Data Processing Agreement
Last updated: July 27, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between BountEx Labs, LLC ("Processor", "Riskora") and the customer identified in the Riskora account ("Controller", "you") for use of the Riskora service (the "Service"). It applies whenever Riskora processes personal data on your behalf in the course of providing the Service.
1. Roles and scope
The Controller determines the purposes and means of the processing and is responsible for the lawfulness of the instructions. The Processor processes personal data only on behalf of, and in accordance with, the Controller's documented instructions, including this DPA. The subject matter, duration, nature, purposes, categories of data, and categories of data subjects are set out in Annex I.
2. Processing on documented instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by applicable law — in which case the Processor informs the Controller of that legal requirement before processing, unless prohibited from doing so. The Controller's use of the Service (submitting addresses for scoring, retrieving results, configuring retention) constitutes its standing instructions.
3. Confidentiality and personnel
The Processor ensures that persons authorized to process personal data are bound by confidentiality obligations and receive appropriate training on data protection.
4. Security
The Processor implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of the processing, to ensure a level of security appropriate to the risk (GDPR Art. 32).
5. Subprocessing
The Controller grants general authorization for the subprocessors listed on the subprocessor page, which is kept current. The Processor will announce intended changes (additions or replacements) by updating that page and, for material changes, by email, at least 14 days in advance. The Controller may object to a change on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected Service. The Processor remains fully liable for its subprocessors' performance.
6. Data subject rights
Taking into account the nature of the processing, the Processor assists the Controller in fulfilling requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection), including by providing self-service deletion and export where available and by responding to requests routed via privacy@riskora.co.
7. Personal data breach notification
The Processor notifies the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting data processed under this DPA, providing the information reasonably available about the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
8. Assistance with Controller obligations
The Processor provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where the processing is likely to result in a high risk (Art. 35–36), and makes available the information necessary to demonstrate compliance with this DPA — including the documentation on the Security & Compliance page, completed CSA CAIQ self-assessment, and infrastructure attestation reports available under NDA.
9. Audits
The Controller may audit compliance with this DPA once per year (and additionally following a personal data breach) on reasonable notice, by questionnaire and document review. On-site inspections occur only where required by law or where document review is demonstrably insufficient, at the Controller's reasonable expense, without disruption to operations and subject to confidentiality.
10. International transfers
Where processing involves a transfer of personal data outside the EEA/UK to a country without an adequacy decision, the parties rely on the European Commission's 2021 Standard Contractual Clauses (Module 2: controller to processor), which are incorporated into this DPA by reference, with Annexes I and II of this DPA serving as the SCC annexes. For transfers to the United States, the Processor will additionally rely on the EU–U.S. Data Privacy Framework once its self-certification is complete.
11. Return and deletion
At the end of the Service, and at the Controller's choice at any earlier time, the Processor deletes or returns personal data processed under this DPA and deletes existing copies, unless storage is required by law. Scan records are retained as a reproducible audit trail only while the account is active and are erased on request.
12. Liability and term
Liability under this DPA is subject to the limitations in the Terms of Service. This DPA takes effect when the Controller first uses the Service and remains in force for the duration of that use, plus the period needed to complete deletion under Section 11.
Annex I — Details of the processing
| Item | Description |
|---|---|
| Subject matter | Provision of AML risk scoring for blockchain addresses via dashboard and API. |
| Duration | For the term of the Controller's use of the Service, plus deletion per Section 11. |
| Nature and purposes | Storage of account data; retrieval of public on-chain data; computation and storage of risk scores and scan records; generation of AI explanations on request; credit accounting. |
| Categories of personal data | Account data (name, email, hashed password); usage and security logs (IP address, timestamps); queried blockchain addresses and associated scan records (pseudonymous personal data). |
| Categories of data subjects | The Controller's authorized users; pseudonymous holders of queried blockchain addresses. |
| Special categories | None intentionally processed. |
| Retention | Account data: account lifetime + 90 days. Scan records: while account active, erasable on request. Security logs: up to 12 months. Billing records: per tax law. |
Annex II — Technical and Organisational Measures (TOMs)
| Domain | Measures |
|---|---|
| Encryption | TLS 1.2+ on all endpoints; AES-256 encryption at rest managed by database/infrastructure providers. |
| Authentication & access control | Short-lived JWT access tokens; refresh tokens in httpOnly cookies; API keys stored only as SHA-256 hashes; least-privilege access to production systems; MFA on administrative consoles. |
| Pseudonymization & minimization | Blockchain addresses treated as pseudonymous personal data; AI narrative generation receives only the queried address and scan metadata — never account data. |
| Integrity & resilience | Managed database backups; provider rotation across redundant blockchain data nodes; reproducible scan records. |
| Logging & monitoring | Authentication and API access logs; error monitoring; security event review. |
| Vulnerability management | Public vulnerability disclosure policy and security.txt; dependency and application scanning; coordinated remediation timelines. |
| Secure development | Version-controlled changes with review; static type checking and linting in CI; separation of secrets from source control. |
| Personnel & organization | Confidentiality obligations for all persons with data access; access provisioning and revocation procedures; breach response procedure with 72-hour notification. |
Questions about this DPA: legal@riskora.co — for execution as a countersigned document, contact us and we will return it the same business day.
