Privacy Policy
1. Introduction and data controller
This Privacy Policy explains how “Sixth Sense Group” d.o.o. Bijeljina (“Sixth Sense Pay”, “we”, “us” or “our”) processes personal data in connection with the Sixth Sense Pay self-custodial wallet application and related website (together, the “App”). We are the data controller. Our registered office is at Meše Selimovića 4, Bijeljina, Bosnia and Herzegovina. For any privacy question, request or complaint, contact soporte@sixthsensepay.com.
We are committed to protecting your privacy and to processing personal data in accordance with applicable data-protection law, including the law of Bosnia and Herzegovina and the laws of the countries where our users are located: Argentina, Paraguay, Uruguay and Brazil.
2. Privacy by design: a self-custodial wallet
The App is a self-custodial wallet. We never collect, hold or have access to your Private Keys or Recovery Phrase — these are generated and stored only on your device and remain under your sole control. We do not require identity verification (“KYC”) for you to store, send or receive virtual assets using the App. As a result, we collect only a limited amount of personal data, as described below.
3. Personal data we collect
Data you provide to us
- contact and support data: your name, email address and the content of your message when you contact us (for example, at soporte@sixthsensepay.com); and
- any other information you choose to provide.
Data collected automatically when you use the App
- device and technical data: device type, operating system, App version, language settings and device identifiers;
- network data: IP address and the approximate location derived from it;
- usage and diagnostic data: interactions with the App and diagnostic or crash information; and
- cookies and similar technologies on our website (see Section 13).
On-chain data
Public wallet addresses, transaction hashes, amounts and timestamps that you generate are recorded on the public blockchain. This data is public by nature and is not created or controlled by us.
What we do not collect
We do not collect your Recovery Phrase, your Private Keys, or the contents of your wallet beyond what is publicly recorded on the blockchain.
Third-Party Services (on-ramp, off-ramp, swaps)
If you choose to use Third-Party Services such as fiat on-ramp/off-ramp or swaps, the relevant provider collects and processes your identity-verification (KYC) and transaction data as an independent data controller under its own privacy policy. We may receive limited confirmation data, such as the fact that verification succeeded or a transaction reference.
4. How we use personal data and legal bases
We use personal data to:
- provide, maintain and support the App;
- secure the App and prevent, detect and investigate fraud, abuse and security incidents;
- comply with legal obligations, including anti-money-laundering and counter-terrorist-financing (AML/CFT), sanctions screening and transaction monitoring (KYT) applied to public wallet addresses that interact with our infrastructure;
- respond to your support requests;
- analyze and improve the App; and
- send you service, security and legal notices. Depending on the law that protects you, we rely on the following legal bases: performance of a contract with you (providing the App); our legitimate interests in the security, integrity and improvement of the App, balanced against your rights and freedoms; compliance with a legal obligation (AML/CFT, sanctions and record-keeping); and your consent where required (for example, certain cookies or analytics), which you may withdraw at any time.
5. Transaction monitoring and sanctions screening
To meet legal obligations and prevent financial crime, wallet addresses and transactions that interact with our infrastructure and with Third-Party Services may be screened and risk-scored using specialized blockchain-analytics tools (Know Your Transaction, or “KYT”). This processing uses on-chain data and does not involve any access to your keys or funds. Where a sanctions match or high-risk indicator arises, we may restrict access to the App or to Third-Party Services and, where legally required, report to competent authorities.
This screening may involve automated analysis. It does not produce a legal effect that deprives you of custody of your assets, which always remain under your control. Where an automated decision significantly affects you, you may request human review and contest the decision as provided by applicable law.
6. Sharing and disclosure
We share personal data with:
- service providers and processors acting on our behalf under contract (for example, cloud/hosting, analytics, crash reporting, blockchain-analytics/KYT and customer-support tools);
- Third-Party Service providers you choose to use, which act as independent controllers;
- competent authorities, regulators and law-enforcement bodies where required by law, including the Financial Intelligence Unit and APIF of Bosnia and Herzegovina; and
- professional advisers, or a successor entity in connection with a corporate transaction such as a merger or acquisition. We do not sell your personal data.
7. International transfers
We are based in Bosnia and Herzegovina and may process personal data there, in the European Union / European Economic Area, and in other countries where our service providers operate. Where personal data is transferred across borders, we rely on appropriate safeguards recognized by applicable law, such as an adequacy recognition, standard contractual clauses, or your consent. The European Union and Uruguay are recognized as providing an adequate level of data protection; for transfers to other countries we implement contractual and technical safeguards.
8. Blockchain data is public and permanent
Transactions you make are recorded on public blockchains that we do not control. On-chain data is public, immutable and generally cannot be modified or deleted, including by us. This limits our ability to satisfy certain requests — such as a request for erasure — with respect to data already recorded on-chain.
9. Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy. Where we act as an obliged entity under applicable AML law, certain records — including compliance and transaction-monitoring records — are retained for the legally required period, which is a minimum of five (5) years. Support communications and technical logs are kept for shorter periods consistent with their purpose.
10. Security
We apply appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls and monitoring. No system is completely secure. You remain responsible for securing your device, your access credentials and your Recovery Phrase, which we never hold and cannot recover.
11. Your rights and how to exercise them
Depending on the law that protects you, you may have the right to access your personal data; to rectify inaccurate data; to request erasure or deletion; to object to or restrict certain processing; to data portability; to withdraw consent; and not to be subject to certain automated decisions. To exercise any right, contact soporte@sixthsensepay.com. We may need to verify your identity before responding. You may also lodge a complaint with the data-protection authority that applies to you:
| Country | Authority and principal law |
|---|---|
| Argentina | Agencia de Acceso a la Información Pública (AAIP) — Ley 25.326 de Protección de los Datos Personales (habeas data / ARCO rights). |
| Paraguay | Ley 7.593/2025 de Protección de Datos Personales (general framework; supervisory authority and full obligations phasing in through November 2027) and Ley 6534/2020 on credit data. |
| Uruguay | Unidad Reguladora y de Control de Datos Personales (URCDP) — Ley 18.331. |
| Brazil | Autoridade Nacional de Proteção de Dados (ANPD) — Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018). |
| Bosnia and Herzegovina | Personal Data Protection Agency of Bosnia and Herzegovina. |
12. Children
The App is not directed to, and is not intended for, persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us so we can delete it.
13. Cookies and analytics
Our website may use cookies and similar technologies for functionality, security and analytics. You can manage or reject non-essential cookies through the consent tool on our website or through your browser settings. The App may use analytics and diagnostic tools to understand usage and improve stability; where required, we obtain your consent.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will publish the updated version with a new effective date and, where material changes are made, notify you as required by law.
15. Contact
Data controller: “Sixth Sense Group” d.o.o. Bijeljina, Meše Selimovića 4, Bijeljina, Bosnia and Herzegovina. For any privacy question, request or complaint, contact soporte@sixthsensepay.com.