PC
PROOFCHAIN//NETWORK
Legal Notice  ·  GDPR  ·  EU AI Act Art. 50

Privacy Policy

Version 1.0 / Effective: August 11, 2026 / Last reviewed: August 11, 2026

Contents

  1. Introduction & Our Commitment
  2. Data Controller
  3. Scope & Definitions
  4. Personal Data We Process
  5. Purposes of Processing
  6. Legal Bases (Art. 6 GDPR)
  7. HXMP Encryption at Rest on the X1 Blockchain
  8. On-Chain Immutability & Cryptographic Erasure
  9. Your Data Subject Rights (Art. 15–20)
  10. How to Exercise Your Rights
  11. Data Protection Officer
  12. No Sale of Personal Data
  13. No Automated Decision-Making
  14. Cross-Border Transfers (SCCs)
  15. EU AI Act Article 50 Context
  16. Data Retention
  17. Security Measures
  18. Recipients & Processors
  19. Cookies & Local Storage
  20. Changes to This Policy
  21. Contact & Complaints
§ 01

Introduction & Our Commitment

ProofChain Network operates an attestation and compliance infrastructure that records verifiable, timestamped evidence of AI agent conduct for the purpose of demonstrating compliance with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), in particular Article 50 concerning transparency obligations for AI systems.

This Privacy Policy explains, in plain language and in the formal terms required by the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), what personal data ProofChain Network processes, why we process it, on which legal bases, how long we keep it, and the rights you hold over it.

We process personal data only to the extent necessary to operate the ProofChain network, to issue and maintain compliance attestations, to protect the integrity of the audit trail, and to fulfil our legal obligations. We design our systems so that personal data is minimised, encrypted, and — where technically possible — removed entirely from the reach of any party, including ourselves.

If you are an individual based in the European Economic Area (EEA), the United Kingdom, or Switzerland, the rights and protections described in this Policy apply to you in full. If you are located elsewhere, we extend the same high standard of care to your data as a matter of policy.

Plain English Summary

We are a compliance-record service, not a data broker. We record cryptographic evidence about AI agents — not dossiers about people. Where identifiers or logs could relate to a natural person, they are minimised, encrypted at rest, and never sold.

§ 02

Data Controller

The data controller for the processing described in this Policy is:

ProofChain Network
Stearns County, Minnesota
United States of America
Contact: dpo@proofchain.us

ProofChain Network is a distributed network operation. For the purposes of the GDPR, the entity that determines the purposes and means of the processing described in this Policy is the ProofChain Network operator headquartered in Stearns County, Minnesota, acting as controller for the platform services offered at proofchain.us.

Where the ProofChain network is used by a deploying organisation (a "Client") to record attestations about AI agents that the Client operates, the Client acts as an independent controller for its own decisions about the agents, and ProofChain Network acts as a processor on the Client's behalf with respect to the records we hold for them. That relationship is governed by our Data Processing Agreement, available at /legal/dpa.

§ 03

Scope & Definitions

This Policy applies to all personal data processed by ProofChain Network in connection with the proofchain.us website, the ProofChain dashboard, the KYA (Know Your Agent) compliance seal, the ProofChain API, and any related services (together, the "Services").

Personal Data
Any information relating to an identified or identifiable natural person ("data subject").
Agent Operator
The natural or legal person who operates, deploys, or controls an AI agent registered with or attested by the ProofChain network.
Agent Operator Identifier
A pseudonymous, cryptographically derived identifier (such as a wallet address or public key) that an operator uses to sign attestations and register agents. It is not the operator's name, email address, or any directly identifying credential.
Attestation Record
A timestamped, signed statement — recorded on the X1 blockchain — asserting facts about an AI agent's identity, behaviour, or transparency posture for EU AI Act Article 50 purposes.
Action Log
A chronological record of operations performed through the Services, including API calls, registrations, attestation submissions, and administrative events.
HXMP
The Homomorphic X1 Multi-Party encryption scheme used to encrypt attestation payloads at rest on the X1 blockchain.

Terms defined in the GDPR and in the EU AI Act have the meanings given to them there, unless this Policy provides a more specific definition.

§ 04

Personal Data We Process

We process the following categories of personal data, each only to the extent necessary for the Services:

We do not intentionally collect special categories of personal data (Article 9 GDPR), such as health data, political opinions, religious beliefs, or biometric data. We also do not collect data relating to criminal convictions (Article 10 GDPR). If you send us such data unsolicited, we will delete it or render it inaccessible to the extent legally possible.

We never process more data than the Services require, and we design new features with data minimisation as a default constraint rather than an afterthought.

§ 05

Purposes of Processing

We process personal data for the following purposes:

We do not use personal data for purposes incompatible with those listed above. If we intend to process personal data for a new, incompatible purpose, we will update this Policy and, where the GDPR requires, obtain fresh consent.

§ 06

Legal Bases (Art. 6 GDPR)

In accordance with Article 6 of the GDPR, the legal bases we rely on for each category of processing are:

Where processing is based on legitimate interests, you have the right to object under Article 21 GDPR. We will cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

We keep a current record of our processing activities (Article 30 GDPR) that maps each processing operation to its legal basis, retention period, and security measures.

§ 07

HXMP Encryption at Rest on the X1 Blockchain

Attestation payloads recorded on the X1 blockchain are encrypted at rest using HXMP — the Homomorphic X1 Multi-Party encryption scheme — before they are anchored on-chain.

HXMP encryption ensures that the content of an attestation record is not readable by any party holding only the on-chain bytes. The ciphertext is resistant to inspection by node operators, indexers, and any third party who obtains a copy of the chain, because decryption requires key material that is never stored on-chain.

The scheme is designed so that key shares are distributed across independent parties, so no single party — including ProofChain Network — can decrypt attestation payloads unilaterally. This property is what makes it possible for us to process attestation metadata without being able to read the underlying agent content, a structural privacy guarantee rather than a policy promise.

Because encryption operates at rest on the blockchain itself, the privacy guarantee applies to the permanent, replicated record — not merely to our servers. Even in the event of a total compromise of our infrastructure, the on-chain attestation content remains ciphertext.

§ 08

On-Chain Immutability & Cryptographic Erasure

Blockchain records are, by design, immutable: once an attestation is anchored on the X1 blockchain, the bytes cannot be altered or removed by any party. This immutability is the foundation of the tamper-evident audit trail that makes EU AI Act Article 50 attestations trustworthy.

Immutability of the record must be reconciled with the GDPR's right to erasure (Article 17). We resolve this tension through cryptographic erasure: where a data subject exercises a right that requires removal of personal data contained in an on-chain record, we do not — and cannot — rewrite the blockchain. Instead, we destroy the cryptographic key material necessary to decrypt that record, permanently.

Once the relevant key shares are destroyed, the ciphertext on-chain becomes computationally irrecoverable: the bytes remain, but the personal data they encode is rendered permanently inaccessible to every party, including us. Cryptographic erasure is carried out under a documented, audited procedure that is logged and, where appropriate, evidenced on-chain by a key-destruction attestation.

We will only ever rely on cryptographic erasure where it is technically necessary (i.e., where the data resides in an immutable record). For data held in our mutable operational systems — databases, logs, support mailboxes — we perform ordinary deletion in accordance with Section 16, and we prioritise that deletion wherever it is sufficient.

How Erasure Works

Erasure request received → we identify every copy of the data → mutable copies are deleted in the ordinary way → immutable on-chain copies are rendered unreadable by destroying the HXMP key shares → a destruction receipt is issued and logged. You receive confirmation that the data is no longer accessible by any party.

§ 09

Your Data Subject Rights (Art. 15–20 GDPR)

As a data subject, you have the following rights under the GDPR. We honour these rights without charge, within one month of a verified request, unless a request is manifestly unfounded or excessive.

Right What it means
Art. 15Right of Access Obtain confirmation of whether we process personal data about you, a copy of that data, and information about the processing: purposes, categories, recipients, retention, and your rights.
Art. 16Right to Rectification Have inaccurate personal data corrected without undue delay, and incomplete data completed — including by supplementary statement.
Art. 17Right to Erasure Have personal data deleted where it is no longer necessary, where consent is withdrawn, where you object and no overriding grounds exist, or where processing is unlawful. On-chain data is erased cryptographically as described in Section 8.
Art. 18Right to Restriction Restrict processing while a dispute about accuracy, lawfulness, or your objection is resolved. Restricted data is stored but not further processed.
Art. 20Right to Portability Receive the personal data you provided to us, in a structured, commonly used, machine-readable format, and transmit it to another controller where processing is based on consent or contract and carried out by automated means.
Art. 21Right to Object Object, on grounds relating to your particular situation, to processing based on legitimate interests or carried out for direct marketing. We will stop unless compelling legitimate grounds override your interests.
Art. 22Right re: Automated Decisions Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. See Section 13.
Art. 7(3)Right to Withdraw Consent Withdraw any consent you have given at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. See Section 21.

§ 10

How to Exercise Your Rights

To exercise any of the rights described in Section 9, contact us at dpo@proofchain.us with the subject line "Data Subject Request", or write to us at the controller address in Section 2.

To protect your privacy and the security of the records we hold, we verify the identity of requesters before acting on a request. We may ask you to confirm details we hold about you, or to provide proof of identity where the request concerns sensitive records. This verification is necessary to prevent unauthorised access to — or alteration of — your personal data.

We respond to verified requests within one month. Where requests are complex or numerous, we may extend the period by two further months, and we will inform you of any extension and its reasons within the first month.

Where requests are manifestly unfounded or excessive — in particular because of their repetitive character — we may charge a reasonable fee or refuse to act. In either case we will explain our decision and remind you of your right to complain to a supervisory authority.

Requests concerning on-chain attestation records are handled under the cryptographic-erasure procedure in Section 8. Because we may not be able to associate an on-chain record with an individual without the operator identifier you provide, we ask that you include the relevant wallet address or public key in your request so that we can identify the records at issue.

§ 11

Data Protection Officer

ProofChain Network has appointed a Data Protection Officer (DPO) to oversee compliance with the GDPR and to serve as a direct point of contact for data subjects and supervisory authorities.

Data Protection Officer
ProofChain Network DPO
Stearns County, Minnesota, USA
Email: dpo@proofchain.us

The DPO is the primary contact for all privacy matters, including data subject requests, complaints, and questions about this Policy. The DPO operates independently and reports directly to the highest level of management of ProofChain Network.

Supervisory authorities may contact the DPO directly for all matters concerning the processing of personal data by ProofChain Network, including requests for cooperation under Article 58 GDPR.

§ 12

No Sale of Personal Data

ProofChain Network does not sell, rent, lease, or otherwise trade personal data for monetary or any other consideration. This prohibition is absolute and applies to all categories of personal data we process, in every jurisdiction, regardless of whether local law would permit it.

We do not share personal data with advertisers, data brokers, or analytics vendors for their independent use. The only disclosures we make are those necessary to operate the Services, to comply with law, or to protect the rights and safety of our users and the public — each as described in this Policy.

Because we do not sell personal data, there is no opt-out to exercise: the practice simply does not occur. If we ever propose to engage in a data transaction that could be characterised as a sale under any applicable law, we will first update this Policy, obtain any required consent, and honour every applicable right to opt out.

§ 13

No Automated Decision-Making

ProofChain Network does not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.

Our Services record and attest facts about AI agents; they do not make decisions about natural persons. Attestation issuance is driven by the cryptographic verification of agent identity and the operator's declared transparency posture — verification logic, not decision-making about individuals.

Automated security systems (rate limiting, abuse detection, and fraud screening) may act on patterns in action logs. These systems are narrowly directed at infrastructure protection: they do not evaluate personal characteristics, and any resulting action affects access to the Services, not the legal status or contractual rights of a person in a manner Article 22 addresses. Where a person is affected by such an action, a human review path is always available via dpo@proofchain.us.

If we ever deploy processing that constitutes Article 22 decision-making, we will: (a) inform affected individuals, (b) implement suitable safeguards including human intervention, and (c) provide a meaningful right to contest the decision.

§ 14

Cross-Border Transfers (Standard Contractual Clauses)

ProofChain Network is headquartered in the United States. Where personal data of data subjects in the EEA, the United Kingdom, or Switzerland is transferred to, or accessed from, the United States or any other third country, we ensure that the transfer is subject to appropriate safeguards under Chapter V of the GDPR.

Our primary transfer safeguard is the European Commission's Standard Contractual Clauses (SCCs) for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), including the module applicable to controller-to-processor and controller-to-controller transfers, together with a Transfer Impact Assessment (TIA) covering the destination jurisdiction.

Where an adequacy decision applies to a destination (such as the EU-US Data Privacy Framework for certified recipients), we rely on it; where it does not, SCCs apply and are supplemented by the technical measures described in this Policy — most notably HXMP encryption at rest and key-share distribution — which we take into account in our TIA when assessing the level of protection.

Copies of the relevant safeguards are available on request from dpo@proofchain.us, subject to redaction of commercial confidentiality and the protection of security-relevant details.

§ 15

EU AI Act Article 50 Context

ProofChain's Services exist to help deployers and operators of AI systems meet the transparency obligations of Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which requires, among other things, that AI systems intended to interact with natural persons are designed and developed so that the persons are informed that they are interacting with an AI system, and that certain AI-generated content is marked as such.

Article 50 imposes obligations on providers and deployers, not on the infrastructure that records their compliance. ProofChain Network is therefore not, itself, a provider or deployer of the AI systems attested through our network, and this Policy does not purport to discharge any Client's Article 50 duties. Clients remain responsible for their own compliance posture.

What our infrastructure contributes is evidence: an immutable, timestamped, cryptographically verifiable record that an operator declared its agent's identity and transparency posture, and that this declaration existed at a specific point in time. This evidentiary record can support an operator's documentation duties under the AI Act, including the transparency-related documentation obligations, and is offered without prejudice to the operator's independent legal analysis.

In this context, the personal data dimension is deliberately narrow: an on-chain attestation binds an agent to a declaration, not a natural person to a behavioural profile. Where an operator identifier could be linked to a natural person, the protections of this Policy — minimisation, encryption, erasure by key destruction, and the full catalogue of data subject rights — apply to that linkage.

We do not use the records we hold to train AI models, to build profiles of natural persons, or for any purpose other than those stated in Section 5.

§ 16

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, in accordance with the following schedule:

At the end of the applicable retention period, data is deleted from active systems and from backups according to their respective cycles, or rendered permanently inaccessible through cryptographic erasure where deletion is technically impossible.

Where a legal hold applies — for example, pending litigation, a supervisory authority investigation, or a lawful preservation request — the relevant data is frozen for the duration of the hold and deleted (or cryptographically erased) when the hold is lifted.

§ 17

Security Measures

We implement technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. These include:

In the event of a personal data breach, we will notify the competent supervisory authority in accordance with Article 33 GDPR (within 72 hours where feasible, unless the breach is unlikely to result in a risk to rights and freedoms), and we will notify affected data subjects in accordance with Article 34 where the breach is likely to result in a high risk to their rights and freedoms.

§ 18

Recipients & Processors

We disclose personal data only to the following categories of recipients, and only to the extent necessary:

All processors are bound by written data processing agreements that reflect the requirements of Article 28 GDPR, including the obligation to process personal data only on our documented instructions, to implement appropriate security measures, and to assist us in fulfilling data subject rights.

Our Data Processing Agreement, including the standard clauses applicable to processor engagements, is published at /legal/dpa.

§ 19

Cookies & Local Storage

The proofchain.us website uses only strictly necessary cookies and local-storage tokens to maintain session state and security posture. We do not deploy advertising cookies, cross-site tracking pixels, or third-party behavioural profiling on our legal pages.

Where optional analytics are enabled on product surfaces, they are configured in a privacy-respecting mode: aggregated, IP-anonymised, and never combined with on-chain identifiers. You can block or delete cookies through your browser settings at any time; the Services will continue to function, though some conveniences may be lost.

For full details of the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.

§ 20

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or the technical safeguards we deploy. The current version will always be published at /legal/privacy with its effective date shown at the top of the page.

Material changes — for example, new purposes of processing, new categories of data, or new recipients — will be communicated to account holders by email or by a prominent notice on the Services before they take effect, where we hold a contact address for you. We will not apply material changes retroactively to personal data already collected, except where required by law.

If a change requires your consent under the GDPR or other applicable law, we will obtain it before the changed processing begins.

§ 21

Contact & Complaints

If you have any questions about this Policy, about the data we hold about you, or about any aspect of our processing, please contact our DPO:

ProofChain Network DPO
Stearns County, Minnesota, USA
Email: dpo@proofchain.us
Subject line: "Data Subject Request" or "Privacy Enquiry"

We aim to resolve all privacy enquiries promptly and in any event within one month. If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

We cooperate with supervisory authorities in the performance of their tasks and will honour any binding decision issued by a competent authority in accordance with the GDPR.

Nothing in this Policy limits any right you have under mandatory provisions of the law of your country of residence, including rights that grant you more protection than this Policy provides.

↑ Back to top