BlockACountry

Legal

Privacy Policy

Version 1.0 · Effective 2026-08-16

Controller and roles

Poslovne storitve, Marc Jeroen Witteveen s.p. is controller for accounts, billing, support, public-site operations, and service security. For customer Website protection telemetry processed under customer instructions, Block A Country may act as processor or service provider; the customer remains responsible for its own notices and lawful instructions.

Public visitors

Web servers and security infrastructure may process IP address, request metadata, timestamps, and diagnostic logs for delivery, abuse prevention, and legitimate security interests. The audited marketing site does not load optional analytics or advertising trackers. Contact submissions are used to answer the selected request and should be retained only as operationally necessary.

Registered users

We process name, email, password hash, email-verification state, passkeys, two-factor settings, account membership, roles, security events, and activity metadata to provide and protect the contracted service. Passwords and authentication secrets are not stored in readable form.

Billing

Stripe processes checkout and payment information. Block A Country stores customer, subscription, price, status, billing-period, and limited payment metadata needed for billing; it does not receive or store full card numbers. Legal obligations may require billing records to be retained.

Website and policy data

Domains, verification evidence, country decisions, trusted exceptions, targets, schedules, policy revisions, generated artifacts, checksums, frozen dataset provenance, and deployment history are processed to provide reproducible protection.

Protection telemetry

Hosted block requests may produce a reference ID, time, country when reliably supplied, normalized browser/device fields, source, reason, and rotating keyed visitor fingerprint. Request bodies, query strings, cookies, authorization headers, full referrers, raw User-Agent strings, and persistent raw IP addresses are excluded. Retention follows Plan-configured event and metric periods.

Cloudflare

Cloudflare OAuth uses state and PKCE and requests configured account/zone scopes. Encrypted tokens, provider account and zone identifiers, mappings, deployment state, read-back checksums, and supported aggregate analytics are used for discovery, deployment, verification, and reporting. Disconnect attempts revocation and removes local credentials while preserving necessary history.

Google API data

Google OAuth uses minimum configured scopes for identity, read-only GA4 discovery/import, Search Console or Site Verification ownership evidence where enabled. Tokens are encrypted. Imported properties, streams, aggregate metrics, and ownership evidence are used only for Website setup, analytics, and verification; they are not sold or used for advertising. Disconnect revokes access and clears credentials while historical associations and imported aggregate data are preserved until account deletion or applicable retention cleanup.

Recipients and transfers

Confirmed service providers appear on the Subprocessors page. Customer-directed Cloudflare and Google integrations process data under their own service terms. International transfers must use the provider’s documented transfer mechanism where required; production hosting, email, monitoring, backup locations, and safeguards require verification before launch.

Retention and deletion

Account data lasts while the account is active and for necessary legal, security, dispute, and backup periods afterward. Short-term block events and longer aggregate metrics follow plan retention. Policy, configuration, and deployment evidence may be retained for audit and reproducibility. Users can correct profiles and use account deletion controls; some billing and security records may be retained when legally necessary.

Your rights

Depending on law, you may request access, rectification, erasure, restriction, portability, objection, or withdrawal of consent, and complain to a supervisory authority. EU/EEA users may contact the Slovenian Information Commissioner. Canadian users may request access/correction or raise concerns under applicable federal or provincial law. US users can use the Privacy Choices process.

Children and automated decisions

The service is intended for business and professional Website operators, not children. We do not knowingly seek children’s data. The service does not make legal or similarly significant decisions about registered users through automated profiling.