Privacy Policy
Last updated: April 2026
1. Data Controller
Crivacy ("we", "us", or "our") is the data controller responsible for the processing of your personal data. We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK, Law No. 6698), and other applicable data protection legislation.
For questions about this policy or to exercise your rights, contact our Data Protection Officer at privacy@crivacy.io.
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, display name, phone number, and password hash.
- Identity verification data: full legal name, date of birth, nationality, document type, document country, and identity document images (processed by Didit).
- Address verification data: street address, city, and country (from Didit phase 2 verification).
- Technical data: IP address, user agent, device information, session data, and browser cookies.
- Usage data: pages visited, features used, timestamps of interactions, and KYC verification status.
- Blockchain data: KYC credential records stored on Sepolia distributed ledger.
3. How We Use Your Data
We process your personal data for the following purposes:
- To create and manage your account.
- To perform identity and address verification through our KYC process.
- To issue and manage on-chain KYC credentials.
- To communicate with you regarding your account and verification status.
- To provide customer support via our ticketing system.
- To detect, prevent, and address fraud, abuse, and security incidents.
- To comply with legal obligations, including AML/CTF regulations.
- To improve and optimize the Service.
4. Legal Basis for Processing
We process your personal data under the following legal bases as defined by GDPR Article 6 and KVKK Article 5:
- Contract performance: Processing necessary to provide the Service you requested (account management, KYC verification, credential issuance).
- Legal obligation: Processing required to comply with AML/CTF regulations, tax laws, and other legal requirements.
- Legitimate interest: Processing for fraud prevention, security, and service improvement, where our interests do not override your fundamental rights.
- Consent: Where explicitly required, such as for certain marketing communications. You may withdraw consent at any time.
5. Data Retention
We retain your personal data according to the following schedule:
- Account data: Retained for the duration of your account plus 30 days after deletion request, unless extended retention is required by law.
- KYC verification data: Retained for a minimum of 5 years after the last verification, as required by AML/CTF regulations.
- Audit logs: Retained for 7 years to comply with regulatory requirements.
- Technical logs: Retained for 90 days for security and debugging purposes.
- Blockchain records: On-chain records are immutable and cannot be deleted. Credentials may be revoked but the record of issuance persists.
6. Your Rights (GDPR/KVKK)
Under GDPR and KVKK, you have the following rights regarding your personal data:
- Right of access: Request a copy of all personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to restriction: Request that we limit the processing of your data in certain circumstances.
- Right to data portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: You may file a complaint with the relevant supervisory authority (KVKK Board in Turkey, or your local EU/EEA data protection authority).
To exercise any of these rights, contact us at privacy@crivacy.io. We will respond within 30 days as required by GDPR, or within 30 days as required by KVKK.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including Turkey and countries within the European Economic Area (EEA). We ensure that such transfers are carried out with appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the relevant data protection authority.
- Explicit consent where required and no other safeguard mechanism is available.
8. Cookies
We use only essential cookies that are strictly necessary for the operation of the Service:
- Session cookies: Used to maintain your authenticated session and keep you signed in. These are HTTP-only, secure cookies that expire when your session ends or after the configured timeout period.
- CSRF protection cookies: Used to prevent cross-site request forgery attacks.
We do not use analytics, advertising, or tracking cookies. No third-party cookies are set by the Service.
9. Third-Party Services
We share personal data with the following third-party processors:
- Didit: Our identity verification provider. Didit processes your identity documents and biometric data to perform KYC verification. Didit acts as a data processor under a Data Processing Agreement (DPA) with Crivacy. For more information, see Didit's Privacy Policy.
- Ethereum (Sepolia): KYC credential records are stored on Sepolia distributed ledger. The Sepolia network stores credential data (sensitive fields encrypted via FHE) (verification level, issuance date, credential ID) but does not process raw identity documents or biometric data.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256).
- Passwords stored using Argon2id hashing with per-user salts and appropriate memory/time parameters.
- Role-based access control (RBAC) for internal administrative access.
- Comprehensive audit logging of all data access and modifications.
- Regular security assessments and vulnerability scanning.
- Brute-force protection with account lockout and IP-based rate limiting.
11. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes by posting a notice on our website or sending an email to your registered email address. Your continued use of the Service after the effective date of the updated policy constitutes acceptance of the changes.
12. Contact
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a data protection concern, please contact us:
- Data Protection Officer: privacy@crivacy.io
- General inquiries: info@crivacy.io
- Website: https://crivacy.io