Last updated 1 August 2026
Purpose
This policy explains how CrestPoint Capital protects the data entrusted to us. It sits alongside our Privacy Policy, which explains what we collect and why; this document explains how it is secured.
Encryption
- All traffic between your browser and our platform is encrypted in transit using TLS with modern cipher suites; plain HTTP requests are redirected.
- Databases and object storage are encrypted at rest.
- Credentials are stored only as salted one-way hashes; nobody at CrestPoint Capital can read your password.
- API keys and integration secrets are held in a managed secret store and never written into application code or logs.
Access control
- Every database table enforces row-level authorisation, so a signed-in client can reach only their own records.
- Staff access is role-based and granted on a least-privilege basis; sensitive roles are assignable only by a senior administrator and never self-assigned.
- Administrative actions — verification decisions, funding approvals, role changes — are written to an append-only audit log that cannot be edited or deleted.
- Sessions expire after a period of inactivity, and two-factor authentication is available on client accounts.
Secure storage of documents
Identity and address documents are uploaded directly over an encrypted connection into a private storage bucket that is not publicly addressable. Access is limited to authorised compliance staff, and every retrieval is logged.
Data minimisation and retention
We collect only the data needed for the purpose at hand, and retain it for the period required by financial record-keeping and tax rules. Once that period ends records are deleted or irreversibly anonymised. Backups are encrypted and expire on a fixed schedule.
Service providers
Providers that process data on our behalf — hosting, identity verification, payment processing, email delivery and analytics — are assessed before engagement and bound by written agreements that restrict them to our instructions and require equivalent security standards. International transfers are made only where a lawful transfer mechanism is in place.
Incident response
We monitor for unauthorised access and maintain an incident response process covering containment, investigation, remediation and notification. Where an incident is likely to affect your rights we will notify you and the relevant supervisory authority within the timeframes required by law. Suspected security issues can be reported to compliance@crestpointcapital.net.
Compliance and your rights
We work to applicable data protection laws, including the GDPR where it applies to our processing, and to relevant financial record-keeping rules. To exercise access, correction, deletion, restriction or portability rights, write to privacy@crestpointcapital.net; see our Privacy Policy for details.
Questions about this document? Email support@crestpointcapital.net or call +1 801-415-5166.
