Legal
Personal data processing protection policy
This policy describes the personal data this SafeScore origin actually stores when you create an account, run a screen or upload an assistance pack. It is not a GDPR certification, not a claim that SafeScore is your KYC vendor, and not a substitute for the house’s own privacy notice.
Also read Terms and conditions.
1. Who processes personal data
The controller of the workspace account, eligibility questionnaire, assistance pack and session cookie is the operator of this SafeScore origin.
A registered company name, company number, registered office, named data-protection officer and Article 27 representative are not published on this page. Those facts are therefore not stated here.
Each examiner (ScoreGuard, ChainTrace, Holistix) stores the screen you run in that product’s own database. Scores are not merged on the control plane.
2. What we collect
Account: name, email, password hash, phone number, and the time the account was created.
Eligibility questionnaire: entity type, selected crypto-asset services, answers to provider-published gates, optional wallet/exchange background, and the score computed from those answers.
Assistance pack: the house you marked, item ticks, free-text notes, and the files you upload (identity scans, proof of address, source-of-wealth evidence and similar documents you choose to attach).
Screens: the wallet, transaction or entity subject you submit, the resulting report, and the workspace token that marks the report as yours.
Session: an HTTP-only cookie named safescore_session so the browser stays signed in. It is not an advertising cookie.
3. Why we process it
To create and operate the workspace you asked for (account, plan metering, eligibility report).
To run the screen you submitted on the examiner you opened, using the indexers configured for that product.
To hold the assistance pack you are assembling so you can complete a house-specific checklist before you open the lender site.
We do not run the pack as the house’s customer-due- diligence file, we do not sell the pack, and we do not use uploaded identity documents for marketing.
4. Files you upload
Pack files are stored on this origin, under your account, against the checklist item you attached them to. Allowed types are ordinary documents and images (PDF, PNG, JPEG, WebP, CSV, text, Word, Excel). Executables are refused. A file is limited to 15 MB; an item may hold up to eight files.
Uploading a file does not send it to the lender. You can download or remove a file from the pack. Removing it deletes the stored copy for that account.
Do not upload documents you have no right to store. SafeScore does not certify authenticity or run liveness on an identity scan.
5. Wallet addresses and chain data
A screen sends the subject you typed to the live indexers configured for this deployment (the fail- closed path Alchemy → QuickNode → Blockscout → Etherscan, and CoinGecko for asset prices). Those providers receive the address or hash you submitted. They are not SafeScore companies.
Public chain data is public. A report may quote cited labels and the OFAC SDN overlay loaded in this build. Unlabelled counterparties stay unlabelled. Permissioned ledgers that cannot be observed are reported as not observable — they are not guessed.
6. Who we share with
We do not sell personal data.
A marked house does not receive your pack automatically. Requesting assistance is an introduction: you still deliver the file on the house’s own channel, and that house’s privacy notice then applies to what you send them.
Indexers and the price feed receive the technical data needed to run a screen, as above. TLS certificates for a public origin are issued by the certificate authority configured for this deployment.
We may disclose data if required by law or to protect a person from serious harm. There is no other sharing described on this page.
7. Cookies
safescore_session is set when you sign in or create an account. It authenticates the workspace. It is not used to advertise on other sites. Signing out clears it.
8. How long we keep it
Account, questionnaire and pack data are kept while the account exists. Pack files you remove are deleted from this origin. Reports stay in the examiner that produced them so My reports can reopen them.
Self-serve account erasure is not built on this origin. You can remove pack files, stop submitting screens, and sign out. To ask for the account itself to be closed, use the email address on that account.
9. Your rights
You can open and download the eligibility report (JSON, CSV, HTML), retake the questionnaire, tick or reopen pack items, and download or delete pack files.
You can ask, via the account email, for a copy of what this origin holds on the account, for a correction, or for the account to be closed. Those requests are handled as the deployment actually allows — there is no separate portal and no claimed statutory deadline published here.
This policy does not name a supervisory authority. Naming one would imply an establishment or a filing that this page does not evidence.
10. International access
This origin may be reached from more than one country. Indexers and the price feed are third-party services. This page does not claim an adequacy decision, standard contractual clauses, or a specific hosting region.
11. Children
The workspace is not directed at children. Do not create an account or upload identity documents for a person under 18.
12. Changes
This policy is version 2026-09-12, effective 12 September 2026. A new version is published on /privacy (also /data-protection). Material changes that affect an existing account are accepted again in the workspace before the assistance pack can be marked complete.
13. What this policy is not
It is not a claim that SafeScore is ISO/IEC 27001 or SOC 2 certified — see /assurance.
It is not a claim that SafeScore verified your identity or that a house will accept the pack.
It is not the privacy notice of Sygnum, AMINA, Arch, Ledn, Unchained or any other directory house.