Data Processing Agreement

The Article 28 terms for payer data — Blockra is your processor, you are the controller, and this is the sub-processor list.

Last updated August 2, 2026

This Agreement applies where Blockra processes personal data on your behalf — that is, the data of your customers who pay through your checkout. It forms part of the Terms of Service and takes effect when you create an account. No signature is needed; if your organisation requires a countersigned copy, email support@blockra.io.

It is written to meet Article 28 of the UK GDPR and the EU GDPR.

1. Roles

  • You (the merchant) are the controller of your payers' personal data. You decide why it is collected and what happens to it.
  • Blockra ("we", "us") is the processor, acting only on your documented instructions.
  • For your own account data, Blockra is a controller in its own right. That is covered by the Privacy Policy, not this Agreement.

2. Subject matter and duration

Blockra processes payer personal data for as long as your account exists, in order to present a checkout, take a payment, notify you of it, and produce receipts and reporting. Processing ends when the account is closed, subject to the retention in section 9.

3. Nature and purpose of processing

Collection, storage, structuring, retrieval, transmission to the sub-processors listed below, and erasure. Specifically: presenting the checkout, deriving a payment address or creating a card intent, watching for settlement, emailing a receipt, firing a webhook to you, and showing the payment in your dashboard and analytics.

4. Categories of data subject

Your customers who begin or complete a payment through a Blockra checkout.

5. Categories of personal data

Only what the checkout collects:

  • Email address, where you require it.
  • Country, resolved at the CDN edge from the connecting IP address.
  • For card payments: name, country and postcode entered for billing; and card brand, last four digits, funding type, expiry, and wallet used. The card number and security code are entered into Stripe-hosted fields and never reach Blockra's systems.
  • For bank payments: the payer's email address, and afterwards the payment status, currency, amount and expected clearing date. The payer's bank account details are entered on GoCardless-hosted pages and on the payer's own bank, and never reach Blockra's systems.
  • Payment details: amount, currency, exchange rate at the time, asset and network, deposit address, transaction hash, confirmation count, status and timestamps.
  • Your own reference and any metadata you attach to the payment. You control this field — do not put special-category data in it.
  • A record that terms were accepted, where you require it.

No special-category data is processed. Blockra does not collect a street address, a phone number, a date of birth, or an identity document from payers.

6. Your instructions

Your documented instructions are: these terms, the Terms of Service, and the configuration you set in the dashboard and through the API. Blockra will not process payer data for any other purpose.

If we believe an instruction breaches data-protection law, we will tell you and may suspend that processing.

You warrant that you have a lawful basis for the data you collect through the checkout, and that your own privacy notice tells your customers about it — including that Blockra processes it for you.

7. Confidentiality and staff

Access to payer data is limited to personnel who need it to run or support the service, each bound by confidentiality obligations.

8. Security

Blockra applies the measures set out in the Security Policy, including encryption in transit, row-level security on the database, hashed credentials, optional two-factor authentication for merchant accounts, signed webhooks, and rate limiting.

Two architectural points are relevant to your risk assessment:

  • Card numbers never enter our systems, so they cannot be exposed by a breach of Blockra.
  • Crypto payments settle to addresses derived from your own extended public key, so a breach of Blockra cannot move funds.

9. Retention and deletion

Payer data is retained while your account is open. On deletion of your account, personal identifiers on payment and customer records are stripped and the financial facts — amount, currency, date — are retained as a business and tax record.

On your written request, we will delete or return payer data sooner, except where we must keep it by law.

Blockchain data cannot be deleted by anyone. Deposit addresses and transactions are permanent public records. Neither you nor we can erase, rectify or restrict them, and any erasure request must be answered on that basis.

10. Sub-processors

You give general authorisation for the sub-processors below. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds; if the objection cannot be resolved you may terminate the affected service.

Sub-processorFunctionData it receives
SupabaseDatabase and authenticationAll stored payment and customer records
RailwayAPI hostingData in transit, application logs
CloudflareSite and checkout hosting, custom domainsServed content, IP at the edge, country header
StripeCard processing under your Connect accountCard details, billing name, country, postcode, email, amount
GoCardlessBank payment collection under your connected accountBank account details entered by the payer, email, amount
ResendTransactional emailRecipient address and message content
UpstashRate limitingIP address or account id, counters
mempool.space, litecoinspace.org, an Ethereum RPC provider, TronGridBlockchain readsDeposit addresses and transaction data (public)
ip-api.comIP-to-country fallback, disabled by defaultIP address, only if enabled

Frankfurter (exchange rates) and CoinGecko (prices) receive no personal data and are therefore not sub-processors.

If you configure your own SMTP server, receipts go through your provider rather than Resend, and that provider is yours rather than a Blockra sub-processor.

11. International transfers

Sub-processors operate internationally. Transfers outside the UK and EEA rely on an adequacy decision or on Standard Contractual Clauses. Blockchain data is inherently global and public.

12. Assistance

Taking into account the nature of processing, Blockra will assist you with:

  • Data-subject requests. Most are self-service: your dashboard shows the payer records held for your account and lets you act on them. Where you need more, email support@blockra.io. If a payer contacts us directly, we will refer them to you.
  • Personal data breaches. We will notify you without undue delay after becoming aware of a breach affecting your payer data, with the detail available at the time, and update you as we learn more.
  • Impact assessments and prior consultation, to the extent the information is ours to give.

13. Audit

We will make available the information reasonably necessary to demonstrate compliance with this Agreement, and will respond to a reasonable written questionnaire no more than once a year. On-site audits are by prior written agreement, at your cost, subject to confidentiality, and must not compromise the security of other merchants.

14. Liability and precedence

Liability under this Agreement is subject to the limits in the Terms of Service. Where this Agreement conflicts with the Terms on the processing of payer personal data, this Agreement prevails.

15. Contact

Data protection queries: support@blockra.io

Blockra