Enterprise Privacy Policy
Effective Date: July 1, 2026 • Last Revised: September 4, 2026 • Operating Entity: UnyKorn LLC (EIN: 42-3536633)
1. Introduction & Operating Scope
UnyKorn LLC, doing business as Y3K Markets ("Y3K Markets", "Company", "we", "us", or "our"), provides enterprise white-label financial technology software, real-world asset (RWA) tokenization infrastructure, and application development kits to commercial institutions, licensed banks, and institutional sponsors ("Clients").
This Enterprise Privacy Policy governs how personal and non-public financial information (NPI) is ingested, encrypted, processed, and maintained across our cloud infrastructure, APIs, and client-facing applications.
2. Fundamental Data Principles
- Zero Data Monetization: We do not sell, rent, license, or monetize Client, user, or transaction data under any circumstances.
- Tenant Isolation: Client databases, ledger entries, and encryption key shards are segregated logically and cryptographically per tenant.
- Hardware Key Isolation: Cryptographic private keys on Android and iOS devices are generated directly inside hardware StrongBox / Secure Enclave hardware and never touch Y3K Markets servers.
3. Categories of Information Processed
In our role as a software and workflow provider, we process the following categories strictly on behalf of our Clients:
- Institutional Account Information: Corporate entity names, jurisdiction of formation, Employer Identification Numbers (EIN), authorized signers, and corporate resolution records.
- Regulated Onboarding Data (KYC/AML): Cryptographic verification hashes from licensed identity networks, accredited investor status attestations (Rule 506(c)), and PEP/OFAC scanning receipts.
- Ledger & Transaction Telemetry: Account balances, wire instructions, FedNow settlement identifiers, token minting allocations, and audit logs.
- Technical Diagnostics: IP addresses, TLS handshake ciphers, API latency logs, and device hardware identifiers strictly for security monitoring and fraud prevention.
4. Gramm-Leach-Bliley Act (GLBA) & Safeguards Rule
Where we act as a technology service provider to financial institutions subject to the Gramm-Leach-Bliley Act (15 U.S.C. § 6801 et seq.) and FTC Safeguards Rule (16 C.F.R. Part 314), we implement a comprehensive written information security program (WISP), annual penetration tests, multi-factor authentication across all engineering surfaces, and automated audit logging.
5. Subprocessors & Cloud Infrastructure
We partner exclusively with enterprise-grade infrastructure providers that maintain active SOC 2 Type II and ISO 27001 certifications:
- Cloudflare Inc. — Edge routing, Anycast DDoS mitigation, and Web Application Firewall (WAF).
- Amazon Web Services (AWS) / Google Cloud Platform (GCP) — Dedicated tenant compute, AES-256 database storage, and Key Management Service (KMS).
- Qualified Banking & Custody Partners — FDIC-insured partner banks and institutional custodians holding funds and digital assets under separate custodial agreements.
6. Data Retention & Erasure
Non-public financial records, KYC verification hashes, and ledger entries are retained in accordance with federal anti-money laundering regulations (Bank Secrecy Act / FinCEN mandates) for a minimum of five (5) years following account closure. Non-statutory application telemetry is purged on a rolling 90-day cycle.
7. Contact Information & Data Protection Officer
For inquiries regarding this policy, data subject access requests, or to contact our Data Protection Officer:
Alpharetta, Georgia, USA
Email: EMAIL_PLACE • Phone: +1-800-555-Y3KM