Legal
Privacy Policy
This policy explains what personal data Sarrafe processes within this service and why.
Data we process
- The email address associated with your Sarrafe account.
- Your account record and the figures relating to your case.
- Any receiving wallet address you submit, together with the selected network.
- Technical and security data, including the IP address used during verification and submission, and timestamps of your activity.
How we use it
Data is processed to verify your identity, present your case, review and process your request, prevent fraud and abuse, and satisfy our internal record-keeping obligations.
Security
Verification codes and session tokens are stored only as irreversible hashes. Sessions are short-lived and can be ended at any time. Access to client records is restricted to authorised Sarrafe personnel, and all administrative actions are recorded in an append-only audit log.
Sharing
We do not sell personal data. Data is shared only with service providers necessary to operate this service, such as our email delivery provider, and with authorities where we are legally required to do so.
Retention
Case records, requests and audit entries are retained for as long as required for financial record-keeping and legal compliance. Verification codes are retained only briefly and expire automatically.
Your rights
You may request access to the personal data we hold about you, or ask us to correct inaccurate data, by contacting Sarrafe support from your verified email address. Some data cannot be deleted while it forms part of a required financial record.