Privacy Policy
Version: August 2026
Translation notice: This English version is provided for convenience. The German Privacy Policy remains the authoritative legal text.
1. Controller
Varga-Tech – Attila Varga
Leipziger Str. 3, 37085 Göttingen
Email: vargatech@attila-varga.eu
Phone: +491728400913
2. Hosting and server logs
The application is hosted by Varga-Tech, Leipziger Str. 3. When the website is accessed, technically necessary data such as IP address, timestamp, requested URL, referrer, browser identifier and status code are processed. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is secure and uninterrupted operation. Security logs are generally deleted after 30 days unless an incident requires longer retention.
3. Registration and magic link
For sign-in we process your email address, a time-limited token, IP address, browser identifier and login timestamps. The token is stored only as a hash and cannot be reused after use or expiry. The legal basis is Art. 6(1)(b) GDPR; security data is additionally processed under Art. 6(1)(f) GDPR.
4. SMTP email delivery
Emails are sent via send.one.com, noreply@attila-varga.eu. In particular, the recipient address, sender, subject, content and technical delivery data are processed. Sellers may store a separate notification address and configure individual notifications for rental start, pool changes and rental end. A different address is used only after confirmation through a time-limited token stored as a hash. The legal basis is Art. 6(1)(b) GDPR where the message is necessary for contract performance; optional convenience settings additionally rely on Art. 6(1)(a) GDPR and can be changed at any time in the profile.
5. Customer account, orders and invoices
We process master data, billing address, pool and worker data, order numbers, payment status, service periods, invoices, complaints and communication data. For on-chain payments we also process the publicly visible sender address, transaction ID, block/confirmation data, payment amount and the conversion rate used where required to match the payment and perform the contract. Processing is carried out for pre-contractual steps and contract performance under Art. 6(1)(b) GDPR and to meet commercial and tax-law obligations under Art. 6(1)(c) GDPR. Invoices and tax-relevant documents are retained for the statutory retention periods.
6. Seller/provider data
For providers we process identity, company, address, tax and bank details, rig data, performance metrics and settlements. The legal bases are Art. 6(1)(b) and (c) GDPR. Provider profiles are manually reviewed before activation.
7. PayPal
Payments are processed using PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. When PayPal checkout is started, order number, amount, currency, service description and technical data are transmitted to PayPal. PayPal processes data as an independent controller and may also process data outside the European Economic Area. PayPal components are loaded only after your explicit action in checkout. The legal basis for payment processing is Art. 6(1)(b) GDPR.
8. Stratum and performance data
To provide and account for hashrate we process connection timestamps, rig tokens, target pool, worker identifier, share difficulty, accepted and rejected shares, live hashrate, connection interruptions and routing status. Mining passwords are stored encrypted. The legal basis is Art. 6(1)(b) GDPR; security and abuse detection additionally rely on Art. 6(1)(f) GDPR.
9. Cookies and local storage
We use a technically necessary HTTP-only protected session cookie. It is used for sign-in, CSRF protection and account functions and is permitted without consent under § 25(2) TDDDG. Your selection for loading external PayPal components is stored locally in the browser. Analytics, marketing or profiling cookies are not integrated by default.
10. Recipients
Data is disclosed only to parties that need it for operation, payments, email delivery, accounting, legal advice or statutory obligations. Where required, data-processing agreements are concluded with processors acting on our instructions.
11. Security
We use TLS, encrypted secrets, separated services, access restrictions, audit logs, rate limits, secure session cookies and blocks for private pool targets. Absolute protection cannot be technically guaranteed.
12. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority.
13. No automated decision-making
No decision producing legal or similarly significant effects is made solely by automated means. Provider approvals and material dispute decisions are handled manually.
14. Changes
We update this policy when services, the legal framework or processing activities change. The currently published version applies.