blockfunded
Terms Withdrawal Cookies Support
Open app
Back to blockfunded Privacy

Privacy Policy

This notice explains how Kiwea Trading Group OÜ processes personal data when you use blockfunded.

Effective: August 12, 2026Controller: Kiwea Trading Group OÜVersion: 2026-08-12
On this page 1. Controller2. Data we process3. Purposes and legal bases4. Recipients5. International transfers6. Retention7. Your rights8. Choices and cookies9. Security10. Contact
At a glance

We use account and transaction data to deliver a paid simulated trading evaluation. Google Analytics is optional and its tag is not loaded until analytics consent is granted.

01

Controller

Kiwea Trading Group OÜ, registry code 16668415, VAT ID EE102583234, Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Estonia, is the controller.

Privacy contact: [email protected]. Phone: +49 159 06040495.

02

Personal data we process

Account and identity data: name, email, phone only if voluntarily provided, password hash, account identifiers, age/eligibility confirmations and, where a funded-stage or compliance review requires it, identity, residency, sanctions and KYC evidence.

Order and payment data: billing address, optional company and VAT details, selected product, price, currency, invoice, payment reference, payment status, provider identifiers and, for blockchain payments, public wallet address and transaction data. We do not receive a wallet private key.

Service and support data: simulated account balances, orders, positions, performance, objectives, rule events, device push subscriptions, support messages and records necessary to investigate complaints.

Technical and security data: IP address, timestamps, browser or device details, authentication and activity logs, security events, cookie choices, language and checkout state. A referral code requested by you is stored as necessary attribution. With analytics consent, we store only allow-listed campaign-source and channel categories plus a coarse external-referrer category; raw campaign names, click identifiers, referrer URLs, query values and landing paths are not retained.

Optional analytics data: after consent, Google Analytics 4 receives a pseudonymous client identifier, page and interaction events, limited approximate location and device/browser information, plus allow-listed campaign-source and channel categories. After payment has been confirmed and the challenge activated, the pseudonymous server order identifier is sent as the GA4 purchase transaction ID so a reload or return from a hosted payment page does not count the same purchase twice. Detailed location and device-data collection, Google Signals, user-provided data collection and advertising personalisation are disabled. We do not intentionally send names, email addresses, account IDs, payment references, wallet addresses, raw referrer URLs, click identifiers or other direct identifiers to Google Analytics.

We obtain data from you and your device; from the payment provider or public blockchain needed to verify a payment; from the referral partner identified by a referral link; and from public or specialist verification sources if a compliance review is required.

03

Purposes and legal bases

Contract (GDPR Article 6(1)(b)): create and authenticate accounts, process checkout, issue invoices, reconcile payments, provide the simulated evaluation, calculate progress and respond to service requests.

Legal obligations (Article 6(1)(c)): accounting, tax, consumer-law records, sanctions and other mandatory compliance duties.

Legitimate interests (Article 6(1)(f)): prevent fraud and abuse, secure and diagnose the service, establish or defend legal claims, operate service logs, improve reliability and produce aggregated business reporting. We balance these interests against your rights.

Consent (Article 6(1)(a)): optional Google Analytics, optional marketing messages and browser push notifications. Consent can be withdrawn at any time without affecting prior lawful processing.

Providing identity, billing and contact data marked as required is necessary to enter into and perform the contract. Without it, we cannot create or activate an order. Marketing and analytics data are optional.

04

Recipients and processors

Access is limited to personnel and contractors who need it. Depending on the selected flow, recipients include hosting, database, email and support infrastructure providers; banks and payment providers; Solana network/RPC infrastructure for public blockchain verification; professional legal, tax and accounting advisers; identity or sanctions-verification providers if a review is initiated; and public authorities where legally required.

After analytics consent, Google Ireland Limited processes Google Analytics data for us. Google LLC and its infrastructure may also process that data as described below. We disclose only the data necessary for each service.

05

International transfers

Some providers may process data outside the European Economic Area. We use an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures. You may request information or a copy of the applicable safeguards from [email protected].

06

Retention

Orders, invoices, contract acceptance and accounting records are generally kept for seven years after the relevant financial year so transactions can be reconstructed under Estonian accounting and tax rules. Account and simulated trading records are kept for the contract period and ordinarily up to three years afterward for support, fraud prevention and legal claims, unless a longer legal period or an active dispute requires retention.

Support and complaint records are ordinarily kept for up to three years after closure. Security logs are ordinarily kept for up to 12 months, with shorter operational logs deleted sooner unless needed for incident investigation. Uncompleted checkout recovery data is ordinarily deleted or anonymised within 90 days. Marketing data is kept until consent is withdrawn or after 24 months of inactivity.

Google Analytics event- and user-level retention is configured to 14 months without resetting the period on new activity. The first-party _ga and _ga_* cookies can last up to two years unless deleted or consent is withdrawn. Aggregated standard reports may remain available without directly identifying you.

07

Your rights and automated rule enforcement

Subject to the GDPR conditions, you may request access, correction, deletion, restriction, portability and object to processing based on legitimate interests or direct marketing. You may withdraw consent at any time. You also have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, aki.ee, or your local EEA supervisory authority.

We may need to verify your identity. We ordinarily respond within one month. The evaluation automatically compares simulated equity, profit, drawdown and time/trading-day data with the published program thresholds. A recorded threshold breach can close the simulated evaluation account. This standardised processing is necessary to perform the evaluation contract. You may contest a suspected data or calculation error, provide your view and request human review through support.

08

Cookies, analytics and marketing choices

Necessary browser storage supports language, consent, security, checkout recovery and requested affiliate attribution. Optional Google Analytics and marketing storage remain off unless separately allowed. You can reopen the cookie settings from the website footer, change choices at any time and read the Cookie Policy.

The Google Analytics property uses measurement ID G-9D6RDPZL12. Enhanced Measurement is limited to page views, scrolls, outbound clicks and file downloads; site search, form interactions and video engagement are disabled. Email-like values are redacted and configured sensitive URL parameters are masked. Google account data-sharing settings are disabled and no Google Ads account is linked.

Marketing consent is separate from transactional account, security, order and payment messages. Use the unsubscribe facility or contact us to stop marketing.

09

Security and updates

We use access controls, encryption in transit, credential hashing, audit logging, backups and service monitoring appropriate to the risks. No system is completely secure. If a personal-data breach creates a legally reportable risk, we notify the competent authority and affected people as required.

We may update this notice when processing changes. Material changes are communicated where required and do not retroactively change the legal basis for earlier processing.

10

Contact

Send privacy questions or rights requests to [email protected].

© 2026 blockfunded.io is a brand of Kiwea Trading Group OÜTerms of UsePrivacy PolicyCookie PolicyWithdrawalSepapaja tn 6, 15551 Tallinn, Estonia