Legal Documentation

Privacy Policy

How Fomotion B.V. handles your personal data under the GDPR (AVG). Last updated: 31 July 2026

TL;DR - The Quick Version

  • The controller of your personal data is Fomotion B.V. (trading as Blockchain Decoded), based in Groningen, the Netherlands
  • We collect only what's needed to run our crypto analytics service, and each use has a lawful basis under the GDPR
  • We never sell your personal data. We share it only with the processors that make the service work (listed in full below)
  • You can access, correct, delete, export, or object to the use of your data at any time — and withdraw consent for analytics
  • Essential cookies keep the app working; analytics cookies (GA4, Microsoft Clarity) only load if you accept them
  • Questions or a complaint? Email support@blockchaindecoded.com, or contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

1. Who we are (controller)

This Privacy Policy explains how we collect, use, and protect your personal data when you use our crypto analytics platform at blockchaindecoded.com (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR), known in the Netherlands as the Algemene verordening gegevensbescherming (AVG).

The controller (verwerkingsverantwoordelijke) responsible for your personal data is:

Fomotion B.V. (trading as "Blockchain Decoded")
Bottemaheerd 77
9737 NB Groningen
The Netherlands
Chamber of Commerce (KvK): 87420309

2. Personal data we collect

Data you provide

  • Account data: your email address when you create an account (we don't store passwords — you log in via magic email links)
  • Profile data: any optional information you choose to add to your profile
  • Payment data: billing details for paid subscriptions, processed by our payment provider Stripe — we never receive or store full card numbers
  • Communications: the content of support requests or feedback you send us

Data collected automatically

  • Usage data: how you interact with the platform and the features you use
  • Device & connection data: browser type, operating system, and IP address (used for security and rate limiting, and at country/region level for analytics)
  • Cookies: essential cookies for authentication and preferences; analytics cookies only after your consent (see Section 7)

What we DON'T collect

  • We never access your crypto wallets
  • We don't store your private keys
  • We don't collect special categories of data (e.g. biometric data)
  • We don't track you across other websites or use advertising pixels

3. Why we process your data, and our legal basis

Under the GDPR we may only process personal data when we have a lawful basis (Article 6 GDPR). For each purpose, our basis is:

Providing your account and the Service

Basis: performance of a contract (Art. 6(1)(b)). We need your email and usage data to give you access and run the platform.

Processing subscription payments and invoicing

Basis: performance of a contract (Art. 6(1)(b)) and a legal obligation (Art. 6(1)(c)) — Dutch tax law requires us to keep invoice records.

Analytics and product improvement (GA4, Microsoft Clarity)

Basis: your consent (Art. 6(1)(a)). These load only after you accept analytics cookies, and you can withdraw consent at any time.

Security, fraud prevention, and rate limiting

Basis: our legitimate interest (Art. 6(1)(f)) in keeping the Service secure and available.

Responding to support requests

Basis: performance of a contract (Art. 6(1)(b)) or our legitimate interest (Art. 6(1)(f)) in helping our users.

Sending our newsletter (via Beehiiv)

Basis: your consent (Art. 6(1)(a)). Every newsletter includes an unsubscribe link.

  • We never sell or rent your personal data, and we don't share it with third parties for their own marketing
  • Our market data comes from third-party sources; it is informational only and not financial advice

4. Who we share data with (processors)

To run the Service we use a small number of carefully selected processors, each bound by a data-processing agreement and only permitted to use your data on our instructions. Where a processor is located outside the European Economic Area, transfers are covered by an adequacy decision, the EU-US Data Privacy Framework, and/or the European Commission's Standard Contractual Clauses.

ProcessorPurpose
StripePayment processing (iDEAL, credit card, PayPal)
VercelApplication hosting, content delivery, and storage of screenshots you attach to feedback (accessible to anyone with the link)
NeonManaged PostgreSQL database (account and app data)
UpstashRedis for caching and rate limiting
ResendTransactional and account emails
BeehiivNewsletter email (consent-based)
SentryError monitoring to detect and fix bugs
Google Analytics 4Usage analytics (only after consent)
Microsoft ClaritySession replay and UX analytics (only after consent)

We may also disclose data where required by law (for example a valid court order) or to establish, exercise, or defend legal claims.

5. Your rights under the GDPR

You have the following rights over your personal data:

  • Access: ask for a copy of the personal data we hold about you
  • Rectification: have inaccurate or incomplete data corrected
  • Erasure: have your data deleted ("right to be forgotten") — email us and we delete your account and data as described in Section 8
  • Restriction: ask us to limit how we use your data while a request is resolved
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing based on our legitimate interest
  • Withdraw consent: withdraw consent for analytics or the newsletter at any time, without affecting processing already carried out

To exercise any of these rights, email support@blockchaindecoded.com. We respond within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

6. Data Security

We take appropriate technical and organisational measures to protect your data, including:

  • No password storage (authentication via magic email links)
  • Encryption of data in transit (TLS)
  • Encryption of sensitive data at rest
  • Access limited to authorised personnel on a need-to-know basis

No method of transmission over the internet is completely secure. If a personal-data breach is likely to result in a high risk to your rights, we will notify you and the Autoriteit Persoonsgegevens as required by law.

7. Cookies and Tracking

Essential Cookies (always active)

These are required for the Service to function and cannot be switched off:

  • Session cookie: Keeps you signed in
  • Beta access cookie: Remembers early-access status where applicable
  • Consent cookie: Remembers your cookie choice so we don't ask again on every visit

Analytics Cookies (only after consent)

We only load these once you click "Accept" on the cookie banner. If you click "Decline", neither tool loads.

  • Google Analytics 4: Usage analytics — page views, feature usage, and aggregate traffic trends
  • Microsoft Clarity: Session recording and replay, used to understand how visitors use the Service and find UX issues

Your Consent Choice

On your first visit, a banner asks you to Accept or Decline analytics cookies. Your choice is stored for 12 months. You can change it at any time via the "Cookie settings" link in the footer.

We don't use advertising cookies or ad-tracking pixels. You can also disable cookies entirely in your browser, but some features may not work properly.

8. Data Retention

  • Active accounts: we keep your data for as long as your account is active
  • Deleted accounts: your data is deleted within 30 days of your deletion request
  • Invoices and payment records: retained for 7 years, as required by Dutch tax law
  • Anonymised data: we may keep anonymised, aggregated statistics that can no longer identify you

9. International Data Transfers

We are based in the Netherlands and process data primarily within the European Economic Area. Some of our processors (listed in Section 4) are established outside the EEA, mainly in the United States. Where that is the case, the transfer is protected by an EU adequacy decision, the EU-US Data Privacy Framework, and/or the European Commission's Standard Contractual Clauses, so that your data enjoys an equivalent level of protection.

10. Children's Privacy

The Service is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a significant change, we will notify you by:

  • Email to your registered address
  • A notice on the platform
  • Updating the "Last updated" date at the top of this page

We encourage you to review this page periodically to stay informed about how we protect your data.

12. Contact Us

Questions, concerns, or requests about your privacy? We're here to help:

Controller:
Fomotion B.V. (trading as Blockchain Decoded)
Bottemaheerd 77
9737 NB Groningen
The Netherlands
KvK: 87420309

You can also lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

Remember: Blockchain Decoded is a crypto analytics platform. We provide data and insights, NOT financial advice. We don't custody your crypto assets. Your investment decisions are entirely your own responsibility.