Last updated: August 2026
1. Overview
The Global Fraud Intelligence Network (GFIN) is an international law enforcement platform for fraud detection, investigation, and prevention. We take your privacy seriously and comply with GDPR, the EU Data Protection Regulation, and applicable national data protection laws.
When you file a fraud complaint, we collect information necessary to investigate and route your case to the appropriate national cybercrime authorities.
2. Data We Collect
- Complaint Data: Scam details, target information (domains, phone numbers, crypto wallets), financial loss amounts, and supporting evidence you provide
- Account Data: Your name, email, country, and phone number (optional) when you register on the Victim Portal
- Technical Data: IP address, browser type, and timestamp for security and abuse prevention
- Uploaded Files: Screenshots, chat logs, transaction records, and other evidence files you submit
3. How We Use Your Data
- To investigate and analyze your fraud complaint
- To route cases to the appropriate national cybercrime authority (e.g., UK Action Fraud, Spanish Policía, German BKA)
- To share anonymized intelligence with Interpol and Europol for cross-border coordination
- To detect patterns across multiple complaints and identify organized fraud networks
- To send you status updates about your complaint
- To improve our scam detection and prevention capabilities
4. Data Sharing
GFIN shares complaint data with:
- National Cybercrime Authorities: Based on the victim's country and the scam's origin country
- Interpol: For cross-border case coordination via National Central Bureaus (NCBs)
- Europol: For EU member state cases via the European Cybercrime Centre (EC3)
We never share your data with private companies, marketing firms, or third-party advertisers.
5. Data Security
- All data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256)
- Police access requires authenticated JWT tokens with role-based permissions
- All system access is logged and auditable
- Victims cannot see other victims' data or police investigation details
- Rate limiting and firewall protections prevent unauthorized access
6. Data Separation
GFIN enforces strict separation between victim and police data:
- Victim Portal: Shows only your complaint status and stage updates
- Police Dashboard: Restricted to authorized law enforcement personnel
- Victims cannot access police investigation records, evidence chains, or other victims' complaints
7. Your Rights (GDPR)
Under GDPR and similar regulations, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Erasure: Request deletion of your data (subject to ongoing investigation requirements)
- Restriction: Limit how we process your data
- Portability: Receive your data in a structured format
- Object: Object to certain types of processing
To exercise these rights, contact: privacy@gfin-system.com
8. Data Retention
- Active investigation data: Retained for the duration of the investigation + 7 years
- Closed cases: Retained for 7 years for pattern analysis and legal compliance
- Account data: Deleted 1 year after last login if no active complaints
- Backups: Daily encrypted backups with 30-day retention
9. International Transfers
GFIN operates on servers in the European Union (Frankfurt region). Data may be transferred to national law enforcement agencies in 189 countries. All transfers are governed by appropriate legal frameworks including MLAT (Mutual Legal Assistance Treaty) and Europol cooperation agreements.
10. Cookies
GFIN uses minimal cookies:
- Authentication: JWT token cookie for police login (7-day expiry)
- No tracking cookies: We do not use Google Analytics, Facebook Pixel, or any third-party tracking
- No advertising cookies
11. Contact
For privacy questions or requests: privacy@gfin-system.com
For data protection officer (DPO) inquiries: dpo@gfin-system.com