This page is available in English

View in English·

Esta página está disponible en español

Ver en español·

  • Stablecoins
  • Sobre nós Por que criamos a Stable Mint. Casos de uso Como as empresas usam a Stable Mint. Conteúdos O que escrevemos sobre pagamentos com stablecoins. Perguntas frequentes Como funcionam as contas e as stablecoins. Fale conosco Agende uma demonstração ou tire suas dúvidas.

    Últimos conteúdos

    Stable Mint USDSM Lists on Kraken, Expanding Institutional Access to a Regulated Dollar Token Regulação e conformidade MiCA's Transitional Period Has Ended: What It Means for Businesses Holding Non-Compliant Stablecoins Regulação e conformidade What Is Reserve of Assets Under MiCA? How EMT Issuers Protect Token Holders Todos os conteúdos
English Español Português
Entrar
Agendar demonstração
Empresas Stablecoins
Sobre
Sobre nós Casos de uso Conteúdos Perguntas frequentes Fale conosco
Entrar
Empresas Sua conta empresarial
Idioma
EnglishEspañolPortuguês
Agendar demonstração
Legal
Termos e Condições Política de Privacidade Política de Cookies

Privacy Policy

Última atualização: August 14, 2026 · Esta página está disponível apenas em inglês.

1. Identity of the Controller

This privacy notice explains how Stable mint Ltd (“Stable Mint”, “we”, “us”) collects, uses and otherwise processes personal data when providing its services as a licensed financial institution and electronic money token issuer, and when you visit our website. It has been prepared in accordance with Articles 13 and 14 of the General Data Protection Regulation (the “GDPR”).

The data controller of your personal data is Stable mint Ltd, a company incorporated in Malta with company registration number C 109060 and registered office at Level 2, The ‘Fort’, HardRocks Business Park, Burmarrad Road, Naxxar NXR 6345, Malta. Stable Mint can be contacted by email at [email protected] or by post at the registered office.

Stable Mint has appointed a Data Protection Officer. The Data Protection Officer can be contacted by email at [email protected] or by post at the registered office. All privacy and data protection matters, including the exercise of your rights under this notice, should be addressed to [email protected].

2. Categories of Personal Data

“Personal Data” means all personally identifiable information about you, whether provided by you or by third parties, that can be identified with you personally. We collect the following categories:

  • Identity Data: your identity details such as name, surname, nationality, residence status, passport or identity card number, tax identification numbers where applicable, internal references generated by Stable Mint (including request identifiers), risk scores and risk profile, beneficial ownership information and transaction records forming part of the customer file;

  • Contact Data: your email address, physical address and telephone numbers;

  • Financial Data: IBAN and bank account numbers and digital wallet identifiers;

  • KYC Data: copies of identification documents, information on source of funds and source of wealth, and screening results generated during onboarding and ongoing monitoring;

  • Screening Data: the results of sanctions, politically-exposed-person and adverse-media screening carried out to comply with our anti-money laundering obligations under the Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01, the “PMLFTR”). Screening Data is not collected from you directly: in accordance with Article 14(2)(f) of the GDPR, it is sourced from publicly and commercially available sources, namely sanctions lists issued by competent authorities, politically-exposed-person databases, adverse-media aggregators and, where applicable, public registers (including company and beneficial-ownership registers). Adverse-media and related screening may involve personal data relating to criminal convictions and offences within the meaning of Article 10 of the GDPR; such data is processed only under the applicable legal obligations, including the PMLFTR, and with appropriate safeguards;

  • Communications Data: records of correspondence and other communications with us;

  • Online Data: cookies and similar technologies activated when visiting our website or applications, and the IP address of the device you use. Analytics and marketing technologies operate only with your consent; the categories, providers and durations are set out in our Cookies Policy;

  • General Data: any personal data we process as a result of legal obligations imposed on Stable Mint, our or a third party’s legitimate interests, or which you voluntarily provide to us.

Other than the Article 10 data described above, we do not collect special categories of personal data within the meaning of Article 9 of the GDPR.

3. Purposes of Processing and Legal Basis

We use your personal data for the following purposes, on the legal bases indicated. Where more than one basis applies, contact us for details of the specific basis relied on in a given context.

  • To process and respond to queries, requests, feedback or complaints: Identity, Contact and General Data; legitimate interest in handling communications efficiently, or steps taken at your request prior to entering into a contract.

  • To enter into and perform a contract with you or the entity you represent, including the provision of issuance, redemption, custody and payment services: Identity, Financial, KYC, Contact, Online and General Data; necessity for the performance of a contract, or legitimate interest in maintaining contractual relationships.

  • To comply with our legal and statutory obligations, including anti-money laundering, sanctions and regulatory reporting obligations under the PMLFTR and other applicable law: Identity, Financial, KYC, Screening, Communications and General Data; compliance with legal obligations. This purpose covers beneficial owners and other third-party individuals whose personal data we receive indirectly from the entities they are connected with or from the sources described under Screening Data in section 2; section 12 explains how those individuals are informed.

  • Verification and identification of clients and their representatives and beneficial owners: Identity, Financial, KYC, Screening and Contact Data; compliance with legal obligations, and steps taken to enter into a contract.

  • Onboarding and ongoing monitoring of client relationships, including transaction monitoring: Identity, Financial, KYC, Screening and General Data; compliance with legal obligations, and legitimate interest.

  • To administer and secure our website and applications: Online Data; legitimate interest in operating our website efficiently and securely (essential cookies).

  • To measure how our website is used and improve it (analytics): Online Data; your consent, given through the cookie banner or settings and withdrawable at any time.

  • To measure our marketing campaigns and reach people who have visited our website (marketing): Online Data; your consent, given through the cookie banner or settings and withdrawable at any time.

  • To establish, exercise or defend legal claims: all categories; legitimate interest in establishing, exercising or defending legal claims.

4. Categories of Recipients

We may disclose, transfer or share personal data with the following categories of recipients in order to provide our services and operate our business: entities forming part of our corporate group and our shareholders, where strictly necessary and subject to appropriate safeguards; our regulatory, compliance and audit partners; our banking partners and other credit institutions; our professional advisors, including lawyers, auditors and accountants; exchanges and market makers; regulators and supervisory authorities; and our technology service providers.

Technology service providers include: Google (website analytics, subject to your consent); LinkedIn (marketing measurement, subject to your consent); Matomo (privacy-focused analytics); Clerk (sign-in and authentication for our applications); Cloudflare (website security and performance); and the providers of our hosting, email and contact-form infrastructure. Providers acting as processors do so under Article 28 GDPR data processing agreements.

5. International Transfers of Personal Data

We may transfer personal data outside the European Economic Area in order to provide our services and operate our business.

Entities in our corporate group, and our shareholders, are located in Jersey, Switzerland and the United Kingdom. Each of those jurisdictions benefits from an adequacy decision of the European Commission under Article 45 of the GDPR, and transfers to them are made on that basis.

Certain technology providers process personal data in the United States. Where the provider is certified under the EU-US Data Privacy Framework (including Google LLC and LinkedIn Corporation), transfers are made on the basis of the adequacy decision for that framework. In all other cases, and if the adequacy status of any jurisdiction changes, we implement one of the transfer safeguards in Article 46 of the GDPR, typically the European Commission’s Standard Contractual Clauses. You may obtain a copy of the safeguards used by contacting [email protected].

6. Retention of Personal Data

We retain personal data only for as long as necessary to fulfil the purposes we collected it for, including satisfying legal, accounting and reporting requirements. In determining retention periods we consider the amount, nature and sensitivity of the data, the risk of harm from unauthorised use or disclosure, the purposes of processing and the applicable legal requirements.

Personal data processed for the purpose of providing our services is generally retained for five (5) years from the date of termination of our contractual relationship, on the basis of the Financial Institutions Act (Chapter 376 of the Laws of Malta) and our legitimate interest in defending legal claims.

KYC Data, Screening Data and other records retained under the PMLFTR are retained for five (5) years from the end of the business relationship or the date of the occasional transaction, being the minimum period required at law, and for longer only where required by law or directed by the competent authorities.

Communications Data, including records of queries, feedback and complaints, is retained for five (5) years from the date of the relevant communication or, where the communication forms part of a client file, from the end of the business relationship, in line with our record-keeping obligations as a licensed financial institution and our legitimate interest in defending legal claims.

General Data is retained for no longer than is necessary for the purpose for which it was collected, determined by reference to the following criteria: the duration of any legal obligation requiring its retention, the subsistence of the legitimate interest pursued, the applicable limitation periods for legal claims, and whether the purpose can be achieved with anonymised data. When no criterion requires further retention, the data is deleted or anonymised.

7. Processing Requirements

The processing of your personal data is both a statutory requirement and a contractual requirement: we are required to process certain personal data (particularly KYC Data) to comply with anti-money laundering obligations, and processing is necessary for the performance of the services contract we enter into with you or the entity you represent. Failure to provide the required personal data will result in the relevant services being unavailable.

8. Automated Decision-Making

We use automated screening and risk-scoring in our compliance processes. A risk score is generated when a client relationship is established and when transactions, including mint and redemption requests, are screened. The score is based on factors including geography, the nature of the business relationship, interaction type, political exposure and adverse media.

A request may be declined, or referred for manual review, where the resulting risk score exceeds Stable Mint’s risk-appetite thresholds. Compliance personnel regularly review the scores generated and the thresholds applied, and adverse outcomes with legal or similarly significant effect are subject to human review.

Where a decision is based solely on automated processing and produces legal or similarly significant effects, you have the rights set out in Article 22 of the GDPR, including the right to obtain human intervention, to express your point of view and to contest the decision, except where the decision is necessary for entering into or performing our contract with you or is authorised by applicable law. You may exercise these rights by contacting [email protected].

9. Your Rights

For as long as we retain your personal data, you have the following rights, exercisable by contacting [email protected]:

  • Right to object: to object to processing based on our or a third party’s legitimate interests.

  • Right of access: to obtain confirmation of whether we process your personal data and access to it, with the information in Article 15(1) GDPR.

  • Right to erasure: in certain circumstances, to request deletion of your personal data.

  • Right to portability: to receive personal data concerning you in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.

  • Right to rectification: to correct inaccurate or incomplete personal data.

  • Right to restriction: to request that we stop using your personal data in certain circumstances.

  • Right to withdraw consent: where processing is based on consent (including analytics and marketing cookies), to withdraw it at any time, without affecting prior processing; cookie consent can be withdrawn at any time through the settings on the Cookies Policy page.

  • Right to be informed of the source: where personal data was not provided by you directly, to be informed of its source.

These rights are not absolute, and we may be unable to comply with a request where an applicable law prevents us from doing so.

10. Complaints

If you have any complaint regarding our processing of your personal data, we ask that you first contact us at [email protected]. You also have the right at any time to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta (https://idpc.org.mt).

11. Minors

Our services are not available to persons under the age of 18 (“Minors”). We do not knowingly collect personal data from or about Minors. If you are a Minor, you should not use our services or provide any personal data to us. If we become aware that a Minor has shared personal data with us, we will delete it; if you believe a Minor has done so, please contact [email protected].

12. Third-Party Personal Data Provided by Corporate Clients

If you represent a company, intermediary or other corporate entity and you provide Stable Mint with personal data of third-party individuals (such as employees, directors, beneficial owners, service providers or underlying clients), you are responsible for ensuring that: you bring this privacy notice to the attention of those individuals; the collection, transfer and provision of that personal data complies with applicable law; the entity you represent, as a controller, remains responsible towards those individuals under applicable data protection law; you obtain any notices, approvals or consents required before providing the personal data to Stable Mint; and the information you give us is accurate and kept up to date.

Where we receive personal data of such third-party individuals indirectly, Stable Mint relies on Article 14(5)(b) of the GDPR in respect of the obligation to provide the information in Article 14 directly to each individual, on the basis that individually notifying every employee, director, beneficial owner or underlying client of every corporate client would involve disproportionate effort given the number of individuals concerned, the absence of a direct relationship with them and the compliance-driven nature of the processing. As the appropriate measures required by Article 14(5)(b), we make this privacy notice publicly available on our website, we require the corporate client to bring it to the attention of the individuals concerned as set out above, and, where beneficial owners or authorised representatives are identified to us in the course of onboarding and their contact details are on file, we provide this notice to them directly where practicable.

The entity you represent shall indemnify Stable Mint on first written demand against all costs, damages or liability resulting from claims or litigation against Stable Mint arising from the provision of such personal data in breach of this section. This indemnity does not affect Stable Mint’s own responsibility for compliance with its obligations under the GDPR.

13. Updates to this Notice

We may update this privacy notice from time to time, including as a result of changes in applicable law or in our processing activities. Material changes will be communicated to you before the relevant processing commences, and the “last updated” date will be revised on each change.

Nesta página

  • 1. Identity of the Controller
  • 2. Categories of Personal Data
  • 3. Purposes of Processing and Legal Basis
  • 4. Categories of Recipients
  • 5. International Transfers of Personal Data
  • 6. Retention of Personal Data
  • 7. Processing Requirements
  • 8. Automated Decision-Making
  • 9. Your Rights
  • 10. Complaints
  • 11. Minors
  • 12. Third-Party Personal Data Provided by Corporate Clients
  • 13. Updates to this Notice

A Stable mint Ltd. é uma Instituição de Moeda Eletrônica (EMI) plenamente licenciada, autorizada pela Malta Financial Services Authority nos termos do artigo 4 do Financial Institutions Act (Chapter 376 of the Laws of Malta) a emitir moeda eletrônica conforme definida no Third Schedule; a prestar os serviços de pagamento 2(a), 2(b) e 2(c) do Schedule 2 da referida lei; e a prestar custódia e administração de criptoativos em nome de clientes nos termos do artigo 60(4) do Regulamento relativo aos Mercados de Criptoativos (MiCA).

Produtos

  • Empresas
  • Stablecoins
  • API para desenvolvedores

Sobre

  • Sobre
  • Casos de uso
  • Conteúdos
  • Perguntas frequentes
  • Contato

Siga-nos

© 2026 Stable mint Ltd. Todos os direitos reservados.

Política de PrivacidadeTermos e CondiçõesPolítica de Cookies Whitepaper USDSM Whitepaper EURSM
English Español Português

Usamos cookies para melhorar sua experiência e para marketing. Só ativamos depois que você aceitar. Leia nossa política de cookies ou gerencie os cookies.