Skip to main content

Legal information

PRIVACY POLICY

HOME4BITCOIN.COM

Effective from: 6 September 2026

Translation notice: This document is a translation of the original Czech Privacy Policy. The Czech version is the original and controlling version. In the event of any discrepancy, ambiguity or difference in interpretation, the Czech version shall be used to determine the intended meaning, subject to rights and obligations arising from mandatory applicable law.

1. Controller of personal data

The controller of personal data processed in connection with operation of the Home4Bitcoin.com platform is:

Dušan Kmetyo, self-employed individual

Company ID No.: 446 010 77

VAT ID No.: CZ6805302317

place of business: Franklinova 579, Liberec 15, 460 01, Czech Republic

e-mail: h4b.com@cryptobyte.cz

(the “Controller”).

The Controller is also the Operator of the Platform within the meaning of the Home4Bitcoin.com Terms and Conditions.

For the purposes of this Privacy Policy, “Platform” means Home4Bitcoin.com and “User” means a natural person using the Platform.

2. Data minimisation principle

Home4Bitcoin is designed so that ordinary use of the Platform does not require the User to disclose their civil identity to the Controller.

When a standard User account is created, the Platform does not normally require, in particular:

  • first and last name,
  • date of birth,
  • residential address,
  • telephone number,
  • identity card or other identification document number,
  • bank account,
  • payment card information,
  • a traditional User password,
  • Lightning wallet seed phrase or private key,
  • Nostr private key.

To recognise a User account, the Platform primarily uses a pseudonymous technical identifier associated with the authentication method used.

With the current LNURL-auth login method, this is a cryptographic public identifier. In the future, a public identifier associated with a Nostr account or another supported authentication mechanism may be used in a similar manner.

Such an identifier does not in itself reveal the User’s civil identity to the Controller. However, it may constitute personal data under the GDPR.

3. What data we process

3.1. Login and User account

In connection with an account, the Platform may process in particular:

  • a pseudonymous cryptographic identifier used for login,
  • an internal account identifier,
  • technical data relating to the authentication process,
  • a hash of the session token,
  • timestamps relating to creation, validity and possible revocation of a session,
  • account status and technical data necessary to secure it.

The Platform does not store a traditional password for an ordinary User.

3.2. Data contained in a Listing

The User enters information relating to the offered or requested rental, for example:

  • country, region and locality,
  • street, where applicable,
  • property type,
  • price and conditions,
  • title and description,
  • photographs for offers.

These data do not normally serve to identify the User. However, the User may place information in free text or a photograph that constitutes personal data.

Public fields of a Listing are intended for publication.

3.3. Contact details

The User may voluntarily provide one or more supported contact methods, for example:

  • e-mail address,
  • Signal,
  • Telegram,
  • Nostr.

These contacts are not used to verify the User’s civil identity.

Contact details in a Listing are not normally displayed to every visitor. They may be disclosed to another authorised User through the relevant Platform function.

Where the User voluntarily uses a contact detail containing a telephone number, for example in connection with certain forms of Signal use, the number is processed as part of the contact method selected by the User. The Platform does not itself require a telephone number.

3.4. Watchdog and notifications

Where the User uses notifications for newly matching offers, the Platform may process in particular:

  • an e-mail address used for notifications,
  • a public Nostr identifier used for notifications,
  • Watchdog settings,
  • information about identified matches,
  • notification delivery status,
  • technical data required to verify and deliver the message.

The e-mail address or Nostr identifier used for notifications is technically separated from the contact detail included in a Listing.

3.5. Security and operational data

For the purpose of securing the Platform and protecting it against spam, fraud and abuse, the following may in particular be processed:

  • timestamps of selected operations,
  • technical action identifiers,
  • records of contact disclosures,
  • moderation records,
  • data relating to reported content,
  • short-term rate-limit identifiers.

An unmodified IP address is not normally stored in the application database.

For certain short-term security mechanisms, an IP address may be converted into a hashed or HMAC representation used to distinguish requests without the need to retain the IP address itself on a long-term basis.

Standard technical operational and security logs may be generated at server infrastructure level.

3.6. Reporting illegal content

Ordinary registration and use of an account do not require the User’s name.

However, where a person submits a formal notice of illegal content under applicable law, proper processing of that notice may require:

  • the name of the person or designation of the notifying entity,
  • e-mail address,
  • identification of the reported content,
  • explanation of why the content is considered illegal,
  • declaration concerning the accuracy and completeness of the notice.

Where applicable law provides an exception to the requirement to provide a name or e-mail address, the Platform will respect such exception.

These data are used solely to process the notice and comply with related legal obligations and do not form part of the ordinary User profile.

3.7. Potential paid features

Where paid functions are provided through the Platform, data necessary to create, verify and record a payment may be processed, for example:

  • internal payment identifier,
  • amount,
  • Lightning invoice,
  • invoice or payment request identifier,
  • payment status,
  • creation, expiry or payment timestamp.

The Platform does not normally require the identity of the Lightning wallet, payer name, bank account or payment card details.

4. Why we process data and the legal basis

4.1. Provision of the Platform

On the basis of Article 6(1)(b) GDPR, the Controller processes data necessary in particular to:

  • create and recognise a pseudonymous account,
  • log in and manage sessions,
  • publish and manage Listings,
  • disclose contact details,
  • provide the Watchdog feature,
  • send notifications requested by the User,
  • automatically translate Listings,
  • provide potential paid features,
  • delete the User account.

Without data necessary for a particular function, that function may not be available.

4.2. Security and protection of the Platform

On the basis of the Controller’s legitimate interest under Article 6(1)(f) GDPR, data may be processed to the extent necessary for:

  • protection of the Platform and User accounts,
  • prevention of spam, fraud and abuse,
  • rate limiting,
  • handling security incidents,
  • content moderation,
  • protection of legal claims of the Controller or other persons,
  • diagnosis of technical problems.

The Controller has a legitimate interest in operating the Platform securely and preventing abuse while seeking to use only the minimum technical data necessary.

4.3. Compliance with legal obligations

On the basis of Article 6(1)(c) GDPR, data may be processed in particular for:

  • receiving and handling statutory notices of illegal content,
  • compliance with obligations towards competent authorities,
  • compliance with potential accounting and tax obligations,
  • handling data subject rights,
  • other obligations imposed by Czech or European law.

4.4. Consent

Basic operation of the Platform is not based on consent to personal data processing.

If a function requiring consent as the legal basis is introduced in the future, consent will be requested separately and may be withdrawn.

5. What is public and what is private

Data entered by the User into public fields of an active Listing are public, in particular:

  • title and description,
  • location,
  • price and conditions,
  • photographs,
  • other information intended for publication.

Private data include in particular:

  • account authentication identifier,
  • session data,
  • internal identifiers,
  • notification endpoints,
  • internal security records,
  • potential payment data,
  • non-public moderation records.

A contact detail associated with a Listing is disclosed only through the relevant Platform feature.

Once lawfully disclosed, another User may store the contact detail or use it for communication outside the Platform. The Controller cannot fully control such subsequent handling by another person.

6. Photographs

Photographs may contain personal data, for example where they depict persons, documents or other identifying information.

The User is responsible for having the right to publish the photograph.

When uploaded photographs are processed, the Platform removes common image metadata including EXIF, XMP and IPTC data and creates technically adjusted versions for publication.

7. Automatic translations

The title and description of a Listing may be automatically translated into other supported languages.

For translation purposes, the following may be sent to an external translation provider:

  • title,
  • description,
  • source and target language.

The account authentication identifier and contact details stored in separate contact fields are not normally included in the translation request.

The User should not include personal data in the title or description unless necessary for the Listing.

8. Recipients and technical service providers

The Controller does not sell personal data, provide it to advertising networks or use it to create marketing profiles.

However, data may be processed to the necessary extent through technical service providers.

8.1. Hosting and server infrastructure

Platform data are processed on technical infrastructure used by the Controller to operate the application, database, storage and related services.

8.2. Brevo

The Brevo service may be used for sending e-mail notifications and other transactional messages.

The following may in particular be provided:

  • recipient e-mail address,
  • message subject,
  • message content,
  • technical information necessary for delivery.

Home4Bitcoin does not use Brevo for advertising profiling of Users.

8.3. DeepL

The DeepL service may be used for automatic translation.

Text required for translation, in particular a Listing title and description, is transmitted. The separately stored contact detail and account authentication identifier are not normally included in the translation request.

8.4. Nostr relays

Where the User voluntarily activates notifications through the Nostr network, the Platform may use Nostr relays.

A relay may receive in particular:

  • the public Nostr identifier necessary for routing,
  • an encrypted Nostr event,
  • related technical network and timing metadata.

The content of a private message is cryptographically encrypted before transmission.

Nostr is a decentralised network and individual relays may be operated by independent third parties.

8.5. Payment infrastructure

Where paid features are activated, the Platform may use BTCPay Server or other supported payment infrastructure.

Only data necessary to create and verify the payment are processed.

9. Transfers outside the European Economic Area

Certain external or decentralised services may, depending on their technical configuration, involve processing outside the European Economic Area.

Where such a transfer is under the Controller’s control and the GDPR rules on international transfers apply, the Controller will use the appropriate legal mechanism required by the GDPR.

In particular, where the User voluntarily uses the decentralised Nostr network, encrypted messages and technical metadata may pass through relays operated by independent entities in different countries.

The Controller cannot guarantee deletion of data from independent decentralised infrastructure after such data have been properly transmitted outside systems controlled by the Controller at the User’s request.

10. How long we retain data

The Controller retains personal data only for the period necessary for the purpose of processing or for as long as retention is required or permitted by applicable law.

10.1. Account and Listings

Data necessary to maintain a User account are retained for the lifetime of the account.

Data associated with an active Listing are retained for the period during which the Listing is published and valid. The validity of a Listing may be automatically renewed within the service by User activity, for example by logging in or otherwise using the User account.

The User may delete their account at any time through account settings.

Once account deletion is confirmed, active Listings are made unavailable and personal data associated with the account for which no further legal basis exists are deleted or anonymised.

10.2. Photographs and contact details

Photographs, contacts, notification settings and other personal data associated exclusively with a deleted account are removed unless there is a separate legal basis for limited further retention.

10.3. Sessions and short-term security data

A session is retained only for its validity period or until it is revoked.

Short-term hashed or HMAC identifiers used for security and rate limiting are retained only for the necessary security window.

10.4. Notices and moderation

Data associated with illegal-content notices, moderation or security incidents may be retained for the period necessary to handle the matter and subsequently for the period required to comply with legal obligations or protect legal claims.

10.5. Payments

Data that the Controller is required to retain for accounting, tax or other legal reasons may remain stored for the statutory period even after deletion of the User account.

10.6. Security backups

After deletion of a User account, personal data are removed from the Platform’s active systems. Copies may remain for a limited period in security backups used exclusively for system recovery following a technical failure or security incident. Such backups are not used for ordinary operation or further processing of personal data and are automatically deleted or overwritten no later than 30 days later.

If a backup must be restored during that period, data previously designated for deletion will be deleted again as part of the recovery process.

11. Deletion of a User account

The User may permanently delete their account at any time through the account settings without having to contact the Controller.

Once deletion is confirmed:

  • the User’s Listings are made unavailable,
  • access to the account is terminated,
  • personal data associated with the account are removed from active systems unless another legal basis for retention exists,
  • related active settings and notifications are cancelled.

Copies of deleted data may subsequently remain only in security backups under Section 10.6 of this Policy, but for no longer than 30 days.

Deletion cannot retroactively remove:

  • a contact detail previously lawfully stored by another User,
  • an e-mail or Nostr message already delivered to the recipient’s device,
  • data the Controller must retain by law,
  • data whose limited retention is necessary for the establishment, exercise or defence of legal claims,
  • information already transmitted to independent decentralised infrastructure not controlled by the Controller.

Account deletion therefore means removal of personal data from active systems controlled by the Controller without undue delay and from security backups no later than within 30 days, except where a separate legal basis exists for further retention.

12. Cookies

The Platform uses only technical cookies necessary for secure login and operation of the service.

A session cookie is used to recognise a logged-in User and secure the session.

The Platform currently does not use in particular:

  • advertising cookies,
  • remarketing,
  • behavioural advertising tracking,
  • Google Analytics,
  • Meta Pixel,
  • marketing fingerprinting.

Technical cookies are not used for marketing profiling.

If the Platform introduces cookies or similar technologies requiring consent under applicable law in the future, they will be activated only after the relevant consent has been obtained.

13. Automated decision-making and Watchdog

The Platform does not carry out automated decision-making that produces legal effects concerning the User or similarly significantly affects them within the meaning of Article 22 GDPR.

The Watchdog automatically compares parameters of requests with parameters of offers and may notify the User where a matching offer is found.

This function is purely informational and does not decide whether the User may conclude a contract or what contractual terms may be agreed.

The Platform also uses certain automated security mechanisms such as input validation, request rate limiting and anti-spam protection.

14. Rights of the data subject

To the extent provided by the GDPR, a person whose personal data are processed by the Controller has, in particular, the right to:

  • obtain information about the processing of their data,
  • request access to their personal data,
  • request correction of inaccurate data,
  • request deletion of personal data,
  • request restriction of processing,
  • object to processing based on legitimate interests,
  • exercise the right to data portability where the statutory conditions are met,
  • withdraw consent where specific processing is based on consent,
  • lodge a complaint with the competent supervisory authority.

The right to erasure is not absolute. Personal data do not have to be deleted, for example, where their further processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.

15. Verification of requests concerning pseudonymous accounts

Because Home4Bitcoin does not normally know the User’s civil identity, the Controller will not unnecessarily require an identity card, residential address or other data that the Platform otherwise does not need solely for the purpose of handling a request.

Where the User is logged in, they may manage their data and account directly through Platform functions.

Where an applicant no longer has access to the account and asks the Controller to take action concerning a particular pseudonymous account, the Controller may require reasonable verification of the applicant’s entitlement, for example cryptographic verification using an authentication method associated with the account.

Where the applicant’s connection to the pseudonymous account cannot reasonably be verified, it may not be possible to perform the requested action safely.

16. Security of personal data

The Controller uses technical and organisational measures appropriate to the nature of the data processed.

Such measures include in particular:

  • pseudonymous authentication without traditional passwords for ordinary Users,
  • storage only of hashes of session tokens,
  • secure session cookies,
  • separation of public content from non-public contact and authentication data,
  • access control for non-public data,
  • rate limiting and protection against automated abuse,
  • limitation of long-term storage of IP addresses,
  • removal of common metadata from uploaded photographs,
  • cryptographic encryption of private Nostr messages,
  • separation of application and internal infrastructure services.

No information system can, however, guarantee absolute data security.

17. Personal data of other persons

The User must not unlawfully publish personal data of other persons through the Platform.

If the User publishes a photograph of another person, their contact details or other identifying information, the User is responsible for having the right to use such data.

The Platform is not intended for publication of special categories of personal data, such as health data, biometric or genetic data or data concerning a person’s sex life.

18. Persons under 18 years of age

The Platform is intended only for persons over 18 years of age.

The Controller does not normally verify the User’s age and does not knowingly request data for age verification purposes.

If the Controller becomes aware that an account is being used by a person who does not meet the age requirement, the Controller may terminate that person’s access to the Platform and delete or otherwise process the related data in accordance with applicable law.

19. Supervisory authority

For matters concerning personal data protection, the Controller may be contacted at:

h4b.com@cryptobyte.cz

This does not affect the right to lodge a complaint with the competent supervisory authority.

In the Czech Republic, the supervisory authority is:

Office for Personal Data Protection Pplk. Sochora 27 170 00 Prague 7 Czech Republic

Under the GDPR, a data subject may also have the right to contact a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.

20. Changes to this Policy

The Controller may update this Policy, in particular following changes to:

  • Platform features,
  • technical services used,
  • scope or method of data processing,
  • applicable law.

The current version will always be published on the Platform.

Where a change materially affects how personal data are processed, Users will be informed in an appropriate manner.

21. Language versions

This Policy was originally created in Czech.

Translations into other languages are provided to facilitate use of the Platform by foreign Users and constitute translations of the Czech document.

In the event of any discrepancy or ambiguity between the Czech text and its translation, the Czech version is the reference text for determining the intended meaning. This does not affect the data subject’s rights or the Controller’s obligations arising from mandatory applicable law.

22. Contact

Questions concerning personal data protection or requests to exercise rights under the GDPR may be sent to:

h4b.com@cryptobyte.cz

Controller:

Dušan Kmetyo

Franklinova 579

Liberec 15, 460 01

Czech Republic

Back to home