Legal

Privacy Notice

Version 1.1Effective May 2026

At Everstake, the privacy of the users of our products and technology is one of our main priorities. This Privacy Notice outlines the information that is collected, processed, and used by Everstake Inc., a Delaware corporation, and its affiliates (collectively, “Everstake,” “Company,” “we,” “us,” or “our”) in connection with the personal data of users of the Platform, accessible through the web dashboard located at app.blockspace.everstake.one and any related domains, interfaces, and technical documentation (the “Site”), and the products and services we provide through the Platform (the “Services”).

This Privacy Notice should be read together with the Terms of Use applicable to the Platform and any product-specific terms applicable to particular Services.

Navigate this Privacy Notice to understand:

  1. Who we are and how to contact us
  2. The scope of this Privacy Notice
  3. What data we process
  4. Third-party services and intended international transfers
  5. How we protect your data
  6. Online presence on social media
  7. Links to third-party sites
  8. Exercising your data subject rights
  9. Cookies and tracking technologies

If you do not agree with our policies and practices, your choice is not to use the Site or the Services. By accessing or using the Site or the Services, you acknowledge this Privacy Notice.

1. Who We Are And How To Contact Us

The entity responsible for your personal data is:

Everstake Inc.
A Delaware corporation, with its registered office in the United States of America.

If you have additional questions or require more information about this Privacy Notice or your personal data, please contact us at legal@everstake.one.

As an entity established outside the European Union and the United Kingdom, the contact details of our European and UK Representatives are as follows:

EU Representative

TechGDPR DPC GmbH
Willy-Brandt-Platz 2
12529 Berlin-Schönefeld, Germany

Our European Representative can be contacted at everstake.rep@techgdpr.com.

UK Representative

Legal Nodes Ltd
Office 2, Bennet’s House, 21 Leyton Road,
Harpenden, England, AL5 2HU

Our UK Representative can be contacted at everstake.rep@legalnodes.com.

2. Scope Of This Privacy Notice

This Privacy Notice applies to the following categories of people:

  • Visitors to our Site and prospective users of the Services.
  • Authorized Users of the Services, who register an account on the Platform and use the Services made available through it.
  • Company representatives who reach out to us to request information about the Services or with whom we communicate in connection with the provision of the Services to the company they represent (our leads and clients).
  • Vendor contact personnel with whom we communicate in the course of their service provision to us (our prospective and active suppliers).
  • Partners with whom we have commercial relationships in connection with the Platform.

The Site and the Services are intended for business and professional use and are not directed to, and we do not knowingly collect personal data from, anyone under the age of 18. If a parent or guardian becomes aware that their child has provided us with personal data, please contact us. We will delete such information from our records as soon as reasonably practicable. By requesting any of the Services from us, you acknowledge that you are at least 18 years of age.

We may update this Privacy Notice based on evolving laws, regulations, industry standards, or as we may make changes to the Site or the Services. We will post changes to this Privacy Notice on the Site and encourage you to review it periodically to stay informed. If we make changes that materially affect your privacy rights, we will take appropriate measures to inform you, consistent with the significance of the changes. If you disagree with the changes, you should discontinue your use of the Site and the Services.

3. What Data We Process

The categories of personal data we process depend on how you interact with the Site and the Services. The tables below describe each processing activity, the purpose it serves, the data we collect or process, the legal basis under the GDPR, the retention period, and the data subject rights available to you.

3.1 Data processed from Site visitors

ActivityPurpose servedData collected / processedLegal basis (GDPR Art. 6)Retention periodAvailable data subject rights
Visiting and interacting with the SiteAllows us to provide information through the Site, perform Site maintenance, and improve the Site based on user interaction and analytics.IP address; browser information (e.g., device type, operating system, language, time zone, browser type and version); approximate location information derived from IP address; performance and interaction telemetry.Legitimate Interest (Art. 6(1)(f) GDPR)Up to 2 years, depending on the cookie or analytics tool used.All except the right to data portability (see Section 8)
Marketing and promotional activitiesAllows us to engage prospective customers and analyze the effectiveness of our communications.Name; contact information (e.g., email address); browsing behavior; marketing preferences; data from social media (see Section 6).Legitimate Interest (Art. 6(1)(f) GDPR), or Consent (Art. 6(1)(a) GDPR) where required by law.1 year, or until the data subject requests deletion or withdraws consent, whichever is earlier.All except the right to data portability (see Section 8)

3.2 Data processed from Authorized Users of the Services

ActivityPurpose servedData collected / processedLegal basis (GDPR Art. 6)Retention periodAvailable data subject rights
Account creation and authenticationAllows us to create and authenticate Authorized User accounts on the Platform, manage sessions, and gate access to the Services.Email address; authentication identifier issued by our authentication provider; email verification status; authentication tokens and session metadata.Performance of a contract (Art. 6(1)(b) GDPR)For the duration of the account and up to 12 months after account closure, unless a longer period is required by law.All except the right to opt-out from automated decision-making (see Section 8)
Provision of the ServicesAllows us to provide the Services purchased or selected by the Authorized User, including configuration of API tokens, projects, validator endpoints, and routing parameters.API tokens issued to the account; project names and configurations; validator public keys (where applicable); IP addresses or endpoints configured for direct shred forwarding (where applicable); service-tier configuration (e.g., selected plan, throughput tier, data center location).Performance of a contract (Art. 6(1)(b) GDPR)For the duration of the account and up to 12 months after account closure, unless a longer period is required by law.All except the right to opt-out from automated decision-making (see Section 8)
Billing and payment processingAllows us to charge Fees, issue invoices, and maintain billing records for the Services. Payment-card data is processed solely by our third-party payment processor and is not stored on our infrastructure.Email address used for invoicing; customer identifier issued by our payment processor; subscription history and invoice records; billing address (where provided); payment-card data (held by the payment processor only).Performance of a contract (Art. 6(1)(b) GDPR); Legal Obligation (Art. 6(1)(c) GDPR) for tax and accounting records.Up to 7 years pursuant to applicable tax and accounting law.All except the right to erasure and data portability (see Section 8)
Usage metering and rate-limitingAllows us to meter Service usage against credit allowances, enforce rate limits, detect and prevent abuse, and bill for overage where applicable.Request counts and credits consumed; request timestamps; subscription usage per billing period; API token identifiers.Performance of a contract (Art. 6(1)(b) GDPR); Legitimate Interest (Art. 6(1)(f) GDPR) for fraud prevention and platform integrity.Up to 13 months on a rolling basis, after which records are aggregated or deleted.All except the right to opt-out from automated decision-making (see Section 8)
Customer supportAllows us to handle customer inquiries, resolve issues related to the Services, and maintain communication records to ensure a responsive user experience.Email address; customer queries and communication records; account and transaction context relevant to the inquiry.Performance of a contract (Art. 6(1)(b) GDPR)1 year for any data no longer required for operational, legal, or regulatory purposes, or until deletion is requested by the user.All except the right to opt-out from automated decision-making (see Section 8)
System monitoring and securityAllows us to monitor and manage the Platform infrastructure to detect, prevent, and respond to security threats and vulnerabilities, ensuring the integrity, availability, and confidentiality of the Services.IP addresses and system access logs (where applicable for security purposes); authentication events and anomaly indicators; security incident reports and vulnerability assessments.Legitimate Interest (Art. 6(1)(f) GDPR); Legal Obligation (Art. 6(1)(c) GDPR) where applicable.6 to 12 months for routine logs; longer for records associated with confirmed security incidents.All except the right to data portability (see Section 8)
Service improvement and analyticsAllows us to analyze how the Site and Services are used in order to improve performance, identify defects, and prioritize feature development.Aggregated usage patterns; performance metrics; feedback (where voluntarily provided).Legitimate Interest (Art. 6(1)(f) GDPR)1 year, after which data is aggregated or deleted, or until deletion is requested by the user where the data is identifiable.All except the right to data portability (see Section 8)
Drafting, agreeing, and performing service contracts negotiated outside the standard Terms of Use (e.g., enterprise agreements)Allows us to establish clear and enforceable agreements with Authorized Users where commercial terms are negotiated separately.Contact information; negotiation records; contract terms and signatures.Performance of a contract (Art. 6(1)(b) GDPR)Up to 6 years pursuant to legal obligations.All except the right to opt-out from automated decision-making (see Section 8)

3.3 Data processed from Vendors and Partners

ActivityPurpose servedData collected / processedLegal basis (GDPR Art. 6)Retention periodAvailable data subject rights
Contracting and negotiation with Vendors and PartnersAllows us to establish clear and enforceable agreements with our suppliers and commercial partners.Contact information; negotiation records; contract terms; signatures.Performance of a contract (Art. 6(1)(b) GDPR)Up to 6 years pursuant to legal obligations.All except the right to opt-out from automated decision-making (see Section 8)
Financial accountingAllows us to maintain accurate financial records, comply with tax and financial-reporting regulations, manage transactions and operational costs, and prepare financial statements.Customer Data: invoices, payment details, transaction records; Vendor Data: payment information, contract details.Legal Obligation (Art. 6(1)(c) GDPR)Up to 7 years pursuant to applicable tax and accounting law.All except the right to erasure and data portability (see Section 8)
Technical and commercial communication with PartnersAllows us to communicate with Partners regarding contractual terms, technical issues, integrations, and improvements to the Services.Name and/or username; email address; company name; communication records; phone number (optional).Performance of a contract (Art. 6(1)(b) GDPR)Up to 6 years.All except the right to opt-out from automated decision-making (see Section 8)

4. Third-Party Services And Intended International Transfers

To operate the Site and provide the Services, we rely on a limited number of third-party service providers. These providers process personal data on our behalf in accordance with written data processing agreements. Where personal data is transferred outside of the European Economic Area or the United Kingdom, such transfers are protected by an adequacy decision, EU/UK Standard Contractual Clauses, or another appropriate safeguard recognized under applicable law.

4.1 Categories of providers we share data processed from Site visitors

Third parties / categories of third partiesPurpose servedInternational transfers of data
Web analytics and performance-monitoring providersCollecting and analyzing Site visitor analytics and performance metrics.United States (Standard Contractual Clauses)
Hosting and content-delivery networkHosting the Site, delivering content, and protecting against malicious traffic.United States (Standard Contractual Clauses)

4.2 Categories of providers we share data processed from Authorized Users of the Services

Third parties / categories of third partiesPurpose servedInternational transfers of data
Authentication providerAccount creation, email verification, and authentication of Authorized Users.United States (DPA with Standard Contractual Clauses)
Payment processorProcessing of subscription Fees and one-off payments. Payment-card data is collected and stored solely by the payment processor and is not retained on our infrastructure.United States (DPA with Standard Contractual Clauses)
Hosting and content-delivery networkHosting the Platform, delivering the dashboard, and protecting against malicious traffic.United States (DPA with Standard Contractual Clauses)
Cloud database and analytics infrastructureStoring account, project, and usage records and performing usage metering.European Union and United States (DPA with Standard Contractual Clauses)
Blockchain infrastructure partnersRouting of transactions, shred data, and related blockchain traffic in connection with the Services.United States and other jurisdictions, as relevant to the routing of the underlying blockchain traffic.
CRM and customer engagement toolsCustomer engagement, sales outreach, and support communications.United States (DPA with Standard Contractual Clauses)
Internal workplace communication platformInternal communication, including in connection with customer inquiries.United States (DPA with Standard Contractual Clauses)

4.3 Categories of providers we share data processed from Vendors and Partners

Third parties / categories of third partiesPurpose servedInternational transfers of data
Cloud service providerCommunication, collaboration, and cloud storage.United States (DPA with Standard Contractual Clauses)
CRM(s)Customer engagement and sales outreach.United States (DPA with Standard Contractual Clauses)
Internal workplace communication platformInternal communication, including in connection with vendor and partner inquiries.United States (DPA with Standard Contractual Clauses)

Only data relevant to the functionality of the Services is shared with these providers. We only transfer data to the third-party service providers listed above where this is necessary for the purposes described and permitted by law.

In addition to the categories of providers listed above, Everstake Inc. may share data within the wider Everstake group of companies (including affiliated entities established in other jurisdictions) under intra-group data processing or data sharing agreements. Where independent contractors are engaged for the provision of the Services and are located outside the European Union or the United Kingdom, a relevant Data Processing Agreement is concluded with each contractor to ensure the safe transfer of personal data.

In limited circumstances, we may also disclose personal data to law enforcement, regulatory, or governmental authorities, or to third parties involved in actual or threatened legal proceedings, where we are required to do so by law or where disclosure is necessary to protect our rights, the rights of our users, or the integrity of the Platform.

5. How We Protect Your Data

We are committed to protecting the security and confidentiality of your personal data through comprehensive technical and organizational measures designed to prevent unauthorized access, disclosure, or misuse. Our security practices include, among others, encryption of data in transit, access controls, network segmentation, monitoring and logging, vulnerability management, secure software-development practices, and the engagement of trusted infrastructure providers under written data-processing agreements.

Authentication credentials and API tokens are sensitive. You are responsible for keeping your credentials and API tokens confidential and for rotating tokens promptly upon any suspected compromise. We recommend the use of strong, unique passwords and the enablement of any additional authentication factors offered through the Platform from time to time.

For a more detailed overview of the security measures, policies, and procedures implemented across the Everstake group, please visit https://security.everstake.one/.

6. Online Presence On Social Media

We maintain online presences on social networks in order to communicate with customers, prospective users, and other interested parties, manage and analyze user interactions, and monitor brand presence. Data submitted by users to those social networks is generally processed by the operators of those networks for market research and advertising purposes, and usage profiles may be created based on the interests of the users.

As part of operating our online presences, we may access aggregated statistics provided by the social networks, which can include data on interactions with our online presences (e.g., likes, follows, shares, views) and on the posts and content distributed via them. The collection and use of these statistics are generally subject to joint responsibility with the operators of the relevant social networks.

The legal basis for our data processing in this context is Art. 6(1)(f) GDPR, based on our legitimate interest in providing customer support and responding to inquiries, analyzing engagement to improve user experience, responding to comments, and monitoring our brand presence. Where you have an account with the social network, we may see your publicly available information and media when we access your profile, and the social network may allow us to contact you (e.g., via direct messages). The communication of content via a social network and the processing of such content data is subject to the responsibility of the social network as a messenger and platform service.

For information on the data processing carried out by the social networks under their own responsibility, please refer to the data-protection information of the respective social network. Data-protection requests can usually be asserted most efficiently with the operator of the relevant social network, as only that operator has direct access to the data and can take appropriate measures. You may also contact us, in which case we will process your request and forward it to the operator of the relevant social network, where appropriate.

We currently maintain online presences on the following social networks:

  • Telegram;
  • X (Twitter);
  • Reddit;
  • LinkedIn;
  • Discord;
  • YouTube.

7. Links To Third-Party Sites

The Site may contain links to other websites, mobile applications, and online services operated by third parties. These links do not constitute an endorsement of, or a representation that we are affiliated with, any third party. In addition, our content may appear on web pages, mobile applications, or online services that are not associated with us. We do not control third-party websites, mobile applications, or online services and are not responsible for their actions. Other websites, mobile applications, and services follow different rules regarding the collection, use, and sharing of personal data. We encourage you to read the privacy notices of any other websites, mobile applications, and online services you use.

8. Exercising Your Data Subject Rights

Depending on where you reside, you may be entitled to specific rights under data-protection laws such as the General Data Protection Regulation (GDPR), the UK GDPR, the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada), or various U.S. state privacy laws. These rights are designed to give you greater control over how your personal data is collected, used, and shared. The tables below provide an overview of the rights available to residents of the European Economic Area, the United Kingdom, Canada, and applicable U.S. states. If you reside in a country whose laws are not specifically addressed below, please refer to the section on rights for European Economic Area and United Kingdom residents.

If you wish to make a request or have questions about your privacy rights, please contact us at legal@everstake.one.

You are not required to pay any fee to exercise your data-protection rights.

8.1 European Economic Area and United Kingdom Residents

You have the following rights with respect to the personal data we hold about you:

Your RightDescription
Right to AccessYou have the right to request information about the personal data we hold about you, its origin, the recipients to whom it has been disclosed, and the purposes of processing (Art. 15 GDPR).
Right to RectificationYou can ask us to correct any inaccurate personal data, or complete data you believe is incomplete (Art. 16 GDPR).
Right to ErasureYou can request the deletion of your personal data unless processing is necessary to fulfill a legal obligation or task carried out in the public interest (Art. 17 GDPR).
Right to Restrict ProcessingYou can ask us to limit the processing of your personal data in certain circumstances (Art. 18 GDPR).
Right to Object to ProcessingYou can object to the processing of your personal data in certain situations, including for direct marketing purposes.
Right to Data PortabilityYou can request that we transfer the personal data you have provided to another organization, or directly to you, in certain cases (Art. 20 GDPR).
Right to Withdraw ConsentWhere processing is based on your consent, you can withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
Right to File a ComplaintIf your request is not satisfied, you may file a complaint with the supervisory authority in your country of residence.

EEA Residents — If you are in the EEA and have not received a response from us, or are not satisfied with our response, you have the right to lodge a complaint with the data-protection authority where you reside.

UK Residents — If you are in the United Kingdom and have not received a response from us, or are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at 0303 123 1113 or www.ico.org.uk/concerns.

You have the right to data portability where your data is processed on the basis of your consent or for the performance of a contract (Article 20 GDPR). You also have the right to withdraw your consent at any time, in which case we will no longer process your data on that basis going forward (the withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal).

Where we process your data based on our legitimate interests, you have the right to object to that processing at any time on grounds relating to your particular situation. Where the objection concerns the processing of data for direct-marketing purposes, you have a general right to object, which we will respect without requiring any justification.

To exercise your rights, an informal message to the contact details provided above is sufficient. We will aim to respond as quickly as possible, and no later than within one month of receiving your request.

8.2 United States Residents

If you are a resident of a U.S. state with active privacy legislation — including but not limited to California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — you may be entitled to specific rights regarding the collection, use, and sharing of your personal information. These rights vary by state but generally include the ability to access your personal data, request its deletion or correction, limit how it is used, or opt out of certain types of data processing.

The table below provides an overview of the rights that may be available to you depending on your state of residence:

Your RightDescriptionState
Right to AccessYou may request information about how your personal data is being processed and obtain a copy of the personal data we hold about you.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to RectificationYou may request that we correct any inaccurate personal data we hold about you.CA, CO, CT, DE, IN, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, VA
Right to DeletionYou may request that we delete the personal data we have collected about you.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to opt out of certain purposesThe right to opt out of processing for profiling or targeted-advertising purposes.CA, CO, CT, DE, IN, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to opt out of salesYou may request to opt out of the sale of your personal data to third parties.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to PortabilityYou may request that we transfer the personal data you provided to another organization, or directly to you, in certain cases.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to information on automated decision-makingWhere automated decision-making is used, you may request details and, in certain states, opt out of such processing.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA
Right to AppealIf we deny your request, you may appeal by contacting legal@everstake.one. We will review and respond to your appeal within 45 days.CA, CO, CT, DE, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA

You may also exercise your rights by contacting us at legal@everstake.one.

Please note: some U.S. states do not have their own privacy laws. The rights of residents of such states are governed by U.S. federal law. If, upon exercising your right to appeal, you remain dissatisfied with the outcome, you have the right to contact the privacy authority in your state, such as your State Attorney General’s Office, to file a formal complaint or inquiry.

Additional rights of California Residents

If you are a California resident, you are entitled to certain additional rights under the California Consumer Privacy Act (“CCPA”) and other applicable California privacy laws. These rights are outlined below.

Your RightDescription
Do Not Sell My Personal InformationUnder the CCPA, California residents have the right to opt out of the “sale” of their personal information by businesses subject to the CCPA.
Right to Opt Out of the Processing of Sensitive Personal InformationYou have the right to opt out of the processing of your sensitive personal information, which may include precise geolocation, racial or ethnic origin, health data, or biometric information, where applicable.
Do-not-track RequestCalifornia law also permits residents to request that companies do not track their online browsing activity over time and across different websites or online services. These requests are typically communicated through browser settings or other technologies that signal a preference not to be tracked.
Private Right of ActionCalifornia law provides a private right of action, allowing individuals to seek civil damages in certain circumstances, particularly in the case of data breaches resulting from a failure to implement reasonable security measures.

8.3 Canada Residents

You have the following rights concerning the data we hold about you:

Your RightDescription
Right to AccessYou may request information about how your personal data is being processed and obtain a copy of the personal data we hold about you.
Right to RectificationYou may request that we correct any inaccurate personal data we hold about you.
Right to DeletionYou may request that we delete the personal data we have collected about you.
Right to Data PortabilityYou may request that we transfer the personal data you provided to another organization, or directly to you, in certain cases.
Right to Object / Opt OutYou may object to or request that we limit the processing of your personal data in certain circumstances.
Right to Withdraw ConsentYou may withdraw your consent to data processing at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Right Not to Be Subject to Automated Decision-MakingYou may object to being subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects.
Right to File a ComplaintIf you are not satisfied with our response to your request, you may file a complaint with the Office of the Privacy Commissioner of Canada.

If you have any questions or wish to exercise any of the rights described in this Section 8, please contact us at legal@everstake.one.

9. Cookies And Tracking Technologies

We and our third-party service providers use cookies and similar tracking technologies (such as pixels, local storage, and SDK identifiers) to operate the Site, remember your preferences, measure performance, and — where you have consented — to support analytics and marketing communications. A cookie is a small text file that is placed on your device when you visit a website; pixels and similar technologies fulfill comparable functions through other means.

We classify the cookies and tracking technologies used on the Site into the following categories:

  • Strictly necessary — required for the Site to function (e.g., load-balancing, security, consent-state storage). These are set on the basis of our legitimate interest and cannot be disabled through the consent banner.
  • Functional — remember choices you make (e.g., theme preference) to provide a more personalized experience. Set only with your consent.
  • Analytics / performance — help us understand how visitors interact with the Site so we can improve content, navigation, and performance. Set only with your consent.
  • Marketing / advertising — used by us or our partners to deliver and measure marketing communications. Set only with your consent.

A live, auto-updated inventory of every cookie and tracker active on the Site — including provider, category, purpose, duration, and whether it transfers data outside the EEA/UK — is available below.

Managing your preferences

You can review and change your cookie preferences at any time by clicking or, where you reside in a U.S. state with applicable privacy laws, by clicking the “Do Not Sell or Share My Personal Information” link in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

You can also control cookies through your browser settings (block all cookies, delete existing cookies, or be notified before a cookie is set). Note that blocking strictly necessary cookies may prevent parts of the Site from working.

We honor the Global Privacy Control (GPC) browser signal. Where required by applicable U.S. state privacy law, a GPC signal from your browser is treated as a valid request to opt out of the sale or sharing of personal information.