Drafted against NDPR (Nigeria), PIPEDA (Canada) and GDPR principles · Data Protection Officer: [email protected]
| Product | Data | Lawful basis |
|---|---|---|
| Bolrach ID | name (first/middle/last), sex, date of birth, email, phone, verification result | contract · legal obligation (KYC) |
| Payments | transactions, payout accounts, device signals for fraud | contract · legal obligation (AML) · legitimate interest (fraud) |
| Mail / Workspace | your content — never scanned, never profiled | contract only |
| Sites / Store / Stream | your published content, buyer records you control | contract · you act as controller for your buyers |
| Analytics | first-party events, joined only after sign-in or payment | legitimate interest · consent where required |
| Ads | contextual serving data · no cross-site profiles, ever | legitimate interest |
| Transaction and ledger records | 7 years · financial-records law |
| KYC files | 5 years after relationship ends · AML law |
| Mail and files you delete | 30-day recovery window, then gone |
| Guard event detail | 90 days, then aggregates only |
| Closed-account data | export offered, then minimised to legal holds only |
Each request is acknowledged with a case number and answered within 30 days. Escalation: [email protected], then your data-protection authority.