Privacy notice
We process other people's tax data for a living, so this needs to be specific rather than reassuring. Where we are a controller and where we are a processor is the part that matters most.
Last updated 2026-09-08.
Status of this document
Who we are, and in which role
DTech SIA (Riga, Latvia) operates AEOI Reporting. We act in two different roles, and which one applies changes your rights and who you should contact.
For our own customers — the organisations that hold accounts with us — we are a controller of their account data: names, work email addresses, sign-in records.
For the tax data those customers process through the platform, including the self-certifications their own customers complete, we are a processor. The reporting organisation is the controller. If you completed a self-certification form and want your data corrected or erased, the organisation you have an account with is who decides, not us — though we will always pass a request on.
What we collect from visitors to this site
Almost nothing. We set no cookies of our own, there is no advertising, and there is no cross-site profiling.
We do use Google Analytics to count page views, and we should be precise about what that means rather than claim it is invisible. It is loaded with consent denied for every storage category, so it sets no cookies and stores nothing in your browser, and it cannot recognise you on a later visit or on another site. What it does receive is a page view: the address of the page, the page that referred you, your approximate location from your IP address, and your browser and device type. That is a request to Google, and Google is outside the EU. If you would rather not send it, any content blocker or a browser Do Not Track setting will stop it, and nothing on this site breaks when it is blocked.
It runs on these public pages only. It is not loaded in the console, and it is not loaded on a hosted self-certification form — those pages hold data we process on a customer's behalf, and their addresses alone would say who the data is about.
- The free validators run entirely in your browser. The file you check is never transmitted to us, never stored, and never seen. There is no request to our servers when you validate a file — and no analytics event is raised about the file, its name or its contents.
- If you ask for a validation report by email, we receive the report text, the counts, the file name and your address — never the file.
- If you complete the readiness check and ask for the result, we receive your answers, the score and your address. The answers tell us which parts of the problem people are stuck on, which is why we keep them.
- If you write to us through the contact form we receive your name, address, whatever you type in the message, and optionally your organisation. We use it to answer you. It is not added to a mailing list, so there is nothing to unsubscribe from — and please do not paste a client dataset into it, because it is a form and not the product.
- Our host records standard server logs, including IP addresses, for security and troubleshooting.
What we process on behalf of our customers
When an organisation uses the paid product, we process the data they need in order to meet their reporting obligation. That is the data the OECD schema requires and no more:
- Identity: name, address, date and place of birth for individuals; legal name, registered address and identifiers for entities.
- Tax residence and tax identification numbers, or an explicit record that none was issued.
- Controlling persons of entity account holders, and the nature of their control.
- Aggregated transaction totals per crypto-asset and category for the reporting year. We do not hold individual trades.
- The self-certification trail: when a request was sent, when reminders went out, when it was completed, and from what address it was opened.
Why we are allowed to process it
For account data we rely on the contract with our customer, and on our legitimate interest in running and securing the service.
For the page-view analytics on this public site we rely on legitimate interest — knowing which pages are read is how a small team decides what to write next. We do not ask for consent because we do not store anything on your device: the tag runs with every storage category denied, so it sets no cookie, and the ePrivacy consent requirement attaches to that storage rather than to the counting. You can object to this processing, and a content blocker is the fastest way to give effect to that objection.
For the data we process on our customers' behalf, the lawful basis is theirs to establish. In practice it is a legal obligation: the Crypto-Asset Reporting Framework, DAC8 and their national implementations require the reporting organisation to collect and report exactly this information.
We do not use any of it for marketing, we do not sell it, and we do not use it to train models.
Where it is held
In the European Union. Application hosting and the database are in EU regions, and this is a deliberate architectural commitment rather than a default — it is one of the questions every prospective customer asks first.
There is one exception and it is worth naming rather than burying: the page-view analytics on this public site are Google's, so that request leaves the EU. Google Ireland Limited is our counterparty and Google LLC is certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses as the fallback. It carries a page address, a referrer, an approximate location and a browser type — nothing else, because the tag is not loaded on any page that holds data we process for a customer.
Our subprocessors are listed below. We do not add one without updating this page, and customers on a DPA are notified before a new subprocessor starts processing.
How long we keep it
Account data lasts as long as the account, plus the period we are required to keep business records.
Data processed for a customer is kept according to the retention period they set, subject to a floor: reporting obligations have to be defensible for years after a filing, so a retention period shorter than the statutory record-keeping period in the relevant jurisdiction would not be doing the customer a favour. When the period lapses, the personal data is deleted.
The audit log is the exception. It is append-only by design and is not deleted while the account exists: it records that something happened and who did it, which is the point of having it. Entries reference records rather than duplicating their contents.
Contact messages and readiness-check answers are kept until you ask us to remove them, or until we have clearly stopped being relevant to you. Earlier waitlist addresses are held on the same terms.
Your rights
Under the GDPR you can ask for access, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests.
Where we are the controller — your account with us, a message you sent us, the readiness check — write to privacy@aeoireporting.com and we will respond within a month.
Where we are a processor, the organisation whose form you completed decides. Write to them; if you write to us instead we will forward it and tell you we have done so.
You can also complain to a supervisory authority. Ours is the Data State Inspectorate in Latvia; you can equally complain to the authority where you live.
Security
Encryption in transit and at rest. Passwords are stored as scrypt hashes, never recoverable. Session tokens and self-certification links are stored only as SHA-256 hashes, so a database copy does not yield working credentials.
Access to production data is limited to the people who need it, and every access to a customer record through the product is written to that customer's audit log.
We do not hold credentials to any tax administration's portal. The submission file is generated for the customer to upload themselves.
We are not SOC 2 certified and we do not claim to be. We would rather say so than let a badge imply an audit that has not happened.
Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and content delivery | EU region (Frankfurt) |
| Managed PostgreSQL provider | Primary database | EU region |
| Resend | Transactional email — self-certification requests, reminders, reports | Sending region eu-west-1 (Ireland); see their DPA |
| Google Ireland Limited | Page-view analytics on the public website only. Not loaded in the console or on self-certification forms, and therefore never in contact with data we process for a customer | Outside the EEA; EU–US Data Privacy Framework, Standard Contractual Clauses |
Contact
DTech SIA, Riga, Latvia. Privacy questions and data-subject requests: privacy@aeoireporting.com. Everything else: info@aeoireporting.com.