PROOFCHAIN
Home Dashboard KYA Pricing Get Started
Legal · Data Processing Addendum

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between ProofChain and its customers (each a "Controller") under which ProofChain processes personal data on the Controller's behalf in connection with the ProofChain service. It reflects the requirements of the GDPR (Regulation (EU) 2016/679), the UK GDPR, and the Swiss FADP.

Effective: 11 August 2026 Version: 1.2 Contact: dpo@proofchain.us
§1

Definitions and Interpretation

Capitalized terms used but not defined in this DPA have the meanings given in the GDPR and the ProofChain Terms of Service. In particular: "Controller" means the ProofChain customer who determines the purposes and means of processing; "Processor" means ProofChain, which processes personal data on the Controller's behalf; "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"); "Sub-processor" means any processor engaged by ProofChain to process Personal Data on behalf of the Controller; and "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and erasure.

In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

§2

Controller and Processor Roles

ProofChain processes Personal Data strictly as a Processor on behalf of the Controller, who acts as Controller with respect to the personal data uploaded to, generated by, or recorded through the ProofChain service. The parties acknowledge and agree that:

  • The Controller determines the purposes and means of processing, including which agent actions are recorded, which audit trails are generated, and which reports are produced.
  • The Processor processes Personal Data only on documented instructions from the Controller, unless required to do so by applicable law — in which case ProofChain will inform the Controller of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
  • Neither party is a joint controller. ProofChain does not determine the purposes and means of processing and does not use Controller Personal Data for its own independent purposes, including advertising, profiling, or product improvement, except as permitted under this DPA.
  • The Controller warrants that it has a lawful basis for the processing and that it has provided all required privacy notices to Data Subjects.
§3

Processing Details

The subject matter, nature, and purpose of the processing are described below and are further specified in the Controller's configuration of the ProofChain service:

ElementDescription
Subject matterProvision of ProofChain's verifiable AI agent compliance infrastructure, including agent registration, audit trail recording, compliance reporting, and KYA attestations.
Nature and purposeRecording, encrypting, storing, and verifying agent actions and operator attributions; generating tamper-evident compliance evidence; and providing the associated dashboard, registry, and reporting surfaces.
Categories of dataAgent operator identifiers (wallet-derived pseudonymous identifiers), agent metadata, action logs, timestamps, configuration data, and compliance-report data; payment and account data processed by Stripe.
Categories of data subjectsAgent operators, administrators, and end users of the Controller's AI systems whose actions are recorded through ProofChain.
RetentionPersonal Data is retained for the duration of the agreement and then for the minimum period required by law or the Controller's documented instructions, subject to the immutability of on-chain records (see §6).
§4

Instructions and Compliance

ProofChain will process Personal Data only on the Controller's documented instructions, which are established by this DPA and the Controller's configuration of the service. The Controller instructs ProofChain to:

  • Process Personal Data to provide, secure, and operate the ProofChain service;
  • Encrypt Personal Data using HXMP prior to on-chain recording, such that only authorized key holders can decrypt it;
  • Retain and, where applicable, cryptographically erase Personal Data in accordance with the Controller's documented instructions and this DPA; and
  • Assist the Controller in meeting its obligations under the GDPR, including Articles 32–36.

If ProofChain believes an instruction infringes the GDPR or other applicable data protection law, it will promptly inform the Controller.

§5

Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, ProofChain implements the following technical and organizational measures pursuant to Article 32 of the GDPR:

  • HXMP encryption at rest. All potentially personal data is encrypted using HXMP (ProofChain's hybrid encryption scheme) prior to storage or on-chain recording. Only authorized key holders — designated by the Controller — can decrypt records. Keys are managed independently of ciphertext.
  • Encryption in transit. All data transmitted to and from ProofChain infrastructure is protected with TLS 1.2 or later.
  • Cryptographic erasure. Where erasure is required, ProofChain destroys the encryption keys associated with the relevant records, rendering the ciphertext permanently inaccessible. Key destruction is logged, attested, and itself recorded on-chain for verifiability.
  • Access control. Access to decrypted data is restricted to authenticated principals using wallet-based authentication (AgentID), with per-key and per-scope authorization enforced at the application layer.
  • Network security. ProofChain infrastructure is protected by a firewall with CrowdSec-managed reputation filtering, rate limiting, and least-privilege network segmentation.
  • Personnel. Access to production systems is restricted, role-based, logged, and subject to confidentiality obligations and periodic access review.
  • Regular testing. Security controls are assessed through penetration testing, vulnerability scanning, and continuous monitoring; findings are remediated according to severity.
§6

On-Chain Recording and Immutability

ProofChain records cryptographic commitments of agent actions on the X1 blockchain. On-chain records are immutable by design: ProofChain cannot delete, modify, or redact data committed to the ledger. This immutability is the tamper-evidence property on which the service's compliance value depends.

To reconcile immutability with data protection obligations, ProofChain encrypts all potentially personal data with HXMP before on-chain recording. Where the Controller requires erasure of Personal Data under GDPR Article 17 or this DPA, ProofChain will destroy the encryption keys for the relevant records, rendering them permanently inaccessible — a measure recognized as erasure under applicable data protection law. The encrypted ciphertext remains on the ledger; the Controller acknowledges and accepts this architectural constraint as a documented instruction under this DPA.

§7

Sub-processor Authorization

The Controller grants ProofChain a general authorization to engage sub-processors to support the provision of the service, subject to the following conditions:

  • ProofChain will maintain a current list of sub-processors and make it available to the Controller on request, with notification of any intended additions or replacements.
  • ProofChain will provide the Controller at least 30 days' prior notice of any new or replacement sub-processor before that sub-processor begins processing Personal Data.
  • The Controller may object to a new sub-processor within 10 days of notice on reasonable data-protection grounds; where a mutually agreeable resolution cannot be reached, the Controller may terminate the affected service without penalty.
  • Each sub-processor will be bound by a written contract imposing data-protection obligations no less protective than those in this DPA, including confidentiality, security, and assistance obligations.
  • ProofChain remains fully liable to the Controller for the performance of its sub-processors' obligations.

Current sub-processors include Stripe (payment processing) and cloud infrastructure providers used to host the service. The complete list is available at /subprocessors or on request from dpo@proofchain.us.

§8

Data Subject Request Assistance

Taking into account the nature of the processing, ProofChain will assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR — including rights of access, rectification, erasure, restriction, portability, and objection.

Where a Data Subject contacts ProofChain directly with such a request, ProofChain will promptly forward it to the Controller and provide reasonable cooperation, which may include:

  • Locating and providing access to records associated with the Data Subject's pseudonymous identifiers;
  • Executing cryptographic erasure where the Controller instructs erasure of specific records;
  • Producing attestations of erasure and of the access controls applied to the records; and
  • Supporting the Controller's response with technical documentation where required.

ProofChain will not respond to a Data Subject request on the Controller's behalf except as the Controller directs or as required by law.

§9

Breach Notification

ProofChain will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Controller Personal Data, as required by GDPR Article 33(2) and Article 4(12). The notification will include, to the extent available:

  • The nature of the personal data breach, including the categories and approximate number of Data Subjects and records concerned;
  • The likely consequences of the breach;
  • The measures taken or proposed to address the breach and mitigate its possible adverse effects; and
  • The contact point from whom further information can be obtained.

ProofChain will document all breaches, including the facts, effects, and remedial action taken, and will cooperate with the Controller in the Controller's own notification and documentation obligations to supervisory authorities and Data Subjects. Notifications are sent to the Controller's registered contact details and to security@proofchain.us.

§10

International Transfers

Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, ProofChain will ensure that appropriate safeguards are in place, primarily the EU Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914, together with Supplementary Measures where required following the Schrems II framework.

  • Module Two (Controller to Processor) applies where ProofChain processes Personal Data as a processor for a Controller established in the EEA, UK, or Switzerland.
  • Module Three (Processor to Processor) applies to transfers between ProofChain and its sub-processors.
  • Where the UK GDPR applies, transfers are governed by the UK International Data Transfer Addendum to the EU SCCs (or the UK's approved transfer mechanism).
  • ProofChain will implement supplementary measures (including encryption in transit and at rest, and access restrictions) to ensure an essentially equivalent level of protection, and will promptly inform the Controller if it can no longer ensure compliance.
§11

Audit Rights

Upon reasonable notice, and no more than once per calendar year (or more frequently in the event of a personal data breach or upon a supervisory authority's request), the Controller or a mandated auditor may audit ProofChain's compliance with this DPA, including by reviewing the security documentation, attestations, and on-chain evidence described in this DPA. ProofChain will provide all information necessary to demonstrate compliance and will contribute to audits and inspections. The Controller will ensure any audit does not unreasonably disrupt ProofChain's operations and is conducted under confidentiality obligations.

Because ProofChain's controls are evidenced on-chain and in verifiable attestations, much of the audit evidence is available programmatically and continuously, without the need for an on-site visit.

§12

Records of Processing and Documentation

ProofChain maintains records of processing activities in accordance with GDPR Article 30, including the categories of processing performed, technical and organizational measures applied, and sub-processors engaged. These records are available to the Controller on request and are reflected in the ProofChain compliance report generated for each customer workspace.

§13

Liability and Indemnification

Each party's liability arising out of or related to this DPA — including liability for fines, penalties, claims, and damages arising from that party's breach of its data-protection obligations — shall be subject to the limitation of liability provisions in the applicable agreement between the parties, and neither party's aggregate liability under this DPA shall exceed the limitations set out in that agreement. Each party shall indemnify the other for claims arising from its own processing in breach of this DPA to the extent permitted by law.

§14

Duration and Termination

This DPA takes effect on the effective date above and continues in force until the earlier of (a) termination of the underlying agreement between the Controller and ProofChain, or (b) the date on which ProofChain ceases to process Personal Data on the Controller's behalf.

Upon termination or expiry:

  • ProofChain will, at the Controller's documented choice, delete or return all Controller Personal Data within a reasonable period (not exceeding 90 days), except where continued storage is required by applicable law;
  • Where on-chain records cannot be deleted due to the immutability of the X1 blockchain, ProofChain will perform cryptographic erasure — destroying the encryption keys for the relevant records — and provide a verifiable erasure attestation to the Controller;
  • ProofChain will certify in writing that deletion or key destruction has been completed, unless legal retention obligations apply; and
  • Any provision of this DPA that by its nature should survive termination — including liability, confidentiality, and audit provisions — will survive.
§15

Governing Law and Miscellaneous

This DPA is governed by the laws of the State of Minnesota, without regard to conflict-of-law principles, and disputes shall be resolved in the state or federal courts located in Stearns County, Minnesota, except where data protection law of the EEA, UK, or Switzerland provides a different mandatory basis for a claim by a Data Subject or supervisory authority. This DPA may be amended only in writing. If any provision is held invalid or unenforceable, the remaining provisions remain in effect.

§16

Contact and Sign-off

Questions about this DPA, sub-processor authorization, or data protection matters should be directed to:

dpo@proofchain.us security@proofchain.us Sub-processor List Privacy Policy

By using the ProofChain service, the Controller accepts and agrees to the terms of this DPA, including the general sub-processor authorization in §7, the on-chain immutability and cryptographic erasure framework in §6, and the international transfer safeguards in §10.

Summary. ProofChain acts as a processor on your documented instructions, encrypts personal data with HXMP at rest and in transit, notifies you of breaches within 72 hours, assists with data subject requests, transfers data under SCCs, and — where on-chain records are immutable — performs cryptographic key destruction as a recognized form of erasure. You can audit our controls continuously via on-chain attestations.

PROOFCHAIN

Verifiable AI agent compliance infrastructure. On-chain identity. Tamper-evident audit trails. Automated regulatory reporting.

Product

Dashboard KYA Report Pricing

Legal

Privacy Policy Terms of Service Cookie Policy Data Processing Addendum

Trust

Security KYA Report a Vulnerability

Not Legal Advice. ProofChain is a technology platform and compliance automation tool. ProofChain is not a law firm, does not employ attorneys, and does not provide legal advice, legal opinions, or legal representation. The compliance reports, templates, and documentation generated by ProofChain are provided for informational and operational purposes only. You should consult qualified legal counsel regarding your specific regulatory obligations under the EU AI Act, GDPR, SOC 2, ISO standards, NIS2, or any other applicable law or regulation.

On-Chain Data. Agent audit trail data recorded on the X1 blockchain is immutable by design. ProofChain cannot delete, modify, or redact data committed to the blockchain. This is a feature, not a bug — it ensures tamper-evidence. Prior to recording agent actions on-chain, ProofChain encrypts all potentially personal data using HXMP such that only authorized key holders can decrypt it. If you require erasure of personal data under GDPR Article 17, ProofChain will destroy the encryption keys for the relevant records, rendering them permanently inaccessible, which constitutes erasure under applicable data protection law. However, the encrypted ciphertext will remain on the blockchain ledger. By using ProofChain, you acknowledge and accept this architectural constraint.

PROOFCHAIN · X1 CHAIN · FKwU1im523MSGnuJG6YLHEZu4rUGj3xqxHJ6ipQMBG9B © 2026 ProofChain. All rights reserved.