Privacy Policy

Last Updated: August 25, 2026

Home

Red Leaf Chicago, LLC, together with its current and future subsidiaries, affiliates, successors, and assigns, as well as all brands, trade names, trademarks, service marks, assumed names, fictitious business names, and “doing business as” (DBA) names under which it operates (collectively, the “Company”, “we”, “us”, or “our”) is an incident response and digital asset services provider, specializing in incident response services, including but not limited to services relating to pre-and post-incident response readiness, threat actor communications, dark web monitoring, threat intelligence, blockchain forensics and tracking, the secure handling of ransomware incidents, and the facilitation of secure payments (collectively, the “Services”).

This Privacy Policy applies to the Company’s processing activities related to the personal data of its current, past, and prospective customers, clients, employees, and other stakeholders (“you” or “your”), unless a separate privacy notice, agreement, or policy expressly applies.

This Privacy Policy describes how and why we might access, collect, receive, record, store, use, disclose, transfer, share, and/or otherwise process your personal information in connection with your access to or use of the Company’s websites, applications, products, services, platforms, and other business operations or interactions with the Company.

This Privacy Policy applies whenever you interact with us, including when you:

  • Use our Services;
  • Contact us via our websites;
  • Communicate with us via email, text, phone, or other electronic methods;
  • Interact with our advertising on third-party websites, if the advertising includes links to this policy;
  • Engage with us in other related ways, including:
    • Participating in industry conferences;
    • Completing surveys or questionnaires;
    • Applying for employment; or
    • Participating in other business activities.

Please read this Privacy Policy carefully to understand how we process your personal information. If you do not agree with our policies and practices, you may choose not to use our Services. However, certain data processing may be required by law or necessary for our Services even without your consent, particularly for Anti-Money Laundering (AML) and Know-Your-Customer (KYC) compliance.

By accessing or using services provided by the Company, you agree to this Privacy Policy. This Privacy Policy may change from time to time (see “Changes to Our Privacy Policy” below). Your continued use of our Services after we make changes to this Privacy Policy is deemed to be acceptance of those changes.

1. DEFINITIONS

The following terms are defined as follows:

  • “Personal data” or “personal information” means any information that (a) can be used to identify the individual to whom such information relates, or (b) is or might be directly or indirectly linked to an individual or household.
  • “Processing of personal data” means an operation or set of operations performed upon personal data. Examples of processing operations of personal data include, but are not limited to, the collection, storage, alteration, retrieval, consultation, disclosure, anonymization, pseudonymization, dissemination or otherwise making available, deletion or destruction of personal data.
  • “AML” means Anti-Money Laundering
  • “KYC” means Know-Your-Customer

2. HOW WE DEFINE PERSONAL DATA

We believe strongly in fundamental privacy rights and that those fundamental rights should not differ depending on where you live in the world. That’s why we treat any data that relates to an identified or reasonably identifiable individual, or that is linked or reasonably linkable to an individual by the Company, as “personal data,” regardless of where that individual resides. This means that data that directly identifies you – such as your name – is personal data, and also data that does not directly identify you, but that can reasonably be used to identify you when combined with other similar information, is personal data.

Aggregated data and properly de-identified data that cannot reasonably be used to identify an individual is not considered personal data for the purposes of this Privacy Policy.

Our Privacy Policy does not apply to how third parties define personal data or how they use it. We encourage you to read the privacy policies of third parties and know your privacy rights before interacting with them.

3. WHY DO WE NEED YOUR PERSONAL DATA?

We collect and process your personal data only for legitimate business purposes, in accordance with applicable data protection and privacy laws, and only as necessary to provide, manage, secure, and improve our Services. We do not sell your personal data and we do not use your personal data for targeted advertising purposes. Any data sharing for analytical or advertising purposes is first anonymized or de-identified in accordance with applicable law.

4. PERSONAL INFORMATION WE COLLECT

Information you provide to us. We collect personal information that you voluntarily provide when you express an interest in our products and Services, use the Services, or otherwise communicate with us. The personal data collected, and how we use it, depends on the context of how you interact with us.

You are not required to provide the personal information that we request. However, if you choose not to provide certain information, in many cases we may be unable to provide the requested products or services, respond to your inquiries, complete transactions, or otherwise fulfill the purpose for which the information was requested.

Third party sources. In certain cases, we combine personal information we receive from you with personal information we obtain from other sources. We may receive personal data about you from other individuals, from businesses or third parties acting at your direction, from third parties who work with us to provide our products and services and assist us in security and fraud prevention, and from other lawful sources.

  • Individuals. We may collect data about you from other individuals – for example, if that individual has referred you to us, or shared content with you.
  • At your direction. You may direct other individuals or third parties to share data with us.
  • Third-party service providers. We may validate the information you provide – for example, during the client intake process, with a third party for security, and for AML compliance and fraud-prevention purposes.
  • Affiliates. Our affiliates include the group of companies related to us by common control or ownership. In accordance with applicable law, we may obtain information about you from our affiliates as a normal part of conducting business, so that we may offer our affiliates’ services to you.
  • Public databases, credit bureaus, and ID verification service providers. We may obtain information about you from public databases and ID verification service providers for purposes of verifying your identity and in order to conduct due diligence or fraud prevention checks in accordance with applicable law. ID verification service providers use a combination of government records and publicly available information about you to verify your identity. Such information may include your name, address, job role, public employment profile, credit history, status on any sanctions lists maintained by public authorities, and other relevant data. We obtain such information to comply with our legal obligations, such as AML laws. In some cases, we may process additional data about you to assess risk and ensure our Services are not used fraudulently or for other illicit activities. In such instances, processing is necessary for us to continue to perform our contractual obligations with you and others.
  • Blockchain data. We analyze public blockchain data to (i) verify compliance with our Terms of Service, (ii) detect and prevent illegal activities, (iii) meet our regulatory obligations, (iv) conduct transaction trend analysis for service improvement and research purposes, and (v) comply with law enforcement and regulatory requests as required by applicable law.

The categories of personal information we may collect, including types of personal information we have collected in the past twelve (12) months, are listed below:

Category of Personal InformationExamples of Personal Information CollectedCategories of Recipients
A. IdentifiersReal name, alias, postal address, telephone or mobile number, email address, account name, account status, signature, and unique personal identifiers (such as device identifiers).Third Party Identity Verification Services
Financial Institutions
Service Providers
Professional Advisors
Our Affiliates
B. Protected Classification CharacteristicsGender, age, date of birth, national origin, marital status, citizenship status, and other demographic information.Third Party Identity Verification Services
Professional Advisors
C. Sensitive Personal InformationCitizenship or immigration status, government-issued ID (e.g., driver’s licenses, ID cards) and ID numbers, financial information including account access details, passport numbers, social security numbers, and contents of mail, email, and text messages.Third Party Identity Verification Services
Service Providers
Professional Advisors
D. Financial or Commercial InformationBank account details, wallet addresses, transaction records, purchase history, payment information (including billing address and payment method such as bank details, credit/debit card information), salary, income, and asset details, and information related to our branded financial products or services.Third Party Identity Verification Services
Financial Institutions
Service Providers
Professional Advisors
Our Affiliates
E. Device and Technical InformationDevice identifiers, such as IP address, browser type, operating system, application identifiers, network information, and technical logs. Signals relating to user behavior, including clickstream through our application and page interaction information.Service Providers
Our Affiliates
F. Audio, Electronic, Sensory, or Similar InformationImages and audio, video, or call recordings created in connection with our business activities.Third Party Identity Verification Services
Service Providers
Professional Advisors
Our Affiliates
G. Professional or Employment-Related InformationBusiness contact details (e.g., office location, job title) in order to provide you with our Services at a business level, or job title, work history, and professional qualifications (including education) if you apply for a job with us.Third Party Identity Verification Services
Service Providers
Professional Advisors
Our Affiliates
H. Institutional InformationEmployer Identification number (or comparable number issued by a government), proof of legal entity formation (e.g., Articles of Incorporation), and personal identification information for all material beneficial owners.Third Party Identity Verification Services
Service Providers
Professional Advisors
Our Affiliates
I. Correspondence, Survey, or Questionnaire ResponsesInformation you provide through requests, surveys, or questionnaires, including any personal data you voluntarily share. Other information provided to us via email or phone correspondence.Service Providers
Professional Advisors
Our Affiliates
J. Biometric InformationData derived from fraud prevention and identity verification processes, including facial imagery collected through selfie-based identity verification methods.Third Party Identity Verification Services
Financial Institutions
Professional Advisors
K. Fraud Prevention or Other Legal Compliance InformationData used to detect and prevent fraud, including other personal, commercial, and/or identification information. Information deemed necessary for us to comply with legal, AML, and KYC obligations.Third Party Identity Verification Services
Financial Institutions
Professional Advisors
Our Affiliates
L. Inferences Drawn From Collected Personal InformationInferences derived from information collected through business users’ use of our private, membership-based knowledge base web application only, and not from the Company’s public-facing website(s). These may include insights about how authorized users interact with the web application, such as search patterns, navigation behavior, feature usage, content interaction metrics, and workflow preferences. These inferences are used to operate, improve, secure, and support the application and related services.Service Providers
Professional Advisors
Our Affiliates

These categories of data may be shared with third parties only as necessary for purposes including identity verification, fraud prevention, or to comply with applicable law. Any such sharing is subject to appropriate contractual safeguards, data protection requirements, and data minimization principles. We maintain oversight of third parties’ data handling practices through contractual provisions and regular assessments.

We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:

  • Receiving assistance through our support channels;
  • Participation in events, surveys, or social media engagements; and
  • Facilitation of the delivery of our Services and to respond to your inquiries.

When necessary for improving our Services, we may process datasets for research and development purposes that may contain personal data, including biometric information such as images and voice data. Any such processing is conducted in strict compliance with applicable data protection laws and with appropriate safeguards in place, including data minimization and purpose limitation principles.

5. HOW WE USE PERSONAL INFORMATION

We only process your personal data when we have a valid legal basis under applicable law, including: (i) your express consent; (ii) compliance with legal obligations; (iii) performance of our contractual obligations; (iv) protection of vital interests; (v) our legitimate business interests, provided such interests do not override your fundamental rights and freedoms; or (vi) as otherwise permitted by applicable law. We maintain documentation of these legal bases as required by law.

If you choose to limit the use of your personal information, our Services may not be available to you.

To the extent permitted by applicable law, we may use your personal information for various legitimate purposes, including:

  • With your consent. Where required by applicable law, we will obtain your specific, informed, and explicit consent before collecting or processing certain categories of personal information, or particularly sensitive personal data. Such consent will be obtained through clear affirmative action and documented in accordance with applicable privacy laws. you have the right to withdraw your consent for that specific processing at any time. However, please note that if you withdraw your consent, we may no longer be able to provide you with our Services.
  • Performance of a contract. We collect personal information necessary to provide our Services and fulfill our contractual obligations to you, which may include personal information collected to improve our product and service offerings, enhance your experience, for internal purposes such as auditing or data analysis, or for client support.
  • Transaction processing. We must collect data such as your name, purchase, and payment information to process purchase transactions.
  • To communicate with you. We may use your personal information to respond to your inquiries, engage with you regarding your transactions or account, promote our products and services, provide relevant updates, and request feedback. Additionally, we may occasionally send important notices, such as updates about your account or changes to our terms and policies. Because this information is important to your interaction with us, you may not opt out of receiving these notices.
  • To personalize the Services. If you choose to personalize your services or communications where such options are available, we will use information that we collect so that we can offer you those personalized services or communications.
  • Legal obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with government, law enforcement, and regulatory authorities where required by applicable law, exercise or defend our legal rights, to satisfy tax, regulatory or reporting obligations, or disclose your information as evidence in litigation in which we are involved.
  • Vital interests, security, and fraud prevention. We may process your information to protect individuals, employees, and the Company, and for loss prevention and to combat fraud, spam, or other malware and security risks, including to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
  • To enforce our Terms of Service. To enforce and apply our Terms of Service, Privacy Policy, and all other applicable policies or agreements.

If you are located in Canada:

We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). you have the right to withdraw your consent for that specific processing at any time. However, please note that if you withdraw your consent we may no longer be able to provide you with our Services.

In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:

  • If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
  • For investigations and fraud detection and prevention
  • For business transactions provided certain conditions are met
  • If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
  • If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
  • If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
  • If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
  • If the collection is solely for journalistic, artistic, or literary purposes
  • If the information is publicly available and is specified by the regulations

If you have questions about a legal basis described in this Privacy Policy, you can send an email to privacy@digitalmint.io.

6. SHARING OF PERSONAL INFORMATION

We may share personal data with affiliated companies or third-party service providers who act on our behalf and are bound by written confidentiality obligations and data processing agreements, or others as explicitly authorized by you in writing. Further, we do not share personal data with third parties for the third parties’ marketing purposes.

We may share your data with the following groups:

  • Within the Company. We may share your personal information with our affiliates, subsidiaries, and employees.
  • Service providers. We may engage third parties to act as our service providers and perform certain tasks on our behalf, such as processing or storing data, including personal data, in connection with your use of our Services. Our service providers are contractually obligated to handle personal data consistent with this Privacy Policy, applicable data protection laws, and according to our written instructions, and must maintain appropriate technical and organizational security measures. They cannot use the personal data we share for their own purposes and must delete or return the personal data once they’ve fulfilled our request. Examples of the types of service providers we may share personal data with may include:
    • Network infrastructure and hosting
    • Cloud data storage
    • Payment processing and billing
    • Transaction monitoring
    • Information technology
    • Security
    • Document repository services
    • Internet (e.g., ISPs)
    • Data analytics
    • Identity verification
    • Fraud prevention
    • Sanctions screening
  • Other third parties. At times, we may contract with third parties to provide services or other offerings. Such third parties are contractually required to protect your personal data through appropriate technical and organizational measures, maintain confidentiality, and process data only as explicitly authorized by us and in compliance with all applicable data protection laws and regulations.
    • Financial institutions to process transactions you have authorized. If you send us funds from your bank account, your bank will provide us with identifying information in addition to information about your account in order to complete the transaction.
    • Companies or other entities that we plan to merge with or be acquired by, or who purchase our assets pursuant to a court-approved sale, or where we are required to share your information pursuant to insolvency law in any applicable jurisdiction. In such cases, you will receive prior notice of any change in applicable policies and the opportunity to opt-out of any materially different use of your personal information by the successor entity, where permitted by law.
    • Our professional advisors who provide banking, legal, compliance, insurance, accounting, or other consulting services in order to complete third party financial, technical, compliance and legal audits of our operations or otherwise comply with our legal obligations.
  • Law enforcement, officials, or other third parties when we are compelled to do so by a subpoena, court order, or similar legal procedure, or when we believe in good faith that the disclosure of personal information is necessary to prevent physical harm or financial loss, to report suspected illegal activity, or to investigate violations of our policies.
  • Our affiliates as a normal part of conducting business and offering Services to you.
  • As necessary in our judgment in order to protect the vital interests of any person.
  • At your direction. We may share personal data with others at your direction or with your consent. We may also disclose information about you where there is a lawful basis for doing so, including but not limited to: (i) enforcing our terms and conditions; (ii) protecting our legal rights, property, or safety; (iii) responding to legal process or government requests; or (iv) preventing fraud or other illegal activities.

<ins?Note: If you create or access an account indirectly through a third-party website, application, or service, any information you enter may be collected by the owner of the third-party website, application, or service and your information will be subject to that third party’s privacy policy and terms of use. We are not responsible for the privacy, security, or data handling practices of third-party websites, applications, or services, including unauthorized access to or use of your information by such third parties. We encourage you to review the privacy policies and terms of any third-party services you use before providing your personal information.

7. WHAT ARE YOUR PRIVACY RIGHTS?

Depending on your jurisdiction, you may have specific rights regarding your personal information. These rights vary by jurisdiction and may include rights to access, correct, delete, port, or restrict processing of your personal information. We have listed a non-exhaustive summary of some of these rights below. If any of the rights listed are not provided under applicable law in your operating entity or jurisdiction, we may, in our sole discretion, choose to extend similar benefits to you.

  • Access. You may request that we provide you a copy of your personal information held by us, subject to applicable legal exceptions.
  • Data portability. In certain circumstances, you may request your personal information in a structured, commonly used and machine-readable format, or to have us transfer your information directly to another business.
  • Rectification of incomplete or inaccurate personal information. You may request that we correct or update your personal information if it is inaccurate or incomplete.
  • Restriction of processing. In some jurisdictions, applicable law may give you the right to restrict or object to us processing or transferring your personal information under certain circumstances. We may continue to process your personal information if it is necessary for the defense of legal claims, or for any other exceptions permitted by applicable law.
  • Automated individual decision-making, including profiling. We rely on automated tools to help detect and mitigate fraud or legal risk. In some jurisdictions, you may have the right not to be subject to a decision based solely on automated processing of your personal information, including profiling, which produces legal or similarly significant effects on you, save for the exceptions applicable under relevant data protection laws. Due to the nature of our Services and our legal obligations regarding fraud prevention and security, certain automated processing is necessary to provide our core Services and comply with legal requirements. We do not use algorithms or profiling to make any final decision that would significantly affect you without the appropriate human oversight and review, as required by applicable law.
  • Marketing communications. You can opt-out of receiving marketing communications from us. Direct marketing includes any communications to you that are only based on advertising or promoting our products and Services. We will only contact you by electronic means with your consent, or based on our legitimate interests where permitted by applicable law. If you do not want us to send you marketing communications, email privacy@digitalmint.io or call us at 1-855-274-2900.

We will consider and act upon any request in accordance with applicable data protection laws. There may be situations where we cannot grant your request – for example, if you ask us to delete your transaction data and we are legally obligated to keep a record of that transaction to comply with the law. We may also decline to grant a request where doing so would undermine our legitimate use of data for compliance with applicable laws and regulations, including but not limited to AML requirements, Bank Secrecy Act obligations, anti-fraud measures and security purposes. Other reasons your privacy request may be denied include, but are not limited to, situations where granting the request would jeopardize the privacy of others, where the request is frivolous or vexatious, would be extremely impractical, would compromise our legitimate business interests or legal obligations, or where a denial is permitted under applicable law.

Canada residents have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) or, where applicable, with the provincial privacy commissioner.

Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section “How to Contact Us” below. However, please note that your withdrawal will not affect the lawfulness of the Company’s data processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent. If you withdraw your consent, we may no longer be able to provide you with our Services.

8. SPECIFIC PRIVACY RIGHTS FOR UNITED STATES RESIDENTS

You may have specific rights under certain U.S.-state data protection laws if you are a resident of the State of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia. These rights may include the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. Because privacy laws vary by state and may change from time to time, the preceding list is nonexhaustive, subject to change, and you are encouraged to review the laws applicable in your state of residence to determine what rights may be available to you. You may also have the right to withdraw your consent to our processing of your personal information. These rights are not absolute and may be limited or denied in certain circumstances as permitted by applicable law, including but not limited to situations involving fraud prevention, security requirements, legal obligations, or where the rights of others would be violated. Where permitted by applicable law, you may designate an authorized agent to make requests on your behalf.

These rights include the:

  • Right to know whether or not we are processing your personal information.
  • Right to access your personal information.
  • Right to correct inaccuracies in your personal information.
  • Right to request the deletion of your personal information, subject to applicable law.
  • Right to obtain a copy of the personal information you have provided to us or that we have collected about you, in a portable and, where technically feasible, readily usable format.
  • Right to non-discrimination for exercising your rights.
  • Right to opt out of the processing of your personal information if it is used for targeted advertising , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.

8.1. CALIFORNIA RESIDENTS’ RIGHTS

Pursuant to the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the “CCPA”), California residents may have certain consumer rights in relation to their personal information, in addition to those referenced above, subject to limited exceptions. Please note that these rights are not absolute and in certain cases are subject to conditions or limitations as specified in the CCPA:

  • For personal information collected by us during the 12 months preceding your request that is not otherwise subject to an exception, California residents have the right to access and request the deletion of their personal information.

If you are a California resident and would like to make such a request, please submit your request in writing to us at privacy@digitalmint.io or call us at 1-855-274-2900 following the guidelines in the “How to Exercise your Rights” section. We will respond to verifiable consumer requests within forty-five (45) days, with a possible forty-five (45) day extension when reasonably necessary.

We do not share personal data with third parties for the third parties’ direct marketing purposes.

9. INFORMATION SECURITY AND PROTECTION OF PERSONAL DATA

We are committed to protecting your privacy and we know that data privacy depends on data security. We use administrative, technical, and physical safeguards to protect your personal data, taking into account the nature of the personal data and the processing, the current state of technology, implementation costs, and the severity and likelihood of potential risks to rights and freedoms of individuals. To make sure your personal data is secure, we communicate our privacy and security guidelines to our employees and strictly enforce privacy safeguards within the Company. We are constantly working to improve on these safeguards.

For additional information on our information security practices, please visit our Trust Center.

10. RETENTION OF YOUR PERSONAL DATA

We will only retain your personal data for as long as it is necessary to fulfill the purposes for which it was collected, including as described in this Privacy Policy, unless a longer retention period is required by law.

When assessing retention periods, we first carefully examine whether it is necessary to retain the personal data collected. This includes considerations such as when the information was collected or created, whether it is necessary in order to continue offering you our Services, whether we are required to hold the information to comply with our legal obligations, including AML/KYC compliance, other financial regulatory obligations, or information preservation requirements (such as tax, accounting, or reporting obligations or to resolve disputes). If retention is required, we work to retain the personal data for the shortest possible period permissible under law. We store your personal information securely throughout the duration of your relationship with us.

When we have no ongoing legitimate business need to retain your personal data, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.

11. CHILDREN’S PRIVACY

We understand the importance of safeguarding the personal data of children, which we consider to be an individual under the age of 13 or the equivalent age as specified by law in your jurisdiction. Our Services are not intended for children below the age of 18, and individuals under 18 are expressly prohibited from using our Services. We do not knowingly collect or solicit data from children. If we learn that a child’s personal data was collected without appropriate authorization, it will be deleted as soon as reasonably practicable, subject to any legal retention requirements.

12. HOW TO EXERCISE YOUR RIGHTS

To exercise your rights, please submit a request to us by calling us at 1-855-274-2900 or sending an email to privacy@digitalmint.io.

If you are contacting us to exercise your rights with regard to your personal data as detailed in this Privacy Policy, please adhere to the following guidelines:

  • Specify which right you wish to exercise and the personal data to which your request relates (if not to you);
  • If you are acting on behalf of another individual, please clearly indicate this and your authority to act on such individual’s behalf (see “Authorized Agents” below for more information); and
  • Provide us enough information to verify your identity. Please see “Request verification” below.

We will not discriminate against those who exercise their privacy rights under applicable laws. Specifically, if you exercise your rights, we will not deny you services, charge you different prices for services or provide you a different level or quality of services.

12.1. AUTHORIZED AGENTS

Under certain data protection laws, you may be permitted to authorize a person (“Authorized Agent”) to make a request on your behalf. To do so, you must: (i) give the Authorized Agent signed, written permission to submit the request; and (ii) verify your own identity with us.

We may deny a request from an Authorized Agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws, if we are unable to verify their identity, if we suspect fraudulent or malicious activity, or if the request is excessive or unfounded.

12.2. REQUEST VERIFICATION

We will verify your identity before processing any request. While we strive to limit the personal information collected in connection with a request to exercise your rights, certain requests may require us to obtain additional personal information from you to match the information we maintain about you in our systems. We will let you know via email if we need more information from you to authenticate your request. Please reply to our requests promptly. Failure to provide requested verification information may result in your request being denied.

In certain circumstances, we may decline a request to exercise the right to know, particularly where we are unable to verify your identity.

12.3. RESPONDING TO YOUR REQUESTS

We aim to respond to your verified requests within the timeframe required by applicable privacy legislation. This information will be provided without undue delay subject to a potential fee associated with gathering of the information (as permitted by law), unless such provision negatively impacts others’ rights or is prohibited by applicable law, regulation, or legal process.

If we determine that we cannot take the action that you requested, we will let you know. We will contact you at the email address you provided when submitting your request(s) to inform you of our reasons for not taking action.

12.4. RIGHT TO APPEAL

Under certain data protection laws, if we decline to take action regarding your data rights request, you may be entitled to appeal our decision in accordance with applicable laws and may do so by following the instructions provided in the correspondence we sent to you communicating our decision. To appeal our decision regarding a data rights request, please email privacy@digitalmint.io within sixty (60) days of our initial response. We will inform you in writing of any action taken or not taken in response to the appeal within sixty (60) days of receipt of your written notice of appeal, including a written explanation of the reasons for the decision. If your appeal is denied, you may have the right to submit a complaint to your state attorney general or relevant data protection authority, subject to applicable laws and jurisdictional requirements.

13. JOB APPLICANTS

When you apply to work with us, the personal information submitted with your application will be used to process your application. Personal information may include:

  • Contact details (name, address, email, phone number)
  • Professional and educational background (résumé, CV, references)

These details may be provided through the Careers portion of our website, via email, third-party platform recruitment portals, or direct communications with our hiring team. By submitting this information, you confirm it is accurate and current. Providing incomplete or incorrect information may affect our ability to assess your application or consider you for employment.

We use your information to:

  • Evaluate and process applications – Assess qualifications, verify details, and make hiring decisions.
  • Communicate – Contact You about your application, schedule interviews, and provide updates.
  • Comply with legal requirements – Fulfill employment, immigration, and other obligations.
  • Maintain records – Keep internal records for reporting, auditing, and analytics.
  • Consider future opportunities – Invite You to apply for other positions, unless you opt out.

Our legal bases for processing your data may include our legitimate interest in recruiting qualified personnel, your consent (where required by law), and any applicable legal obligations (e.g., verifying work eligibility).

Retention of Applicant Information. We retain your personal information for a minimum of 12 months and as long as needed for the purposes for which it was collected and other permitted purposes, including retention of Personal Information pursuant to any applicable contract, law, or regulation. As such, our retention periods vary based on business, legal, and regulatory needs.

Your Rights. We retain your personal information for a minimum of 12 months and as long as needed for the purposes for which it was collected and other permitted purposes, including retention of Personal Information pursuant to any applicable contract, law, or regulation. As such, our retention periods vary based on business, legal, and regulatory needs.

14. INTERNATIONAL TRANSFERS OF PERSONAL DATA

The Company is headquartered in the United States. To provide and operate our Services, it is necessary for us to process the personal information you provide in the United States. When we transfer personal information across borders, we implement appropriate safeguards and comply with applicable data protection laws, including but not limited to standard contractual clauses, internal policies and procedures, and other legally recognized transfer mechanisms as required by applicable law.

Please visit our Trust Center for information on our data security practices or contact us for further information about any such transfers or the specific safeguards applied.

15. COOKIES

Our websites do not use cookies to collect or track personal information about visitors. View our Cookie Policy for more information about our privacy-focused, no-cookie approach.

Our websites employ performance and diagnostic technologies that track and monitor website operation, improve reliability, and identify technical issues. These technologies are not used to track user behavior across websites. They may collect limited technical logging information, such as browser types used to access the website, network-related information, and website performance metrics, including page load times and the performance of certain website elements.

Membership-based databases, private knowledge bases, and other restricted-access content hubs may utilize access-control, authentication, security, and monitoring technologies subject to each service’s Terms of Service or Terms of Use, which are separate from the Cookie Policy.

16. CHANGES TO OUR PRIVACY POLICY

We may update this Privacy Policy from time to time. The date this Privacy Policy was last revised is indicated by the “Last Updated” date at the top of the page. If we make material changes to this Privacy Policy, we will notify you by prominently posting a notice of such changes on our website and, where appropriate, sending you a direct notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your data.

17. HOW TO CONTACT US

If you have questions or concerns regarding this Privacy Policy, if you have a complaint, or if you would like to submit a data subject access request, please contact our Privacy Team at 1-855-274-2900 or send an email to privacy@digitalmint.io.

Connect with DigitalMint Today

For general inquiries, email us at cyber@digitalmint.io