This Privacy Policy explains what personal data B28 OÜ processes, why, on what legal basis, and the rights you have over it. We are a non-custodial crypto wallet: your keys and recovery phrase are generated and stored on your own device, and we never hold or access your funds. That design means we process far less data than a bank or an exchange, and this policy is written to reflect that reality honestly rather than to claim powers we do not have. It is provided in line with Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus, the "IKS").
1. Who we are (the controller)
The controller of your personal data is B28 OÜ, a private limited company incorporated in Estonia, with its registered office at [registered street address, Tallinn, Estonia, to be confirmed] and Estonian commercial registry code [registry code to be confirmed]. Two of these values are mandatory identity information under GDPR Article 13(1)(a) and the Estonian Information Society Services Act, and they must be completed with confirmed values before this policy is published; they are shown as placeholders here and are not invented.
You can reach us about anything in this policy at hello@joinb28.app, and on security or data-incident matters at security@joinb28.app.
Data Protection Officer. We have assessed Article 37 of the GDPR honestly. Our core activity is providing non-custodial wallet software; it does not consist of large-scale, regular and systematic monitoring of individuals, nor of large-scale processing of special categories of data or criminal-conviction data. We are a small organisation (fewer than ten staff). On that basis we are not legally required to appoint a Data Protection Officer, and we have not appointed one. We will re-assess this if our scale or processing changes, and you can always raise data-protection questions at the contacts above. We will not name a person as DPO unless we actually appoint one.
2. The on-device reality (data minimisation by design)
The most important thing to understand about B28 is what we do not receive. Your recovery phrase, private keys and the seed they derive from are created and held only on your device, protected by your device's secure hardware and biometrics. We never receive them, cannot recover them, and cannot move your funds. We do not operate accounts that hold your crypto. Most wallet activity, including signing transactions, reading your balances and screening an address before you send, happens on your device or against public blockchain data, not by sending your holdings to us. This is data minimisation built into the product, in the spirit of GDPR Article 5(1)(c) and Article 25.
3. What we process, why, and on what legal basis
Each purpose below is mapped to a legal basis under GDPR Article 6. Where a basis is "legitimate interests" (Article 6(1)(f)), you have the right to object as described in Section 7.
- Early-access waitlist. If you submit your email address on our marketing site, we process that email to add you to the waitlist and to contact you about early access. Legal basis: your consent (Article 6(1)(a)); you can withdraw it at any time by using the unsubscribe link or emailing us, with no effect on processing already carried out.
- Responding to you. If you contact us by email (support, security, a rights request), we process the contents of your message and your contact details to answer and keep a record. Legal basis: our legitimate interest (Article 6(1)(f)) in handling and documenting enquiries, and, where you raise a legal claim, compliance with a legal obligation (Article 6(1)(c)).
- Running and securing the app and site. When you use the app or visit the site, our infrastructure necessarily processes technical data such as IP address, device and request metadata and security logs, to deliver the service, prevent abuse and keep it secure. Legal basis: our legitimate interest (Article 6(1)(f)) in operating a secure, functioning service. Strictly necessary cookies and equivalent local storage are used only to make the service work.
- Sanctions and geographic restrictions. To comply with the law, we apply server-side geographic and sanctions restrictions, which involves processing technical location signals such as your IP-derived country. Legal basis: compliance with a legal obligation (Article 6(1)(c)) and our legitimate interest in lawful operation.
- The Sentinel scam-shield. Before you sign, the Sentinel screens the destination address and token against risk signals and warns you. This runs to protect you and runs largely on your device or against public data; we do not build a profile of you from it and it does not make a legally significant automated decision about you, it advises you and you decide. Legal basis: our legitimate interest (Article 6(1)(f)) in protecting users from fraud, which the GDPR itself recognises as a legitimate interest (Recital 47).
We do not set advertising, analytics or other non-essential cookies, and we do not run third-party analytics or advertising tracking on the site or in the app today. If that ever changes, we will ask for your consent first (under the ePrivacy Directive 2002/58/EC Article 5(3) as transposed in Estonia) and update this policy and our Cookie Notice before any such processing begins. Our Cookie Notice reflects this same zero-non-essential-cookies position.
4. The on-ramp and card partners are separate controllers
Some features rely on regulated third parties, and your relationship with them is direct, not through us:
- Buying crypto with a card (on-ramp). Buying crypto with a bank card is handled by a third-party on-ramp provider. That provider, not B28, collects and processes the identity and payment data needed to complete the purchase and to meet its own anti-money-laundering and know-your-customer duties. For that processing the on-ramp provider is an independent controller under its own privacy policy. B28 does not receive or store your card number, and we do not perform KYC identity verification on you ourselves.
- The instant-convert Visa card. The card is coming, not live. When it launches it will be issued through a regulated partner, which will be the controller for the personal and payment data that the card programme requires. We will update this policy with the partner's role before the card goes live.
Because these partners are separate controllers, you exercise your data-protection rights for that data with them directly; we will help you reach the right contact.
5. Who else may process data for us (processors and recipients)
We keep the list of recipients short and name the categories, as Articles 13(1)(e) and 14(1)(e) require:
- Hosting and infrastructure. Our servers and data are hosted with an EU-based infrastructure provider (Hetzner, with data centres in the European Union). They act as our processor under a written agreement meeting GDPR Article 28.
- Waitlist email tool. The tool we use to store waitlist emails and send early-access messages acts as our processor under an Article 28 agreement.
- Crash and diagnostics. If we use a crash-reporting or diagnostics tool to keep the app stable, it acts as our processor and is limited to that purpose. We do not use it to track or profile you, and we do not sell personal data to anyone.
- Public blockchains. When you broadcast a transaction, its on-chain data (such as addresses and amounts) is, by the nature of public blockchains, published to a permanent public ledger that no one controls. This is inherent to the technology, not a transfer we make on your behalf to a recipient we choose, and it is irreversible. See the erasure caveat in Section 7.
6. International transfers
Our hosting and primary processing are within the European Union, so for that processing there is generally no transfer of personal data outside the EU or EEA, and Chapter V of the GDPR (Articles 44 to 49) does not come into play. If any processor we use would process personal data outside the EEA, we will only allow it where a valid GDPR transfer mechanism is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and we will say so here. Public-blockchain data is global by design, as explained above.
7. Your rights
Under the GDPR (Articles 15 to 22) and the IKS, and at no charge in normal cases, you have the right to:
- Access the personal data we hold about you and receive a copy (Article 15);
- Rectify inaccurate or incomplete data (Article 16);
- Erase your data in the circumstances the law allows (Article 17, the "right to be forgotten");
- Restrict processing in certain cases (Article 18);
- Data portability, to receive data you gave us in a structured, commonly used, machine-readable format and have it sent to another controller where technically feasible (Article 20);
- Object to processing based on our legitimate interests, including any direct-marketing contact (Article 21); and
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22). We do not make such decisions about you; the Sentinel advises, it does not decide for you.
To exercise any right, email hello@joinb28.app. We will respond within one month, as Article 12(3) requires, and will tell you if we need to extend that period for complex requests.
The blockchain erasure caveat. Because confirmed blockchain transactions are written to a permanent, public, decentralised ledger that no single party controls, we cannot delete, alter or erase on-chain data, and neither can anyone else. This is a technical limit of the technology, not a refusal by us; your right to erasure under Article 17 applies fully to the data we ourselves hold off-chain, such as a waitlist email or a support thread.
Complaint to a supervisory authority. If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a supervisory authority (Article 77). Estonia's authority is the Data Protection Inspectorate (Andmekaitse Inspektsioon), the independent body that supervises and enforces data-protection law in Estonia. You can reach it at Tatari 39, 10134 Tallinn, Estonia, by email at info@aki.ee, or via www.aki.ee. You may also complain to the authority in your EU country of residence. We would be grateful for the chance to resolve your concern first, but you are not required to come to us before going to the regulator.
8. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, then delete or anonymise it:
- Waitlist email: until you unsubscribe or ask us to delete it, or until the early-access programme ends, whichever comes first.
- Support and security correspondence: for as long as needed to resolve the matter and then for a limited period to handle any follow-up or legal claim, after which it is deleted.
- Operational and security logs: for a short period appropriate to security and abuse-prevention, then deleted or anonymised.
Where a specific Estonian or EU legal obligation requires a longer retention period (for example accounting records), we keep the relevant data for that legally required period and no longer.
9. Security
We apply appropriate technical and organisational measures to protect personal data, in line with GDPR Article 32, taking account of the state of the art and the risks involved. These include encryption in transit, access controls, EU-based hosting and the on-device key model described above. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Inspectorate within 72 hours where required (Article 33) and inform affected users without undue delay where the breach is likely to result in a high risk (Article 34). No system is perfectly secure, and we cannot guarantee absolute security, but we treat the data we hold as a responsibility, not an asset.
10. Children
B28 is intended only for adults aged 18 or over. We do not knowingly process the personal data of anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
If we change how we process personal data, we will update this policy and change the date below. Where a change is significant, we will take reasonable steps to bring it to your attention. The current version always governs.
12. Contact
For any privacy question or to exercise a right, email hello@joinb28.app, or for security and data-incident matters security@joinb28.app. You can write to us at B28 OÜ, [registered street address, Tallinn, Estonia, to be confirmed].
Last updated: June 2026.