← Back to Privacy Policy

1.4 Sensitive Personal Information

This section outlines how RaiseIt identifies, collects, processes, secures, and manages sensitive personal information in strict compliance with global data protection frameworks, including GDPR, CCPA/CPRA, and applicable financial regulatory standards.

1.4.1 Definition & Scope

For the purposes of RaiseIt's data governance, “Sensitive Personal Information” refers to data that, if compromised, could result in significant identity theft, financial loss, unauthorized account access, or personal harm. This explicitly includes:

🔒 Strict Necessity Principle

RaiseIt only collects sensitive personal information when legally mandated, explicitly consented to by you, or essential for core platform operations (e.g., KYC/AML compliance, payout processing, fraud prevention, and age/identity verification).

1.4.2 Collection & Lawful Basis

We collect sensitive data through secure, encrypted channels under the following lawful bases:

Data TypeCollection MethodLawful Basis / Purpose
Payment & Payout DetailsPCI-DSS Compliant GatewaysContractual Necessity (Fund Processing)
Government ID / KYCVerified Upload PortalLegal Obligation (Anti-Money Laundering)
Authentication CredentialsAccount Setup & Security SettingsLegitimate Interest (Fraud Prevention)
Biometric DataOptional Face/Scan VerificationExplicit Consent (Enhanced Security)

1.4.3 Security & Protection Measures

All sensitive personal information is safeguarded using enterprise-grade infrastructure:

1.4.4 Your Rights & Controls

Depending on your jurisdiction, you retain the right to:

To exercise these rights, navigate to Settings → Privacy & Security in your RaiseIt dashboard, or submit a formal request to our Data Protection Officer.

1.4.5 Incident Response & Notification

In the event of a security breach affecting sensitive personal information, RaiseIt will:

Questions about your sensitive data?

Our Privacy & Compliance team is available to assist you securely.

Contact Data Protection Team →