Faihoplo Inc. ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use QRYPTA. We comply with the General Data Protection Regulation (GDPR) and applicable US privacy laws including the ESIGN Act and UETA.
| Data Type | Purpose | Required |
|---|---|---|
| Full name | Account identification, contract signing | Yes |
| Email address | Authentication, OTP verification, account recovery | Yes |
| Phone number | SMS OTP authentication (future) | Yes |
| Date of birth | Client key recovery (3-factor auth) only | Yes |
| Country & address | Legal jurisdiction, compliance | Yes |
| Password (hashed) | Account authentication | Yes |
| Data Type | Purpose | Stored |
|---|---|---|
| IP address | Legal audit trail per party | In signed PDF + S3 |
| Device type & browser | Legal audit trail per party | In signed PDF + S3 |
| Signing timestamp | Legal record of when signed | In signed PDF + S3 |
| Contract PDF | Vault storage | AWS S3 Object Lock |
| SHA-256 hash | Contract integrity verification | In signed PDF + S3 |
We record vault access events (STORE, VIEW, DOWNLOAD) in AWS S3 faihoplo-vault-logs bucket. Each log includes: event type, contract ID, user email, user ID, IP address, device type, and timestamp. These logs are required by GDPR and US regulations for data access accountability.
Account information is stored on our secure AWS EC2 server (Ubuntu 24.04) located in the US East (N. Virginia) region. Passwords are hashed using bcrypt — plaintext passwords are never stored.
Executed contracts are stored in AWS S3 with Object Lock Compliance Mode. Contract data is encrypted using AES-256-CBC. Once stored with Object Lock, contracts cannot be deleted or modified by anyone — including Faihoplo Inc. — until the retention period expires.
Vault access event logs are stored in AWS S3 faihoplo-vault-logs bucket with versioning enabled. These logs satisfy GDPR Article 30 records of processing activities.
We share your information only in the following limited circumstances:
QRYPTA records the following information in the legal audit trail embedded in signed contract PDFs:
This information is embedded permanently in the signed PDF and stored in AWS S3. It constitutes the legal audit trail required by ESIGN Act, UETA, and eIDAS. By signing a contract through QRYPTA, you consent to this information being permanently recorded in the contract PDF.
Your date of birth is collected exclusively for client key recovery through three-factor authentication (email + password + date of birth). It is:
| Data Type | Retention Period |
|---|---|
| Account data (name, email, etc.) | Duration of account + 3 years after deletion |
| Password hash | Duration of account only |
| Date of birth | Duration of account only |
| Contract PDFs in vault | Selected retention period (3-30 years) — Object Lock |
| Vault access logs | 5 years minimum (US regulatory requirement) |
| Payment records | 7 years (financial record requirement) |
| OTP codes | 10 minutes (automatically deleted) |
To exercise any of these rights, contact us at htkim@faihoplo.com. We will respond within 30 days.
Faihoplo Inc. implements the following security measures to protect your data:
QRYPTA uses browser localStorage (not cookies) to store:
No tracking cookies, advertising cookies, or third-party analytics are used. Local storage data is cleared upon logout.
QRYPTA is not intended for use by persons under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete such information.
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The effective date at the top of this page indicates when the policy was last updated. Continued use of QRYPTA after changes constitutes acceptance of the updated policy.
For privacy-related questions, requests, or complaints:
For GDPR related complaints in the EU, you have the right to lodge a complaint with your local data protection authority.