Skip to content
Data Protection & Privacy Policy

Sanctix Privacy Policy

Last Updated: July 31, 2026 • GDPR, UK GDPR & Cross-Border Compliance

ZERO DATA MONETIZATION & STRICT PROCESSOR ISOLATION

Sanctix processes screening data strictly to calculate fuzzy matching scores and render compliance audit reports. We do not sell personal data, monetization screening inputs, or use screened-party data to train general-purpose public AI models.

1. Overview

This Privacy Policy explains how Sanctix Inc. ("Sanctix," "we," "us," "our") collects, uses, discloses, and protects personal data in connection with the Sanctix platform, website, and API (the "Service").

This Policy addresses two distinct categories of personal data we process:

Account Data

Personal data about you, our Customer, and your authorized administrative users (registration, billing, usage logs).

Screened-Party Data

Personal data about third parties whose names Customers submit to the Service for screening, or which appears in public watchlists.

2. Account Data We Collect

  • Registration data: name, work email, company name, job title, phone number.
  • Billing data: handled by our payment processor; we retain limited billing metadata (plan, transaction status) but do not store full payment card details.
  • Usage and technical data: IP address, browser/device information, API call logs, timestamps, feature usage, and technical metrics.
  • Support communications: content of support tickets, emails, or chat messages sent to us.

3. Screened-Party Data

3.1. When a Customer submits a name or entity for screening, Sanctix processes that input against publicly available government and intergovernmental sanctions and watchlist data (e.g., OFAC, UN, EU, UK OFSI, and other public sources) to generate a Report.

3.2. Source of screened-party data on matches: where a match is found, the personal data returned (name, aliases, listed jurisdiction, sanction program, source ID) originates from publicly published government sanctions lists, not from private investigation.

3.3. Legal basis & controller role: Sanctix processes Screened-Party Data on the basis of (a) legitimate interests in providing sanctions compliance tooling to trade-exposed businesses, and (b) Customer's own legal obligations to screen counterparties under applicable sanctions and AML law. Sanctix acts as a data processor on behalf of Customer with respect to the names Customer submits for screening; Customer is the data controller responsible for having a lawful basis to submit that data.

3.4. Sanctix does not use Screened-Party Data for any purpose other than generating the Report and improving matching accuracy (in de-identified/aggregated form where feasible), and does not sell this data.

4. How We Use Personal Data

We use the data described above to:

  • Provide, operate, and maintain the Service, including generating Reports;
  • Process billing and manage subscriptions;
  • Authenticate users and secure accounts and API keys;
  • Monitor, detect, and prevent fraud, abuse, and security incidents;
  • Provide customer support;
  • Improve matching accuracy and Service performance (using aggregated/de-identified data where possible);
  • Comply with legal obligations, including responding to lawful requests from authorities;
  • Communicate service updates, security notices, and (with consent) marketing.

We do not use Screened-Party Data to train general-purpose AI models outside the context of improving Sanctix's own matching functionality, and we do not sell personal data.

5. Legal Bases (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we rely on:

  • Contract: processing Account Data necessary to provide the Service under our Terms of Service;
  • Legitimate interests: for security, fraud prevention, service improvement, and processing Screened-Party Data;
  • Legal obligation: where processing is required to comply with law, including sanctions and AML obligations;
  • Consent: for optional marketing communications, revocable at any time.

6. Sub-processors and Third-Party Sharing

We share personal data with the following categories of sub-processors, strictly as necessary to operate the Service:

Sub-processor CategoryPurposeProvider / Example
Cloud Hosting / InfrastructureApplication hosting, database storage, API edge proxiesGoogle Cloud Platform, Cloud Run
Payment Processing / Merchant of RecordSubscription billing, tax compliance, invoice processingStripe / Merchant Processor
AI Report Summarization EngineGenerating automated compliance report summariesGoogle Gemini API (Server-side)
Transactional CommunicationsAPI key security alerts, report delivery, verification emailsSecure SMTP Provider
Bot Protection (contact form)Challenge verification on the public contact form only — no advertising cookies, no tracking profileCloudflare Turnstile
Advertising Measurement (consent-gated)Google Ads campaign measurement on marketing pages and the purchase confirmation page only — loads only after you click Accept, never inside the workspace, screening, or reportsGoogle Ads (AW-18468212454)

We do not sell personal data to third parties. We may disclose data where required by law, subpoena, or lawful government request.

7. International Data Transfers

7.1. Sanctix operates across multiple jurisdictions, and personal data may be transferred to, stored in, and processed in countries other than the one in which it was collected (including the United States, European Union, and Singapore).

7.2. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an applicable adequacy decision.

7.3. China PIPL note: where processing involves personal information subject to Mainland China's Personal Information Protection Law (PIPL), cross-border transfers adhere to required statutory security assessments, standard contracts, or separate consent frameworks where required.

8. Data Retention

Account Data: retained for the duration of your subscription and for required statutory retention periods afterward for legal, tax, audit, and dispute-resolution purposes.

Screening Reports & Audit Logs: retained according to Customer configuration to support Customer's own audit-trail and recordkeeping obligations under sanctions/AML regimes.

Screened-Party Data (no-match results): retained only as long as necessary to support the audit trail of that screening event.

9. Security

We implement technical and organizational measures designed to protect personal data, including encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls, API key cryptographic hashing, and regular security reviews.

10. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Request deletion, subject to our legal retention obligations;
  • Object to or restrict certain processing;
  • Request data portability;
  • Withdraw consent for optional processing at any time;
  • Lodge a complaint with your local data protection authority.

Note on Screened-Party Data: because Sanctix acts as a processor with respect to names Customers submit for screening, individuals whose names were screened should generally direct data-subject requests to the Customer (the controller) who submitted the screening.

11. Cookies & Tracking

We use essential session cookies required for authentication and security. For aggregate website statistics we count anonymous pageviews on our own infrastructure — no cookies, no personal data, no third-party trackers, no advertising profiles.

Optional advertising measurement: visitors in the EEA, UK, or Switzerland — or anywhere we cannot determine — see a cookie banner, and the Google Ads tag (AW-18468212454) stays fully blocked until you click Accept (Consent Mode v2, all storage denied by default, with the denial additionally pinned to those regions on Google's side). Visitors clearly outside those regions are measured without a banner, but still without ad personalization, remarketing lists, or personal data: the tag runs on marketing pages and the purchase confirmation page only, never inside your workspace, screening, reports, or API surfaces, and the purchase signal carries only an opaque transaction ID — no email, no name, no screening content. You can change your choice anytime via the "Cookies" button.

12. Children's Privacy

The Service is intended for business use by individuals over 18 and is not directed at children. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or in-Service notice at least 14 days before taking effect.

Sanctix Privacy & Data Protection Office
Sanctix Inc. • Global Privacy Team
Privacy Contact: privacy@sanctix.io