Privacy Policy for Kadindexer

1. Introduction

Welcome to Kadindexer. We value your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, share, and protect your information when you access or use our website, API services, and user dashboard (collectively, the "Services").

This Privacy Policy applies to all users of the Services, whether you are accessing them through a free or paid plan.

By accessing or using Kadindexer, you agree to the terms of this Privacy Policy. If you do not agree with this policy, please do not use our Services.

Kadindexer is operated by Hack-a-Chain Blockchain Technology Ltda, a company registered in the Brazilian jurisdiction under CNPJ number 46.243.993/0001-23 ("Hack-a-Chain"). We process personal data in accordance with the Lei Geral de Proteção de Dados (LGPD), the General Data Protection Regulation (GDPR), and other applicable data protection laws.

If you have any questions about this Privacy Policy or your personal data, you can contact us at:

admin@hackachain.io

2. Information We Collect

We collect personal and technical information to provide, maintain, secure, and improve our Services. The types of information we collect include:

2.1 Information You Provide to Us

We collect the following information directly from you when you create or manage your account, request an API key, or subscribe to a plan:

  • Full name (if provided during registration)
  • Email address (via Google account login)
  • Company name (optional)
  • Billing and subscription information, including payment method, billing address, and tax-related identifiers (collected and processed by Stripe)
  • Any information you provide through support requests, contact forms, or feedback submissions

2.2 Information We Collect Automatically

When you interact with our website, dashboard, or APIs, we automatically collect technical information such as:

  • IP address and approximate geolocation
  • Browser type, operating system, and device information
  • Access times and referring URLs
  • Pages visited on our site or dashboard
  • Logs of API usage (e.g., endpoints accessed, number of requests, timestamps)

2.3 Blockchain-Related Data

As part of providing blockchain indexing services, we may collect and process:

  • Public blockchain data, including wallet or account addresses
  • Public keys associated with transactions or smart contract events
  • Metadata related to your usage of our API, such as chain ID, block height, or requested data types

Note: We do not collect or store private keys or sensitive on-chain credentials. Any blockchain-related data processed is limited to publicly available or user-submitted identifiers.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 To Provide and Maintain the Services

  • Authenticate your account and manage user access
  • Generate and manage API keys and rate limits
  • Deliver the features and functionality of our indexing API
  • Process your subscription and manage billing through Stripe

3.2 To Improve and Secure Our Platform

  • Monitor usage patterns to optimize performance and reliability
  • Identify and resolve bugs or errors
  • Prevent abuse, fraud, unauthorized access, and other security threats
  • Conduct internal research and diagnostics

3.3 To Communicate with You

  • Send essential service notifications (e.g., API key updates, downtime alerts)
  • Respond to your inquiries and support requests
  • Provide technical updates, documentation improvements, or product changes

3.4 For Legal and Compliance Purposes

  • Comply with applicable laws and regulations, including tax and financial reporting obligations
  • Cooperate with regulatory authorities or law enforcement when required
  • Enforce our Terms of Use and defend against legal claims

3.5 For Marketing and Product Updates

  • Send optional communications about new features, events, or updates (only with your consent or where allowed by law)
  • Allow you to unsubscribe or opt out of promotional messages at any time

4. Legal Basis for Processing

If you are located in the European Economic Area (EEA), United Kingdom, or Brazil, we process your personal data in accordance with the lawful bases defined under the General Data Protection Regulation (GDPR) and the Lei Geral de Proteção de Dados (LGPD).

We rely on the following legal bases to process your personal data:

4.1 Performance of a Contract

We process your personal data to provide the Services you request under our Terms of Use, including account management, API access, and billing.

4.2 Legitimate Interests

We process certain data to operate, maintain, and improve the Services, protect against misuse or fraud, and communicate with users about service-related matters. We do so only when our legitimate interests are not overridden by your rights and freedoms.

4.3 Compliance with Legal Obligations

We may process your personal data when required to comply with applicable legal and regulatory obligations, such as financial reporting, anti-fraud measures, and cooperation with competent authorities.

4.4 Consent

Where required, we rely on your consent to send promotional communications or to place non-essential cookies and trackers. You may withdraw your consent at any time by following the unsubscribe link in our emails or by contacting us directly.

5. How We Share Your Information

We do not sell your personal data. However, we may share your information with trusted third parties in the following limited circumstances:

5.1 Service Providers and Subprocessors

We engage third-party providers to help us operate our Services. These providers may have access to your personal data only to perform tasks on our behalf and are contractually obligated to protect it. Examples include:

  • Authentication providers (e.g., Google)
  • Payment processors (e.g., Stripe)
  • Infrastructure and hosting (e.g., cloud platforms)
  • Analytics and monitoring tools

5.2 Affiliates and Business Partners

We may share information with affiliated entities and select partners that support the development and delivery of our Services, always under strict confidentiality obligations.

5.3 Legal and Regulatory Disclosures

We may disclose personal data if required to:

  • Comply with legal obligations or respond to lawful requests
  • Protect the rights, safety, or property of Kadindexer, our users, or others
  • Enforce our Terms of Use or defend against legal claims

5.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the protections of this Privacy Policy.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Maintaining your account and access to the Services
  • Providing customer support
  • Complying with legal, tax, or accounting obligations
  • Preventing abuse, fraud, or misuse of our platform

The specific retention periods may vary depending on the type of data:

  • Account information (e.g., email, API keys) is retained while your account is active and for a reasonable period thereafter for legal or operational reasons.
  • Billing and payment data is retained as required by applicable financial and tax regulations.
  • Usage logs and technical diagnostics may be stored for up to 1–3 years to support performance monitoring, debugging, and abuse prevention.

You may request deletion of your personal data at any time (see Section 7: Your Rights and Choices). In some cases, we may retain certain data as required or permitted by law, even after account closure.

7. Your Rights and Choices

Depending on your location and applicable law, you may have the following rights regarding your personal data:

7.1 Right to Access

You have the right to request confirmation of whether we process your personal data and to receive a copy of the data we hold about you.

7.2 Right to Correction

You may request correction of inaccurate or incomplete personal data.

7.3 Right to Deletion

You may request that we delete your personal data, subject to certain legal exceptions (e.g., when we are required to retain data for tax or regulatory purposes).

7.4 Right to Withdraw Consent

If we process your data based on your consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.

7.5 Right to Object or Restrict Processing

You may object to or request that we restrict the processing of your data in certain circumstances, such as for direct marketing or where our legal basis is legitimate interest.

7.6 Right to Data Portability

You may request to receive your personal data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another service provider.

7.7 Right to File a Complaint

You have the right to file a complaint with your local data protection authority if you believe your rights have been violated.

How to Exercise Your Rights

To exercise any of your rights, please contact us at admin@hackachain.io. We may ask you to verify your identity before processing your request. We will respond within the timeframes required by applicable law.

8. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction.

These measures may include:

  • Encryption of data in transit (e.g., HTTPS)
  • Firewalls and network protections
  • Access controls and authentication requirements
  • Monitoring and logging of system activity
  • Regular updates and vulnerability assessments

Access to your personal data is restricted to authorized personnel and trusted service providers who need the information to perform tasks on our behalf and are contractually obligated to protect it.

While we strive to protect your personal data using industry-standard security practices, no method of transmission or storage is 100% secure. Therefore, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your API keys, credentials, and any activity that occurs under your account.

If you believe your account or data may have been compromised, please contact us immediately at admin@hackachain.io

9. International Data Transfers

Kadindexer is operated by Hack-a-Chain Blockchain Technology Ltda, based in Brazil. However, in order to provide our Services globally, your personal data may be transferred to and processed in countries outside of your jurisdiction, including countries that may not offer the same level of data protection as your home country.

When we transfer your data internationally, we take appropriate safeguards to ensure your personal data remains protected in accordance with applicable data protection laws, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA or UK
  • Contractual safeguards and data processing agreements with our subprocessors
  • Ensuring subprocessors are located in jurisdictions with adequate levels of data protection or comply with similar legal mechanisms

By using our Services, you acknowledge that your data may be processed in countries where we or our service providers operate.

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve your experience, understand how our Services are used, and enhance functionality.

10.1 What Are Cookies?

Cookies are small text files stored on your device by your browser. They help us recognize you, remember your preferences, and track how you use our website and dashboard.

10.2 Types of Cookies We Use

  • Essential Cookies – Required for core site functionality, such as login and session management.
  • Analytics Cookies – Help us understand how users interact with the site so we can improve performance (e.g., page views, click behavior).
  • Preference Cookies – Store your language or interface preferences.
  • Marketing Cookies – (If used in the future) May help us deliver relevant content or promotions via third-party platforms.

We currently use services like Google Analytics to collect aggregated usage statistics. These services may set their own cookies in accordance with their privacy policies.

10.3 Your Choices

You can control or disable cookies via your browser settings. Please note that disabling certain cookies may affect your experience or limit functionality.

If you are located in a jurisdiction that requires consent (such as the EU), we will display a cookie banner to allow you to accept or reject non-essential cookies.

For more information on managing cookies, visit www.allaboutcookies.org.

11. Children's Privacy

Our Services are not intended for use by individuals under the age of 13 (or the minimum age required in your jurisdiction to consent to data processing). We do not knowingly collect or process personal data from children.

If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete such information promptly.

If you believe a child has provided us with personal data, please contact us at admin@hackachain.io.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, legal obligations, or how we handle your personal data.

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify users by email or through a notice on our website or dashboard, where required by law

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

Your continued use of the Services after any changes signifies your acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

admin@hackachain.io

We aim to respond to all requests within the timeframes required by applicable data protection laws.