(Formal Legal Version – GDPR, ePrivacy, and CNPD Compliant)
Last updated: 07/08/2026
Scorechain S.A.("Scorechain", "we", "our", "us") is ablockchain analytics and crypto-compliance provider headquartered in Luxembourg. This Privacy Policy explains how we collect, use, disclose, transfer, and protect personal data when you visit our websites (including scorechain.com and ai.scorechain.com), use our products (such as Scorechain Analytics Platform and Scorechain AI) and APIs, engage with ourevents and marketing, or receive professional services from us (together, the"Services"). It also describes choices and rights available to individuals under applicable laws, in particular the EU General Data ProtectionRegulation (GDPR).
Important: We operate a privacy-by-design program. Except where we expressly actas an independent controller (for example, for our own websites,account creation and authentication, sales and marketing, billing, security and fraudprevention), we generally act as a processor of personal data on behalfof our enterprise customers who are the controllers of their own datasets. This Policy covers both roles and explains the differences.
Scorechain S.A., 11, Boulevard duJazz, L-4370 Belvaux, Luxembourg (RCS Luxembourg B199146)
Contact: support@scorechain.com
Data Protection Officer (DPO): support@scorechain.com
This Policy applies where we decide the purposes and means of processing (controller activities) and where we process on documented instructions from our customers (process or activities). If there is any conflict between this Policy and a written agreement with a customer (e.g., a Data Processing Addendum), the agreement prevails for that customer’s data.
We seek to minimize personal data andfavor aggregation, hashing, and tokenization. The categories we may process are:
We process this data as controller, for the purpose of operating your account. In this context the wallet address identifies you, our user: it is not customer-submitted content under (F), and it is not processed as part of an analytics query under (G). Where the same address later appears in an analysis carried out by a customer, that processing is separate and governed by (F) and (G).
A wallet address is pseudonymous but capable of identifying an individual. Because a connected address is linked to your account and to the email address you provide, we treat it as personal data within the meaning of the GDPR.
We never collect, request, receive or store private keys, seed phrases or recovery phrases, and we cannot initiate any transaction from your wallet. Connecting a wallet does not authorise any payment (see Terms and Conditions, Section 5).
We may incorporate official sanctions or regulatory lists where required by law, with appropriate safeguards.
We process personal data only where we have a valid legal basis under the GDPR. The purposes for which we use personal data, and the corresponding legal bases, are:
Operating and providing our services
We use personal data to create and manage accounts, provide authentication, operate APIs, and deliver the services you request.
Legal basis: Performance of a contract and our legitimate interests in operating the service.
Security and fraud prevention
We process personal data to detect and prevent fraud, abuse, or security incidents, and to maintain the integrity of our systems.
Legal basis: Legitimate interests and compliance with legal obligations.
AML / compliance and risk analysis
Where required, we process relevant data to help meet anti-money laundering or regulatory requirements, including on behalf of customers.
Legal basis: Legitimate interests and legal obligations, where applicable.
Marketing and communications
We may send newsletters, event information, or marketing communications.
Legal basis: Consent (where required by local law); otherwise legitimate interests. You can opt out at any time.
Product improvement and analytics
We analyze usage to improve our services and develop new features. Where possible, we use aggregated or pseudonymized data. Legal basis: Legitimate interests. For non-essential cookies or similar technologies, we obtain consent where required.
Recruitment and HR
If you apply for a role with us, we use your data for recruitment and employment processes.
Legal basis: Legitimate interests, employment law obligations, and consent where required by local law.
We process personal data for the following purposes, under the legal bases permitted by the GDPR:
If we later adopt new processing outside of these purposes, we will ensure compatibility with the original purpose or obtain a new legal basis (such as consent) as required.
Our Services compute risk indicators about blockchain activity (e.g., exposure to sanctioned entities). These risk outputs are decision support for compliance teams and are not designed to be the sole basis for decisions producing legal or similarly significant effects about a person. Where a customer configures automated rules, they remain responsible for human review as appropriate. We provide explanations of key factors and allow customers to tune rules and thresholds.
Risk information about your own wallet address. Where you connect a wallet, we may display risk information about that address, drawn from the same analytics we make available to our customers. This is provided for your information only.
It is not used to make any decision about you. Access to the Services is not granted, restricted or refused on the basis of an automated assessment of your address, and no automated processing producing legal effects, or similarly significantly affecting you, is carried out as part of authentication. We retain the discretionary right to refuse or terminate access described in Section 12 of our Terms and Conditions; the exercise of that right involves human assessment.
We host core production systems in the EU. Where transfers outside the EU occur (e.g., to vetted vendors, global support, or at a customer’s direction), we use appropriate safeguards such as the EU Standard Contractual Clauses, plus technical and organizational measures (encryption in transit/at rest, access controls). We disclose transfer details in our DPA and vendor list.
Wallet authentication. Connection of a wallet involves a relay operated by reown inc. (formerly WalletConnect, Inc.), established in the United States. reown states that data is stored or processed in Europe or at facilities maintained by it or its partners, and that transfers from the EEA to the United States rely on the EU Standard Contractual Clauses. We rely on those clauses, together with the encryption of connection payloads inherent to the protocol.
We share personal data:
We do not sell personal information and do not share it for cross-context behavioral advertising. If this changes, we will update this Policy, honor opt-out/limit rights, and display required notices.
We keep personal data only as long as necessary for the purposes described above or as required by law. Typical retention periods are:
Backups and archives are purged on rolling schedules. When retention ends we delete, aggregate, or irreversibly anonymize data.
We maintain technical and organizational measures aligned with industry standards and EU financial-sector resilience expectations, including:
Customers regulated in the EU financial sector can incorporate our security controls and audit rights into their operational resilience programs. We provide security whitepapers and detailed TOMs (technical and organizational measures) upon request provided there is a legitimate business reason and the information requested is relevant to the engagement.
We use cookies and similar technologies to enable site functionality, measure performance, and deliver personalized advertisements, across our public websites and our authenticated product environments. Part of this measurement is conducted through our own server-side infrastructure, and data is forwarded to the relevant platforms only with your consent. We categorize them as:
Consent Management: We use Usercentrics to manage your consent preferences. You can grant, refuse, or withdraw consent for non-essential cookies at any time via the settings on our website. Cookie data is retained in accordance with applicable laws (typically up to 13 months) or until you withdraw consent.
Wallet session storage. Where you authenticate by connecting a wallet, the connection library stores technical information in your browser's local storage (localStorage / sessionStorage), including a session identifier, the connected address and the selected network. This storage is strictly necessary to keep you signed in and is therefore not subject to consent. It is not used for analytics or advertising. It is cleared when you disconnect your wallet, sign out, or when the session expires, and may also be cleared through your browser settings.
European Economic Area individuals have the right to: access; rectification; erasure; restriction; portability; and to object to processing based on legitimate interests or direct marketing. Where processing relies on consent, you may withdraw it at any time.
We comply with GDPR for EU/EEA and UK users, and respect applicable local privacy laws elsewhere.
Limits applicable to wallet addresses. Where you request erasure of data relating to a connected wallet address, we will delete our own account and authentication records, subject to the following limits:
For requests, email contact@scorechain.com. We may verify your identity and will respond within the deadlines set by Applicable Privacy Laws. If you believe your rights have been infringed, you may lodge a complaint with your local supervisory authority (e.g., the CNPD in Luxembourg).
Our Services are for professional/business use and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us to delete it.
When we act as a processor, we process customer personal data only on documented instructions, implement security measures, assist with data subject requests and impact assessments, and flow down protections to sub-processors. We notify customers of any legally binding request for disclosure from public authorities unless prohibited by law and challenge overbroad or unlawful requests.
Information about categories of sub-processors used by Scorechain (e.g., hosting, email delivery, support tools) is available on request by contacting contact@scorechain.com. We will provide notice of material changes as specified in our DPA.
We assess privacy risks of our processing activities and implement proportionate mitigations where required by law.
We will revise this Policy from time to time. We will post the updated version and, if changes are material, provide prominent notice (e.g., in-product notice or email to account owners). The "Last updated" date at the top shows the effective date of the latest version.
Email: support@scorechain.com
Postal: Scorechain S.A., Attn: Privacy, 11, boulevard du Jazz, L-4370 Belvaux, Luxembourg.
If you have questions about this Policy or how we protect privacy on and off the chain, contact us at support@scorechain.com.