← Back to Bonfium
EN LT LV ET PL DE FR FI SV

Privacy Policy

Last updated: 16 August 2026

Who we are

Bonfium is operated by MB "Department 03", a private limited company registered in Lithuania.

Data controller
MB "Department 03"
Company code 308106631
Mindaugo g. 3-9A, LT-03108 Vilnius, Lithuania
bonfium@gmail.com

We are the controller of the personal data described below. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; privacy questions go to the address above.

What we collect, and why

We collect only what the service needs to work. Each item below has a legal basis under Article 6 GDPR.

DataWhyLegal basisKept for
Name and email address To create your account, sign you in, and show the other side of a trade who they are dealing with Performance of a contract (Art. 6(1)(b)) While your account is open, then 12 months
Quick Trade name, email, private-link hash, confirmation and access timestamps To create passwordless access limited to one trade, confirm control of the email address, notify both parties, prevent duplicate acceptance and recover access Performance of a contract (Art. 6(1)(b)); legitimate interest in access security and fraud prevention (Art. 6(1)(f)) Participation record with the trade; private-link hashes are erased when they expire. Raw links are never stored
Password To secure your account. Stored as a one-way password hash, never as readable plaintext. A strong, unique password is still important because stolen hashes can be attacked offline Performance of a contract While your account is open
Two-factor authentication secret and backup codes To protect your account and the money in it. Encrypted at rest; backup codes are hashed Legitimate interest in account security (Art. 6(1)(f)) While two-factor is enabled
Trade records: item description, price, category, counterparty, status, timestamps To operate the pre-launch trade workflow and, after a licensed payment provider is connected, administer trades, payments and disputes Performance of a contract; legal obligation for accounting (Art. 6(1)(c)) 10 years from the trade, as Lithuanian accounting law requires
Identity verification result (verified / rejected, and the date) To confirm both sides of a trade are real people, and to meet anti-money-laundering duties Legal obligation; performance of a contract 5 years after the account closes, as AML law requires
Courier tracking number and delivery scans To know when a parcel arrived and operate the trade timeline. Automatic payment release is not active during pre-launch Performance of a contract With the trade record
Dispute evidence you submit (text, photos, video) To decide the dispute. Both sides see the same file – there are no secret submissions Performance of a contract 3 years after the dispute closes
Failed login attempts To slow down attackers guessing passwords Legitimate interest in security 15 minutes
Page views (page, referring site, date) To understand which pages people use. No cookies, no cross-site tracking, no advertising Legitimate interest in improving the service 13 months, aggregated
Administrative access log To record which administrator viewed or changed personal data, and when – so that access is accountable Legal obligation (Art. 5(2) accountability) 12 months

What we deliberately do not collect

Cookies

We use two cookies, both strictly necessary, so no consent banner is required:

Who else sees your data

We share data only with processors who help run the service, each under a written data processing agreement, and only what each one needs:

ProcessorWhat they handleWhere
HostingerHosting and databaseEU
TrackingMoreParcel tracking numbers and delivery scansOutside the EU, under Standard Contractual Clauses
Payment institutionHolding and moving funds, and identity verification for larger payouts. Named here once appointedEU
Anthropic (Claude)When a dispute is opened: a role-based account of what happened ("buyer" / "seller", never your name), the trade facts, and any photos either side submits as evidence – used only to draft an advisory summary for our reviewer. Not yet activeUnited States, under Standard Contractual Clauses and the EU–US Data Privacy Framework

We also disclose data where the law requires it – for example to tax authorities under the EU platform reporting rules (DAC7), or to law enforcement acting on a valid legal basis.

What the other side of a trade sees

When you open or accept an account trade, your counterparty sees your name, whether your identity is verified, your number of completed trades, and your trader rank. In Quick Trade, the counterparty sees the name you entered, that your email was confirmed, and that your identity was not verified. They do not see your email address, your address, private access link, or any other trade.

Your rights

Under the GDPR you can ask us to:

Write to bonfium@gmail.com. We answer within one month, as Article 12 requires. There is no charge.

Complaints

If you think we have handled your data badly, please tell us first – we would rather fix it. You also have the right to complain to the Lithuanian supervisory authority:

Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
vdai.lrv.lt

Security

HTTPS traffic is encrypted in transit. Passwords are hashed, newly enabled two-factor secrets require authenticated encryption, and sign-in attempts are rate limited. Administrative access to personal data is logged. If a breach ever put your rights at risk, we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.

Automated decisions

The pre-launch site can update workflow deadlines automatically, but it cannot accept, release or refund real money. Those actions remain disabled until a licensed payment provider is implemented. Future automated trade actions will follow the published deadlines on our trade rules page. Disputes are intended to be decided by a person, not an algorithm.

When a dispute is opened or answered, our system can ask an AI model (Claude, made by Anthropic) to read the trade record, what each side wrote, and any evidence photos, and produce a written summary with a recommended outcome. This is a briefing for our reviewer, not a decision: the AI cannot release, withhold or move any money, and our reviewer remains free to agree, disagree, or act differently, as Article 22 GDPR requires. Names are replaced with "buyer" or "seller" before anything is sent. This feature is built but not yet active; it will only be switched on once this policy names it as live, below.

Children

Bonfium is not for anyone under 18. Account users failing identity verification on age are closed. Quick Trade users must declare that they are 18 or older, and verification may still be required before payment or payout.

Changes

If we change this policy in a way that matters, we will email registered users before it takes effect. The date at the top always shows the current version.

This policy describes the service as built. Some features referenced here – payments, automated identity verification, and the Anthropic-powered dispute assistant – are not yet live; this policy will be updated, and this notice removed, before each is switched on.