Legal

Privacy Policy

What we collect, why, who processes it, how long we keep it, and how to get it removed. Because we compute reputation from public profiles, this page is deliberately explicit.

Last updated: set publication date

Draft — review with counsel before relying on it

A good-faith starting draft reflecting how the platform works — not legal advice. Because you process public-profile data and wallet addresses, have a lawyer confirm your GDPR/CCPA posture, lawful basis, and any data-processing agreements before you rely on this.

1. Who is responsible

Legal entity, jurisdiction("Proof of Audits") is the controller of personal data processed through the Services. Contact: privacy@proofofaudits.com (confirm this inbox is monitored before publishing).

2. The data we process

CategoryExamplesSource
Public auditor dataContest results, accepted findings, severities, placements, payouts, public handle & bioPublic profiles (Code4rena, Sherlock, Cantina, Immunefi, CodeHawks)
Verification dataOne-time bio code, confirmation that the code appeared in your public bioYou (via your public profile)
Account dataEmail, account role, notification preferencesYou
Wallet / on-chain dataConnected wallet address, agreement-signature record, timestampYou (wallet connection)
Protocol submissionsRepository scope, chain details, review evidenceProtocol teams
Usage & device dataConsent choice, page and session activity, Web Vitals, coarse attribution, and security/anti-Sybil device signalsAutomatically, after analytics consent where required

On public data

Auditor scores are computed from information that is already public. Claiming a profile lets you verify and correct what we show — see the methodology and safety statement.

3. Why we process it (purposes & lawful basis)

  • Provide the Services: compute reputation, verify profile ownership, route engagements, publish passports you've agreed to publish.
  • Security & integrity: prevent fraud, Sybil attacks, and abuse.
  • Communication: respond to requests and send opt-in notifications.
  • Legal compliance and enforcing our Terms.

Where GDPR applies, our lawful bases are typically legitimate interests (aggregating public professional reputation, security), consent (opt-in notifications), and contract (delivering an engagement). Confirm bases with counsel.

4. Wallet & on-chain data

Connecting a wallet exposes your public address. If you sign our engagement agreement, we record the address, signature, and timestamp as proof of acceptance. We never request a signature that moves funds, a token approval, a seed phrase, or a private key. On-chain attestations are, by nature, public and permanent — we cannot delete data written to a public blockchain.

5. Sharing & processors

We do not sell personal data. We share it only with:

  • Service providers who process data on our behalf (e.g. hosting, email, and scraping/enrichment infrastructure) under contract. List actual processors — e.g. hosting, email, Firecrawl.
  • Counterparties to an engagement you enter, to the extent needed to deliver it.
  • Authorities where required by law.

6. Retention

We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymize it. State concrete retention periods once decided.

7. Your rights & how to exercise them

You can access, correct, or delete your data, object to or restrict processing, and request a copy of it.

  • Correction / dispute a score: contact us and we'll review and re-score.
  • Deletion: request removal of your profile and associated data; we'll action it (except immutable on-chain records and data we must retain by law).
  • Opt out: notifications are opt-in and you can unsubscribe anytime.

Make a request

Email privacy@proofofaudits.com. We aim to respond within 30 days. If you're in the EU/UK you may also complain to your local data protection authority.

8. Cookies, transfers & changes

  • We use necessary cookies/local storage for sessions and security. If you allow analytics, Amplitude records page, session, Web Vital, and defined product events. We do not send raw wallet addresses, private source, report contents, credentials, signatures, or security findings to Amplitude. Production Session Replay is disabled pending privacy review.
  • Data may be processed in regions/countries; where required we use appropriate safeguards for international transfers.
  • We may update this policy; material changes are posted here with a new "last updated" date.