This privacy notice explains how the Blockcontrol website handles personal data when you browse the site, contact us or submit an IBDCP business-case assessment. The design principle is simple: collect what is needed to make a business decision, keep sensitive data out of unnecessary systems and preserve accountability for the information that is used.
1. Controller
The controller responsible for this website is Dean Rakic / Blockcontrol, Landhausstr. 63B, 70190 Stuttgart, Germany. Privacy enquiries can be submitted through the verified Privacy contact route, which is delivered server-side to privacy@ibdcp.blockcontrol.com only after sender verification.
2. Data we may process
Depending on how you use the site, we may process:
- contact information such as name, work email, organisation and information you include in correspondence;
- business-case information such as the outcome you want, the process where trust breaks down, current impact and the system categories involved;
- technical server information that may be generated by the hosting environment, such as IP address, timestamp, requested page, browser/user-agent and security-relevant log events;
- communication metadata generated by your and our email providers when you contact Blockcontrol.
Please do not submit passwords, seed phrases, private keys, raw KYC files, medical records, payment-card data or other unnecessary sensitive information through the assessment form.
3. Why we use this data
We use personal data to respond to enquiries, evaluate requested services or collaborations, prepare an executive assessment, maintain website and information security, establish or perform pre-contractual/commercial relationships, meet legal obligations and protect legitimate business interests.
Where GDPR applies, the legal basis may include steps taken at your request before entering a contract (Art. 6(1)(b) GDPR), legitimate interests in business communication and security (Art. 6(1)(f)), compliance with legal obligations (Art. 6(1)(c)), or consent where it is specifically requested (Art. 6(1)(a)).
4. What the “Assess Your Business Case” form does
The “Assess Your Business Case” form submits the minimum required assessment data to the same-origin /api/contact endpoint on ibdcp.blockcontrol.com. The service validates a signed browser challenge and sends a one-time verification link to the work email supplied by the visitor. The request is held temporarily in encrypted pending storage and is not forwarded to Blockcontrol until the sender explicitly verifies the email address. After verified delivery, the temporary pending record is removed; expired unverified requests are automatically deleted.
The assessment information is used to understand commercial fit, architecture fit and the smallest proof path. Submitting an assessment does not create a binding contract, does not constitute a token or investment order and does not automatically create an IBDCP ledger record.
5. IBDCP privacy principle
IBDCP is designed around minimum necessary data with maximum verifiability. Sensitive personal or regulated source material should generally remain in the appropriate authoritative domain. Where a deployment requires cross-system proof, the architecture can use cryptographic digests, issuer references, status, policy evidence and selective disclosure rather than copying unnecessary personal data into a shared ledger or interoperability layer.
6. Recipients, processors and hosting
Data may be processed by service providers that support hosting, infrastructure, email, security, professional advice or other business operations, but only to the extent needed for the relevant purpose and subject to appropriate contractual or legal safeguards. Data may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.
7. Retention
Unverified contact and assessment submissions are held only as short-lived encrypted pending records and expire automatically if the sender does not verify the email address within the configured verification window (30 minutes in the supplied production configuration). After verified delivery, the pending record is deleted. Delivered business correspondence may then be retained only for as long as reasonably necessary to evaluate and manage the relationship, document decisions, comply with legal/accounting obligations or establish and defend claims. Security logs are retained according to the hosting and security configuration and should be limited to a justified operational period.
8. Security
The website package is designed to minimise browser-side attack surface: local assets, restrictive content-security policy, no third-party advertising scripts, no iframes and a single documented same-origin assessment endpoint with server-side validation and rate limiting. Production hosting should additionally enforce HTTPS/TLS, secure headers, access control, patching, backups, monitoring and incident response.
IBDCP deployments require a broader security model, including zero-trust identities, least privilege, protected key custody, signed evidence, encryption, tamper-evident logs, rate limiting, change control and recovery/key-rotation procedures. See the Security page.
9. Your data-protection rights
Where GDPR or similar law applies, you may have rights to access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. You may also have the right to lodge a complaint with a competent data-protection supervisory authority.
To exercise a privacy right, use the verified Privacy contact route and provide enough information for us to identify the relevant relationship or correspondence.
10. Cookies, analytics and tracking
The supplied website build does not require advertising trackers or third-party analytics to function. Essential hosting or security technology may still process technical request data. If a production deployment later adds analytics, marketing pixels, consent-management tools or non-essential cookies, this notice and the applicable consent controls should be updated before those tools are activated.
11. External websites and built cases
The site links to separate Blockcontrol-related or third-party deployments such as the IBDCP Wallet, eKarton.io, aicrm_ibdcp, RWAT and Bedora. Those sites may have their own controllers, terms, privacy notices, cookies and security configurations. Their notices apply when you visit them.
12. Changes and contact
This notice may be updated when the website, hosting model, form delivery, analytics, legal requirements or IBDCP service model changes. The current version date is shown at the top of this page.
Privacy requests use the verified Privacy route. General commercial requests use the verified Contact page.
