This Privacy Policy governs the manner in which BigeDirect collects, uses, maintains, and discloses information collected from users (each, a “User”) of the BigeDirect website (the “Site”). This Privacy Policy applies to the Site and all products and services offered by BigeDirect.
Data Controller:
BigeDirect ApS is a limited liability company organised under the laws of Denmark, registered under no. 43762125, with its registered office at Nannasgade 28, st. 2200 København N, Denmark. BigeDirect ApS is the controller of your personal data within the meaning of the GDPR. You can contact us at info@bigedirect.com or by post at the address above.
Data Protection Officer:
We have appointed a Data Protection Officer whom you may contact on any matter relating to the processing of your personal data or the exercise of your rights under the GDPR. E-mail: info@bigedirect.com.
Personal Identification Information:
We may collect personal identification information from Users in various ways, including but not limited to when Users visit our Site, fill out a form, subscribe to our newsletter, register for our services, or perform a transaction. Categories of personal data we may process include identification data (name, date of birth, nationality, government-issued ID details), contact data (email address, phone number, postal address), transaction data (amounts, counterparties, blockchain addresses, timestamps), authentication data (login credentials, device identifiers), KYC/AML data (proof of identity and address, source-of-funds information, sanctions and PEP screening results), and technical data (IP address, browser, device). Users may visit our Site anonymously; however, certain services cannot be provided without the data required by law.
Non-personal Identification Information:
We may collect non-personal identification information about Users whenever they interact with our Site. Non-personal identification information may include the browser name, the type of computer or device, technical information about Users’ means of connection to our Site, such as the operating system and the Internet service providers utilized, and other similar information.
Web Browser Cookies:
Our Site may use “cookies” to enhance User experience. Users’ web browsers place cookies on their hard drives for record-keeping purposes and sometimes to track information about them. Users may choose to set their web browsers to refuse cookies or to alert them when cookies are being sent. If they do so, note that some parts of the Site may not function properly. Read more at bigedirect.com/cookies.
How We Use Collected Information:
BigeDirect may collect and use Users’ personal information for the following purposes:
- To provide our services: processing transactions, operating user accounts, and enabling the sending, receiving, and converting of virtual currencies and means of payment.
- To improve customer service: information provided helps us respond to customer service requests and support needs more efficiently.
- To personalize user experience: we may use information in the aggregate to understand how our Users as a group use the services and resources provided on our Site.
- To improve our Site: we continually strive to improve our website offerings based on the information and feedback we receive from Users.
- To send periodic emails: we may use the email address to respond to inquiries, questions, and other requests. If the User opts in to our mailing list, they will receive emails that may include company news, updates, and product or service information. Each email contains unsubscribe instructions.
- To comply with legal obligations: as an obligated institution under the Danish AML Act, we process personal data to perform customer due diligence (KYC), monitor transactions, screen against sanctions and politically exposed persons lists, and report to the General Inspector of Financial Information where required by law.
- To prevent fraud and ensure security of our services and Users.
- To establish, exercise, or defend legal claims.
Legal Bases for Processing:
We process your personal data on the following legal bases under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR) — to provide our services and operate your account.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — to fulfil obligations under the Danish AML Act, accounting and tax law, and other applicable laws.
- Consent (Art. 6(1)(a) GDPR) — for marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legitimate interests (Art. 6(1)(f) GDPR) — to operate, secure, and improve our Site and services, prevent fraud, and establish, exercise, or defend legal claims.
How We Protect Your Information:
We adopt appropriate data collection, storage, and processing practices and security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal information, username, password, transaction information, and data stored on our Site.
Data Retention:
We retain your personal data only for as long as is necessary for the purposes for which it was collected and, in particular, for the following periods:
- Customer identification data, transaction records, and other KYC/AML documentation — retained for 5 years, counted from the day on which business relations with the customer ended, or from the day on which the occasional transaction was carried out, in accordance with Article 49 sec. 1 of the Danish AML Act. This period may be extended by a further period of up to 5 years where the General Inspector of Financial Information so requests under Article 49 sec. 3 of the Danish AML Act.
- Results of analyses carried out under Article 34 sec. 3 of the Danish AML Act — retained for 5 years from the day on which they were carried out, in accordance with Article 49 sec. 2 of the Danish AML Act.
- Accounting and tax documentation — retained for 5 years, counted from the end of the calendar year in which the tax payment deadline expired, in accordance with the Danish Tax Ordinance and the Accounting Act.
- Data processed on the basis of your consent (e.g. marketing) — retained until consent is withdrawn.
- Data necessary to establish, exercise or defend legal claims — retained until the relevant limitation period expires under the Danish Civil Code.
After the applicable retention period expires, your personal data is deleted or irreversibly anonymised.
Sharing Your Personal Information:
We do not sell, trade, or rent Users’ personal identification information to others. We may share your personal data with the following categories of recipients:
- Service providers acting as processors on our behalf, including:
- website hosting and content infrastructure (Automattic Inc., United States, providing WordPress and WooCommerce);
- security and bot-management services (Cloudflare, Inc., United States);
- web analytics (Google LLC, United States, providing Google Analytics);
- marketing automation, CRM, and form processing (HubSpot, Inc., United States);
- identity verification (KYC) and document verification providers;
- blockchain analytics and transaction-monitoring providers;
- communications and email-delivery providers;
- customer-support tools.
- Banks and payment institutions involved in the execution of transactions.
- Danish public authorities, including the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej), the National Revenue Administration (Krajowa Administracja Skarbowa), the Danish Financial Supervision Authority, law enforcement and judicial authorities, where required by law.
- Professional advisors, including auditors, legal counsel, and tax advisors, bound by professional secrecy.
We may also share generic aggregated demographic information not linked to any personal identification information regarding visitors and users with our business partners, trusted affiliates, and advertisers.
International Data Transfers:
We do not transfer personal data that we hold as controller to third countries. However, when you interact with our Site, certain data may be collected directly by third-party service providers located outside the European Economic Area (EEA) — in particular in the United States — before reaching us. These include Google LLC (web analytics), HubSpot, Inc. (lead capture and marketing forms), Cloudflare, Inc. (security and bot management), and Automattic Inc. (WordPress and WooCommerce infrastructure). For example, when you submit a HubSpot form on our Site, your submission is transmitted to HubSpot’s infrastructure and from there made available to us as a lead. Each of these providers acts on its own legal bases and safeguards under Chapter V of the GDPR, including, where applicable, the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses (Article 46(2)(c) GDPR). For details of the safeguards each provider applies, please refer to their respective privacy policies. You may also contact our Data Protection Officer at info@bigedirect.com with any questions.
Automated Decision-Making and Profiling:
In order to comply with our obligations under the Danish AML Act and to prevent fraud, we use automated tools to assess customer risk, screen against sanctions and politically exposed persons (PEP) lists, and monitor transactions. Decisions based on these tools may, in certain cases, produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR — for example, refusal to enter into a business relationship, blocking of a transaction, or termination of a business relationship. Such processing is necessary for compliance with a legal obligation to which we are subject (Article 22(2)(b) GDPR in conjunction with the Danish AML Act). You have the right to obtain meaningful information about the logic involved, to request human intervention by contacting our Data Protection Officer, to express your point of view, and to contest the decision.
Your Rights:
Subject to the conditions set out in the GDPR, you have the right to:
- access your personal data and obtain a copy (Article 15 GDPR);
- request rectification of inaccurate or incomplete data (Article 16 GDPR);
- request erasure of your data (Article 17 GDPR), noting that this right may be limited where we are required to retain data under the Danish AML Act or other laws;
- request restriction of processing (Article 18 GDPR);
- receive your data in a structured, commonly used, and machine-readable format and transmit it to another controller (Article 20 GDPR);
- object to processing based on our legitimate interests (Article 21 GDPR);
- withdraw consent at any time, where processing is based on consent (Article 7(3) GDPR);
- lodge a complaint with the President of the Personal Data Protection Office — the Danish supervisory authority — or with the supervisory authority in your EU country of residence.
To exercise any of these rights, contact us at info@bigedirect.com.
Compliance with GDPR and Danish Law:
We process your personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the GDPR), and other applicable provisions of Danish and European Union law.
Changes to this Privacy Policy:
BigeDirect has the discretion to update this Privacy Policy at any time. When we do, we will revise the updated date at the bottom of this page.
Last modified: 01 July 2026.