Privacy statement
What data this service processes, why, who receives it, how long it is kept and what you can ask us to do about it.
This statement explains how the FORCE consortium handles personal data when you use this website. It is written to meet Articles 13 and 14 of Regulation (EU) 2016/679 (the GDPR).
Who is responsible
The controller is the FORCE consortium, acting through its coordinating entity. The coordinator’s registered name and address, and the contact details of the data protection officer where one is appointed, are to be completed before the service is published. General enquiries: privacy@force-consortium.eu.
What is processed, and why
| Processing | Legal basis |
|---|---|
| A public wallet check: the address you enter, the network, and the time of the check. | Legitimate interests (Art. 6(1)(f)) - operating a screening service that was asked for. |
| A wallet signature, when you choose to connect a wallet. | Consent (Art. 6(1)(a)) - you choose to sign; the signature binds a report to the address. |
| A message sent through the contact form: name, email, organisation, country and the message itself. | Legitimate interests (Art. 6(1)(f)) - answering the person who wrote to us. |
| An institutional account: the identity of the signed-in user and an audit record of what was screened and when. | Legal obligation of the account holder (Art. 6(1)(c)) and our contract with them (Art. 6(1)(b)). |
| Server logs and rate limiting: IP address, request time and the endpoint called. | Legitimate interests (Art. 6(1)(f)) - keeping the service available and resisting abuse. |
Is a wallet address personal data?
Often, yes. A public address is a pseudonymous identifier, and where it can be linked to a person - by you, by us or by anyone else with lawful access - it is personal data and this statement applies to it. FORCE does not try to identify the holder of an address, and it does not enrich addresses with identity data from other sources.
A public wallet check is not linked to an account and requires no registration. We do not build a profile of the person running a check.
Who receives your data
To perform a check, the address you submit is sent to the upstream indexers and sanctions sources named in the data sources documentation. Those parties are independent controllers for what they do with a request they receive.
- Blockchain indexers and public RPC endpoints, to read the on-chain history of the address.
- Sanctions publishers, whose lists are downloaded whole; matching happens on our own servers, so the address is not sent to them.
- A price source, which receives an asset identifier and never an address.
- The hosting provider that runs the service infrastructure, as a processor under Article 28.
We do not sell personal data, and we do not use it for advertising or for automated decisions producing legal effects concerning you within the meaning of Article 22. A risk score is a decision-support signal; the decision to act on it is taken by a person at the regulated firm.
Transfers outside the EEA
Some sanctions publishers and indexers are established outside the European Economic Area, notably in the United States. Downloading a published list involves no transfer of your data. Where a request to a non-EEA indexer necessarily carries the address being checked, the transfer relies on the safeguards in Chapter V of the GDPR, and the service is designed so that the EU-published sources remain sufficient for a result.
How long it is kept
| Data | Retention |
|---|---|
| A public wallet check | Not stored against you. Upstream responses are cached briefly for performance only. |
| A wallet signature | Held in your browser session and discarded when it ends. |
| A contact message | Up to 24 months after the enquiry is closed. |
| Institutional audit records | Five years, where Regulation (EU) 2024/1624 requires it of the account holder. |
| Server logs | Up to 90 days. |
Your rights
Under the GDPR you may ask for access to your personal data, its rectification or erasure, restriction of processing, and portability. Where processing rests on our legitimate interests you may object to it at any time, and where it rests on consent you may withdraw that consent without affecting the lawfulness of what came before.
Write to privacy@force-consortium.eu - contact form. We answer within one month, and will tell you if we need longer.
If you are not satisfied you may lodge a complaint with the supervisory authority of the member state where you live, work, or where you believe the problem occurred. A list of national authorities is published by the European Data Protection Board.
Security
Traffic is served over TLS. Access to institutional audit records is restricted to the account that produced them. We do not ask for, and you must never send us, a private key or a seed phrase - no part of this service will ever need one.
Changes
Material changes to this statement will be announced on this page before they take effect. The version in force is the one published here.
Text last revised 13 Aug 2026