Privacy Policy
Last updated: July 8, 2026
Custodian HQ ("Custodian", "we", "us", or "our") is a Wyoming C-Corporation operating a digital inheritance and asset transfer platform. We are committed to protecting the privacy and security of your personal data with the highest standards of care, transparency, and legal compliance.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, with whom we share it, how long we retain it, and what rights you have in relation to it. This Policy applies to all users of the Custodian platform globally, including users in the United States, the European Union, the United Kingdom, Nigeria, and all other jurisdictions.
If you have questions about this Privacy Policy or our data practices, you may contact our Data Protection Officer at: [email protected]
1. Definitions
| "Personal Data" | Any information relating to an identified or identifiable natural person ('data subject'). |
|---|---|
| "Sensitive Data" | Personal Data revealing passwords, private keys, seed phrases, financial credentials, health information. |
| "Processing" | Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion. |
| "Data Controller" | Custodian HQ, the entity that determines the purposes and means of processing your Personal Data. |
| "Data Processor" | A third-party entity that processes Personal Data on our behalf and under our instructions. |
| "User" or "you" | Any individual who creates an account on, accesses, or interacts with the Custodian platform. |
| "Beneficiary" | A person designated by a User to receive the User's digital asset access instructions upon the activation of the transfer process. |
| "Custodian Network Member" | A person designated by a User to hold a cryptographic key share and participate in the transfer verification process. |
| "Platform" | The Custodian HQ website, application, and all related digital services. |
2. Data We Collect
- When you create an account or use our Services, we collect the following categories of personal data:
Identity Data Full legal name Contact Data Email address, phone number Account Credentials Password (we store only a cryptographic hash; we do not store plaintext passwords) Asset Information The asset identifier, value, encrypted text, asset detail or access instructions, and any documents you upload. The documents and asset details are encrypted with your Secret Key prior to storage, we store only the encrypted ciphertext and cannot read its contents. Beneficiary & Custodian Data Names and email addresses of persons you designate as Beneficiaries Payment Data Payment method details. We do not store credit card numbers. Cryptocurrency wallet addresses used for payment may be retained. Communications Records of any communications you send to us, including support tickets and feedback - When you visit or interact with the Platform, we automatically collect certain technical data:
- IP address and approximate geolocation
- Browser type, version, and language
- Operating system and device type
- Pages visited, time spent on pages, links clicked
- Referring URLs and exit pages
- Session identifiers and authentication tokens (stored securely)
- Cookies and similar tracking technologies
- Data from Third Parties
- Google Analytics provides us with aggregated usage and behaviour data about how users interact with the Platform.
- Stripe may provide us with transaction confirmation data and fraud signals.
- We do not purchase or acquire personal data from data brokers.
- Data Relating to Minors - Our Platform does not impose an age restriction, and Beneficiaries designated by Users may include minors. Where personal data of a minor (under 13 in the USA, under 16 in the EU/UK) is submitted to the Platform, we process that data solely to fulfill the User's estate planning intent. We do not knowingly seek to market to or engage with minors directly. Parents and guardians should supervise any account creation by or on behalf of minors.
3. How We Use Your Data
We use your Personal Data only for the following lawful purposes:
| Service Delivery | To create and manage your account, process subscriptions, execute the transfer process, and provide all platform features. |
|---|---|
| Security & Authentication | To verify your identity, protect your account, distribute cryptographic key shares, authenticate Custodian Network Members and beneficiaries. |
| Communications | To send account alerts, security notifications, trial and billing reminders, and transfer-event notifications (including multiple ping attempts during the Security Window). |
| Payment Processing | To process subscription payments via Stripe and cryptocurrency payment channels. |
| Analytics & Improvement | To understand how users interact with the Platform via Google Analytics in order to improve features and user experience. |
| Legal Compliance | To comply with applicable laws, respond to lawful government requests, enforce our Terms of Service, and protect the rights and safety of users and the Company. |
| Fraud Prevention | To detect, investigate, and prevent fraudulent, malicious, or unauthorized access to the Platform. |
| Future Services | We may use your contact data to notify you of new services, features, or updates, subject to applicable marketing consent requirements. |
4. Legal Bases for Processing
For users in the European Union, the United Kingdom, and other jurisdictions that require a legal basis for processing, we rely on the following bases:
- Contractual Necessity: Processing is necessary to perform our contract with you i.e., to provide the Custodian platform and Services.
- Legitimate Interests: To improve the Platform, prevent fraud, ensure security, and communicate service updates, where such interests are not overridden by your rights.
- Legal Obligation: To comply with applicable legal requirements, including data breach notification obligations and law enforcement requests.
- Consent: For non-essential cookies, analytics, and any marketing communications where consent is required by law. You may withdraw your consent at any time.
For the processing of sensitive categories of data (if applicable), we rely on your explicit consent or the necessity of processing for the establishment, exercise, or defense of legal claims.
5. Data Storage and Security
I. Storage Location
Your Personal Data is stored on servers located in the European Union, operated by Contabo GmbH ("Contabo"), a German cloud infrastructure provider and Cloudflare. By storing data in the EU, we benefit from the GDPR's robust data protection framework.
II. Security Measures
We implement the following technical and organizational security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using industry-standard TLS/SSL protocols.
- Encryption at rest: All stored Sensitive Data, including encrypted asset instructions, is encrypted at rest using AES-256 or equivalent encryption standards.
- Cryptographic key splitting: Your Secret Key is split into shares using a secure cryptographic algorithm and distributed to your custodians. Custodian HQ does not retain a copy of your Secret Key or any share thereof.
- Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication enforced.
- Infrastructure security: Our hosting provider, Contabo, maintains physical and infrastructure security in accordance with ISO 27001 and applicable EU data protection standards.
- Penetration testing and vulnerability management: We conduct periodic security assessments of the Platform.
III. No Absolute Guarantee
While we implement industry-standard security measures, no system is completely secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and Secret Key.
6. Data Retention
- We retain your Personal Data for as long as your account is active or as necessary to provide our Services.
- Following the successful execution of a transfer on the Platform, we retain account records and associated data as necessary to: (a) maintain audit records of the transfer; (b) resolve any disputes regarding the execution of the transfer; and (c) comply with applicable legal obligations. Retention in this case may be indefinite.
- If you cancel your subscription, your account data is retained for a period of ninety (90) days to allow for account reactivation, after which your data may be anonymized or deleted, subject to any legal retention obligations.
- We may be required to retain certain data for longer periods pursuant to applicable law, including financial records for tax and audit purposes.
7. Sharing Your Data
- We do not sell, rent, license, or trade your Personal Data to any third party for monetary or other consideration.
- We share your data only with the following vetted third-party processors who act on our behalf and under our instructions:
Stripe, Inc. Payment processing. Stripe may collect and process your payment method details in accordance with its own Privacy Policy and applicable PCI-DSS standards. Custodian does not store card numbers. Zoho Corporation Email delivery and communications platform. Zoho processes email addresses and communication content on our behalf to deliver platform notifications. Google LLC (Analytics) Aggregated website analytics via Google Analytics. Data may be transmitted to Google servers. Google acts as a data processor under our Google Analytics data processing agreement. Contabo GmbH & Cloudflare Cloud hosting and server infrastructure located in the EU. Contabo processes all stored data on our behalf. Cloudflare provides storage services via R2. - Upon execution of the transfer process, the decrypted asset access instructions are transmitted to the designated Beneficiaries. You acknowledge that this is the intended function of the Platform and constitutes the core service delivery.
- We may disclose your Personal Data without your consent where required or permitted by law, including in response to: valid legal process such as subpoenas, court orders, or warrants; requests by government or regulatory authorities; or to protect the rights, property, or safety of Custodian HQ, its users, or the public.
- In the event of a merger, acquisition, restructuring, or sale of all or substantially all of the Company's assets, your Personal Data may be transferred to the acquiring entity as part of the transaction, subject to the acquiring entity's agreement to be bound by data protection obligations at least as protective as those in this Policy.
8. Cookies and Tracking Technologies
We use the following categories of cookies and similar technologies on the Platform:
| Strictly Necessary Cookies | Essential for platform functionality: session management, authentication, security tokens. Cannot be disabled. |
|---|---|
| Performance/Analytics Cookies | Google Analytics cookies to track aggregate usage patterns and improve platform performance. |
| Functional Cookies | To remember your preferences, language settings, and session state. |
9. International Data Transfers
Your data is stored in the European Union on Contabo or Cloudflare's infrastructure. However, certain third-party processors (including Google and Stripe) may process data in the United States or other countries. Where such transfers occur, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-US Data Privacy Framework (for transfers to the United States)
- Binding corporate rules or other legally recognized transfer mechanisms
Users in Nigeria and other jurisdictions outside the EU/US: By using the Platform, you consent to the transfer of your data to EU servers and the processing arrangements described herein.
10. Your Rights
- If you are located in the European Union or the United Kingdom, you have the following rights under applicable data protection law:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction of Processing: Request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right not to be subject to Automated Decision-Making: Request human review of any automated decisions that significantly affect you.
- California residents have the following rights under the California Consumer Privacy Act (CCPA) / CPRA:
- Right to Know: What personal information we collect, use, disclose, and sell.
- Right to Delete: Request deletion of personal information we hold about you.
- Right to Opt-Out: We do not sell personal information. Therefore, no opt-out is required.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- For users in Nigeria, the Nigerian Data Protection Act 2023 confers rights to access, correct, delete, and object to the processing of your personal data. We are committed to honoring these rights in respect of Nigerian users.
- To exercise any of the above rights, please contact us at [email protected]. We will respond to your request within thirty (30) days (or within the timeframe required by applicable law). We may require identity verification before processing your request.
11. Data Breach Notification
In the event of a personal data breach, we will:
- Notify affected users without undue delay and within 72 hours of becoming aware of the breach where required under GDPR.
- Notify the Wyoming Attorney General's Office within 45 days of discovering a breach affecting more than 500 Wyoming residents.
- Notify relevant supervisory authorities in other jurisdictions as required by applicable law.
- Provide information about the nature of the breach, the categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
12. Children's Privacy
The Platform is not designed to market to or directly collect data from children under the age of 13. While Beneficiaries may be minors, the Platform is operated by adult Users. We do not knowingly collect personal data directly from children under 13 without verifiable parental consent. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will delete such data promptly. Parents or guardians with concerns should contact us at [email protected].
13. Third-Party Links
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party service you access through our Platform.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. We will notify you of material changes by: (a) posting the updated Policy on the Platform with a revised effective date; (b) sending an email notification to the address associated with your account; and (c) for material changes affecting EU/UK users, providing at least 30 days' advance notice. Your continued use of the Platform following the effective date of any update constitutes your acceptance of the revised Policy.
For privacy-related inquiries, complaints, or to exercise your rights, contact us at: [email protected]