Arcana Crypto LTD ("Arcana", "we", "us", "our") is a private limited company incorporated in England and Wales, Company Number 16371124, with registered office at 12 Pullman Gardens, London, SW15 3DF, United Kingdom.
We act as Data Controller for the personal data described in this Policy and are registered with the Information Commissioner's Office (ICO) under registration reference ZC133290.
We provide cryptocurrency wallet recovery, blockchain forensic investigation, security consulting, and related digital-asset services under the brand Arcana Crypto. We are also developing two additional workstreams — Arcana Heritage (heir-discovery research) and Arcana Property (property-sourcing intelligence) — which are not yet accepting clients. References to those workstreams in this Policy describe activities that are in development or limited internal testing only; no client data is currently processed under those workstreams. This Policy applies to data processed through arcana-crypto.com (the "Site") and through our engagement with you as a Client or prospective Client across all our workstreams.
We have not appointed a statutory Data Protection Officer because our processing activities do not meet the mandatory criteria under Article 37 UK GDPR. The single point of contact for all data protection enquiries, requests and complaints is the Sole Director acting in the role of Data Protection Lead:
Email: legal@arcana-crypto.com (primary) | legal@arcana-crypto.com (operational alternative)
Postal: Data Protection Enquiries, Arcana Crypto LTD, 12 Pullman Gardens, London, SW15 3DF, United Kingdom
This Policy covers personal data of:
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name, date of birth, nationality, government-issued ID | You (during onboarding / KYC) |
| Contact data | Email address, telephone number, postal address | You (enquiry form, contract) |
| Jurisdictional data | Residence, citizenship(s), tax residence(s), US / Canada exposure indicators | You (Client Jurisdictional Warranty, HEX-06) |
| Financial data | Cryptocurrency wallet addresses, transaction hashes, asset values, payment method | You; on-chain public sources |
| KYC / AML data | Proof of address, source-of-funds documentation, source-of-wealth documentation, sanctions screening results, PEP status | You + third-party verification providers + sanctions databases |
| Vulnerability data | Information voluntarily disclosed about health, life events (bereavement, scam victimisation, divorce), financial pressure, capability needs — only to the extent needed to provide reasonable adjustments under our Client Vulnerability Policy | You (Vulnerability Indicators Checklist, CVP-02) + observed indicators |
| Conflict-screening data | Identities of counterparties, intermediaries and other persons relevant to a conflict-of-interest screen | You (Conflict of Interest Declaration Form, COI-02) + investigation |
| Communications data | Emails, messages, meeting notes, call records (with consent) | Our correspondence with you |
| Case data | Engagement notes, investigation findings, evidence files, deliverables, expert opinions | You + our investigation |
| Heir-discovery data | Bona Vacantia estate references; genealogical records; alleged heir contact information | UK Government Legal Department Bona Vacantia public list; public genealogical records; you (where you contact us as a potential heir) |
| Property-sourcing data | Property addresses, UPRN, Land Registry data, planning records, public auction records | Public registers; published intelligence sources |
| Technical data | IP address, browser type, device data, pages visited, cookies | Automatically via the Site |
| Usage data | How you navigate and use the Site | Automatically via the Site |
| Whistleblowing disclosure data | Identity (where disclosed); content of disclosure; supporting evidence | You, via the channels described in §18 |
We do not actively seek special category data. Where such data is incidentally or voluntarily processed, we rely on the following lawful bases:
An Appropriate Policy Document is maintained in respect of all substantial-public-interest and criminal-offence processing, as required by DPA 2018, Schedule 1, Part 4.
Our investigative work routinely involves processing personal data relating to criminal convictions, offences and alleged offences (including theft, fraud, money laundering, sanctions evasion, and matters relating to deceased persons in the context of heir discovery). For such processing we rely on:
In the course of our services we may process personal data of individuals who are not our Clients. This applies in three distinct contexts:
We may process personal data of counterparties to suspect transactions, recipients of misappropriated funds, beneficial owners disclosed by Clients, or other persons identified through chain-analysis or open-source intelligence.
We may process personal data of: (a) deceased persons whose estates appear on the UK Government Legal Department Bona Vacantia unclaimed estates list; (b) potential heirs identified through genealogical research; (c) family members and relatives identified as part of an estate-mapping exercise. Sources include the published Bona Vacantia list, the General Register Office records, public genealogical databases, and (with their consent) potential heirs themselves.
We may process personal data of property owners identified through public registers (HM Land Registry, Companies House, planning records, EPC public datasets, Council registers) for the limited purpose of evaluating motivated-seller signals and considering outreach.
Where direct notification of such third parties under Article 14 UK GDPR is impossible, would involve disproportionate effort, would prejudice the investigation, or is otherwise exempt under Article 14(5)(b), (c) or (d) UK GDPR, we rely on those exemptions and do not provide individual notice. We document our reliance on such exemptions and conduct a balancing assessment.
Where outreach to a third party is contemplated (e.g. a potential heir we have identified; a motivated seller we may wish to approach), we apply the principles of necessity, proportionality and minimisation. We do not retain heir-discovery research or property-sourcing intelligence on third parties beyond the periods set out in §12.
| Purpose | Lawful Basis (UK GDPR Art. 6) |
|---|---|
| Providing and managing our Services to you | Performance of a contract — Art. 6(1)(b) |
| Identity verification and KYC/AML compliance | Legal obligation — Art. 6(1)(c) (MLR 2017) |
| Sanctions screening | Legal obligation — Art. 6(1)(c) (SAMLA 2018, UK OFSI consolidated list) |
| Conflict-of-interest screening | Legitimate interests — Art. 6(1)(f); integrity of professional service (CoI-01) |
| Vulnerability screening and reasonable adjustments | Legitimate interests — Art. 6(1)(f); Equality Act 2010 reasonable adjustments duty |
| Jurisdictional (US / Canada) screening for PI cover compliance | Legitimate interests — Art. 6(1)(f); preservation of professional indemnity cover (HEX-01) |
| Detection and prevention of fraud and unlawful acts | Legitimate interests — Art. 6(1)(f) |
| Submission of Suspicious Activity Reports to the National Crime Agency | Legal obligation — Art. 6(1)(c) (POCA 2002 ss.327–330) |
| Responding to your enquiries | Legitimate interests — Art. 6(1)(f) |
| Sending service-related communications | Performance of a contract — Art. 6(1)(b) |
| Receiving and handling whistleblowing disclosures | Legal obligation — Art. 6(1)(c) (PIDA 1998); legitimate interests — Art. 6(1)(f) (integrity of the company) |
| Heir-discovery research (Arcana Heritage) | Legitimate interests — Art. 6(1)(f) (commercial heir-hunting); subject to balancing test for non-client third parties |
| Property-sourcing intelligence (Arcana Property) | Legitimate interests — Art. 6(1)(f) (commercial sourcing); subject to balancing test for property owners |
| Improving the Site and our Services (aggregated/anonymised analysis) | Legitimate interests — Art. 6(1)(f) |
| Establishing, exercising or defending legal claims | Legitimate interests — Art. 6(1)(f); Art. 9(2)(f) where applicable |
| Direct marketing of our own services | Consent — Art. 6(1)(a) for individuals; legitimate interests — Art. 6(1)(f) for B2B soft opt-in (PECR Reg. 22(3)) |
We do not engage in data selling, data brokering or behavioural advertising as defined under applicable law.
We use automated tools to support sanctions screening, PEP screening, KYC verification, blockchain risk-scoring, and (in Arcana Property) lead-signal scoring against public datasets. These tools may produce automated outputs (e.g. a risk score, a sanctions match alert, or a lead-tier label).
However, no decision producing legal or similarly significant effects is taken solely by automated means. All automated outputs are reviewed by a human before any onboarding, refusal, suspension, termination or outreach decision is taken. You have the right to obtain human intervention, express your point of view and contest any decision affecting you.
We share personal data only where necessary, with the following categories of recipient. Our material processor and recipient list is reviewed at least annually and on any onboarding of a new processor.
| Recipient Category | Examples (current or potential) | Role and basis |
|---|---|---|
| Identity verification providers | Onfido, Veriff, Sumsub | Processor — Art. 28 UK GDPR contract |
| Blockchain analytics providers | Chainalysis, Elliptic, TRM Labs | Independent controller (re: their attribution datasets) and / or Processor (re: specific lookups commissioned by us) |
| Scam-database providers | Chainabuse, CryptoScamDB, BitcoinWhosWho | Independent controller of their published data; we are recipient by API lookup |
| Cloud and IT service providers | ProtonMail (email), local on-premise hosting (case files), Cloudflare (Site DNS / CDN), occasional encrypted-cloud backup providers | Processor — Art. 28 UK GDPR contract; UK / EEA primary; US sub-processors only with Art. 46 safeguards |
| Professional advisers | Kaur Maxwell, Edmonds Marshall McMahon, Go Legal, accountants, insurance broker | Independent controllers, bound by professional confidentiality |
| Insurer (Professional Indemnity) | Hiscox (Policy PL-PSC10003926034/00) | Independent controller — data shared for the purposes of notification, claim handling, renewal, or coverage clearance under HEX-01 |
| Regulators and law enforcement | HMRC, ICO, FCA, National Crime Agency, UK OFSI, foreign equivalents where applicable | Independent controllers — disclosure as required by law (including SARs / DAMLs) |
| Courts and tribunals | Civil and criminal courts in any relevant jurisdiction (excluding USA and Canada per HEX-01) | Independent controllers — disclosure for legal proceedings, expert reports under CPR Part 35 / CrimPR Part 19 |
| Whistleblowing prescribed persons | SFO, NCA, FCA, ICO, HMRC, City of London Police, others under the Public Interest Disclosure (Prescribed Persons) Order 2014 | Independent controllers — disclosure where the discloser is a "worker" under ERA 1996 and the disclosure is to a prescribed external recipient |
| UK Government Legal Department (heir discovery) | Government Legal Department, HM Treasury Solicitor (in respect of Bona Vacantia estates) | Independent controller — communications regarding identified heirs |
An up-to-date list of our material sub-processors is available on written request to the contact in §1.1.
Where personal data is transferred outside the United Kingdom, we rely on one or more of the following lawful transfer mechanisms under Articles 44–49 UK GDPR:
Where a service provider may process data through the United States or other non-UK jurisdictions, we conduct a transfer risk assessment ("TRA") and implement appropriate supplementary measures where required, in line with ICO guidance.
The Site uses cookies and similar technologies. We obtain your consent before placing any non-essential cookies, in accordance with PECR Regulation 6.
| Cookie | Purpose | Duration |
|---|---|---|
| Session / security cookies | Maintain session integrity, CSRF protection, basic Site functionality | Session (deleted on browser close) |
| Cookie-consent record | Records your cookie preferences so we do not ask repeatedly | 12 months |
The Site does not currently use analytics, performance, advertising or social-media cookies. Should we introduce any in the future, this Policy and our cookie banner will be updated accordingly, and your prior consent will be sought.
You can manage cookie preferences at any time through your browser settings or our cookie banner. Disabling strictly necessary cookies may impair Site functionality.
We will only send you direct marketing where: (a) you have given prior consent; or (b) you are an existing or recent business client and the marketing relates to similar Services, in reliance on the "soft opt-in" under PECR Regulation 22(3).
Every marketing email we send contains a clear and free-of-charge unsubscribe link. You may also withdraw marketing consent at any time by emailing us at the contact in §1.1.
Where you have been identified as a vulnerable customer (see §15), we do not subject you to follow-up marketing unless you specifically opt in.
| Data Type | Retention Period | Basis |
|---|---|---|
| KYC / AML records | 5 years from end of engagement | MLR 2017 reg. 40 |
| Contract and financial records | 6 years from end of engagement | Limitation Act 1980 / tax records |
| Case files, deliverables, evidence | 6 years from end of engagement; 20 years for matters involving litigation, expert evidence or capacity findings | Establishment, exercise or defence of legal claims; long civil tail on expert and capacity matters |
| Vulnerability and reasonable-adjustment records | 6 years from end of engagement; 20 years where a capacity assessment was performed | Defence of claims; CVP-01 cl.14 retention |
| Conflict-of-interest records | 6 years from end of engagement; 20 years where the work product was used in litigation | Defence of claims; CoI-01 cl.12 retention |
| Jurisdictional warranties (HEX-06) | Indefinite (long PI claim tail) | HEX-01 cl.12 retention |
| Whistleblowing disclosure records | 6 years; longer where investigation is ongoing or litigation is reasonably foreseeable | PIDA 1998 framework; WB-01 retention |
| Heir-discovery research records | 3 years from last contact with the potential heir; 6 years where an engagement followed | Legitimate interests; limitation |
| Property-sourcing intelligence (third-party data) | 12 months from collection where no engagement results; 6 years where engagement results | Necessity and minimisation |
| Marketing data (where consent-based) | Until consent withdrawn or 24 months of inactivity | Consent / legitimate interests |
| Communications | 3 years from last contact | Legitimate interests |
| Technical / website logs | 12 months | Legitimate interests / security |
After the applicable retention period, data is securely deleted, destroyed or anonymised. See §14 for the technical destruction controls.
You have the following rights regarding your personal data:
To exercise any right, email us at legal@arcana-crypto.com or write to the postal address in §1.1.
We may ask you to verify your identity before responding (for example, by providing a copy of identification document) under Article 12(6) UK GDPR. This protects your data from unauthorised disclosure.
We will respond within one calendar month of receiving a valid request. Where requests are complex or numerous, we may extend this period by up to two further months and will notify you within the first month, in accordance with Article 12(3) UK GDPR.
If you have been identified as a vulnerable customer (§15) and require reasonable adjustments to exercise these rights (e.g. large print, alternative communication channel, Italian-language correspondence, presence of a Trusted Person), please tell us when you write — we will accommodate.
You have the right to lodge a complaint with the ICO:
If you are resident outside the United Kingdom, you may additionally lodge a complaint with the data protection supervisory authority in your country of residence (for example, the Garante per la Protezione dei Dati Personali in Italy, the CNIL in France, the BfDI in Germany, the AEPD in Spain, the Irish DPC, etc.).
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. As at the date of this Policy, the operational controls in place include:
arcana_clients.db is encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256), with the key derived from a master password held only by the Sole Director, using PBKDF2-HMAC-SHA256 with 600,000 iterations and a per-installation salt. The database is auto-decrypted into a working copy only while the application is open, and is securely re-encrypted on exit.recovered_secure/ in Fernet-encrypted form using the same key-derivation regime.requirements.txt) with no runtime installation, to mitigate supply-chain risk.No method of transmission over the internet is 100% secure. In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and inform you without undue delay where required by Article 34 UK GDPR.
We operate a Client Vulnerability Policy (CVP-01) reflecting the framework set out by the Financial Conduct Authority in Finalised Guidance FG21/1 ("Guidance for firms on the fair treatment of vulnerable customers", February 2021). The Policy is adopted by analogy (we are not FCA-authorised) because the matters our clients bring to us — lost wallets, scam victimisation, bereavement-related crypto inheritance, divorce-related disputes — structurally produce vulnerable circumstances.
Information you share with us about your circumstances (health, life events, financial pressure, capability needs) is treated as sensitive. We process it under Article 9(2)(a) consent — you control whether to share it — and only to the extent needed to provide reasonable adjustments. It is recorded in a Reasonable Adjustments Log (CVP-03), kept under the same encryption controls as the SAR Register and accessible only to the Sole Director acting as Data Protection Lead.
Email legal@arcana-crypto.com with a short note (no medical or sensitive detail required) about what would help. Examples: "please send me documents in 14-point Arial as my eyesight is poor"; "please copy my son on correspondence as we are doing this together"; "please write to me in Italian where possible"; "please give me an extra week between sending and asking me to sign". We will accommodate without question.
We operate a written Conflict of Interest Policy (CoI-01) reflecting the spirit of SRA Principle 7 ("acting in the best interests of each client") and FCA Principle 8 ("Conflicts of Interest"), and the statutory framework of Companies Act 2006 ss.175–177 (director fiduciary duties).
Contact us at legal@arcana-crypto.com. Independently of contacting us, you have the right to seek independent advice from a solicitor or to lodge a complaint with the ICO (§13.2) where the conflict has data-protection implications.
Our professional indemnity insurance with Hiscox (Policy PL-PSC10003926034/00) excludes claims arising out of, or connected with, the United States of America and Canada. We do not currently accept engagements from clients resident in those territories, nor engagements where the deliverable is intended for use in courts, arbitrations or regulatory proceedings of those territories.
The full statement of our geographical limits is published at arcana-crypto.com/geographical-limits.html and is incorporated by reference into this Privacy Policy.
We operate a Whistleblowing Policy (WB-01) reflecting the Public Interest Disclosure Act 1998 (PIDA), the Employment Rights Act 1996 sections 43A–43L, the Worker Protection (Amendment of Equality Act 2010) Act 2023, and the Public Interest Disclosure (Prescribed Persons) Order 2014.
Subjects of disclosures retain their normal data-protection rights, subject to exemptions appropriate to investigations (DPA 2018 Schedule 2 Part 1 paragraphs 1–5 as applicable).
We operate a Business Continuity Plan (BCP-01) addressing operator-incapacity, key loss and disruption scenarios. This is materially relevant to data protection because the company is currently a sole-director operation; the disruption or death of the Sole Director would otherwise leave client data without an immediate steward.
If the Sole Director becomes incapacitated or dies, your personal data will not be immediately exposed or orphaned. The transition plan in BCP-01 Annex G is calibrated to the protection of client data as a priority. If you have a specific concern (e.g. you wish your data to be returned to your solicitor in such circumstances), tell us in writing and we will record the instruction in the engagement file.
Our Services are contractual in nature and provided only to persons aged eighteen (18) or over. Although the UK age of digital consent under DPA 2018 s.9 is thirteen (13), we do not knowingly collect personal data from any individual under 18. If you believe a minor has provided us with personal data, please contact us immediately and we will take appropriate steps to delete it.
We may update this Privacy Policy from time to time. The "Last updated" and Version fields at the top of this page will reflect any changes. Material changes will be communicated to active Clients by email and posted prominently on the Site. The Change Log at §23 summarises version-by-version what has changed.
Arcana Crypto LTD
12 Pullman Gardens, London, SW15 3DF, United Kingdom
Company Number: 16371124 | ICO Registration: ZC133290
Data protection enquiries: legal@arcana-crypto.com
Whistleblowing channel: whistleblowing@arcana-crypto.com
Website: arcana-crypto.com
| Version | Date | Changes |
|---|---|---|
| 1.0 | ~April 2024 | Initial Privacy Policy. |
| 1.1 | 25 April 2026 | Comprehensive rewrite for UK GDPR / DPA 2018 / PECR alignment; introduction of cookie controls; clarification of automated decision-making position; addition of international transfer mechanisms; ICO registration shown. |
| 1.2 | 20 May 2026 |
Aligned with the Tier 2 governance pack (issued 29 April — 3 May 2026) and the pre-primo-cliente Ultra Pack (20 May 2026):
|