Legal

Privacy Policy

Effective 8 September 2026

This policy explains what personal data CryptoTaxLogic (CTR) collects, why, who it is shared with, how long it is kept, and the rights you have under the EU General Data Protection Regulation (GDPR). It applies alongside our Terms of Service.

1. Who is responsible

The data controller is Baltas Mazgas, registered in Lithuania, company code 307574335. Contact for anything in this policy: [email protected].

2. What we collect and why

We only process data CTR needs to work, to keep accounts safe, and to meet our legal obligations.

DataWhy we process itLegal basis
Account: email address, name, password (stored only as a bcrypt hash), language, tax country and settingsTo create and run your account and calculate your figures under the right country's rulesContract (Art. 6(1)(b))
Google or Facebook sign-in: the provider's account id, and the verified email and name it reportsTo sign you in and to link that identity to your account. We never receive your provider password.Contract
Transaction history you import: CSV files, exchange data read through API keys, public blockchain activity for wallet addresses you addThe core of CTR: cost-basis accounting, tax figures, reports, reconciliation and harvesting toolsContract
Exchange API keys, and any AI provider keys you choose to saveTo read your exchange history on your behalf, or to answer your “Ask AI” questions. Stored encrypted (AES-256-GCM); exchange keys must be read-only.Contract; consent for AI keys
Security and audit log: logins and failed logins, IP address, browser user agent, sensitive account actions (connecting an exchange, adding a wallet, exporting data, creating an accountant link)To detect account takeover, brute-force attempts and abuse, and to show you what happened on your accountLegitimate interest in security (Art. 6(1)(f))
Accountant links: the label and optional email you enter, when the link was opened and from which IP addressTo let you share a read-only view with your accountant and see when it was usedContract; legitimate interest
Newsletter signup: email address and the site it was entered onTo email you product news you asked forConsent (Art. 6(1)(a)) — withdraw at any time
Support correspondenceTo answer youLegitimate interest

We do not sell personal data, do not build advertising profiles, and do not use your transaction data for anything other than providing CTR to you.

3. Cookies and analytics

Session cookie. A signed, HTTP-only cookie keeps you logged in. It is strictly necessary and set only when you sign in.

Preferences. Small settings such as your selected tax year, table columns and filter choices are kept in your browser’s local storage and never sent to us as tracking data.

Analytics. Our pages load Google Tag Manager, which we use for Google Analytics to understand how the site is used (pages visited, approximate location, device type). Google may set its own cookies for this. Google processes this data under its own terms; IP addresses are handled by Google Analytics’ anonymisation. You can block these cookies in your browser or with a content blocker without affecting CTR.

4. Who we share data with

We use a small number of service providers, each only for the purpose named:

  • Hosting. CTR and its database run on a server we rent in a European Union data centre. Backups are kept on that server.
  • Exchanges and blockchain data providers. When you connect an exchange or add a wallet, we send that exchange or a public blockchain explorer only what is needed to read your history (your API key, or the public address). They see the request come from us.
  • Market price providers (for example CoinGecko and CoinMarketCap). We request prices for asset symbols and dates. No account or personal data is included in those requests.
  • Google and Facebook, only if you choose to sign in with them. They learn that you used your account to sign in to CTR.
  • AI providers (OpenAI, Anthropic or Google Gemini), only if you save your own API key and use “Ask AI about this transaction”. The details of that transaction are then sent to the provider you chose, under its own terms.
  • Email delivery. Transactional emails (accountant invitations, security notices, newsletter) go through our SMTP provider.
  • Google Analytics, as described in section 3.
  • Your accountant, only through a read-only link you create yourself and can revoke at any time.

We disclose data to authorities only where the law requires it.

5. International transfers

Your account and transaction data are stored in the EU. Some providers above (Google, Facebook, OpenAI, Anthropic, CoinGecko, CoinMarketCap) are established or process data in the United States. Where that happens we rely on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses, and we send only the minimum described above.

6. How long we keep data

  • Account and transaction data: for as long as your account exists. You can delete every transaction, disconnect every source and remove saved keys yourself at any time; when your account is closed the data is deleted.
  • Security and audit log: kept while the account exists so you and we can review activity on it, and for a reasonable period afterwards to investigate abuse.
  • Login-attempt and rate-limit counters: a few hours to days, then deleted automatically.
  • Upstream request monitoring (which of our providers we called, how fast, whether it failed): individual records for 7 days, hourly totals for 90 days. These contain no transaction data.
  • Accountant links: until they expire (at most one year) or you revoke them; the record of when a link was used stays with the account.
  • Newsletter address: until you unsubscribe.
  • Backups: rotated on a short cycle, so deleted data leaves backups within a few weeks.

7. Your rights

Under the GDPR you can ask us at any time to:

  • access the personal data we hold about you;
  • correct it (most of it you can edit yourself under Settings);
  • delete it (close your account, or delete your transactions and connections yourself);
  • receive a copy in a portable format — the Transactions page exports your full history as CSV, and your reports as PDF;
  • restrict or object to processing based on our legitimate interests;
  • withdraw consent where processing is based on it (the newsletter, AI keys) without affecting what was done before.

Write to [email protected]; we answer within one month. You also have the right to complain to a supervisory authority — in Lithuania, the State Data Protection Inspectorate (VDAI, vdai.lrv.lt) — or to the authority in the EU country where you live.

8. How we protect data

  • All traffic is encrypted in transit (HTTPS).
  • Passwords are stored only as bcrypt hashes; exchange and AI keys are encrypted at rest with AES-256-GCM.
  • Exchange connections require read-only API keys; wallet imports use public addresses only — we never ask for a private key or seed phrase.
  • Repeated failed logins lock the account and the source address temporarily; sensitive actions are rate-limited and logged; automated monitoring raises alerts on suspicious patterns.
  • Changing your password signs you out on every device; a suspended account stops working within minutes.
  • Accountant links are random 256-bit tokens of which only a hash is stored, and are read-only by construction.

9. Children

CTR is for adults. We do not knowingly collect data from anyone under 18; if you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We may update this policy as CTR changes. The effective date at the top shows the current version; for material changes we will notify registered users by email or an in-app notice.

11. Contact

Questions or requests about your data: [email protected].

Terms of ServiceBack to CryptoTaxLogic