Privacy Policy

Public Privacy Policy


Last Updated July 10, 2026 · Version 1.5

1. Introduction and Scope

AssetFynd Ltd. (“AssetFynd,” “we,” “us,” or “our”) provides an AI-powered platform and related services that help identify and facilitate the recovery of lost, dormant, unclaimed, or otherwise recoverable financial assets. We work primarily with individuals, corporations, partnerships, joint ventures, trusts, unincorporated organizations, associations, professional firms, insolvency practitioners, estate administration professionals, fiduciaries, advisory firms, charities, governments (or any department or agency thereof), strategic alliance partners, and other incorporated or unincorporated entities.

This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website, use our services, or interact with us, including as a client, strategic alliance partner, vendor, job applicant, or an individual whose information is processed in connection with an asset recovery matter (for example, as a claimant, beneficiary, estate representative, or authorized representative).

This Privacy Policy is intended to be consistent with AssetFynd’s internal privacy, security, and compliance governance framework. AssetFynd maintains supporting internal policies, procedures, and controls designed to protect personal information and comply with applicable legal and regulatory requirements.

2. Information We Collect

The personal information we collect depends on how you interact with us:

  • Website and contact information: name, email address, phone number, mailing address, company name, and the content of any message you send us.
  • Client, partner, and vendor information: business contact details, contracting entity information, and authorized representative or signatory information.
  • Asset recovery and claim-support information: where we are engaged directly or through a client or strategic alliance partner, we may process identity information, contact details, asset or account descriptions, entitlement and ownership records, and, where relevant to a specific matter, identity verification or KYC materials, estate or probate records, and financial account information.
  • Automatically collected information: IP address, browser and device characteristics, operating system, referring URLs, and usage data collected through cookies and similar technologies, as described in Section 9.
  • Employment information: for job applicants, employees, and contractors, information relevant to recruitment, onboarding, and engagement.

3. Sensitive Information

In connection with specific asset recovery matters, we may process categories of information considered sensitive in certain jurisdictions, including government identifiers (such as Social Security numbers, driver’s licenses, passports, or company-issued identifying documents, or equivalents) and financial account information. We process this information only where necessary to verify entitlement to a claim, support a client’s or partner’s claim compliance obligations, or comply with law, and we apply the heightened access, encryption, and retention controls described in our internal Security Policy and Data Privacy Policy to this category of information specifically, rather than treating it the same as ordinary contact information.

4. Our Role: When We Act as a Service Provider vs. When We Determine the Purpose of Processing

AssetFynd primarily provides business-to-business or business-to-fiduciary platform, asset search, asset-to-owner matching, reporting, and claim-support services to corporate clients and strategic alliance partners (such as unclaimed property consultants, insolvency practitioners, law firms, transfer agents, and asset holders, and other custodians). In those relationships, our client or partner typically determines the purpose and means of processing personal information relating to underlying asset owners, claimants, beneficiaries, or estates, and AssetFynd acts as a service provider or processor under the terms of the applicable agreement.

Where AssetFynd determines the purpose and means of processing personal information for its own purposes, for example, information about website visitors, job applicants, our own employees and contractors, or our direct clients and vendors, AssetFynd acts as a controller (or the equivalent role under applicable law) for that information.

If you are an individual whose information was provided to AssetFynd by a corporate client or strategic alliance partner in connection with a specific asset recovery matter, that client or partner is generally the appropriate first point of contact for exercising your privacy rights, though we will support and coordinate with them to respond to your request.

5. How We Use Personal Information

  • To provide, operate, and improve our website and services, including asset discovery, data matching, and claim-support workflows.
  • To communicate with clients, partners, vendors, and website visitors, including responding to inquiries.
  • To perform due diligence, sanctions and fraud screening, and other functions described in our AML, Sanctions, Fraud and Financial Crime Risk Policy.
  • To maintain the security of our systems and prevent fraud, consistent with our Security Policy.
  • To comply with legal, regulatory, contractual, and reporting obligations.
  • To manage recruitment, employment, and contractor relationships.

6. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)

Where applicable data protection law requires a legal basis for processing, we rely on one or more of the following:

  • Performance of a contract, where processing is necessary to provide services requested by a client, partner, or vendor.
  • Legitimate interests, where processing is necessary for asset matching, fraud and sanctions screening, security, or other business purposes, and is not outweighed by the individual’s interests or fundamental rights.
  • Legal obligation, where processing is necessary to comply with applicable law, including sanctions, anti-money laundering, and financial crime requirements.
  • Establishment, exercise, or defence of legal claims, where processing is necessary to investigate, pursue, defend, or resolve legal rights, claims, or disputes arising in connection with our services.
  • Consent, where we ask for and you provide consent for a specific purpose, which you may withdraw at any time.
  • Vital interests, in limited circumstances necessary to protect the life or safety of an individual.

7. How We Share Information

We do not sell personal information and do not share it for cross-context behavioral advertising. We may share personal information with:

  • Corporate clients and strategic alliance partners, where necessary to support an asset recovery matter, verification, or claim-support activity.
  • Asset holders, financial institutions, government agencies, courts, custodians, or other responsible institutions involved in a specific recovery, consistent with AssetFynd’s role as described in our AML, Sanctions, Fraud and Financial Crime Risk Policy.
  • Service providers and vendors who process information on our behalf under written agreements that require appropriate confidentiality and security protections, consistent with our internal vendor review process. This includes our website hosting provider (Squarespace), which also runs our website contact form, and our marketing and analytics providers (Google, for Tag Manager and Analytics, and HubSpot, for marketing automation), each of which processes limited categories of information as described in Section 9.
  • Professional advisors, regulators, or law enforcement, where required or permitted by law.
  • A successor entity in connection with a merger, acquisition, financing, or sale of business assets.

8. Artificial Intelligence and Automated Tools

AssetFynd’s platform uses AI and automation to support asset discovery, data matching, and workflow tasks. Any AI or automation tool that processes personal information on AssetFynd’s behalf must be an approved tool reviewed under our internal Corporate AI Usage Policy. Restricted information including claim documents, identity or KYC materials, and financial account information is not entered into general-purpose or unapproved AI tools, and any AI-assisted output relevant to a claim, entitlement, or identity determination is subject to human review before it is relied upon or communicated externally.

9. Cookies and Similar Technologies

We use cookies and similar technologies for the purposes described below. This list reflects the vendors and technologies currently used on our website, based on our most recent review of our website technologies, and will be updated as our technology stack changes.

Website hosting and platform analytics

Our website is hosted on Squarespace, which serves our core scripts, styles, and images, and separately collects first-party visitor and commerce analytics through its own platform (including its Census analytics endpoint). Squarespace also provides the cookie-consent banner used on our site and directly processes submissions made through our website contact form.

Fonts

We use Google Fonts to display website typography. Loading fonts involves a connection to Google’s font-delivery infrastructure, which may receive limited technical information such as IP address.

Analytics and tag management

We use Google Tag Manager to manage tracking scripts on our website, and Google Analytics (GA4) to understand website usage. Data collected includes IP address, device and browser information, and pages viewed.

Marketing and lead management

We use HubSpot for marketing automation and customer relationship management, including tracking website visits and following up with inquiries. Our website contact form is run directly through Squarespace, as described above; if you submit a form on our website, the information you provide (such as name, email address, and company) may also be processed through HubSpot to manage our relationship with you.

Managing your cookie preferences

You can accept or reject non-essential cookies through the cookie consent banner presented on our website, or through your browser settings. Essential cookies required for basic website functionality cannot be rejected. We do not use cookies to serve targeted or cross-context behavioral advertising. We periodically review our website technologies and will update this section whenever vendors or services change.

10. International Data Transfers

AssetFynd is based in the Cayman Islands and may process personal information in Canada, the United States, and other countries where our service providers operate. Where we transfer personal information from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we implement appropriate safeguards required by applicable law, including Standard Contractual Clauses or equivalent transfer mechanisms where applicable.

11. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law, regulation, or contract. Retention periods vary by category of information — for example, asset recovery and claim-support records, sanctions and fraud-screening records, and website contact data are subject to different retention schedules, which are documented in our internal Data Privacy Policy and data retention procedures.

We do not retain sensitive information such as financial data or government identifiers indefinitely; such information is deleted or anonymized once it is no longer needed for the purpose it was collected, or as required by applicable recordkeeping law. We periodically review retained information and securely delete, anonymize, or otherwise dispose of personal information when it is no longer required for the purposes for which it was collected or as required by applicable law.

12. Data Accuracy

AssetFynd relies on information provided by clients, strategic alliance partners, public records, government sources, financial institutions, and other lawful sources. While we take reasonable steps to maintain accurate and current information, we may rely on the accuracy of information supplied by third parties. Individuals may request correction of inaccurate personal information where permitted by applicable law by contacting us using the details in Section 17.

13. How We Protect Your Information

We apply administrative, technical, and organizational measures designed to protect personal information, consistent with our internal Security Policy. These measures include access controls, encryption where appropriate, vendor review, and incident response procedures. While we implement safeguards designed to protect personal information, no method of transmission over the Internet or electronic storage is completely secure. Accordingly, we cannot guarantee absolute security. Where required by applicable law, we will notify affected individuals, clients, partners, and regulators of a personal information breach.

14. Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal information, to receive a copy of it in a portable format, to withdraw consent, or to object to certain processing, including profiling with legal or similarly significant effects. This includes rights available under the GDPR and UK GDPR (EEA, UK, and Switzerland), applicable U.S. state privacy laws, Canada’s PIPEDA and applicable provincial laws, and Australia’s Privacy Act 1988 and New Zealand’s Privacy Act 2020. We aim to offer these rights consistently to individuals regardless of where they live, rather than limiting them only to jurisdictions where they are legally required.

To exercise these rights, contact us using the details in Section 17. If your information was provided to us by a corporate client or strategic alliance partner in connection with a specific matter, we will coordinate with that client or partner to respond, consistent with Section 4 above. If you are located in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Categories of information: collection, disclosure, and sale

The table below summarizes, for the twelve months preceding the effective date of this Policy, the categories of personal information AssetFynd has collected, whether each category has been disclosed to a service provider or business partner for a business purpose, and whether any category has been sold or shared for cross-context behavioral advertising. AssetFynd does not sell personal information and does not share personal information for cross-context behavioral advertising.

Category Collected? Disclosed for a Business Purpose? Sold or Shared for Advertising?
Identifiers (name, email, phone, business contact details) Yes Yes No
Personal records under Cal. Civ. Code § 1798.80(e) (e.g., government ID, financial account information) — collected only in specific claim-support matters Limited / context-specific Yes, to the relevant client, partner, or verification service provider No
Commercial information (service and engagement records) Yes Yes No
Internet or electronic network activity (website usage, cookies) Yes Yes No
Geolocation data (precise) No No No
Professional or employment-related information (job applicants, business contacts) Yes Yes No
Inferences drawn to create a consumer profile No No No
Biometric information No No No
Protected classification characteristics No No No
Audio, visual, or similar sensory information No No No

Do Not Sell or Share My Personal Information

AssetFynd does not sell personal information to third parties and does not share personal information for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws. Because we do not engage in these practices, there is no opt-out mechanism required for them; if this changes in the future, we will implement an opt-out mechanism and update this Policy before doing so.

15. Children’s Privacy

Our website and services are not directed to children and are not intended for individuals under the age at which they can lawfully provide consent under applicable privacy laws. We do not knowingly collect personal information from children without appropriate legal authorization or consent. If we become aware that we have collected such information unintentionally, we will take reasonable steps to delete it.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, services, or legal obligations. We will post the updated version with a revised effective date, and, where changes are material, we will provide additional notice as appropriate.

17. Contact Us

If you have questions about this Policy or wish to exercise a privacy right, contact us at:

AssetFynd Ltd.
Attn: Compliance Owner
PO Box CEC-320
George Town, Grand Cayman
Cayman Islands KY1-9012
compliance@assetfynd.com