Solana Beta is now live
Try it freeLast updated: May 22, 2026
Effective date: May 22, 2026
This Privacy Policy ("Policy") describes how Matrixedlabs Technologies FZ-LLC ("Matrixedlabs", "BoltRPC", "we", "us" or "our"), the operator of the BoltRPC brand and the website available at https://boltrpc.io (the "Website") and the BoltRPC infrastructure services (the "Services"), collects, uses, discloses, transfers, retains and protects Personal Data relating to visitors of the Website, users of the Services, prospective customers and other individuals who interact with us (each a "Data Subject" or "you").
This Policy is issued in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL") and its Executive Regulations, the EU General Data Protection Regulation 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation as incorporated under the Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"), and other applicable data protection laws to the extent they apply to our processing activities.
Capitalised terms used in this Policy have the meaning given to them in the UAE PDPL or, where applicable, in the GDPR. By accessing the Website, submitting a form, subscribing to the newsletter, or otherwise providing us with Personal Data, you acknowledge that you have read and understood this Policy.
1.1 Controller. The controller responsible for processing Personal Data under this Policy is:
1.2 EU Representative (Article 27 GDPR). For Data Subjects located in the European Economic Area, our representative for the purposes of Article 27 GDPR is:
1.3 Data Protection Enquiries. All requests, complaints and enquiries concerning the processing of your Personal Data, including the exercise of the rights set out in Section 12, should be addressed to [email protected]. We will respond to verifiable requests within the statutory time limits applicable to your jurisdiction (typically thirty (30) days under the UAE PDPL and the GDPR, extendable by a further sixty (60) days under the UAE PDPL where reasonably necessary).
2.1 This Policy applies to Personal Data processed in connection with (a) your use of the Website, (b) communications you initiate with us through the contact, newsletter, or expert consultation forms, (c) your participation in any trial or commercial relationship with BoltRPC, and (d) any other interaction governed by this Policy.
2.2 This Policy does not apply to third-party websites, applications or services to which we may link, even when those resources are referenced from the Website. We are not responsible for the privacy practices of third parties and we encourage you to review their privacy notices.
2.3 The Services are not intended for use by individuals under the age of eighteen (18). Section 15 sets out our position on children's privacy.
We process the following categories of Personal Data:
3.1 Identification and Contact Data. Your name, business email address, company name, job title, telephone number (where provided), and the content of any message you submit through our contact, newsletter, or expert consultation forms.
3.2 Technical and Connection Data. Your Internet Protocol (IP) address, approximate geolocation derived from your IP address, browser type and version, operating system, device characteristics, referring URL, timestamps of requests, and other technical metadata transmitted automatically by your client when accessing the Website.
3.3 Usage and Analytics Data. Pages visited, time spent on pages, scroll depth, links clicked, form interactions, and aggregated patterns derived from your navigation of the Website. Where you have consented to analytics cookies, this category may also include persistent identifiers used to recognise you across sessions.
3.4 Security and Anti-Abuse Data. Information processed by our content delivery network and security services for the purpose of detecting, preventing, and investigating fraud, abuse, automated attacks, and unauthorised access. This includes data generated by Cloudflare Turnstile, bot management cookies, and threat-intelligence signals.
3.5 Commercial Relationship Data. Where you become a customer or enter a free trial, additional Personal Data may be processed in connection with that relationship (for example, account credentials, billing contacts, API key usage metadata). The processing of such data is governed by the agreement entered into between BoltRPC and the relevant customer entity and, where applicable, by a separate Data Processing Addendum.
3.6 No Special Categories. We do not knowingly or intentionally collect special categories of Personal Data (sensitive personal information) under Article 9 GDPR or Article 15 UAE PDPL. You should not submit such data to us through any form on the Website.
4.1 Directly from You. When you submit a form, subscribe to our newsletter, request a consultation, or otherwise correspond with us.
4.2 Automatically. When you access the Website, certain technical data is transmitted by your browser and collected by our hosting infrastructure, content delivery network, and analytics tooling.
4.3 From Third Parties. In limited circumstances, we may receive your Personal Data from third parties such as referral partners, mutual customers, publicly accessible business directories (e.g. LinkedIn), or from your employer where they have introduced you to us. We rely on the originating party to have a lawful basis for sharing such Personal Data with us.
We process Personal Data only where a lawful basis exists. The principal purposes for which we process Personal Data, and the corresponding legal bases under the UAE PDPL and the GDPR, are set out below.
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Responding to business enquiries and consultation requests | 3.1 | Performance of, or pre-contractual steps at the request of, the Data Subject (Art. 6(1)(b) GDPR; Art. 5(2) PDPL) |
| Delivering the newsletter to subscribers | 3.1 | Consent (Art. 6(1)(a) GDPR; Art. 6 PDPL), withdrawable at any time |
| Operating, securing and maintaining the Website | 3.2, 3.4 | Legitimate interests in operational security and availability (Art. 6(1)(f) GDPR; Art. 5(7) PDPL) |
| Measuring website performance via analytics (with consent) | 3.3 | Consent (Art. 6(1)(a) GDPR; Art. 6 PDPL) |
| Aggregate, cookieless measurement (no identifier set) | 3.3 (aggregated) | Legitimate interests (Art. 6(1)(f) GDPR) |
| Preventing fraud, spam and automated abuse | 3.2, 3.4 | Legitimate interests (Art. 6(1)(f) GDPR; Art. 5(7) PDPL) |
| Performing contracts with customers and managing accounts | 3.5 | Performance of a contract (Art. 6(1)(b) GDPR; Art. 5(2) PDPL) |
| Complying with legal, tax, accounting or regulatory obligations | 3.1, 3.5 | Legal obligation (Art. 6(1)(c) GDPR; Art. 5(4) PDPL) |
| Establishing, exercising or defending legal claims | As applicable | Legitimate interests (Art. 6(1)(f) GDPR; Art. 5(8) PDPL) |
Where processing relies on legitimate interests, we have conducted a balancing test and concluded that our interests are not overridden by the fundamental rights and freedoms of the Data Subject. You may request a summary of that balancing test by contacting [email protected].
6.1 General. We use cookies, local storage and similar technologies (collectively, "Cookies") to operate the Website, to ensure its security, and—where you have provided consent—to measure its performance. A "cookie" is a small text file stored on your device by your browser.
6.2 Strictly Necessary Cookies. Cookies in this category are required for the secure operation of the Website and do not require consent under Article 5(3) of the EU ePrivacy Directive (Directive 2002/58/EC) as transposed into national law. They include cookies set by Cloudflare for bot mitigation and challenge resolution, as well as session cookies used to operate forms and security tokens.
6.3 Analytics Cookies (Google Analytics 4 with Consent Mode v2). We use Google Analytics 4 with Google Consent Mode v2 to measure Website usage. When you accept analytics cookies via our cookie consent banner, Google Analytics uses cookies to record page views, time spent on pages, bounce rates, and interaction events such as form submissions and button clicks. We have configured Google Analytics with IP anonymisation enabled, ads_data_redaction=true and url_passthrough=true so that no advertising identifiers are transmitted.
6.4 Cookieless Measurement. If you decline analytics cookies, or do not respond to the cookie banner, no analytics cookies are set and no unique identifier is stored on your device. Google Analytics instead receives anonymous, aggregated signals containing your approximate country, device type, referring URL, and whether a page was viewed. These signals do not contain cookies, advertising identifiers, or persistent personal data and cannot be used to recognise you across visits.
6.5 Cloudflare Web Analytics (RUM). We deploy Cloudflare's Web Analytics product, which uses a privacy-first measurement approach. Cloudflare Web Analytics does not set cookies, does not use fingerprinting techniques, and does not track individual users across websites. It collects aggregated technical performance metrics (such as page load timings, Core Web Vitals, response status codes, and country-level geolocation derived from IP) which are used solely to monitor and improve Website performance. Because Cloudflare Web Analytics does not set Cookies on your device, it does not require user consent under Article 5(3) of the EU ePrivacy Directive.
6.6 Cloudflare Turnstile. We deploy Cloudflare Turnstile as a privacy-friendly alternative to traditional CAPTCHA on our contact, newsletter, and expert consultation forms. Turnstile assesses whether a form submission originates from a human or an automated agent by analysing technical signals (browser characteristics, interaction patterns, IP reputation). Turnstile typically runs invisibly and does not require user interaction. The processing is necessary for our legitimate interests in preventing spam and abuse.
6.7 Specific Cookies. The principal Cookies set in connection with the Website are:
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
__cf_bm | Cloudflare | Bot management | 30 minutes | Strictly necessary |
cf_clearance | Cloudflare | Records successful challenge resolution | Up to 30 days | Strictly necessary |
cf_chl_* | Cloudflare Turnstile | Challenge state during form submission | Session | Strictly necessary |
_ga, _ga_* | Google Analytics 4 | Distinguishes users for analytics | 2 years (only set with consent) | Analytics (consent required) |
| Consent record | BoltRPC | Stores your cookie preferences | 12 months | Strictly necessary |
6.8 Managing Cookies. You can manage your cookie preferences at any time through (a) the cookie consent banner displayed on first visit, (b) the cookie-settings link in the footer of the Website, and (c) the privacy or cookie controls in your browser settings. Blocking strictly necessary Cookies may impair the functionality and security of the Website.
7.1 Recipients. We disclose Personal Data only to the extent necessary to deliver the Website and Services, comply with applicable law, or protect our legitimate interests. The principal recipients are: (a) our employees and contractors bound by contractual confidentiality obligations; (b) sub-processors and service providers acting on our instructions under written agreements; (c) professional advisers (legal, tax, accounting) under duties of confidentiality; and (d) competent authorities where disclosure is mandated by law or by a binding order.
7.2 Sub-Processor List. The sub-processors and service providers engaged by Matrixedlabs to deliver the Website and the Services are set out below. Each engagement is governed by a written contract incorporating the obligations required under Article 28 GDPR (or equivalent under the UAE PDPL).
| Sub-Processor | Service Provided | Processing Location | Reference |
|---|---|---|---|
| Cloudflare, Inc. | CDN, WAF, DDoS mitigation, Turnstile, Web Analytics (RUM) | United States (global edge network) | Privacy / DPA |
| Google LLC / Google Ireland Limited | Google Analytics 4 (with Consent Mode v2) | European Union and United States | Privacy |
| DigitalOcean LLC | Cloud hosting infrastructure for the Website origin | United States / European Union | Privacy |
| TransIP B.V. | Domain registrar; inbound and outbound email | European Union (the Netherlands) | Privacy |
| Matrixed.Link | ISO/IEC 27001:2022 certified blockchain infrastructure platform underlying the BoltRPC Services | European Union | By contract |
7.3 Updates to the Sub-Processor List. We may from time to time engage additional sub-processors. Where we do so in connection with the provision of the Services to enterprise customers under a Data Processing Addendum, we will notify those customers in accordance with the notice provisions of that addendum. Material changes to the list of sub-processors set out above will be reflected in an updated version of this Policy.
7.4 No Sale of Personal Data. We do not sell Personal Data and we have not done so in the preceding twelve (12) months for the purposes of the CCPA. We do not engage in "sharing" of Personal Data for cross-context behavioural advertising as defined by the CCPA.
8.1 Transfers Outside the UAE. As a controller established in the United Arab Emirates, we may transfer Personal Data outside the UAE to (a) jurisdictions that the UAE has determined to provide an adequate level of protection, or (b) other jurisdictions on the basis of an appropriate safeguard recognised under Articles 22 and 23 of the UAE PDPL, including binding contractual undertakings and the explicit consent of the Data Subject where required.
8.2 Transfers from the EEA, the UK or Switzerland. Where Personal Data of Data Subjects in the European Economic Area, the United Kingdom or Switzerland is transferred to a jurisdiction not benefiting from an adequacy decision of the European Commission or the relevant authority, we rely on the European Commission's Standard Contractual Clauses 2021 ("SCCs") (and the UK International Data Transfer Addendum or UK International Data Transfer Agreement, where applicable) as the appropriate safeguard. We also assess, on a transfer-by-transfer basis, whether supplementary measures (technical, contractual or organisational) are necessary to ensure an essentially equivalent level of protection.
8.3 Cloudflare and Google. Transfers to Cloudflare, Inc. and to Google LLC are covered by the SCCs as incorporated into their respective data processing addenda. Google LLC and certain Cloudflare entities are self-certified under the EU-U.S. Data Privacy Framework, the UK Extension thereto, and the Swiss-U.S. Data Privacy Framework, providing an additional layer of safeguards for transfers from the EEA, the UK and Switzerland to the United States.
8.4 Copies of Safeguards. You may obtain a copy of the safeguards applicable to a specific transfer by writing to [email protected], subject to redaction of commercially sensitive terms.
9.1 Retention Periods. We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements. Indicative retention periods are:
| Data Category | Retention Period |
|---|---|
| Contact form submissions and consultation requests | Up to 24 months from last contact, or longer where required to defend legal claims |
| Newsletter subscription data | Until you unsubscribe, plus 6 months for suppression-list purposes |
| Server access logs and security telemetry | Up to 90 days, except where extended retention is necessary for active investigations |
| Aggregated analytics data | Up to 14 months (Google Analytics 4 default; configurable) |
| Customer account, billing and contract data | Duration of the contractual relationship plus the statutory limitation period applicable to the relevant claim (typically up to 10 years for tax and accounting records) |
9.2 Anonymisation. Once retention is no longer required, we will either delete Personal Data securely or render it anonymous in such a manner that the Data Subject is no longer identifiable.
10.1 Technical and Organisational Measures. We implement technical and organisational measures appropriate to the risks presented by our processing activities, including: (a) encryption of data in transit using TLS 1.2 or higher; (b) firewalling and rate-limiting at the network edge through Cloudflare; (c) access controls based on the principle of least privilege; (d) logging and monitoring of administrative activity; (e) regular patching of operating systems and dependencies; and (f) contractual confidentiality obligations on all personnel and contractors.
10.2 Underlying Infrastructure. The blockchain infrastructure operated under the BoltRPC brand runs on systems managed by Matrixed.Link, whose information security management system is certified to ISO/IEC 27001:2022. Certification covers, inter alia, risk management, incident response, capacity planning, change management, and operational continuity.
10.3 Personal Data Breach. In the event of a Personal Data breach, we will assess the breach and, where required by Article 9 UAE PDPL or Article 33 GDPR, notify the competent supervisory authority within the prescribed timeframe and the affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. The bot-mitigation and challenge-resolution functions operated by Cloudflare may classify individual requests as legitimate or suspicious; such classification is purely technical, operates in real time, and does not constitute automated decision-making within the meaning of Article 22 GDPR.
12.1 Rights under the UAE PDPL. Subject to the conditions and exceptions set out in the UAE PDPL, you have the following rights:
12.2 Rights under the GDPR and UK GDPR. If you are located in the EEA, the United Kingdom or Switzerland, you have substantially the same rights under Articles 15-22 GDPR (and the equivalent provisions of the UK GDPR), including the right to lodge a complaint with a supervisory authority (Section 17 below).
12.3 Rights under the CCPA. If you are a California resident, you have the rights set out in California Civil Code §§ 1798.100-1798.150, including: (a) the right to know what categories of personal information are collected, used, shared or sold; (b) the right to delete personal information; (c) the right to correct inaccurate personal information; (d) the right to opt out of the sale or sharing of personal information (noting that we do not sell or share personal information as defined by the CCPA); (e) the right to limit the use and disclosure of sensitive personal information; and (f) the right not to be discriminated against for exercising any of these rights.
12.4 How to Exercise Your Rights. To exercise any of the rights set out above, please send a written request to [email protected]. To protect your Personal Data we may need to verify your identity before responding. We will respond to verified requests within the timeframes prescribed by applicable law and at no charge, unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
13.1 Newsletter. We send a newsletter only to Data Subjects who have actively subscribed via our Website. Each newsletter contains an unsubscribe mechanism. You can also unsubscribe at any time by writing to [email protected].
13.2 No Behavioural Advertising. We do not engage in cross-site tracking for advertising purposes and we do not transmit Personal Data to advertising networks.
The Website may contain links to third-party websites, including documentation, social media profiles, and customer or partner properties. We are not responsible for the privacy practices or the content of such third parties, and we encourage you to read the privacy notices applicable to those resources.
The Website and the Services are intended for use by business professionals and are not directed at children under the age of eighteen (18). We do not knowingly collect Personal Data from individuals under the age of eighteen. If you become aware that a person under eighteen has provided us with Personal Data, please contact [email protected] and we will take appropriate steps to delete such data.
We may amend this Policy from time to time. The "Last updated" date at the top of this Policy reflects the most recent revision. Material changes will be brought to your attention by a prominent notice on the Website or, where appropriate, by email. Your continued use of the Website following the publication of an updated Policy constitutes your acknowledgement of the revised version.
You have the right to lodge a complaint with the competent supervisory authority in your jurisdiction. Without prejudice to that right, we kindly request that you contact us first at [email protected] so that we may seek to resolve the matter directly.
This Policy is governed by the laws of the United Arab Emirates, without prejudice to mandatory provisions of the data protection laws of your country of residence. Nothing in this Policy excludes or limits any rights that you may have under applicable law that cannot be excluded or limited by contract.
If you have any questions about this Policy or about the processing of your Personal Data, please contact us at: