Privacy policy
Version 1.0 · Effective date: 03.08.2026
1. Why this Policy was created
MiCA Intelligence was founded on the belief that trust is built through transparency. That is why we want to explain, in a simple way:
- what data we process,
- why we process it,
- how long we keep it,
- who it may be shared with,
- what rights you have as a user.
Our goal is to process the smallest possible amount of data necessary for the Service to function.
2. Data Controller
The controller of personal data is:
LW Capital
Tax ID (NIP): 6262868375
E-mail: contact form
3. What data we process
The scope of the data processed depends on how the Service is used.
3.1. Investor Archetype Test
When you use the Test, we record an anonymous session that includes:
- the answers given to the eighteen questions,
- the time taken to give each answer,
- the moment the Test started,
- the moment the Test ended,
- the calculated Investor Archetype,
- the partial scores on the eight axes from which the Archetype is calculated, and the intermediate data of the Investment Awareness Age calculation,
- the calculated Investment Awareness Age,
- the three recommended regulated European cryptocurrency exchanges,
- the version of the models used to calculate the results,
- a random identifier of the link to your result, which lets you return to your result at the /wynik/… address,
- whether the session started from a link shared on social media, and from which channel.
We do not record data that would allow the User to be identified. In particular, we do not record:
- first and last name,
- e-mail address,
- phone number,
- IP address,
- a user account.
The answers given in the Test concern the way investment decisions are made and do not concern special category data, such as data on health, political opinions, religious beliefs or sexual orientation.
Sharing the result. If you use the share button on the result screen, an additional, separate record is created: the moment of sharing, the archetype name, the image variant (the archetype alone, or the archetype with the Investment Awareness Age), the sharing channel and the language. This record is linked neither to your Test session nor to the identifier of your result - it cannot be traced back to any particular run of the Test.
3.2. Contact form
If you use the contact form, we process:
- first name,
- e-mail address,
- the subject of the message,
- the content of the message,
- the language of the message.
We use this data solely to provide a response and to conduct correspondence.
3.3. Visitor’s country
When the Service is used, the country from which the connection is made is determined. This information is used solely for anonymous statistical analysis. The IP address is not recorded or stored by MiCA Intelligence.
The country is recorded with three kinds of statistical records:
- with an anonymous Investor Archetype Test session,
- with a visit sent to an exchange website (section 3.5),
- in the exchange card view counter, that is, the tally of how many times a given exchange’s card was shown on a given day.
We record only the two-letter country code (for example “PL”). If the country cannot be determined, the record is created without that information - a missing country is a normal state. The exchange card view counter contains no User identifier and no moment more precise than the day: a single row states how many times a given exchange’s card was shown on a given day, in a given part of the Service, in a given language and from a given country.
The results of such analyses may be published in aggregate form - for example as the distribution of archetypes in a given country. Published summaries contain no data that would identify anyone.
3.4. Service language
We remember the selected language version of the Service so that the appropriate language is shown on your next visit.
3.5. Visits sent to exchange websites
The Service contains links leading to exchange websites. Either of the two buttons shown for an exchange may be an affiliate link - both the one leading to registration and the one leading to the exchange’s home page; the latter leads to the exchange’s plain address when we hold no such link for it. We count how many times a visit took place. We record only: the moment of the visit, which exchange it concerned, which part of the Service it came from, which of the two buttons was clicked, the language version, and the country from which the connection was made (section 3.3). On the Test result screen we additionally record which of the three presented exchanges was chosen, and the anonymous Test outcome - the archetype name and the Investing Awareness Age range - with no link to any particular run of the Test.
This record is not linked to any person or to a Test session, contains no User identifier and does not allow one person’s history to be reconstructed. The IP address is not recorded or stored. The information is used solely for anonymous statistical analysis and for settlements with partners.
3.6. Protecting the counters against inflation
The Service keeps anonymous counters (advertising banner impressions and clicks, Test starts, exchange card views, visits sent to exchange websites, result shares, contact form submissions). So that these numbers cannot be inflated artificially, we limit how frequently requests may arrive from one place on the network.
The advertising banner counters are two numbers stored on the campaign itself - how many times the banner was shown and how many times it was clicked. No record about an individual User accompanies them. Separately, we keep a tally of exchange card view reports that were not counted because the limits above were exceeded - so that missing data does not look like zero. That tally contains only: the day, the part of the Service, the language, the reason for skipping and two numbers. It contains no country and nothing that would point to a person.
For this purpose the connection’s IP address is used only momentarily: for the duration of handling a single request we convert it into an irreversible hash which lives in the server’s memory and disappears when the server restarts. The IP address itself is not recorded by us - it does not reach our database, any log we keep, or any cookie. Independently of that, the address does reach the technical logs of the hosting provider, which are created outside the Service and which we do not use (see section 3.7). We do not link it to any statistical record and it does not serve to recognise or track the User. The basis for processing is the legitimate interest of the controller (Art. 6(1)(f) GDPR) in protecting the Service against abuse and in the reliability of our own statistics.
3.7. The hosting provider’s technical logs
The Service runs on the infrastructure of a hosting provider (Vercel). In its own technical logs, the provider records basic information about every request sent to the Service - including the connection’s IP address and the browser identifier (User-Agent). These logs are created on the provider’s side and are necessary for the operation and security of the hosting service.
We do not create these logs and we do not use them: we do not build statistics on them and we do not link them to Test sessions or to any other record created within the Service. The basis for processing is the legitimate interest of the controller (Art. 6(1)(f) GDPR) in ensuring the operation and security of the Service. How long the logs are kept is covered in section 9.
4. For what purpose we use the data
We process data solely in order to:
- operate the Service,
- calculate the Test results,
- present the Exchange Match results,
- respond to messages,
- improve the quality of the platform’s operation,
- conduct anonymous statistical analysis,
- ensure the security of the Service,
- fulfill obligations arising from the law.
We do not use data to sell databases or for advertising profiling.
5. Google Analytics
The Service uses Google Analytics 4. Google Analytics is activated only after consent to analytics cookies has been given. Google Analytics is a service provided by Google. Using this tool may involve transferring data outside the European Economic Area in accordance with the rules applied by Google. Detailed information on how Google Analytics works can be found in Google’s documentation and in the cookie settings available in the Service.
6. Technical error tracking
The Service uses Sentry, a service that notifies us about technical errors - for example that a page has stopped opening. Without such a tool we would only learn about an outage once a User reported it to us.
An error report is created only at the moment an error occurs. As long as the Service works correctly, nothing is sent. A report contains:
- a description of the error, including where in the Service’s code it occurred,
- the address of the page on which the error occurred - without address parameters and without any identifiers contained in the address,
- technical information about the environment: the type of browser or server, the version of the Service, and whether the error occurred on the public site or in the administration panel.
What a report does NOT contain. The list below is the essence of this section, not an addition to it - the data listed is removed before a report leaves the Service:
- the IP address - the identity field is explicitly set to empty and the service receives an unambiguous instruction not to determine the address on its own,
- cookies, including the administration panel session cookie,
- request headers, including the browser identifier (User-Agent) and the address of the page you arrived from,
- the content of the contact form - neither the name, e-mail address, subject nor the message itself,
- the answers given in the Investor Archetype Test or its results,
- the identifier of your Test result - if an error occurs on the result page, the identifier from the address is replaced with a placeholder before the report is sent,
- the values of data written to or read from the database, nor the values of variables at the moment the error occurred.
Error tracking does not use cookies and does not store anything in your browser’s memory. It does not serve analytics, does not measure how the Service is used, does not record User sessions and does not measure performance. For that reason it is not covered by the cookie consent mechanism - it operates on the basis of our legitimate interest, which is keeping the Service functional and secure (see section 8).
The project serving the Service is hosted in the European region of Sentry, which means that error reports are processed within the European Union.
7. Cookies
The Service uses cookies. Detailed information on their types, the purpose of using them and how to manage consents can be found in the Cookie policy.
8. On what basis we process data
Depending on the purpose of processing, we rely on various legal bases arising from Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
| Purpose of processing | Legal basis |
|---|---|
| Providing the services available in the Service | Article 6(1)(b) GDPR |
| Handling the contact form | Article 6(1)(b) and (f) GDPR |
| Ensuring the security of the Service | Article 6(1)(f) GDPR |
| Conducting anonymous statistical analysis | Article 6(1)(f) GDPR |
| Google Analytics | Article 6(1)(a) GDPR (consent) |
| Technical error tracking | Article 6(1)(f) GDPR (legitimate interest) |
9. How long we keep data
We do not keep data longer than is necessary to achieve the purpose for which it was collected.
Contact form
Messages sent through the contact form are kept for 24 months from the day we receive them. Once that period ends, the message - together with the name, e-mail address and content - is deleted automatically and permanently. We can also delete a message earlier, including at your request.
Investor Archetype Test results
Anonymous Test results may be kept indefinitely for the purpose of statistical analysis, model development and improving the operation of the Service. These results do not allow a specific person to be identified.
Analytics data
Data processed by Google Analytics is kept in accordance with the settings and the rules applicable within the Google Analytics 4 service.
Technical error reports
Error reports are kept for the period resulting from the settings and the rules applicable within the Sentry service, after which they are deleted by it. Reports do not contain data that would allow a person to be identified (see section 6).
The hosting provider’s technical logs
We do not store the visitor’s IP address - neither our database nor any log we keep records it. The address is, however, recorded by the hosting provider in its own technical logs, which are necessary for the operation and security of the service (see section 3.7). Those logs are kept for a short period resulting from the settings and the rules applicable within the Vercel service, after which they are deleted by it. We do not use them for any purpose.
10. Who your data may be entrusted to
In connection with the operation of the Service, we use the services of external providers. Data may be entrusted only to the extent necessary to provide those services.
Currently these are:
- Vercel - application hosting (the provider records the connection’s IP address in its own technical logs - see sections 3.7, 9 and 11),
- Supabase - storing the Service’s data, including messages from the contact form and anonymous Test sessions (project hosted in the EU region - Frankfurt),
- Google - Google Analytics 4,
- Sentry - technical error tracking (project hosted in the European region; the scope of the data transferred is described in section 6),
- Google Workspace - e-mail handling.
Each provider processes data in accordance with its own documentation and applicable law.
11. Transfer of data outside the European Economic Area
Some of the service providers used by MiCA Intelligence may process data outside the European Economic Area. This applies in particular to services provided by Google. In such cases, data is transferred using the appropriate mechanisms provided for by applicable law, in particular the standard contractual clauses approved by the European Commission or other legal bases permitting such a transfer.
This does not apply to the two services in which the data recorded by the Service is stored. The database (Supabase) is hosted in the EU region - Frankfurt, and the technical error tracking project (Sentry) in the European region. Contact form data, anonymous Test sessions and error reports are therefore processed within the European Union.
A separate matter is the hosting provider’s technical logs (see section 3.7). They are created on the provider’s side, outside the Service, and where they are processed and stored depends on that service’s infrastructure, not on our settings. If this involves a transfer of data outside the European Economic Area, the mechanisms described in the first paragraph apply. We do not create these logs, we do not use them, and we do not record the IP address ourselves (see sections 3.6 and 9).
12. Your rights
You have the right to:
- obtain information about the processing of your data,
- access your data,
- rectify your data,
- erase your data,
- restrict processing,
- object to processing,
- data portability,
- withdraw consent at any time, if the processing is carried out on that basis.
Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn. If you believe that your data is being processed unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office.
13. Consent to cookies
During your first visit to the Service, you can decide which types of cookies you consent to. You can change your decision at any time using the cookie settings available in the Service. Detailed information can be found in the Cookie policy.
14. Profiling and automated decision-making
MiCA Intelligence does not make decisions in relation to Users that produce legal effects or similarly significantly affect their situation. The Investor Archetype Test, the Ranking and Exchange Match serve solely to present information and support the exchange selection process. The results presented by the Service do not constitute an administrative, financial or investment decision.
15. Links to exchange websites
The Service contains links leading to the websites of cryptocurrency exchange operators. After moving to the website of a selected exchange, that operator’s data processing rules and privacy policy apply. MiCA Intelligence is not responsible for how third parties process data.
16. What we do not do
For the sake of transparency, we want to state clearly what MiCA Intelligence does not do.
- We do not sell personal data.
- We do not share data for marketing purposes.
- We do not profile users for advertising.
- We do not require creating an account.
- We do not record IP addresses - neither our database nor any log we keep records them (see sections 3.6 and 3.7).
- We do not record User sessions - we do not capture mouse movements, clicks or screen recordings.
- We do not pass the IP address, cookies or the content of the contact form to the tool that detects outages (see section 6).
- We do not link Investor Archetype Test results to a specific person.
- We do not use Test answers to assess a person or to make decisions concerning the User.
17. Changes to the Privacy policy
The Privacy policy may be changed in the event of:
- changes in the law,
- a change in the way the Service operates,
- the implementation of new features,
- a change of service providers.
The current version of the document is always published in the Service. Each version includes a version number and an effective date.
Key information at a glance
If you do not want to read the entire document, you will find the most important information below.
- Using the Service does not require creating an account.
- We do not record IP addresses - only the hosting provider records them in its own technical logs, which we do not use (sections 3.6 and 3.7).
- Investor Archetype Test results are anonymous.
- We use the contact form solely to respond to messages.
- We delete contact form messages 24 months after we receive them.
- Google Analytics runs only after consent is given.
- Sentry notifies us about outages of the Service - a report is created only at the moment of an error and contains no IP address, cookies or contact form content (section 6).
- We do not record User sessions.
- We do not sell personal data.
- We do not profile users for advertising.
- We do not link Test results to a specific person.
Binding language version
This Privacy policy was drawn up in Polish. In the event of any discrepancy between the Polish version and a translation into another language, the Polish version shall prevail.