The result is a new set of data that contains no personal information, but retains the format and statistics of the original. The only way that each field in the new data set can be returned to its old state is by applying the key used to generate the hash
these keys are held by the accounts teams. The development teams working on the pseudonymous data never see them
Right ... but I would feel better if I supply this hash/key back to them. I understand I can request erasure, but I would like the option to request "hashed" (or a user friendlier term) when I want to keep my data on their server, but I control it.