ChainTrace Labs
Data Privacy

Your data.
Handled with care.

Chain Trace Labs supports sensitive individual and professional investigations. We therefore design data handling around purpose limitation, controlled access, data minimisation and clear accountability across cases, workspaces and integrations.

GDPR-aware practices
No data selling -ever
Minimal collection only
How your data flows
You
Authorised case data
Platform
Controlled processing
Data sources
Minimal collection We collect information reasonably required to provide, secure and administer the services you choose.
No credentials -ever We will never ask for private keys, seed phrases, wallet passwords, or exchange logins.
Never sold Your data is used only to serve you. It is not sold, rented, or traded to any third party.
Your rights respected You have the right to access, correct, or request deletion of your personal data at any time.
Data We Handle

What We Handle - and Why

The information involved depends on whether you browse the site, submit an individual case, use a firm workspace, connect an integration or contact our team. The categories below explain the principal data we may handle.

What we do collect
Blockchain and case identifiers
Why: Wallet addresses, transaction hashes, networks and case references enable authorised tracing, monitoring and case organisation.
Account, organisation and contact details
Why: Used for authentication, workspace administration, notifications, support and agreed communications.
Evidence and investigation context
Why: Files, narratives, source references and communications supplied by authorised users help establish context and support investigation workflows.
Workspace, workflow and audit records
Why: Roles, assignments, notes, approvals, activity history and output records support collaboration, security and accountability.
Commercial and payment records
Why: Where applicable, we retain invoices, payment status, transaction references and tax records. Full card details are handled by authorised payment providers.
Standard server logs
Why: IP addresses and access timestamps collected automatically by the server for security. Retained for 30 days.
What we never collect
Private keys or seed phrases
Private keys, seed phrases and wallet or exchange credentials are never required. Anyone asking for them while claiming to represent Chain Trace Labs should be treated as suspicious.
Wallet passwords or exchange credentials
We never require access credentials for your wallet or exchange accounts. Blockchain queries are read-only; other case material is processed only where submitted or authorised for an agreed investigation purpose.
Advertising or behavioural profiles
We do not build profiles, track browsing behaviour, or run advertising of any kind.
Government ID or financial records
We do not request identity documents as a routine input to blockchain analysis. Limited identity or organisational verification may be required where necessary for account security, contracting, fraud prevention or legal compliance.
Location data or device fingerprints
We do not use geolocation APIs, browser fingerprinting, or device tracking scripts.
Third-party social logins
We do not offer or require sign-in via Google, Facebook, Apple, or any other social platform.
Data Usage

How Your Data Is Used

We use information for stated, authorised and legally permitted purposes.

01

Providing investigation capabilities

We use authorised case and blockchain data to provide tracing, risk analysis, monitoring, evidence management, OSINT-supported research, workflows, collaboration, integrations and agreed outputs.

02

Operating accounts and workspaces

Account and contact information supports authentication, role-based access, workspace administration, service notices, case communications, delivery and support. Marketing communications, where offered, require an appropriate basis and can be opted out of.

03

Administering engagements

Commercial records are used to manage proposals, orders, invoicing, payment status, entitlements, usage, renewals where agreed, accounting and applicable legal obligations.

04

Platform security

Standard server logs (IP address, access time) are retained for 30 days to detect abuse, brute-force attempts, and fraudulent submissions. They are not used for any other purpose.

05

Legal compliance

In the event we are subject to a lawful legal order from a competent authority, we may be required to disclose data. We will notify you where legally permitted to do so.

What we never do

We never sell, share, rent, or otherwise transfer your data to advertisers, data brokers, analytics companies, or any third party for commercial purposes.

Retention

How Long We Keep Your Data

We retain information only for as long as reasonably necessary for the engagement, account or purpose for which it was collected, and for security, audit, dispute, contractual, regulatory and legal requirements. Retention may therefore differ by data category and customer arrangement.

If you request deletion of your data at any point, we will action that request promptly -see your rights below.

Note: Public blockchain records are maintained independently of Chain Trace Labs. Deleting information from our systems cannot erase transaction data that remains recorded on a blockchain or information retained by an independent third party.

Data type Retention period
Case submission data Engagement period plus documented retention needs
Account and contact details Engagement period plus documented retention needs
Commercial and payment records As required for accounting, tax, contractual and legal obligations
Server access logs 30 days (security)
Case data and outputs As required by law
Data on deletion request Deleted within 30 days
Your Rights

Rights You Hold Over Your Data

Regardless of where you are in the world, we recognise and honour these fundamental data rights.

Right of Access

You can request a copy of all personal data we hold about you. We will provide it in a readable format within 30 days.

Right to Rectification

If data we hold about you is inaccurate or incomplete, you can request that we correct or complete it.

Right to Erasure

You can request deletion of your personal data. We will respond within the period required by applicable law, subject to identity verification, lawful exemptions and retention obligations.

Right to Object

You can object to how we process your data. Where your objection is valid, we will cease the relevant processing.

Right to Restrict Processing

In certain circumstances you can request that we limit how we use your data while a dispute or review is in progress.

Right to Portability

You can request your data in a structured, machine-readable format so that it can be transferred to another service.

To exercise any of these rights, email us at privacy@chaintracelabs.com. We will respond within the period required by applicable law. You may also have the right to lodge a complaint with your national data protection authority if you believe your rights have not been respected.

Cookies & Tracking

No Tracking. No Ad Cookies.

We use only technically essential cookies required for the platform to function. We do not use advertising cookies, third-party trackers, analytics platforms that profile users, or pixel tracking of any kind.

We do not use Google Analytics, Facebook Pixel, Hotjar, Intercom, or any similar third-party tool that collects data on your browsing behaviour.

Third Parties

Who We Do (and Don't) Share Data With

Never shared

Advertisers & marketing companies

We have no advertising relationships. Your data is never shared with or sold to any advertiser, marketing platform, or data broker for advertising or unrelated commercial use.

Never shared

Other crypto platforms or exchanges

We do not disclose case data to exchanges or other external organisations unless directed or authorised by the customer, necessary for an agreed service, required to protect rights and security, or compelled by applicable law.

Only if legally required

Law enforcement & legal authorities

If compelled by a valid, lawful legal order from a competent authority in an applicable jurisdiction, we may be required to disclose data. We will notify you where permitted by law.

Never shared

AI training or research datasets

Customer case content is not used to train general-purpose public AI models. Where an engagement includes AI-assisted functions, relevant content may be processed only to provide that function under applicable controls and provider terms.

Security

How We Protect Your Data

We apply reasonable technical and organisational measures to protect data from unauthorised access, loss, or disclosure. These include encrypted transmission (HTTPS), access controls, and regular review of data handling practices.

No internet-based system can guarantee absolute security. If we become aware of a breach that affects your personal data, we will notify you in accordance with applicable law.

HTTPS encryption in transit All data transmitted between your browser and our server is encrypted via TLS.
Access controls Case data is accessible only to authorised team members on a need-to-know basis.
Data minimisation We minimise collection and securely delete or anonymise information when applicable retention requirements expire.
No third-party trackers No analytics, ad networks, or tracking scripts that could expose your data to third parties.
Questions & Requests

Get in Touch About Your Data

To exercise any of your data rights, ask a question about how your information is handled, or raise a concern, contact us directly. We respond within the period required by applicable privacy law.

Continue exploring

Find the right ChainTrace pathway.