Clamp
Legal

Privacy Policy

Last updated

Draft pending legal review

Items in brackets are not filled in yet. This policy describes how Clamp works today and will be finalised before general availability.

Who we are

Clamp is a crypto sub-ledger for finance teams, operated by [Company legal name], [registered address], registered under [company number and register] ("we", "us"). For personal data about our own users and visitors we are the controller. You can reach us about privacy at [privacy contact email].

Data we collect

CategoryWhat it includesWhere it comes from
Access requestsName, work email, company, role, number of wallets, your optional noteThe request access form
Account dataName, email address, company membership, role, password hash, authenticator app secretYou, or the administrator who invites you
Sign-in recordsTime of sign-in and sign-out, failed attempts, IP address, browserOur sign-in service when you use it
Activity recordsChanges you make in Clamp (settings, period locks, users, exports), with your name and the timeYour use of the application
Server logsIP address, requested address, time, response statusEvery request to our servers
Website visitsPage, referring site, browser, device type, country; no IP address and no cookiesOur self-hosted analytics (Umami) when you browse this website

We do not collect payment card data, government identifiers or special categories of personal data.

How we use it

  • To review access requests and contact you about them.
  • To create and secure your account, including two-factor sign-in and locking an account after repeated failed attempts.
  • To provide the service: show your company's books to the people your company has authorised, and record who changed what.
  • To keep the service secure and available: detect abuse, investigate incidents, enforce rate limits.
  • To meet legal obligations.

We do not sell personal data, do not use it for advertising and do not use it to train machine learning models.

Where the EU or UK General Data Protection Regulation applies, we rely on: performance of a contract (providing accounts and the service), our legitimate interests (reviewing access requests, securing the service, keeping an audit trail that your company and its auditors rely on), and legal obligations (keeping records the law requires).

Data in your books

The wallet addresses, transactions, balances, prices and reports your company keeps in Clamp belong to your company. For that data we act on your company's instructions as its processor, under [Company legal name]'s data processing terms with your company. Most of it is public blockchain data; it can become personal data when an address is linked to a person.

Each company's records are kept in a separate database. API keys you store are encrypted with AES-256-GCM and can only be decrypted for the company they belong to.

Service providers

ProviderPurposeData they receive
Hetzner Online GmbH, GermanyServers, storage and backupsAll data stored in Clamp, encrypted in transit
Blockchain data providers: Etherscan, Routescan, mempool.space, TronGrid, Toncenter, a Solana RPC provider, an XRP Ledger node operatorReading transaction history and balancesThe wallet addresses being synced, without names or account data
Market data providers: Coinbase, Bitfinex, Bitstamp, Binance, KuCoin, OKX, CoinGecko, Gate.ioAsset pricesAsset symbols and dates only, no personal data
[Email delivery provider]Invitation and password emailsName and email address

Where data is stored

Clamp's servers and backups are in Germany, in the European Union. Some blockchain data providers listed above may be located outside the European Economic Area; they receive wallet addresses only. Where a transfer of personal data outside the EEA is needed, we use [transfer safeguard, for example Standard Contractual Clauses].

How long we keep it

DataKept for
Access requests that are declined[period, for example 12 months]
Account dataWhile the account exists, then deleted within [period]
Sign-in records1 year
Activity records (audit log)For as long as your company keeps its books in Clamp, because they form part of its audit trail
Server backups7 days, then overwritten
Server logs[period]
Website visit statistics[period, for example 24 months]

Security

Every user signs in with a password and an authenticator app. Connections are encrypted. Each company has its own database, and the application's database role cannot change table structure or rewrite activity records. Servers accept administrative access only by key from known addresses, and we apply security updates automatically.

Cookies and analytics

This website sets no cookies and loads nothing from third parties: no advertising, no embedded fonts or scripts from other domains. We count visits with Umami, which we run on our own server: it uses no cookies, does not store IP addresses (an address is turned into an anonymous identifier that changes every day) and records the page, referring site, browser, device type and country. Visitors whose browser sends a Do Not Track signal are not counted. When you sign in to the application, our sign-in service sets cookies that keep your session; they are strictly necessary and expire when the session ends or after at most 10 hours.

Your rights

Depending on where you live, you can ask us for access to your personal data, correction, deletion, restriction of processing, a copy in a portable format, or object to processing based on legitimate interests. Write to [privacy contact email]; we answer within one month. If the data is part of your company's books, we will pass your request to your company, which decides on it. You can also complain to a data protection authority, for example [competent supervisory authority].

Changes

We will update this page when our processing changes and change the date at the top. Material changes are announced to account holders by email before they apply.

Contact

[Company legal name], [registered address]. Email: [privacy contact email].