Privacy Policy

This Privacy Policy describes how ChainAttest (“we”, “us”, “controller”) collects, uses, and shares personal data when you use our website and application (“Service”). It is intended to meet transparency requirements under the EU GDPR and UK GDPR for a SaaS product. It is not legal advice.

Controller: ChainAttest (sole trader trading as ChainAttest). Privacy contact: [email protected] or the contact form. Payment-related personal data for purchases is also processed by Paddle as Merchant of Record (see their privacy policy).

1. Information we collect

2. Why we process data (purposes & legal bases)

We do not currently send marketing emails. If we introduce marketing, we will rely on consent or soft opt-in where allowed and provide an unsubscribe option.

3. Sharing & processors

We share personal data only with providers needed to run the Service, under appropriate agreements where required:

We may disclose information if required by law or to protect rights, safety, and security. We do not sell your personal information.

4. Cookies and similar technologies

Authentication is primarily via a bearer token stored in localStorage (not a tracking cookie). On the billing page we load Paddle.js so you can complete checkout; Paddle may set cookies or similar technologies as described in their policies. We do not use advertising cookies. If we add non-essential analytics cookies later, we will present a consent choice where required by ePrivacy/GDPR rules.

5. Retention

We retain account and scan data while your account is active and for a reasonable period afterward for backups, abuse prevention, billing disputes, and legal obligations (for example, payment records related to Paddle transactions). You may request deletion of your account; we will delete or anonymise personal data we no longer need, except where retention is required by law or necessary for disputes/security.

6. Security

We use reasonable technical and organisational measures, including password hashing (bcrypt), session expiry, TLS in production, and access controls for administrative functions. No method of transmission or storage is completely secure.

7. International transfers

We and our processors may process data in countries outside your own (including outside the EEA/UK). Where required, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses with processors.

8. Your rights (EU/UK and similar laws)

Depending on your location, you may have rights to:

To exercise these rights, email [email protected] or use the contact form (choose Delete my account). We aim to respond within one month. You may also lodge a complaint with your local supervisory authority (in the UK: the ICO; in the EU: your member-state DPA).

Account deletion is processed manually by an administrator after we verify the request. We then remove the account, sessions, portfolio, and scan history. Anonymised purchase records may be retained for accounting and legal obligations.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

10. Changes

We may update this policy. The “Last updated” date will change when we do. Material changes will be communicated where appropriate (for example, a notice in the product or by email if we have a reliable address).

11. Contact

Privacy questions: contact form or [email protected].