← preblock.io Privacy · GDPR Art. 13 DE · EN

Privacy Policy

GDPR Articles 13, 14 · Version 2026-07-06

Governing language: The German version (Datenschutzerklärung) is legally binding. This English translation is provided for convenience only.

1. Data Controller

Joachim Richter-Steidl
Süderwürden 10, 27570 Bremerhaven, Germany
Email: sales@preblock.io

A Data Protection Officer is not required under § 38 BDSG (below the statutory threshold).

2. Data We Collect and Process

Server logs (Art. 6(1)(f) GDPR — legitimate interest): hashed IP address (rotating daily salt, non-reversible), user agent (truncated 200 chars), referrer URL, timestamp (UTC), requested URL, ISO country code (from IP geolocation, no precise location). Retention: 90 days, then automatic deletion.

Newsletter (Art. 6(1)(a) GDPR — consent): email address only, double opt-in required. You can unsubscribe any time via the link in every newsletter or by emailing sales@preblock.io.

Inquiry form / purchase (Art. 6(1)(b) GDPR — contract): name, email (required); company, country, tier, hashrate range, pool setup, message (optional); for paid tiers: full billing address (street, postcode, city, country) — required by § 14 German VAT Act. Retention: 10 years for invoice-relevant data (§ 147 AO / § 257 HGB); otherwise up to 12 months after contract end.

Bitcoin payments via BTCPay Server (Art. 6(1)(b) GDPR): processed on our self-hosted pay.preblock.io — no external payment processor. Stored: invoice number, amount, timestamp, payment blockchain address.

Card / wallet payments via Stripe (Art. 6(1)(b) GDPR): processed by Stripe Payments Europe, Ltd. (Ireland). When you choose the "Card / wallet" payment option, you are redirected to Stripe's checkout page. We transmit to Stripe: name, email, billing address, amount, invoice number, country, optionally VAT ID. Stripe additionally processes payment details (card number, PayPal account) — we never see these; we only receive a payment confirmation (session ID and status). Stripe privacy policy: stripe.com/privacy. Stripe may transfer data to its US parent company (certified under the EU-US Data Privacy Framework).

Discord community (Art. 6(1)(a) and (f) GDPR): optional. Discord Inc. (USA) processes the data under its own privacy policy.

3. Data Processors and External Services

We use the following processors under data processing agreements (DPA) or equivalent legal frameworks:

Third-country transfers occur only to countries with an adequacy decision under Art. 45 GDPR (currently the USA under the EU-US Data Privacy Framework for certified companies) or with supplementary safeguards under Art. 46 GDPR (Standard Contractual Clauses).

4. Cookies and Local Storage

Our sites use no tracking cookies and no analytics such as Google Analytics.

Browser localStorage is used to store your language preference (DE/EN) and for the newsletter double opt-in. This data stays on your device and is not sent to us.

5. Your Rights Under GDPR

You may exercise these rights at any time by email to sales@preblock.io:

You also have the right to lodge a complaint with a supervisory authority. Our competent authority is:

Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen
Arndtstraße 1, 27570 Bremerhaven, Germany
datenschutz.bremen.de

6. Security

We implement technical and organisational measures under Art. 32 GDPR: TLS encryption (HTTPS) via Let's Encrypt · WireGuard VPN tunnel to the internal reference node · bcrypt hashing (rounds 12) for API keys (plaintext never persisted) · role-separated systems (public vs internal ops) · encrypted backups at rest.

Version: 2026-07-06 · Joachim Richter-Steidl · PreBlock · Süderwürden 10 · 27570 Bremerhaven · Germany