This Privacy Policy explains how Real Vault Shipping/Security ("Real Vault", "we", "us") collects, uses, stores and shares personal data when you visit our website, contact us, become a client or use the Real Vault client portal. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Polish Act on the Protection of Personal Data of 10 May 2018 and the Polish Act on Counteracting Money Laundering and Terrorism Financing of 1 March 2018.
1. Who is the data controller
The controller of your personal data is Real Vault Shipping/Security, ul. Międzyosiedlowa 8, 04-763 Warsaw-Wawer, Masovian Voivodeship, Poland. You can contact us about anything in this policy by email at realvaults@diplomats.com, by post at the address above, or by phone on +48 89 383 85 74 during office hours (Monday to Friday, 8:30 AM – 5 PM).
Where we act on behalf of an institutional client — for example when we process the personal data of a client company's employees or beneficial owners — we do so as a controller in our own right for the purposes of identity verification and anti-money-laundering compliance, and as a processor for any additional purposes agreed in the client agreement.
2. What personal data we collect
We collect only the data we need for the purpose at hand. Depending on how you interact with us, this may include:
- Identity data: name, date of birth, nationality, identity document type and number, a copy of the identity document, photograph and, for corporate clients, the identity of directors, authorised signatories and beneficial owners.
- Contact data: postal address, email address, telephone numbers and preferred language.
- Account data: client code, portal login email, hashed password, portal language preference, sign-in timestamps and security events.
- Custody data: details of deposits, bars (serial numbers, refinery, fineness, weight, certificates), documents you upload or that we issue, shipment and withdrawal requests, and the name of any representative who delivers or collects metal on your behalf.
- Next-of-kin data: the name, relationship, contact details and identity document reference of the person you nominate, which we collect from you and verify.
- Financial and compliance data: source-of-funds and source-of-wealth information, bank account details used to pay our fees, invoices, and the results of sanctions, politically-exposed-person and adverse-media screening.
- Communications: messages sent through the website contact form or the portal messaging system, emails, call notes and correspondence.
- Technical data: IP address, browser type and version, device identifiers, operating system, referring pages and the pages you visit, collected through server logs and strictly necessary cookies.
- Physical security data: CCTV images and access-control logs if you visit our facility.
3. Why we process your data and on what legal basis
Under the GDPR we must have a legal basis for every purpose. We rely on the following:
- Performance of a contract (Art. 6(1)(b)): to onboard you as a client, provide vault storage and transport services, operate your portal access, respond to requests, issue documents and invoices, and communicate with you about your holdings.
- Compliance with a legal obligation (Art. 6(1)(c)): to verify your identity, screen against sanctions lists, identify beneficial owners, retain records and report suspicious activity under anti-money-laundering law; to keep accounting and tax records; and to respond to lawful requests from courts and authorities.
- Our legitimate interests (Art. 6(1)(f)): to protect the security of our facility, systems and the assets we hold — including CCTV, access control, fraud prevention and IT security monitoring; to manage our business and relationships; to defend legal claims; and to respond to enquiries sent through the website. When we rely on legitimate interests we balance them against your rights and freedoms.
- Your consent (Art. 6(1)(a)): for optional cookies (if and when we introduce them) and for any marketing communications. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Vital interests or substantial public interest (Art. 9(2)): in the rare cases where we need to process special-category data — for example a medical certificate in a succession matter — we do so only where the law permits.
5. International transfers
Our facility, our staff and our primary data storage are in the European Union. Where a movement you request involves a destination outside the European Economic Area — for example Switzerland, the United Kingdom or the United Arab Emirates — we share only the data needed for that movement with the carriers and custodians involved. Switzerland and the United Kingdom benefit from European Commission adequacy decisions. For other countries we rely on the European Commission's Standard Contractual Clauses or on the derogation for transfers necessary for the performance of a contract concluded at your request.
Some of our technology providers may process limited technical data outside the EEA (for example when a content-delivery network serves the website to you). Those providers are bound by Standard Contractual Clauses and equivalent safeguards.
6. How long we keep your data
- Identity, verification and transaction records: five years from the end of the business relationship or the date of the transaction, as required by Polish anti-money-laundering law; longer if a competent authority requires it.
- Contractual and custody records (agreements, deposit receipts, bar lists, movement records, invoices): for the duration of the relationship and for six years afterwards, or longer where needed to defend legal claims or to satisfy insurers.
- Accounting records: five years from the end of the financial year to which they relate, as required by the Polish Accounting Act.
- Portal account data: for the duration of the relationship; accounts are deactivated on termination and personal data is deleted or anonymised at the end of the retention periods above.
- Website enquiries and messages: up to three years from the last message, unless they form part of a client relationship.
- CCTV recordings: up to 90 days, unless an incident requires retention as evidence.
- Server logs and technical data: up to 12 months.
7. Your rights
Subject to the conditions in the GDPR, you have the right to:
- Access the personal data we hold about you and receive a copy (Art. 15).
- Have inaccurate data corrected and incomplete data completed (Art. 16).
- Have your data erased where there is no longer a lawful reason to keep it (Art. 17). Note that anti-money-laundering and accounting laws require us to keep certain records for fixed periods even after you ask for erasure.
- Restrict processing in certain circumstances (Art. 18).
- Receive the data you provided to us in a structured, machine-readable format and have it transmitted to another controller where processing is based on contract or consent (Art. 20).
- Object to processing based on our legitimate interests (Art. 21).
- Withdraw consent at any time where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions; sanctions and PEP screening results are always reviewed by a member of staff.
To exercise any of these rights, email realvaults@diplomats.com or write to us at the address above. We will respond within one month, extendable by two further months for complex requests. We may ask you to verify your identity before acting on a request.
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl, or with the supervisory authority in the EU member state where you live or work.
8. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data we hold. Personal data and custody records are stored in access-controlled systems with encryption in transit and at rest; portal passwords are stored only as salted hashes; documents are held in a private storage bucket and served through short-lived signed links; database access is governed by row-level security so that each client can see only their own records; and administrative access is limited to named staff and logged.
Physical records and identity documents are kept in locked storage within our secured facility. Staff receive data-protection and anti-money-laundering training and are bound by confidentiality obligations. We review our security measures regularly and test them with our insurers and external advisers.
No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and inform you without undue delay where the risk is high.
10. Children
Our services are intended for adults and businesses. We do not knowingly collect personal data from anyone under 18. Where holdings are held for the benefit of a minor, the account is opened in the name of a parent, guardian or trustee, who provides the necessary data.
11. Changes to this policy
We may update this policy from time to time, for example when the law changes or when we introduce new services. The date of the latest version is shown at the top. Material changes affecting clients will be notified by email or through the portal at least 30 days before they take effect.
12. Contact
Questions, requests and complaints about personal data should be sent to realvaults@diplomats.com or to Real Vault Shipping/Security, ul. Międzyosiedlowa 8, 04-763 Warsaw-Wawer, Masovian Voivodeship, Poland. Please mark correspondence "Data protection".