← Back to Home

Privacy Policy

SableAssent Coin Corporation | Version 1.0 | June 2026

Effective Date: June 1, 2026 | Last Updated: June 7, 2026

Section 1 — Data Controller & Contact Information

SableAssent Coin Corporation is the Data Controller responsible for the collection and processing of your personal data as described in this Privacy Policy.

Company: SableAssent Coin Corporation

Also operating as: SableAssent Treasury Reserve SPV LLC

Privacy Inquiries: privacy@sableassent.net

Compliance Officer: compliance@sableassent.net

General Contact: Admin@SableAssent.com

To exercise any data rights or submit a privacy inquiry, contact privacy@sableassent.net. We will respond within 30 days.

Section 2 — Personal Data We Collect

We collect the following categories of personal data:

KYC / Identity Data

Full legal name, date of birth, nationality, government-issued ID (passport, driver's license), proof of address, selfie/liveness photo, PEP/sanctions screening results.

Financial Data

Bank account details (for remittance), payment card type and last 4 digits (actual card data is processed by Stripe — PCI-DSS compliant), transaction amounts, wire transfer records, SAR/CTR filings.

Blockchain & Wallet Data

Ethereum/blockchain wallet addresses, SAC1 token balances, on-chain transaction history, staking records, governance vote records. Note: blockchain data is inherently public and immutable.

Technical & Usage Data

IP address, device type, browser fingerprint, session tokens, login timestamps, pages visited, feature usage, API call logs.

Communication Data

Email address, support ticket contents, governance proposal submissions, notification preferences.

Section 4 — Data Retention Schedule

SableAssent retains personal data for the minimum period required by applicable law. The following schedule reflects FATF R.11, FinCEN 31 CFR 1022.320, GDPR Art. 5(1)(e), and internal policy SAC-DRDP-2026-001:

Data CategoryRetention PeriodLegal Reference
KYC identity documents (passport, ID, selfie)5 years after relationship endsFATF R.11, FinCEN BSA
AML transaction records5 years minimum from transaction dateFATF R.11, 31 CFR 1022.320
SAR / CTR filings5 years from filing date31 CFR 1022.320(d)
Financial transaction history5–10 years (jurisdiction-dependent)IRS, FinCEN, state law
SAC1 governance membership recordsDuration of membership + 5 yearsReg D, corporate records law
Marketing / consent recordsUntil consent withdrawn + 3 yearsGDPR Art. 7(1), CCPA
Technical logs (IP address, session data)12 monthsGDPR data minimization principle
Payment card dataNot stored — processed by Stripe (PCI-DSS)PCI-DSS compliance
Social login data (Google OAuth)Until account deletion requestGDPR Art. 17 (Right to Erasure)

After retention periods expire, data is securely deleted or anonymized in accordance with NIST SP 800-88 guidelines. Requests for early deletion are subject to legal hold obligations.

Section 5 — Third-Party Data Processors & Sharing

We share personal data only with processors necessary to deliver our services. All third-party processors are bound by Data Processing Agreements (DPAs) and are prohibited from using your data for their own purposes.

ProcessorPurposeData SharedLocation
StripePayment processing (PCI-DSS)Payment card data, billing addressUSA / Global
PayPalAlternative payment processingName, email, transaction amountUSA / Global
PersonaKYC identity verificationGovernment ID, selfie, DOBUSA
SumsubKYC/AML document verificationIdentity documents, address proofUK / EU
AMLBotBlockchain AML screeningWallet addresses, transaction hashesEU
ChainalysisBlockchain transaction monitoringWallet addresses, on-chain dataUSA
AWSCloud infrastructure & data storageAll platform data (encrypted)USA (us-east-1)
Google CloudSecondary cloud & AI servicesOperational data (encrypted)USA
AlchemyBlockchain node infrastructureWallet queries, transaction broadcastsUSA
TRISA EnvoyTravel Rule compliance (VASP)Counterparty KYC dataGlobal
MailerLiteEmail marketing (opt-in only)Email address, name, preferencesEU

We do not sell, rent, or trade personal data to third parties for marketing purposes. Government/law enforcement disclosures are made only when legally required and where legally permissible, we will notify you.

Section 6 — International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. We ensure adequate safeguards are in place:

Standard Contractual Clauses (SCCs): All transfers to AWS and Google Cloud are governed by the EU Standard Contractual Clauses (2021/914) approved by the European Commission. Copies are available upon request.
Adequacy Decisions: Where transfers are to countries with an EU adequacy decision, no additional safeguards are required.
Blockchain Data: Blockchain transaction data (wallet addresses, on-chain records) is inherently global and public by nature of the underlying technology. Submitting transactions to a blockchain constitutes a voluntary public disclosure.

Section 7 — Your Data Rights

Depending on your jurisdiction, you have the following rights. To exercise any right, contact privacy@sableassent.net. We will respond within 30 days (GDPR) or 45 days (CCPA).

RightGDPR ArticleCCPA EquivalentNotes
Right to AccessArt. 15§ 1798.110Copy of your data + processing information
Right to RectificationArt. 16§ 1798.106Correct inaccurate personal data
Right to Erasure ("Right to be Forgotten")Art. 17§ 1798.105Subject to legal hold obligations
Right to Restrict ProcessingArt. 18N/APause processing while dispute is resolved
Right to Data PortabilityArt. 20§ 1798.100Machine-readable format (JSON/CSV)
Right to ObjectArt. 21N/AParticularly for direct marketing
Right to Opt-Out of SaleN/A§ 1798.120We do not sell data — this is a confirmation
Right to Non-DiscriminationN/A§ 1798.125No service penalty for exercising rights
Right to Lodge a ComplaintArt. 77N/AContact your national supervisory authority

Note: certain rights may be limited where we have overriding legal obligations (e.g., AML/KYC retention requirements under FinCEN regulations).

Section 8 — Security Measures

SableAssent employs enterprise-grade security measures in accordance with internal policy OPSEC-POL-2026-001, SAC-PACP-2026-001, and SAC-SIRP-2026-001:

Encryption at Rest

AES-256 encryption for all stored data across AWS and Google Cloud

Encryption in Transit

TLS 1.3 enforced on all data transmissions — no TLS 1.0/1.1

Key Management

Dual-cloud KMS (AWS KMS + Google Cloud KMS), FIPS 140-2 Level 3 HSMs

Multi-Factor Authentication (MFA)

MFA enforced for all admin and privileged accounts

Access Controls

Role-segregated access (RBAC), 2-of-3 super_admin approval for vault access

Key Rotation

90-day cryptographic key rotation policy

Monitoring

24/7 anomaly detection, SIEM logging, real-time alerting

Breach Notification

72-hour notification to regulators; customer notification without undue delay (GDPR Art. 33/34, DORA 4-hour ICT incident report)

PCI-DSS Compliance

Payment card data processed exclusively by Stripe (Level 1 PCI-DSS certified)

Penetration Testing

Annual third-party penetration tests; smart contract audit before mainnet

Section 9 — Cookies & Tracking

We use cookies and similar tracking technologies to operate the platform. For full details of which cookies we use and how to manage your preferences, please see our Cookie Policy.

You can update your cookie preferences at any time using the Cookie Preferences link in our website footer.

Section 10 — Complaints & Data Protection Authority

If you have a complaint about how we handle your personal data, please contact us first at privacy@sableassent.net. We aim to resolve all complaints within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority:

EU/EEA residents: Your national supervisory authority (e.g., CNIL in France, BfDI in Germany, DPC in Ireland)

UK residents: Information Commissioner's Office (ICO) — ico.org.uk

California residents: California Privacy Protection Agency (CPPA) — cppa.ca.gov

© 2026 SableAssent Coin Corporation | SableAssent Treasury Reserve SPV LLC

privacy@sableassent.net | compliance@sableassent.net

Chat
Ava
● Online
Powered by Avatara