1. Scope and controller
1.1 Scope. This Policy applies to icterminal.com, the Request Access and billing-information form, commercial and contractual communications, electronic signatures, payments and invoicing, the restricted terminal, support, Alerts, Official Materials and related professional services (the “Services”).
1.2 Controller. The data controller is the Provider identified in the Legal Notice (the “Controller”). Privacy requests may be submitted using the contact details available there.
1.3 Representatives. Where a Customer is an organisation, this Policy also applies to its contact persons, authorised signatories, billing contacts and Authorised Users. The Customer should provide this Policy to those persons.
2. Personal data processed
| Category | Examples |
|---|---|
| Identity and business contact | Name, surname, business email, telephone number where provided, job title, role, organisation and communications. |
| Request and eligibility | Requested use, professional status, country, application answers, review status, verification notes and related correspondence. |
| Business, billing and tax | Legal business name, establishment and billing address, company or registration number, VAT or tax identifier, SDI/PEC where relevant, invoice details and tax-treatment evidence. |
| Contract and signature | Service Agreement content, signer name and capacity, email, signature representation, document version, completion certificate, timestamps, IP address and signing audit events supplied by the electronic-signature provider. |
| Payment | Stripe payment and transaction references, amount, currency, payment status, fraud-prevention signals and limited payment-method information. The Provider does not ordinarily receive or store full card details. |
| Account and settings | Username, authentication and password-reset events, plan, Authorised Users, access dates, favourites, saved wallets, Custom Metrics, Alert settings and account preferences. |
| Technical, usage and security | IP address, browser and device data, access and activity logs, session events, Cloudflare Ray ID or similar request identifiers, errors, diagnostics, security and abuse-prevention events, and consent preferences. |
| Alert and integration | Metric or wallet selections, thresholds, Telegram bot tokens, Slack webhooks, notification destinations and related configuration. These credentials should be treated as confidential. |
| Public-ledger and analytical | Public wallet addresses, transactions, historic balances, labels, confidence indicators, classifications, inferred entity relationships and methodology metadata. These may be personal data when reasonably linkable to a person. |
| Support and commercial communications | Emails, form messages, support requests, feedback, sales discussions and records of contractual or operational communications. |
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Receive and assess a Request Access submission; verify business eligibility, billing and tax information; communicate next steps | Steps requested before a contract (GDPR Art. 6(1)(b)); legitimate interests in selecting professional customers, preventing misuse and administering requests (Art. 6(1)(f)) |
| Prepare, send, electronically sign and preserve the Service Agreement and signature evidence | Pre-contract steps and contract performance (Art. 6(1)(b)); legitimate interests in proving formation, authority and agreed terms and defending claims (Art. 6(1)(f)) |
| Create accounts; authenticate users; operate the terminal, settings, favourites, Custom Metrics and Alerts; provide support | Contract performance (Art. 6(1)(b)); legitimate interests in reliable and secure service operation where appropriate (Art. 6(1)(f)) |
| Collect payment; issue invoices; maintain accounting, tax and contractual records | Contract performance (Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)) |
| Protect security; prevent fraud, credential sharing, abuse and unlawful access; diagnose errors and maintain service integrity | Legitimate interests in security, fraud prevention, protection of rights and reliable operation (Art. 6(1)(f)); contract performance where necessary (Art. 6(1)(b)) |
| Ingest, structure, label, calculate and analyse public Internet Computer ledger data within the conventional icterminal IT environment; improve and defend methodology and outputs | Legitimate interests in operating, improving and protecting a professional analytical environment and freedom of information (Art. 6(1)(f)), balanced against individual rights |
| Respond to support, correction and label-review requests; improve quality and methods | Contract performance where customer-related (Art. 6(1)(b)); legitimate interests in quality, accuracy and service development (Art. 6(1)(f)) |
| Send access, security, service, billing and contractual messages | Contract performance and pre-contract steps (Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c)) |
| Use non-essential analytics cookies or similar tracking technologies | Consent where required (Art. 6(1)(a) GDPR and applicable ePrivacy rules) |
| Establish, exercise or defend legal claims; enforce terms; respond to lawful authority requests | Legitimate interests (Art. 6(1)(f)); legal obligations (Art. 6(1)(c)) |
3.1 Necessary information. Business, contact, contract, account, payment and tax information marked as required is necessary to assess a request, enter into or perform the contract, or comply with law. If it is not provided or cannot be verified, the Provider may be unable to issue an agreement, collect payment, invoice or activate access.
3.2 Consent. Where processing relies on consent, it may be withdrawn at any time without affecting processing already carried out. A privacy acknowledgement on the request form confirms receipt of this Policy; it is not consent for processing that relies on another legal basis and is not acceptance of a Service Agreement.
4. How data is collected
4.1 From you. Data is obtained when you browse the websites, submit a request, provide billing information, communicate with the Provider, sign an agreement, complete payment, use the terminal, configure Alerts or request support.
4.2 Automatically. Web, security, authentication and terminal systems generate technical, session, device, activity, diagnostic and security records. Cookies and comparable technologies operate as described in Section 10.
4.3 From service providers and public sources. The Provider may receive limited contract, signature, payment, tax, delivery or fraud-prevention data from relevant providers. Public Internet Computer ledger data is obtained from public network interfaces, nodes, indexers and other lawful public sources and is processed within the Provider’s conventional IT infrastructure.
5. Request Access and contractual workflow
5.1 Non-binding form. Submitting billing and contact information is a non-binding request. Data is stored in Cloudflare infrastructure and an internal Slack notification may be generated so the Provider can review the request. No contract is formed and no payment is due at that stage.
5.2 Verification. The Provider may verify the submitted business and tax information against VIES, public business registers, tax-validation tools, sanctions sources and information supplied by the applicant, to the extent appropriate and lawful.
5.3 Signature and payment. If approved, customer-specific information is inserted into a private Service Agreement and processed through an electronic-signature provider, currently PandaDoc. After signature, payment is processed through Stripe. Contract and payment providers process some data under their own privacy terms and may also act as independent controllers for fraud prevention, compliance or platform security.
5.4 Minimisation in notifications. Internal notifications should contain only the information reasonably required to identify and review the request. Full card details must never be sent to the Provider or entered in the Request Access form.
6. Public-ledger data, labels and corrections
6.1 Public and persistent data. Internet Computer ledger transactions and wallet addresses are generally public and may be permanently recorded on the underlying public network. The Provider cannot erase or alter that source ledger.
6.2 Analytical classifications. Labels, confidence levels and inferred relationships are analytical outputs, not official certifications. They may rely on public sources, disclosed addresses, observations, heuristics and estimates and may be revised as evidence or methodology changes.
6.3 Requests concerning displayed information. A person who believes an address label or analytical inference displayed by the Service is materially inaccurate may contact the Provider using the contact details available in the Legal Notice and provide clear supporting information. The request will be assessed in light of data-protection law, data integrity, security, freedom of expression and information, the public nature of the source data and the rights of others.
6.4 Legitimate-interest balancing. When relying on legitimate interests for public-ledger analytics, the Controller considers the public character and persistence of the data, reasonable expectations, sensitivity, identifiability, potential impact, data minimisation, confidence indicators, correction procedures, access restrictions and contractual controls.
7. Recipients and service providers
| Recipient category | Purpose / examples |
|---|---|
| Website, security and form infrastructure | Cloudflare, including Pages/Workers, Turnstile, D1 or related hosting, security and database services actually used. |
| Internal collaboration | Slack, for limited internal notifications and operational review. |
| Electronic signature | PandaDoc or another e-signature provider used to send, sign, seal, evidence and preserve agreements. |
| Payments | Stripe, for Checkout or Payment Links, card processing, receipts, fraud prevention and payment administration. |
| Invoicing and accounting | Aruba or another electronic-invoicing/accounting provider, and the Provider’s accountant or tax adviser. |
| Terminal and infrastructure | Hosting, VPS, cloud, database, backup, logging, security, node, RPC, indexer, data and communications providers actually used to operate the Services. |
| Email and support | Email hosting, delivery and support providers used for contractual, access, billing and support messages. |
| Customer-selected integrations | Telegram, Slack or another channel selected by the Customer for Alerts, acting under its own terms and privacy notice. |
| Analytics | Google Analytics or another analytics provider only where enabled consistently with the user’s consent choices and applicable law. |
| Professional and public recipients | Lawyers, insurers, auditors, debt-recovery providers, competent public authorities and courts where necessary or legally required. |
7.1 Roles. A recipient may act as processor, independent controller or, in limited circumstances, joint controller depending on its service and legal responsibilities. Appropriate contractual and organisational safeguards are used where required.
7.2 No sale of personal data. The Controller does not sell personal data or disclose it for third-party behavioural advertising. If this practice changes, the Policy and any required choices will be updated before the change takes effect.
8. International transfers
8.1 Transfers outside the EEA. Some providers or their support personnel may process or access personal data outside the European Economic Area. Where GDPR Chapter V applies, transfers rely on an adequacy decision, the European Commission’s Standard Contractual Clauses with supplementary measures where appropriate, another recognised safeguard or a lawful derogation.
8.2 Information. You may request general information about the safeguard relevant to a particular category of transfer by contacting the Provider using the contact details available in the Legal Notice. Commercially sensitive or security information may be redacted where lawful.
9. Retention
| Record | Typical retention |
|---|---|
| Requests not converted to customers | Normally up to 12 months after the last meaningful interaction, unless a shorter period is sufficient or a longer period is needed for a dispute, compliance, fraud prevention or a renewed request. |
| Signed agreements, signature evidence and key contractual communications | Normally 10 years after termination or expiry, or longer where necessary for an active claim, authority request or mandatory limitation period. |
| Billing, tax, invoice and accounting records | For the period required by Italian law, commonly at least 10 years where applicable. |
| Account and access records | For the contract term and normally up to 24 months after closure; essential evidence may be retained with the contract record for longer where necessary. |
| Support communications | For the relationship and normally up to 24 months afterward, unless needed for contract evidence, security, tax, audit or a claim. |
| Security and access logs | For a proportionate period based on log type and risk, normally no longer than 12 months unless an incident, abuse investigation, legal hold or security need requires longer. |
| Alert and integration credentials | Until deleted by the Customer, account closure or the end of the purpose, subject to short backup and security-retention cycles. |
| Cookie and consent records | For the period needed to remember and demonstrate choices, according to the live consent configuration and applicable guidance. |
| Public-ledger source data and analytical history | Potentially for extended periods where necessary to preserve historical research integrity, methodology and public-record analysis, subject to periodic review and applicable rights. |
9.1 Retention criteria. Actual periods may vary according to legal obligations, contractual limitation periods, data volume, sensitivity, security risk, the continuing purpose, backup cycles and whether a dispute or authority request is pending. Data is deleted, anonymised or restricted when no longer required.
10. Cookies and similar technologies
10.1 Necessary technologies. Strictly necessary cookies, local storage and comparable technologies may be used to provide security, authentication, load balancing, session continuity, theme or preference storage, consent records and other functions requested by the user. These are not used for unrelated advertising.
10.2 Analytics. Google Analytics or another non-essential analytics technology may be used to understand aggregate website usage and improve the Services. Where consent is legally required, it must remain disabled until the user makes an affirmative choice. Legitimate interest is not used to bypass a legally required cookie consent.
10.3 Choices. The live cookie banner or preference centre identifies the categories and providers actually enabled and allows consent to be accepted, rejected or changed. Rejecting non-essential technologies must not prevent access to equivalent core website content. Browser controls may also delete or block cookies, but doing so can affect necessary functionality.
10.4 Consistency requirement. The Policy describes intended practice; the live implementation must match it. A technology must not be described as necessary or consent-free unless its actual purpose and configuration satisfy applicable law.
11. Security
11.1 Measures. The Controller uses risk-appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, transport encryption, authentication controls, least-privilege administration, logging, backups, patching, separation of environments and incident procedures.
11.2 Customer security. Customers must protect credentials, password-reset links, Telegram tokens and Slack webhooks, limit recipients and promptly report suspected compromise. No internet-based service can guarantee absolute security.
12. Your rights
12.1 Rights. Subject to the conditions and limitations in applicable law, an individual may request access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent. An individual may also request information about relevant safeguards for international transfers.
12.2 Objection. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. The Controller will stop the processing unless compelling legitimate grounds override the individual’s interests, rights and freedoms, or processing is needed for legal claims.
12.3 Exercising rights. Send a request by contacting the Provider using the contact details available in the Legal Notice and provide enough information to identify the relevant data. Additional information may be requested where reasonably necessary to verify identity and protect against unauthorised disclosure. Responses will be provided within the period required by law.
12.4 Complaint. You may lodge a complaint with the supervisory authority in your habitual residence, place of work or place of the alleged infringement. You are encouraged, but not required, to contact the Provider first.
13. Automated decisions, children and restricted data
13.1 Automated decisions. The Controller does not intentionally make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. Rankings, labels, Alerts and analytics are technical outputs, not decisions about a person’s legal rights or customer eligibility.
13.2 Children. The Services are directed to businesses and professionals, not children. Do not submit a child’s personal data unless you have lawful authority and have contacted the Provider first.
13.3 Sensitive and client data. The Standard Service is not intended for special-category data, criminal-conviction data, confidential customer databases or extensive third-party personal data. A separate assessment and data-processing agreement may be required before any bespoke service involving such data.
14. Changes and contact
14.1 Changes and contact. This Policy may be updated for legal, technical, vendor or operational changes. The current version is published on icterminal.com; material changes may also be notified through the Service or email. Questions, rights requests and label-correction requests may be submitted by contacting the Provider using the contact details available in the Legal Notice.