This Data Processing Addendum ("DPA") forms part of the agreement between ProofChain and its customers (each a "Controller") under which ProofChain processes personal data on the Controller's behalf in connection with the ProofChain service. It reflects the requirements of the GDPR (Regulation (EU) 2016/679), the UK GDPR, and the Swiss FADP.
Capitalized terms used but not defined in this DPA have the meanings given in the GDPR and the ProofChain Terms of Service. In particular: "Controller" means the ProofChain customer who determines the purposes and means of processing; "Processor" means ProofChain, which processes personal data on the Controller's behalf; "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"); "Sub-processor" means any processor engaged by ProofChain to process Personal Data on behalf of the Controller; and "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and erasure.
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.
ProofChain processes Personal Data strictly as a Processor on behalf of the Controller, who acts as Controller with respect to the personal data uploaded to, generated by, or recorded through the ProofChain service. The parties acknowledge and agree that:
The subject matter, nature, and purpose of the processing are described below and are further specified in the Controller's configuration of the ProofChain service:
| Element | Description |
|---|---|
| Subject matter | Provision of ProofChain's verifiable AI agent compliance infrastructure, including agent registration, audit trail recording, compliance reporting, and KYA attestations. |
| Nature and purpose | Recording, encrypting, storing, and verifying agent actions and operator attributions; generating tamper-evident compliance evidence; and providing the associated dashboard, registry, and reporting surfaces. |
| Categories of data | Agent operator identifiers (wallet-derived pseudonymous identifiers), agent metadata, action logs, timestamps, configuration data, and compliance-report data; payment and account data processed by Stripe. |
| Categories of data subjects | Agent operators, administrators, and end users of the Controller's AI systems whose actions are recorded through ProofChain. |
| Retention | Personal Data is retained for the duration of the agreement and then for the minimum period required by law or the Controller's documented instructions, subject to the immutability of on-chain records (see §6). |
ProofChain will process Personal Data only on the Controller's documented instructions, which are established by this DPA and the Controller's configuration of the service. The Controller instructs ProofChain to:
If ProofChain believes an instruction infringes the GDPR or other applicable data protection law, it will promptly inform the Controller.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, ProofChain implements the following technical and organizational measures pursuant to Article 32 of the GDPR:
ProofChain records cryptographic commitments of agent actions on the X1 blockchain. On-chain records are immutable by design: ProofChain cannot delete, modify, or redact data committed to the ledger. This immutability is the tamper-evidence property on which the service's compliance value depends.
To reconcile immutability with data protection obligations, ProofChain encrypts all potentially personal data with HXMP before on-chain recording. Where the Controller requires erasure of Personal Data under GDPR Article 17 or this DPA, ProofChain will destroy the encryption keys for the relevant records, rendering them permanently inaccessible — a measure recognized as erasure under applicable data protection law. The encrypted ciphertext remains on the ledger; the Controller acknowledges and accepts this architectural constraint as a documented instruction under this DPA.
The Controller grants ProofChain a general authorization to engage sub-processors to support the provision of the service, subject to the following conditions:
Current sub-processors include Stripe (payment processing) and cloud infrastructure providers used to host the service. The complete list is available at /subprocessors or on request from dpo@proofchain.us.
Taking into account the nature of the processing, ProofChain will assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR — including rights of access, rectification, erasure, restriction, portability, and objection.
Where a Data Subject contacts ProofChain directly with such a request, ProofChain will promptly forward it to the Controller and provide reasonable cooperation, which may include:
ProofChain will not respond to a Data Subject request on the Controller's behalf except as the Controller directs or as required by law.
ProofChain will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Controller Personal Data, as required by GDPR Article 33(2) and Article 4(12). The notification will include, to the extent available:
ProofChain will document all breaches, including the facts, effects, and remedial action taken, and will cooperate with the Controller in the Controller's own notification and documentation obligations to supervisory authorities and Data Subjects. Notifications are sent to the Controller's registered contact details and to security@proofchain.us.
Where Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, ProofChain will ensure that appropriate safeguards are in place, primarily the EU Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914, together with Supplementary Measures where required following the Schrems II framework.
Upon reasonable notice, and no more than once per calendar year (or more frequently in the event of a personal data breach or upon a supervisory authority's request), the Controller or a mandated auditor may audit ProofChain's compliance with this DPA, including by reviewing the security documentation, attestations, and on-chain evidence described in this DPA. ProofChain will provide all information necessary to demonstrate compliance and will contribute to audits and inspections. The Controller will ensure any audit does not unreasonably disrupt ProofChain's operations and is conducted under confidentiality obligations.
Because ProofChain's controls are evidenced on-chain and in verifiable attestations, much of the audit evidence is available programmatically and continuously, without the need for an on-site visit.
ProofChain maintains records of processing activities in accordance with GDPR Article 30, including the categories of processing performed, technical and organizational measures applied, and sub-processors engaged. These records are available to the Controller on request and are reflected in the ProofChain compliance report generated for each customer workspace.
Each party's liability arising out of or related to this DPA — including liability for fines, penalties, claims, and damages arising from that party's breach of its data-protection obligations — shall be subject to the limitation of liability provisions in the applicable agreement between the parties, and neither party's aggregate liability under this DPA shall exceed the limitations set out in that agreement. Each party shall indemnify the other for claims arising from its own processing in breach of this DPA to the extent permitted by law.
This DPA takes effect on the effective date above and continues in force until the earlier of (a) termination of the underlying agreement between the Controller and ProofChain, or (b) the date on which ProofChain ceases to process Personal Data on the Controller's behalf.
Upon termination or expiry:
This DPA is governed by the laws of the State of Minnesota, without regard to conflict-of-law principles, and disputes shall be resolved in the state or federal courts located in Stearns County, Minnesota, except where data protection law of the EEA, UK, or Switzerland provides a different mandatory basis for a claim by a Data Subject or supervisory authority. This DPA may be amended only in writing. If any provision is held invalid or unenforceable, the remaining provisions remain in effect.
Questions about this DPA, sub-processor authorization, or data protection matters should be directed to:
By using the ProofChain service, the Controller accepts and agrees to the terms of this DPA, including the general sub-processor authorization in §7, the on-chain immutability and cryptographic erasure framework in §6, and the international transfer safeguards in §10.
Summary. ProofChain acts as a processor on your documented instructions, encrypts personal data with HXMP at rest and in transit, notifies you of breaches within 72 hours, assists with data subject requests, transfers data under SCCs, and — where on-chain records are immutable — performs cryptographic key destruction as a recognized form of erasure. You can audit our controls continuously via on-chain attestations.