Data Processing Addendum
This DPA forms part of the Eagle Virtual Terms of Use and applies, without any further signature, whenever Customer Data includes personal data protected by the GDPR, UK GDPR, Swiss FADP, or Brazil’s LGPD. Customers whose procurement process requires a countersigned copy can request one from hello@eaglevirtual.com.
As of 17 August 2026.
1. Definitions
"Customer" means the customer entity under the Agreement. "Customer Personal Data" means personal data contained in Customer Data that Eagle Virtual processes on Customer’s behalf — for example, blockchain addresses, saved-list entries, and labels Customer submits, to the extent they relate to an identified or identifiable natural person.
"Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under the Agreement, including (as applicable) the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, and Brazil’s LGPD. "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914; "UK Addendum" means the UK ICO’s International Data Transfer Addendum to the EU SCCs. "Controller," "processor," "data subject," "personal data," "personal data breach," and "processing" have the meanings given in the GDPR.
2. Roles and scope
For Customer Personal Data, Customer is the controller (or a processor acting for its own controllers, in which case Customer warrants it is authorized to engage Eagle Virtual as a sub-processor) and Eagle Virtual is a processor, processing only as described in Annex A.
Eagle Virtual acts as an independent controller — not as Customer’s processor — for account, billing, support, usage, and security data, and for the public on-chain record it compiles and publishes (see Data we publish).
3. Processing instructions
Eagle Virtual processes Customer Personal Data only on Customer’s documented instructions — the Agreement, Customer’s configuration and use of the service, and this DPA — unless required otherwise by law, in which case Eagle Virtual informs Customer before processing unless the law prohibits it. Eagle Virtual informs Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
Eagle Virtual ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations, and limits access to personnel with an operational need.
5. Security
Eagle Virtual implements and maintains the technical and organizational measures described in Annex B, and may update them provided the updates do not materially reduce the overall level of protection.
6. Subprocessors
Customer generally authorizes the subprocessors listed at /subprocessors, which is incorporated into this DPA as Annex C. Eagle Virtual will update that page before adding or replacing a subprocessor; customers who require advance notice can request it, and may object on reasonable data protection grounds, in which case the parties will work in good faith on a resolution. Eagle Virtual remains responsible for its subprocessors’ performance.
7. Assistance with data subject requests
Taking into account the nature of the processing, Eagle Virtual assists Customer with appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to data subject requests. Requests received directly by Eagle Virtual that concern Customer Personal Data are forwarded to Customer without undue delay.
8. Assistance with security, breach, and impact assessments
Eagle Virtual assists Customer in ensuring compliance with obligations on security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of the processing and the information available to Eagle Virtual.
9. Personal data breach notification
Eagle Virtual notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides information reasonably required for Customer’s own notification obligations as it becomes available.
10. Deletion and return
On termination or expiry of the Agreement, Eagle Virtual deletes Customer Personal Data within 90 days, unless law requires longer storage. Before termination, Customer can export its saved lists through the service. A canceled subscription never deletes a customer’s saved addresses by itself — the account drops to the free tier and the data stays under the customer’s control.
11. Audits and information
Eagle Virtual makes available the information reasonably necessary to demonstrate compliance with this DPA and, where required by Data Protection Laws, allows for and contributes to audits conducted by Customer or its mandated auditor, subject to reasonable notice, confidentiality, and frequency limits.
12. International transfers
EEA transfers: where Customer Personal Data protected by the GDPR is transferred to Eagle Virtual in the United States, the parties enter into the SCCs (Module Two, controller-to-processor), which are incorporated by reference; Annexes I and II are populated by Annex A, Annex B, and the subprocessor page.
UK and Switzerland: transfers from the UK are governed by the SCCs as amended by the UK Addendum; transfers from Switzerland by the SCCs adapted as required by the Swiss FADP.
Brazil: transfers of LGPD-protected data rely on the safeguards in this DPA and applicable ANPD-recognized mechanisms as they become available.
13. LGPD provisions
Where Brazil’s LGPD applies, "controller" and "processor" read as "controlador" and "operador" respectively; Eagle Virtual processes Customer Personal Data only for the purposes described in Annex A, and assists Customer in meeting its LGPD obligations to data subjects and the ANPD.
14. Liability, precedence, and term
Each party’s liability under this DPA is subject to the limitations of liability in the Agreement. If this DPA conflicts with the Agreement, this DPA prevails for the subject matter of the conflict; the SCCs prevail over both where they apply. This DPA remains in force as long as Eagle Virtual processes Customer Personal Data.
Annex A — description of processing
Subject matter: provision of the Eagle Virtual service — checking, saving, and monitoring blockchain addresses against the on-chain record of stablecoin freezes, seizures, and blacklists.
Duration: the term of the Agreement, plus the deletion period in Section 10.
Nature and purpose: hosting, storage, monitoring, export, and related support, as configured by Customer.
Categories of personal data: blockchain addresses and associated on-chain event references; saved-list entries and Customer-assigned labels; identifiers of Customer personnel using the service (name, email, role). No special categories of data are intended or required to be submitted, and Customer agrees not to submit them.
Categories of data subjects: natural persons associated with blockchain addresses Customer checks or saves (for example, Customer’s customers and counterparties), and Customer’s authorized users.
Frequency: continuous, as driven by Customer’s use.
Annex B — technical and organizational measures
Encryption in transit: TLS on all public endpoints, served through Cloudflare’s edge.
Access control: server-side, organization-scoped authorization on every customer data route — a request for another organization’s row answers as not found; least-privilege administrative access; no password database exists — sign-in is federated (OAuth) or one-time links only.
Session security: HttpOnly, Secure, SameSite session cookies; idle-session expiry; state-changing routes accept POST only.
Application security: bot protection and DDoS mitigation at the edge; a published vulnerability-disclosure policy at /security.
Auditability: an append-only audit log of customer data changes; the published event record itself is immutable — corrections are new rows that supersede old ones, never edits.
Infrastructure: production workloads run on Cloudflare’s managed platform (Workers, D1, KV) with the platform’s replication and point-in-time recovery; production and development are separate environments.
Vendor management: subprocessors under written data protection terms; see /subprocessors.
Annex C — subprocessors
The current list of subprocessors, including purpose, processing locations, and transfer mechanisms, is maintained at /subprocessors and is incorporated into this DPA.
Contact
Questions about this DPA, and requests for a countersigned copy: hello@eaglevirtual.com. Data subject requests: legal@eaglevirtual.com.