What data we collect, why, how long we keep it and what you can demand.
This version applies from 2026-09-10
This document was drawn up in Lithuanian. Translations into other languages are provided for convenience; in the event of any discrepancy, the Lithuanian version prevails. This does not deprive a consumer of the protection of the mandatory rules of the law of their own country of residence.
MB Kriptika, company code 306375825, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania.
Questions about data - info@kriptika.lt.
We have no data protection officer - the scale of the company's activity does not require one.
When ordering: email address, blockchain address or transaction hash, chain, date of the incident (if you give one), report language.
Record of consent: the text of the confirmations about starting the service and about the right of withdrawal, the exact time and the IP address.
During the free check: the address checked, the chain, the verdict, the time and the IP address. We do not ask for an email address for the check.
When paying: Stripe handles the payment data and passes us only the payment status and identifiers. We never see the card number.
We use no cookies for analytics or advertising.
Performance of a contract (GDPR Art. 6(1)(b)): producing and delivering the report, correspondence about the order.
Legal obligation (Art. 6(1)(c)): accounting records and the recording of consents required by consumer protection law.
Legitimate interest (Art. 6(1)(f)): the log of free checks and rate limiting - so that the service is not abused and so that in a dispute we can show what the customer saw before buying.
Stripe Payments Europe, Ltd. (Ireland) - payment processing.
HOSTINGER, UAB (Lithuania, company code 302710386, Švitrigailos g. 34, LT-03230 Vilnius) - the mailbox and delivery of the report email.
Cloudflare, Inc. - network protection and availability of the website.
Etherscan and other blockchain data sources - they receive only the blockchain address, which is public in any case. We never pass them your email address or your name.
We do not sell data and do not pass it on for advertising purposes.
Order data is stored on a server we operate in Lithuania.
The mailbox is operated by a Lithuanian company, so the content of the emails does not leave the European Economic Area.
Stripe and Cloudflare may process data outside the EEA under the standard contractual clauses approved by the European Commission.
The report and the tracing data - 12 months from delivery. That is what we need to be able to reproduce the document if you lose it or if questions arise about its content.
The log of free checks - 12 months.
Order and payment accounting records - for the period required by law.
Once the period ends, the data is deleted.
You have the right to access your data, to have it corrected or erased, to restrict processing, to object to processing based on legitimate interest, and to receive the data in a structured format.
Write to info@kriptika.lt. We reply within 30 days.
Some data we cannot erase while the statutory obligation to keep accounting records still applies - we will tell you when that is the case.
If you believe your data is being handled improperly, you may contact the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt) or the supervisory authority in your own country.
Blockchain addresses and transactions are public and cannot be removed - nobody can delete them, ourselves included.
On our side we delete the link between you and the address: the order, the email and the tracing data. The address itself stays on the chain, because it was there before we ever met.
In reports we label only companies and services. We do not name natural persons and we do not look for them.
This version applies from 2026-09-10. If we change the policy, we publish the new version on this page.