Privacy Policy

„Digital Assist" Ltd.

Last Updated: 02/20/2026.

Introduction

The current privacy policy describes how Digital Assist Ltd , EIK: 206079266, with its registered office and management address in Sofia, postcode 1606, 13 Pencho Slaveykov Blvd., Entrance A, Floor 1, Apt. 1 („The Company,“ „we,“ „us“) collects, processes, and protects the personal data of its clients in connection with the cryptoasset exchange services provided through a network of crypto ATMs.

The company processes personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - „GDPR“) and the Personal Data Protection Act.

2. Personal data administrator

Administrator: „Digital Assist" Ltd.

Address: Sofia 1606, 13 „Pencho Slaveykov“ Blvd., Entrance A, 1st Floor, Apt. 1

Email support@digitalassist.bg

Website https://digitalassist.bg

3. What personal data do we collect

In connection with the provision of crypto-asset exchange services, the Company may process the following categories of personal data:

Credentials

  • First name, middle name, and last name;
  • Date of birth;
  • Data from an official identification document (identity card, passport, or driver's license);
  • Photo;

Contact Information:

  • Phone number
  • Email address, when presented

Transaction data:

  • Information on cryptocurrency purchases and sales;
  • Transaction date, time, and location;
  • Transaction value;
  • Transaction Hash (ID);
  • Client crypto wallet address.

Other data related to the fulfillment of legal obligations, when necessary:

  • Declaration of Origin of Funds;
  • Declaration concerning status as a politically exposed person;
  • Declaration of Beneficial Owner.

4. Purposes and legal bases for processing

We process the categories of personal data under item 3 to provide the services you requested, to respond to your inquiries, complaints, and reports, as well as to comply with our applicable legal obligations. Specifically, the Company processes your personal data for the following purposes:

Purpose of processingLegal basis (under Article 6 of GDPR)
Providing cryptocurrency exchange servicesContract performance
Customer Identification (KYC) and AML/CFT Compliance. Combating Money Laundering and Terrorist FinancingStatutory obligation
Handling of complaints and inquiriesLegal obligation, legitimate interest, performance of contract

Please note that if you do not provide some of the requested data under item 3, the Company will not be able to provide you with the requested services, as this will not be possible or would constitute a violation of the current Bulgarian legislation.

5. Personal Data Recipients

The company may send your personal data to the following recipients:

  • Regulatory, judicial, and supervisory authorities, when necessary for the purposes of fulfilling legal obligations;
  • Service providers – e.g. accounting, legal, and ICT services. Compliance with legal requirements.

6. International Data Transmission

Personal data is stored on secure servers within the European Union. The company does not transfer personal data to third countries outside the European Union and the European Economic Area.

7. Storage Periods

The company stores personal data for the following periods:

Data CategoriesShelf life
Identification, contact and transaction data, other data related to the fulfillment of legal obligations, where necessary5 years after the termination of our relationship or last transaction
Complaint data5 years after the review is completed

8. Your Rights

Under the terms of the GDPR, you have the following rights:

  • Right of access – to obtain information about whether and what data of yours we process
  • Right to rectification – to request rectification of inaccurate or incomplete data
  • Right to erasure („right to be forgotten“) – under certain conditions, to the extent that there is no legal obligation to retain
  • Right to restriction of processing
  • Right to portability – to obtain your data in a structured format, when technically feasible;
  • Right to object – when processing is based on legitimate interest;

To exercise your rights, please contact us using the details provided in section 1 of this Policy. We will respond to your request within 1 month. In complex cases, the period may be extended by another 2 months, for which you will be promptly notified.

9. Right to lodge a complaint with a supervisory authority

In addition to the rights under item 9, you have the right to lodge a complaint with a supervisory authority. You can lodge a complaint with the Commission for Personal Data Protection at the following address: Sofia 1592, Prof. Tsvetan Lazarov Blvd. № 2, Email: kzld@cpdp.bg, website: www.cpdp.bg

10. Policy Changes

The company reserves the right to update this Privacy Policy in case of changes in legislation or data processing practices. The current version is always available on our website and at the cryptomat devices.