits set out in the GDPR, you have the following rights in relation to your personal data:
- Access. To obtain confirmation of whether we process your data and to receive a copy of it, together with information about the processing.
- Rectification. To have inaccurate data corrected and incomplete data completed.
- Erasure. To have your data deleted where there is no longer a lawful reason for us to keep it. Please note two important limits: we cannot delete data that we are legally required to retain under AML/CFT law for the periods described in section 7, and we cannot alter or erase data recorded on public blockchains, as explained in section 3.4.
- Restriction. To have processing restricted in the circumstances set out in Article 18 GDPR, for example while a dispute about accuracy is resolved.
- Portability. To receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible, for processing based on contract or consent.
- Objection. To object to processing based on our legitimate interests, on grounds relating to your particular situation, and to object at any time to processing for direct marketing.
- Withdrawal of consent. To withdraw any consent you have given, at any time, with effect for the future.
To exercise any of these rights, contact privacy@mbwalletconnect.com. We may need to verify your identity before acting on a request. We respond within one month, which may be extended by two further months for complex or numerous requests; if we extend, we will tell you why.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. You may also complain to the supervisory authority of the EU member state where you live or work.
9. Automated decision-making
Parts of the identity verification process are automated. Document authenticity checks, facial comparison and liveness checks, and screening against PEP and sanctions lists are performed by automated systems operated by us and by our identity verification providers. In some cases an automated result may lead to a decision that significantly affects you — for example, a refusal to activate regulated fiat services because verification could not be completed or a sanctions match was found. This processing is necessary for compliance with AML/CFT law and for entering into the contract with you.
Where an automated decision has a legal or similarly significant effect on you, you have the right to obtain human review of the decision, to express your point of view, and to contest the decision. To request a human review, contact privacy@mbwalletconnect.com.
10. Cookies
This website uses only strictly necessary cookies. These are cookies that are essential for the site to function: maintaining your session, remembering security state, and protecting forms against abuse. Because they are strictly necessary, they do not require consent under EU law. We do not use advertising cookies, cross-site tracking, or third-party marketing trackers of any kind.
You can block or delete cookies through your browser settings. If you block strictly necessary cookies, some parts of the service may not work correctly.
11. How we protect your data
We apply technical and organisational measures appropriate to the risk, including:
- encryption of personal data in transit (TLS) and at rest;
- a self-custody architecture in which private keys are generated and held on your device and never touch our servers;
- strict access controls, so that personal data — and KYC data in particular — is accessible only to personnel who need it for their role;
- secure, authenticated API connections to our verification and financial infrastructure partners;
- logging, monitoring, and regular review of our systems for vulnerabilities;
- staff confidentiality obligations and data protection training;
- an incident response process. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it and, where the risk is high, notify you directly, as required by Articles 33 and 34 GDPR.
No system is completely secure. You are responsible for keeping your device, credentials, and recovery phrase safe; anyone who obtains your recovery phrase can control your assets, and we have no ability to intervene.
12. Children
The service is intended solely for persons aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete it, subject to any statutory retention obligations. If you believe a minor has provided us with personal data, please contact privacy@mbwalletconnect.com.
13. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in the service, in our partners, or in the law. The current version is always published at https://mbwalletconnect.com/privacy.html with its "Last updated" date. If we make material changes, we will give you reasonable advance notice through the service or by email before the changes take effect. Your continued use of the service after the effective date of an updated policy constitutes acceptance of the update, to the extent permitted by law.
14. Contact
Data controller: Waveform Services OÜ, registry code 17205686, Seebi tn 1-1501, Kristiine linnaosa, Tallinn, Harju maakond, Estonia.
- Privacy matters: privacy@mbwalletconnect.com
- General support: support@mbwalletconnect.com
- Legal matters: legal@mbwalletconnect.com
This Privacy Policy is governed by Estonian law. Any dispute relating to it that cannot be resolved amicably falls under the jurisdiction of the Harju County Court in Tallinn, Estonia, without prejudice to any mandatory consumer protections available to you under the law of your country of residence.