Legal · Privacy

We hold as little
as the work allows.

TrustChange builds regulated crypto and payment systems. Our clients are licensed firms. They audit their vendors. So this policy is written to be read, not skimmed past. It says what we collect, why we keep it, and how long it stays.

It covers this website and our sales contact. Work we do inside your own platform runs under your contract and data processing agreement.

Section 01

What we collect

Four kinds of data, and nothing else. There is no ad network on this site. We run no tracking pixels and no cross-site profiling.

You send it

Contact details

Your name, work email, company and the brief you type into an enquiry. We use it to answer you and to scope the work.

  • Name and role
  • Work email
  • Company
  • Project brief

You send it

Hiring data

If you apply to join us, we read your CV and notes. We keep it apart from client data. We never use it for marketing.

  • CV or profile link
  • Interview notes
  • Right-to-work status

Server logs

Technical records

Our host writes a short access log for every page. It guards the site against abuse. We do not build profiles from it.

  • Truncated IP
  • Browser and device type
  • Page and timestamp

Under contract

Client project data

On an engagement we may touch your systems. We act as your processor there. Your contract and DPA set the terms, not this page.

  • Named user accounts
  • Test and staging data
  • Support tickets

Section 02

Why we keep it, and for how long

Every record has one purpose and one clock. When the clock runs out, the record goes. The same discipline we apply to compliance engineering applies here.

Retention schedule · reviewed 27 July 2026
Purpose Legal basis We keep it
Answering a sales enquiry Legitimate interest 24 months from last contact
Contracts, invoices and tax records Legal obligation 10 years
Job applications Consent 12 months, then deleted
Website access logs Legitimate interest 90 days, then rotated out
Client project data on an engagement Contract Per your DPA; wiped at handover

Section 03

Your rights, and how to use them

GDPR gives you four practical levers. One email pulls any of them. We reply within 30 days, and usually much sooner.

  1. Ask what we hold

    Email us and ask for a copy. We confirm who you are first. Then we send the file.

  2. Fix or delete it

    Wrong details get corrected. You can ask us to erase your record where no law makes us keep it.

  3. Object or restrict

    You can tell us to stop using your data for outreach. We stop. You can also freeze use while a dispute runs.

  4. Take it with you

    We export your record in a common machine-readable format on request.

Unhappy with our answer? You may complain to your national data protection authority. You do not need our permission first.

Section 04

Access, sharing and transfers

Our engineers work inside regulated platforms every day. The habits carry over. Read more on our compliance approach.

Who sees your data

Only the people who need it. Sales staff see enquiries. Engineers see project systems. Access is granted per role and reviewed.

Role-based access

Who we share it with

A short list of vendors: our email host, our site host, and our accountants. Each one is bound by a written data agreement. We never sell your data.

No data sales, ever

Where it lives

Our systems sit in the EU or EEA. If a vendor moves data outside, we rely on the EU Standard Contractual Clauses.

EU and EEA hosting

This site sets no marketing cookies. Details sit on our cookie page. Service terms sit on our terms page.

Need this in a vendor questionnaire?

Send it over. We answer security and privacy reviews as part of normal onboarding. Ask us for a signed DPA, our sub-processor list, or a walkthrough with the engineers who would run your build.