ChainProof

Privacy Notice

Effective October 1, 2026.

1. Controller

The controller is ChainproofS, a sole trader established in Sweden, with business address Östergatan 16, 21125 Malmö, Sweden. VAT number (Momsregistreringsnummer): SE881026593701. The organization number is available to customers on request by emailing privacy@chainproofcloud.com. Contact: privacy@chainproofcloud.com.

2. Information processed

Depending on how you use ChainProof, the service processes your name, company name, email address, password hash, email-verification status, API credential hashes, hashed session and verification/reset tokens, subscription and Stripe customer identifiers, plan, billing status, and usage totals. API requests contain a blockchain network and transaction identifier; service audit records may also contain request ID, time, method, endpoint, outcome, and related verification details. Security and hosting systems may process technical connection data. ChainProof does not ask for wallet private keys or store payment-card numbers.

3. Purposes and legal bases

Account, authentication, email verification, API delivery, usage measurement, and subscription management are processed to provide the requested service and take steps requested before a contract. Security, abuse prevention, troubleshooting, and service reliability are based on the Operator’s legitimate interests, subject to applicable balancing requirements. Invoices and required business records are processed to meet legal obligations.

4. Service providers and disclosures

Transaction identifiers are sent to the configured blockchain RPC providers, including Alchemy and QuickNode, to retrieve public transaction data; the relevant public blockchain may also be queried. Stripe processes checkout, subscription, and billing events. DigitalOcean hosts the production VPS and encrypted off-site backups in Frankfurt, Germany. SiteGround hosts this site and the support/privacy mailboxes. Mailgun sends transactional email. These providers process information under their own terms and applicable agreements.

5. International transfers

Because the service uses external providers, information may be processed outside Sweden or the European Economic Area, depending on the provider and service. For details about a specific provider’s processing location and transfer safeguards, contact privacy@chainproofcloud.com.

6. Cookies and similar technologies

The account portal uses an essential `chainproof_session` cookie to keep a signed-in session. It is HTTP-only, uses SameSite=Lax, is marked Secure over HTTPS, and expires after 12 hours. The application pages do not contain analytics or advertising tracking code. This notice will be updated before any non-essential tracking is introduced.

7. Retention and deletion

Account and service records are retained while needed to provide the service, protect it, resolve disputes, and meet legal obligations. Account-closure and deletion requests are handled manually by email, not through a self-service control. Billing and accounting records may be retained for periods required by applicable Swedish law. Encrypted disaster-recovery backups use a 7-daily, 4-weekly, and 12-monthly snapshot policy, so deleted data may remain in an inaccessible backup until that snapshot expires, for up to 12 months.

8. Your rights

Where applicable law grants these rights, you may request access, correction, deletion, restriction, portability, or object to certain processing. Contact privacy@chainproofcloud.com. You may also lodge a complaint with the competent supervisory authority; for Sweden, the Swedish Authority for Privacy Protection (IMY).

9. Security and updates

Passwords, API credentials, sessions, and email tokens are stored as one-way hashes where applicable; backups are encrypted with Restic. No internet service can guarantee absolute security. This notice will be updated if the service, vendors, tracking, retention, or data uses change. Effective date: October 1, 2026.