Logo

Legal information

Privacy policy

Last updated: 18 August 2026

1. Data controller

The controller of personal data collected through Cedefix is:

ZAIRUX TECHNOLOGIES, S.L.U.
Tax ID: B75431189
Registered office: Pasaje de Sitja, 2, floor 6, 38004 Santa Cruz de Tenerife, Spain
Trading name: Cedefix
Privacy contact email: support@zairux.com

2. Scope

This policy applies to personal data processed through Cedefix and its associated features: digital-asset route searches and comparisons, account creation and management, preferences and alerts, information about routes that may require external wallets or providers, support forms, transactional or commercial communications, and platform measurement and advertising only when the relevant cookies are accepted.

External websites, applications, exchanges, wallets, bridges, DEXs, CEXs and other services linked from Cedefix have their own terms and privacy policies.

3. Personal data we process

Account data

When you create an account, we may process your email address, also used as an internal account identifier, access credentials, password stored using cryptographic hashing, verification status and date, account creation and last-login dates, preferred language, country where provided, settings, product-update preference and its consent record, session identifiers and access records. Cedefix does not store passwords in readable text.

Account security

For email verification, access recovery, email or password changes and account deletion, we store hashed single-use tokens, their purpose, creation and expiry dates, use status, requesting IP address and the minimum context required to complete the operation. Codes and links have limited validity. We also keep authenticated sessions on the server and use a protected session cookie that is not accessible to JavaScript. To limit abuse of sensitive actions, we temporarily store a non-reversible hashed identifier derived from the action, IP address and relevant identifier, together with attempt counts and the control-window expiry.

Searches, technical data and security

We may record the source and destination assets, search currency or asset, networks and providers consulted, selected filters, viewed routes, route-detail openings, interactions with nodes, providers or external links, preferences relating to KYC, speed, cost, network or provider type, language and approximate region. We may also process IP address, browser and device information, session identifiers, first and latest access dates, visit count, connection timing, technical logs, errors, performance, security events, unauthorised access attempts and abusive use.

This information may be associated with an account, session, device or IP address where necessary to provide the service, maintain its security or generate consented statistics. We do not obtain precise GPS location unless a feature expressly requests it and you authorise it.

Public blockchain data

Cedefix queries public data from blockchains, RPC nodes, market APIs and other sources to calculate and compare routes. It does not currently allow a user to connect a wallet and does not request, link or store users' public wallet addresses.

Cedefix will never request or store private keys, seed phrases or secret recovery codes. Do not enter or send these in forms, emails or support messages. Public addresses and transaction metadata can constitute personal data, and records already on a public blockchain may remain available outside Cedefix's control.

Support and email

When you report an issue, we store the contact email address, description, page URL and whether the report came from an authenticated account, as well as communication history and technical information needed to investigate it. For verification, alerts, security or updates, we may process your email address, communication type, subject, provider message identifier, sending date and status, delivery attempts, technical errors, bounces, spam complaints, unsubscribe requests and evidence of consent for commercial communications. To respect unsubscribes, permanent bounces and complaints, we may keep the email address, reason and relevant dates on a suppression list. Commercial updates require a valid legal basis and voluntary, separate consent.

Alert settings and history

When you configure alerts, we store the associated account, source and target assets, reference amount, alert type, direction or threshold, minimum change percentage, provider and network filters, frequency, recovery preference and active status. We also retain baseline and latest snapshots, evaluation and trigger dates, the latest notified average price, evaluation errors and deduplicated notification records. This allows alerts to be evaluated asynchronously without repeatedly sending the same message.

Cookies and advertising

When you accept optional cookie categories, we may collect identifiers and data about pages visited, searches, routes, filters, provider interactions, campaign performance, audiences and advertising conversions. Necessary technical cookies may be used without consent where legally exempt. Analytics, non-essential personalisation and advertising cookies do not activate until accepted. See the Cookie Policy for details.

Anti-abuse protection

Google reCAPTCHA may be used during registration. When enabled, the challenge token and IP address are sent to Google to verify that the request is not automated, in accordance with the provider's configuration and terms.

4. Sources of data

Data may come directly from you; from your device or browser through technical logs and cookies; from public blockchains, RPC nodes, market APIs and public sources; from email and authentication providers; from Google reCAPTCHA when enabled to protect registration; and from analytics or advertising platforms in line with your consent settings. Cedefix does not use data from a public blockchain to deliberately reveal the civil identity of address holders unless necessary to prevent fraud, meet a legal obligation or protect the service.

5. Purposes and legal bases

PurposeLegal basis
Provide route searches and comparisons of providers, costs, networks, ETA, KYC and confidence.Provision of the requested service and, where applicable, performance of the terms of use.
Create and manage accounts, sessions, preferences and requested alerts.Performance of the contractual relationship.
Personalise results for language, approximate region, availability and preferences.Service provision and legitimate interest in showing relevant results.
Send verification, security, access-recovery and requested-alert emails.Performance of the contractual relationship.
Provide support, maintain technical records, prevent abuse and fraud, protect infrastructure, investigate errors and improve performance.Contractual relationship, requested measures or legitimate interest in security, availability, integrity and technical improvement.
Send newsletters, product updates or promotions; use analytics or advertising cookies.Consent.
Respond to authorities, meet legal obligations and establish, exercise or defend claims.Legal obligation and legitimate interest.

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Where processing relies on legitimate interest, you may request information about the balancing assessment and object for reasons relating to your particular situation.

6. Route ranking and automated processing

Cedefix uses automated processes to search, rank, discard and highlight routes. Ranking may consider estimated total cost, base price, provider fees, network or gas costs, slippage, liquidity, number of steps, estimated time, data freshness and origin, source confidence, network or provider status, KYC requirements and regional availability.

The “best option” is the algorithm's result at the time of the search. It does not guarantee that it suits everyone or remains available when accessing a provider. These processes do not produce legal effects or similarly significant decisions for users. Cedefix does not decide whether a provider accepts a user, perform a provider's KYC or grant financing, credit or access to financial products. The user makes the final decision whether to use a route.

7. External providers and KYC

Cedefix may show routes involving centralised or decentralised exchanges, bridges, wallets, onramps, protocols and other providers. Those providers may receive technical data such as IP address, browser and referring page; request personal data, identity documents or financial information; apply their own geographic-availability and KYC rules; and process data under their own privacy policies.

Unless expressly stated otherwise, Cedefix does not receive or store identity documents submitted to an external provider. A “KYC required” indication is an informational route characteristic, not an identification process performed by Cedefix.

8. Recipients and processors

We may allow access to personal data to providers needed for our operation, including Amazon Web Services for hosting, cloud infrastructure, databases, storage, backups and transactional email through Amazon SES; security, logging, monitoring and diagnostics; forms and support; authentication and anti-abuse protection, including Google reCAPTCHA where enabled; RPC nodes and blockchain infrastructure; Google Tag Manager and Google Analytics for consented analytics and measurement; Google AdSense for consented advertising; and legal, tax, accounting or technical advisers.

Processors act on Cedefix's instructions and are bound by the relevant agreements. We may disclose data to authorities where legally required, to advisers or insurers where necessary to defend claims and in a corporate transaction with required safeguards. Cedefix does not sell personal data. External providers voluntarily accessed from a route may act as independent controllers.

9. International transfers

Some technology providers, analytics platforms, blockchain services or decentralised-network nodes may be outside the European Economic Area. Where Cedefix makes an international transfer, it uses GDPR mechanisms such as an adequacy decision, the EU-US Data Privacy Framework where applicable, standard contractual clauses with supplementary measures, binding corporate rules or another recognised safeguard or exception. Public blockchains may have globally distributed nodes; Cedefix seeks not to introduce additional personal data on-chain and limits on-chain processing to public information strictly needed for the requested feature.

10. Data retention

Account data is kept while the account is active; on deletion it is erased or restricted unless retention is required for legal obligations or liabilities. Server sessions become invalid on logout, security invalidation or expiry, currently after no more than 14 days; expired session records may remain until technical cleanup. Confirmation codes are valid for 15 minutes, password-reset links for 1 hour and email-verification links for 24 hours; related technical records may remain where needed for security and audit or until account deletion. Preferences, alerts, snapshots and notification history are kept while the account is active or until disabled or deleted, so conditions, frequency limits and deduplication can be applied. Support and security data is retained for the request and a limited, proportionate period for claims, incidents, fraud and unauthorised access. Email-delivery history is kept as needed for delivery evidence, failures, security and compliance; suppression entries may remain as long as needed to prevent unwanted messages. Expired anti-abuse records are periodically deleted. Analytics, advertising and legal-obligation data follow the Cookie Policy, provider settings and applicable limitation periods. Data is deleted, aggregated or anonymised where possible once no longer needed.

11. Your rights

You may request access, rectification, erasure, restriction, objection, portability, withdrawal of consent and, where the legal requirements apply, the right not to be subject to automated decisions with legal or similarly significant effects. Write to support@zairux.com and state the right you wish to exercise, information needed to locate your data and a contact method for our response.

If we reasonably doubt your identity, we may request limited additional information to verify it. You may also lodge a complaint with the Spanish Data Protection Agency or the supervisory authority for your place of residence. Exercising your rights is free, except for manifestly unfounded or excessive requests where permitted by law.

12. Cookies and consent management

The separate Cookie Policy identifies the cookies and technologies used, their owner, purpose, duration, possible international transfers and the procedure to accept, reject or withdraw consent. Optional analytics and advertising tools do not load before the relevant consent is obtained. You may change or withdraw consent at any time from the cookie-settings panel.

13. Minors

Cedefix is not directed at people under 18 and does not intend to deliberately collect their personal data. If we learn that a minor has provided data contrary to the service terms, we may block the account and erase or restrict the relevant data.

14. Security

Cedefix applies technical and organisational measures appropriate to the risk to protect data against unauthorised access, accidental loss or destruction, improper alteration, unauthorised disclosure, fraudulent use and availability or integrity incidents. Measures may include access controls, credential management, encryption in transit, backups, security logs, updates and incident-response procedures.

No internet-connected service can guarantee absolute security. Cedefix does not custody private keys or seed phrases. You are responsible for keeping them under your control and not disclosing them to third parties.

15. Changes to this policy

Cedefix may update this policy to reflect product changes, new features, changes to providers, regulatory developments or new processing operations. The version in force is the one published on the website and identified by its update date. Where a change is material, we may show a prominent notice or inform registered users.