Skip to content

Privacy Policy

Last Updated: 31 August 2026

Data Controller: Sarraf Finansal Teknolojiler A.Ş. ("Sarraf", "Platform") Address: Atatürk Mah. Ertuğrul Gazi Sok. Metropol İstanbul No: A109, 34758 Ataşehir / İstanbul Email: [email protected] Phone: +90 850 532 47 34 Web: sarrafintech.com

1. Scope

This policy covers the personal data of: (a) website visitors, (b) account holders (buyers, sellers and organization members), (c) counterparties and team members invited to the platform by a user, and (d) contact form users.

2. Data We Collect

Visitors: Our site contains no analytics, advertising or tracking tools. For security and error diagnosis, our servers keep your IP address and request metadata in technical logs.

Account holders:

Contact form users: Name, email, company (optional) and your message. This information is not written to our database; it is only forwarded to our corporate mailbox as an email.

Invited people: When a user invites you as a counterparty or organization member, your email address and the inviter's message are held in the system and an invitation email is sent to you. If you do not open an account, your data remains limited to the invitation process.

3. Purposes of Processing and Legal Basis (KVKK Art. 5 / GDPR)

4. Blockchain and the "Immutability" Dilemma

The monetary records of escrow transactions are kept on public, EVM-based blockchain networks. When funds are locked, released or refunded, the following is written to the chain: buyer and seller wallet addresses, amount, timestamps and transaction status.

By the nature of blockchain records:

Your name, email, documents or document contents are NOT written to the chain — the chain holds only wallet addresses, amounts and transaction summaries. By confirming fund-locking transactions you explicitly accept the permanence of blockchain data (and that the right to be forgotten is technically inapplicable to on-chain data).

Platform-managed wallets: For users without their own wallet, the platform creates a wallet on the user's behalf. Private keys are stored with strong encryption (AES-256-GCM), transactions are signed only upon your instruction given through the platform, and every custody operation is written to the audit trail. This section will be updated if we move to an institutional custody provider.

5. Commercial Documents, Storage Infrastructure and Automated Review

Commercial documents and corporate verification documents you upload are encrypted on the platform (AES-256-GCM) and stored on a distributed file network (IPFS, via the Pinata service). IPFS is a public network, so your documents are kept in encrypted form only, and decryption keys never leave the Sarraf platform. For audit trail integrity, documents are archived; an archived document record is not physically deleted. Once the key is deleted from the platform, the document becomes unreadable.

AI-assisted document review: So that the fields of your commercial documents (amount, date, parties, shipment details and similar) can be read automatically, the document content is sent through our AI service provider OpenRouter to a language model (Google Gemini).

6. Identity Verification — Sumsub

Identity verification is carried out through Sumsub, a specialist provider in this field. You enter your identity documents and face verification data directly into Sumsub's secure interface embedded in our platform; this data does not pass through our servers and is not stored by us. Only the applicant number, verification level, result and rejection reason (if any) are held on the platform. The only data we send to Sumsub is your internal user number.

7. Parties We Share Data With

We do not share your personal data with anyone for advertising or marketing purposes, and we do not sell it. To operate the service we use a limited number of service providers (data processors):

Your counterparty sees limited information: display name, company name, verification level and, in the context of the trade, wallet address. Your email and phone are not shared with the counterparty; your public profile shows only display name, verification badge and trade statistics.

Authorities: Data may be shared where legally required. Platform administrators: Authorised staff may access data for support and compliance purposes; administrator actions are written to the audit trail.

8. International Data Transfer (KVKK Art. 9 / GDPR)

Our servers are located in Frankfurt, Germany, and therefore your personal data is stored and processed outside Türkiye. In addition, all service providers listed in Section 7 are established abroad. As no adequacy decision has been issued for the countries concerned, these transfers are carried out on the basis of the standard contract provided for in Article 9(2)(b) of the KVKK; each executed standard contract is notified to the Personal Data Protection Authority within five business days of signature. Where EU citizens or businesses are concerned, transfers are made under the European Commission's standard contractual clauses (SCC) in line with GDPR requirements. Explicit consent is relied on only for the occasional transfers described in Article 9(6) of the KVKK, and in that case is requested from you separately.

9. Cookies and Local Storage

We do not use tracking or advertising cookies. What we do use:

10. Retention Periods

11. Security Measures

Passwords are stored as irreversible hashes; two-factor authentication secrets, custody keys and documents are encrypted; session and verification tokens are held as hashes only; system logs contain no passwords, tokens or document content; the database is not exposed to the internet; all traffic is encrypted with TLS. On suspicious session activity, all sessions are terminated and you are informed by email.

12. Your Rights (KVKK Art. 11 / GDPR)

You have the right to request information about your data, its correction and erasure, to object to its processing, and to exercise your other rights under KVKK Article 11. To do so, apply to [email protected]. Applications are answered within 30 days at the latest.

Important limits:

In these cases, compensating measures such as restricting access and masking are applied instead of erasure.

13. Changes

Changes to this policy are published on this page; material changes are notified to your registered email address. Effective date: 31 August 2026

Privacy Policy · Sarraf