GDPR Compliance & Blockchain Data Rights

1. Introduction & scope

The General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") establishes strict frameworks for the collection, processing, and storage of personal data of individuals located within the European Economic Area (EEA), the United Kingdom, and Switzerland.

Fraudalysis ("we", "us", "our") is committed to upholding data privacy rights. This document outlines our compliance framework across our off-chain databases and our public on-chain ledger processing.

2. Roles: data controller & data processor

3. The Web3 privacy paradox: on-chain vs off-chain data

A fundamental tension exists between the GDPR's data minimisation and erasure principles (Right to Be Forgotten) and the immutable, permanent nature of public blockchains. We resolve this by categorising data into two domains:

A. Off-chain data (traditional databases)

Direct personal data such as names, contact details, and IP addresses. Stored in secure databases; fully subject to standard GDPR rights including erasure, correction, and portability.

B. On-chain data (decentralised ledgers)

Public wallet addresses, transaction hashes, contract bytecode, and cryptographic state changes. Public cryptographic wallet addresses are considered "pseudonymised personal data" because they can occasionally be linked to real-world identities via exchange records. Blockchain records are permanently written across thousands of global nodes — no single entity, including Fraudalysis, can modify or erase blocks.

We process this public, pseudonymised ledger data under the lawful basis of Legitimate Interests (GDPR Article 6(1)(f)) — specifically, to prevent financial crime, combat money laundering, secure smart contracts, and protect the Web3 ecosystem from scams.

4. Lawful bases for processing

  1. Contractual necessity (Article 6(1)(b)): to set up your account and fulfil our terms of service.
  2. Consent (Article 6(1)(a)): when you opt in to marketing communications or security research reports.
  3. Legal obligation (Article 6(1)(c)): to comply with statutory financial tracking, AML regulations, and lawful court orders.
  4. Legitimate interests (Article 6(1)(f)): to analyse and score transactions for threat detection, fraud patterns, and exploit prevention.

5. Your data protection rights

A. Right of access (Article 15)

Request a copy of the off-chain personal data we hold about you.

B. Right to rectification (Article 16)

Request correction of inaccurate or incomplete off-chain personal data.

C. Right to erasure / "right to be forgotten" (Article 17)

Off-chain data: we will delete your email, account records, and marketing preferences upon request. On-chain limitation: public transaction history cannot be erased from blockchains — that is technologically impossible. However, on request we will remove any off-chain identity associations (such as linking a name to a wallet address) from our internal analytics, rendering the address strictly anonymous within our platform.

D. Right to restrict processing (Article 18)

Request that we pause or limit processing of your data in specific scenarios (e.g. where you dispute its accuracy).

E. Right to data portability (Article 20)

Receive your personal data in a structured, commonly used, machine-readable format.

F. Right to object (Article 21)

Object to our processing of pseudonymised on-chain data under legitimate interests. We will review objections weighing our interest in preventing financial crime against your privacy interests.

6. How to exercise your rights

To submit a Data Subject Access Request (DSAR) or exercise any GDPR right, contact our compliance team at compliance@fraudalysis.com. We will verify your identity to protect security and respond to valid requests within one (1) month of receipt.