IsoFort exists to protect people from financial crime. That mandate only works if we hold their data to a higher standard than the fraud we detect. This policy says exactly what we process, why, for how long, and what you can demand of us.
IsoFort is a fraud and financial crime intelligence platform. The brand, the domain isofort.ai, the platform and this website are owned and operated by Evfiam Investment Group SRL, a company incorporated in Romania.
Trade register number, tax identification code and registered office address are provided on request, and are stated in full in every contract and data processing agreement we sign.
Throughout this document, "IsoFort", "we" and "us" mean Evfiam Investment Group SRL. "You" means whoever is reading: a website visitor, a prospect, a user of the platform, or a person whose data one of our customers has asked us to assess.
Under the GDPR, the same company can be a controller for some data and a processor for other data. IsoFort is both, and your rights depend on which one applies.
We decide why and how the data is processed. This covers our own website, our marketing and sales activity, pilot applications, the accounts of people who log into the platform, our suppliers, and our own staff.
Our customers are financial institutions, fintechs, exchanges and payment platforms. When they send us data about their own customers and transactions so we can score risk, they remain the controller and we act strictly on their documented instructions, under a data processing agreement. We do not decide what that data is used for, we do not sell it, and we do not repurpose it.
If a financial institution used IsoFort to assess you, we are their processor, not the controller. Send your access or erasure request to that institution. They can fulfil it through us, and we are contractually bound to help them do it inside the legal deadline. If you do not know which institution is involved, write to privacy@isofort.ai and we will route you.
| Who | What we hold | Where it comes from |
|---|---|---|
| Website visitors | IP address and standard request metadata (browser, referrer, timestamp) captured in edge and server logs for security and abuse prevention. | Automatically, when you load a page. |
| Pilot and contact form applicants | Name, work email, job role, company, company website, the volume band you selected, and whatever you wrote in the free text fields. | You, when you submit a form. |
| Platform users | Name, work email, organisation, assigned role, multi-factor authentication enrolment data, session and login records, and an append only audit trail of the actions taken in the product. | Your employer when the account is created, and the product as you use it. |
| Billing contacts | Billing name, address, tax identifiers, invoice and subscription records. | You or your employer. Card details go directly to our payment processor and never reach our servers. |
| Correspondents | Email content and metadata when you write to any of our published addresses. | You. |
We do not buy marketing lists, we do not enrich your profile from data brokers for sales purposes, and we do not run advertising pixels.
When a customer connects IsoFort, they send us the data needed to assess risk. Depending on the modules they enable, that can include:
This data is logically segregated by organisation. Personal data fields are encrypted at rest at the field level, above and beyond full disk encryption. Access is limited by role, and every access is written to an append only audit log.
We do not sell it. We do not share one customer's data with another customer. We do not use identifiable customer data to train models for other customers without a specific, separately agreed instruction from that customer. We do not send customer personal data to a third party model provider for training.
Where we are the controller, we rely on the following bases under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Running and securing this website, preventing abuse | Legitimate interest in keeping our service available and safe |
| Responding to a pilot application or an enquiry you sent us | Steps taken at your request prior to entering a contract, and legitimate interest |
| Providing platform accounts, support and security | Performance of the contract with your organisation |
| Invoicing, accounting and tax records | Legal obligation |
| Product security, logging, incident investigation | Legitimate interest, and legal obligation where applicable |
| Marketing emails to business contacts | Consent, or legitimate interest in business to business communication, with an unsubscribe link in every message |
Where we act as a processor, the legal basis for the underlying processing is set by our customer as controller. In a financial crime context that is typically a legal obligation (anti money laundering, sanctions screening, payment fraud prevention) or a legitimate interest in preventing fraud, which Recital 47 GDPR recognises explicitly.
IsoFort produces risk scores and human readable reason codes. This is profiling, and we are deliberate about where the decision sits.
If a decision produced legal or similarly significant effects for you, Article 22 GDPR gives you the right to obtain human intervention, express your point of view and contest the decision. Exercise it with the institution that made the decision. We support them in answering you.
We use a small number of third parties to run the service. Each one is bound by a data processing agreement, is assessed before it is engaged, and is reviewed at least annually.
| Category | Purpose | Region |
|---|---|---|
| Cloud infrastructure Amazon Web Services | Hosting, managed database, storage, content delivery, logging and monitoring | EU (Frankfurt), with a global content delivery edge |
| DNS and edge protection Cloudflare | Domain resolution and edge traffic protection | Global edge |
| Email delivery | Transactional and account email | EU |
| Payment processing | Subscription billing and invoicing. Card data goes directly to the processor and never reaches our servers. | EU and US, under standard contractual clauses |
| Error monitoring and secrets management | Operational tooling. Personal data is scrubbed before it leaves the platform. | EU and US, under standard contractual clauses |
| Identity verification providers | Identity and document verification, where the customer enables that module | Depends on the provider and the customer configuration |
| Blockchain and risk data providers | On-chain lookups and risk intelligence. They receive wallet addresses, not the identity behind them. | EU and US, under standard contractual clauses |
| Language model provider | Drafting case narratives and summaries inside the product, under a zero retention, no training agreement | EU and US, under standard contractual clauses |
The register naming each specific provider, the data categories it receives and its processing region is available to customers and to prospective customers under a mutual non disclosure agreement. Write to privacy@isofort.ai. Customers are notified at least 30 days before a new sub-processor starts processing their data, and may object.
We also screen against public sanctions and watch lists, including those published by OFAC, the United Nations, the European Union and the United Kingdom. Those are public sources, not sub-processors.
The platform is hosted in the European Union, in the AWS Frankfurt region. Personal data stays there by default.
Some sub-processors are established outside the European Economic Area, or operate global infrastructure. Where personal data is transferred outside the EEA, we rely on the European Commission standard contractual clauses, on an adequacy decision where one exists, and on supplementary technical measures: encryption in transit, field level encryption of personal data at rest, and minimisation so that a provider receives only what it needs. A transfer impact assessment is on file for each such transfer.
Customers with a strict data residency requirement should raise it during the pilot. Residency constraints are part of the deployment design, not an afterthought.
| Data | Retention |
|---|---|
| Website and edge request logs | Up to 90 days, then deleted |
| Pilot applications and enquiries that do not convert | 24 months from the last contact, then deleted |
| Platform account and authentication records | For the life of the account, then 90 days |
| Customer data processed under a contract | For the term the customer instructs, then deleted or returned within 30 days of the contract ending |
| Audit trail and security logs | Retained for the period required for security and compliance evidence. The audit log is append only and is never silently altered. |
| Anti money laundering records and regulatory filings | Retained for the statutory period, typically five years or more. This retention overrides an erasure request, which the GDPR expressly permits. |
| Invoices and accounting records | As required by Romanian and EU accounting law |
| Database backups | Daily snapshots on a rolling 7 day window, plus point in time recovery. Deletions propagate out of backups as that window rolls forward. |
Encryption in transit and at rest, envelope encryption of personal data fields under a managed key, mandatory multi-factor authentication for privileged roles, least privilege access, an append only audit trail, a web application firewall in front of the API, and a tested restore procedure.
The full picture, including our incident response commitments and the current state of our certification work, is on the security page.
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time where consent is the basis we rely on.
Some data cannot be erased on request. Suspicious activity reports and the records behind them are retained by law, and in many jurisdictions the institution is forbidden from telling the subject that such a report exists. Where an erasure request collides with that obligation, we erase what we can, retain what the law requires, and record the legal basis for the part retained. We will not tell you the data is gone when it is not.
Exercising your rights is free. We may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and we will explain why in writing.
IsoFort is a business to business product. It is not directed at children, and we do not knowingly collect data from anyone under 16 in a controller capacity. If a customer compliance obligation involves a minor, that processing runs under the customer instruction and legal basis, not ours.
We version this document. The version number and effective date are at the top of the page. If we make a material change, we update both and notify customers through the account contact on file before the change takes effect. Previous versions are available on request.
Privacy questions, data subject requests and DPA requests: privacy@isofort.ai.
Security vulnerabilities: security@isofort.ai. See the security page for our disclosure policy.
If you believe we have handled your data unlawfully, you can complain to a supervisory authority. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania. You may also complain to the authority in the EU country where you live or work.
We would rather hear from you first. Write to us and we will answer.
Our terms of service and our security posture, written to the same standard as this page.