// Legal
Privacy Policy
- Controller
- Overview of Processing Activities
- Registration & Account
- Payment Processing (Stripe)
- Lead Data & Data Enrichment
- Our Business Contact Database (Notice pursuant to Art. 14 GDPR)
- AI Features
- Cookies, Consent & Analytics
- Hosting & Infrastructure
- Recipients & Processors
- International Data Transfers
- Data Retention
- Your Rights
- Data Security
- Changes to This Policy
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
Blox Code LLC
651 N Broad St, Suite 201
Middletown, Delaware 19709
United States of America
Contact: via blox-code.com
Data subjects and supervisory authorities in the EU may contact Blox Code LLC directly with any questions regarding the processing of personal data.
A data protection officer has not been appointed, as the legal requirements for such an appointment are not met.
2. Overview of Processing Activities
PromptMarketer.io is a software platform for entrepreneurs in network marketing. We process personal data in three roles:
- As a controller for your account, contract, and usage data as well as for our own business contact database (Section 6).
- As a processor for lead and contact data that you as a user upload to the platform or enrich through it – in this case, you are the controller responsible under data protection law (Section 5).
- As a website operator for visitor data of this website (Section 8).
3. Registration & Account
For registration, we collect only your email address and a password (stored as a cryptographic hash). Registration is free of charge; premium features can be tested free for 3 days.
In addition, we process technical usage data (login timestamps, IP address, device/browser information, activity logs) to ensure operation, to detect abuse – such as automated browser usage or simulated user activity – and to protect our token flat rate.
Legal bases: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).
4. Payment Processing (Stripe)
Paid subscriptions are processed entirely by Stripe, Inc. (USA) and Stripe Payments Europe Ltd. (Ireland), respectively. Payment data (e.g., credit card numbers) are collected and stored exclusively by Stripe – we ourselves do not receive or store complete payment data. You can view, manage, and cancel your subscription through the Stripe customer portal. Stripe's privacy policy applies in addition.
Legal basis: Art. 6(1)(b) GDPR.
5. Lead Data & Data Enrichment
As a user, you can manage contacts (leads) on the platform and have them automatically enriched with email addresses, mobile numbers, and social media profiles. For this purpose, we use the following data providers:
- People Data Labs, Inc. (USA)
- NinjaPear (USA)
- Cleanlist (Canada, USA)
- ContactOut (USA)
- our own business contact database (Section 6)
Allocation of roles: For lead data that you upload or have enriched, you, as an entrepreneur, are the controller responsible under data protection law; we process this data on your behalf (Art. 28 GDPR). You are obligated to ensure the lawfulness of the processing and of your outreach (in particular the GDPR, Sec. 7 of the German Act Against Unfair Competition (UWG), or the corresponding rules of your market). We provide a data processing agreement (DPA): [add link to the DPA].
6. Our Business Contact Database – Notice pursuant to Art. 14 GDPR
We operate our own database containing business contact information of more than 320,000 network marketing professionals from the USA and Europe. This section informs the individuals included in that database whose data we did not collect directly from them:
- Categories of data: name, business contact details (email, mobile number where applicable), publicly accessible social media profiles, professional information (occupation, company, region).
- Sources: publicly accessible sources (in particular professional networks and websites) and licensed B2B data providers (see Section 5).
- Purposes: providing B2B contact information to our users for business outreach.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in business-to-business communication). No special categories of data (Art. 9 GDPR) are processed.
- Retention: for as long as the data is current and necessary for the stated purpose; subject to regular review and cleansing.
- Objection & erasure: Data subjects may object to the processing at any time and request the erasure of their record – contact us via blox-code.com. We will comply with the objection unless compelling legitimate grounds prevail.
7. AI Features
For message generation, the AI chat, and other AI features, we use API services of the following providers: OpenAI (USA), Anthropic (USA), Google Gemini (USA/Ireland), and Perplexity (USA). The content required for the respective feature (e.g., lead information, prompt input, product knowledge) is transmitted to the respective provider and processed there to generate the response.
We exclusively use business/API access under which, pursuant to the providers' applicable terms, the transmitted content is not used to train the AI models.
Legal bases: Art. 6(1)(b) GDPR (provision of the booked features); lead data is processed on your behalf (Section 5).
8. Cookies, Consent & Analytics
When you visit our websites, we use the following services:
| Service | Purpose | Legal Basis |
|---|---|---|
| Usercentrics | Consent management | Art. 6(1)(c) GDPR |
| sitebehaviour | Website reach and usage analytics | Consent, Art. 6(1)(a) GDPR |
Non-essential cookies and tracking technologies are set only after you have given consent via the Usercentrics banner. You may withdraw your consent at any time with effect for the future via the cookie settings.
9. Hosting & Infrastructure
Our application and databases are operated on Supabase, Amazon Web Services (AWS), and Cloudflare – in data centers located in the USA and, in part, in the EU. For technical reasons, connection data (including IP address, timestamp, requested resource) is processed in server logs.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, high-performance operation).
10. Recipients & Processors
We share personal data only to the extent necessary to provide our services, and exclusively with contractually bound service providers:
- Infrastructure: Supabase, AWS, Cloudflare
- Payments: Stripe
- AI services: OpenAI, Anthropic, Google, Perplexity
- Data enrichment: People Data Labs, NinjaPear, Cleanlist, ContactOut
- Website: Usercentrics, sitebehaviour, Rewardful
Data is disclosed to other third parties only where we are legally required to do so.
11. International Data Transfers
As a US company, we process data primarily in the United States. Where data of individuals from the EU/EEA is transferred, we rely on: the adequacy decision under the EU-U.S. Data Privacy Framework for certified service providers, as well as the EU Standard Contractual Clauses (SCCs) with supplementary safeguards for non-certified recipients.
12. Data Retention
- Account data: for the duration of the contractual relationship; deletion no later than 90 days after account deletion, unless statutory retention obligations apply.
- Billing data: in accordance with statutory retention periods.
- Users' lead data: until deleted by the user or upon account deletion.
- Server logs: generally no longer than 30 days.
13. Your Rights
Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with effect for the future.
To exercise your rights, contact us via blox-code.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence.
14. Data Security
We implement state-of-the-art technical and organizational measures, including TLS encryption of all connections, encrypted storage, password hashing, role-based access controls, and logging of security-relevant events.
15. Changes to This Policy
We update this privacy policy when our processing activities or the legal situation change. The version published on this page applies; the effective date is shown above.