Legal

Privacy Policy

Last updated September 30, 2026.

This Privacy Policy explains how Altrady B.V. ("Coinray", "we", "us" or "our"), the provider of the Coinray crypto market-data API and website (the "Service"), collects, uses, discloses, and protects personal data, and your rights under the EU General Data Protection Regulation (GDPR) and Dutch data-protection law.

Data controller. Altrady B.V., registered in the Netherlands under Chamber of Commerce (KvK) number 77469607, VAT (BTW) number NL861016804B0, registered postal address (not a visiting address) Vlietweg 17, 2266 KA Leidschendam, the Netherlands, is the controller of personal data processed under this Policy. For privacy questions or to exercise your rights, contact [email protected].

1. Scope

This Policy applies to personal data we process about visitors to our website and users of the Service (who are business customers and their authorized personnel). It does not cover third-party websites or services we link to, or the market data itself, which is factual, non-personal information.

2. Personal data we collect

  • Identity and contact data: name, business email address, company name, and role, provided when your account is created or when you contact us.
  • Account and credential data: login credentials (passwords are stored only as salted hashes) and metadata about your API keys (we store key identifiers and hashed secrets, never your raw secret after issuance).
  • Billing data: your purchases are processed by Stripe as Merchant of Record (see our Terms). We receive limited billing metadata such as subscription status, invoice records, and a payment reference; we do not receive or store full payment-card numbers.
  • Usage and technical data: API request counts, endpoints called, timestamps, quota and rate-limit information, IP address, device and browser information, and diagnostic and error logs.
  • Communications data: the content of messages you send us (for example, support or sales enquiries).

3. How we use your data and our legal bases

We process personal data for the following purposes and on the following legal bases under Article 6(1) GDPR:

  • To provide the Service : create and administer your account, issue and authenticate API keys, and deliver the API, on the basis of performance of a contract (Art. 6(1)(b)).
  • To meter usage, enforce rate limits, secure the Service, prevent fraud and abuse, and improve and troubleshoot the Service , on the basis of our legitimate interests (Art. 6(1)(f)) in operating a reliable and secure service.
  • To handle billing and keep records , on the basis of performance of a contract and compliance with a legal obligation (Art. 6(1)(b) and (c)), including tax and accounting laws.
  • To communicate with you about the Service, respond to enquiries, and send service-related notices, on the basis of contract and legitimate interests. Any marketing emails are sent only where permitted, and you can opt out at any time.
  • To comply with legal obligations and establish, exercise, or defend legal claims, on the basis of legal obligation and legitimate interests.

4. Cookies and analytics

Our website and developer portal use strictly necessary cookies required for authentication, security, and basic functionality. Where we use any non-essential cookies or analytics, we do so only with your consent, which you can manage or withdraw at any time. We do not sell your personal data or use it for cross-site advertising.

5. How we share your data

We do not sell your personal data. We share it only with the following categories of recipients, who act as our processors under written agreements or as independent controllers where applicable:

  • Payments: Stripe (payment processing and Merchant of Record).
  • Hosting and infrastructure: our cloud and hosting providers (including OVHcloud) that host the Service in the EU.
  • Monitoring and diagnostics: error- and performance-monitoring providers (including Sentry and New Relic) and cloud storage (Amazon Web Services) used to operate and secure the Service.
  • Professional advisers and authorities: accountants, auditors, legal advisers, and public authorities where required by law.
  • Business transfers: a successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. International data transfers

We aim to keep personal data within the European Economic Area (EEA). Where a processor processes data outside the EEA, we ensure an appropriate safeguard is in place under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, so your data receives an equivalent level of protection.

7. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy. Account and profile data are retained for the life of your account and for a reasonable period afterward. Billing and transaction records are retained for the period required by applicable tax and accounting law (in the Netherlands, generally seven years). Usage and technical logs are retained for a limited period for security, debugging, and capacity planning, after which they are deleted or anonymized.

8. Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit, hashing of passwords and API secrets, access controls, network segmentation, and monitoring. No method of transmission or storage is completely secure; if we become aware of a personal-data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals in accordance with the GDPR.

9. Your rights

Subject to the conditions in the GDPR, you have the right to: access your personal data; have inaccurate data corrected; have your data erased; restrict or object to certain processing (including processing based on legitimate interests and any direct marketing); receive your data in a portable format; and, where processing is based on consent, withdraw that consent at any time without affecting prior processing.

To exercise any of these rights, contact [email protected] . We will respond within the time limits set by the GDPR. You also have the right to lodge a complaint with your local data-protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us personal data, please contact us and we will delete it.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, including profiling.

12. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide reasonable notice by posting the updated Policy with a new "Last updated" date and, where appropriate, by email. Your continued use of the Service after the changes take effect constitutes acknowledgment of the updated Policy.

13. Contact

Questions about this Policy or our data practices: [email protected].