Get a site key

Data Processing Addendum

Last updated 23 August 2026

This DPA forms part of the Terms of Service. It is shorter than most, for a reason worth stating up front: there is almost nothing here for us to process.

This DPA is between you (“Customer”, the controller) and [Legal entity name] (“BlockAgents”, the processor), and applies where you use the service to process personal data subject to the UK GDPR, the EU GDPR, or both. It takes effect when you accept the Terms of Service; no signature is required, but we will sign a countersigned copy on request at legal@blockagents.ai.

The unusual part

A DPA normally enumerates the categories of personal data a processor handles on the controller’s behalf. For challenge traffic, ours is empty. We receive no name, no email, no account identifier, no cookie, no device identifier and no behavioral data about the people who solve challenges on your site. We set nothing on their device and we retain no IP address. Article 28 obligations still apply to us as your processor; there is simply very little for them to attach to.

1. Definitions

Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR (2016/679), and any successor legislation. Controller, processor, data subject, personal data, processing and personal data breach have the meanings given in the EU GDPR.

2. Roles

For challenge traffic on your site, you are the controller and we are the processor. For your own account data — the email, label and domains you gave us — we are an independent controller, and the privacy policy governs it, not this DPA.

3. Scope of processing (Annex I)

ItemDetail
Subject matterDistinguishing automated from human form submissions on the Customer’s site.
DurationThe term of the Terms of Service.
Nature and purposeIssuing a challenge, grading an answer, issuing and redeeming a single-use verification token.
Types of personal dataNone. Challenge issuance and grading involve no personal data. An IP address is present at the transport layer and is used transiently for rate limiting; it is HMAC-hashed under an in-memory salt that is never persisted, and no raw address is stored.
Special categoriesNone. The service cannot receive them.
Categories of data subjectVisitors to the Customer’s site, insofar as the transport-layer address above concerns them.
FrequencyContinuous, per challenge.

4. Our obligations

We will:

We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law.

5. Subprocessors

You give general authorization for us to engage subprocessors. The current list is at /subprocessors. We will give at least 30 days’ notice before adding or replacing one; you may object on reasonable data protection grounds within that period, and if we cannot resolve the objection you may terminate the affected service without penalty. Each subprocessor is bound by terms no less protective than these, and we remain fully liable for their performance.

6. Security

We implement appropriate technical and organisational measures under Article 32. The measures are set out in full on the security page; in summary:

The strongest measure available to us is holding nothing, and it is the one we have built the product around.

7. Breach notification

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, with the nature of the breach, the likely consequences, and the measures taken. You remain responsible for notifying your supervisory authority and data subjects.

8. Audit

On reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this DPA and permit an audit by you or an independent auditor bound by confidentiality. Audits must not unreasonably disrupt the service, and you bear your own costs.

We do not hold a SOC 2 report. The security page explains why, and what we offer instead.

9. International transfers

Where we transfer personal data out of the UK or EEA to a country without an adequacy decision, the transfer relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two, controller to processor) and, for UK transfers, the ICO’s International Data Transfer Addendum. Those clauses are incorporated into this DPA by reference and take precedence over it where they conflict. Docking clause: optional clauses are excluded save as stated; the governing law and forum are those in the Terms of Service; Annexes I and II are populated by sections 3 and 6 of this DPA and the subprocessor list.

10. Deletion

Ephemeral records expire on their own within minutes. On termination we delete account data within 30 days, other than what we must retain by law. Backups are purged on their own cycle, within [N] days.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails; where either conflicts with the Standard Contractual Clauses, those clauses prevail.