Data Security and KYC on 8lends: How Data Is Protected

Passport photo, selfie, wallet address — who actually holds your data on 8lends, and why the platform physically cannot touch your funds.

8lends works with two categories of sensitive data: KYC data (document photo, selfie, personal information) and on-chain data (wallet address, transaction history). KYC data is stored with Sumsub — a provider with ISO 27001 and SOC 2 certifications and GDPR compliance, not with 8lends. On-chain data is public by the nature of blockchain. The platform operates under a non-custodial model — 8lends does not have the private key to your wallet and physically cannot withdraw funds. AML screening of the wallet is mandatory for all investments — this is a basic regulatory requirement.

What data 8lends collects

CategoryWhat it includesWhere it is stored
KYC data (identity)Passport/ID photo, selfie, name, date of birth, citizenship, addressWith Sumsub, not with 8lends
AML data (wallet)Wallet address, transaction history, risk scoringWith AML provider + on-chain
Transactional dataInvestments, payouts, claims, sales on the Secondary MarketOn-chain (public) + personal dashboard
Email and notificationsEmail (optional), notification settingsWith 8lends, encrypted
Contact dataSupport requests, correspondenceWith 8lends

KYC data — who stores it and how it is protected

KYC is completed through Sumsub — an international identity verification provider used by major exchanges (Binance, OKX, Bybit) and regulated financial platforms.

Sumsub's certifications and standards:

  • ISO 27001 — international information security standard
  • SOC 2 Type II — audit of security, availability, and confidentiality controls
  • PCI DSS — payment data protection standard
  • GDPR compliance (EU) — personal data protection requirements
  • CCPA compliance (California) — privacy rights
  • GDIC (Global Digital Identity Certification) — Sumsub was the first provider to receive this certification (August 2024)

What this means in practice:

  • 8lends does not store the document photo and does not store the selfie — after KYC they remain only with Sumsub
  • Encryption at rest — data at Sumsub is encrypted on the storage side
  • Encryption in-transit — data transfer over TLS
  • Regular external audits — ISO 27001 and SOC 2 standards require annual checks by independent auditors
  • Biometric data is processed according to the ISO/IEC 30107 standard (Biometric Presentation Attack Detection)

AML wallet screening — mandatory for all

For every investment (including under $500 without KYC), the wallet undergoes automatic AML screening. This is a basic regulatory requirement (VABA 2022 in Saint Vincent, FATF Travel Rule).

What is checked:

  • Sanctions lists: OFAC (USA), UN, EU, HM Treasury (UK)
  • Connection to crypto mixers (Tornado Cash and similar)
  • History of interaction with darknet services
  • Connection to known fraudulent addresses or hacks
  • Connection to jurisdictions on sanctions lists

What is NOT required for AML:

  • Identity documents (this is KYC, not AML)
  • Selfie or biometrics
  • Employer information

AML works only with the public on-chain data of your wallet. No private information is needed for the check.

On-chain data — what is public and what is not

The Base blockchain is public by nature. This means:

What is publicly visible:

  • Your wallet address
  • The full transaction history for that address
  • Balances of USDC, ETH, and other tokens
  • Interaction with the 8lends smart contract
  • The amount of each investment and which project it went into

What is NOT publicly visible:

  • Your identity (name, passport) — this is off-chain at Sumsub
  • The link between the address and a real person
  • The content of support messages

This is pseudonymity — your wallet is visible to everyone, but without KYC data, third parties do not know who owns it. 8lends knows the "address ↔ KYC" link within its own system, but does not publish it on-chain.

Non-custodial model — what it means for security

8lends operates on a non-custodial principle: the platform has no control over your funds.

What this means technically:

  • 8lends does not know your seed phrase — only you know it
  • 8lends does not have the private key to your wallet
  • Every transaction requires your signature in the wallet (MetaMask, Trust Wallet)
  • The platform cannot deduct USDC without explicit confirmation through the wallet
  • If 8lends servers are hacked, your funds remain on the blockchain under your control

Risk surface — what is reduced

Comparative table of custodial vs non-custodial risks:

ScenarioCustodial platform (exchange)8lends (non-custodial)
Server hackHigh risk of losing fundsFunds on the blockchain are safe
Platform bankruptcyFunds frozen, return not guaranteedFunds available in the wallet
Regulator shuts down the platformWithdrawal access blockedFunds remain on-chain
Loss of platform passwordRecovered through KYCNot applicable (no password)
Loss of wallet seed phraseNot applicableFunds lost forever

The investor's main responsibility in the non-custodial model is keeping the seed phrase safe.

Data retention periods

Type of dataRetention periodBasis
KYC dataAt least 5 years after the end of the relationshipVABA 2022, AML/CFT Act 2014, FATF Recommendation 16
AML checksAt least 5 yearsFATF, SVG regulation
Transactional dataAt least 5 yearsAML/CFT Act 2014
Email and support correspondenceUp to 3 years after the relationship endsGDPR + business needs
Session cookiesSession (until the browser is closed)Technical

The periods comply with international standards, including FATF Recommendation 16 and SVG VABA 2022 regulatory requirements. Data may be retained beyond the basic minimum in cases where the data is critical for ongoing investigations or legal proceedings.

Your rights as an investor

In accordance with GDPR (for EU residents) and similar rules in other jurisdictions, you have the right to:

  • Request a copy of your data — what data is stored, where, and in what format
  • Request correction of inaccurate data
  • Request deletion of data (with caveats — some data must be retained under AML)
  • Object to data processing for marketing purposes
  • Request data portability — receive data in a machine-readable format
  • File a complaint with the supervisory authority of your country of residence

To exercise these rights — contact [email protected] specifying the particular request.

Wallet security — on the investor's side

8lends protects data on its side, but wallet security is the investor's responsibility. Basic recommendations:

  • Write down the seed phrase on paper, store it separately from the device, not in the cloud or on your phone
  • Never share the seed phrase with anyone, including "8lends support" (we do not request it)
  • A hardware wallet (Ledger / Trezor) is the best option for large amounts
  • Two-factor authentication on email and exchanges
  • Anti-phishing: always check the URL — only app.8lends.io, no clones
  • Regular updates to the wallet and operating system
  • A separate wallet for investments — do not mix it with your wallet for DeFi experiments

More on scam protection

Regulatory data protection

Regulator / regulationWhat applies to 8lends
VABA 2022 (SVG)AML/CFT, retention periods, reporting to the regulator
AML/CFT Act 2014 (SVG)Customer identification, record keeping
FATF Travel RuleTransfer of sender/recipient transaction data
GDPR (for EU clients)Rights to access, deletion, portability
CCPA (for California clients)US equivalent of GDPR
PolyReg SRO / FINMASwiss AML standards via Maclear AG

What 8lends does NOT do with data

  • Does not sell data to third parties
  • Does not use KYC data for marketing or advertising
  • Does not transfer biometrics to third parties (it remains with Sumsub)
  • Does not publish the "address ↔ identity" link on-chain
  • Does not store payment information (cards are processed by Meld.io)
  • Does not have access to your private key or seed phrase

Frequently asked questions

Where exactly are the photos of my documents stored? With Sumsub — the KYC provider. Sumsub has data centers in the EU (for GDPR compliance) and in the USA. The exact geographic placement is in the Sumsub Privacy Policy. 8lends receives from Sumsub only the result of the check (passed/rejected/pending), not the documents themselves.

Can someone find out that I invest on 8lends through the blockchain? It is visible that your wallet address interacts with the 8lends smart contract — this is public. But who is behind that address is not published. The "address ↔ identity" link is known only to 8lends and Sumsub in their internal systems, and is not disclosed publicly without a legal basis.

What if I am hacked and my seed phrase is stolen? This is a critical situation. 8lends cannot return the funds — the wallet and its contents are fully controlled by the seed phrase. This is a basic property of Web3. That is why protecting the seed phrase is the most important aspect of personal security.

Can the regulator request my data from 8lends? Yes, if there is a lawful basis (a court request, an AML/CFT investigation, a tax audit with international legal assistance). 8lends is obliged to provide data to the regulator upon request — this is a standard norm for all regulated financial platforms. But without a lawful basis, data is not provided.

Does 8lends report data to tax authorities? Not automatically. Alpha Systems LLC (the operator of 8lends) is a VASP company under the FSA SVG; it does not file CRS/DAC reports to the national tax authorities of European countries. If such reporting is needed for you, this is your responsibility as an investor. Upon an official request from a tax authority (for example, through international legal assistance), data is provided.

What if Sumsub is hacked? Sumsub has ISO 27001, SOC 2 Type II, and regular external audits. This reduces the risk but does not eliminate it entirely. In the event of a breach, Sumsub is obliged to notify users and regulators in accordance with GDPR. For the user, this means a risk of a leak of KYC data (document photo, selfie) — the same risks as in a hack of any bank or exchange with KYC.

How do I delete my data from 8lends? Through a request to [email protected]. The following will be deleted: email, support correspondence, marketing data. The following cannot be deleted (due to regulatory requirements): KYC data and AML checks (at least 5 years according to FATF / SVG AML/CFT Act), transaction records. After the regulatory periods expire, the data is deleted.

Is it safe to hold large amounts on 8lends? 8lends is a non-custodial platform, so funds are not on 8lends but in your wallet. "Large amounts on 8lends" technically means "large amounts in my wallet, invested in 8lends smart contracts." The protection is:

  • A hardware wallet (Ledger/Trezor) for large amounts
  • CertiK + Cyberscope audits for 8lends smart contracts
  • Diversification across several projects
  • A backup wallet for other experiments

Does 8lends use cookies or tracking? Only technical cookies for the interface to function. Marketing tracking is used minimally — only aggregated analytics are used, with no link to a specific user.

Where can I find the full text of the Privacy Policy? On app.8lends.io in the documents section — Privacy Policy and Terms & Conditions. These documents are updated regularly as the regulatory environment changes.

See also:

  • How to Start Investing on 8lends: Video Overview
  • Completing KYC via Sumsub on 8lends
  • How 8lends Protects Investors
  • How to Identify Official 8lends Team Members and Avoid Scammers
  • Tax Guide for 8lends Investors via Blockpit
  • Glossary: Key 8lends Terms

Disclosure: 8lends is a platform operated by Alpha Systems LLC, registered as a VASP under the supervision of the FSA of Saint Vincent and the Grenadines. Maclear AG (Switzerland), a member of PolyReg SRO under the supervision of FINMA, acts as Collateral Agent. KYC through Sumsub complies with the requirements of the AML/CFT Act Regulations 2014 and the Virtual Asset Business Act 2022 (in force since 31 May 2025). Sumsub holds ISO 27001, SOC 2 Type II, PCI DSS certifications and GDPR compliance. Regulatory framework as of May 2026.