Version 1.0 · Effective August 2, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween you ("Controller") and MadeOnSol ("Processor") and applies where we process personal data on your behalf under Article 28 GDPR. To receive a countersigned PDF for your records, email [email protected] with your legal entity name, address and enterprise/VAT number, and we will return an executed copy.
Processor: MadeOnSol, the sole proprietorship (eenmanszaak) of Stijn Poortmans, Mgr. Raeymaekersstraat 37, 2235 Hulshout, Belgium. Enterprise number (KBO/BCE) 1039.535.538, also VAT identification number BE 1039.535.538 (art. 56bis exemption). Contact: [email protected].
Controller: the customer entity accepting the Terms of Service. We have not appointed an Article 27 EU representative because we are established in the EU.
The overwhelming majority of what MadeOnSol serves is public blockchain data — transactions, wallet addresses, token deployments. That is not personal data provided by you, and for it we act as an independent controller, not your processor. This DPA covers the narrower set of personal data we process on your behalf as a result of your use of the Service.
Categories of data subjects: your authorised users (typically the individuals holding your account and API keys).
Categories of personal data: account identifiers (email address, username), authentication metadata, billing details you supply (name, country, VAT number), API request metadata (timestamps, endpoints called, originating IP address), and any wallet addresses you choose to submit to watchlists, alerts or webhook configurations.
Special categories: none. Do not submit special-category data under Article 9 — the Service is not designed for it and we do not accept it.
Nature and purpose: providing, securing, metering and supporting the Service. Duration: the term of your subscription, plus the retention periods in section 7.
You give general written authorisation for the sub-processors below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected Service without penalty for the unused period.
Analytics is self-hosted (Umami) on our own infrastructure, so no analytics data is shared with a third party. Blockchain RPC and streaming providers receive public chain queries, not your personal data.
Measures under Article 32 include: TLS on all public endpoints; hashed API keys that cannot be recovered after creation; row-level security isolating account data; encrypted, checksum-verified off-site backups; continuous write-ahead-log archiving giving a recovery-point objective of approximately one minute; a warm standby database on separate hardware; a rehearsed restore procedure with a measured recovery time of approximately 3 to 3.5 hours; default-deny host firewalling; and continuous automated health and integrity monitoring.
Known limitations are stated openly at /security, including the absence of disk-level encryption, the absence of third-party security certification, and the single-primary-host architecture. We prefer you to weigh those before signing rather than discover them after.
Personal data is stored and processed in the European Union. Where a sub-processor transfers data outside the EEA, that transfer is covered by European Commission Standard Contractual Clauses or an adequacy decision. We do not transfer personal data outside the EEA on our own account.
You can export or delete your account data at any time from your profile. On termination we delete personal data within 90 days, except where retention is required by law — Belgian accounting rules require invoice and payment records to be retained for seven years, and those records are kept on that basis regardless of deletion requests. API request logs are retained on a rolling 90-day window for security and abuse detection. Backups age out on their own retention cycle; data in an encrypted backup is not individually erasable, but is overwritten as the cycle rotates.
On reasonable written notice, and no more than once in any 12-month period unless required by a supervisory authority or following a personal-data breach, we will respond to a security questionnaire and provide documentation evidencing the measures in section 5. On-site audits are available on Enterprise terms.
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal-data breach affecting your data, with the information available at that time and further detail as the investigation progresses. We maintain a documented internal breach procedure.
Liability under this DPA is subject to the limitations in the Terms of Service. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. A signed agreement between the parties prevails over both for the matters it covers.
Belgian law, with the courts of Belgium having jurisdiction, without prejudice to any mandatory rights you have as a consumer or under the GDPR.
Related: Privacy Policy · Security · Terms of Service