1.4 Sensitive Personal Information
This section outlines how RaiseIt identifies, collects, processes, secures, and manages sensitive personal information in strict compliance with global data protection frameworks, including GDPR, CCPA/CPRA, and applicable financial regulatory standards.
1.4.1 Definition & Scope
For the purposes of RaiseIt's data governance, “Sensitive Personal Information” refers to data that, if compromised, could result in significant identity theft, financial loss, unauthorized account access, or personal harm. This explicitly includes:
- Payment credentials, bank routing/account numbers, and cryptocurrency wallet addresses
- Government-issued identification (e.g., SSN, Passport, Driver’s License, Tax ID)
- Biometric identifiers (where voluntarily submitted for enhanced verification)
- Authentication tokens, security credentials, and recovery codes
- Protected characteristics (health status, religious/political beliefs) if disclosed in campaign or profile content
🔒 Strict Necessity Principle
RaiseIt only collects sensitive personal information when legally mandated, explicitly consented to by you, or essential for core platform operations (e.g., KYC/AML compliance, payout processing, fraud prevention, and age/identity verification).
1.4.2 Collection & Lawful Basis
We collect sensitive data through secure, encrypted channels under the following lawful bases:
| Data Type | Collection Method | Lawful Basis / Purpose |
|---|---|---|
| Payment & Payout Details | PCI-DSS Compliant Gateways | Contractual Necessity (Fund Processing) |
| Government ID / KYC | Verified Upload Portal | Legal Obligation (Anti-Money Laundering) |
| Authentication Credentials | Account Setup & Security Settings | Legitimate Interest (Fraud Prevention) |
| Biometric Data | Optional Face/Scan Verification | Explicit Consent (Enhanced Security) |
1.4.3 Security & Protection Measures
All sensitive personal information is safeguarded using enterprise-grade infrastructure:
- Encryption: AES-256 at rest and TLS 1.3 in transit across all endpoints
- Tokenization: Raw payment data is never stored on our servers; it is replaced with secure, non-reversible tokens
- Access Controls: Role-based permissions, mandatory MFA for internal systems, and real-time audit logging
- Data Minimization: We retain sensitive data only as long as legally required or necessary for transaction fulfillment, after which it is securely purged or anonymized
1.4.4 Your Rights & Controls
Depending on your jurisdiction, you retain the right to:
- Access, verify, or request deletion of your sensitive personal information
- Restrict or object to its processing where legally permitted
- Request data portability in a structured, machine-readable format
- Withdraw consent at any time (where processing relies on explicit consent)
- Opt out of sensitive data sharing with third-party processors for marketing or analytics
To exercise these rights, navigate to Settings → Privacy & Security in your RaiseIt dashboard, or submit a formal request to our Data Protection Officer.
1.4.5 Incident Response & Notification
In the event of a security breach affecting sensitive personal information, RaiseIt will:
- Contain, investigate, and assess the incident within 24 hours
- Notify affected users and relevant regulatory authorities within legally mandated timeframes
- Provide transparent, actionable communication including remediation steps, fraud monitoring options, and account security upgrades