Privacy Notice

Effective date: [To be confirmed]Version: Draft 1.0

1. Data controller

EscrowSign ([Entity name and registered address to be confirmed]). Contact: [privacy contact email to be confirmed].

2. Categories of personal data we collect

  • Identity data: name, date of birth, nationality, government ID documents
  • Contact data: email address, phone number, residential address
  • Account data: login credentials (password hash only), account settings
  • Business data: company name, registration number, UBO information, director details
  • Transaction data: asset details, payment amounts, counterparty identifiers, milestone records
  • Technical data: IP address, device fingerprint, browser, session data
  • Communications: messages and documents submitted through the Platform
  • Verification data: results of identity, sanctions, PEP, and adverse-media checks
  • Biometric data (where liveness verification is required and lawful in your jurisdiction)

3. Sources of data

Directly from you, from identity verification and screening providers, from payment and escrow partners, and from publicly available sources where permitted.

4. Purposes and legal bases

  • Contract performance: providing the transaction coordination service
  • Legal obligation: identity verification, AML/CTF compliance, sanctions screening, tax reporting
  • Legitimate interests: fraud prevention, security, platform improvement
  • Consent: marketing communications (separate opt-in required)

5. Automated decision-making

We use automated screening for sanctions, PEP, fraud risk, and identity verification. Where a decision significantly affects you, you may have the right to request human review. [PLACEHOLDER — rights depend on applicable law.]

6. Sharing with third parties

We share data with licensed payment and escrow partners, identity verification providers, sanctions screening providers, legal and professional advisors, and law enforcement where required. We do not sell personal data.

7. International transfers

[PLACEHOLDER — Transfer mechanisms and data-residency requirements to be confirmed by legal counsel based on operating jurisdictions.]

8. Retention

We retain personal data for as long as required to provide services and comply with legal obligations. Financial, AML, legal, fraud, and tax records may be retained after account closure as required by applicable law.

9. Your rights

Depending on your jurisdiction, you may have rights to access, rectify, erase, restrict, port, or object to processing of your data. To exercise your rights, submit a request through the official contact page. We will respond within applicable legal timeframes.

Note: Some data cannot be erased where retention is required by law, fraud prevention, or legal proceedings.

10. Security

We use TLS, encryption at rest, access controls, and regular security testing. We do not store plaintext passwords, full card data, or crypto seed phrases. Identity documents are not visible to counterparties.

11. Children

The Platform is not directed at persons under 18 (or the applicable age of majority). We do not knowingly collect data from minors.

12. Cookies

See our Cookie Notice for information on how we use cookies and similar technologies.

13. Complaints

You may complain to the relevant supervisory authority in your jurisdiction. Contact details are available on your national data protection authority’s website.

14. Changes

We will notify you of material changes to this Notice. Continued use after the effective date constitutes acceptance where permitted by law.