Privacy · Records of Processing Activities

What we process, and why

A public summary of Infinihash's Records of Processing Activities (RoPA), in the spirit of GDPR Article 30. One row per activity: what data, why we touch it, what lets us, how long we keep it, and who else sees it.

Last reviewed: September 2026 · Maintained by Infinihash Security & Compliance · Closes GDPR gap #2 tracked on /trust.

Summary register

Subprocessor names link to the full list and regions on the Trust Center rather than duplicating it here.

Activity Data categories Purpose Legal basis Retention Subprocessors
KYC identity verification Identity documents, biometric/selfie images, extracted PII (name, DOB, document number, address) Verify tenant end-customers to satisfy BSA/AML obligations Legal obligation / Contract ~7 years for BSA-eligible records (see /privacy) AWS, Google (Gemini — document extraction). Not Anthropic: Claude is used only for AML narrative text and never receives document images.
KYT wallet screening Wallet addresses, transaction hashes, chain identifiers, risk-decision metadata (pseudonymous on-chain data, not directly identifying on its own) Sanctions screening and transaction monitoring for regulated counterparties Legal obligation / Contract ~5 years for audit trails, then anonymized (see /trust) AWS, Cloudflare
Account & signup data Email, name, organization, role, password hash, login IP Provision and operate Infinihash accounts across products Contract Deleted within 30 days of account closure, except legal hold AWS, Resend
Rails / BaaS tenant onboarding (KYB) Business identifiers (legal name, entity type, tax identification number, incorporation and operating addresses, description, website); beneficial-owner and control-person personal data (name, date of birth, residential address, personal tax identification number, government-ID images); source-of-funds answers Verify the business and its owners before it can transact, as required by the regulated payments partner and by BSA/AML rules Legal obligation / Contract Owner personal data and ID images are not retained by Infinihash — they stream through to the partner. Business-level identifiers and status are retained on the application record. Bridge (regulated payments partner), Persona (Bridge's identity-verification vendor), AWS
Rails / BaaS settlement Invoice and payer details, ACH collection instructions, destination wallet address and chain, amounts, screening and decision metadata Collect a USD invoice and settle it as stablecoin to the tenant's own wallet, with sanctions screening of the destination wallet before any conversion Contract / Legal obligation Retained with financial and AML records; screening results follow the KYT retention above Bridge, AWS, Cloudflare
Website analytics Visitor IP address, cookie identifiers, pages viewed, referrer Understand how visitors use the marketing site Consent Per Google Analytics retention settings; not linked to product accounts Google (Analytics, Fonts), Cloudflare
Billing Stripe customer ID, last-4 card digits, invoice and subscription history Charge for and administer paid subscriptions Contract Per Stripe's own retention as payment processor; invoice records kept for financial recordkeeping Stripe
Support correspondence Email content, account identifiers referenced in a ticket, attachments the requester chooses to send Respond to support and account requests Contract / Legitimate interest Retained for the life of the support relationship, then trimmed with other operational data Resend
Security logging IP addresses, request paths, response codes, auth events, error traces Detect abuse, fraud, and security incidents; operational health Legitimate interest 90 days, then aggregated (see /privacy) AWS, Cloudflare
This table is a public-facing summary, not the full internal RoPA. It intentionally omits sub-activity detail, named data flows between internal systems, and processor-level technical controls. The complete internal Records of Processing Activities is maintained continuously and is made available to Data Protection Authorities on request, and to enterprise customers under an executed confidentiality agreement. Note that Infinihash does not yet have a Data Processing Agreement available for signature — a template is drafted and under counsel review, and /trust says so plainly rather than implying one exists.

Questions or a formal request

Compliance & Privacy
Full RoPA access under confidentiality, vendor questionnaires, DPIAs. No DPA is executable yet — see /trust.
Exercise a data subject right
Access, correction, deletion, portability, objection.