Last updated: replace with the date you publish this.
Who is responsible
CoinSentry Recovery Ltd is the controller of personal data described here. Contact us at cases@coinsentryrecovery.com for any privacy question, including a request to exercise your rights.
What we collect
When you submit a case
- Your name, email address, and if you give them, phone number and country
- Your description of what happened, including dates and amounts
- Wallet addresses, transaction hashes and platform details you supply
- Details of any report you have made to police or a fraud reporting body
- Documents you later upload to the client portal
When you use the site
- Addresses you check with the address tool, which are not linked to you
- A salted hash of your IP address for rate limiting. We do not retain the address itself; the hash exists to correlate repeated requests, not to identify a visitor
- Your email address if you subscribe to briefings or use the contact form
When you use live chat
This site uses a third-party live chat widget. If you open it, the provider processes the content of your messages, your IP address, browser and device information, the pages you viewed on this site, and any name or email you choose to give in the chat. The provider sets cookies on your device to keep a conversation continuous between page loads and visits.
The widget is not loaded on the client portal or the staff console. Those pages display case material, and we do not expose it to a third-party script.
Live chat is a convenience, not a secure channel. Do not send documents, financial details or anything sensitive through it. Use the client portal, where transfers are encrypted and access is scoped to your case.
What we do not collect
We do not use advertising or cross-site tracking cookies, and we do not sell, rent or share personal data with data brokers or marketers. We will never ask for a wallet seed phrase or private key, and you should never provide one to anyone.
Why we hold it, and on what basis
- To assess and carry out your matter. Performance of a contract, or steps taken at your request before entering one.
- To protect the service from abuse. Legitimate interests, covering rate limiting and bot mitigation.
- To maintain the address intelligence dataset. Legitimate interests in preventing fraud. Reports are published in a form that does not identify the reporter.
- To send briefings. Consent, withdrawable from any email.
- To operate live chat. Consent, given when you open the widget, and our legitimate interest in answering enquiries.
- To meet legal and regulatory obligations, including responding to lawful requests.
How it is protected
- Encrypted in transit and at rest
- Access controlled at the database level, so a client can only ever read their own case, and staff access is scoped by role
- Evidence files held in private storage, readable only through short-lived signed links issued after an access check
- Privileged actions recorded in an audit log
- Passwordless sign-in, so there is no password to reuse or leak
How long we keep it
- Case records: for the duration of the matter and afterwards for as long as needed for legal and regulatory purposes, typically six years.
- Evidence files: as above, and deleted earlier on request where no legal obligation requires retention.
- Enquiries that do not become cases: twelve months.
- Rate limiting records: cleared automatically after the window expires.
- Newsletter subscriptions: until you unsubscribe.
Who else sees it
Only where necessary, and only what is necessary: our hosting and database providers acting as processors under contract, our email delivery provider for transactional messages, our live chat provider for conversations you start in the widget, and, with your instruction, law enforcement or legal counsel acting for you.
We do not disclose client identity or case details publicly. Where findings inform the public address dataset, they are published as address-level intelligence without anything identifying the client.
Your rights
Subject to your jurisdiction, you may request access to your data, correction of inaccuracies, deletion, restriction of processing, portability, or object to processing based on legitimate interests. You may withdraw consent for briefings at any time. Contact cases@coinsentryrecovery.com and we will respond within one month. You may also complain to your local data protection authority.
International transfers
We work internationally, and our infrastructure providers may process data outside your country. Where that happens, transfers are made under appropriate safeguards.
This page is a template and is not legal advice. Have it reviewed by a qualified data protection lawyer, and confirm it reflects your actual processing and retention practices, before publishing.