LEGAL COMPLIANCE // GLBA, GDPR & CCPA

Enterprise Privacy Policy

Effective Date: July 1, 2026 • Last Revised: September 4, 2026 • Operating Entity: UnyKorn LLC (EIN: 42-3536633)

1. Introduction & Operating Scope

UnyKorn LLC, doing business as Y3K Markets ("Y3K Markets", "Company", "we", "us", or "our"), provides enterprise white-label financial technology software, real-world asset (RWA) tokenization infrastructure, and application development kits to commercial institutions, licensed banks, and institutional sponsors ("Clients").

This Enterprise Privacy Policy governs how personal and non-public financial information (NPI) is ingested, encrypted, processed, and maintained across our cloud infrastructure, APIs, and client-facing applications.

2. Fundamental Data Principles

  • Zero Data Monetization: We do not sell, rent, license, or monetize Client, user, or transaction data under any circumstances.
  • Tenant Isolation: Client databases, ledger entries, and encryption key shards are segregated logically and cryptographically per tenant.
  • Hardware Key Isolation: Cryptographic private keys on Android and iOS devices are generated directly inside hardware StrongBox / Secure Enclave hardware and never touch Y3K Markets servers.

3. Categories of Information Processed

In our role as a software and workflow provider, we process the following categories strictly on behalf of our Clients:

  • Institutional Account Information: Corporate entity names, jurisdiction of formation, Employer Identification Numbers (EIN), authorized signers, and corporate resolution records.
  • Regulated Onboarding Data (KYC/AML): Cryptographic verification hashes from licensed identity networks, accredited investor status attestations (Rule 506(c)), and PEP/OFAC scanning receipts.
  • Ledger & Transaction Telemetry: Account balances, wire instructions, FedNow settlement identifiers, token minting allocations, and audit logs.
  • Technical Diagnostics: IP addresses, TLS handshake ciphers, API latency logs, and device hardware identifiers strictly for security monitoring and fraud prevention.

4. Gramm-Leach-Bliley Act (GLBA) & Safeguards Rule

Where we act as a technology service provider to financial institutions subject to the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and FTC Safeguards Rule (16 C.F.R. Part 314), we implement a comprehensive written information security program (WISP), annual penetration tests, multi-factor authentication across all engineering surfaces, and automated audit logging.

5. Subprocessors & Cloud Infrastructure

We partner exclusively with enterprise-grade infrastructure providers that maintain active SOC 2 Type II and ISO 27001 certifications:

  • Cloudflare Inc. — Edge routing, Anycast DDoS mitigation, and Web Application Firewall (WAF).
  • Amazon Web Services (AWS) / Google Cloud Platform (GCP) — Dedicated tenant compute, AES-256 database storage, and Key Management Service (KMS).
  • Qualified Banking & Custody Partners — FDIC-insured partner banks and institutional custodians holding funds and digital assets under separate custodial agreements.

6. Data Retention & Erasure

Non-public financial records, KYC verification hashes, and ledger entries are retained in accordance with federal anti-money laundering regulations (Bank Secrecy Act / FinCEN mandates) for a minimum of five (5) years following account closure. Non-statutory application telemetry is purged on a rolling 90-day cycle.

7. Contact Information & Data Protection Officer

For inquiries regarding this policy, data subject access requests, or to contact our Data Protection Officer:

UnyKorn LLC • Attn: Data Protection Officer
Alpharetta, Georgia, USA
Email: EMAIL_PLACE • Phone: +1-800-555-Y3KM