100%
This policy covers personal data we process about visitors to this website and users of our escrow service.
Kuwait's data protection framework sits with the Communication and Information Technology Regulatory Authority (CITRA) under its Data Privacy Protection Regulation, Resolution No. 42 of 2021, as amended by Decision No. 26 of 2024. We have written this policy to that standard.
Two open questions for counsel.
Scope. Decision No. 26 of 2024 appears to have narrowed the Data Privacy Protection Regulation so that it binds CITRA-licensed telecommunications and internet service providers rather than every business processing Kuwaiti personal data. If so, an offshore escrow platform may fall outside it and instead be governed by Law No. 20 of 2014 on Electronic Transactions. We have chosen to apply the stricter reading rather than assume the exemption.
Breach timing. Practitioner guidance published in 2026 states 24 hours for breach notification, not the 72 hours often quoted from GDPR-influenced summaries. We have adopted 24 hours. Counsel must confirm both points against the operative Arabic text.
Kafil W.L.L., Office 1502, Al Shuhada Street, Block 8, Sharq, Kuwait City 15300, Kuwait, is the controller of this data.
Data protection enquiries: privacy@kafil.com, for the attention of the Compliance Officer.
When you browse. Technical data necessary to serve the site. With your consent, usage measurement. Nothing is loaded for measurement until you choose, which is why you see a banner on your first visit.
When you enquire. Your name, contact details, and whatever you tell us about the deal.
When you use the service. Identity documents, evidence of source of funds, wallet addresses, transaction records and correspondence. We are required to collect and retain this.
| Purpose | Basis |
|---|---|
| Responding to your enquiry | Your request |
| Providing the escrow service | Performance of our agreement with you |
| Identity and source-of-funds verification | Legal obligation |
| Sanctions and illicit-finance screening | Legal obligation |
| Record retention and regulatory reporting | Legal obligation |
| Usage measurement | Your consent, which you may withdraw at any time |
Kuwait's regime is consent-centric and does not offer a legitimate-interest basis of the kind found in European law. Processing we carry out to meet anti-money-laundering obligations is therefore framed as a legal obligation, not as consent. You cannot withdraw consent to a check we are required to perform.
Under the Kuwaiti regime you may:
Note what is not in that list, because we would rather be accurate than flattering: there is no statutory right to data portability, no general right to object to processing, no right to restriction of processing, and no statutory deadline by which we must answer. We aim to respond within 30 days regardless.
To exercise any right, contact us using the details at the foot of this page.
We name them, because "trusted third parties" is not a disclosure:
| Processor | What they do | Where |
|---|---|---|
| Shufti | Identity verification | United Kingdom / EEA |
| Crystal Intelligence | Wallet and transaction screening | United Arab Emirates |
| Hetzner | Application hosting | Germany |
| Fastmail | Business email | Netherlands |
There is no custody processor, because there is no third-party custodian. Our signing key is held on our own offline hardware.
We do not sell personal data, and we do not share it for anyone else's marketing.
We disclose data to regulators and law enforcement where legally required, and where we do so under anti-money-laundering law we may be legally prohibited from telling you.
Application data is hosted in Germany. Identity documents are stored encrypted in the same region and are not replicated outside it. Screening queries are processed in the United Arab Emirates; business email in the Netherlands.
Where personal data leaves Kuwait we tell you the destination countries, as above, and identify the legal representative there, as the regime requires.
Anti-money-laundering law sets the floor and it is longer than most people expect: five years from the end of the business relationship or the date of the transaction, whichever is later. Complaint records are kept for ten years.
This constrains deletion. Where you ask us to delete records we are required to retain, we will tell you which category applies and when the obligation expires, rather than refusing without explanation.
Enquiries that do not become deals are deleted after 12 months.
Access to personal data is restricted to staff who need it for a specific task. Identity documents are stored separately from operational systems. Our signing key is held offline and is not connected to any system that touches personal data.
Specifically: data is encrypted in transit and at rest; access is role-based, individually attributed and reviewed quarterly; multi-factor authentication is mandatory for every member of staff; identity documents sit in a separate store from operational systems with its own access list, and access to that store is logged and reviewed. Signing keys are held offline on dedicated hardware and are not reachable from any system holding personal data.
Where a breach affecting personal data occurs we will notify CITRA and the affected individuals within 24 hours. We will tell you what happened, what data was involved, what we have done, and what you should do.
If you are not satisfied with how we have handled your data you may complain to CITRA. You do not need to come to us first, though we would prefer the chance to fix it.
We post changes here and update the date at the top. Material changes affecting active clients are notified directly.
Questions about this policy? Contact us at hello@kafil.com or on +965 2249 5500.