Last update: February 17, 2026
Dear Visitor,
Thank you for visiting our website and for your interest in our services. In the course of operating this website and providing our services, we process personal data that you provide to us. The protection of such data is extremely important to us.
This document contains information regarding the processing of your personal data and information about your rights under Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “GDPR”), and Act No. 110/2019 Coll., on the Processing of Personal Data (hereinafter the “Act”).
This document also includes information about the cookies used on our websites, in accordance with Act No. 127/2005 Coll., on Electronic Communications, as amended.
When we refer to AML regulations in this document, we primarily mean Act No. 253/2008 Coll., onCertain Measures Against the Legalisation of Proceeds of Crime and Financing of Terrorism, as amended, as well as related national and European binding legal regulations concerning AML and the application of international sanctions.
ILAVO GROUP a.s., having its registered office at Pražákova 1024/66a, Štýřice, 639 00 Brno, Company ID No.: 223 77 301, registered with the Commercial Register maintained by the Regional Court in Brno under file no. B 9042 (hereinafter “we” or “ILAVO”), acts as the data controller within the meaning of the GDPR and the Act, determining the purposes and means of processing your personal data as a data subject.
Processing of personal data under this document applies to any processing of data by ILAVO, primarily through the websites https://kvapay.com/, https://kvakomat.com, Ilavo Group - Innovative cryptographic fintech solutions in the EU | Ilavo Group, as well as through the automated device – Kvakomat (Bitcoin ATM).
In connection with the processing of personal data, our company has appointed a Data Protection Officer in accordance with the GDPR, who may be contacted via email at: gdpr@kvapay.com.
The Data Protection Officer oversees the personal data protection system within ILAVO. His responsibilities include providing advice to us and our processors involved in personal data processing regarding their obligations in the field of data protection. He also serves as the contact point for the supervisory authority.
ILAVO processes your personal data in the following situations:
The purpose of processing personal data also includes the implementation of security measures to prevent fraud.
If the processing of your personal data is based on the performance of contractual (or pre-contractual) obligations arising from a contract with you, or on compliance with legal obligations—especially those under AML regulations—such processing is a prerequisite for us to provide our services. If you do not provide the required personal data, we cannot offer our services.
Personal data is collected directly from data subjects, but to the necessary extent it may also be obtained from publicly available registers and sanctions lists for the purpose of fulfilling legal obligations.
If the processing of your personal data by us is based on legitimate interest, the processing is carried out on the basis of balancing tests of proportionality prepared by our company. If you did not provide the data, we would not be able to pursue this interest. When processing your personal data, we pay attention to your rights, respect the principle of data minimisation with regard to the purpose of processing, and follow the conducted balancing tests.
For the purposes listed in the table, we rely on the legal basis of legitimate interest pursuant to Art. 6(1)(f) GDPR. Below you will find a more detailed explanation of the legitimate interests we pursue. ILAVO does not pursue the legitimate interests of third parties.
| Purpose of personal data processing | Legitimate interest |
|---|---|
| Marketing purposes | Increasing awareness of ILAVO (e.g. activity of profiles on social networks), direct/indirect marketing communication, content personalisation and display of advertising. |
| Protection of clients’ assets | We process personal data for the purpose of protecting clients’ assets, fraud prevention, and securing our systems based on the legitimate interest in ensuring the security of financial resources and IT infrastructure. |
If, despite the above, you believe that this processing violates your rights, you may object to the processing of your personal data based on legitimate or public interest, as well as to processing for direct marketing purposes, including objection to related profiling pursuant to Art. 21 GDPR. In such a case, we will restrict the processing of your personal data until we demonstrate the existence of legitimate grounds for processing that override your right not to be subject to such processing. If we do not demonstrate these grounds, we will no longer process your personal data for the given purpose. If you object to processing for direct marketing purposes, we will immediately cease processing for that purpose.
If you have given consent to the processing of personal data, you have the right to withdraw this consent at any time, while the withdrawal does not affect the lawfulness of the processing of personal data obtained before the withdrawal of consent.
Your other rights as a data subject are further specified in Article 7 of this Information.
Telephone calls
Telephone calls made through support to the phone numbers listed on our websites (www.kvapay.com / www.kvakomat.com / www.ilavo.io) or at any Kvakomat may be recorded and stored in accordance with the purpose of their collection.
The legal bases for the processing of personal data for call recording are:
During a telephone call, we create an audio recording which we store for the period necessary to fulfil the purpose of the telephone conversation in accordance with Article 5 of this Information. The legitimate interest of the controller is to ensure customer care, increase customer satisfaction, ensure proper fulfilment of obligations (legal and contractual), create an audio recording for the purpose of improving the services provided, and also to verify the information provided during calls in case of complaints/claims/customer inquiries.
Audio recordings may be systematically processed and evaluated and may also be used in the handling of complaints or in the event of a dispute.
| Purpose | Legal basis |
|---|---|
| Information related to AML regulations | Art. 6(1)(c) of the GDPR Regulation |
| Performance of the contract | Art. 6(1)(b) of the GDPR Regulation |
| Service improvement | Art. 6(1)(f) of the GDPR Regulation |
The client is informed at the beginning of each call that telephone calls are recorded and stored, primarily for the protection of customer deposits and ensuring service quality. If the client does not agree with the creation and storage of an audio recording, they should terminate the telephone connection after being informed about the recording and choose another form of communication.
In most cases, we process your personal data for purposes defined by us as the data controller. In such cases, processing is carried out by our employees. Occasionally, we must use external service providers to ensure proper delivery of our services. These service providers process your personal data on our behalf for purposes we define, including:
If a third party acts as a processor, it processes personal data exclusively on the basis of our instructions and under a personal data processing agreement pursuant to Art. 28 GDPR. If it acts as an independent controller, it processes personal data in its own name and on its own responsibility.
If your personal data is processed via social media, we act as joint controllers with the operators of the respective social media platforms (especially Facebook, Instagram). In such cases, we are obligated to inform you about such processing and provide a lawful basis for the processing of personal data. For more information regarding processing of personal data on Facebook and Instagram, see:
Where required by generally binding legal regulations, we are also obliged to disclose your personal data to competent public and administrative authorities, in particular to regulatory authorities, law enforcement agencies, tax authorities, and other government institutions. However, in such cases, we only disclose your data to the necessary extent required by law.
The list of recipients of personal data is always specified in the relevant legal regulation that obliges us to provide personal data (e.g. courts, law enforcement authorities, bailiffs, insolvency administrators, public authorities, the National Bank of Slovakia, banks), or is stated directly in the consent, if personal data is processed on the basis of the data subject’s consent. If personal data is provided on the basis of a contract between ILAVO and the client, or based on the client’s instruction, the recipients are specified in that contract or instruction.
Most of the processing of personal data by our company and its partners takes place within the EU, the European Economic Area, the United Kingdom of Great Britain and Northern Ireland, or Switzerland. However, in some cases, we may transfer your data to third countries when transferring them to processors, which do not ensure an adequate level of personal data protection. ILAVO uses the services of certain providers such as Google, LLC., Facebook, Inc., and Microsoft Corporation, mainly for marketing and statistical purposes. These providers are located in the United States of America, which constitutes a third country. However, companies that have certified under the so-called EU-US Data Privacy Framework (DPF) mechanism are, according to the decision of the European Commission, considered to provide an adequate level of personal data protection comparable to that in the EU.
The transfer of personal data to third countries (including the United States of America) is carried out on the basis of the European Commission’s adequacy decision within the EU-US Data Privacy Framework (DPF), or on the basis of standard contractual clauses pursuant to Art. 46 GDPR.
ILAVO retains your personal data only for as long as necessary to achieve the purposes of processing, or as long as required by applicable legal regulations. If you have provided consent for data processing, your personal data will be processed until you withdraw that consent. The duration may vary depending on the purpose, but we always ensure data minimization and only process data that is necessary for the specific purpose. Once the purpose ceases, your data is deleted or anonymized.
We process your personal data for the following durations:
Within the fulfilment of obligations under AML regulations, ILAVO uses automated decision-making, including profiling within the meaning of Art. 22 GDPR.
Automated decision-making takes place mainly in:
Based on algorithmic evaluation, the system:
Based on these parameters, a risk rating is assigned to the client or the registration may be automatically rejected, a transaction suspended, or the contractual relationship with the controller terminated.
The legal basis for the processing of biometric data as a special category of personal data is Art. 9(2)(g) GDPR, as the processing is necessary for reasons of substantial public interest on the basis of Union or Member State law, specifically for the purpose of fulfilling obligations under AML regulations.
Automated decision-making is carried out:
In some cases, the automated decision is subsequently subject to manual review by an employee of ILAVO. In case of rejection, you have the right to request that the decision be reviewed by a human.
As a data subject, under Articles 12 et seq. of the GDPR and relevant national law, you have a range of rights concerning the processing of your personal data by ILAVO.
Your primary right is the right to information about the processing of personal data. ILAVO fulfils this obligation through this document, which contains all key details.
Other rights under the GDPR include:
Definition of cookies
Cookies are small text files that are downloaded to your electronic device (e.g., smartphone, tablet, or computer) when you visit a website. The purpose of cookies is to enhance the overall user experience and to enable certain website functionalities (depending on the type of cookie used).
Cookies essential for the proper functioning of our website may be set and used without your consent (so-called essential cookies). All other cookies require your explicit consent before they are activated. While cookie files themselves cannot be directly linked to an identifiable person, data derived from them may be associated with a specific individual. For more information on the processing of such data, please refer to Section 2 above.
The processing of cookies themselves and the data obtained from them may be assigned to a specific person. More about the processing of such data can be found above in Article 2.
Types and Purposes of Cookies Used
By duration, we distinguish between:
We use both session and persistent cookies on our website.
By function, we distinguish between:
| Cookie | Source | Duration | Description |
|---|---|---|---|
| __Host- kvapaycom_session | https | 2 hours | The cookie is used to store session info for multiple browser windows. |
| XSRF-TOKEN | https | 2 hours | This cookie enhances visitor browsing security by preventing cross-site request forgery |
| rc::a | https | Never expires | This cookie is set by the Google reCAPTCHA service to identify bots to protect the website against malicious spam attacks. |
| rc::c | https | Session | This cookie is set by the Google reCAPTCHA service to identify bots to protect the website against malicious spam attacks. |
| cookieyes-consent | https | 1 year | CookieYes sets this cookie to remember users' consent preferences so that their preferences are respected on subsequent visits to this site. It does not collect or store any personal information about the site visitors. |
| _GRECAPTCHA | https | 6 months | Google reCAPTCHA service sets this cookie to identify bots to protect the website against malicious spam attacks. |
| rc::f | https | Never expires | This cookie is set by Google reCAPTCHA service to identify bots to protect the website against malicious spam attacks. |
| rc::b | https | Session | This cookie is set by Google reCAPTCHA service to identify bots to protect the website against malicious spam attacks. |
Microsoft Clarity
On our websites, we use the analytical tool Microsoft Clarity, operated by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, United States of America, link to: Microsoft Privacy Statement - Microsoft privacy, which allows us to analyse visitor behaviour on websites through tools such as heatmaps and session recordings. More information about cross-border data transfers can be found in Article 4 of this Information. Microsoft Clarity uses input field masking technologies to prevent the recording of sensitive personal data entered into forms. The purpose of personal data processing is to improve website functionality, optimise the user interface, and increase the quality of services provided. The legal basis for processing is your consent pursuant to Art. 6(1)(a) GDPR. Data is retained for a maximum period of 12 months from the granting of consent or for the entire duration of your consent.
| Cookie | Source | Duration | Description |
|---|---|---|---|
| prism_* | https | 1 month | Active Campaign sets this cookie to track and store interactions. |
| _ga_* | https | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| _ga | https | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _clck | https | 1 year | Microsoft Clarity sets this cookie to retain the browser's Clarity User ID and settings exclusive to that website. This guarantees that actions taken during subsequent visits to the same website will be linked to the same user ID. |
| _clsk | https | 1 day | Microsoft Clarity sets this cookie to store and consolidate a user's pageviews into a single session recording. |
Advertising cookies (Advertisement)
Advertising cookies are used to provide visitors with personalised advertisements based on the pages you have previously visited and to analyse the effectiveness of advertising campaigns.
| Cookie | Source | Duration | Description |
|---|---|---|---|
| _gcl_au | https | 3 months | Google Tag Manager sets this cookie to experiment with advertisement efficiency of websites using their services. |
| _fbp | https | 3 months | Facebook sets this cookie to store and track interactions. |
We also use so-called third-party cookies, which are cookies managed by a third party and which our company has allowed to be placed on its website.
We use the following third-party cookies:
https://www.google.com/recaptcha/about/
https://clarity.microsoft.com/
On your first visit to our website, a small pop-up window with cookie information will appear, where you can also choose which cookies you want to allow. By selecting and clicking the "Accept all" button, you consent to the use of all the types of cookies described above. By clicking the "Preferences" button, you can set which types of cookies you allow us to use. By clicking the "Reject all" button, you refuse the use of cookies. In that case, we will only store the necessary cookies. You can manage cookie usage directly via the pop-up window or through your web browser:
We reserve the right to change or update this document at any time and to any extent in order to ensure it contains up-to-date information. If we make a material change to the information contained in this document, we will notify you of this change, for example, through a general announcement on our main websites or via email.