# Privacy Notice

> How personal data is processed, stored encrypted, deleted and protected from sharing across the Legichain website, platform and services, and the rights of data subjects.

Canonical URL: https://legichain.com/en/legal/privacy
Language: en
Other language: https://legichain.com/legal/privacy

This Privacy Notice explains how personal data is processed in connection with the Legichain website (legichain.com), the Legichain platform (panel.legichain.com and the API) and your communication with us: what we process, with whom it is or is not shared, how long it is kept and how you can exercise your rights. Last updated: 9 September 2026.

## 1. Scope and definitions

This notice applies to three groups:

- **Visitors:** people who visit our website and contact us through the contact form, email or a call request.
- **Platform Users:** authorised employees and representatives of our Customers who hold an account on the Legichain platform.
- **End Users:** people whose data our Customers submit to the platform when using identity verification, AML screening or blockchain screening services.

**Customer** means the institution that has a service agreement with Legichain. **Service Data** means all data that Customers submit to the platform about End Users, together with the check results, match records and review notes produced from that data.

In this notice, “Legichain”, “we” and “us” refer to Legichain as the service provider. Address and tax details are stated in customer agreements and are provided on request via contact@legichain.com.

## 2. Controller and processor roles

For Visitor and Platform User data, Legichain is the **data controller**.

For Service Data, the data controller is the Customer. Legichain processes Service Data only as a **data processor**, on the Customer's documented instructions and for the purposes defined in the service agreement. Legichain does not use Service Data for its own purposes, does not evaluate it to market its own products and does not disclose it to anyone other than the Customer.

End Users should direct questions about their data and requests to exercise their rights to the institution that provided them the service (the Customer). End User requests that reach Legichain are forwarded to the relevant Customer and resolved on the Customer's instructions.

## 3. Visitor and contact data

The following data is processed in connection with the website and contact processes:

- **Server access logs:** IP address, request time, requested address, browser and operating system information. Purpose: service security, abuse prevention and error detection. Legal basis: legitimate interest. Retention: limited to the period necessary for technical security; deleted on a regular cycle unless a security incident requires investigation.
- **Contact requests:** full name, work email, company, topic and your message. The contact form sends the message to contact@legichain.com through your own email application; the website itself does not store this information. Purpose: responding to your request and running the demo and evaluation process. Legal basis: steps prior to entering into a contract, and legitimate interest. Retention: until the request is resolved and for as long as necessary for a potential business relationship.
- **Preferences:** your theme preference (light/dark) is kept only in your browser's local storage and is not transmitted to us.

The website uses no advertising, analytics or tracking cookies and contains no third-party tracking code. Fonts are loaded from the Fontshare and Google Fonts content delivery networks; your IP address and browser information are transmitted to the relevant provider during those requests. The system status page retrieves live status from Legichain's own API (api.legichain.com).

## 4. Platform User data

The following data is processed in connection with platform accounts:

- **Account details:** full name, work email, company, role and permission level, authentication credentials. Purpose: account creation, authorisation and account security. Legal basis: performance of a contract.
- **Usage and security records:** login records, API key usage, types and times of checks run, error logs. Purpose: providing the service, security, abuse detection, billing and support. Legal basis: performance of a contract and legitimate interest.
- **Commercial details:** plan, credit usage, invoicing and payment records. Legal basis: performance of a contract and legal obligation (commercial and tax law).

Retention: for the life of the account and, after the agreement ends, for the period necessary for legal obligations and potential disputes.

## 5. Service Data: identity verification, AML and blockchain screening

Our Customers may submit identity document images and chip data, face images and liveness-check data for identity verification; full name, date of birth, country and entity details for AML screening; and wallet addresses and transaction references for blockchain screening. Check results, match records and review notes are produced from this data.

Face data processed during identity verification may be biometric in nature. The Customer is responsible for establishing the legal basis required for processing such special-category data (for example explicit consent or a statutory obligation) and for informing the End User; Legichain processes this data solely to perform the requested check. The website and platform are not directed at children; where Service Data about a child is submitted, the Customer is responsible for establishing the necessary legal basis.

Service Data is processed solely to perform the check the Customer requests, to return the result to the Customer and to keep the record for the period defined in the Customer's agreement. **All data submitted to the identity verification, AML and blockchain screening services is encrypted in transit and at rest; it is not disclosed to any third party other than the Customer, is not sold and is not used for any other purpose.**

**The retention period** is determined by the Customer's plan and agreement (7 days on the Free plan, up to 10 years on other plans; see [Pricing](https://legichain.com/en/pricing)). When the period expires, Service Data and the records produced from it are deleted from active systems; backup copies are destroyed within the regular backup cycle. The Customer may request earlier deletion within the framework defined in its agreement.

Statutory retention obligations that apply to the Customer (for example retention periods under Turkish Law No. 5549) are the Customer's responsibility; the Customer selects a retention period consistent with those obligations. Legichain's deletion of expired data does not remove the Customer's obligations regarding its own records.

## 6. Anonymised and statistical data

Data about the use of the platform may be processed for service improvement, capacity planning, security analysis and statistics only in **anonymised and aggregated** form (for example numbers of checks, response times, error rates) that cannot be linked to an identified or identifiable person.

Anonymised data is not personal data; no operation is performed to re-identify a person from it. Raw Service Data (document images, biometric data, person and entity details, wallet addresses and screening results) is not used for product development or model training; only aggregated, anonymous measurements are processed.

## 7. Legal bases

We process personal data under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and, to the extent applicable, the EU and UK General Data Protection Regulations (GDPR / UK GDPR) on the following bases:

- Entering into or performing a contract: Platform User accounts, contact and evaluation processes.
- Compliance with our legal obligations: commercial, tax and regulatory record-keeping obligations and requests from competent authorities.
- Our legitimate interests: service security, abuse prevention and service improvement, provided the fundamental rights and freedoms of the data subject are not overridden.
- For Service Data, the Customer's instructions: the Customer determines and documents its own legal basis (for example a statutory customer due diligence obligation or explicit consent).

## 8. Sharing and transfers

**We do not sell or rent personal data and do not share it with third parties for advertising, marketing or profiling.** Service Data is returned only to the relevant Customer.

Personal data is not disclosed to third parties except in the following limited cases:

- **Infrastructure providers:** the infrastructure providers used to host the service and deliver email may access data only to the extent technically necessary to provide the service. These providers are bound by confidentiality and data processing agreements and may not use the data for their own purposes. The provider list and region information are set out in customer agreements.
- **Legal requirement:** upon a lawful request from a competent court or public authority, limited to the scope of the request. For requests concerning Service Data, the Customer is informed unless legally prevented.
- **Change in corporate structure:** in the event of a merger, acquisition or transfer of assets, subject to continued adherence to this notice and prior notification.

**International transfers:** Service Data is processed and stored in the region defined in the Customer's agreement and is not transferred outside that region without the Customer's instruction or a legal requirement. Any transfer relies on an adequacy decision, standard contractual clauses or another valid transfer mechanism under Article 9 of the KVKK and Chapter V of the GDPR.

## 9. Security

We apply technical and organisational measures to protect personal data against unauthorised access, loss and alteration:

- Encryption in transit with TLS; encryption at rest.
- Role-based access control on a least-privilege basis; logging of access.
- Additional restriction of access to identity document images and biometric data.
- Technical documentation directing that secret API keys are used server-side only, and the ability to revoke keys.
- In the event of a breach affecting personal data, notification to the competent authority and affected Customers within the period required by applicable law.

No system provides absolute security. Platform Users are responsible for keeping their account credentials and API keys confidential.

## 10. Retention periods and deletion

Personal data is kept only for as long as necessary for the purpose for which it is processed:

- Server access logs: the period necessary for technical security.
- Contact requests: until the request is resolved and for as long as necessary for a potential business relationship.
- Platform User data: the life of the account and, afterwards, the period necessary for legal obligations and potential disputes.
- Service Data: the period defined in the Customer's plan and agreement (between 7 days and 10 years); deleted when the period expires.
- Anonymised statistics: may be kept without a time limit, as they are not personal data.

Deletion covers removal from active systems and destruction from backups within the regular backup cycle. A statutory retention obligation or an ongoing dispute may require the relevant data to be kept solely for that purpose and for that period.

## 11. Your rights and how to make a request

Under Article 11 of the KVKK and, to the extent applicable, the GDPR, you have the following rights:

- To learn whether your personal data is processed and, if so, to request information about it.
- To learn the purpose of processing and whether the data is used in line with that purpose.
- To know the third parties to whom the data is transferred, domestically or abroad.
- To request rectification of incomplete or inaccurate data; to request erasure or destruction where the conditions are met; and to request that these operations be notified to third parties to whom the data was transferred.
- To object to a result that is unfavourable to you arising exclusively from automated analysis.
- To claim compensation for damage suffered as a result of unlawful processing.
- Under the GDPR, additionally to request restriction of processing and data portability.

Requests may be sent to contact@legichain.com. We may ask for reasonable information to verify your identity. Requests are resolved within 30 days at the latest (within one month under the GDPR). End Users should direct their requests to the Customer that provided them the service; requests that reach us are forwarded to the relevant Customer.

You retain the right to lodge a complaint with the Turkish Personal Data Protection Board or the data protection authority in your country (for example the ICO in the United Kingdom).

## 12. Changes and contact

Changes to this notice are published on this page together with the updated text and effective date; Platform Users are informed separately of material changes.

For questions about our data processing, contact us at contact@legichain.com.

---
Legichain — technology for identity verification, AML and blockchain screening. Contact: contact@legichain.com
