Privacy policy
Last updated: October 10, 2025
1. Scope
This policy applies to all users of Trustiatis.com, including residents of the European Economic Area (EEA), Switzerland, Canada, the United States and New Mexico. We comply with the data protection laws of all these jurisdictions: GDPR (EU), Swiss FADP, Canadian PIPEDA, applicable US laws (CCPA, COPPA, etc.).
2. Data controller
Trustiatis LLC is the controller of your personal data.
Data protection officer: the contact form
Main contact: the contact form
Legal address: Trustiatis LLC, 4405 Jager Dr NE, Ste C4-4148, Rio Rancho, NM 87144, United States
3. IT sub-processing
Trustiatis LLC also acts as a processor for certain clients and partners, under strict contracts guaranteeing data confidentiality and security, in compliance with applicable law (GDPR, FADP, PIPEDA, US laws). Trustiatis only accesses data for hosting, maintenance and system security.
4. Payment providers and financial data processing
4.1 Payment providers
Stripe, Inc.; PayPal Holdings, Inc.; Wise Payments Limited; Mercury Financial, LLC — each an independent data controller.
4.2 Data collected by these providers
Credit/debit card details (number, expiry date, CVV), transaction history, identity verification (KYC), billing and shipping addresses, mandatory financial documents.
4.3 Legal basis and purpose
Contract performance, regulatory compliance (PSD2, AML/KYC), security and fraud prevention.
4.4 Disclaimer
Trustiatis LLC is not responsible for data processing by these providers. Each entity acts as an independent controller under its own privacy policy.
5. Information collected and purposes
A. Automatic technical data: browser, IP address, time zone, cookies — for site security, abuse prevention and anonymous statistics.
B. Personal data — individuals (KYC): name, date and place of birth, address, email, phone, banking data, ID documents and selfies where required — for service delivery, client management and compliance.
C. Business data — KYC compliance: identity documents of executives, articles of incorporation, official extracts, minutes, list of beneficial owners (>25%), commercial, tax and financial documents — for KYC/AML compliance and service validation.
6. Disclosure to authorities
On lawful request: judicial authorities, financial regulators, tax authorities, intelligence services, strictly within the applicable legal bases.
7. Legal bases for processing
Contract performance; explicit consent (marketing, newsletters); legitimate interest (security, analytics); legal obligations (tax, KYC/AML, notification to authorities).
8. Your rights by jurisdiction
EEA and Switzerland: access, rectification, erasure, restriction and objection, data portability, withdrawal of consent, post-mortem directives.
Canada: access, correction, withdrawal of consent, complaint to the Privacy Commissioner.
United States: California — access, opt-out of sale, deletion, non-discrimination. New Mexico — breach notification, access and rectification.
9. Protection of minors
Under 13 (United States, Canada), under 14 (Switzerland), under 16 (EEA): immediate deletion of data collected without parental consent.
10. Data retention
User account: account lifetime + 3 years. Transactions: 10 years. Prospects: 3 years after last contact. Analytics cookies: 13 months. KYC documents: 5 years after end of relationship. Biometric data: 90 days after verification. Financial data: per provider (about 7 years).
11. International transfers
EEA/Switzerland → Canada: EU adequacy decision. EEA/Switzerland → USA: Data Privacy Framework or standard contractual clauses. Payment providers: PCI DSS and contractual clauses. Canada → other countries: PIPEDA compliance. USA: internal transfers compliant with applicable laws.
12. Security and data breaches
Encryption, access control, monitoring, backups, MFA recommended. PCI DSS for payment. Breach notification per jurisdiction: 72h EEA/Switzerland, PIPEDA Canada, New Mexico Data Breach Act.
13. Cookie management
Essential: site operation (consent-exempt). Analytics: audience measurement (consent required in EEA/Switzerland). Personalization: preferences (consent required).
14. Fraud protection
Active security measures, but Trustiatis is not liable for phishing, impersonation, hacking, or incidents at payment providers. Recommendations: verify the sender, enable two-factor authentication (2FA), never share your password, monitor your statements.
15. Contact details and exercising your rights
General email: the contact form
Data protection officer: the contact form
Response time: 1 month (up to 2 months for complex requests)
Free of charge, except for manifestly unfounded requests. For anything payment-related, contact the relevant provider directly.
16. Changes and complaints
Regularly updated as the law evolves. Email notice 30 days before any substantial change. Complaints: local authorities depending on jurisdiction, or directly with the relevant provider.
17. Providers and vendors
Trustiatis LLC works with the following providers and vendors for its infrastructure, email, security and connectivity services:
Amazon Web Services (AWS) — Seattle, WA, USA. Cloud hosting, scalable infrastructure, storage and backup.
Oracle Corporation — Redwood Shores, CA, USA. Cloud computing, enterprise infrastructure, database management.
OVHcloud — Roubaix, France. Web hosting, dedicated servers, cloud.
Infomaniak Network SA — Geneva, Switzerland. Hosting, professional email, secure cloud.
Hostinger International Ltd. — Vilnius, Lithuania. Web hosting, VPS, domains.
Proton AG — Bern, Switzerland. Encrypted email, VPN, secure communications.
Cloudflare, Inc. — San Francisco, CA, USA. CDN, SSL, DDoS protection, web optimization.
Telnyx, Inc. — Chicago, IL, USA. VoIP, SMS, IoT connectivity, telecom routing.
Workynet LLC — Albuquerque, NM, USA. IT infrastructure, managed services, cloud operations.
Each provider acts in accordance with local and international data protection laws. Trustiatis LLC selects its providers for their reliability, security and performance.