Superseded — version 1.0 is not the text currently in force. It is published here because Section 14 of the Terms undertakes that every version we have published remains available. Records issued while this version was in force are governed by it.
The current text is at /legal/terms/.
Terms of Service
Status: v1.0, in force from 2026-08-28. Written by engineering from the running system and published without prior review by outside counsel; that review is pending, and a revised version will be published under Section 14 when it completes. Nothing here overstates what the Service does.
Version: 1.0 · Prepared: 2026-08-18 · Effective: 2026-08-28
1. Who these terms are between
These terms are an agreement between ProChatFlow LLC, a Minnesota limited liability company formed on 25 April 2025 under Minn. Stat. ch. 322C, Minnesota Secretary of State file number 1558059000024, whose registered office is on file with the Minnesota Secretary of State ("ProChatFlow", "we") and the organisation that creates an account ("Customer", "you"). If you accept them on behalf of an organisation, you confirm you are authorised to bind it.
BurnLedger is the name of the Service these terms govern. It is a product of ProChatFlow LLC and is not a separate legal person, a subsidiary, or a party to this agreement. Where these terms describe what BurnLedger does, they describe the Service; the party bound is ProChatFlow LLC.
2. What the Service does
BurnLedger connects to datastores you register, using read-only credentials you supply, and records how many records match a query you define — once before you delete data, and once afterwards. Where the second measurement finds none, it issues a signed, independently verifiable record of both observations.
BurnLedger does not delete your data. You perform deletions in your own systems. BurnLedger observes and records.
Who may use it. The Service is offered only to organisations established outside the European Economic Area and the United Kingdom. By creating an account you represent that your organisation is not established in either, and you will tell us if that ceases to be true. We may decline or terminate an account that does not meet this.
Business decision, 2026-08-27, recorded here because two other positions rest on it: the Privacy Policy declines to appoint an Art. 27 representative on the strength of this clause, and the DPA's transfer clauses are dormant because of it. Two things this restriction does not do, which counsel should weigh: it does not prevent a customer established elsewhere from having data subjects in the EEA or UK — in which case the GDPR applies to that customer and to us as its processor, and the DPA's transfer clauses become live; and it sits awkwardly beside marketing that sells the Service on GDPR Article 17 compliance, which a regulator could read as offering services to data subjects in the Union under Art. 3(2) regardless of who we contract with.
3. What a verification record does and does not say
The scope and limits of each record are set out in Schedule A (Certificate Scope), which forms part of these terms. Schedule A is not marketing text: it states what was measured and what was not, and you agree that your reliance on any record is subject to it.
In particular, and without limiting Schedule A, a record does not establish that your query identified every copy of a data subject's information, that data in unregistered systems was deleted, or that any legal obligation has been satisfied.
4. Your responsibilities
You are responsible for:
- The credentials you supply. They must be read-only and you must be entitled to grant us access with them. We reject credentials we can prove are write-capable; for some datastores this cannot be proven from outside and we rely on your statement that they are read-only.
- The queries you define. Their accuracy and completeness determine what a record means. We execute them; we do not audit them.
- The lawfulness of the data you cause us to process, including having a lawful basis to send us identifiers of data subjects.
- Performing deletions, and for the legal sufficiency of your own compliance programme.
- Keeping your certificates. Verification is offline by design; a record you have retained can be verified after any BurnLedger outage, and after BurnLedger itself.
5. Acceptable use
You will not use the Service to obtain access to systems you are not authorised to access, to attempt to obtain a record you know to be inaccurate, or to present a record as asserting more than Schedule A says it does.
6. Fees
6.1 Price list. Fees are those published at burnledger.io/#pricing when you subscribe: Just a few at USD 1 per certificate issued, with no monthly fee; Proof at USD 349 per month for up to 1,000 certificates a month across up to 5 systems; Audit-ready at USD 1,250 per month for up to 15,000 certificates a month; and Enterprise on a written order form. The plan you hold, its limits and its price are shown in the dashboard at all times.
6.2 How you are billed. Subscription fees are billed monthly in advance. Per-certificate fees are metered and billed in arrears at the end of each billing month. Payment is by card through Stripe, Inc., our payment processor; card details are entered on Stripe's hosted page and never reach our systems. Enterprise customers are invoiced on the terms of their order form.
6.3 Taxes. Fees exclude sales, use, VAT, GST and similar taxes, which are added where we are required to collect them. You are responsible for any withholding.
6.4 Non-payment. If a payment fails or an invoice is unpaid when due, we will notify you and allow 15 days to cure. After that we may suspend the issuing of new records until the balance is paid. Records already issued are unaffected: they remain valid and verifiable, and Section 11 applies.
6.5 Changes to prices. We may change prices on at least 30 days' notice by email to the account address; a change takes effect at the start of your next billing month after the notice period. Founding-rate accounts are excluded from price increases for as long as they remain on that plan.
7. Trial
Trial accounts are granted at our discretion, not by self-service. A trial is limited to 2 registered systems, 100 certificates and 30 days, and may be withdrawn or changed at any time. Records issued during a trial remain valid and verifiable; nothing about a trial reduces the integrity of a record already issued.
8. Warranties, and the absence of them
BurnLedger warrants that it will perform the Service with reasonable care and skill, and that a record it issues accurately reports the measurements described in Schedule A.
Otherwise the Service is provided "as is". BurnLedger does not warrant that the Service will be uninterrupted or error-free, that any record will be accepted by any regulator, court or counterparty, or that your compliance obligations are satisfied by using it. To the maximum extent permitted by law, all other warranties, express or implied, are excluded.
9. Limitation of liability
Structure settled 2026-08-27 (Determination 3); figures are the positions to negotiate from and counsel owns the final wording. The reasoning is at the foot of this section because it explains why the shape is unusual.
9.1 Nothing is limited that cannot be. Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for wilful misconduct, or for anything else that cannot lawfully be limited in the Customer's jurisdiction.
9.2 General cap. Subject to 9.1, 9.3 and 9.4, each party's total liability arising out of or in connection with these terms is limited to the greater of (a) the fees paid or payable by the Customer in the twelve months preceding the event giving rise to the claim, or (b) USD 50,000.
9.3 Verification-record claims. Where a claim arises from a verification record alleged to be inaccurate, BurnLedger's liability is limited to the limit of BurnLedger's technology errors-and-omissions insurance in force when the record was issued, in place of the cap in 9.2. Such claims are subject to Schedule A, and in particular to the limits on what a record asserts.
9.4 Data protection. Liability for breach of the Data Processing Agreement or of applicable data-protection law is subject to a separate cap of twice the amount in 9.2.
9.5 Excluded in all cases. Subject to 9.1, neither party is liable for indirect, consequential, special or punitive loss, loss of profit, revenue, goodwill or reputation, howsoever arising. BurnLedger is not liable for regulatory fines or penalties levied on the Customer by any authority.
9.6 Insurance. BurnLedger intends to maintain technology errors-and-omissions insurance, including cyber cover, of not less than USD 1,000,000, and will produce a certificate of insurance on request once a policy is bound. Until a policy is bound, no such policy is in force, and the limit in 9.3 is the cap in 9.2 rather than an insurance limit. We will update this section, under Section 14, on the day cover starts.
Why this shape, recorded so it is not "simplified" later.
A flat twelve-months-of-fees cap is the industry default and is the wrong answer here in both directions. At founding-partner pricing it yields USD 1,788, which risks failing for unconscionability or failure of essential purpose in several US states, would not survive a reasonableness test under UK unfair-terms law, and is rejected on sight by enterprise procurement. Uncapped liability on a product priced at USD 349/month is equally indefensible. The floor in 9.2 is what makes the clause both enforceable and credible; the separate tier in 9.3 is proportionate to where the real risk sits without being unlimited.
The exclusion of the Customer's own regulatory fines in 9.5 is defensible on the facts rather than merely convenient: BurnLedger does not perform deletions. A fine follows from the Customer's deletion, which is the Customer's act.
9.1 concedes the standard carve-outs at the outset. Procurement will demand them regardless, and conceding them without argument is what buys credibility for the floor in 9.2.
The clause is the backstop, not the defence. What defeats an inaccurate-record claim is Schedule A — that the record never asserted the thing relied upon. That is why signing the scope statement into the certificate payload (Determination 2) ranks above this section: a contractual cap does not bind a third party who never signed these terms, and a third party reading a certificate years from now is the realistic claimant.
10. Revocation and correction
BurnLedger may revoke a record it determines was issued in error. Revocation is published as a signed statement retrievable by anyone holding the record's identifier, without authentication.
We will notify you of a revocation of your record by email to the account address and, where you have configured one, by webhook, promptly after the revocation statement is published. We cannot identify parties you have given a record to and undertake no obligation to notify them; the published revocation statement is what allows any holder of the record to check its status without our involvement.
11. Suspension and termination
11.1 By you. You may close your account at any time from the dashboard or by written notice. Subscription fees already paid for the current billing month are not refunded; metered fees accrued are billed.
11.2 By us, on notice. We may terminate on 30 days' written notice for any reason, in which case we refund any subscription fee paid for the period after termination.
11.3 By us, immediately. We may suspend or terminate without notice if you breach Section 4 or 5, if fees remain unpaid after the cure period in 6.4, if the representation in Section 2 ceases to be true, or if we are required to by law or by a court or authority. Where practicable we will tell you why.
11.4 Effect. On termination your access ends and the Data Processing Agreement governs the return or deletion of data processed on your behalf. Records issued before termination remain valid and independently verifiable; termination does not and cannot retract them.
12. Data protection
Where BurnLedger processes personal data on your behalf, the Data Processing Agreement applies and takes precedence over these terms in respect of that processing. Our own processing as a controller is described in the Privacy Policy.
13. Confidentiality, IP, publicity, force majeure, assignment, notices
13.1 Confidentiality. Each party will keep the other's non-public information confidential and use it only for this agreement, save for disclosures required by law. Your datastore credentials and query definitions are confidential information; a record you choose to give to a third party is not.
13.2 The public transparency log. BurnLedger operates a public, append-only transparency log. Every record we issue or revoke is entered in it. An entry contains a certificate identifier, a hash of the record, an entry type and a timestamp — no subject identifiers, no Customer name and no data — and entries cannot be removed. You accept this as a condition of the Service; it is what allows a record to be trusted by someone who does not trust us.
13.3 Intellectual property. We own the Service and everything in it other than your data. You own your data, your queries and the records issued to you, and you may give records to anyone. We may use anonymous, aggregate usage statistics to operate and improve the Service.
13.4 Publicity. Neither party will name the other in marketing without written consent, except that you may state that your records were issued by BurnLedger, which is already printed on them.
13.5 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment of fees already due.
13.6 Assignment. Neither party may assign this agreement without the other's consent, except to a successor to substantially all of its business on written notice.
13.7 Notices. Notices to you go to the email address on your account. Notices to us go to legal@burnledger.io. A notice is effective when sent, unless it bounces.
13.8 Whole agreement. These terms, Schedule A, the Data Processing Agreement and any order form are the whole agreement between the parties on their subject matter. If any part is unenforceable, the rest stands.
14. Changes to these terms
We may change these terms. For a material change we will give at least 30 days' notice by email to the account address and by publishing the new version, with its version number and effective date, at burnledger.io/legal/. Using the Service after the effective date is acceptance; if you do not accept, close your account before that date and Section 11.1 applies. Records already issued are governed by the terms in force when they were issued, and every version we have published remains available at that address.
15. Governing law and disputes
These terms are governed by the laws of the State of Minnesota, without regard to its conflict-of-laws rules, and the United Nations Convention on Contracts for the International Sale of Goods does not apply. Any dispute arising out of or in connection with these terms will be brought exclusively in the state or federal courts sitting in Hennepin County, Minnesota, and each party submits to their jurisdiction. Before filing, the parties will try in good faith to resolve the dispute between senior representatives for at least 30 days. Nothing in this section prevents either party from seeking urgent injunctive relief in any competent court.
Schedule A — Certificate Scope
The Certificate Scope statement is incorporated here in full. It is the text printed in the "Scope and Limitations" block of every certificate we issue, it is reproduced verbatim by the public verifier at burnledger.io/verify/, and from certificate format 4.0 it is signed into the certificate payload. The version that binds a given record is the one that record carries.