Last updated: 17 September 2026
This Privacy Policy explains how Trusty Digital Ltd handles personal data when you visit trusty.digital, create or use an account, complete an assessment, communicate with us, purchase a service, or use tokenisation, wallet, project or related functionality.
1. Who is responsible for your data
Trusty Digital Ltd is the controller of personal data covered by this Policy unless a specific service notice says otherwise. We are registered in England and Wales under company number 14672896 and our registered office is 124 City Road, London, England, EC1V 2NX. Privacy enquiries and rights requests can be sent to [email protected].
2. Personal data we may collect
- Account and contact data: name, email address, organisation, role, account identifiers and authentication information.
- Identity and verification data: information and evidence used for identity, organisation, sanctions, eligibility or similar checks where a service requires them.
- Assessment and project data: answers, project descriptions, asset information, declarations, reviewer notes, findings and reports. The current assessment flow does not include document-evidence upload or verification.
- Wallet and blockchain data: public wallet addresses, asset identifiers, transaction references and other public-ledger information associated with your use of a Service.
- Payment and commercial data: product purchased, payment status, invoices and transaction references. Payment-card data may be handled directly by a payment provider rather than stored by us.
- Technical and security data: IP address, browser and device information, timestamps, application logs, security events and session data.
- Usage and communications data: pages or features used, support correspondence, feedback, preferences and records of communications with us.
- Cookie and similar-technology data: as described in our Cookies Policy.
3. Where data comes from
We collect data directly from you, from people authorised to act for your organisation, from your use of the Services, from public blockchains and public sources, and from service providers such as identity-verification, payment, infrastructure or communications providers where appropriate.
4. Why we use personal data
- to create, secure and administer accounts;
- to provide assessments, reports, project workflows, wallet connectivity and other requested Services;
- to process purchases, invoices and customer support;
- to verify identity or organisation information and manage fraud, security and compliance risk;
- to operate, troubleshoot, monitor and improve our software and infrastructure;
- to communicate service messages and, where permitted, marketing communications;
- to establish, exercise or defend legal claims and comply with legal obligations.
5. Legal bases
Depending on the activity, we rely on one or more lawful bases under applicable UK data-protection law:
- Contract: where processing is necessary to provide a Service you request or take steps before entering into a contract.
- Legal obligation: where we must process information to meet legal or regulatory duties.
- Legitimate interests: including securing the Services, preventing fraud, supporting customers, improving operations and protecting legal rights, where those interests are not overridden by your rights.
- Consent: where the law requires consent, for example for certain optional storage/access technologies or marketing activities. You can withdraw consent for future processing.
If special-category or criminal-offence data is processed, we also rely on an additional condition permitted by law and apply appropriate safeguards.
6. Assessments and automated processing
Fit uses rules and scoring to generate an informational result. Readiness and Maturity use deterministic scoring together with professional review. The current assessment runtime does not use artificial-intelligence processing and is not intended to make solely automated decisions that produce legal or similarly significant effects on you. If that processing model changes, we will update this Policy and provide any information and safeguards required by law before the change is relied on.
7. Who we share data with
We may share personal data only where reasonably necessary with:
- cloud hosting, security, communications, analytics and software providers;
- identity-verification, payment and professional-service providers;
- professional advisers, auditors, insurers and prospective transaction advisers under appropriate confidentiality duties;
- courts, regulators, law-enforcement bodies or other authorities where required or legally justified; and
- a buyer, investor or successor in connection with a corporate transaction, subject to appropriate safeguards.
We do not sell personal data as a commodity.
8. Public blockchain data
Public blockchains are designed to preserve transaction records. If you use a public wallet address or authorise a blockchain transaction, information written to the ledger may be visible to anyone and may not be technically erasable by Trusty Digital. We minimise unnecessary linkage between public-ledger data and directly identifying account data, but we cannot alter the underlying properties of a public blockchain.
9. International transfers
Some providers may process personal data outside the United Kingdom. Where a restricted transfer occurs, we use a lawful transfer mechanism where required, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard.
10. Retention
We keep personal data for no longer than reasonably necessary for the purpose for which it was collected, taking account of the service relationship, legal and accounting requirements, security needs, dispute periods and the need to demonstrate compliance. Different records therefore have different retention periods. Where possible, data that no longer needs to identify you is deleted or anonymised.
11. Security
We use technical and organisational measures intended to protect personal data against accidental or unlawful loss, alteration, disclosure or access. Access is restricted according to role and business need. No online service can guarantee absolute security, so you should also protect passwords, devices, wallets and recovery information under your control.
12. Your rights
Subject to applicable law and any exemptions, you may have rights to be informed, access your personal data, correct inaccurate data, request erasure, restrict processing, object to certain processing, receive eligible data in a portable format, and withdraw consent where processing is based on consent. You may also have rights and safeguards relating to significant automated decisions.
To exercise a privacy right, email [email protected]. We may need information to verify your identity and scope the request. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
13. Children
The Services are intended for adults and business users. We do not knowingly offer accounts or tokenisation services to children under 18. If you believe a child has provided personal data to us, contact us so that we can assess and address it.
14. Cookies and similar technologies
We use storage and access technologies for essential functions and may use optional analytics technologies subject to the choices and legal requirements described in our Cookies Policy. The Cookies Policy explains categories, purposes and how to control optional technologies.
15. Changes to this Policy
We may update this Policy when our Services, providers or legal obligations change. The current version is published on this page with the date of the latest update. Material changes may also be communicated through the Site or account where appropriate.
16. Contact
Privacy questions and requests can be sent to [email protected] or by post to Trusty Digital Ltd, 124 City Road, London, England, EC1V 2NX.