Privacy notice
This English version is provided for convenience. In case of doubt, the German version prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is olaMac Security & Logistics, (not yet published), email: (not yet published).
For data protection matters, contact us at (not yet published).
2. What we process
- Identification and contact data: name, date and place of birth, nationality, address, email, telephone number and details of your identity document.
- Documents you upload to verify your identity and address; for companies also register extracts and details of representatives and beneficial owners.
- Account and custody data: your metal holdings, deposits, releases, transfers of ownership, delivery addresses, documents you request, invoices and payment references. If you transfer metal to another client, or receive it, the other party sees your name and account number.
- Communications: secure mailbox messages, chat transcripts and support requests.
- Security data: sign-in times, IP addresses, device information and a log of actions in your account.
We do not collect or store payment card data.
3. Purposes and legal bases
- Performance of the contract: custody, storage, verification, transport and billing (Art. 6(1)(b) GDPR).
- Compliance with legal obligations, in particular under the Money Laundering Act and commercial and tax record-keeping rules (Art. 6(1)(c) GDPR).
- Legitimate interests in securing your account and our premises and preventing fraud (Art. 6(1)(f) GDPR).
- Consent for optional notifications such as SMS alerts, which you can withdraw at any time in your profile (Art. 6(1)(a) GDPR).
Providing the data needed to open an account and identify you is required by law; without it we cannot enter into a contract.
4. Recipients
We disclose personal data only to: transport and insurance providers where needed to move and protect your metal; banks and payment service providers; auditors, legal advisers and IT providers bound by confidentiality (processors under Art. 28 GDPR); and authorities where required by law, such as the Financial Intelligence Unit (FIU), tax and law-enforcement authorities. We do not sell personal data.
5. Transfers to third countries
Transfers to countries outside the EU/EEA take place only under the conditions of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision or the European Commission's standard contractual clauses.
6. Security
Identity documents and records are stored encrypted and unalterably with integrity checks. Only authorised staff have access for their duties, and every access is logged. Sessions expire automatically and can be ended in your profile.
7. Retention
We keep data for the duration of the relationship and afterwards as long as the law requires: records under the Money Laundering Act for five years (section 8(4) GwG), commercial and tax records for six or ten years (section 257 HGB, section 147 AO). Security logs are deleted after two years at the latest.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21 GDPR). You may withdraw consent at any time with effect for the future. Contact (not yet published). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
9. Cookies
We use only strictly necessary cookies. See our cookie notice.
10. Changes
We publish updates to this notice on this page and inform you of material changes in the portal.