Skip to content
Join the waitlist

Legal

Privacy notice

Short version: we ask for an email address, encrypt it, keep it in the EU and use it for one thing. You can remove it at any time.

Last updated: 1 October 2026. Version 2026-10-01.

What this notice covers

This notice covers this website: the waitlist, the partner form and the demo app. Zeltis does not offer services yet, so no customer accounts, payments or identity documents are processed. A full notice for the real app will be published before launch.

Who is responsible

The controller is Zeltis SIA (in formation), Riga, Latvia. Until the registration of the company is complete, its founders are responsible for the processing described here.

Contact for anything about your data: privacy@zeltis.money.

What we collect and why

DataWhyLegal basis (GDPR)
Waitlist: your email address and, if you choose one, your country To tell you when Zeltis opens in your country Your consent, Article 6(1)(a)
Partner form: company, name, work email, the kind of service and your message To answer your inquiry and prepare a possible contract Your consent, Article 6(1)(a), and steps before a contract, Article 6(1)(b)
With both forms: the two-letter country code of your connection, the page the form was on, and the time and version of your consent To plan launch countries and to be able to show that consent was given Legitimate interest, Article 6(1)(f), and the duty to demonstrate consent, Article 7(1)
Abuse protection: a one-way code made from your IP address and the date To limit repeated requests to the forms and the demo app Legitimate interest, Article 6(1)(f)

Giving your email is voluntary. Without it we cannot tell you about the launch; nothing else depends on it.

What we do not collect

  • We do not store your IP address. The one-way code above cannot be turned back into an address and is deleted after one day.
  • The pages of this site set no cookies and store nothing on your device. The demo app sets one cookie, described below.
  • There are no analytics, advertising or social media scripts, and no fonts or files loaded from other companies.
  • We do not build profiles and make no automated decisions about you.

Please do not send identity documents, passwords, wallet keys or account details through these forms.

The demo app

The demo app asks for no personal data. Its balances, cards, account details and transfers are simulated.

  • One cookie: when you create a demo wallet, the app sets a cookie that keeps your demo session open. The demo cannot work without it. Scripts cannot read it and it is not used to track you.
  • App files: your browser may keep a copy of the app's own files, so that it opens quickly and can be installed on a home screen. No demo data is kept in that copy.
  • What we store: the simulated data of your demo wallet, the two-letter country code of your connection and the name you may type in the settings, which is encrypted. Please do not type your real name.
  • How long: a demo wallet expires 7 days after it was created and is then deleted with everything in it. You can end the session earlier in the settings of the app.

How it is protected

  • Email addresses, names, company names and messages are encrypted in our application (AES-256-GCM) before they are written to the database. The database provider encrypts the storage again.
  • The database is located in the European Union.
  • Only named members of staff can read the entries. They sign in with a password and a one-time code, and their rights depend on their role.
  • Every time staff open a list, export it or change an entry, the action is written to a log that shows any later alteration.

Who receives it

We use one processor: Cloudflare, our hosting, network and database provider. It handles the data only on our instructions, under its data processing terms. The database with your entries is kept in the EU.

When you open a page, the provider's network handles your request, including your IP address, to deliver the page and to stop attacks, and keeps short technical logs. Where this involves a transfer outside the European Economic Area, it relies on the safeguards in those terms: the EU–US Data Privacy Framework and the standard contractual clauses of the European Commission.

We do not sell your data and do not share it with anyone else. We would disclose it only where a law obliges us to.

How long we keep it

  • Waitlist entries: until you remove yourself, and at the latest 12 months after Zeltis opens.
  • Partner inquiries: 24 months after the last contact, unless a contract is signed.
  • Demo wallets: 7 days.
  • One-way codes for abuse protection: one day.

Your rights

You can ask us for a copy of your data, have it corrected or deleted, restrict or object to its use, and receive it in a portable format. You can withdraw your consent at any time; this does not affect what was done before.

  • Waitlist: after signing up you see a personal removal link. It deletes your entry in one click, without an account.
  • Everything else: write to privacy@zeltis.money. We answer within one month.

If you think we handle your data wrongly, you can complain to the data protection authority of your country or to the Data State Inspectorate of Latvia (Datu valsts inspekcija), dvi.gov.lv.

Age

The waitlist is meant for people aged 18 or over.

Changes

If this notice changes, the date and the version at the top change with it. The version you agreed to is stored with your entry.