SableAssent Coin Corporation | Version 1.0 | June 2026
Effective Date: June 1, 2026 | Last Updated: June 7, 2026
SableAssent Coin Corporation is the Data Controller responsible for the collection and processing of your personal data as described in this Privacy Policy.
Company: SableAssent Coin Corporation
Also operating as: SableAssent Treasury Reserve SPV LLC
Privacy Inquiries: privacy@sableassent.net
Compliance Officer: compliance@sableassent.net
General Contact: Admin@SableAssent.com
To exercise any data rights or submit a privacy inquiry, contact privacy@sableassent.net. We will respond within 30 days.
We collect the following categories of personal data:
Full legal name, date of birth, nationality, government-issued ID (passport, driver's license), proof of address, selfie/liveness photo, PEP/sanctions screening results.
Bank account details (for remittance), payment card type and last 4 digits (actual card data is processed by Stripe — PCI-DSS compliant), transaction amounts, wire transfer records, SAR/CTR filings.
Ethereum/blockchain wallet addresses, SAC1 token balances, on-chain transaction history, staking records, governance vote records. Note: blockchain data is inherently public and immutable.
IP address, device type, browser fingerprint, session tokens, login timestamps, pages visited, feature usage, API call logs.
Email address, support ticket contents, governance proposal submissions, notification preferences.
| Processing Activity | Legal Basis (GDPR Art. 6) | Notes |
|---|---|---|
| Account registration & authentication | Art. 6(1)(b) — Contract performance | Necessary to provide the platform service |
| KYC identity verification | Art. 6(1)(c) — Legal obligation | FinCEN BSA, AML/CFT, Reg D requirements |
| AML transaction monitoring | Art. 6(1)(c) — Legal obligation | FATF R.10, 31 CFR 1022.320 |
| SAR / CTR filing | Art. 6(1)(c) — Legal obligation | FinCEN mandatory reporting |
| SAC1 token governance operations | Art. 6(1)(b) — Contract performance | Membership agreement execution |
| Remittance services | Art. 6(1)(c) — Legal obligation | FinCEN MSB license obligations |
| Marketing communications | Art. 6(1)(a) — Consent | Withdrawal available at any time |
| Platform security & fraud prevention | Art. 6(1)(f) — Legitimate interest | Protecting users and the platform |
| Legal claims defense | Art. 6(1)(f) — Legitimate interest | Retention during dispute periods |
SableAssent retains personal data for the minimum period required by applicable law. The following schedule reflects FATF R.11, FinCEN 31 CFR 1022.320, GDPR Art. 5(1)(e), and internal policy SAC-DRDP-2026-001:
| Data Category | Retention Period | Legal Reference |
|---|---|---|
| KYC identity documents (passport, ID, selfie) | 5 years after relationship ends | FATF R.11, FinCEN BSA |
| AML transaction records | 5 years minimum from transaction date | FATF R.11, 31 CFR 1022.320 |
| SAR / CTR filings | 5 years from filing date | 31 CFR 1022.320(d) |
| Financial transaction history | 5–10 years (jurisdiction-dependent) | IRS, FinCEN, state law |
| SAC1 governance membership records | Duration of membership + 5 years | Reg D, corporate records law |
| Marketing / consent records | Until consent withdrawn + 3 years | GDPR Art. 7(1), CCPA |
| Technical logs (IP address, session data) | 12 months | GDPR data minimization principle |
| Payment card data | Not stored — processed by Stripe (PCI-DSS) | PCI-DSS compliance |
| Social login data (Google OAuth) | Until account deletion request | GDPR Art. 17 (Right to Erasure) |
After retention periods expire, data is securely deleted or anonymized in accordance with NIST SP 800-88 guidelines. Requests for early deletion are subject to legal hold obligations.
We share personal data only with processors necessary to deliver our services. All third-party processors are bound by Data Processing Agreements (DPAs) and are prohibited from using your data for their own purposes.
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing (PCI-DSS) | Payment card data, billing address | USA / Global |
| PayPal | Alternative payment processing | Name, email, transaction amount | USA / Global |
| Persona | KYC identity verification | Government ID, selfie, DOB | USA |
| Sumsub | KYC/AML document verification | Identity documents, address proof | UK / EU |
| AMLBot | Blockchain AML screening | Wallet addresses, transaction hashes | EU |
| Chainalysis | Blockchain transaction monitoring | Wallet addresses, on-chain data | USA |
| AWS | Cloud infrastructure & data storage | All platform data (encrypted) | USA (us-east-1) |
| Google Cloud | Secondary cloud & AI services | Operational data (encrypted) | USA |
| Alchemy | Blockchain node infrastructure | Wallet queries, transaction broadcasts | USA |
| TRISA Envoy | Travel Rule compliance (VASP) | Counterparty KYC data | Global |
| MailerLite | Email marketing (opt-in only) | Email address, name, preferences | EU |
We do not sell, rent, or trade personal data to third parties for marketing purposes. Government/law enforcement disclosures are made only when legally required and where legally permissible, we will notify you.
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. We ensure adequate safeguards are in place:
Depending on your jurisdiction, you have the following rights. To exercise any right, contact privacy@sableassent.net. We will respond within 30 days (GDPR) or 45 days (CCPA).
| Right | GDPR Article | CCPA Equivalent | Notes |
|---|---|---|---|
| Right to Access | Art. 15 | § 1798.110 | Copy of your data + processing information |
| Right to Rectification | Art. 16 | § 1798.106 | Correct inaccurate personal data |
| Right to Erasure ("Right to be Forgotten") | Art. 17 | § 1798.105 | Subject to legal hold obligations |
| Right to Restrict Processing | Art. 18 | N/A | Pause processing while dispute is resolved |
| Right to Data Portability | Art. 20 | § 1798.100 | Machine-readable format (JSON/CSV) |
| Right to Object | Art. 21 | N/A | Particularly for direct marketing |
| Right to Opt-Out of Sale | N/A | § 1798.120 | We do not sell data — this is a confirmation |
| Right to Non-Discrimination | N/A | § 1798.125 | No service penalty for exercising rights |
| Right to Lodge a Complaint | Art. 77 | N/A | Contact your national supervisory authority |
Note: certain rights may be limited where we have overriding legal obligations (e.g., AML/KYC retention requirements under FinCEN regulations).
SableAssent employs enterprise-grade security measures in accordance with internal policy OPSEC-POL-2026-001, SAC-PACP-2026-001, and SAC-SIRP-2026-001:
AES-256 encryption for all stored data across AWS and Google Cloud
TLS 1.3 enforced on all data transmissions — no TLS 1.0/1.1
Dual-cloud KMS (AWS KMS + Google Cloud KMS), FIPS 140-2 Level 3 HSMs
MFA enforced for all admin and privileged accounts
Role-segregated access (RBAC), 2-of-3 super_admin approval for vault access
90-day cryptographic key rotation policy
24/7 anomaly detection, SIEM logging, real-time alerting
72-hour notification to regulators; customer notification without undue delay (GDPR Art. 33/34, DORA 4-hour ICT incident report)
Payment card data processed exclusively by Stripe (Level 1 PCI-DSS certified)
Annual third-party penetration tests; smart contract audit before mainnet
If you have a complaint about how we handle your personal data, please contact us first at privacy@sableassent.net. We aim to resolve all complaints within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority:
EU/EEA residents: Your national supervisory authority (e.g., CNIL in France, BfDI in Germany, DPC in Ireland)
UK residents: Information Commissioner's Office (ICO) — ico.org.uk
California residents: California Privacy Protection Agency (CPPA) — cppa.ca.gov
© 2026 SableAssent Coin Corporation | SableAssent Treasury Reserve SPV LLC
privacy@sableassent.net | compliance@sableassent.net