Privacy Policy
Last Updated: March 2026 | Effective Immediately
Our Privacy Commitment
At Creston Refund Services, we recognize that our clients entrust us with exceptionally sensitive financial information, banking records, and personal histories. We maintain an uncompromising commitment to institutional confidentiality, deploying bank-grade AES-256 encryption, adhering to GDPR, CCPA, and international financial intelligence standards, and never selling or commercializing your personal data under any circumstance.
1. Scope and Controller Information
This Privacy Policy outlines how Creston Refund Services ("we," "our," or "us"), operating as a specialized financial recovery and dispute resolution consultancy, collects, utilizes, safeguards, and discloses your personal data when you interact with our website, access our client portal, or retain our investigative and advisory services.
For the purposes of the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and California Consumer Privacy Act (CCPA), the Data Controller responsible for your personal information is Creston Refund Services Global Operations.
2. Categories of Information We Collect
To deliver competent forensic investigation, compile dispute documentation, and interact with banking clearinghouses on your behalf, we collect several categories of information:
- Identity and KYC Verification Data: Full legal name, date of birth, residential address, government-issued photo identification (passport, national ID, driver's license), and utility documentation required for statutory Anti-Money Laundering (AML) checks.
- Financial & Transaction Records: Bank account statements, credit/debit card statements showing masked account numbers, SWIFT/wire confirmation slips, payment gateway invoices, and merchant receipts.
- Cryptographic & Blockchain Data: Public wallet addresses, transaction hashes (TxIDs), smart contract interaction receipts, and cryptocurrency exchange deposit/withdrawal logs.
- Dispute Evidence & Correspondence: Emails, chat logs, platform trading screenshots, brochures, contracts, and audio/written records of your interactions with alleged fraudulent entities.
- Technical & Telemetric Information: IP addresses, browser types, operating systems, session timestamps, and device identifiers collected automatically through secure log files.
3. Lawful Basis for Processing
Under international data protection regulations, we process your personal data under the following recognized legal bases:
- Performance of a Contract (Article 6(1)(b) GDPR): Processing is strictly necessary to conduct preliminary case evaluations, prepare statutory chargeback dossiers, and execute fund recovery services requested by you.
- Legal & Regulatory Compliance (Article 6(1)(c) GDPR): Mandatory reporting, anti-fraud verifications, and compliance with statutory financial regulations and subpoena mandates.
- Legitimate Interests (Article 6(1)(f) GDPR): Preventing fraudulent submissions, optimizing our forensic software capabilities, and protecting our legal rights in dispute arbitrations.
- Explicit Consent (Article 6(1)(a) GDPR): Explicit authorization provided by you to represent your interests before acquiring banks, card schemes, and supervisory ombudsmen.
4. How We Utilize Your Data in Recovery Proceedings
We deploy your information exclusively for authorized casework and procedural representation:
- Conducting forensic financial triages and tracing multi-hop wallet transfers across decentralized ledgers.
- Drafting formal demand letters, chargeback claim bundles, and pre-arbitration requests submitted directly to card networks (Visa, Mastercard, American Express).
- Engaging in direct inter-bank communications with issuing and acquiring banks to execute SWIFT recalls and freeze mandates.
- Providing regular milestone updates and secure status reporting through your encrypted client portal.
5. Disclosure & Information Sharing Protocols
We do not sell, rent, or trade client personal information. Information sharing is strictly confined to entities essential to executing your fund recovery:
- Financial Institutions & Card Schemes: Issuing banks, clearinghouses, acquiring processors, and payment gateways reviewing your dispute.
- Regulatory & Supervisory Bodies: Financial Conduct Authority (FCA), Consumer Financial Protection Bureau (CFPB), European Financial Ombudsman, and national financial intelligence units when formal statutory complaints are filed.
- Law Enforcement Agencies: When required by court order, search warrant, or statutory subpoena in criminal fraud investigations.
- Specialized Forensic Partners: Secure blockchain intelligence systems operating under strict non-disclosure and data protection sub-processor covenants.
6. Cryptographic Security Standards & Technical Safeguards
We maintain state-of-the-art security safeguards designed to prevent unauthorized access, data breach, or alteration:
- End-to-End & At-Rest Encryption: All client documents and claim submissions are encrypted using 256-bit Advanced Encryption Standard (AES-256) at rest and TLS 1.3 in transit.
- Role-Based Access Control (RBAC): Only case managers and forensic specialists directly assigned to your specific file possess cryptographic keys to decrypt your documents.
- Automated Audit Logging: Every access, export, or viewing of client evidence is permanently logged in immutable audit trails.
7. Retention and Secure Deletion Schedules
We retain client records only for the period necessary to fulfill recovery objectives and comply with statutory financial record-keeping obligations (typically 5 to 7 years following case closure under international Anti-Money Laundering legislation). Following the expiration of statutory retention windows, documents are scrubbed using DoD-standard digital shredding protocols.
8. Your Statutory Rights & Privacy Controls
Depending on your geographic location, you hold significant enforceable legal rights regarding your personal information:
- Right of Access: Request a complete copy of the personal information and case files we maintain on record.
- Right to Rectification: Request correction of inaccurate, outdated, or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your data, subject to statutory AML legal record retention mandates.
- Right to Restrict or Object: Restrict certain processing activities or revoke previously granted representation permissions.
- Right to Data Portability: Receive your evidentiary dossier in a structured, machine-readable format.
9. Contact the Data Protection Officer (DPO)
To exercise any of your data protection rights, or if you have inquiries regarding our data handling standards, contact our Data Protection Officer:
Data Privacy & Compliance Directorate
support@crestonrefundservices.com
Creston Refund Services International, Suite 500, Financial District, NY 10005, USA
Response SLA: Within 3 business days for statutory inquiries