Privacy · Data Subject Requests

Exercise your privacy rights

If you want to access, correct, delete, restrict, port, or object to the processing of your personal data, this page explains exactly how Infinihash handles that request — including the one honest limit: regulatory retention obligations can override erasure.

Last reviewed: September 2026 · Maintained by Infinihash Security & Compliance · Closes GDPR gap #1 tracked on /trust.

Two kinds of data subject

Infinihash plays two different roles depending on whose data is involved. Which one applies changes who actually handles your request.

You have an Infinihash account

For your own signup and account data (email, org, billing contact, login history), Infinihash is the controller. We handle your request directly.

You were verified through a tenant's product

If you submitted KYC documents or were screened because you're a customer of one of our tenants (an exchange, fund, or OTC desk running on Infinihash), Infinihash is the processor. Your tenant is the controller and the legal decision-maker on your request; we assist them.

How a request is handled

The same intake handles both roles above — we route internally once we know which one applies.

1

Submit the request

Email [email protected] (compliance and privacy) or [email protected] (if it also involves a security or account-access concern). Tell us which right you're exercising and, if known, which Infinihash-powered product you interacted with.

2

We verify your identity

Before we disclose, correct, or delete anything, we confirm you are who you say you are — typically by matching the request to the account or verification record on file, or asking for a government ID that matches the record in question. We will not act on a request we can't verify; this protects the subject as much as it protects us.

3

We determine controller vs. processor

If the data belongs to one of our tenants' end customers, we route the request to that tenant as controller and commit to assisting them in fulfilling it (data export, deletion execution, etc.) under our processing agreement. If it's your own Infinihash account data, we act on it ourselves.

4

We respond within 30 days

Per GDPR Article 12(3), we aim to respond within one month of a verified request. Complex requests can extend this by up to two further months — if that happens, we'll tell you within the first 30 days and explain why.

What you can ask for

These map to GDPR Articles 15–21 and the equivalent CCPA/CPRA consumer rights.

Access

A copy of the personal data we (or, for tenant end-customers, our tenant) hold about you.

Rectification

Correction of inaccurate or incomplete identity or account data.

Erasure

Deletion of your data — subject to the retention carve-out below.

Restriction

Pausing active processing while a dispute or accuracy challenge is resolved.

Portability

Your data in a structured, machine-readable format, where technically feasible.

Objection

Objecting to processing based on legitimate interest, including profiling used for risk scoring.

Erasure vs. regulatory retention

Infinihash operates BSA/AML compliance infrastructure. Some of the records we hold exist because the law requires them to survive a deletion request.

If a record is under active regulatory retention, we will refuse the erasure request and tell you why — not silently ignore it or pretend to comply. Per our published retention posture (/trust, /privacy): KYC identity documents are generally retained around 7 years for BSA-eligible records, and KYT screening results around 5 years for audit trails before anonymization. GDPR Article 17(3)(b) and equivalent CCPA exemptions permit this: the right to erasure does not override a legal obligation to retain records. Where a record falls outside active retention (e.g. general account data, marketing preferences, logs past their TTL), we delete it on request within the response window above.

Where to send a request

Compliance & Privacy / DSR intake
Primary channel for access, correction, deletion, portability, and objection requests.
Security & Incident Response
If the request involves account compromise or a security concern alongside the privacy request.