Privacy Policy

Effective: March 2026
Contents
  1. Introduction
  2. Data Controller
  3. What Data We Collect
  4. Legal Basis
  5. How We Use Data
  6. Cookies
  7. Data Sharing
  8. Data Retention
  9. Your Rights
  10. Security
  11. International Transfers
  12. Changes to This Policy
  13. Contact
01

Introduction

Chainbrium AS operates a professional blockchain forensics and intelligence platform designed to support law enforcement agencies, financial institutions, compliance teams, and legal professionals in investigating cryptocurrency transactions and tracing on-chain activity.

This Privacy Policy explains how we collect, use, store, and protect personal data when you access or use the Chainbrium platform, website, and related services. It also describes the rights you hold under applicable data protection law, including the General Data Protection Regulation (GDPR) as implemented in Norway through the Personal Data Act (personopplysningsloven).

By creating an account or using Chainbrium, you acknowledge that you have read and understood this policy. If you do not agree with how we handle personal data, please do not use our services.

02

Data Controller

The data controller responsible for your personal data is:

Company Chainbrium AS
Org.nr 930 748 501
Address Haraldsgata 90, 5528 Haugesund, Norway

If you have questions about this policy or wish to exercise your rights, please contact us at the details above.

03

What Data We Collect

We collect only the personal data necessary to provide our services. This includes:

Account Information

Usage Data

Investigation Data

Cookies and Similar Technologies

We use cookies and similar browser-based storage to maintain your session and support platform functionality. See Section 6 for a full breakdown.

04

Legal Basis for Processing

We process personal data only where we have a valid legal basis under GDPR Article 6. The bases we rely on are:

05

How We Use Data

We use the data we collect for the following purposes:

06

Cookies

We use the following categories of cookies:

Essential Cookies

Required for the platform to function. These include your authentication session token (cb_token), which keeps you logged in securely. These cookies cannot be disabled without breaking core functionality.

Analytics Cookies

Optional cookies used to understand how users interact with the platform, such as which features are used most often and where errors occur. These are only set with your consent and can be declined or withdrawn at any time via your account settings.

Preference Cookies

Cookies that remember your settings, such as selected theme (dark, semi-dark, or light) and display preferences. These improve your experience but are not strictly necessary.

You can manage cookie preferences through your browser settings or within the Chainbrium platform settings page. Blocking essential cookies will prevent you from signing in.

07

Data Sharing

We do not sell, rent, or trade your personal data to third parties. We do not use your data for advertising purposes.

We may share data in the following limited circumstances:

Any third-party recipient of personal data is required to process it only for the purposes for which it was shared, in accordance with applicable law.

08

Data Retention

We retain personal data for only as long as necessary to fulfil the purposes for which it was collected, or as required by law.

You may request deletion of your data at any time. See Section 9 for how to exercise this right.

09

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights with respect to your personal data:

To exercise any of these rights, contact us at hq@chainbrium.com. We will respond within 30 days. In complex cases, we may extend this by up to two additional months and will notify you accordingly.

If you believe we have processed your data unlawfully or failed to respond adequately to a rights request, you have the right to lodge a complaint with Datatilsynet, the Norwegian Data Protection Authority, at datatilsynet.no.

10

Security

We take the security of your data seriously and apply industry-standard technical and organisational measures to protect it against unauthorised access, disclosure, alteration, and destruction. These include:

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Article 33 and 34.

11

International Transfers

Chainbrium primarily stores and processes data on infrastructure located within the European Economic Area (EEA), in compliance with GDPR requirements.

In limited circumstances, technical service providers may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, including:

You may request details of any specific third-country transfers and the safeguards applied by contacting us at hq@chainbrium.com.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The date at the top of this page indicates when the policy was last updated.

For material changes that significantly affect your rights or how we process your data, we will notify registered users by email and/or by displaying a prominent notice within the platform at least 14 days before the changes take effect.

We encourage you to review this policy periodically. Continued use of Chainbrium after changes take effect constitutes acceptance of the updated policy.

13

Contact

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

Company Chainbrium AS
Address Haraldsgata 90, 5528 Haugesund, Norway
Org.nr 930 748 501

We aim to respond to all privacy-related inquiries within 5 business days. For formal GDPR rights requests, the statutory response window is 30 days.