Sensitive Data Processing Policy

How RaiseIt handles, protects, and complies with regulations regarding special category and sensitive personal information.

Last Updated: October 15, 2025

1. Scope & Definitions

This policy supplements the main RaiseIt Privacy Policy and specifically addresses how we handle sensitive personal data (also referred to as "special category data" under GDPR and "sensitive personal information" under CCPA/CPRA). Sensitive data requires a higher standard of protection due to its potential to cause significant harm if misused.

As a crowdfunding platform, we process sensitive data only when strictly necessary for campaign verification, fraud prevention, regulatory compliance, or with your explicit, informed consent.

2. Categories of Sensitive Data

We classify and protect the following data types as sensitive:

  • Financial & Payment Information: Bank account details, tax IDs, and transaction history required for payout verification and anti-money laundering (AML) compliance.
  • Government-Issued Identifiers: Passports, national IDs, or driver’s licenses submitted during identity verification (KYC).
  • Biometric Data: Optional facial recognition or fingerprint scans used solely for secure login or fraud prevention (if enabled).
  • Health & Medical Information: Voluntarily shared data for medical crowdfunding campaigns, strictly processed only with campaign creator authorization.
  • Location & Device Data: Precise GPS coordinates and device fingerprints used for fraud detection and geolocation-based compliance.
  • Criminal Records & Legal Proceedings: Processed only when required by law enforcement or regulatory authorities with proper legal documentation.
Important Notice: We do not process genetic data, philosophical beliefs, political opinions, or trade union membership unless explicitly required by applicable law or with explicit, documented consent.

3. How We Collect & Use It

Sensitive data is collected through:

  • Direct submission via secure forms during campaign setup or payout configuration.
  • Integrated third-party verification services (e.g., Stripe Identity, Sumsub, Onfido).
  • Automated security systems for fraud detection and account protection.

Usage is strictly limited to:

  1. Verifying identity to prevent fraud and meet financial regulations.
  2. Processing payouts securely to verified campaign creators.
  3. Complying with legal obligations (tax, AML, sanctions screening).
  4. Responding to legitimate law enforcement or regulatory requests.

5. Security & Safeguards

We implement industry-leading technical and organizational measures to protect sensitive data:

  • Encryption: AES-256 encryption at rest and TLS 1.3 in transit for all sensitive fields.
  • Access Controls: Role-based access, multi-factor authentication (MFA), and principle of least privilege.
  • Tokenization: Payment and identification data are tokenized; raw sensitive values are never stored on our primary databases.
  • Audits & Compliance: Regular third-party penetration testing, SOC 2 Type II compliance, and annual data protection impact assessments (DPIAs).
  • Incident Response: 72-hour breach notification protocol aligned with GDPR requirements.

6. Data Retention Periods

Sensitive data is retained only as long as necessary:

  • Active Campaigns: Retained for the duration of the campaign plus 12 months post-completion.
  • Financial/AML Records: Retained for 5 years post-account closure as required by financial regulations.
  • Identity Verification: Stored securely for 3 years or until account termination, whichever comes first.
  • Health/Medical Data: Deleted immediately upon campaign completion or upon written request from the data subject.

When retention periods expire, sensitive data is permanently erased using cryptographically secure deletion methods.

7. Third-Party Sharing & International Transfers

We never sell or rent sensitive data. Sharing occurs only with:

  • Payment Processors & Verification Partners: Bound by strict data processing agreements (DPAs) and ISO 27001 certification.
  • Legal Authorities: Only with valid subpoenas, court orders, or statutory requirements.
  • Service Providers: Cloud infrastructure, fraud detection, and customer support vendors operating under strict confidentiality clauses.

For international transfers, we rely on EU Standard Contractual Clauses (SCCs), Privacy Shield alternatives, and adequacy decisions to ensure equivalent protection levels worldwide.

8. Your Rights & Controls

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your sensitive data.
  • Restrict or object to specific processing activities.
  • Data portability (where technically feasible).
  • Withdraw consent at any time without affecting prior lawful processing.
  • Lodge a complaint with your local data protection authority.

Requests are processed within 30 days. Verification may be required to protect your privacy.

9. Contact & Data Protection Officer

For questions, concerns, or data subject requests regarding sensitive data handling:

📧

RaiseIt Data Protection Team

Email: dpo@raiseit.com
Phone: +1 (888) 555-0199 (Mon–Fri, 9AM–6PM EST)
Mailing: RaiseIt Inc., Privacy Compliance Dept., 100 Innovation Dr, San Francisco, CA 94105

🌍

EU/UK Representative

For GDPR inquiries, contact our appointed representative in Ireland via the email above or visit our contact portal.