Privacy Policy

Last updated

1. Who we are

TRUSTLINE DIGITAL ASSET LTD ("Trustline", "we", "us", "our") is a private company limited by shares registered in England and Wales under company number 17356174, whose registered office is at The Barn, c/o Integral Associates Limited, Rear of 3-5 Church Street, Ampthill, Bedford, England, MK45 2PJ, United Kingdom.

This policy explains how we handle personal data when you visit https://www.trustline.id and its subdomains (the "Site"), when you contact us, and when you use our services (the "Services"). We handle personal data in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

Contact us about anything in this policy at privacy@trustline.id.

2. When we are a controller and when we are a processor

We are a controller where we decide why and how personal data is processed: visitors to the Site, people who contact us, business contacts at customers, prospects and partners, job applicants, and holders of accounts on the Trustline platform.

We are a processor where we process data on behalf of a customer and on that customer's instructions. This covers the end users of our customers ("End Users"). The customer is the controller. If you are an End User, contact that customer first and we will support their response.

We are non-custodial. Our applications are interfaces to smart contracts on public blockchains. We do not hold your private keys, take custody of your assets, or keep a copy of the private information held in your wallet. We also do not store the underlying sensitive information used in security checks: that sits with the relevant security provider or with the customer.

3. What we process, why, and on what lawful basis

Personal dataPurposeLawful basis
Business contact details: name, business email, telephone, job title, employer, and the content of messages you send us.Responding to enquiries, managing our relationship with you, considering job applications.Performance of a contract; legitimate interests in developing business relationships; consent where we ask for it.
Pricing call details: your name, work email, company, the scope you describe, and the time you choose.Arranging and holding the call you asked for, and preparing a price for your case.Steps taken at your request before entering a contract; legitimate interests in responding to enquiries.
Account data: name, business email, authentication credentials and multi-factor identifiers, role and permissions, wallet address, and a record of actions taken in the platform.Creating and securing accounts, authenticating users, applying the customer's security requirements, maintaining an audit trail.Performance of a contract; legitimate interests in security; legal obligation where records must be kept.
Validation reference data: a non-sensitive mapping linking a user's credential to their identifier with a security provider, plus the outcome and time of each check.Matching a security result to the right transaction without holding the underlying information.Performance of a contract. Processed as a processor on the customer's instructions where the individual is an End User.
Server access logs: IP address, user agent, page requested, time, response code, referring page. Plus diagnostic data such as technical errors.Keeping the Site and Services available and secure, diagnosing faults, detecting and preventing abuse. Not used for profiling or marketing.Legitimate interests. The Site sets no cookies and does no tracking, so no consent is required.
Marketing data: your contact details, your preferences, and whether you opened or interacted with a communication we sent.Sending you information about Trustline and its Services.Consent, or legitimate interests in marketing to business contacts. Withdraw at any time using the unsubscribe link or privacy@trustline.id.

We do not seek special category data and ask that you do not send it to us.

3A. What each application does

Section 3 covers what we process and why. Because our applications differ from one another, this section says which of them is involved when. All of them run on subdomains of trustline.id, are built and deployed separately, and none carries analytics, advertising or session-recording tools. What each stores on your device is listed in section 3 of our Cookie Policy.

www.trustline.id — this website. No account and no login. If you email us we process the address you write from and what you say, so that we can reply.

The pricing page has one form: a three-step request for a pricing call. It asks for your name, work email and company, and for the scope of what you want to protect, so that the call is useful. Those answers stay in the page while you work through it. At the last step a calendar provided by Cal.com, Inc. appears so that you can choose a time, and the answers are passed to it as the booking details and its notes. The calendar loads only when you reach that step, and the booking is created in our calendar. Section 3 of our Cookie Policy describes what it puts on your device.

auth.trustline.id — the authentication screen. The only place we ask you for anything directly. It is designed to be embedded in the page of the company whose service you are using, rather than visited on its own, and you will normally meet it as a panel inside that page at the moment you approve a transaction. It collects the email address or mobile number you enter, the one-time code you enter back, and the session identifier the embedding site passes so that your approval is matched to the right transaction. When you succeed we generate an authentication token and record the time, together with any choices you make in the follow-on steps. The result is handed back to the company that embedded the screen, which is how your transaction proceeds; where you are that company's End User, we act as its processor and it is the controller.

Identity verification does not run in the service today. The step that will one day carry it collects nothing and engages no provider. We will name the provider and the applicable regime in this policy before that changes.

onboarding.trustline.id — the onboarding portal. For our customers' developers rather than their end users. It collects the email address of whoever signs in, verified by the same one-time code flow, and the blockchain address of the wallet they connect. When configuring a rule, a customer can enter the email addresses of other people who will be asked to approve transactions; those people did not give us their address themselves, and section 4A explains what that means for them. Everything else the portal collects is technical configuration, such as contract addresses and rule names, which is not personal data.

dev.trustline.id — the developer documentation. Reference material only. It collects nothing, has no forms and no sign-in.

4. Where it comes from

From you, from the organisation you work for, from our customers where you are one of their users, from security providers in the form of a check result rather than the underlying information, and from public sources such as company registers and professional networks when we research a prospective customer or partner.

4A. If someone else entered your address

A customer configuring Trustline can list the email addresses of the people who need to approve transactions. If you were added that way, you did not give us your address: the customer did, and it is responsible for having a basis to share it with us.

We use it only to ask you for the approvals that rule requires. You have every right set out in section 8, including erasure, and you can ask us who added you. Write to privacy@trustline.id.

5. Blockchain data

Some data is recorded on a public blockchain, in particular the proof that a transaction was validated against a customer's security requirements. That record is a proof of validation; it is not designed to contain personal data.

Data written to a public blockchain cannot be modified or erased. We do not control public blockchains and cannot exercise your rights against them, so the rights in section 8 are limited in respect of anything recorded there.

6. Who we share it with

  • Security providers selected by us and chosen by the customer, to perform the checks the customer has configured.
  • Service providers acting as our processors: cloud hosting and infrastructure, identity and authentication, key management, communications, scheduling, error monitoring, and customer relationship management. Each is bound by a written contract meeting Article 28 UK GDPR. Scheduling for the pricing call is provided by Cal.com, Inc.
  • Our customers, where you are one of their users.
  • Professional advisers, and public authorities, regulators, courts and law enforcement where required by law or necessary to establish or defend legal claims.
  • A purchaser or investor, in connection with a sale, merger or financing, subject to confidentiality.

We do not sell personal data. For the identity of the processors we use, write to privacy@trustline.id.

7. International transfers and retention

Personal data may be processed outside the United Kingdom, including in the European Economic Area and the United States. Where it is, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses together with a transfer risk assessment. A copy of the safeguards for a given transfer is available on request.

CategoryRetention
Business enquiry and contact records3 years from the last meaningful contact
Customer account and relationship recordsThe term of the contract plus 6 years
Security validation logs and audit records24 months from the validation
Server access logsNo longer than 12 months
Marketing recordsUntil you withdraw or object, then a suppression record
Unsuccessful job applications12 months

Data held on a blockchain cannot be deleted. See section 5.

8. Your rights

You have the right to access your personal data, to have it corrected, to have it erased, to restrict how we use it, to receive it in a portable format, to object to processing based on our legitimate interests, and to object at any time to direct marketing. Where processing is based on consent, you may withdraw it, without affecting what was done beforehand.

Exercise any of these by emailing privacy@trustline.id or writing to the registered office.

We respond within one month, calculated under Article 12A UK GDPR. Where we need to confirm your identity, that month runs from the date we receive the confirming information. We may extend by up to two further months for complex requests and will tell you if we do. Where you request access and we reasonably need clarification, the time limit pauses while we wait. There is no charge unless a request is manifestly unfounded or excessive.

If you are an End User of one of our customers, send your request to that customer.

9. Automated decisions

The Services apply the security requirements our customers define and produce an automated approval or rejection. The customer sets the criteria and is the controller of that decision.

Where such a decision is taken solely by automated means and has a legal or similarly significant effect on you, you have the right to be given information about it, to make representations, to obtain human intervention and to contest it. Contact the customer whose product you are using, or write to privacy@trustline.id.

10. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit and at rest, hardware-backed key management, multi-factor authentication, and logging and monitoring. No system is completely secure and we do not warrant that a breach will never occur.

Where a personal data breach is likely to result in a risk to your rights, we notify the Information Commissioner's Office within 72 hours. Where the risk is high, we also tell you.

11. Children

The Services are for business use. We do not permit anyone under 18 to use them and do not knowingly collect their data.

12. Cookies and other sites

Neither this website nor any Trustline application sets cookies, and none performs analytics or tracking. The one third-party component anywhere on the website is the scheduling calendar on the pricing page, which loads only if you open it. Our applications do keep a small amount on your device to sign you in and to remember settings you chose; our Cookie Policy lists every item, application by application.

The Site links to third-party sites we do not control. This policy does not apply to them.

13. Changes

We may update this policy. The current version is the one on this page, and the date at the top shows when it last changed. Where a change is material we will take reasonable steps to tell you.

14. Complaints

Tell us first at privacy@trustline.id so we can put it right. You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/, on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.