Document

Privacy Policy

This policy describes what data we receive through the DefCrypt website and communication channels, why we need it, how it is retained, and how you can request access, correction, or deletion.

Updated

Who processes the data

For purposes of this policy, the personal data operator is the public-facing DefCrypt brand. You can contact us about personal data through Telegram or the assessment form on the website.

We do not publish full legal details or an address in this version of the website. DefCrypt services are intended for people aged 18 and over. We do not knowingly request data from minors; if we discover that we have received such data, we will delete it.

What data we collect

Through the website assessment form and correspondence, we may receive:

  • where the assets are held (an exchange, a wallet, or "not sure");
  • what happened (a restriction, AML/KYC/SoF review, P2P issue, theft or scam, loss of access, an active attack, or another event);
  • an approximate amount, if you choose to provide it;
  • a Telegram contact, which is required so that we can respond;
  • an email address, if you choose to provide it;
  • a brief description of the matter and any materials you send voluntarily;
  • confirmation that you consent to personal data processing;
  • technical data generated when you use the website, such as an IP address, browser type, and device type, to the extent necessary to operate and secure the service.

What we do not ask for

We do not ask for or accept seed phrases, private keys, wallet or exchange passwords, or 2FA codes. Anyone requesting this information in DefCrypt's name is a scammer.

Why we need the data

We process data to:

  • receive and review your request for a case assessment;
  • contact you and correspond about the matter;
  • continue the work, with your agreement, including analysis, document preparation, and coordination;
  • notify operators about a new inquiry;
  • operate and secure the website;
  • comply with legal requirements where applicable.

Legal bases

Processing is based on the consent you provide when submitting the form or contacting us through a communication channel, as well as the need to respond to your request and fulfil agreed arrangements if you continue working with us.

More specific wording about applicable law, including Federal Law No. 152-FZ where relevant, may be added as the legal review proceeds. The current text is published on this page.

Retention periods

Assessment-form inquiries and related correspondence are retained for as long as needed to respond and, where necessary, continue the work. As a guideline, this is up to three years after the last contact concerning the inquiry, unless the law requires a longer period.

Materials for a matter accepted for work are retained while the matter is active and, as a guideline, for up to five years after it is closed, unless the law requires otherwise.

You may request earlier deletion. We will delete the data unless there is a lawful basis for retaining it.

Who else may see the data

We engage the following categories of processors: website hosting providers, services that deliver notifications to operators, including Telegram, and internal personnel working on the matter.

Wallet addresses and transaction hashes that you provide for review may be processed in analytics and forensic tools needed for the matter. We do not transfer personal data beyond what is needed for tracing unless necessary for the matter.

We do not ask for or transfer seed phrases, private keys, or passwords because we do not have them.

We do not use advertising or remarketing trackers without consent. If we add website traffic analytics, we will use consent where required and describe the tools in this policy when they are introduced.

Your rights

Depending on the applicable law, you may request access to your data, correction, deletion, restriction of processing, or object to processing for certain purposes.

To exercise a right, contact DefCrypt on Telegram or submit a request through the website assessment form and state that it concerns personal data. Include how we can contact you and what you are requesting. We will respond within a reasonable period after receiving the request; as a guideline, this is up to 30 days.

Cookies and analytics

The website may store technical interface settings in your browser, such as the selected theme. These settings support the interface and are not used for advertising tracking.

We do not set advertising, remarketing, or third-party tracking cookies without consent. If website traffic analytics are introduced, we will request consent where required and update this section.

Changes to this policy

We may update this policy when the services or requirements change. The current version is always available on this page, and the update date appears at the beginning.

Security

We restrict access to inquiry materials and do not ask for wallet secrets through the website. Sensitive details are better shared through an agreed secure channel; where necessary, we put an NDA arrangement in place.

If you notice suspicious activity in DefCrypt's name, report it through the same contact channels.

Contact

Questions about personal data

Contact us on Telegram or briefly describe your request through the homepage form. That is enough to ask about this privacy policy or request a case assessment.