Legal
Privacy notice
How SanctionsKit handles account information, screening inputs, retained evidence, service providers, and privacy requests.
On this page
Responsible business and contact
SanctionsKit is operated by Sanctions Kit, LLC. This notice describes the information processed by the service and the controls available to account holders. Contact the business with questions about data handling or the terms applicable to your organization.
The privacy contact is support@sanctionskit.com. Do not send identity documents, production secrets, or screening files by ordinary email when asking a general privacy question.
Information processed by the service
Account information includes organization and membership details supplied through authentication and billing services. Screening information can include a name, subject type, identifiers, dates, country, results, monitoring inputs, and analyst notes that an authorized customer submits. Official source records may also contain personal information.
The application uses this information to authenticate users, perform requested screening, retain selected evidence, operate monitoring, meter usage, support accounts, and investigate security or reliability issues. It is not designed to send screening inputs to advertising analytics. The public demonstration uses invented records.
Retention, deletion, and provider involvement
Standard evidence defaults to 90 days and can be configured from 1 to 3,650 days. Minimal mode does not retain the submitted subject or request and keeps reduced evidence for 24 hours. Active monitoring retains the subject until stopped and deleted. Uploads expire after 24 hours, delivery history after 90 days, and audit events after 365 days.
Service integrations include Vercel for hosting, private storage, and jobs; Neon for PostgreSQL; WorkOS for authentication; Stripe for subscriptions; and Resend for transactional email. Contact SanctionsKit for the contractual terms and processing arrangements applicable to your organization.
Deletion from current application records does not promise immediate removal from provider backups. Contact SanctionsKit for information about backup expiry, deletion requests, legal holds, and restored records. Retention of official source files must also comply with source rights and retained evidence requirements.
Questions and requests
Contact support@sanctionskit.com to discuss access, correction, deletion, or a concern about source-derived information. The operator must verify the requester’s authority and applicable rights before disclosing or altering personal information. Customers remain responsible for the legality and relevance of the data they submit and for copies they export.
Your organization is responsible for selecting an appropriate retention period and ensuring it has authority to submit screening information. Contact SanctionsKit before submitting information that requires a specific processing arrangement.