Privacy notice
This notice describes how personal data is processed when you visit 402rates.com, call its API or MCP interface, make an x402 payment, or contact the provider.
Controller
Can Inac402rates.com
c/o MDC#inac-consulting
Welserstraße 3
87463 Dietmannsried
Germany
Email: info@402rates.com
Website and API delivery
The static website is delivered through Cloudflare Pages. The API runs on a Contabo server in Germany. Caddy terminates encrypted connections and forwards requests to the Node process. Delivery, abuse prevention and error analysis can involve the IP address, time, requested address, technical connection data and error messages.
Caddy does not keep HTTP access logs for 402rates.com. The Node process does not keep a general access log either. Server operating and error events are stored in the system journal. Under the operator policy, journal records are retained for no more than 30 days and rotated into a new journal file daily.
The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure, stable and traceable delivery of the service.
Cloudflare Web Analytics
The website uses Cloudflare Web Analytics for aggregate measurements of page views and loading performance. Cloudflare may add a JavaScript beacon when delivering the page. 402rates.com does not set cookies for this purpose and does not create individual user profiles. Cloudflare states that Web Analytics does not collect or use personal data from website visitors. According to its published product description, unaggregated beacon data is retained for seven days and dashboard analytics can cover up to six months.
To the extent that the technical transmission nevertheless processes personal data, the legal basis is Article 6(1)(f) GDPR. The legitimate interest is privacy-preserving measurement of reach and technical performance.
Cloudflare information: Web Analytics and Privacy policy.
Free API calls and abuse prevention
Free calls are rate-limited so that individual clients cannot overload the service. The general protection uses a client identifier determined by the server in volatile memory. It is effective for rate limiting for one minute. An expired entry can remain in memory until the same identifier is used again, capacity cleanup runs, or the process restarts. It is not stored persistently.
The breadth limit for instrument and history views processes a client identifier hashed with a salt generated only for the respective process. It uses a rolling one-hour window. Only aggregated event counts without a client identifier are stored persistently. The legal basis is Article 6(1)(f) GDPR. The legitimate interests are abuse prevention, availability and separating free individual queries from the paid complete snapshot.
Synthetic agent test runs
The purposes are to provide the requested synthetic run, reconstruct its observed sequence and enable an optional comparison with a previous run. Separate aggregate counts measure use of the test and repeat flow. Where personal data are involved, provision of a requested contractual service relies on Article 6(1)(b) GDPR where applicable; operational measurement and abuse prevention rely on Article 6(1)(f). The legitimate interests are reliable test delivery, proportionate capacity management and understanding whether the test and repeat flow are used.
The free synthetic test stores run and task identifiers, timestamped test events, synthetic operation records, hashed action keys and a hashed access token. An optional linked repeat references a previous run and can include a caller-declared configuration change. No model prompt, model credential, wallet or real purchase is needed. Run access expires 24 hours after creation; expired records are removed when the test store opens and by its 30-second maintenance cycle while running. A repeat does not extend the earlier run's retention. Downloaded reports remain under the holder's control.
Separate aggregate counters contain day, case version, transport, internal or unattributed origin, event type and count. They contain no run identifier, token or wallet address. They cover the current and previous 29 UTC days; cleanup runs on worker startup, writes and once per minute. Client software may retain MCP tool arguments, including the short-lived token, in its own history. General delivery and abuse-prevention processing is described above.
Paid x402 calls
402rates.com provides data and calculation services only. For a paid API call, the payment proof and settlement are processed through the x402 facilitator identified in the payment requirement and the selected public blockchain. 402rates.com does not hold user assets, maintain payment accounts or transfer money between third parties.
Execution, error handling, idempotency and internal demand analysis can involve the network, transaction identifier, capability, payment rail, public payer address, price, time, and classification as an own or external payment. A payer address is treated as potentially personal data even though it and the transaction are publicly visible on a blockchain. The internal demand journal and internal Base reports are retained for no more than 24 months.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to perform the paid data call. Abuse prevention, technical error analysis and operational demand analysis rely on Article 6(1)(f) GDPR. Records subject to statutory retention are stored for the applicable legal period under Article 6(1)(c) GDPR.
Email contact
Messages sent to info@402rates.com are forwarded through Cloudflare Email Routing to a Gmail mailbox. This processes the sender and recipient addresses, time, technical delivery data and message content. Pre-contractual or contractual communication relies on Article 6(1)(b) GDPR. Other business enquiries rely on Article 6(1)(f) GDPR.
Messages are normally deleted twelve months after the enquiry is closed. Messages required under contract or tax law can remain stored in restricted form until the applicable statutory retention period expires.
Recipients and international processing
Depending on use, the following recipients or categories receive data to the extent necessary for the respective purpose:
- Contabo GmbH for hosting the API server in Germany;
- Cloudflare for website delivery, security functions, Web Analytics and email forwarding;
- Google for the Gmail destination mailbox;
- the x402 facilitator identified in the payment requirement;
- participants in the selected public blockchain.
Cloudflare, Google and facilitators can process data outside the European Economic Area, in particular in the United States. Where applicable, a transfer relies on an adequacy decision for certified recipients or other safeguards under Chapter V GDPR. Public blockchains operate globally and published transactions generally cannot be deleted retrospectively.
Retention summary
| Processing | Retention period or criterion |
|---|---|
| Caddy access logs | Disabled |
| Server and application messages | No more than 30 days |
| Cloudflare Web Analytics | Unaggregated beacon data: seven days; dashboard analytics: up to six months |
| General free rate limit | Volatile, until one of the deletion events described above |
| Hashed breadth limit | One hour |
| Internal payment demand journal and Base reports | No more than 24 months |
| Synthetic test runs and links to earlier runs | Access ends 24 hours after creation; cleanup on store opening and its 30-second maintenance cycle |
| Aggregate synthetic test counts | Current and previous 29 UTC days; cleanup on worker start, writes and its one-minute maintenance cycle |
| Contact emails | Twelve months after closure, subject to statutory duties |
| Public blockchain | Under the immutable rules of the respective network |
Source of data not collected directly
Wallet and transaction data come from the payment proof submitted by the caller, the facilitator response and the public blockchain. 402rates.com does not connect these data to a civil identity unless that identity is independently provided in a business communication.
Required data and automated decisions
A free call does not require further personal information. A paid call requires a technically valid payment proof. Without it, the paid response cannot be delivered. No decision based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR takes place.
Your rights
Where the statutory conditions are met, data subjects have rights of access, rectification, erasure, restriction of processing, data portability and objection. An objection to processing based on Article 6(1)(f) GDPR can be sent to info@402rates.com.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority. For private-sector controllers in Bavaria, this includes the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Last updated
9 September 2026. Changes to services, recipients or retention periods will be reflected in this notice before they are used in production.