Token Logo
contact sales

contact sales

Website Privacy & Cookie Notice

Choose Language

ENGLISH - EN

down arrow
  • ENGLISH - EN

 

1. Introduction

Token GmbH and Token.io Ltd (hereinafter referred to as “Token.io”, “we”, “our”, “us”) are always aware of the importance of the data entrusted to us. 

The responsible handling, confidentiality and protection of your data is therefore of particular importance to us. 

The Processing of your personal data is carried out exclusively within the framework of the statutory provisions, the applicable data protection law and this privacy Notice. 

This Privacy Notice informs you which personal data is processed by Token.io, including where this arises from your use of our website, https://token.io/ ("website"; "Token.io website"), your contact with us, your subscription to our marketing services, or your use of our products and services.

 

2. Purpose of this Privacy & Cookie Notice

This privacy and cookie notice aims to provide you information on how Token.io collects and processes your personal data, including when you:

  • use this website;
  • contact us or subscribe to our marketing services;
  • use our products and services, or otherwise engage with us as a customer, partner, or user of our payment or other financial services;

We ask you to take note of this privacy and cookie notice, alongside any other policies published on our website, which outlines the data we collect about you, so you’re fully informed and aware of how and why we are using your data.

 

This privacy and cookie notice supports and supplements other notices published on our website and is not intended to override them. 

 

3. The subject of data protection

The subject of data protection is personal data. Individual specifications about the personal or objective relationships of a defined or definable natural person. Personal data is, therefore, information that can be used to draw conclusions about an identified or identifiable natural person. In principle, all information about which a personal reference can be established also falls under the concept of personal data. For example, a person’s name, address, e-mail address, telephone number, personnel number, vehicle registration number plate, appearance, or gait are all personal data. Furthermore, usage data also has a personal connection. Usage data means data that is required to use our website. This includes, for example, information about the start, end, and scope of your use.

 

4. Controller/Contact

Token.io acts as the Data Controller for personal data gathered through your use of our website and our marketing services, and is responsible for determining the purposes and means of that processing.

Where Token.io provides its payment initiation and account information services under a contractual relationship with a client, Token.io acts as a Data Processor, processing personal data on behalf of, and in accordance with the instructions of, that client, who acts as the Data Controller for such data.

As Token.io has operating subsidiaries across Europe, there are different supervisory authorities based on your location and therefore the contact information may vary; please see Section 5 'Contact Details'.

 

5. Contact Details

Full Name of Legal entities: Token GmbH and Token.io Ltd

Email: Privacy@token.io

 

Token.io Ltd is a company registered in England and Wales under number 10143662 whose registered office is at 10 John Street, London WC1N 2EB, UK. Token.io Ltd. is authorised by the UK’s Financial Conduct Authority to provide Payment Initiation Services and Account information Services under Reference number: 795904. 

 

Token GmbH is a company registered in Germany under number 217765B whose registered office is at Token GmbH: c/o Industrious, Schicklerstraße 5, 10179 Berlin, Germany. Token GmbH is authorised by Germany’s Federal Financial Supervisory Authority (BaFin) and the Bundesbank to provide Payment Initiation Services and Account information Services under ID number: 158595.

 

You have a right to make a complaint at any time to the supervisory authority where you live, work or believe a breach has occurred. The contact details for each of the supervisory authorities responsible for data protection can be found in section 13 of this privacy policy. We would, however, appreciate the opportunity to manage your concerns directly, so please do contact us at the outset at Privacy@token.io  

 

6. Scope of personal data processing

We only process your personal data where this is necessary for one of the purposes described in this notice, including providing a functional website, responding to your enquiries, providing our marketing services, or performing our contractual, regulatory and legal obligations in connection with providing our payment and account information services.

Depending on the purpose, this processing is carried out on the basis of your consent, the performance of a contract, our legitimate interests, or compliance with a legal obligation, as set out in further detail in Section 7.

Where processing would otherwise be based on consent, and such consent cannot be obtained for legal or factual reasons, we will only process personal data where this is permitted by law.

 

7. The Data we collect about you

Type of interaction: Automated Data Collection

Data Captured: 

  • Date and time of access
  • Browser type/version
  • Operating system used
  • Resource retrieved
  • Quantity of data transmitted
  • The user’s IP address

Purpose of Processing: The data is stored in log files to ensure the website’s functionality. The data is also used to optimise the website and to ensure the security of our information technology systems. No evaluation of the data for marketing purposes is undertaken in this context.

 

GDPR / Data Protection Act / BaFin reference: Art. 6 Para. 1 lit. f GDPR (EU) - Legitimate interest of allowing the website to function for the users purpose.

Retention Period: As soon as no longer necessary and after 31 days as a maximum timeframe.

Objection & Removal Option: No, as the collection of data for this purpose is necessary for the operation of the website.

 

Type of interaction: Direct contact by you (Webforms)
Data Captured: 

  • Email Address
  • Name
  • Phone number
  • Any other personal information you provide to us as part of your communication via our webforms.

Purpose of Processing: Due to legal regulations, the Token.io website contains information that enables quick electronic contact to our company, in particular a general e-mail address.  Such personal data transmitted to us on a voluntary basis will be stored for the purposes of contacting or dealing with the matter for you.
GDPR / Data Protection Act / BaFin reference:  Art. 6 para. 1 lit. a GDPR (EU) - Implied Consent as you have asked us to contact you and willingly provided us this information.
Retention Period: After 5 years of no contact
Objection & Removal Option: Yes - A user who has contacted us by email/our webforms can object at any time to the storage of his or her or their personal data. It will not be possible to continue the conversation in this case.

 

Type of interaction: Direct contact by you (Webforms)
Data Captured: 

  • Email Address
  • Name
  • Phone number
  • Any other personal information you provide to us as part of your communication via our webforms.

Purpose of Processing: The data is stored in log files to ensure the website’s functionality. The data is also used to optimise the website and to ensure the security of our information technology systems. No evaluation of the data for marketing purposes is undertaken in this context.

GDPR / Data Protection Act / BaFin reference:  Art. 6 Para. 1 lit. f GDPR (EU) - Legitimate interest of allowing the website to function for the users purpose.

Retention Period: After 5 years of no contact

Objection & Removal Option:  No, as the collection of data for this purpose is necessary for the operation of the website.

 

Type of interaction: Token Newsletter
Data Captured: 

  • Email address
  • Name

Purpose of Processing: Token.io informs business partners at regular intervals by means of a newsletter about company news and insights.  Data processing in connection with this activity is only done if you have given your explicit consent to receive marketing information.  We save this information in our CRM platform, HubSpot.
GDPR / Data Protection Act / BaFin reference: Art. 6 Para. 1 lit. a GDPR (EU) - You have provided us explicit consent to process your information in order to receive this letter.
Retention Period: The user’s email address will therefore be stored as long as the subscription to the newsletter has not been revoked.
Objection & Removal Option:  Yes - a user can revoke consent at any time.

 

Type of interaction: Customer Due Diligence

Data Captured: Publicly available company information.
Purpose of Processing: To carry out initial due diligence on prospective customers to ensure they are within Token’s risk appetite levels.
GDPR / Data Protection Act / BaFin reference: Art 6. Para 1. Lit C. - Compliance with legal obligations for companies on anti-money laundering.
Retention Period: 5 years
Objection & Removal Option:  No - records need to be kept and maintained to comply with anti-money laundering regulations.

 

Type of interaction: Know Your Business (KYB) and Know Your Customer (KYC)

Data Captured: 

  • Name(s) of the directors and beneficial owners of prospective and existing merchant/customer companies
  • Date of birth
  • Nationality and/or country of residence
  • Sanctions, Politically Exposed Person (PEP), and adverse media screening results
  • Company-level financial and credit information

 

Purpose of Processing: In addition to our initial due diligence on prospective customers, Token.io screens the directors and beneficial owners of our merchant and customer companies on an ongoing basis, in order to comply with our anti-money laundering and sanctions obligations. This screening applies to the directors and beneficial owners of our business customers and merchants, it does not apply to individual website visitors or to end-users of the payment services provided to our customers.
GDPR / Data Protection Act / BaFin reference: Art 6. Para 1. Lit C. - Compliance with legal obligations for companies on anti-money laundering.
Retention Period: 5 years following the termination of the contractual relationship with the customer or merchant.
Objection & Removal Option:  No - records need to be kept and maintained to comply with anti-money laundering regulations.

 

8. Third Party Sub-Processors

Token.io may share your personal data with one of the following 3rd Parties solely for the purpose of providing you with functioning services.

Token.io ensures GDPR compliance with these processors by having standard contractual clauses and data processing agreements with all parties.

 

Processor: AWS
Description: Cloud computing infrastructure to support the successful operation of Token
Location of Services: European Economic Area

 

Processor: Hubspot
Description: Customer Management system used to store sales information, customer insights and marketing preferences.
Location of Services: United States of America

 

Processor: Microsoft
Description: Productivity and analytics suite used across the business for communication, document creation, collaboration, data analysis, reporting, forecasting.
Location of Services: European Economic Area

 

Processor: Google
Description: Cloud-based productivity suite (G Suite) used for communication, day-to-day operations, shared document management and team coordination across the business.
Location of Services: The United States of America and European Economic Area

 

Processor: Zendesk
Description: Customer communication tool used to respond to queries, complaints, issues with customers to ensure correct running of Token services
Location of Services: The United States of America

 

Processor: Slack
Description: Internal communication tool used for cross-department coordination to ensure correct running of Token services
Location of Services: The United States of America and Ireland

 

Processor: Atlassian
Description: Customer communication tool used to respond to queries, complaints, issues with customers to ensure correct running of Token services
Location of Services: Ireland

 

Processor: Signicat
Description: Anti-Money Laundering relevant checks
Location of Services: United Kingdom of Great Britain and Northern Ireland

 

Processor: Matomo
Description: Cookieless Website Tracking/Webapp Tracking
Location of Services: European Economic Area

 

Processor:  Payever GmbH.
Description: Only Applicable for payments from Shop systems such as Shopify, Woo Commerce & others.
Location of Services: Germany

 

Processor: Modulr
Description: Only applicable for Settlement Account Services
Location of Services: European Economic Area

 

Processor: CreditSafe
Description: Anti-Money Laundering relevant checks
Location of Services: European Economic Area

 

Processor: Sage
Description: Financial management and accounting system used to support core finance operations, including invoicing and reporting
Location of Services: European Economic Area

 

Processor: Draftspotting
Description: Cloud‑based Contract Lifecycle Management (CLM) platform
Location of Services: The Netherlands

 

Processor: Comply Advantage
Description: Anti-Money Laundering relevant checks
Location of Services: European Economic Area

 

Processor: Dotfile
Description: Anti-Money Laundering relevant checks
Location of Services: European Economic Area

 

9. cVRP Scheme Participants

This section only applies if you use our cVRP (commercial Variable Recurring Payments) service. If you don't use cVRP, this section does not apply to you and you can skip to the next section.

Unlike the service providers listed above, some organisations receive personal data from us as independent data controllers in their own right, not as our processors acting on our instructions.

Where you use our cVRP service, we may share personal data relating to your cVRP mandate or transactions with:

  • ASPSP Participant (your bank), as an independent controller, as part of the normal operation of the cVRP scheme — for example, to set up, execute, or manage your mandate; 
  • our clients who make cVRP available to you as a payment option, whether or not they are themselves payment initiation providers, as part of the normal operation of the cVRP scheme — for example, so they can confirm your mandate and receive the payments you've authorised.

We may also share limited, and where possible redacted, personal data with:

  • UK Payments Initiative Limited ("UKPI"), as the operator of the cVRP payment scheme; 
  • other ASPSP Participants in the cVRP scheme,

where necessary to investigate and resolve an issue or dispute relating to a cVRP mandate or transaction.

ASPSP Participant (your bank), UKPI, and other ASPSP Participants in the cVRP scheme each act as an independent controller of any personal data shared with them for these purposes, and are separately responsible for how they handle that data in accordance with their own privacy notices and applicable data protection law. Our clients' role in relation to any personal data we share with them depends on our contractual arrangements with them, as set out in their own terms or privacy notices.

 

10. International Transfers

If you use our cVRP service, your payment account and the recipient's account must both be held in the UK — this is a requirement of the cVRP scheme rules. This does not mean, however, that all processing of your cVRP data takes place in the UK. We use service providers (such as our cloud infrastructure provider) that may process or store data within the EEA. The same international transfer safeguards described in this section apply to that data in the same way as for our other services.

Information captured on our website may be stored in our internal systems or within our databases, solely for the purposes mentioned above.

Some of our providers process data outside the European Economic Area (EEA), including in the United States and the United Kingdom. 

Where a provider is located in the United Kingdom, this transfer is covered by the European Commission's adequacy decision for the UK (Art. 45(3) GDPR), which confirms that the UK ensures an adequate level of data protection for transfers from the EEA.

Where a provider is located in the United States and is certified under the EU-U.S. Data Privacy Framework (DPF), this transfer is covered by the European Commission's adequacy decision for the DPF (Art. 45(1) GDPR), which recognizes that certified U.S. organizations offer a level of data protection comparable to that of the European Union.

Where a provider is not (or no longer) certified under the DPF, Token.io relies on Standard Contractual Clauses (Art. 46(2)(c) GDPR), together with supplementary measures where necessary, to ensure an adequate level of protection for the transferred data.

For transfers made by Token.io Ltd, equivalent protections are ensured through the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as applicable, in accordance with the UK GDPR and the Data Protection Act 2018.

All of Token.io's processors have clearly defined contractual requirements regarding their roles and responsibilities in processing this data.

 

11. Cookies

What are Cookies?

Cookies are small text files that make it possible to store specific device-related information on the user’s device. 

On the one hand, they serve the user-friendliness of websites and thus the users. 

On the other hand, they serve the collection of statistical data for the use of the website and analysis of these for the purpose of improving the offer. 

The user can control the use of cookies. Most browsers have an option which limits or completely prevents storage of cookies.

 

What Cookies does Token.io use and why?

We use cookies across our site to help improve its performance, to enhance the user experience and to support some key site functionality.

 

Necessary - Necessary cookies are crucial for the basic functions of the website and the website will not work in its intended way without them. These cookies do not store any personally identifiable data. These cookies are opt-out.

Functional - Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collecting user feedback, and other third-party features. These cookies are opt-in.

Analytics - Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc. These cookies are opt-in.

Performance - Performance cookies are used to understand and analyse the key performance indexes of the website, which helps in delivering a better user experience for the visitors. These cookies are opt-in.

Advertisement - Advertisement cookies are used to deliver visitors with customised advertisements based on the pages they visited before, and to help analyse the effectiveness of advertising campaigns.

 

The user data collected in this way is pseudonymised via technical provisions. It is therefore no longer possible to assign the data to the accessing user. 

The data is not stored together with users’ other personal data. 

 

When accessing our website, users are informed by an information banner on the use of cookies for analytical purposes and referred to this data protection declaration. A note is also included in this context as to how the user can disable the storage of cookies in the browser settings.

 

Third-Party Cookies

By using some areas of our website, ‘Necessary’ Cookies may be stored that are not controlled by us; this is usually when that particular part of the website makes use of third-party analytics or technical tools such as load balancing.

 

Necessary Cookies

Cookie Identifier:  __hssrc
Purpose: This cookie is set by HubSpot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session.
Duration: Session

 

Cookie Identifier:  CRAFT_CSRF_TOKEN
Purpose:  This cookie is set by the provider Craft CMS. This cookie is used for the purpose of website security that is Cross-Site-Request forgery prevention whenever a form is used.
Duration:  Session

 

Cookie Identifier:  cookieyesID
Purpose:  CookieYes sets this cookie as a unique identifier for visitors according to their consent.
Duration: 1 year

 

Cookie Identifier:  cky-consent
Purpose:  The cookie is set by CookieYes to remember the users' consent settings so that the website recognises the users the next time they visit.
Duration: 1 year

 

Cookie Identifier:  cookieyes-necessary
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Necessary' category.
Duration: 1 year

 

Cookie Identifier:  cookieyes-functional
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Functional' category.
Duration: 1 year

 

Cookie Identifier:  cookieyes-analytics
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Analytics' category.
Duration: 1 year

 

Cookie Identifier:  cookieyes-performance
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Performance' category.
Duration: 1 year

 

Cookie Identifier:  cookieyes-advertisement
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Advertisement' category.
Duration: 1 year

 

Cookie Identifier:  cookieyes-other
Purpose:  CookieYes sets this cookie to remember the consent of users for the use of cookies in the 'Other' category.
Duration: 1 year

 

Cookie Identifier:  cky-action
Purpose:  This cookie is set by CookieYes and is used to remember the action taken by the user.
Duration: 1 year

 

Cookie Identifier:  AWSALBCORS
Purpose:  This cookie is managed by Amazon Web Services and is used for load balancing.
Duration: 7 days

 

Cookie Identifier:  __cfruid
Purpose:  Cloudflare sets this cookie to identify trusted web traffic.
Duration: Session

 

Performance Cookies (not mandatory)

Cookie Identifier:  _gat
Purpose:  This cookie is installed by Google Universal Analytics to restrain request rate and thus limit the collection of data on high traffic sites.
Duration: 1 minute

 

Cookie Identifier:  AWSALB
Purpose:  AWSALB is an application load balancer cookie set by Amazon Web Services to map the session to the target.
Duration: 7 days

 

Analytics Cookies (Not mandatory)

Cookie Identifier:  _dc_gtm_UA-62082987-
Purpose:  The _dc_gmt_UA-62082987-1 cookie, installed by Google Tag Manager, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors.
Duration: 1 minute

 

Cookie Identifier:  _ga
Purpose:  The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors.
Duration: 1 yr 1 month 4 days

 

Cookie Identifier:  _gid
Purpose:  Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
Duration: 1 day

 

Cookie Identifier:  __hstc
Purpose:  This is the main cookie set by HubSpot, for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session).
Duration: 5 months 27 days

 

Cookie Identifier:  hubspotutk
Purpose:  HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts.
Duration: 5 months 27 days

Cookie Identifier:  sid
Purpose:  The sid cookie contains digitally signed and encrypted records of a user’s Google account ID and most recent sign-in time
Duration: Session

 

Cookie Identifier:  _gat_gtag_UA_*
Purpose:  Google Analytics sets this cookie to store a unique user ID.
Duration: 1 minute
 

Cookie Identifier:  _ga_*
Purpose:  This cookie is provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
Duration: 1 year 1 month 4 days
 

Cookie Identifier:  _gcl_au
Purpose:  This cookie is provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
Duration: 3 months

 

Cookie Identifier:  ln_or
Purpose:  Linkedin sets this cookie to register statistical data on users' behaviour on the website for internal analytics.
Duration: 1 day

 

Functional Cookies

Cookie Identifier:  UserMatchHistory
Purpose:  LinkedIn sets this cookie for LinkedIn Ads ID syncing.
Duration: 1 month

 

Cookie Identifier:  bcookie
Purpose:  LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognise browser ID.
Duration: 1 year

 

Cookie Identifier:  lidc

Purpose:  LinkedIn sets the lidc cookie to facilitate data center selection.
Duration: 1 day

 

Cookie Identifier:  __hssc
Purpose:  HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie.
Duration: 30 minutes

 

Cookie Identifier:  __cf_bm
Purpose:  This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
Duration: 30 minutes

 

Cookie Identifier:  bscookie
Purpose:  LinkedIn sets this cookie to store performed actions on the website.
Duration: 1 year
 

Advertisement Cookies (Not mandatory)
Cookie Identifier:  AnalyticsSyncHistory
Purpose:  LinkedIn sets this cookie for LinkedIn Ads ID syncing
Duration: 1 month

 

Cookie Identifier:  li_gc
Purpose:  LinkedIn sets this cookie for LinkedIn Ads ID syncing.
Duration: 5 months 27 days

 

Cookie Identifier:  YSC
Purpose:  YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
Duration: Session

 

Cookie Identifier:  VISITOR_INFO1_LIVE
Purpose:  A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface
Duration: 5 months 27 days

 

Cookie Identifier:  yt-remote-device-id
Purpose:  YouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
Duration: Never

 

Cookie Identifier:  yt-remote-connected-devices
Purpose:  YouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
Duration: Never

 

Cookie Identifier:  test_cookie
Purpose:  The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies
Duration: 15 minutes

Cookie Identifier:  IDE
Purpose:  Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile.
Duration: 1 year 24 days
 

Others (Not mandatory)
Cookie Identifier:  next-i18next
Purpose:  This cookie provides the functionality and management for the translation of multiple languages, enabling the localisation of content from web to mobile and desktop.
Duration: 1 year

 

Cookie Identifier:  lightstep_guid%2Fdeveloper-portal-service
Purpose:  Lightstep sets this cookie to improve access and navigation for returning users of the developer portal (dashboard.sandbox.token.io)
Duration: 7 days

 

Cookie Identifier:  lightstep_session_id
Purpose:  Lightstep sets this cookie to help web pages to load faster and improve navigation for returning users (dashboard.sandbox.token.io).
Duration: 7 days
 

Cookie Identifier:  cf_clearance
Purpose:  Cloudflare sets this cookie for when CAPTCHA or Javascript challenge is solved such as for a Firewall Rule or IP Access Rule, a cf_clearance cookie is set in the client browser. cf_clearance specifies the duration our website is accessible to a visitor that successfully completed a previous Captcha or JavaScript challenge.
Duration: 1 year

 

For all other types of cookie, you can see their use by visiting ‘Preferences’ on the Cookie Consent banner, where descriptions are provided for all cookie types, along with duration of storage. 

 

What is the legal basis for the Cookies Token.io uses?

For necessary Cookies -  The legal basis for processing personal data using cookies is Art. 6 para. 1 lit. f GDPR (EU). Legitimate interest of allowing the website to function for the users purpose.

 

For all other cookies - The legal Art. 6 Para. 1 lit. a GDPR (EU) as well as incorporated in the DPA 2018, Chapter 2, Article 6, A (UK) - You have provided us explicit consent to use these cookies by opting-in, either via the ‘preferences’ button on our banner or by choosing ‘accept all’ on our banner. Please ensure you have read and understood what each non-necessary cookie does before clicking ‘accept all’ so you are fully informed of which first and third party cookies are being used. 

 

Duration of storage, objection and removal option

Cookies are stored on the user’s computer and transmitted to our site. 

Therefore, as a user you have full control of the use of cookies. 

By changing the settings in your Internet browser, you can disable or restrict the transmission of cookies. 

Cookies that have already been saved can be deleted at any time. This can also be done automatically. 

Users can, for example, find information about how to manage Cookies in the most commonly used browsers at the following addresses:

 

If cookies are deactivated for our website, it may no longer be possible to use all of the website’s features in full.

 

12. Rights of the data subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and DPA2018, and you have the following rights with respect to Token.io:

 

The right to be informed

As a data subject, you have the right granted by the European Directive and Regulator, UK law and other national data protection rights within the EEA to receive free information from Token.io about your stored personal data and a copy of this information at any time. 

Furthermore, the European Directive and Regulator and other regulators have granted you, as the person concerned, access to the following information:

  • the purposes of processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of a right to rectification or erasure of the personal data concerning you or of a restriction of the processing by the person responsible or of a right to object to such processing;
  • the existence of the right to lodge a complaint with a supervisory authority;
  • where the personal data is not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, in accordance with Article 22 Para.1 and 4, GDPR and as incorporated in the DPA 2018, Chapter 3, Section 49 and – at least in these cases – meaningful information on the logic involved and the scope and intended effects of such processing for the data subject.

 

Furthermore, you have a right of access to information as to whether personal data has been transferred to a third country or to an international organisation. If this is the case, you have, in addition, the right to obtain information about the appropriate guarantees in connection with the transfer.

 

When responding to a request to exercise your rights, we will conduct searches that are reasonable and proportionate to locate the relevant personal data. Where we reasonably require clarification from you to process your request, the response timeframe may be paused until that clarification is received.

 

If you would like to make use of this right to information, you can contact us via Privacy@token.io at any time.

 

The right of rectification

You also have the right, granted by the European legislator, UK law and other national data protection rights within the EEA to request the immediate rectification of inaccurate personal data concerning you. You also have the right, taking into account the purposes of the processing, to request the completion of incomplete personal data, including by means of a supplementary declaration.

 

If you would like to make use of this right to information, you can contact our Privacy@token.io at any time.

 

The right to limitation of processing

You have the right, granted by the European legislator of directives and regulations, to require Token.io to restrict processing if one of the following conditions is met:

  • The accuracy of your personal information is contested by you for a period of time that allows us to verify the accuracy of your personal information.
  • The processing is unlawful, you refuse to delete the personal data and instead demand a restriction on the use of the personal data.
  • We no longer need the personal data for the purposes of processing, but you do need it to assert, exercise or defend legal claims.
  • You have objected to the processing pursuant to Art. 21 Para. 1 GDPR (EU) and as incorporated into the DPA 2018 Article 16 and 18 (UK) and it is not yet clear whether Token.io’s legitimate reasons outweigh yours.

 

If one of the above conditions is fulfilled and you wish to request the restriction of personal data stored by Token.io, you can contact us under Privacy@token.io at any time. 

 

Right to erasure

You also have the right, granted by the European legislator, UK law and other national data protection rights within the EEA, to require Token.io to delete your personal data immediately, provided that one of the following reasons applies and insofar as the processing is not necessary:

  • The personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
  • You revoke your consent on which the processing pursuant to Art. 6 Para. 1 Letter. A GDPR or Art. 9 Para. 2 Letter. A GDPR (EU) or as incorporated into the DPA 2018 Article 16, 18, 21 (UK) and there is no other legal basis for processing.
  • You submit an objection to the processing according to Art. 21 Para. 1, GDPR, and there are no overriding legitimate grounds for processing, or you submit an objection according to Art. 21 Para. 2 GDPR (EU) or as incorporated into the DPA 2018 Article 16, 18, 21 (UK) objecting to the processing.
  • The personal data has been unlawfully processed.
  • The personal data must be erased for compliance with a legal obligation under Union or Member State law to which the responsible person is subject.
  • The personal data concerning you has been collected in relation to services offered by the information society according to Art. 8 Para. 1 GDPR (EU) or as incorporated into the DPA 2018 Article 16, 18, 21 (UK).

 

If one of the above conditions is fulfilled and you wish to request your right to erasure, you can contact us under Privacy@token.io at any time. 

 

If the personal data has been made public by us and our company is responsible, pursuant to Art. 17 Para. 1 GDPR (EU) or as incorporated in the DPA 2018, Chapter 3, Section 47 (UK) to delete personal data, we will take appropriate measures, including technical measures, taking into account available technology and implementation costs, to inform other data processors who process the published personal data, that you have requested the deletion of all links to such personal data or of copies or replications of such personal data from those other data processors, where processing is not necessary. Our employees will do what is necessary in individual cases.

 

Right to data portability

You also have the right, granted by the European legislator, UK law and other national data protection rights within the EEA to receive the personal data concerning you that you have provided to Token.io in a structured, common and machine-readable format. You also have the right to transfer this data to another data controller without obstruction by Token.io, provided that the processing is based on the consent provided for in Art. 6 para. 1 Letter A GDPR or Art. 9 para. 2 Letter A GDPR or on a contract in accordance with Art. 6 para. 1 letter b GDPR or as incorporated in the DPA 2018 Chapter 3, Section 3 Article 20 and processing is carried out by means of automated procedures, except where processing is necessary for the performance of a task in the public interest or in the exercise of official authority conferred on the controller.

 

Furthermore, when exercising your right to data transferability pursuant to Art. 20 para. 1 GDPR, or as incorporated in the DPA 2018 Chapter 3, Section 3 Article 20 the right to require that the personal data is transmitted directly from Token.io to another responsible person, as far as technically feasible and provided that this does not affect the rights and freedoms of others.

 

To assert the right to data transferability, you can contact us under Privacy@token.io at any time.

 

Right of appeal

You also have the right, granted by the European legislator, UK law and other national data protection rights within the EEA for reasons arising from your particular situation, to object at any time to the processing of personal data relating to you, which may be processed on the basis of Art. 6 para. 1 letters e or f GDPR or as incorporated in the DPOA 2018 Chapter 8, Article 77. This also applies to profiling based on these provisions.

 

Token.io no longer processes personal data in the event of an objection, unless we can prove compelling reasons worthy of protection for the processing, which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

 

If Token.io processes personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data for the purpose of such advertising. This also applies to any profiling connected with such direct advertising. If you object to Token.io processing for direct advertising purposes, Token.io will no longer process your personal data for these purposes.

 

Furthermore, for reasons arising from your particular situation, you have the right to object to the processing of personal data concerning you which Token.io uses for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 para. 1 GDPR or as incorporated in the DPA 2018, Chapter 9, Article 89 unless such processing is necessary to fulfil a task in the public interest.

 

In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.

 

To exercise your right of objection, you can contact Privacy@token.io at any time.

 

Automated individual decision-making including profiling

You also have the right, granted by the European legislator, UK law and other national data protection rights within the EEA, not to be subject to a decision based exclusively on automated processing – including profiling – which has legal effect against you or which significantly affects you in a similar manner, provided that the decision (1) is not necessary for the conclusion or performance of a contract between you and Token.io, or (2) is admissible under Union or Member State legislation to which Token.io is subject and contains appropriate measures to safeguard your rights and freedoms and your legitimate interests, or (3) takes place with your express consent.

 

If the decision (1) is necessary for the conclusion or performance of a contract between you and us or (2) is made with your express consent, Token.io will take reasonable measures to protect your rights and freedoms as well as your legitimate interests, including at least the right to obtain the intervention of a person by Token.io, to state their own position and to challenge the decision.

 

If you wish to assert rights relating to automated decisions, you can Privacy@token.io at any time.

 

Right to withdraw data protection consent

You have the right to revoke your consent to the processing of personal data at any time as granted by the European Directive and Regulator.

 

If you would like to exercise your right to revoke your consent, you can contact Privacy@token.io at any time.

 

How to raise a data protection complaint with Token.io

If you have a concern about how we have collected, used, or otherwise processed your personal data, you can raise a complaint with us at Privacy@token.io. We will acknowledge your complaint within 30 days of receipt, investigate it without undue delay, keep you informed of its progress, and notify you of the outcome.

This does not affect your right to lodge a complaint with a supervisory authority at any time, see Section 13 below.

 

13. The right of appeal to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right of appeal to a supervisory authority, in particular in the Member State where you reside, work or where the infringement is suspected, if you believe that the processing of personal data that concerns you is in contravention of GDPR.

 

The supervisory authorities responsible for Token.io are:

 

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59-61

10555 Berlin

 

Phone: +49 30 13889-0

 

Fax: +49 30 2155050

 

E-Mail: mailbox@datenschutz-berlin.de

 

The supervisory authority with which the appeal has been lodged shall inform the appellant of the status and results of the appeal, including the possibility of a judicial remedy under Art. 78 GDPR.

 

===============================

 

The Information Commissioner's Office

 

Wycliffe House

 

Water Lane

 

Wilmslow

 

Cheshire SK9 5AF

 

Phone +44 (0)303 123 1113

 

Last updated: August, 2026

 

 

 

The latest news and insights, delivered.

Subscribe

Get started

Fill out this form to be connected with the most suitable expert from our team.