Legal
Privacy Notice
This notice explains what personal data nullrpc collects, why, and your rights. It is written to meet the Mexican Ley Federal de Protección de Datos Personales en Posesión de los Particulares, the EU and UK General Data Protection Regulation (GDPR) and US state privacy laws. In short: we collect as little as we can, we do not sell or share data for advertising, and we use no trackers.
1. Who is responsible
The controller (responsable) is Grupo Kindynos, S.A.P.I. de C.V., RFC GKI180321CW7, Sierra Ventana 419, Lomas 3a Sección, 78210 San Luis Potosí, S.L.P., Mexico. Contact for privacy matters: privacy@nullrpc.dev.
EU representative (GDPR article 27): [TODO: name and address of the EU representative]. UK representative: [TODO, if UK customers are served].
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|---|
| Your wallet address (your account identifier) | Sign-in, your account, keys and plan | Contract | While the account exists, then as below for invoices |
| API key names, and hourly request and credit counts per key | Metering your plan, showing your usage | Contract | 13 months |
| Billing details you give at checkout (name, country, tax ID, address, whether you buy as a business) and the country your request came from | Invoices, calculating and paying taxes, evidence of your location for EU VAT | Legal obligation; contract | 5 years after the payment year (Mexican Código Fiscal, art. 30), or longer where tax law requires |
| Invoices, payment amounts and transaction hashes | Billing, accounting, refunds | Contract; legal obligation | Same as billing details |
| Which Terms version you accepted and when; your acceptance at checkout | Proof of the contract and of consumer information | Legal obligation; legitimate interest | While the account exists plus 5 years |
| Sanctions screening results for your wallet address | Complying with sanctions laws | Legal obligation; legitimate interest | While the account exists plus 5 years |
A session cookie (__Host-nullrpc) | Keeping you signed in to the app | Contract (strictly necessary) | 7 days |
| Requests without an API key: a keyed, non-reversible hash of your IP network (IPv4 address or IPv6 /64) with a monthly request count. We never store the IP address itself. | Applying the keyless rate limit and monthly quota | Legitimate interest (fair use, abuse prevention) | Current and previous month |
All of these purposes are necessary for the Service (in Mexican terms, finalidades primarias). We have no secondary purposes: no marketing, profiling or advertising.
3. What we do not keep: RPC requests and logs
- Request contents. The RPC endpoints read your JSON-RPC requests only to answer them. We do not log them or store them linked to you or your IP address. To answer faster, responses for common requests are cached by a hash of the request, with no IP address, key or account attached.
- IP addresses. Our provider Cloudflare necessarily processes your IP address to deliver traffic, apply rate limits and block attacks and sanctioned locations. The RPC endpoints keep no request logs; errors are logged without IP addresses or request contents. The account app keeps short operational logs at Cloudflare for troubleshooting, kept for at most 7 days.
- Signed transactions you send with
eth_sendRawTransactionare forwarded to a third-party transaction relay (for example Flashbots Protect) to be published on the blockchain, where they become public. - No trackers. Our websites use no analytics, advertising or social-media cookies, pixels or third-party scripts, and use no browser storage.
4. Blockchain data is public
Your wallet address and payments to nullrpc are recorded permanently on a public blockchain. Anyone can see that your address paid our treasury address. We cannot delete or change blockchain data.
5. Who receives data
- Cloudflare, Inc. (United States) hosts the Service, its database and caches, as our processor under its data processing agreement.
- Ethereum RPC providers receive your public wallet address and transaction hashes when we verify payments and query the Chainalysis sanctions oracle (an on-chain contract). Chainalysis does not receive your data from us directly.
- Tax advisors and Mexico's electronic invoicing provider (PAC), and the tax authority (SAT), receive billing data when invoices or tax returns require it.
- Authorities, when the law requires it, and a buyer of our business if Kindynos is sold (under this notice).
We do not sell personal data and do not share it for cross-context behavioural advertising. Transfers to processors do not require your consent under Mexican law; we do not make other transfers that would.
6. International transfers
Kindynos is in Mexico and Cloudflare processes data in the United States and other countries. For data from the EU, EEA, UK or Switzerland, transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Cloudflare is certified) and on standard contractual clauses. Mexico does not have an EU adequacy decision; we apply the same protections described here.
7. Your rights
- Everyone: you may ask for access to, correction of and deletion of your data, and object to its use. Write to privacy@nullrpc.dev from, or with a signature of, the wallet concerned so we can confirm the request is yours.
- Mexico (ARCO rights): access, rectification, cancellation and opposition, and revoking consent or limiting use. Your request must include your name, the wallet address or other data concerned, what you ask for and how we can reply. We answer within 20 business days and, if we accept the request, carry it out within 15 business days after answering. You may complain to the Mexican data protection authority (Secretaría Anticorrupción y Buen Gobierno).
- EU, EEA and UK (GDPR): also restriction, portability, and objection to processing based on legitimate interests. We answer within one month. You may complain to your local supervisory authority.
- United States: residents of states with privacy laws (such as California, Colorado, Virginia or Texas) may ask to know, correct and delete their data. We do not sell or share data, so there is nothing to opt out of; we honour Global Privacy Control signals anyway. We will not discriminate against you for exercising your rights. You may appeal a refusal by replying to our answer.
We keep data that the law requires us to keep (such as invoices and sanctions records) even after a deletion request, and delete it when that duty ends.
8. Security
Data is encrypted in transit, the app uses strict browser security policies, API keys are never stored (only an identifier they are derived from), and access to the database is limited to the people who operate the Service. If a breach affects your data, we will notify you and the authorities as the law requires.
9. Children
The Service is not for anyone under 18, and we do not knowingly collect their data.
10. Changes
We will publish changes to this notice here with a new date, and tell signed-in users in the app about material changes.