Privacy Notice
At Skellig Capithorn, safeguarding your personal information is a critical responsibility. We manage your data transparently, only for defined purposes and in line with the GDPR and relevant legislation. This document explains what information we gather, the reasons for collecting it, retention duration, and the security measures we implement.
1. Data Controller
The data controller responsible for your personal information under the GDPR is the operator of this website and the Skellig Capithorn platform. Our contact information and additional details are provided in the site's legal disclaimers. For privacy-related inquiries, you may reach out to our Data Protection Officer.
2. Collected Information
We gather and handle only the data essential for delivering our services, fulfilling legal requirements, and maintaining platform security. This includes:
- Identification details: full name and date of birth (used for age verification and identity confirmation).
- Contact information: email, optional phone number, country of residence, and potentially mailing address.
- Account and payment data: banking information, deposits, withdrawals, and transaction records.
- Technical and behavioural data: IP addresses, browser types, device specifics, login times, and connection logs.
- Verification documents: identity proofs, address verification, or other documentation for KYC/AML compliance (only when legally mandated).
We typically avoid collecting sensitive personal data categories (such as health or religious information), except when legally necessary or with your explicit permission.
3. How We Collect Data
Your information is obtained through various secure methods:
- Information you submit directly, such as during account creation, profile changes, document uploads for verification, or contact form submissions.
- Automatically collected data through means like cookies, server logs, analytics tools, and device details during platform use.
- Information from third parties, including payment processors (for handling deposits and withdrawals), identity verification services (KYC/AML), or social login providers with your consent.
4. Reasons for Processing
Your personal data is processed solely for clear, legitimate objectives as follows:
- Setting up, managing, and delivering your account and platform functionalities.
- Processing and securing financial transactions, including deposits and withdrawals.
- Providing personalised customer service and addressing your inquiries.
- Adhering to legal and regulatory obligations like KYC, AML, and tax compliance.
- Maintaining cybersecurity and defending against fraud, misuse, and attacks.
- Enhancing user experience and ongoing platform improvements.
- Marketing and communication activities, but only with your explicit approval.
5. Legal Grounds for Processing
- To execute our contract with you or to take pre-contractual steps (Article 6.1.b GDPR).
- To comply with legal duties (Article 6.1.c GDPR), such as anti-money laundering regulations.
- For our legitimate interests (Article 6.1.f GDPR), including platform reliability and security measures.
- Based on your explicit consent (Article 6.1.a GDPR), for optional services or marketing purposes.
6. Data Sharing Practices
Data is disclosed strictly when essential and only to trusted partners:
- Banks and payment service providers to handle deposits and withdrawals.
- Specialist entities conducting KYC/AML identity verifications.
- IT and cloud providers engaged through subcontracting agreements.
- Analytical and security services that generally use anonymised or pseudonymised data.
- External consultants, including legal and tax professionals, bound by confidentiality and legal duties.
- Regulatory bodies or courts when mandated by law or to enforce rights.
We do not sell or commercially transfer your personal data to third parties.
7. Cross-Border Data Transfers
Occasionally, we engage service providers (such as cloud or analytics) outside the European Economic Area. In these instances, we apply appropriate safeguards like EU standard contractual clauses, binding corporate rules, or European Commission adequacy decisions to maintain data protection standards.
8. Data Protection Measures
We apply rigorous technical and organisational safeguards to protect your data:
- Encrypted data transmission using up-to-date protocols (e.g., TLS 1.3 and above).
- Robust encryption methods for sensitive stored data (e.g., AES-256).
- Regular independent security audits, penetration testing, and vulnerability assessments.
- Continuous monitoring of systems to identify suspicious activity or cyberattack attempts.
- Strict access controls and role-based permissions for team members.
- Segregated client funds held with regulated financial partners.
While no system can guarantee absolute security, we implement comprehensive measures to minimise risks effectively.
9. Retention Timeframes
Your information is kept only as long as needed for the purposes outlined or as required by law:
- Throughout the period your account is active and during our contractual engagement.
- After account closure, we retain data for legally mandated durations (e.g., 5–10 years for tax and regulatory compliance).
- For processing based on consent, such as marketing, until you withdraw your approval.
When data is no longer necessary, it is securely erased or irreversibly anonymised.
10. Your Data Rights
You hold various rights regarding your personal data, including the ability to:
- Request access to the personal data we hold about you.
- Ask for corrections to any inaccurate or incomplete information.
- Request deletion of your data, unless retention is legally mandated.
- Seek restrictions on data processing under certain conditions.
- Obtain your personal data in a structured, widely used, and machine-readable format (data portability).
- Withdraw your consent for future processing at any time.
- File a complaint with the appropriate data protection authority.
11. Cookies and Related Technologies
We utilise cookies and comparable technologies to ensure website functionality, analyse user engagement and improve your experience. Essential cookies are always active, while analytical and advertising cookies require your prior consent. Further details are provided in our cookie policy.
12. Updates to This Notice
This privacy notice may be updated periodically in response to legal changes, regulatory demands, or new features. The latest version is always accessible on our site. We will inform you of significant updates via email or directly on the platform.
13. Contact for Privacy Matters
For questions about this privacy notice, data protection, or exercising your rights, please contact us at $site_gmail or through the site's contact form. Our Data Protection Officer will review and respond to your inquiry promptly.
By using Skellig Capithorn, you confirm that you have read and consent to this privacy notice.