Blockcontrol logoBLOCKCONTROLIBDCP
Built CasesSecurityContactAssess Business Case →
Privacy

Minimum necessary data. Maximum accountability.

Privacy should not be a compliance appendix. It should be visible in the architecture. This notice explains what the website processes and how the same data-minimisation principle carries into IBDCP deployments.

Last updated: 30 August 2026 · Blockcontrol / IBDCP
At a glance

What you should know before sending a business case.

  • The website does not need confidential production data to assess fit.
  • Sensitive data should remain in its authoritative domain wherever possible.
  • The assessment and Contact forms use a same-origin verified mail service; unverified submissions are not delivered to Blockcontrol.
  • IBDCP evidence can be verifiable without making personal data public.
On this pageControllerData we processPurposes & legal basesBusiness case formIBDCP privacy principleRecipients & processorsRetentionSecurityYour rightsCookies & trackersExternal linksContact

This privacy notice explains how the Blockcontrol website handles personal data when you browse the site, contact us or submit an IBDCP business-case assessment. The design principle is simple: collect what is needed to make a business decision, keep sensitive data out of unnecessary systems and preserve accountability for the information that is used.

1. Controller

The controller responsible for this website is Dean Rakic / Blockcontrol, Landhausstr. 63B, 70190 Stuttgart, Germany. Privacy enquiries can be submitted through the verified Privacy contact route, which is delivered server-side to privacy@ibdcp.blockcontrol.com only after sender verification.

Decision principle: Blockcontrol does not need confidential datasets, private keys or production credentials to evaluate whether an IBDCP business case is worth pursuing.

2. Data we may process

Depending on how you use the site, we may process:

  • contact information such as name, work email, organisation and information you include in correspondence;
  • business-case information such as the outcome you want, the process where trust breaks down, current impact and the system categories involved;
  • technical server information that may be generated by the hosting environment, such as IP address, timestamp, requested page, browser/user-agent and security-relevant log events;
  • communication metadata generated by your and our email providers when you contact Blockcontrol.

Please do not submit passwords, seed phrases, private keys, raw KYC files, medical records, payment-card data or other unnecessary sensitive information through the assessment form.

3. Why we use this data

We use personal data to respond to enquiries, evaluate requested services or collaborations, prepare an executive assessment, maintain website and information security, establish or perform pre-contractual/commercial relationships, meet legal obligations and protect legitimate business interests.

Where GDPR applies, the legal basis may include steps taken at your request before entering a contract (Art. 6(1)(b) GDPR), legitimate interests in business communication and security (Art. 6(1)(f)), compliance with legal obligations (Art. 6(1)(c)), or consent where it is specifically requested (Art. 6(1)(a)).

4. What the “Assess Your Business Case” form does

The “Assess Your Business Case” form submits the minimum required assessment data to the same-origin /api/contact endpoint on ibdcp.blockcontrol.com. The service validates a signed browser challenge and sends a one-time verification link to the work email supplied by the visitor. The request is held temporarily in encrypted pending storage and is not forwarded to Blockcontrol until the sender explicitly verifies the email address. After verified delivery, the temporary pending record is removed; expired unverified requests are automatically deleted.

The assessment information is used to understand commercial fit, architecture fit and the smallest proof path. Submitting an assessment does not create a binding contract, does not constitute a token or investment order and does not automatically create an IBDCP ledger record.

5. IBDCP privacy principle

IBDCP is designed around minimum necessary data with maximum verifiability. Sensitive personal or regulated source material should generally remain in the appropriate authoritative domain. Where a deployment requires cross-system proof, the architecture can use cryptographic digests, issuer references, status, policy evidence and selective disclosure rather than copying unnecessary personal data into a shared ledger or interoperability layer.

Important: “Verifiable” does not mean “public.” A production IBDCP deployment must define what data remains private, what evidence is shared, who is authorised to see it and which jurisdictional rules apply.

6. Recipients, processors and hosting

Data may be processed by service providers that support hosting, infrastructure, email, security, professional advice or other business operations, but only to the extent needed for the relevant purpose and subject to appropriate contractual or legal safeguards. Data may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.

7. Retention

Unverified contact and assessment submissions are held only as short-lived encrypted pending records and expire automatically if the sender does not verify the email address within the configured verification window (30 minutes in the supplied production configuration). After verified delivery, the pending record is deleted. Delivered business correspondence may then be retained only for as long as reasonably necessary to evaluate and manage the relationship, document decisions, comply with legal/accounting obligations or establish and defend claims. Security logs are retained according to the hosting and security configuration and should be limited to a justified operational period.

8. Security

The website package is designed to minimise browser-side attack surface: local assets, restrictive content-security policy, no third-party advertising scripts, no iframes and a single documented same-origin assessment endpoint with server-side validation and rate limiting. Production hosting should additionally enforce HTTPS/TLS, secure headers, access control, patching, backups, monitoring and incident response.

IBDCP deployments require a broader security model, including zero-trust identities, least privilege, protected key custody, signed evidence, encryption, tamper-evident logs, rate limiting, change control and recovery/key-rotation procedures. See the Security page.

9. Your data-protection rights

Where GDPR or similar law applies, you may have rights to access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. You may also have the right to lodge a complaint with a competent data-protection supervisory authority.

To exercise a privacy right, use the verified Privacy contact route and provide enough information for us to identify the relevant relationship or correspondence.

10. Cookies, analytics and tracking

The supplied website build does not require advertising trackers or third-party analytics to function. Essential hosting or security technology may still process technical request data. If a production deployment later adds analytics, marketing pixels, consent-management tools or non-essential cookies, this notice and the applicable consent controls should be updated before those tools are activated.

11. External websites and built cases

The site links to separate Blockcontrol-related or third-party deployments such as the IBDCP Wallet, eKarton.io, aicrm_ibdcp, RWAT and Bedora. Those sites may have their own controllers, terms, privacy notices, cookies and security configurations. Their notices apply when you visit them.

12. Changes and contact

This notice may be updated when the website, hosting model, form delivery, analytics, legal requirements or IBDCP service model changes. The current version date is shown at the top of this page.

Privacy requests use the verified Privacy route. General commercial requests use the verified Contact page.

© 2026 Blockcontrol / IBDCP. All rights reserved.
HomePrivacyTerms of UseSecurityContact