Data Processing Addendum
Last updated 23 August 2026
This DPA forms part of the Terms of Service. It is shorter than most, for a reason worth stating up front: there is almost nothing here for us to process.
This DPA is between you (“Customer”, the controller) and [Legal entity name] (“BlockAgents”, the processor), and applies where you use the service to process personal data subject to the UK GDPR, the EU GDPR, or both. It takes effect when you accept the Terms of Service; no signature is required, but we will sign a countersigned copy on request at legal@blockagents.ai.
The unusual part
A DPA normally enumerates the categories of personal data a processor handles on the controller’s behalf. For challenge traffic, ours is empty. We receive no name, no email, no account identifier, no cookie, no device identifier and no behavioral data about the people who solve challenges on your site. We set nothing on their device and we retain no IP address. Article 28 obligations still apply to us as your processor; there is simply very little for them to attach to.
1. Definitions
Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR (2016/679), and any successor legislation. Controller, processor, data subject, personal data, processing and personal data breach have the meanings given in the EU GDPR.
2. Roles
For challenge traffic on your site, you are the controller and we are the processor. For your own account data — the email, label and domains you gave us — we are an independent controller, and the privacy policy governs it, not this DPA.
3. Scope of processing (Annex I)
| Item | Detail |
|---|---|
| Subject matter | Distinguishing automated from human form submissions on the Customer’s site. |
| Duration | The term of the Terms of Service. |
| Nature and purpose | Issuing a challenge, grading an answer, issuing and redeeming a single-use verification token. |
| Types of personal data | None. Challenge issuance and grading involve no personal data. An IP address is present at the transport layer and is used transiently for rate limiting; it is HMAC-hashed under an in-memory salt that is never persisted, and no raw address is stored. |
| Special categories | None. The service cannot receive them. |
| Categories of data subject | Visitors to the Customer’s site, insofar as the transport-layer address above concerns them. |
| Frequency | Continuous, per challenge. |
4. Our obligations
We will:
- process personal data only on your documented instructions, which the Terms of Service and your configuration constitute, unless required otherwise by law — in which case we will tell you first unless the law forbids it;
- ensure everyone authorized to process it is under a confidentiality obligation;
- implement the measures in section 6;
- respect the conditions in section 5 for engaging subprocessors;
- assist you, so far as is possible, in responding to data subject requests;
- assist you with Articles 32 to 36 — security, breach notification, and data protection impact assessments;
- delete or return personal data at the end of the service, at your choice;
- make available the information needed to demonstrate compliance, and allow audits under section 8.
We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law.
5. Subprocessors
You give general authorization for us to engage subprocessors. The current list is at /subprocessors. We will give at least 30 days’ notice before adding or replacing one; you may object on reasonable data protection grounds within that period, and if we cannot resolve the objection you may terminate the affected service without penalty. Each subprocessor is bound by terms no less protective than these, and we remain fully liable for their performance.
6. Security
We implement appropriate technical and organisational measures under Article 32. The measures are set out in full on the security page; in summary:
- the challenge answer never leaves our server and is never transmitted to a browser;
- verification tokens are HMAC-SHA-256 signed, bound to a single site key, expire in five minutes, and are destroyed on redemption;
- secrets are compared in constant time, and API responses do not distinguish “no such key” from “wrong secret”;
- all traffic is TLS 1.2 or better;
- rate limiting keys on a salted hash, never a raw address;
- access to production is limited to named personnel and requires multi-factor authentication;
- the ephemeral records the service does hold expire in minutes.
The strongest measure available to us is holding nothing, and it is the one we have built the product around.
7. Breach notification
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, with the nature of the breach, the likely consequences, and the measures taken. You remain responsible for notifying your supervisory authority and data subjects.
8. Audit
On reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this DPA and permit an audit by you or an independent auditor bound by confidentiality. Audits must not unreasonably disrupt the service, and you bear your own costs.
We do not hold a SOC 2 report. The security page explains why, and what we offer instead.
9. International transfers
Where we transfer personal data out of the UK or EEA to a country without an adequacy decision, the transfer relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two, controller to processor) and, for UK transfers, the ICO’s International Data Transfer Addendum. Those clauses are incorporated into this DPA by reference and take precedence over it where they conflict. Docking clause: optional clauses are excluded save as stated; the governing law and forum are those in the Terms of Service; Annexes I and II are populated by sections 3 and 6 of this DPA and the subprocessor list.
10. Deletion
Ephemeral records expire on their own within minutes. On termination we delete account data within 30 days, other than what we must retain by law. Backups are purged on their own cycle, within [N] days.
11. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails; where either conflicts with the Standard Contractual Clauses, those clauses prevail.