Privacy Policy
Last updated: [Insert Date]
1. Information We Collect
When you open an account, we collect the information requested in our Client Account Opening Form, including:
- Business or individual identification details (registration number, tax ID, incorporation date, nature of business)
- Registered office and contact details
- Authorized representatives' names, nationality, and ID/passport numbers
- Expected asset types, estimated values, and source-of-assets information
- Banking details, where provided
- Signatures and applicant initials captured during account opening and compliance review
When you use the Platform, we also collect your login email, a hashed one-time verification code used for multi-factor authentication, and session information. When anyone — including someone without an account — verifies a Safekeeping Receipt, we record the verifying IP address, device fingerprint, and verification result, as part of the SKR's audit trail.
2. How We Use Your Information
As set out in the Account Opening Form's consent section, we use your information to:
- Verify information supplied during onboarding
- Perform identity, compliance, and due diligence checks where required
- Maintain custody records and transaction histories
- Process personal and business information for the administration of requested services
- Detect and investigate fraud, security incidents, and misuse of the Platform
3. Audit & Security Logging
Every action taken on your account — by you or by our staff — is recorded in a permanent audit log, including the actor, action, IP address, device, and timestamp. This is a core part of how Chain of Custody accountability works and cannot be disabled or deleted at a customer's request, though access to it is restricted to authorized personnel.
4. How Your Session Works
The Platform stores your session token in your browser's local storage, not in a cookie. We do not currently use advertising or tracking cookies. If this changes, this policy will be updated to describe what is stored and why.
5. Who We Share Information With
We do not sell your information. We share information with our identity verification service provider (to authenticate your login) and, where you have submitted a request, with staff processing that request (compliance, receiving, vault, or relationship management personnel). We may disclose information where required by law, regulation, or a valid legal process.
6. Data Retention
[Insert retention periods for account records, audit logs, and custody records — should reflect applicable regulatory record-keeping requirements.]
7. Your Rights
[Insert applicable data subject rights — access, correction, deletion, portability — consistent with the data protection law of the jurisdictions you operate in.]
8. Contact
Questions about this Privacy Policy, or requests regarding your personal information, can be directed to [Insert Email] or [Insert Address].