Privacy Policy
Last updated: July 27, 2026
1. Who we are
Riskora is operated by BountEx Labs, LLC ("Riskora", "we", "us"), [ADDRESS — TODO]. Riskora provides anti-money-laundering (AML) risk scoring for blockchain addresses via a web dashboard and a REST API (the "Service").
For the processing described in this policy, the data controller is BountEx Labs, LLC, reachable at privacy@riskora.co. When we process wallet-screening data on behalf of an enterprise customer, that customer is the controller and we act as processor under our Data Processing Agreement.
2. Data we collect
- Account data — first name, last name, email address, and a hashed password when you register.
- Usage data — API requests, authentication events, timestamps, and IP addresses, kept in security and access logs.
- Query data — the blockchain addresses you screen and the resulting scan records (risk score, risk level, reasons, on-chain metrics).
- Billing data — credit balance and transaction history. Payment card details are processed by our payment processor and never touch our servers.
- Communications — emails and support requests you send us.
We do not use advertising or third-party analytics trackers.
3. Blockchain addresses as personal data
Blockchain addresses are pseudonymous identifiers. Because they can sometimes be linked to an individual, we treat queried addresses and their scan records as personal data under GDPR, and we apply the same protections to them as to account data — even though the underlying blockchain data is public.
4. Purposes and legal bases
- Providing the Service (Art. 6(1)(b) GDPR — contract): account management, authentication, credit accounting, generating and storing risk scores.
- Security and abuse prevention (Art. 6(1)(f) — legitimate interest): access logging, rate limiting, API key management, incident detection.
- Product improvement (Art. 6(1)(f) — legitimate interest): aggregated, non-identifying usage statistics.
- Legal obligations (Art. 6(1)(c)): tax, accounting, and regulatory record-keeping.
5. Cookies
We use a single strictly-necessary httpOnly cookie to hold your session refresh token. It is not accessible to JavaScript and is not used for tracking. No marketing, analytics, or third-party cookies are set.
6. Who we share data with
We share data only with the subprocessors required to run the Service — hosting, database, AI narrative generation, and blockchain data retrieval — listed in detail on our subprocessor page. Two flows deserve explicit mention:
- AI narratives — when you request an AI explanation, the queried wallet address and scan metadata are sent to our AI provider (OpenRouter). Account data and user PII are never sent.
- Blockchain lookups — queried addresses are sent to public mempool-compatible nodes to retrieve on-chain data, as with any block explorer.
We do not sell personal data.
7. International transfers
Some subprocessors are located in, or process data in, the United States. Where personal data is transferred outside the EEA/UK, it is protected by the European Commission's 2021 Standard Contractual Clauses or an equivalent lawful transfer mechanism, as reflected in our Data Processing Agreement.
8. Retention
- Account data — kept while your account is active; deleted or anonymized within 90 days of account closure, subject to legal retention duties.
- Scan records — retained while your account is active as a reproducible audit trail for compliance reviews. You may request erasure of specific records or of all records at any time.
- Security logs — retained for up to 12 months.
- Billing records — retained for the period required by tax and accounting law.
9. Your rights
Under GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21), as well as the right to withdraw consent where processing is based on it. To exercise any right, email privacy@riskora.co — we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Security
We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), SHA-256-hashed API keys, short-lived JWT sessions, and least-privilege access. Our full posture is documented on the Security & Compliance page.
11. Children
The Service is intended for business users and is not directed at anyone under 18. We do not knowingly collect data from minors.
12. Changes to this policy
We update this policy as the Service evolves. Material changes are announced by email to registered users before they take effect; the current version is always on this page with its revision date.
13. Contact
Privacy questions, access and erasure requests: privacy@riskora.co.
Security matters: security@riskora.co.
