Legal
Data Processing Policy
Last updated: 28 July 2026
This Data Processing Policy describes, in operational terms, how data moves through ChainProof — from the address you paste to the risk report you receive. It complements the Privacy Policy, which covers your rights as an individual.
Principles
- Minimisation: only data needed for a risk verdict is processed.
- Purpose limitation: screening data is not reused for unrelated purposes.
- Accuracy: risk labels are reviewed and can be disputed.
- Integrity: access is logged and restricted by role.
Categories of data
- Public on-chain data: addresses, transactions, amounts, timestamps, contract interactions.
- Risk attribution data: cluster labels, sanction-list matches, service categories.
- Service data: request metadata, report identifiers, error logs.
Roles
When you run a check for yourself, we act as controller for the service data and as a processor of the blockchain identifiers you supply. When a business client screens its own customers, that client is the controller and ChainProof acts on its documented instructions.
How a check is processed
- 1. The identifier you submit is validated and normalised.
- 2. Public blockchain data is retrieved and clustered.
- 3. Clusters are matched against risk and sanctions datasets.
- 4. A score and exposure breakdown are generated and returned to you.
- 5. Intermediate data is discarded; the report is stored for your access window.
Sub-processors
We use hosting, database, blockchain data and monitoring providers. Sub-processors are selected for their security posture, bound by written terms, and reviewed periodically. A current list is available on request.
International transfers
Where data leaves your region, transfers rely on recognised safeguards such as standard contractual clauses or adequacy decisions, plus encryption in transit.
Retention and deletion
Reports and their inputs are removed or aggregated once the access window ends. Aggregated statistics that cannot be linked back to you may be retained to improve scoring quality. Deletion requests are executed across backups on their normal rotation cycle.
Accuracy and disputes
An AML score is a probabilistic risk signal, not a legal finding. If you believe a label attached to an address is wrong, you can ask for a manual review; we document the outcome and correct the record where justified.
Incidents
If a security incident affects personal data, we investigate immediately, contain the issue, and notify affected users and the relevant authority where legally required.
Requests
Data-processing questions, sub-processor lists and review requests can be sent to the site operator using the contact details published on this website.