# Privacy Policy | CRBN.CREDIT

**URL:** https://crbn.credit/privacy  
**Last Updated:** January 1, 2026  
**Standard:** GDPR-aligned | SOC 2 Type II Compliant

---

## Principle

CRBN.CREDIT treats privacy as a core infrastructure principle, not a compliance checkbox.

---

## 1. Data Collection (Minimal)

| Data Type | Purpose |
|---|---|
| Account Info (institutional email, entity details) | KYC/AML compliance |
| Usage Data (API call logs, dashboard interactions) | Security and platform optimization |
| Portfolio Data (uploaded holdings, wallet-synced assets) | Encrypted at rest, user-controlled |

---

## 2. Data Security

| Measure | Standard |
|---|---|
| Overall Security Certification | SOC 2 Type II |
| Encryption in Transit | TLS 1.3 (end-to-end) |
| Multi-Factor Authentication | MFA enforced for all enterprise accounts |
| Cryptographic Key Storage | Cold storage |

---

## 3. Third-Party Data Sharing

CRBN.CREDIT does **not** sell user data.

Data is shared only in two circumstances:

- **Registry Partners:** Only when the user explicitly initiates a retirement or transfer transaction
- **Regulatory Bodies:** Only when compelled by law (e.g., EU ETS compliance checks, law enforcement orders)

---

## 4. Contact

For privacy questions or data requests:  
**Email:** contact@crbn.credit

---

*Disclaimer: This content is generated with AI assistance. Verify with qualified legal counsel for compliance purposes.*
