Version [2.0]. Last updated on 16 September, 2026.
1. Introduction
2. Data Controller
Company: SMARTFINSERVICE LLC
Identification number: 405607400
Registration number: 0018-9404
Registered office: Tbilisi, Georgia
Website: https://gecrypto.com/
Email: [email protected]
3. Personal Data We Collect
Identification data — full name, date and place of birth, nationality, gender, photograph, signature, identification number, passport or national ID details.
Contact data — postal address, email address, telephone number.
Verification and AML data — copies of identity documents, proof of address, selfies and liveness checks, sanctions and PEP screening results, source-of-funds and source-of-wealth information, beneficial-ownership information.
Biometric data: a numerical model of your face generated from your video selfie and from the photograph on your identity document, used only to calculate how closely the two match (see Section 5).
Financial and transactional data — bank account details, payment card details (tokenised where possible), wallet addresses, transaction amounts, dates, counterparties and references.
Account data — username, password (hashed), Account preferences, communication history with us.
Technical data — IP address, device identifiers, browser type and version, operating system, language settings, time-zone, referring URLs.
Usage data — pages visited, features used, session timestamps, clickstream and similar interaction data.
Video monitoring data — CCTV footage captured at the entrance to our office (see Section 12).
Marketing and preferences data — your consent or objection to marketing communications and your preferences for receiving them.
4. How We Collect Personal Data
Directly from you — when you register an Account, complete KYC verification, place an Order, contact our support team, subscribe to communications or otherwise interact with us.
Automatically — through cookies and similar technologies when you use the Website (see Section 11).
From third parties — from identity-verification providers, sanctions and PEP screening providers, blockchain analytics providers, payment-service providers, banks, public registers, fraud-prevention agencies and government or regulatory authorities.
5. Purposes and Legal Bases of Processing
Providing the Services — to open and operate your Account, execute Orders, process payments and provide customer support. The biometric part of identity verification is described separately below Legal basis: performance of a contract with you.
Identity verification and AML/CFT compliance — to verify your identity, screen against sanctions and PEP lists, monitor transactions, detect and report suspicious activity. Legal basis: compliance with legal obligations.
Fraud prevention and security — to prevent, detect and investigate fraud, abuse and security incidents, and to protect the rights, property and safety of the Company, our Users and third parties. Legal basis: legitimate interests and compliance with legal obligations.
Service improvement and analytics — to understand how our Services are used and to improve and develop them. Legal basis: legitimate interests.
Marketing communications — to send you information about products, services, news and promotions. Legal basis: your consent (or legitimate interests for existing Users in respect of similar products), which you may withdraw at any time.
Legal claims and regulatory cooperation — to establish, exercise or defend legal claims and to respond to lawful requests from public authorities. Legal basis: legitimate interests and compliance with legal obligations.
Electronic identification and biometric data – Before your first Order, we must verify your identity. We do this remotely through the system of our identification service provider, Identomat (see Section 6). You choose the type of identity document you will use and allow access to your camera. The system photographs the document and reads the data from its text and machine-readable zones. You then record a short video selfie, during which the system checks that a real person is present, for example by asking you to smile. The system generates a numerical model of your face from the video selfie and from the document photograph and compares the two. Only the resulting similarity score is returned to us. This numerical model is biometric data.
Legal basis - We process your identity document, video selfie and the verification result to comply with our identification and verification obligations under the anti-money laundering legislation of Georgia. We process your biometric data on the basis of your explicit written consent, which you give electronically in a separate step shown before the document and selfie steps start.
Your choice - You are not obliged to give this consent. If you do not wish to complete the biometric check, you may verify your identity in person at our office in Tbilisi.
Withdrawal - You may withdraw your consent at any time by writing to [email protected]. Withdrawal does not affect processing carried out before it. After withdrawal, we will not subject you to any further biometric check. The numerical model of your face is deleted within seconds of each check, so none is kept. Your video selfie and other identification records are kept only as required by anti-money laundering legislation (see Section 8).
Safeguards - The numerical model of your face exists for no more than ten (10) seconds while the similarity score is calculated and is then irreversibly deleted. During that time, no one, including us and Identomat, can access it, and your face cannot be reconstructed from it. We use biometric data only to verify your identity and to prevent identity fraud. We do not use it for marketing or profiling, and we do not sell it. Identomat may process your data only to provide its service to us and for no other purpose. Access to verification records is limited to authorised compliance staff, and each access is logged. Each video selfie is protected by a unique cryptographic hash, so that any alteration can be detected. The data is encrypted in transit and at rest. If the automated check fails or is inconclusive, we will tell you and explain how you can repeat the verification or use the alternative method described above. You may also contact us at [email protected] to express your view.
6. Disclosure of Personal Data
Service providers and processors acting on our behalf, including identity-verification providers, blockchain analytics providers, cloud and hosting providers, payment-service providers, customer-support and communications platforms, marketing platforms and IT-security vendors. Such providers are bound by written agreements requiring confidentiality and an adequate level of protection.
Electronic identification provider: the document checks, video selfie, liveness check and face comparison are carried out for us by Identomat Inc., registration number 20204194256, 60 Hazelwood Dr, Champaign, IL 61820, USA ("Identomat"). Identomat acts as our processor, only on our instructions and for the purposes of our written agreement with it, and may not engage sub-processors without our prior written consent. Identomat also screens your name against sanctions and PEP lists, using databases licensed from OpenSanctions Datenbanken GmbH, Germany. Your document data may also be checked against databases of lost, stolen or invalid documents. Identomat keeps a depersonalised technical audit log of each verification session, consisting of a unique session identifier and a time-stamped record of the steps taken by you and of any actions by our or Identomat's staff, to secure and evidence its service. That log is separate from our own customer identification records, which we keep as controller (see Section 8).
Banks and counterparties involved in the settlement of your transactions.
Public authorities, including the National Bank of Georgia, the Financial Monitoring Service of Georgia, the Personal Data Protection Service of Georgia, tax authorities, courts and law-enforcement agencies, where required by Applicable Law or pursuant to a lawful request.
Professional advisers such as lawyers, auditors and consultants, under appropriate confidentiality obligations.
Successors in connection with a merger, acquisition, reorganisation or sale of all or part of our business, subject to standard confidentiality protections.
7. International Data Transfers
8. Data Retention
KYC, AML and transaction records — at least five (5) years following the termination of the business relationship or the date of an occasional transaction, as required by Applicable Law.
Video selfie, document images and identification report - kept with the KYC records for the period stated above, as evidence of how your identity was verified. Copies in Identomat's system are kept for the period we set, which does not exceed the term of our agreement with Identomat, and are then deleted.
Numerical model of your face - irreversibly deleted within ten (10) seconds of its creation, once the similarity score is calculated.
Identification session audit logs - kept by Identomat for no longer than three (3) years after our agreement with Identomat ends, unless we ask for earlier deletion.
Consent records - kept for as long as we keep the data to which the consent relates.
Account and communications data — for the duration of the business relationship and for 3 years thereafter to handle queries, complaints and legal claims.
Marketing data — until you withdraw your consent or object to processing.
Technical, usage and cookie data — in accordance with the cookie durations described in Section 11.
Video monitoring data — no more than one (1) month, after which it is destroyed by software (see Section 12).
9. Your Rights as a Data Subject
Right to be informed about the processing of your personal data.
Right of access — to obtain confirmation of whether we process your personal data and, where we do, a copy of the data.
Right to rectification — to have inaccurate or incomplete personal data corrected or completed.
Right to erasure — to have your personal data deleted where there is no overriding legal basis for us to retain it.
Right to restriction of processing in defined circumstances.
Right to object to processing carried out on the basis of our legitimate interests or for direct marketing purposes.
Right to data portability — to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible.
Right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before such withdrawal.
Right to lodge a complaint with the Personal Data Protection Service of Georgia (see Section 16).
10. Security Measures
11. Cookies and Similar Technologies
Strictly necessary cookies — required for the operation of the Website and the Services; you cannot opt out of these.
Functional cookies — remember choices you make (such as language) to provide a more personalised experience.
Analytics cookies — help us understand how visitors interact with the Website so we can improve it.
Marketing cookies — used to deliver advertising that is relevant to you and to measure its effectiveness.
12. Video Monitoring
13. Children's Privacy
14. Marketing Communications
15. Changes to This Privacy Policy
16. Contact Us and Complaints
Company: SMARTFINSERVICE LLC
Registered office: Tbilisi, Georgia
Email: [email protected]
Website: https://gecrypto.com/