Privacy Policy
Last updated: 2 September 2026
1. Controller
The controller for personal data described in this policy is KYTGate Ltd [registered office to be stated upon incorporation]. Contact: hello@kytgate.com. For data our customers submit through the API (section 4), the customer is the controller and we act as processor on its documented instructions.
2. What we deliberately do not collect
This website sets no cookies, runs no analytics or advertising trackers, embeds no social-media pixels, and uses no browser fingerprinting. There is no account signup on the website. We believe a compliance company should be able to say this plainly, so: if you only read our pages, we process no personal data about you beyond the standard server logs kept by our hosting provider for security and operations.
3. Free tool queries
When you use the free wallet sanctions check, the address you enter is processed transiently to produce the result and is not stored — we keep no log of which addresses were queried. To enforce fair rate limits, we store an hourly counter keyed to a truncated cryptographic hash of your IP address; the IP itself is not stored and the counter identifies no one. Legal basis: our legitimate interest in operating and protecting a free service (GDPR art. 6(1)(f)).
4. Customer screening data (we act as processor)
Early-access customers submit wallet addresses, transaction identifiers and related funding metadata to the API. Blockchain identifiers can constitute personal data where they relate to an identifiable person; for this data the customer is the controller — it determines why an address is screened — and KYTGate processes it solely to deliver the screening, decisioning and record-keeping the customer configured. Processor-supplied screening results are held strictly per-tenant and are never shared across customers, aggregated into common intelligence, or sold. A data processing addendum reflecting GDPR art. 28 is available on request.
Screening records, case events and decision receipts are retained append-only for the retention period configured per tenant (default seven years, reflecting typical financial-sector record-keeping obligations), then deleted unless law requires otherwise.
5. Contact and business correspondence
If you email us, we process your name, email address and message content to respond and to maintain our business relationship (art. 6(1)(b) and (f)). We keep correspondence as long as relevant to the relationship and applicable limitation periods.
6. Subprocessors and recipients
We use a small number of infrastructure providers to run the Service: Vercel Inc. (application hosting and server logs) and Neon Inc. (managed Postgres database), each under data processing terms. Screening necessarily sends the queried blockchain identifier to public blockchain RPC endpoints and compares it against published sanctions data; these queries contain the identifier being screened and nothing about you. We disclose personal data to authorities only where legally required, and will notify the affected customer where lawful.
7. International transfers
Our infrastructure providers may process data in the United States and the EEA. Where personal data subject to the GDPR is transferred to a third country, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses as implemented in our providers' data processing terms.
8. Your rights
Where the GDPR or similar law applies to you, you have the rights of access, rectification, erasure, restriction, portability and objection, and — where processing is based on consent — withdrawal at any time. Write to hello@kytgate.com; we respond within one month. Two honest caveats: requests concerning data a customer submitted should be addressed to that customer as controller (we will assist them), and records retained under financial record-keeping obligations may be exempt from erasure (art. 17(3)(b)). You may lodge a complaint with your supervisory authority.
9. Security
All traffic is encrypted in transit. API keys are stored only as cryptographic hashes. Screening records are append-only, and decision receipts are digitally signed so that subsequent alteration is detectable by anyone holding our published verification key. Access to production systems is restricted and credentialed.
10. Changes
We will update this policy as the Service evolves — for example, when payment processing or account signup is introduced — and material changes will be flagged on this page with a new date. We will not weaken the commitments in section 2 silently.