Contents
- Introduction & Our Commitment
- Data Controller
- Scope & Definitions
- Personal Data We Process
- Purposes of Processing
- Legal Bases (Art. 6 GDPR)
- HXMP Encryption at Rest on the X1 Blockchain
- On-Chain Immutability & Cryptographic Erasure
- Your Data Subject Rights (Art. 15–20)
- How to Exercise Your Rights
- Data Protection Officer
- No Sale of Personal Data
- No Automated Decision-Making
- Cross-Border Transfers (SCCs)
- EU AI Act Article 50 Context
- Data Retention
- Security Measures
- Recipients & Processors
- Cookies & Local Storage
- Changes to This Policy
- Contact & Complaints
Introduction & Our Commitment
ProofChain Network operates an attestation and compliance infrastructure that records verifiable, timestamped evidence of AI agent conduct for the purpose of demonstrating compliance with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), in particular Article 50 concerning transparency obligations for AI systems.
This Privacy Policy explains, in plain language and in the formal terms required by the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), what personal data ProofChain Network processes, why we process it, on which legal bases, how long we keep it, and the rights you hold over it.
We process personal data only to the extent necessary to operate the ProofChain network, to issue and maintain compliance attestations, to protect the integrity of the audit trail, and to fulfil our legal obligations. We design our systems so that personal data is minimised, encrypted, and — where technically possible — removed entirely from the reach of any party, including ourselves.
If you are an individual based in the European Economic Area (EEA), the United Kingdom, or Switzerland, the rights and protections described in this Policy apply to you in full. If you are located elsewhere, we extend the same high standard of care to your data as a matter of policy.
We are a compliance-record service, not a data broker. We record cryptographic evidence about AI agents — not dossiers about people. Where identifiers or logs could relate to a natural person, they are minimised, encrypted at rest, and never sold.
Data Controller
The data controller for the processing described in this Policy is:
ProofChain Network
Stearns County, Minnesota
United States of America
Contact: dpo@proofchain.us
ProofChain Network is a distributed network operation. For the purposes of the GDPR, the entity that determines the purposes and means of the processing described in this Policy is the ProofChain Network operator headquartered in Stearns County, Minnesota, acting as controller for the platform services offered at proofchain.us.
Where the ProofChain network is used by a deploying organisation (a "Client") to record attestations about AI agents that the Client operates, the Client acts as an independent controller for its own decisions about the agents, and ProofChain Network acts as a processor on the Client's behalf with respect to the records we hold for them. That relationship is governed by our Data Processing Agreement, available at /legal/dpa.
Scope & Definitions
This Policy applies to all personal data processed by ProofChain Network in connection with the proofchain.us website, the ProofChain dashboard, the KYA (Know Your Agent) compliance seal, the ProofChain API, and any related services (together, the "Services").
- Personal Data
- Any information relating to an identified or identifiable natural person ("data subject").
- Agent Operator
- The natural or legal person who operates, deploys, or controls an AI agent registered with or attested by the ProofChain network.
- Agent Operator Identifier
- A pseudonymous, cryptographically derived identifier (such as a wallet address or public key) that an operator uses to sign attestations and register agents. It is not the operator's name, email address, or any directly identifying credential.
- Attestation Record
- A timestamped, signed statement — recorded on the X1 blockchain — asserting facts about an AI agent's identity, behaviour, or transparency posture for EU AI Act Article 50 purposes.
- Action Log
- A chronological record of operations performed through the Services, including API calls, registrations, attestation submissions, and administrative events.
- HXMP
- The Homomorphic X1 Multi-Party encryption scheme used to encrypt attestation payloads at rest on the X1 blockchain.
Terms defined in the GDPR and in the EU AI Act have the meanings given to them there, unless this Policy provides a more specific definition.
Personal Data We Process
We process the following categories of personal data, each only to the extent necessary for the Services:
- Account and contact data — where you create an account on the ProofChain dashboard or purchase a subscription, we process your name, email address, billing details (processed by our payment processor, who never shares full card data with us), and organisation name.
- Agent operator identifiers — the pseudonymous wallet address or public key you use to sign attestations. These identifiers are published on-chain as part of the attestation record and are not, by themselves, sufficient to identify a natural person.
- Timestamps — the date and time of each registration, attestation, audit query, and administrative action, recorded both in our operational logs and immutably on-chain.
- Action logs — records of operations performed through the Services: which endpoint was called, from which IP address, by which account or identifier, and with what result. IP addresses are retained in truncated or hashed form where possible and never published.
- Correspondence — emails and support messages you send us, including messages to dpo@proofchain.us, which we retain only as long as needed to resolve the matter and to evidence our compliance obligations.
- Compliance metadata — for KYA seal issuance, we process the agent name, operator domain, and attestation status you supply, which may be displayed publicly in the agent registry as part of the attestation you request.
We do not intentionally collect special categories of personal data (Article 9 GDPR), such as health data, political opinions, religious beliefs, or biometric data. We also do not collect data relating to criminal convictions (Article 10 GDPR). If you send us such data unsolicited, we will delete it or render it inaccessible to the extent legally possible.
We never process more data than the Services require, and we design new features with data minimisation as a default constraint rather than an afterthought.
Purposes of Processing
We process personal data for the following purposes:
- Provision of the Services — operating the dashboard, KYA seal issuance, agent registry, audit trail queries, and compliance report generation.
- Attestation integrity — creating, signing, and anchoring timestamped attestation records on the X1 blockchain so that they are verifiable and tamper-evident.
- Security and fraud prevention — detecting abuse, unauthorised access, and denial-of-service activity through action-log analysis.
- Legal and regulatory compliance — fulfilling obligations under the GDPR, the EU AI Act, payment regulations, and tax law, and responding to lawful requests from supervisory authorities.
- Customer support — responding to enquiries, complaints, and data subject requests.
- Service improvement — aggregated, non-personal analytics that help us understand usage patterns without identifying individuals.
We do not use personal data for purposes incompatible with those listed above. If we intend to process personal data for a new, incompatible purpose, we will update this Policy and, where the GDPR requires, obtain fresh consent.
Legal Bases (Art. 6 GDPR)
In accordance with Article 6 of the GDPR, the legal bases we rely on for each category of processing are:
- Performance of a contract (Art. 6(1)(b)) — processing necessary to provide the Services to you under our Terms of Service, including account creation, dashboard operation, attestation issuance, and subscription management.
- Legitimate interests (Art. 6(1)(f)) — processing necessary for the security of our infrastructure, fraud prevention, abuse detection, and the integrity of the on-chain audit trail. We balance these interests against your rights and freedoms and document that balancing in our records of processing activities. You may object to this processing at any time as described in Section 9.
- Legal obligation (Art. 6(1)(c)) — processing necessary to comply with legal obligations, including tax and accounting retention rules, EU AI Act documentation duties, and responses to competent supervisory authorities.
- Consent (Art. 6(1)(a)) — where we rely on consent (for example, for non-essential cookies or optional marketing communications), you may withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.
- Vital interests (Art. 6(1)(d)) — in the rare circumstance that processing is necessary to protect someone's life or physical safety, as permitted by law.
Where processing is based on legitimate interests, you have the right to object under Article 21 GDPR. We will cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
We keep a current record of our processing activities (Article 30 GDPR) that maps each processing operation to its legal basis, retention period, and security measures.
HXMP Encryption at Rest on the X1 Blockchain
Attestation payloads recorded on the X1 blockchain are encrypted at rest using HXMP — the Homomorphic X1 Multi-Party encryption scheme — before they are anchored on-chain.
HXMP encryption ensures that the content of an attestation record is not readable by any party holding only the on-chain bytes. The ciphertext is resistant to inspection by node operators, indexers, and any third party who obtains a copy of the chain, because decryption requires key material that is never stored on-chain.
The scheme is designed so that key shares are distributed across independent parties, so no single party — including ProofChain Network — can decrypt attestation payloads unilaterally. This property is what makes it possible for us to process attestation metadata without being able to read the underlying agent content, a structural privacy guarantee rather than a policy promise.
Because encryption operates at rest on the blockchain itself, the privacy guarantee applies to the permanent, replicated record — not merely to our servers. Even in the event of a total compromise of our infrastructure, the on-chain attestation content remains ciphertext.
On-Chain Immutability & Cryptographic Erasure
Blockchain records are, by design, immutable: once an attestation is anchored on the X1 blockchain, the bytes cannot be altered or removed by any party. This immutability is the foundation of the tamper-evident audit trail that makes EU AI Act Article 50 attestations trustworthy.
Immutability of the record must be reconciled with the GDPR's right to erasure (Article 17). We resolve this tension through cryptographic erasure: where a data subject exercises a right that requires removal of personal data contained in an on-chain record, we do not — and cannot — rewrite the blockchain. Instead, we destroy the cryptographic key material necessary to decrypt that record, permanently.
Once the relevant key shares are destroyed, the ciphertext on-chain becomes computationally irrecoverable: the bytes remain, but the personal data they encode is rendered permanently inaccessible to every party, including us. Cryptographic erasure is carried out under a documented, audited procedure that is logged and, where appropriate, evidenced on-chain by a key-destruction attestation.
We will only ever rely on cryptographic erasure where it is technically necessary (i.e., where the data resides in an immutable record). For data held in our mutable operational systems — databases, logs, support mailboxes — we perform ordinary deletion in accordance with Section 16, and we prioritise that deletion wherever it is sufficient.
Erasure request received → we identify every copy of the data → mutable copies are deleted in the ordinary way → immutable on-chain copies are rendered unreadable by destroying the HXMP key shares → a destruction receipt is issued and logged. You receive confirmation that the data is no longer accessible by any party.
Your Data Subject Rights (Art. 15–20 GDPR)
As a data subject, you have the following rights under the GDPR. We honour these rights without charge, within one month of a verified request, unless a request is manifestly unfounded or excessive.
| Right | What it means |
|---|---|
| Art. 15Right of Access | Obtain confirmation of whether we process personal data about you, a copy of that data, and information about the processing: purposes, categories, recipients, retention, and your rights. |
| Art. 16Right to Rectification | Have inaccurate personal data corrected without undue delay, and incomplete data completed — including by supplementary statement. |
| Art. 17Right to Erasure | Have personal data deleted where it is no longer necessary, where consent is withdrawn, where you object and no overriding grounds exist, or where processing is unlawful. On-chain data is erased cryptographically as described in Section 8. |
| Art. 18Right to Restriction | Restrict processing while a dispute about accuracy, lawfulness, or your objection is resolved. Restricted data is stored but not further processed. |
| Art. 20Right to Portability | Receive the personal data you provided to us, in a structured, commonly used, machine-readable format, and transmit it to another controller where processing is based on consent or contract and carried out by automated means. |
| Art. 21Right to Object | Object, on grounds relating to your particular situation, to processing based on legitimate interests or carried out for direct marketing. We will stop unless compelling legitimate grounds override your interests. |
| Art. 22Right re: Automated Decisions | Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. See Section 13. |
| Art. 7(3)Right to Withdraw Consent | Withdraw any consent you have given at any time, with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal. |
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. See Section 21.
How to Exercise Your Rights
To exercise any of the rights described in Section 9, contact us at dpo@proofchain.us with the subject line "Data Subject Request", or write to us at the controller address in Section 2.
To protect your privacy and the security of the records we hold, we verify the identity of requesters before acting on a request. We may ask you to confirm details we hold about you, or to provide proof of identity where the request concerns sensitive records. This verification is necessary to prevent unauthorised access to — or alteration of — your personal data.
We respond to verified requests within one month. Where requests are complex or numerous, we may extend the period by two further months, and we will inform you of any extension and its reasons within the first month.
Where requests are manifestly unfounded or excessive — in particular because of their repetitive character — we may charge a reasonable fee or refuse to act. In either case we will explain our decision and remind you of your right to complain to a supervisory authority.
Requests concerning on-chain attestation records are handled under the cryptographic-erasure procedure in Section 8. Because we may not be able to associate an on-chain record with an individual without the operator identifier you provide, we ask that you include the relevant wallet address or public key in your request so that we can identify the records at issue.
Data Protection Officer
ProofChain Network has appointed a Data Protection Officer (DPO) to oversee compliance with the GDPR and to serve as a direct point of contact for data subjects and supervisory authorities.
Data Protection Officer
ProofChain Network DPO
Stearns County, Minnesota, USA
Email: dpo@proofchain.us
The DPO is the primary contact for all privacy matters, including data subject requests, complaints, and questions about this Policy. The DPO operates independently and reports directly to the highest level of management of ProofChain Network.
Supervisory authorities may contact the DPO directly for all matters concerning the processing of personal data by ProofChain Network, including requests for cooperation under Article 58 GDPR.
No Sale of Personal Data
ProofChain Network does not sell, rent, lease, or otherwise trade personal data for monetary or any other consideration. This prohibition is absolute and applies to all categories of personal data we process, in every jurisdiction, regardless of whether local law would permit it.
We do not share personal data with advertisers, data brokers, or analytics vendors for their independent use. The only disclosures we make are those necessary to operate the Services, to comply with law, or to protect the rights and safety of our users and the public — each as described in this Policy.
Because we do not sell personal data, there is no opt-out to exercise: the practice simply does not occur. If we ever propose to engage in a data transaction that could be characterised as a sale under any applicable law, we will first update this Policy, obtain any required consent, and honour every applicable right to opt out.
No Automated Decision-Making
ProofChain Network does not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.
Our Services record and attest facts about AI agents; they do not make decisions about natural persons. Attestation issuance is driven by the cryptographic verification of agent identity and the operator's declared transparency posture — verification logic, not decision-making about individuals.
Automated security systems (rate limiting, abuse detection, and fraud screening) may act on patterns in action logs. These systems are narrowly directed at infrastructure protection: they do not evaluate personal characteristics, and any resulting action affects access to the Services, not the legal status or contractual rights of a person in a manner Article 22 addresses. Where a person is affected by such an action, a human review path is always available via dpo@proofchain.us.
If we ever deploy processing that constitutes Article 22 decision-making, we will: (a) inform affected individuals, (b) implement suitable safeguards including human intervention, and (c) provide a meaningful right to contest the decision.
Cross-Border Transfers (Standard Contractual Clauses)
ProofChain Network is headquartered in the United States. Where personal data of data subjects in the EEA, the United Kingdom, or Switzerland is transferred to, or accessed from, the United States or any other third country, we ensure that the transfer is subject to appropriate safeguards under Chapter V of the GDPR.
Our primary transfer safeguard is the European Commission's Standard Contractual Clauses (SCCs) for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), including the module applicable to controller-to-processor and controller-to-controller transfers, together with a Transfer Impact Assessment (TIA) covering the destination jurisdiction.
Where an adequacy decision applies to a destination (such as the EU-US Data Privacy Framework for certified recipients), we rely on it; where it does not, SCCs apply and are supplemented by the technical measures described in this Policy — most notably HXMP encryption at rest and key-share distribution — which we take into account in our TIA when assessing the level of protection.
Copies of the relevant safeguards are available on request from dpo@proofchain.us, subject to redaction of commercial confidentiality and the protection of security-relevant details.
EU AI Act Article 50 Context
ProofChain's Services exist to help deployers and operators of AI systems meet the transparency obligations of Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which requires, among other things, that AI systems intended to interact with natural persons are designed and developed so that the persons are informed that they are interacting with an AI system, and that certain AI-generated content is marked as such.
Article 50 imposes obligations on providers and deployers, not on the infrastructure that records their compliance. ProofChain Network is therefore not, itself, a provider or deployer of the AI systems attested through our network, and this Policy does not purport to discharge any Client's Article 50 duties. Clients remain responsible for their own compliance posture.
What our infrastructure contributes is evidence: an immutable, timestamped, cryptographically verifiable record that an operator declared its agent's identity and transparency posture, and that this declaration existed at a specific point in time. This evidentiary record can support an operator's documentation duties under the AI Act, including the transparency-related documentation obligations, and is offered without prejudice to the operator's independent legal analysis.
In this context, the personal data dimension is deliberately narrow: an on-chain attestation binds an agent to a declaration, not a natural person to a behavioural profile. Where an operator identifier could be linked to a natural person, the protections of this Policy — minimisation, encryption, erasure by key destruction, and the full catalogue of data subject rights — apply to that linkage.
We do not use the records we hold to train AI models, to build profiles of natural persons, or for any purpose other than those stated in Section 5.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, in accordance with the following schedule:
- Account data — retained for the life of your account plus a statutory accounting period where billing records are involved.
- Action logs — operational logs are retained for a maximum of 12 months, after which they are deleted or rendered irrecoverable, except where a legal hold applies.
- On-chain attestation records — retained indefinitely as part of the immutable blockchain record, but encrypted at rest under HXMP; personal data within them is subject to cryptographic erasure on request (Section 8).
- Support correspondence — retained for up to 24 months after the matter is closed, unless a longer period is required by law or litigation hold.
- Financial records — retained for the period required by applicable tax and accounting law (in the United States and the EU respectively), typically 6–10 years.
At the end of the applicable retention period, data is deleted from active systems and from backups according to their respective cycles, or rendered permanently inaccessible through cryptographic erasure where deletion is technically impossible.
Where a legal hold applies — for example, pending litigation, a supervisory authority investigation, or a lawful preservation request — the relevant data is frozen for the duration of the hold and deleted (or cryptographically erased) when the hold is lifted.
Security Measures
We implement technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. These include:
- Encryption — TLS 1.2+ in transit for all Services; HXMP encryption at rest for on-chain attestation payloads; encryption at rest for operational databases.
- Key management — HXMP key shares are distributed across independent parties, so no single party can decrypt attestation content alone. Key-destruction procedures are documented and audited.
- Access control — least-privilege access to production systems, enforced by role-based permissions, with multi-factor authentication for administrative access.
- Monitoring — continuous logging and alerting for unauthorised access attempts, anomalies, and abuse patterns, with automated response for infrastructure-level threats.
- Personnel — confidentiality obligations on all personnel and contractors; privacy and security training; documented data-processing instructions.
- Resilience — regular backups, tested restoration procedures, and a documented incident-response plan.
In the event of a personal data breach, we will notify the competent supervisory authority in accordance with Article 33 GDPR (within 72 hours where feasible, unless the breach is unlikely to result in a risk to rights and freedoms), and we will notify affected data subjects in accordance with Article 34 where the breach is likely to result in a high risk to their rights and freedoms.
Recipients & Processors
We disclose personal data only to the following categories of recipients, and only to the extent necessary:
- Payment processors — to process subscriptions and one-time purchases. Payment data is handled by the processor under its own PCI-DSS obligations; we receive only confirmation and minimal billing metadata.
- Hosting and infrastructure providers — the data-centre operator that physically hosts our servers, bound by a data processing agreement.
- X1 blockchain validators and node operators — who replicate the public chain on which encrypted attestation records are anchored. They receive only ciphertext and public metadata and cannot read attestation content.
- Professional advisers — legal, accounting, and audit advisers bound by professional confidentiality.
- Public authorities — where we are under a legal obligation to disclose, or where disclosure is necessary to establish, exercise, or defend legal claims. We require lawful process before disclosure and we challenge overbroad requests where appropriate.
All processors are bound by written data processing agreements that reflect the requirements of Article 28 GDPR, including the obligation to process personal data only on our documented instructions, to implement appropriate security measures, and to assist us in fulfilling data subject rights.
Our Data Processing Agreement, including the standard clauses applicable to processor engagements, is published at /legal/dpa.
Cookies & Local Storage
The proofchain.us website uses only strictly necessary cookies and local-storage tokens to maintain session state and security posture. We do not deploy advertising cookies, cross-site tracking pixels, or third-party behavioural profiling on our legal pages.
Where optional analytics are enabled on product surfaces, they are configured in a privacy-respecting mode: aggregated, IP-anonymised, and never combined with on-chain identifiers. You can block or delete cookies through your browser settings at any time; the Services will continue to function, though some conveniences may be lost.
For full details of the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or the technical safeguards we deploy. The current version will always be published at /legal/privacy with its effective date shown at the top of the page.
Material changes — for example, new purposes of processing, new categories of data, or new recipients — will be communicated to account holders by email or by a prominent notice on the Services before they take effect, where we hold a contact address for you. We will not apply material changes retroactively to personal data already collected, except where required by law.
If a change requires your consent under the GDPR or other applicable law, we will obtain it before the changed processing begins.
Contact & Complaints
If you have any questions about this Policy, about the data we hold about you, or about any aspect of our processing, please contact our DPO:
ProofChain Network DPO
Stearns County, Minnesota, USA
Email: dpo@proofchain.us
Subject line: "Data Subject Request" or "Privacy Enquiry"
We aim to resolve all privacy enquiries promptly and in any event within one month. If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:
- In the EEA: the supervisory authority of your Member State of habitual residence, place of work, or place of the alleged infringement.
- In the United Kingdom: the Information Commissioner's Office (ico.org.uk).
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC).
We cooperate with supervisory authorities in the performance of their tasks and will honour any binding decision issued by a competent authority in accordance with the GDPR.
Nothing in this Policy limits any right you have under mandatory provisions of the law of your country of residence, including rights that grant you more protection than this Policy provides.
↑ Back to top