Data protection

Privacy policy

Bitaps handles evidence that is often the most sensitive information a client owns: wallet addresses, transaction histories, identity documents and correspondence with the people who defrauded them. This policy explains what we collect, why, how long we keep it, and the control you retain over it.

Last updated 24 August 2026

01Who we are

Bitaps is a blockchain intelligence and digital forensics firm established at Marken 6, Himmelev, 4000 Roskilde, Denmark. For the personal data described in this policy we act as the data controller, except where we process data strictly on the instructions of instructing counsel or a corporate client, in which case we act as a processor under a separate agreement.

Privacy enquiries and data-rights requests: support@bitaps.co.

02Data we collect

We collect only what a case requires. In practice that falls into five groups:

  • Contact and account data — name, email address, phone or messaging handle, portal login credentials and authentication metadata.
  • Case and incident data — your description of the incident, dates, amounts, the service you engaged and correspondence with our analysts.
  • On-chain identifiers — wallet addresses, transaction IDs, contract addresses and bridge messages you submit or that we derive during tracing.
  • Verification documents — identity documents, proof of wallet ownership, authorisations and police or exchange reference numbers, where these are needed to act on your behalf.
  • Technical data — IP address, device and browser information, and security logs generated when you use the client portal.

We do not ask for and do not want your seed phrase, private keys or exchange passwords. No member of our team will ever request them. Treat any such request as fraudulent.

03Why we process it, and on what basis

  • Performance of a contract — to run your investigation, recovery, audit or monitoring engagement and to operate your case file in the client portal.
  • Legitimate interests — to secure our systems, prevent abuse of our services, keep internal records of work performed and improve our methodology.
  • Legal obligation — to meet record-keeping, client-verification and reporting duties that apply to us, and to respond to lawful requests from competent authorities.
  • Consent — for optional communications, and where you ask us to share your findings with a named third party such as an exchange, insurer or law firm.

On-chain data is public by design. Where we combine public ledger data with information that identifies you or a counterparty, we treat the combined result as personal data and protect it accordingly.

04Who we share data with

We disclose case information only where it advances your matter or the law requires it:

  • exchanges, custodians and bridge operators, when filing a freeze, hold or reclaim request;
  • law enforcement, regulators and courts, in response to a lawful request or a filing you authorise;
  • instructing or receiving counsel and insurers you nominate in writing;
  • vetted service providers who host our infrastructure, store case files or supply blockchain attribution data, bound by confidentiality and data-processing terms.

We do not sell personal data and we do not use case data for advertising.

05International transfers

Our work is cross-border by nature: the wallets, exchanges and authorities involved in a single case are rarely in one country. Where personal data moves outside the European Economic Area, we rely on an adequacy decision where one exists, or on standard contractual clauses combined with additional technical measures such as encryption and access minimisation.

06How long we keep it

  • Active case files — for the duration of the engagement and while any related legal action or exchange request remains open.
  • Closed case records and reports — retained so findings remain verifiable and defensible if the matter is reopened or challenged.
  • Verification documents — kept only as long as required for the engagement and any applicable record-keeping duty, then deleted.
  • Security and access logs — kept on a short rolling window for intrusion detection.

You can ask us for the retention period that applies to your specific file, and we will tell you in writing.

07Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability of data you provided to us, and you may object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw that consent at any time.

Send requests to support@bitaps.co. We may need to verify your identity before acting, and we will explain any part of a request we cannot fulfil — for example where deleting evidence would undermine an active investigation, a legal hold or another person’s claim. You also have the right to lodge a complaint with your national data protection authority.

08Security

Access to case files is restricted to the analysts assigned to the matter, portal accounts are isolated so a client can only see their own cases, evidence uploads are stored in private storage, and administrative actions are logged. No system is immune to compromise; if a breach affects your data we will notify you and the relevant authority as required. Our controls are described further in our security practices page.

09Children

Our services are intended for adults and for organisations. We do not knowingly create client accounts for anyone under 18. If you believe a minor has submitted data to us, contact us and we will remove it.

10Changes to this policy

We update this policy when our processing changes. The revision date above always reflects the current version, and material changes affecting existing clients are communicated directly through the client portal or by email.

Questions about this document?

Write to support@bitaps.co or contact us at Marken 6, Himmelev, 4000 Roskilde, Denmark.

See also our legal & policy centre.