Privacy Policy
Last Updated: May 1, 2025
Introduction
Deconflict, Inc. (“Deconflict,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information collected through our crypto wallet intelligence and deconfliction platform (the “Services”).
This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information when verified users, including law enforcement agencies, financial institutions, cryptocurrency exchanges, fintech companies, and other authorized entities (“you” or “users”), access or use our Services.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, you must not use the Services.
Scope and Application
1.1 What This Policy Covers
This Privacy Policy applies to personal information collected through:
- Our website at deconflict.com
- Our web-based application and dashboards
- Our API services
- Account registration and identity verification
- Email and other communications with us
- Personal or organizational identifiers associated with use of the Services
1.2 What This Policy Does Not Cover
This Privacy Policy does not apply to:
- Public blockchain wallet addresses, intelligence indicators, classifications, flags, and related non-personal wallet intelligence submitted through the Services, which are processed in accordance with our Terms of Service
- Third-party websites or services linked from our platform
- Employee or job applicant information, which is governed by separate internal policies
Personal information associated with a user who submits wallet intelligence, including the user’s name, email address, organization, account information, and other identifying information, remains subject to this Privacy Policy.
1.3 User Data vs. Wallet Intelligence
User Personal Information, which is covered by this Privacy Policy, includes information that identifies you as a registered user, such as your name, email address, organization, account credentials, and other information associated with your account or use of the Services.
Submitted Wallet Intelligence includes public blockchain wallet addresses, intelligence indicators, classifications, flags, submission timestamps, and related non-personal metadata.
Users are instructed not to submit suspect names, victim information, case numbers, investigative files, personally identifiable information, or other prohibited personal or sensitive information.
Where wallet submissions are associated internally with a submitting organization, user email address, or other account identifier for verification, security, attribution, or deconfliction purposes, those identifiers are treated as personal information or account information under this Privacy Policy.
2. Information We Collect
2.1 Personal Information You Provide
Account Registration
When you create an account, we collect:
- Full legal name
- Official email address
- Organization or agency name
- Job title or role
- Username and password
- Phone number, if provided, including for multi-factor authentication
- Payment information, if applicable
Passwords are salted and hashed using bcrypt.
Identity Verification
For certain verified users, we may collect:
- Agency or institutional documentation
- Professional credentials or verification codes
- Government-issued badge numbers or employee identification numbers for law enforcement verification purposes
We do not collect Social Security numbers, biometric data, CJIS data, case numbers, investigative files, or criminal histories through our standard user registration and wallet intelligence submission processes.
Communications
When you contact us, we may collect:
- Your name
- Email address
- Phone number
- Organization
- The content of your communications
- Information reasonably necessary to respond to your request
2.2 Wallet Submission Data
When users submit wallet intelligence, we may collect:
- Public blockchain wallet addresses
- Intelligence indicators
- Classifications or flags
- Submission timestamps and metadata
- Submitting organization identifier
- Submitting user email address or account identifier
Users are instructed not to include personal data concerning suspects, victims, witnesses, or other investigative subjects, case numbers, investigative files, or sensitive investigative context.
Public blockchain wallet addresses and associated non-personal intelligence are treated separately from personal information associated with the submitting user.
Information Collected Automatically
When you access our Services, we automatically collect certain technical and usage information, including:
- IP address
- Approximate geographic location derived from IP address
- Browser and device information
- Login timestamps
- Session duration
- API request logs
- Authentication logs
- Security logs
- System activity necessary to maintain the security and integrity of the Services
We do not use advertising cookies, social media tracking pixels, behavioral advertising technologies, or third-party advertising profiles.
4. How We Use Personal Information
We use personal information to:
- Provide and operate the Services
- Authenticate users and control access
- Verify user identities, organizations, and professional credentials
- Enable wallet intelligence submission and review
- Facilitate deconfliction between verified users
- Facilitate authorized communication and coordination between verified users
- Respond to support inquiries
- Maintain platform security
- Detect and prevent abuse, unauthorized access, scraping, fraud, or misuse
- Maintain audit and security logs
- Administer customer and organizational relationships
- Process payments where applicable
- Comply with legal and regulatory obligations
- Enforce our Terms of Service and other agreements
We do not sell personal information.
We do not use personal information for third-party advertising.
We do not engage in behavioral advertising or advertising-based profiling.
4.1 Artificial Intelligence and Machine-Learning Training
We do not use personal information or wallet intelligence submitted by users to train, retrain, fine-tune, or otherwise develop machine-learning or artificial-intelligence models.
Submitted information may be processed as necessary to operate the functionality of the Services, provide intelligence and deconfliction functionality, maintain security, respond to user requests, and perform other uses described in this Privacy Policy and our Terms of Service.
Such operational processing does not authorize the use of submitted user data for training, retraining, fine-tuning, or developing artificial-intelligence or machine-learning models.
5. How Information Is Shared
We disclose personal information only as reasonably necessary to operate the Services, facilitate authorized deconfliction and coordination, comply with legal obligations, or protect the security and integrity of our Services.
5.1 Deconfliction and Coordination
When verified users identify or submit intelligence relating to the same wallet address or other supported identifier, Deconflict may facilitate communication or coordination between authorized users.
Depending on the applicable workflow, information shared may include:
- Organization or agency name
- Official organizational email address
- Authorized contact information
- Other limited information necessary to facilitate legitimate deconfliction or coordination
We do not disclose case files, investigative reports, suspect information, victim information, CJIS information, or other prohibited investigative information through these workflows.
5.2 API and Institutional Customers
Our API and institutional Services may provide verified wallet intelligence, intelligence indicators, classifications, flags, investigative references, or related intelligence to authorized customers.
Except where expressly necessary for an authorized deconfliction or coordination workflow, API customers do not receive:
- Individual user names
- Personal email addresses
- Account credentials
- Badge numbers
- Employee identification numbers
- Personal information identifying the individual who submitted intelligence
5.3 Service Providers
We may use trusted service providers to support functions such as:
- Cloud infrastructure
- Cybersecurity
- Authentication
- Communications
- Payment processing
- Customer support
- Monitoring
- Data storage
- Professional services
Service providers may access personal information only as necessary to perform services on our behalf and are subject to applicable contractual, confidentiality, security, and data protection obligations.
5.4 Legal and Security Disclosures
We may disclose information when reasonably necessary to:
- Comply with applicable law, regulation, court order, subpoena, or valid legal process
- Protect the rights, property, or security of Deconflict
- Protect our users or the public
- Investigate fraud, abuse, cybersecurity incidents, or unlawful activity
- Enforce our Terms of Service
- Establish, exercise, or defend legal claims
5.5 Corporate Transactions
If Deconflict is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
5.6 No Sale of Personal Information
We do not sell, rent, or trade personal information to third parties.
We do not sell submitted wallet intelligence to data brokers or advertising companies.
Data Deletion Requests and Privacy Rights
6.1 Data Deletion Request Process
Deconflict provides a formal process for requesting deletion of personal information.
You may submit a data deletion request using one of the following methods:
Online: Through any Data Deletion Request Form made available through our Services
Email: contact@deconflict.com
Subject: Data Deletion Request
Mail:
Deconflict, Inc.
8 The Green STE A
Dover, DE 19901
United States
Requests should include:
- Full name
- Email address associated with the account
- Description of the request
6.2 Verification and Processing
We may verify your identity before processing a privacy or deletion request to protect against unauthorized access or deletion.
Verified deletion requests are generally completed within 30 days unless retention is reasonably necessary or legally required for:
- Security
- Fraud prevention
- Legal compliance
- Regulatory obligations
- Dispute resolution
- Enforcement of agreements
- Audit requirements
- Other legitimate purposes permitted by applicable law
6.3 Tracking, Logging, and Audit Controls
Data deletion and privacy requests may be:
- Logged in an internal request management system
- Timestamped
- Associated with the verified requester
- Tracked through resolution
- Retained as necessary for security, compliance, and SOC 2 audit purposes
Records may include:
- Request type
- Verification status
- Action taken
- Completion date
- Supporting audit information
Retention of a record showing that a request was received and completed does not mean that deleted personal information remains in active systems.
7. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, our Terms of Service, applicable contractual requirements, and applicable law.
Personal Information
- Active account data is retained while the account remains active
- Inactive accounts may be deleted after 24 months of inactivity
- Personal information associated with an account deletion request is generally deleted within 30 days, subject to applicable legal, security, audit, and operational exceptions
Support and Communications
- Support communications may be retained for up to 24 months
Security and Technical Logs
- Access, authentication, and security logs are generally retained for up to 12 months unless longer retention is reasonably required for security, legal, regulatory, or investigation purposes
Wallet Intelligence
Public blockchain wallet addresses and associated non-personal intelligence may be retained indefinitely to support ongoing intelligence, deconfliction, historical analysis, platform operations, and API services.
Wallet intelligence retained under this provision is not intended to contain personally identifiable information concerning suspects, victims, witnesses, or investigative subjects.
Personal information associated with the submitting user remains subject to this Privacy Policy.
8. Data Security and Compliance
We implement administrative, technical, and physical safeguards designed to protect personal information and the security of our Services.
Security measures include:
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- SOC 2 Type II certification
- Role-based access controls
- Multi-factor authentication where available
- Authentication controls
- Access monitoring
- Security logging
- Continuous security monitoring
No information system or method of transmission can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security.
Users are responsible for safeguarding their account credentials and promptly notifying us of suspected unauthorized access.
International Data Transfers
Personal information may be stored and processed in the United States using secure infrastructure, including AWS infrastructure.
Where required for users located in the European Economic Area, United Kingdom, or Switzerland, international transfers of personal information are handled using legally recognized transfer mechanisms, which may include Standard Contractual Clauses and supplementary technical and organizational safeguards.
Your Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, including the right to:
- Request access to personal information we maintain about you
- Request correction of inaccurate personal information
- Request deletion of personal information
- Request restriction of certain processing
- Object to certain processing
- Request data portability where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with an applicable data protection authority
These rights may be subject to legal limitations and exceptions.
Requests may be submitted using the methods described in Section 6.
We may verify your identity before fulfilling a request.
Children’s Privacy
Our Services are intended for authorized professional users and are not intended for individuals under the age of 18.
We do not knowingly collect personal information from children under the age of 13.
If we become aware that personal information has been collected from a child in violation of applicable law, we will take reasonable steps to delete that information.
Third-Party Services and Links
Our Services may contain links to third-party websites, tools, platforms, or services.
Deconflict is not responsible for the privacy practices, security practices, or content of third-party services.
Your interaction with a third-party service is governed by that third party’s applicable terms and privacy policies.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When material changes are made, we may:
- Post the revised Privacy Policy on our website
- Update the “Last Updated” date
- Provide notice through the Services
- Provide email notice where appropriate or legally required
Your continued use of the Services following the effective date of an updated Privacy Policy constitutes acknowledgment of the updated policy to the extent permitted by applicable law.
Contact Information
If you have questions, concerns, complaints, or privacy requests, please contact:
Deconflict, Inc.
8 The Green STE A
Dover, DE 19901
United States
Email: contact@deconflict.com
For privacy-related requests, use the subject line:
Privacy Request
For deletion requests, use the subject line:
Data Deletion Request
Acknowledgment
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
Last Updated: May 1, 2025