If you want to access, correct, delete, restrict, port, or object to the processing of your personal data, this page explains exactly how Infinihash handles that request — including the one honest limit: regulatory retention obligations can override erasure.
Infinihash plays two different roles depending on whose data is involved. Which one applies changes who actually handles your request.
For your own signup and account data (email, org, billing contact, login history), Infinihash is the controller. We handle your request directly.
If you submitted KYC documents or were screened because you're a customer of one of our tenants (an exchange, fund, or OTC desk running on Infinihash), Infinihash is the processor. Your tenant is the controller and the legal decision-maker on your request; we assist them.
The same intake handles both roles above — we route internally once we know which one applies.
Email [email protected] (compliance and privacy) or [email protected] (if it also involves a security or account-access concern). Tell us which right you're exercising and, if known, which Infinihash-powered product you interacted with.
Before we disclose, correct, or delete anything, we confirm you are who you say you are — typically by matching the request to the account or verification record on file, or asking for a government ID that matches the record in question. We will not act on a request we can't verify; this protects the subject as much as it protects us.
If the data belongs to one of our tenants' end customers, we route the request to that tenant as controller and commit to assisting them in fulfilling it (data export, deletion execution, etc.) under our processing agreement. If it's your own Infinihash account data, we act on it ourselves.
Per GDPR Article 12(3), we aim to respond within one month of a verified request. Complex requests can extend this by up to two further months — if that happens, we'll tell you within the first 30 days and explain why.
These map to GDPR Articles 15–21 and the equivalent CCPA/CPRA consumer rights.
A copy of the personal data we (or, for tenant end-customers, our tenant) hold about you.
Correction of inaccurate or incomplete identity or account data.
Deletion of your data — subject to the retention carve-out below.
Pausing active processing while a dispute or accuracy challenge is resolved.
Your data in a structured, machine-readable format, where technically feasible.
Objecting to processing based on legitimate interest, including profiling used for risk scoring.
Infinihash operates BSA/AML compliance infrastructure. Some of the records we hold exist because the law requires them to survive a deletion request.