// Legal

Privacy Policy

Last updated: July 9, 2026 · PromptMarketer.io · Blox Code LLC

1. Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:

Blox Code LLC
651 N Broad St, Suite 201
Middletown, Delaware 19709
United States of America
Contact: via blox-code.com

Data subjects and supervisory authorities in the EU may contact Blox Code LLC directly with any questions regarding the processing of personal data.

A data protection officer has not been appointed, as the legal requirements for such an appointment are not met.

2. Overview of Processing Activities

PromptMarketer.io is a software platform for entrepreneurs in network marketing. We process personal data in three roles:

3. Registration & Account

For registration, we collect only your email address and a password (stored as a cryptographic hash). Registration is free of charge; premium features can be tested free for 3 days.

In addition, we process technical usage data (login timestamps, IP address, device/browser information, activity logs) to ensure operation, to detect abuse – such as automated browser usage or simulated user activity – and to protect our token flat rate.

Legal bases: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).

4. Payment Processing (Stripe)

Paid subscriptions are processed entirely by Stripe, Inc. (USA) and Stripe Payments Europe Ltd. (Ireland), respectively. Payment data (e.g., credit card numbers) are collected and stored exclusively by Stripe – we ourselves do not receive or store complete payment data. You can view, manage, and cancel your subscription through the Stripe customer portal. Stripe's privacy policy applies in addition.

Legal basis: Art. 6(1)(b) GDPR.

5. Lead Data & Data Enrichment

As a user, you can manage contacts (leads) on the platform and have them automatically enriched with email addresses, mobile numbers, and social media profiles. For this purpose, we use the following data providers:

Allocation of roles: For lead data that you upload or have enriched, you, as an entrepreneur, are the controller responsible under data protection law; we process this data on your behalf (Art. 28 GDPR). You are obligated to ensure the lawfulness of the processing and of your outreach (in particular the GDPR, Sec. 7 of the German Act Against Unfair Competition (UWG), or the corresponding rules of your market). We provide a data processing agreement (DPA): [add link to the DPA].

6. Our Business Contact Database – Notice pursuant to Art. 14 GDPR

We operate our own database containing business contact information of more than 320,000 network marketing professionals from the USA and Europe. This section informs the individuals included in that database whose data we did not collect directly from them:

7. AI Features

For message generation, the AI chat, and other AI features, we use API services of the following providers: OpenAI (USA), Anthropic (USA), Google Gemini (USA/Ireland), and Perplexity (USA). The content required for the respective feature (e.g., lead information, prompt input, product knowledge) is transmitted to the respective provider and processed there to generate the response.

We exclusively use business/API access under which, pursuant to the providers' applicable terms, the transmitted content is not used to train the AI models.

Legal bases: Art. 6(1)(b) GDPR (provision of the booked features); lead data is processed on your behalf (Section 5).

8. Cookies, Consent & Analytics

When you visit our websites, we use the following services:

ServicePurposeLegal Basis
UsercentricsConsent managementArt. 6(1)(c) GDPR
sitebehaviourWebsite reach and usage analyticsConsent, Art. 6(1)(a) GDPR

Non-essential cookies and tracking technologies are set only after you have given consent via the Usercentrics banner. You may withdraw your consent at any time with effect for the future via the cookie settings.

9. Hosting & Infrastructure

Our application and databases are operated on Supabase, Amazon Web Services (AWS), and Cloudflare – in data centers located in the USA and, in part, in the EU. For technical reasons, connection data (including IP address, timestamp, requested resource) is processed in server logs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, high-performance operation).

10. Recipients & Processors

We share personal data only to the extent necessary to provide our services, and exclusively with contractually bound service providers:

Data is disclosed to other third parties only where we are legally required to do so.

11. International Data Transfers

As a US company, we process data primarily in the United States. Where data of individuals from the EU/EEA is transferred, we rely on: the adequacy decision under the EU-U.S. Data Privacy Framework for certified service providers, as well as the EU Standard Contractual Clauses (SCCs) with supplementary safeguards for non-certified recipients.

12. Data Retention

13. Your Rights

Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with effect for the future.

To exercise your rights, contact us via blox-code.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence.

14. Data Security

We implement state-of-the-art technical and organizational measures, including TLS encryption of all connections, encrypted storage, password hashing, role-based access controls, and logging of security-relevant events.

15. Changes to This Policy

We update this privacy policy when our processing activities or the legal situation change. The version published on this page applies; the effective date is shown above.