If funds have moved in the last 24 hours, contact us immediately — early action materially improves outcomes.
Legal

Privacy policy

Last updated 20 August 2026

Template notice

This policy is a working starting point drafted for a digital asset investigation business. It is not legal advice. Before publishing, have it reviewed against the law applying to your jurisdiction and your clients' — in particular the UK GDPR, the EU GDPR, and applicable US state privacy laws — and replace the entity details, retention periods and contact points with your own.

1. Who we are

Pinnacle Recovery Ltd ("we", "us") operates this website and provides digital asset investigation services. We are the data controller for the personal data described in this policy. Data protection enquiries should be sent to support@pinnaclerecoveryservice.com.

2. What we collect

Information you give us

  • Contact details — name, email address, telephone number, country of residence, and your preferred method of contact.
  • Case information — your account of the incident, the platform involved, dates, amounts, wallet addresses, transaction hashes, and details of the party who defrauded you.
  • Evidence files — screenshots, chat exports, email files, financial statements, saved web pages and other documents you upload.
  • Correspondence — messages you send through the case tracker, the contact form, email or WhatsApp.

Information collected automatically

  • Technical data — a one-way hash of your IP address, and your browser's user-agent string, recorded with form submissions for abuse prevention and rate limiting. We do not store raw IP addresses against case records.
  • Session cookie — a single strictly necessary cookie that keeps you signed in to case tracking and protects forms against cross-site request forgery. We do not use advertising or analytics cookies, and we do not embed third-party trackers.

Special category and sensitive data

Case files can contain financial information and, occasionally, information about health or personal circumstances where you have chosen to include it. Please share only what is relevant to your case. Never send us seed phrases, recovery phrases, private keys or account passwords — we do not need them, we will never ask for them, and you should treat any request for them as fraudulent.

3. Why we process it, and on what legal basis

  • To assess and investigate your case — performance of a contract, or steps taken at your request before entering one.
  • To communicate with you about your case and enquiries — contract and legitimate interests.
  • To prepare and submit evidence to exchanges, regulators and law enforcement on your instruction — contract, and in some cases the establishment or defence of legal claims.
  • To prevent abuse of this website, including rate limiting and spam filtering — legitimate interests.
  • To comply with legal obligations, including anti-money-laundering and record-keeping requirements where they apply.
  • To publish a client review — only on the basis of your explicit, separately given consent, which you can withdraw at any time.

4. Who we share it with

We share case information only where it is necessary and, wherever possible, only with your instruction:

  • Cryptocurrency exchanges and financial institutions, when submitting evidence identifying tainted deposits.
  • Law enforcement and financial regulators, when submitting evidence packages or complying with a lawful request.
  • Legal professionals instructed by you, or by us on your behalf with your agreement.
  • Service providers who host our infrastructure and deliver our email, under written data processing terms.

We do not sell personal data, we do not share it for advertising, and we do not disclose your identity publicly without your consent.

5. International transfers

Investigations frequently involve parties in other countries. Where personal data is transferred outside your jurisdiction, we rely on an adequacy decision where one exists, and otherwise on appropriate safeguards such as standard contractual clauses. You may request details of the safeguards applying to your case.

6. How long we keep it

Case records and evidence are retained for 36 months after a case closes, so that material remains available if an investigation reopens or a prosecution follows. Contact enquiries that do not become cases are kept for 12 months. Where a legal, regulatory or evidential obligation requires longer retention, we keep the data for that period and no longer.

7. How we protect it

  • Traffic between your browser and this site is encrypted in transit.
  • Evidence files are stored outside the publicly reachable web directory and are not retrievable by web address; access requires an authenticated staff session.
  • Every uploaded file is hashed on receipt, so any later alteration is detectable.
  • Access to case records is limited to the specialists assigned to that case.
  • Staff actions on case records are recorded in an audit log.
  • Passwords are stored only as salted, computationally expensive hashes.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Have inaccurate data corrected.
  • Have data erased, where we have no overriding legal or evidential reason to keep it.
  • Restrict or object to processing carried out on the basis of legitimate interests.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Complain to your data protection authority — in the UK, the Information Commissioner's Office.

To exercise any of these, email support@pinnaclerecoveryservice.com. We respond within one month. Note that erasing a case file may prevent us from continuing an active investigation, and we will tell you if that is the case before acting.

9. Cookies

We set one strictly necessary session cookie. It contains no personal information, it expires when you close your browser, and it exists to keep you signed in to case tracking and to protect forms against cross-site request forgery. Because we set no analytics, advertising or profiling cookies, no consent banner is required.

10. Third-party services

If you contact us via WhatsApp, that conversation is also subject to WhatsApp's own privacy terms, over which we have no control. Links to external sites — including blockchain explorers, regulators and reporting authorities — are provided for your convenience; we are not responsible for their content or privacy practices.

11. Children

Our services are not directed at people under 18, and we do not knowingly collect their data. If you believe a child's data has been submitted, contact us and we will delete it.

12. Changes

We may update this policy. Material changes affecting how we use case data will be notified to active clients by email. The date at the top of this page shows when it was last revised.

13. Contact

Data protection enquiries: support@pinnaclerecoveryservice.com
General enquiries: our contact page
Post: 1 Example Plaza, Suite 400, Wilmington, DE 19801, USA

Chat with us