Privacy Policy
This policy explains how Isokyn handles personal data, both on this website and in the platform. Isokyn is operated by Evfiam Investment Group SRL, a company incorporated in Romania, which also operates Isofort. If you are the customer of a financial institution that uses Isokyn, direct your data requests to that institution first, as explained below.
01 Who we are
Isokyn is an orchestration and signaling layer for institutional decisions, covering lending, fraud, anti-money-laundering, sanctions and onboarding. It is owned and operated by Evfiam Investment Group SRL, incorporated in Romania, which owns the isokyn.com and isokyn.ai domains and the Isokyn brand. Trade register details are available on request.
02 Controller and processor roles
We act in two capacities. As a controller, we decide how personal data is handled for our own website, our marketing and access requests, our internal staff, and the accounts of people who use the platform directly. As a processor, we handle the data our customers send us to make decisions, under a data processing agreement, on their instructions and under their control.
If you are an end customer of an institution that uses Isokyn (a borrower, an applicant, an account holder), that institution is the controller of your data. Send your requests to them first, and we will support them in answering you.
03 Data we handle as a controller
- Website visitor logs (IP address, browser and device metadata, pages requested).
- Access and demo requests (name, work email, role, company).
- Platform user records (authentication details, roles, audit trails of actions).
- Billing and contract contacts.
- Correspondence you send us by email.
We do not buy marketing lists, and we do not enrich your profile from data brokers for sales purposes.
04 Data we process for customers
When an institution runs a decision on Isokyn, the case may include identity attributes, transaction records, device signals, on-chain and wallet data, bureau and open-banking data, and case materials. This data is encrypted at the field level and segregated by organization. We do not sell it. We do not share one customer's data with another customer, and we do not use it to train models for anyone else.
05 Legal bases
Depending on the purpose, we rely on legitimate interest (running and securing our site and service), performance of a contract (providing the platform), a legal obligation (for example, financial-crime and record-keeping duties), or consent (where we ask for it). In financial-crime contexts, legal obligation and the prevention of fraud are the primary bases our customers rely on.
06 Automated decisions
Isokyn produces an explainable outcome, approve, review or decline, with the reasons it turned on attached as structured reason codes, not an opaque number. Isokyn does not make the decision. The institution decides whether to approve or decline, and a person can review any case. Where a decision produces a legal or similarly significant effect on an individual, our customers are responsible for the human review and the notice that the law requires.
07 Sub-processors
We use a small set of vendors to run the service: Amazon Web Services (infrastructure, in the EU), Cloudflare (DNS and edge), an email delivery provider, a payment processor for billing, and data and on-chain providers used on a customer's instruction. Personal data is scrubbed before it reaches a vendor wherever the function allows it. A named sub-processor register is available to customers under a confidentiality agreement, and we give notice of material changes.
08 International transfers
Our infrastructure runs in Amazon Web Services in Frankfurt, in the European Union. Where a transfer of personal data leaves the EU, we rely on standard contractual clauses together with field-level encryption. If you have a data-residency requirement, raise it during the pilot and we will scope it.
09 Retention
- Website logs: 90 days.
- Access requests that do not convert: 24 months.
- Platform accounts: the life of the account plus 90 days.
- Customer case data: per the contract, and deleted or returned within 30 days of termination.
- Backups: a 7-day rolling window.
- Records we are required by law to keep: for the statutory period, typically five years or more.
10 Security
We encrypt data in transit and at rest, apply envelope encryption to personal-data fields, require multi-factor authentication, grant access on a least-privilege basis, keep append-only audit trails, and require a second authorized signature (two-person control) for sensitive changes. Our SOC 2 and ISO 27001 programs are in progress.
11 Your rights
Subject to the law, you may ask to access, correct, erase, restrict or object to the processing of your data, or to receive it in a portable form. Write to privacy@isokyn.com and we will respond within one month. Some rights have limits: for example, records we must keep for legal reasons, such as suspicious-activity reports, cannot be erased on request.
12 Cookies and storage
This website uses only the strictly necessary browser storage it needs to work and to remember your choice on this notice. It sets no advertising, analytics or session-replay cookies, and we do not track you across other sites. When you first visit, we show a short notice and you can accept or decline; either way, we store only that choice. The logged-in platform uses strictly necessary authentication cookies to keep you signed in.
13 Children
Isokyn is a business-to-business service and is not directed at children. Where a case involves data about a minor, we process it on our customer's instruction and legal basis, not our own.
14 Changes to this policy
This policy is versioned. If we make a material change, we notify customers before it takes effect, and prior versions are available on request.
15 Contact and complaints
For privacy questions, write to privacy@isokyn.com. For security matters, write to security@isokyn.com. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), or with your local supervisory authority in the EU.