Enterprise Data Privacy & Compliance FAQ

What Addressable does

What is Addressable, and what does the tag do?

Addressable helps you understand who your users are and enrich what you know about them. Our crypto identity graph recognises high-value users and adds context from their first visit. The tag is a super-lightweight snippet that reads one piece of information: the Addressable ID — the lightest footprint for the understanding it delivers.

Why put a tag on our site — what do we get?

It turns unrecognized traffic into understood users: you see who your most valuable users are early and enrich your own view of them, without expanding your data exposure.

Is this an invasive tracker?

No. It reads only one piece of information: the Addressable ID, and any optional custom properties you define. It never touches names, emails, or contact details. Minimal data, maximum understanding.

What the tag collects — and what it never touches

Exactly what does the tag collect?

An incredibly short list of just one piece of information: the Addressable ID.

What does it never collect?

It collects nothing else under the sun, including names, email addresses, contact details, home addresses, national IDs or SSNs, passport or government ID numbers, form submissions, communications, or passwords.

Do you use cookies or fingerprinting, and how does that sit with ePrivacy/PECR?

We use pixel tagging, and do it in accordance with the IAB's Transparency and Consent Framework, so it is designed to comply with the consent requirements of the ePrivacy Directive and the UK PECR. We rely on the customer setting up an IAB Consent Management Platform on the customer's website.

The crypto identity graph: how it's built

What is the crypto identity graph, and how do you build it?

It is our proprietary map of on-chain identity — over 130 million wallet owners matched to the devices and behaviour behind them, and what we're best known for. It is built separately and independently from any client engagement. The honest, high-level version, with examples so it isn't a black box:

  • It starts with public blockchain data. Every on-chain action is public by design. For example, public records may show a wallet that has traded across major exchanges for several years, holds a diversified portfolio, and regularly bridges sizable balances between chains — that public history alone marks an experienced, high-value user, with no private data.
  • We enrich that with our own first-party network and licensed, publicly-available sources to link on-chain identity to real engagement — data that is public or properly licensed, never scraped private information.
  • The graph is our own asset, maintained independently and kept separate from your data. We have a thorough Data Protection Impact Assessment (DPIA) and Legitimate Interest Analysis (LIA) at the legal foundation of the graph.

What the output looks like: when a long-active trader lands on your platform, you can recognise them as a serious, high-intent user from the first visit rather than an anonymous signup.

We'll show you: we're glad to walk your team through worked, real examples of the crypto identity graph under NDA — seeing it is the fastest way to get comfortable.

What does it never collect?

It collects nothing else under the sun, including names, email addresses, contact details, home addresses, national IDs or SSNs, passport or government ID numbers, form submissions, communications, or passwords.

Is the matching deterministic or probabilistic, and how accurate is it?

We can share a client-safe description and our accuracy on request.

Our role and lawful basis

Are you a controller or a processor?

For the single piece of data we collect through your website about your users, you are the controller and Addressable is the processor, acting solely on your documented instructions to search for enriched data matching the user's device. Separately, we maintain our crypto identity graph as a controller in our own right — our asset, not shared with you, and outside your project's scope.

What is the lawful basis for the processing?

When we act as a processor for the single piece of information collected from users through the customer's website, the customer, as the controller, determines the legal basis. When we act as a controller for our crypto identity graph data, we rely on Article 6(1)(f) GDPR - legitimate interests of Addressable, and third parties (customers) in developing business leads.

Is there a controller-to-controller transfer, or joint controllership?

The enriched data provided to the customer forms a controller-controller transfer.

Compliance, data location and transfers

Which privacy laws do you comply with?

Addressable is GDPR-aligned and SOC 2 attested, with security measures aligned to Article 32.

Where is our data stored and processed?

Within the EU/EEA, UK, Switzerland, or other adequate jurisdictions.

How are international transfers handled?

Any transfer beyond those jurisdictions is covered by Standard Contractual Clauses and the UK IDTA.

Security

What security assurances do you hold?

A SOC 2 Type II report and GDPR-aligned measures, with a penetration test available on request.

How is data protected, and who can access it?

Measures are aligned to Article 32. Access is strictly need-to-know and under confidentiality obligations.

Can we self-host or localize the tag?

The tag is a static JavaScript file. Whether it is deployed via localization or a self-hosted method depends on your own security and deployment policies — we're happy to work with your team on the right approach.

Retention, sub-processors and user rights

How long do you retain data, and what happens when we end the contract?

On termination, your data is deleted or anonymized within 60 days.

Do you use sub-processors, and will we know if they change?

Yes — our sub-processors are published in advance, and any change comes with prior notice and a right to object. The current list is available with our DPA.

How are data subject requests handled?

As your processor, we support you in meeting access, erasure and objection requests under the DPA. As a controller of the identity graph database, we maintain responsibility for data subject requests relating to the graph.

Does the tag respect opt-outs / Do-Not-Track?

The tag reads the do-not-track signal and relies on user consent under the IAB TCF.

Getting started and what we can share

Do we have to deploy the tag — is there a no-tag option?

Not necessarily. Where a tag doesn't fit your review sequencing, we can start without tag integration and structure a low-commitment pilot — which is how we've moved forward with regulated platforms on their own legal timelines.

How quickly can we start?

A first evaluation takes about 1–2 weeks and needs only a simple implementation after your approval.

What can you give our teams to review?

The DPA and published sub-processor list, our Privacy Policy, the SOC 2 Type II report, a penetration-test summary, and a GDPR compliance pack — plus a live walkthrough and worked graph examples under NDA.

Can our DPO speak with yours directly?

Yes — connecting DPOs directly is often the fastest way to finalise and sign the DPA.

Let Your Web3 Brand Thrive with Smarter Marketing

Unlock the full potential of Web3 with our integrated, data-driven platform designed to optimize user acquisition, boost engagement, and drive innovation.