Privacy Policy

Version: 1.2  |  Last updated: 20 May 2026  |  Supersedes: v1.1 (25 April 2026)  |  ICO Registration: ZC133290

This Privacy Policy explains how Arcana Crypto LTD collects, uses, shares and protects personal data. It is issued in compliance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR). Defined terms used in our Master Services Agreement (Terms of Engagement & Service Agreement v1.3) have the same meaning here.
What changed in v1.2 (20 May 2026): new sections covering vulnerable customers (§15), conflicts of interest disclosure (§16), geographical limits and Hiscox PI exclusion (§17), whistleblowing channel (§18), and Business Continuity / Director Incapacity (§19). Updated §14 (security) with the precise post-audit cryptographic controls. Updated processor list (§8) and international transfers (§9) to reflect Hiscox PI. Added Heir Discovery workstream (Arcana Heritage) to §5 (third-party data) scope. Full change log at §23.

1. Who We Are and Data Controller

Arcana Crypto LTD ("Arcana", "we", "us", "our") is a private limited company incorporated in England and Wales, Company Number 16371124, with registered office at 12 Pullman Gardens, London, SW15 3DF, United Kingdom.

We act as Data Controller for the personal data described in this Policy and are registered with the Information Commissioner's Office (ICO) under registration reference ZC133290.

We provide cryptocurrency wallet recovery, blockchain forensic investigation, security consulting, and related digital-asset services under the brand Arcana Crypto. We are also developing two additional workstreams — Arcana Heritage (heir-discovery research) and Arcana Property (property-sourcing intelligence) — which are not yet accepting clients. References to those workstreams in this Policy describe activities that are in development or limited internal testing only; no client data is currently processed under those workstreams. This Policy applies to data processed through arcana-crypto.com (the "Site") and through our engagement with you as a Client or prospective Client across all our workstreams.

1.1 Data Protection contact

We have not appointed a statutory Data Protection Officer because our processing activities do not meet the mandatory criteria under Article 37 UK GDPR. The single point of contact for all data protection enquiries, requests and complaints is the Sole Director acting in the role of Data Protection Lead:

Email: legal@arcana-crypto.com (primary)  |  legal@arcana-crypto.com (operational alternative)
Postal: Data Protection Enquiries, Arcana Crypto LTD, 12 Pullman Gardens, London, SW15 3DF, United Kingdom

2. Scope

This Policy covers personal data of:

3. What Personal Data We Collect

CategoryExamplesSource
Identity dataFull name, date of birth, nationality, government-issued IDYou (during onboarding / KYC)
Contact dataEmail address, telephone number, postal addressYou (enquiry form, contract)
Jurisdictional dataResidence, citizenship(s), tax residence(s), US / Canada exposure indicatorsYou (Client Jurisdictional Warranty, HEX-06)
Financial dataCryptocurrency wallet addresses, transaction hashes, asset values, payment methodYou; on-chain public sources
KYC / AML dataProof of address, source-of-funds documentation, source-of-wealth documentation, sanctions screening results, PEP statusYou + third-party verification providers + sanctions databases
Vulnerability dataInformation voluntarily disclosed about health, life events (bereavement, scam victimisation, divorce), financial pressure, capability needs — only to the extent needed to provide reasonable adjustments under our Client Vulnerability PolicyYou (Vulnerability Indicators Checklist, CVP-02) + observed indicators
Conflict-screening dataIdentities of counterparties, intermediaries and other persons relevant to a conflict-of-interest screenYou (Conflict of Interest Declaration Form, COI-02) + investigation
Communications dataEmails, messages, meeting notes, call records (with consent)Our correspondence with you
Case dataEngagement notes, investigation findings, evidence files, deliverables, expert opinionsYou + our investigation
Heir-discovery dataBona Vacantia estate references; genealogical records; alleged heir contact informationUK Government Legal Department Bona Vacantia public list; public genealogical records; you (where you contact us as a potential heir)
Property-sourcing dataProperty addresses, UPRN, Land Registry data, planning records, public auction recordsPublic registers; published intelligence sources
Technical dataIP address, browser type, device data, pages visited, cookiesAutomatically via the Site
Usage dataHow you navigate and use the SiteAutomatically via the Site
Whistleblowing disclosure dataIdentity (where disclosed); content of disclosure; supporting evidenceYou, via the channels described in §18

4. Special Category Data and Criminal Offence Data

4.1 Special Category Data (Article 9 UK GDPR)

We do not actively seek special category data. Where such data is incidentally or voluntarily processed, we rely on the following lawful bases:

An Appropriate Policy Document is maintained in respect of all substantial-public-interest and criminal-offence processing, as required by DPA 2018, Schedule 1, Part 4.

4.2 Criminal Offence Data (Article 10 UK GDPR)

Our investigative work routinely involves processing personal data relating to criminal convictions, offences and alleged offences (including theft, fraud, money laundering, sanctions evasion, and matters relating to deceased persons in the context of heir discovery). For such processing we rely on:

5. Personal Data of Third Parties (Article 14 UK GDPR)

In the course of our services we may process personal data of individuals who are not our Clients. This applies in three distinct contexts:

5.1 Blockchain forensic investigations and crypto recovery

We may process personal data of counterparties to suspect transactions, recipients of misappropriated funds, beneficial owners disclosed by Clients, or other persons identified through chain-analysis or open-source intelligence.

5.2 Heir Discovery (Arcana Heritage)

We may process personal data of: (a) deceased persons whose estates appear on the UK Government Legal Department Bona Vacantia unclaimed estates list; (b) potential heirs identified through genealogical research; (c) family members and relatives identified as part of an estate-mapping exercise. Sources include the published Bona Vacantia list, the General Register Office records, public genealogical databases, and (with their consent) potential heirs themselves.

5.3 Property Sourcing (Arcana Property)

We may process personal data of property owners identified through public registers (HM Land Registry, Companies House, planning records, EPC public datasets, Council registers) for the limited purpose of evaluating motivated-seller signals and considering outreach.

5.4 Article 14 exemptions

Where direct notification of such third parties under Article 14 UK GDPR is impossible, would involve disproportionate effort, would prejudice the investigation, or is otherwise exempt under Article 14(5)(b), (c) or (d) UK GDPR, we rely on those exemptions and do not provide individual notice. We document our reliance on such exemptions and conduct a balancing assessment.

Where outreach to a third party is contemplated (e.g. a potential heir we have identified; a motivated seller we may wish to approach), we apply the principles of necessity, proportionality and minimisation. We do not retain heir-discovery research or property-sourcing intelligence on third parties beyond the periods set out in §12.

6. How and Why We Use Your Data

PurposeLawful Basis (UK GDPR Art. 6)
Providing and managing our Services to youPerformance of a contract — Art. 6(1)(b)
Identity verification and KYC/AML complianceLegal obligation — Art. 6(1)(c) (MLR 2017)
Sanctions screeningLegal obligation — Art. 6(1)(c) (SAMLA 2018, UK OFSI consolidated list)
Conflict-of-interest screeningLegitimate interests — Art. 6(1)(f); integrity of professional service (CoI-01)
Vulnerability screening and reasonable adjustmentsLegitimate interests — Art. 6(1)(f); Equality Act 2010 reasonable adjustments duty
Jurisdictional (US / Canada) screening for PI cover complianceLegitimate interests — Art. 6(1)(f); preservation of professional indemnity cover (HEX-01)
Detection and prevention of fraud and unlawful actsLegitimate interests — Art. 6(1)(f)
Submission of Suspicious Activity Reports to the National Crime AgencyLegal obligation — Art. 6(1)(c) (POCA 2002 ss.327–330)
Responding to your enquiriesLegitimate interests — Art. 6(1)(f)
Sending service-related communicationsPerformance of a contract — Art. 6(1)(b)
Receiving and handling whistleblowing disclosuresLegal obligation — Art. 6(1)(c) (PIDA 1998); legitimate interests — Art. 6(1)(f) (integrity of the company)
Heir-discovery research (Arcana Heritage)Legitimate interests — Art. 6(1)(f) (commercial heir-hunting); subject to balancing test for non-client third parties
Property-sourcing intelligence (Arcana Property)Legitimate interests — Art. 6(1)(f) (commercial sourcing); subject to balancing test for property owners
Improving the Site and our Services (aggregated/anonymised analysis)Legitimate interests — Art. 6(1)(f)
Establishing, exercising or defending legal claimsLegitimate interests — Art. 6(1)(f); Art. 9(2)(f) where applicable
Direct marketing of our own servicesConsent — Art. 6(1)(a) for individuals; legitimate interests — Art. 6(1)(f) for B2B soft opt-in (PECR Reg. 22(3))

We do not engage in data selling, data brokering or behavioural advertising as defined under applicable law.

7. Automated Decision-Making and Profiling (Article 22 UK GDPR)

We use automated tools to support sanctions screening, PEP screening, KYC verification, blockchain risk-scoring, and (in Arcana Property) lead-signal scoring against public datasets. These tools may produce automated outputs (e.g. a risk score, a sanctions match alert, or a lead-tier label).

However, no decision producing legal or similarly significant effects is taken solely by automated means. All automated outputs are reviewed by a human before any onboarding, refusal, suspension, termination or outreach decision is taken. You have the right to obtain human intervention, express your point of view and contest any decision affecting you.

8. Who We Share Your Data With

We share personal data only where necessary, with the following categories of recipient. Our material processor and recipient list is reviewed at least annually and on any onboarding of a new processor.

Recipient CategoryExamples (current or potential)Role and basis
Identity verification providersOnfido, Veriff, SumsubProcessor — Art. 28 UK GDPR contract
Blockchain analytics providersChainalysis, Elliptic, TRM LabsIndependent controller (re: their attribution datasets) and / or Processor (re: specific lookups commissioned by us)
Scam-database providersChainabuse, CryptoScamDB, BitcoinWhosWhoIndependent controller of their published data; we are recipient by API lookup
Cloud and IT service providersProtonMail (email), local on-premise hosting (case files), Cloudflare (Site DNS / CDN), occasional encrypted-cloud backup providersProcessor — Art. 28 UK GDPR contract; UK / EEA primary; US sub-processors only with Art. 46 safeguards
Professional advisersKaur Maxwell, Edmonds Marshall McMahon, Go Legal, accountants, insurance brokerIndependent controllers, bound by professional confidentiality
Insurer (Professional Indemnity)Hiscox (Policy PL-PSC10003926034/00)Independent controller — data shared for the purposes of notification, claim handling, renewal, or coverage clearance under HEX-01
Regulators and law enforcementHMRC, ICO, FCA, National Crime Agency, UK OFSI, foreign equivalents where applicableIndependent controllers — disclosure as required by law (including SARs / DAMLs)
Courts and tribunalsCivil and criminal courts in any relevant jurisdiction (excluding USA and Canada per HEX-01)Independent controllers — disclosure for legal proceedings, expert reports under CPR Part 35 / CrimPR Part 19
Whistleblowing prescribed personsSFO, NCA, FCA, ICO, HMRC, City of London Police, others under the Public Interest Disclosure (Prescribed Persons) Order 2014Independent controllers — disclosure where the discloser is a "worker" under ERA 1996 and the disclosure is to a prescribed external recipient
UK Government Legal Department (heir discovery)Government Legal Department, HM Treasury Solicitor (in respect of Bona Vacantia estates)Independent controller — communications regarding identified heirs

An up-to-date list of our material sub-processors is available on written request to the contact in §1.1.

9. International Transfers

Where personal data is transferred outside the United Kingdom, we rely on one or more of the following lawful transfer mechanisms under Articles 44–49 UK GDPR:

Where a service provider may process data through the United States or other non-UK jurisdictions, we conduct a transfer risk assessment ("TRA") and implement appropriate supplementary measures where required, in line with ICO guidance.

Important interaction with our Geographical Limits (§17): Although we may use service providers based in the United States or Canada (subject to Article 46 safeguards), we do not accept engagements from clients resident in the United States or Canada, and we do not direct our services at those territories. The international transfers described in this section are sub-processor flows for the purpose of supporting our UK and EU clients; they are not the basis on which we contract with US / Canadian clients (we do not).

10. Cookies and Similar Technologies (PECR-compliant)

The Site uses cookies and similar technologies. We obtain your consent before placing any non-essential cookies, in accordance with PECR Regulation 6.

10.1 Strictly Necessary Cookies (no consent required)

CookiePurposeDuration
Session / security cookiesMaintain session integrity, CSRF protection, basic Site functionalitySession (deleted on browser close)
Cookie-consent recordRecords your cookie preferences so we do not ask repeatedly12 months

10.2 Analytics, Performance and Marketing Cookies

The Site does not currently use analytics, performance, advertising or social-media cookies. Should we introduce any in the future, this Policy and our cookie banner will be updated accordingly, and your prior consent will be sought.

You can manage cookie preferences at any time through your browser settings or our cookie banner. Disabling strictly necessary cookies may impair Site functionality.

11. Marketing Communications

We will only send you direct marketing where: (a) you have given prior consent; or (b) you are an existing or recent business client and the marketing relates to similar Services, in reliance on the "soft opt-in" under PECR Regulation 22(3).

Every marketing email we send contains a clear and free-of-charge unsubscribe link. You may also withdraw marketing consent at any time by emailing us at the contact in §1.1.

Where you have been identified as a vulnerable customer (see §15), we do not subject you to follow-up marketing unless you specifically opt in.

12. How Long We Keep Your Data

Data TypeRetention PeriodBasis
KYC / AML records5 years from end of engagementMLR 2017 reg. 40
Contract and financial records6 years from end of engagementLimitation Act 1980 / tax records
Case files, deliverables, evidence6 years from end of engagement; 20 years for matters involving litigation, expert evidence or capacity findingsEstablishment, exercise or defence of legal claims; long civil tail on expert and capacity matters
Vulnerability and reasonable-adjustment records6 years from end of engagement; 20 years where a capacity assessment was performedDefence of claims; CVP-01 cl.14 retention
Conflict-of-interest records6 years from end of engagement; 20 years where the work product was used in litigationDefence of claims; CoI-01 cl.12 retention
Jurisdictional warranties (HEX-06)Indefinite (long PI claim tail)HEX-01 cl.12 retention
Whistleblowing disclosure records6 years; longer where investigation is ongoing or litigation is reasonably foreseeablePIDA 1998 framework; WB-01 retention
Heir-discovery research records3 years from last contact with the potential heir; 6 years where an engagement followedLegitimate interests; limitation
Property-sourcing intelligence (third-party data)12 months from collection where no engagement results; 6 years where engagement resultsNecessity and minimisation
Marketing data (where consent-based)Until consent withdrawn or 24 months of inactivityConsent / legitimate interests
Communications3 years from last contactLegitimate interests
Technical / website logs12 monthsLegitimate interests / security

After the applicable retention period, data is securely deleted, destroyed or anonymised. See §14 for the technical destruction controls.

Note on the right to erasure: Where we have a legal obligation to retain data (in particular, KYC and AML records under MLR 2017 reg. 40, and PI-relevant records under our insurer's wording), we cannot erase that data until the statutory or insurance-driven retention period has expired. Other rights (such as restriction of processing) remain available in the meantime.

13. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

13.1 How to Exercise Your Rights

To exercise any right, email us at legal@arcana-crypto.com or write to the postal address in §1.1.

We may ask you to verify your identity before responding (for example, by providing a copy of identification document) under Article 12(6) UK GDPR. This protects your data from unauthorised disclosure.

We will respond within one calendar month of receiving a valid request. Where requests are complex or numerous, we may extend this period by up to two further months and will notify you within the first month, in accordance with Article 12(3) UK GDPR.

If you have been identified as a vulnerable customer (§15) and require reasonable adjustments to exercise these rights (e.g. large print, alternative communication channel, Italian-language correspondence, presence of a Trusted Person), please tell us when you write — we will accommodate.

13.2 Right to Complain

You have the right to lodge a complaint with the ICO:

If you are resident outside the United Kingdom, you may additionally lodge a complaint with the data protection supervisory authority in your country of residence (for example, the Garante per la Protezione dei Dati Personali in Italy, the CNIL in France, the BfDI in Germany, the AEPD in Spain, the Irish DPC, etc.).

14. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. As at the date of this Policy, the operational controls in place include:

14.1 Encryption at rest

14.2 Encryption in transit

14.3 Access controls

14.4 Integrity controls

14.5 Operational controls

No method of transmission over the internet is 100% secure. In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and inform you without undue delay where required by Article 34 UK GDPR.

15. Vulnerable Customers

We operate a Client Vulnerability Policy (CVP-01) reflecting the framework set out by the Financial Conduct Authority in Finalised Guidance FG21/1 ("Guidance for firms on the fair treatment of vulnerable customers", February 2021). The Policy is adopted by analogy (we are not FCA-authorised) because the matters our clients bring to us — lost wallets, scam victimisation, bereavement-related crypto inheritance, divorce-related disputes — structurally produce vulnerable circumstances.

15.1 What this means in practice

15.2 Vulnerability data and Article 9 UK GDPR

Information you share with us about your circumstances (health, life events, financial pressure, capability needs) is treated as sensitive. We process it under Article 9(2)(a) consent — you control whether to share it — and only to the extent needed to provide reasonable adjustments. It is recorded in a Reasonable Adjustments Log (CVP-03), kept under the same encryption controls as the SAR Register and accessible only to the Sole Director acting as Data Protection Lead.

15.3 How to ask for a reasonable adjustment

Email legal@arcana-crypto.com with a short note (no medical or sensitive detail required) about what would help. Examples: "please send me documents in 14-point Arial as my eyesight is poor"; "please copy my son on correspondence as we are doing this together"; "please write to me in Italian where possible"; "please give me an extra week between sending and asking me to sign". We will accommodate without question.

16. Conflicts of Interest

We operate a written Conflict of Interest Policy (CoI-01) reflecting the spirit of SRA Principle 7 ("acting in the best interests of each client") and FCA Principle 8 ("Conflicts of Interest"), and the statutory framework of Companies Act 2006 ss.175–177 (director fiduciary duties).

16.1 What this means in practice

16.2 If you believe a conflict has not been managed correctly

Contact us at legal@arcana-crypto.com. Independently of contacting us, you have the right to seek independent advice from a solicitor or to lodge a complaint with the ICO (§13.2) where the conflict has data-protection implications.

17. Geographical Limits and Hiscox PI Exclusion

Our professional indemnity insurance with Hiscox (Policy PL-PSC10003926034/00) excludes claims arising out of, or connected with, the United States of America and Canada. We do not currently accept engagements from clients resident in those territories, nor engagements where the deliverable is intended for use in courts, arbitrations or regulatory proceedings of those territories.

17.1 What this means in practice

17.2 The full position

The full statement of our geographical limits is published at arcana-crypto.com/geographical-limits.html and is incorporated by reference into this Privacy Policy.

18. Whistleblowing

We operate a Whistleblowing Policy (WB-01) reflecting the Public Interest Disclosure Act 1998 (PIDA), the Employment Rights Act 1996 sections 43A–43L, the Worker Protection (Amendment of Equality Act 2010) Act 2023, and the Public Interest Disclosure (Prescribed Persons) Order 2014.

18.1 How to make a disclosure

18.2 Data protection of whistleblowing disclosures

Subjects of disclosures retain their normal data-protection rights, subject to exemptions appropriate to investigations (DPA 2018 Schedule 2 Part 1 paragraphs 1–5 as applicable).

19. Business Continuity, Director Incapacity and Long-Term Data Stewardship

We operate a Business Continuity Plan (BCP-01) addressing operator-incapacity, key loss and disruption scenarios. This is materially relevant to data protection because the company is currently a sole-director operation; the disruption or death of the Sole Director would otherwise leave client data without an immediate steward.

19.1 What we have put in place

19.2 What this means for you

If the Sole Director becomes incapacitated or dies, your personal data will not be immediately exposed or orphaned. The transition plan in BCP-01 Annex G is calibrated to the protection of client data as a priority. If you have a specific concern (e.g. you wish your data to be returned to your solicitor in such circumstances), tell us in writing and we will record the instruction in the engagement file.

20. Children

Our Services are contractual in nature and provided only to persons aged eighteen (18) or over. Although the UK age of digital consent under DPA 2018 s.9 is thirteen (13), we do not knowingly collect personal data from any individual under 18. If you believe a minor has provided us with personal data, please contact us immediately and we will take appropriate steps to delete it.

21. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" and Version fields at the top of this page will reflect any changes. Material changes will be communicated to active Clients by email and posted prominently on the Site. The Change Log at §23 summarises version-by-version what has changed.

22. Contact Us

Arcana Crypto LTD
12 Pullman Gardens, London, SW15 3DF, United Kingdom
Company Number: 16371124  |  ICO Registration: ZC133290
Data protection enquiries: legal@arcana-crypto.com
Whistleblowing channel: whistleblowing@arcana-crypto.com
Website: arcana-crypto.com

23. Change Log

VersionDateChanges
1.0 ~April 2024 Initial Privacy Policy.
1.1 25 April 2026 Comprehensive rewrite for UK GDPR / DPA 2018 / PECR alignment; introduction of cookie controls; clarification of automated decision-making position; addition of international transfer mechanisms; ICO registration shown.
1.2 20 May 2026 Aligned with the Tier 2 governance pack (issued 29 April — 3 May 2026) and the pre-primo-cliente Ultra Pack (20 May 2026):
  • §1 + §3 added jurisdictional, vulnerability, conflict-screening and heir-discovery / property-sourcing data categories.
  • §4.1 added vulnerability data Article 9 basis (consent).
  • §5 expanded to cover Heir Discovery (Arcana Heritage) and Property Sourcing (Arcana Property) third-party data flows.
  • §6 added conflict-screening, vulnerability screening, jurisdictional screening, whistleblowing, and heir / property workstream purposes with corresponding lawful bases.
  • §8 added Hiscox PI insurer (as independent controller), expanded processor list with concrete vendors (ProtonMail, Cloudflare).
  • §9 added the interaction with §17 (Hiscox geographical limit) to clarify the distinction between sub-processor flows and client acceptance.
  • §12 expanded with retention periods for vulnerability, conflict, jurisdictional, whistleblowing, heir-discovery and property-sourcing data.
  • §14 replaced generic "AES-256" with the precise post-audit cryptographic controls (Fernet AES-128-CBC + HMAC-SHA256, PBKDF2 600,000 iterations; SQLite client DB encryption; subprocess secret handling; integrity controls; reference to the 3 May 2026 security audit).
  • §15 (new) — Vulnerable Customers.
  • §16 (new) — Conflicts of Interest disclosure.
  • §17 (new) — Geographical Limits and Hiscox PI Exclusion.
  • §18 (new) — Whistleblowing channel.
  • §19 (new) — Business Continuity, Director Incapacity, Long-Term Data Stewardship.
  • §22 added the whistleblowing email address; primary data-protection contact changed to legal@arcana-crypto.com.
  • §23 (this Change Log) added.