TokenSoft and GDPR
CertReports found no public GDPR evidence for TokenSoft as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Oct 2019
- Scope
- As a service provider, we collect the following for our customers on users Service Name Description of Service Personal Data Processing Identity Record Check - Identity validation check, which searches for records that link the full name with the given address, date of birth, or other data provided by the User in the US or other countries. Categories of Personal Data: ● Full name ● Address and post code ● Date of birth ● SSN, tax identification number, or other government issued identification number ● Check status/outcome and related tracking information Special Categories of Personal Data: • None Document Image Check - Verifies the likelihood the document (e.g. government issued photo ID) provided is genuine and, if applicable, cross-references the information written on the document with the validated identity. Categories of Personal Data: ● Identity document and information describing the identity document ● Check status/outcome and related tracking information Special Categories of Personal Data: ● Biometric data ● Race/Ethnicity Facial Similarity Check - Compares the face displayed on an identity document with any other image of a face, to verify that they are the same. Categories of Personal Data: ● Photograph/video of the User’s face (a.k.a. selfie) ● Identity document and information describing the identity document ● Check status/outcome and related tracking information Special Categories of Personal Data: ● Biometric data ● Race/Ethnicity Watchlist Report - Takes the User’s full name and searches the international PEPs and sanctions lists checked for AML laws. Categories of Personal Data: ● Full name ● Address and post code ● Date of birth ● PEPs and sanctions related data ● Check status/outcome and related tracking information Special Categories of Personal Data: ● Criminal Offenses Accredited Investor Services-Takes the User’s full name and financial records to confirm the User meets the definition of “accredited investor” under the Accredited Investor Services. Categories of Personal Data: ● Full name ● Address and post code ● Date of birth ● Bank, investment, or other financial account ● Tax records ● Accounting records ● Other financial information which may be helpful in verifying the user is an accredited investor. Other Services The information may be collected for the purposes of (i) verifying a User’s identity; (ii) mitigating chances of fraud or money laundering; (iii) referring User per User’s request to a third party, (iv) collecting data as requested by the Customer; (v) creating a customer profile with Company or Customer; or (vi) helping Customer manage payments to/from a User or transfers of security tokens to/from User. Categories of Personal Data: • IP address • Device ID or fingerprint • Bank account and routing number to send or receive payment • Bitcoin, Ethereum, or other cryptocurrency address to send or receive payment or a token issued by the Customer • Email address • Job title • Proof of address (e.g. utility bill) • Company name • Company address and post code • Company email address • Company phone
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | TokenSoft Inc: Inactive | Live pagesha256 150a0dc1c8 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is TokenSoft GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.