Data Processing Addendum
Contents
- 1. Application and definitions: who the parties are and when this DPA applies.
- 2. Instructions and Customer responsibilities: Recap processes only on documented instructions; what the Customer must do.
- 3. Confidentiality and security: staff confidentiality and the security measures in Annex 2.
- 4. Rights requests, incidents and assistance: rights requests, breach notification within 48 hours, and assistance.
- 5. Subprocessors: the authorised list, 30 days' notice of changes and the right to object, and how public ledger sources differ.
- 6. International transfers: adequacy decisions, transfer safeguards and how public ledger sources are covered.
- 7. Return and deletion: the 30-day retrieval period and deletion afterwards.
- 8. Demonstrating compliance: information, audits and regulator access.
- 9. Liability, precedence and notices: which liability limits apply and how the documents rank.
- Annex 1: Processing details: subject matter, data categories and data subjects.
- Annex 2: Technical and organisational measures: the security measures Recap maintains.
- Annex 3: Subprocessors and service scope: each subprocessor, its entity, locations and transfer safeguard.
- Annex 4: Public ledger sources: the services Recap queries to read public blockchains, why they are not Subprocessors, and the undertakings Recap gives instead.
1. Application and definitions
This Data Processing Addendum (DPA) forms part of the agreement between Recap Technologies Limited, company number 11218777, of 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ (Recap), and the business customer that holds the Recap team or account, or is identified in an order form (Customer).
The Agreement consists of the Terms of Service, this DPA and any agreed order form and Enterprise Terms. This DPA applies whenever Recap processes personal data on the Customer's behalf in providing the Service, whether the Customer manages its own portfolio or provides services to clients. It continues for as long as Recap holds such data as processor.
Customer Personal Data means personal data processed by Recap on the Customer's behalf under the Agreement. Data Protection Law means the UK GDPR and Data Protection Act 2018, and the EU GDPR and applicable implementing legislation where they apply to the processing. Subprocessor means a processor engaged by Recap to process Customer Personal Data. Controller, processor, personal data, data subject, processing and personal data breach have their meanings under Data Protection Law.
The Customer is controller and Recap is processor for this processing. If the Customer acts as a processor for another controller, the Customer confirms its authority to engage Recap as a subprocessor and pass on lawful instructions. References to the Customer's controller obligations then mean its responsibilities to obtain and implement that controller's instructions and authority.
This DPA does not govern processing for which Recap determines its own purposes, such as its own billing, account administration or legal obligations, described in the Privacy Policy.
2. Instructions and Customer responsibilities
The Customer instructs Recap to provide the Service and perform the processing in Annex 1, including the functions and sharing the Customer or its authorised users request. The Agreement, the Customer's recorded settings and written requests are documented instructions. International processing is subject to section 6.
Recap will process Customer Personal Data only on documented instructions, unless UK law or applicable EU or Member State law requires processing. Recap will tell the Customer about that requirement before processing unless that law prohibits it on important public-interest grounds. Recap will immediately inform the Customer if it considers an instruction infringes Data Protection Law and may pause that instruction while the issue is resolved.
The Customer is responsible for lawful collection and disclosure, appropriate privacy information, the rights of data subjects and any additional condition required for sensitive information. It will provide only information needed for the requested Service and control access by its users. This does not reduce Recap's own legal obligations.
The Customer's instructions do not permit Recap to sell Customer Personal Data, use it for advertising, train AI models on it or develop products from it for Recap's own purposes. Subprocessors listed in Annex 3 may use AI features within their own services to provide support or diagnostics, subject to this DPA. Recap uses Amazon Bedrock, an AWS service run within UK and EU regions with no model training on the content, to classify product feedback that users choose to submit; feedback is Recap's own processing and users must not include Customer Personal Data in it. The Customer instructs Recap to produce aggregated statistics that identify no individual or Customer for operating, securing and pricing the Service.
3. Confidentiality and security
Recap will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty, and access is limited to their work.
Recap will implement the technical and organisational measures in Annex 2 and any additional measures expressly agreed in the order form. It will maintain security appropriate to the risks under Article 32, including confidentiality, integrity, availability and resilience, taking account of the nature of the data and processing.
Recap may improve or replace particular measures without materially reducing the overall protection of Customer Personal Data. A specific additional commitment agreed in an order form may be varied only as that agreement permits.
4. Rights requests, incidents and assistance
Recap will promptly notify the Customer of a rights request concerning Customer Personal Data and assist it through appropriate technical and organisational measures, taking account of the processing. Recap will not answer on the Customer's behalf without authorisation, except to acknowledge or redirect the request, or where law requires a response.
Recap will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Recap will not delay an initial notification to establish all the facts. Recap will provide information as it becomes available about the affected data and individuals, likely consequences, response measures and a contact for follow-up, and assist with investigation, containment and notifications. A notification is not an admission of liability.
Taking account of the processing and information available, Recap will assist with the Customer's obligations under Articles 32 to 36, including security, breach notifications, data protection impact assessments and prior consultation with a supervisory authority.
Routine assistance is included in the fees. For substantial additional work, Recap may propose reasonable charges in advance, except for work needed to remedy its own breach. A disagreement about charges will not delay assistance required to meet a legal deadline or relieve Recap of its mandatory obligations.
Recap cannot produce readable copies of portfolio contents merely from the ciphertext it stores. The Customer must retain the necessary keys and use the app or an authorised sharing arrangement where assistance requires readable contents.
5. Subprocessors
The Customer gives general written authorisation for the Subprocessors identified in Annex 3, for the functions described there. Recap will give at least 30 days' written notice before adding or replacing a Subprocessor, including the function and information reasonably needed to assess the change. Recap will give that notice by email to the Customer's designated privacy contact or, if none, to its team administrators, and by updating the list at recap.io/legal/dpa. Where a Subprocessor must be replaced urgently to protect Customer Personal Data or maintain the Service, Recap may do so and will give notice as soon as practicable; the objection right then applies from that notice.
The Customer may object during that period on reasonable data protection grounds. The parties will work to address the concern, including an alternative where reasonably available. Recap will not disclose the affected data to the proposed Subprocessor while a timely objection remains unresolved. If no reasonable solution is available, either party may end the affected Service before the change takes effect, and Recap will refund prepaid fees for the unused part.
Recap will engage each Subprocessor under a written agreement imposing data protection obligations that are in substance no less protective than those in this DPA, including sufficient guarantees of appropriate security. Recap remains responsible to the Customer for its Subprocessors' performance of those obligations.
An independent controller is not a Subprocessor for its own processing. A disclosure to an independent controller requires an appropriate instruction or other lawful authority and transparent identification of that recipient's role.
Public ledger sources. To retrieve blockchain records, Recap queries the node and index services listed in Annex 4. Each builds and operates its own index of a public blockchain, serves the same records to any subscriber and determines its own purposes, means and retention. They are consulted as anyone consults a public source: they are independent controllers of those services, they are not Subprocessors, and Recap does not appoint them under a data processing agreement. Recap sends them only blockchain identifiers (a wallet address, a transaction reference, the contract address of a token or NFT so that the asset can be identified or, for a Bitcoin account added that way, the extended public key the Customer supplied) with the parameters needed for retrieval, from Recap's own infrastructure, one wallet address per request; contract addresses may be sent together. Recap does not send the Customer's name, email address, account or portfolio identifiers, credentials or IP address, or anything else that would let a source connect an identifier to a person. The association between identifiers and the Customer's users exists only within encrypted portfolios and Recap's own systems, protected as Annex 2 describes. Recap has assessed that these lookups do not disclose Customer Personal Data to the source; its written assessment is available on request. The Customer instructs Recap to retrieve blockchain records in this way. Wallet screening through HopTrail, and any supplier that processes Customer Personal Data on the Customer's behalf, is a Subprocessor under this section and Annex 3.
Exchange and broker connections. On the Customer's instruction, Recap retrieves records from exchanges and brokers using the access the Customer or its user authorises for an account held there, whether an API key, an authorisation granted through the service's own login, or another credential the service supports. Those services are independent controllers of the accounts they hold; Recap does not appoint them and they are not Subprocessors. Recap sends a service only the credential or authorisation it issued, the parameters needed to retrieve records, the address of the infrastructure or, for a few connections, the browser making the request, and, where a service requires it to match its own customer, the account identifier or email address held with that service. The Customer instructs Recap to retrieve records in this way. Each service's own terms and privacy notice govern its processing of the account.
6. International transfers
Recap will make restricted international transfers of Customer Personal Data only with the Customer's documented authorisation and in accordance with Data Protection Law. Authorisation for an identified supplier covers the processing locations and transfer arrangements disclosed to the Customer, not undisclosed onward processing.
Recap will ensure an applicable adequacy decision or appropriate safeguards are in place. Safeguards may include the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (the UK Addendum), or EU Standard Contractual Clauses where EU GDPR applies. Recap will carry out required transfer assessments and implement additional measures where needed. Any exceptional transfer must satisfy a legally available derogation and the Customer's instructions.
The lookups described in section 5 and Annex 4 are not restricted transfers of Customer Personal Data, on the assessment stated there. Exchange and broker connections described in section 5 send a service only what it issued or requires to recognise its own customer, on the Customer's instruction, and are not treated as restricted transfers of Customer Personal Data. This section applies to every other disclosure of Customer Personal Data outside the United Kingdom, including instructed screening should any of it be processed outside the United Kingdom. Neither the Customer's instructions nor this DPA authorises such a transfer without a lawful basis under the applicable transfer rules.
Before making such a restricted transfer, Recap must confirm the recipient, processing locations and applicable transfer mechanism, complete any required assessment and document the arrangement for the Customer. If a lawful arrangement cannot be established or ceases to apply, Recap will reroute or suspend the affected processing and notify the Customer. If no reasonable alternative is available, either party may end the affected Service and Recap will refund prepaid fees for its unused part.
Recap will make relevant information about recipients, countries, safeguards and onward transfers available to the Customer, and a summary of its transfer assessments on request. Where transfer clauses apply, they prevail over conflicting provisions of the Agreement.
7. Return and deletion
When the relevant processing Service ends (a free account or another active Service continues the processing it covers), Recap will, at the Customer's choice, return or securely delete Customer Personal Data and delete existing copies, unless UK law or applicable EU or Member State law requires storage. The Customer may give a deletion instruction earlier through the app or in writing. An express instruction for earlier deletion takes priority over a retrieval period.
Readable exports and reports are available in the app while the Service is active, and the Customer is responsible for exporting what it needs before the Service ends; Recap cannot produce readable exports afterwards. Unless otherwise agreed or the Customer requests earlier deletion, the Customer has 30 days after that processing Service ends to instruct return of the data Recap holds. This period is limited to return and closure, not continued use of paid features. After it expires, the Customer instructs Recap to delete data that has not already been returned and deleted.
Return includes readable data that Recap can access and encrypted portfolio data in the form Recap holds it. Readable portfolio export requires the Customer's keys. Recap will not withhold return solely over a disputed fee. Any legally necessary access restriction must be limited to what is required, with a safe alternative offered where possible.
Recap will put data awaiting deletion from protected backups beyond ordinary use, delete it through the applicable replacement cycle and re-delete it if restored. Recap will explain that cycle on request and confirm completion of deletion on written request. Legally required retained copies will be segregated or access-restricted and used only for the required purpose.
8. Demonstrating compliance
Recap will make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits and inspections by the Customer or its appointed independent auditor.
The parties will first use relevant documentation and remote review where these adequately address the request. Routine inspections require reasonable notice, confidentiality safeguards, normal business hours and measures to protect other customers' data and avoid unnecessary disruption. They will normally take place no more than once in 12 months.
Those routine arrangements do not restrict an audit required by law, by a supervisory authority or by a financial services regulator or another regulator with authority over the Customer, an audit following an affected personal data breach, or one where substantiated concerns reasonably require further investigation. Recap will cooperate with competent supervisory authorities and will give such a regulator the access and information it is entitled to require. Recap will provide a completed security questionnaire on request under confidentiality. The Customer bears its auditor's costs; any additional charges by Recap follow section 4 and may not frustrate the audit right.
9. Liability, precedence and notices
Liability between Recap and the Customer is governed by section 12 of the Terms of Service, as expressly varied by an applicable enterprise order form and Enterprise Terms. The higher annual limit in that section applies to claims arising from (a) Recap's breach of the confidentiality obligations in the Terms, (b) a personal data breach caused by Recap's breach of section 3, 4 or 5 of this DPA, or (c) processing of Customer Personal Data by Recap contrary to section 2. Other claims, including loss or unavailability of data caused by a fault in the Service, are ordinary claims. Within the higher limit, and to the extent caused by that breach, the Customer may recover as direct loss compensation it pays to data subjects, reasonable costs of notifying data subjects and regulators, investigation and remediation, and any regulatory fine or penalty to the extent the law allows its recovery. Any claim between the parties under Article 82(5) is subject to these limits so far as the law permits. This DPA does not create an additional liability allowance, and the same loss cannot be recovered twice under the Terms, this DPA, an order form, transfer clauses or statute. Nothing here restricts individuals' rights under Article 82, supervisory authorities' powers or liability that cannot lawfully be limited.
This DPA prevails over other terms on the processing and protection of Customer Personal Data, subject to mandatory transfer clauses and to the commercial liability limits described above. No variation may reduce mandatory data protection obligations.
English law governs this DPA and the courts of England and Wales have exclusive jurisdiction between the parties, without limiting mandatory transfer clauses or data subjects' rights. It is binding through the Agreement without a separate signature; signed copies are available on request.
Send notices to dataprotection@recap.io, or Recap's registered address in section 1. Recap will use the Customer's designated privacy or security contact, or its account contact if none is provided. The Customer must keep those details current.
Annex 1: Processing details
| Item | Description |
|---|---|
| Subject matter | Providing portfolio, transaction, tax reporting, sharing and requested screening functions to the Customer, for cryptoassets, stocks and shares and other chargeable assets the Customer puts through the Service. |
| Purpose | Enable the Customer to manage its own records or provide authorised services to clients, and provide necessary support and diagnostics on its instructions. |
| Duration | While providing the relevant processing Service, followed by return/deletion under section 7. |
| Nature of processing | Receive and transmit import requests and responses; store and transmit encrypted portfolios; administer instructed access and sharing; retrieve blockchain, exchange and market-data information; identify assets and obtain prices and FX rates; obtain and retain requested screening results; support, export and delete information on instructions. Calculations and much portfolio processing run in the user's browser. |
| Data subjects | The Customer's clients and prospective clients, individuals represented in portfolios or transaction information, authorised users to the extent their information is processed on the Customer's behalf, and other people whose information the Customer lawfully provides. |
| Data categories | Contact or identifying information included in Customer data; wallet addresses and transaction references; exchange and broker credentials and authorisations used for instructed imports, stored within the encrypted portfolio and handled in readable form transiently while a request is made, together with limited connection records that Recap keeps for a bounded period to secure the connection and prevent misuse of an authorisation; transaction histories, amounts, balances and tax information; notes and uploaded records; instructed access information; support materials and relevant technical diagnostics. |
| Criminal offence data | Requested screening may involve information relating to actual or alleged offences or related security measures, including information about counterparties. |
| Special category data | Not required for normal portfolio functions. The Customer must avoid unnecessary special category information in notes or uploads and agree appropriate instructions and safeguards before intentionally using the Service for it. |
For screening, the Customer determines the purpose and its applicable Article 6 basis and Article 10/Schedule 1 condition. It must maintain an appropriate policy document where its condition requires one. Recap will assist with safeguards under this DPA and does not use the results for its own purposes. Recap stores screening results without any link to the requesting user or team. The Customer must supply the screening reference held in its portfolio for any request concerning them; Recap cannot locate results by name or address.
Annex 2: Technical and organisational measures
Recap will maintain the following measures for Customer Personal Data:
- Portfolio encryption: encryption of stored portfolio contents on the user's device using AES-GCM (256-bit keys for current data; a small amount of older data uses 128-bit keys pending migration); encrypted key sharing for authorised access. Recap stores only a fingerprint of the secret and key material encrypted under keys derived from it, never the secret phrase itself, and cannot escrow or recover keys. Optional support sharing gives designated staff read access to a selected portfolio. Disabling the team's support-sharing arrangement revokes support access to all portfolios shared through it.
- Separate processing safeguards: protect readable connection, screening, metadata and diagnostic information with controls appropriate to that information. Exchange credentials and retrieved transaction data pass through Recap's services and are not stored; address lookups are recorded without any link to a user, team or portfolio; request logs carry no user identity, IP address or browser details on address-bearing requests; and chain-data caches are keyed by address only and expire within an hour. Screening results are stored without any link to the requesting user or team.
- Access control: authenticated access, role and permission checks, least-privilege staff access, review of access and removal when no longer required. Protect privileged access and separate customer access through application authorisation and encryption.
- Transport and infrastructure: TLS for all customer connections; application services, databases and caches in private subnets of Recap's AWS network; the exchange-connection proxy in a separate network with TLS-only ingress and its own egress addresses; controlled network access to infrastructure, managed hosting in AWS London and protection of credentials.
- Development and maintenance: review changes, apply security updates according to risk and assess vulnerabilities. Test and evaluate safeguards at intervals appropriate to the risks.
- Personnel: confidentiality obligations, relevant security instruction and access limited to authorised work.
- Monitoring and response: security and operational monitoring, proportionate logging, investigation and incident response, with breach notification under section 4.
- Continuity: maintain backup and recovery arrangements appropriate to the Service and test restoration at intervals appropriate to the risk. Backups of encrypted data do not recover lost customer encryption keys.
- Disposal: implement customer deletion instructions in the systems Recap operates and instruct Subprocessors that hold Customer Personal Data on Recap's behalf to delete it, or rely on their disclosed retention period, with protected backup handling and confirmation under section 7.
Additional hosting restrictions, certifications, test frequency, recovery objectives or security reporting commitments apply only where expressly agreed in an order form or attached security schedule.
Annex 3: Subprocessors and service scope
The Customer authorises the Subprocessors, processing locations and transfer safeguards listed below. Where a supplier processes outside the UK, Recap relies on the safeguard shown. Recap will keep this list current under section 5.
| Service | Legal entity | Function and Customer Personal Data | Processing locations | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (the AWS contracting party for account countries in Europe, the Middle East and Africa, which includes the UK) | Infrastructure, delivery and storage: encrypted portfolios and relevant readable import, screening, metadata and technical information, within UK and EU regions. Recap also runs Amazon Bedrock in the same AWS account to classify submitted product feedback. That is Recap's own controller processing under section 2, not Customer Personal Data, and is named here only so the Customer can see everything Recap sends to AWS. | United Kingdom: the Europe (London) region, whose infrastructure entity is Amazon Data Services UK Limited. Amazon Bedrock inference is restricted to European regions (Ireland, Frankfurt, Paris, Stockholm, Milan, Spain and London). AWS support entities outside the UK, including in the United States and India, process data only if Recap shares it when requesting support. | No restricted transfer for processing within the United Kingdom. For any transfer outside the UK, the AWS UK GDPR Addendum forms part of the AWS Service Terms and applies automatically, incorporating the EU Standard Contractual Clauses as amended by the UK Addendum. |
| Auth0 / Okta | Okta, Inc., 100 First Street, San Francisco, California 94105, United States | Authentication and access services, to the extent processing instructed user-access information on the Customer's behalf. | European Union: Recap's tenant is in the Auth0 public cloud EU region. Okta's published Auth0 subprocessors place business analytics, support ticketing, email and SMS in the United States, the data warehouse in Germany, the 24-hour support team in Romania and the content delivery network globally. | EU Standard Contractual Clauses as amended by the UK Addendum, under Annex IV of Okta's Data Processing Addendum, which Recap has executed. |
| Intercom | Intercom R&D Unlimited Company, 124 St Stephen's Green, Dublin 2, D02 C628, Ireland | Support for Customer processing: messages, attachments and relevant diagnostic or account context submitted for that purpose. | Ireland for the contracting entity; United States for the processing, which is Intercom's default region and the region Recap's account uses. | UK adequacy for Ireland. For the United States, the UK Extension to the EU-US Data Privacy Framework, under Intercom, Inc.'s certification, with the EU Standard Contractual Clauses as amended by the UK Addendum incorporated as the fallback. |
| Sentry | Functional Software, Inc. trading as Sentry, 45 Fremont Street, 8th Floor, San Francisco, California 94105, United States | Diagnostics needed to provide and support the Service: technical data, user identifiers and email address, and relevant error context, which may include wallet or transaction information. | United States: Recap sends events to Sentry's US ingest endpoint. Sentry's affiliates in Austria and Canada provide parts of the service and technical support. | The UK Extension to the EU-US Data Privacy Framework, with the EU Standard Contractual Clauses as amended by the UK Addendum as the fallback, both under Sentry's Data Processing Addendum, which Recap has accepted. |
| Postmark (an ActiveCampaign company) | AC PM, LLC, United States | Delivery of Customer-instructed invitations and communications, including recipient details and message contents. | United States only: a data centre near Chicago and Amazon Web Services. Postmark publishes no EU region. | The UK Extension to the EU-US Data Privacy Framework, under ActiveCampaign, LLC's certification, which covers AC PM LLC, with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum incorporated where required. |
| HopTrail | Hoptrail Limited, registered in England and Wales, company number 13691065, 10 John Street, London, WC1N 2EB | Instructed wallet screening for Recap for Professionals: submitted addresses and related identifiers, logs and resulting risk scores, flags and metadata. The signed supplier agreement dated December 2025 includes a Data Protection Schedule appointing HopTrail as Subprocessor for this processing. Recap does not send customer names, emails or Recap account identifiers with a screening request. | United Kingdom. HopTrail has confirmed that the processing it performs for Recap is hosted in AWS Europe (London), region eu-west-2. Hoptrail Limited is the UK contracting entity. HopTrail's further subprocessors for this processing, and any staff or support access outside the United Kingdom, have not been listed to Recap. | No restricted transfer for hosting in the United Kingdom. The Data Protection Schedule requires appropriate safeguards if HopTrail transfers Customer Personal Data outside the UK; any such transfer, including AWS support access from outside the UK, must use a mechanism that satisfies section 6 before it takes place. |
A provider used only for Recap's own billing, marketing or controller analytics is not authorised to receive Customer Personal Data by virtue of that separate role. Recap has accepted supplier data-processing terms with Stripe, Vercel, PostHog, Trustpilot and Tolt for that Recap-controlled processing. Those acceptances do not make them Subprocessors of Customer Personal Data. Any further supplier that Recap engages to process Customer Personal Data on its behalf must be identified and authorised under section 5 before use.
HopTrail processes instructed screening under the Data Protection Schedule to its agreement with Recap (signed December 2025). That schedule requires documented instructions, confidentiality, appropriate security, rights-request assistance, breach notification without undue delay, deletion or return and audit access. It prohibits unrelated use of personal data received through the API and identifiable profiles for independent commercial exploitation unless expressly authorised in writing by Recap and the relevant controller or required by law. It permits retention and use of aggregated, irreversibly anonymised data to improve its services and risk models. This does not permit retaining identifiable wallet-level queries as anonymous statistics. HopTrail acts separately as an independent controller for its own business-contact, billing and revenue-share records. Its own intelligence datasets must be assessed separately from instructed screening; the contractual label does not determine the role of any activity outside those instructions. HopTrail's confirmation of AWS eu-west-2 covers primary hosting. Recap will treat a new HopTrail subprocessor that HopTrail notifies to Recap, or processing outside the United Kingdom, as a change under sections 5 and 6, and is seeking an express notice-and-objection term from HopTrail for such changes.
Annex 4: Public ledger sources
Section 5 sets out Recap's position on the services below: they are independent controllers of the public-ledger indexes they operate, are consulted as anyone consults a public source, and are not Subprocessors. Recap sends them only blockchain identifiers with retrieval parameters, from its own infrastructure, one wallet address per request, with nothing that could associate a request with the Customer, a user or another request. Recap has assessed that these requests do not disclose Customer Personal Data; its written assessment is available on request. A source's own privacy notice or terms governs that source's own processing; none of these services is appointed under a data processing agreement.
| Source | Legal entity | Location | What it receives | Published retention of query data |
|---|---|---|---|---|
| Moralis | Moralis Web3 Technology AB, organisation number 559307-5988, Sweden | Sweden; Moralis states that its own subprocessors are located globally | Wallet and contract addresses and transaction references. The archive RPC source for PulseChain. | Not published. Recap has also accepted Moralis's published data processing agreement, which applies to any processing Moralis performs on Recap's behalf. |
| QuickNode | QuikNode, Inc., 1010 South Federal Highway, Suite 1102, Hallandale, FL 33009, United States | Anycast infrastructure in the United States, United Kingdom, Netherlands, Germany, Singapore, Japan and Malaysia; requests route to the nearest region | Wallet addresses, token contract addresses and transaction references; for a Bitcoin account added by extended public key, that key | Request payloads logged only for send-transaction requests and errors, kept about one day, and not used to build profiles (QuickNode statement to Recap, 14 September 2026) |
| Etherscan | Operator not named in its published terms; API terms governed by the law of Singapore | Not published | Wallet addresses and transaction references, with Recap's server IP address | Inactive personal data purged within 24 months; raw server logs kept for at least five days (Etherscan privacy policy, 7 May 2025) |
| Helius | Helius Blockchain Technologies Inc., 2093 Philadelphia Pike PMB 7808, Claymont, DE 19703, United States | United States | Solana wallet addresses and transaction references | RPC method data retained for up to 20 weeks (Helius privacy policy, 13 March 2024) |
| PulseChain community endpoints (rpc.pulsechain.com and api.scan.pulsechain.com) | No published operator | Not published | PulseChain wallet addresses and transaction references, with no API key | Not published |
Recap's undertakings. For every source in this annex, Recap will:
- send only a wallet address, a transaction reference, the contract address of a token or NFT or, for a Bitcoin account added that way, the extended public key the Customer supplied, and never the identity of the Customer, its users or a portfolio, or any account, billing, contact or credential information;
- send requests from its own infrastructure, one wallet address per request, without batching or labelling a Customer's wallet addresses; token and NFT contract addresses may be batched to identify assets. The extended public key is the exception, because the addresses derived from it are what it is for; the Customer can add a Bitcoin account by address list instead;
- keep this annex current at recap.io/legal/dpa and tell the Customer's designated privacy contact when a source is added or replaced. The notice and objection process in section 5 does not apply to these sources;
- provide its written assessment and relevant information about each source on request. Customer-specific choices of source are not currently available.
Exchanges and brokers the Customer connects are covered by section 5 and are not listed individually: the Customer chooses them, holds the account with them and authorises the access. HopTrail is a Subprocessor and appears in Annex 3.