Logo
Pontus-X Portal ↗

Privacy Policy

This privacy policy informs you about how deltaDAO AG (in the following deltaDAO, we, us, our) processes your personal data when you visit and use our demonstrator and when you contact us. Moreover, this privacy policy informs you about your rights.

Last updated on October 09, 2023.

1. Contact details of the controller and Data Protection Officer

The controller pursuant to the EU General Data Protection Regulation ("GDPR") for the processing of your personal data is:

deltaDAO AG
Katharinenstraße 30a
20457 Hamburg
Germany
E-mail: contact@delta-dao.com

If you have any questions about the protection of your personal data at deltaDAO, please contact our Data Protection Officer:

Data Protection Officer
deltaDAO AG
Katharinenstraße 30a
20457 Hamburg
Germany
E-mail: privacy@delta-dao.com

2. What's personal data?

Personal data is any information that can be (directly or indirectly) related to you. We process the following personal data.

  • IP address: Your IP address is processed when visiting and using our demonstrator.
  • E-mail address: Your e-mail address is processed if you contact us via mail. We will also process additional personal data about you if you provide them in your message (such as your name).

You can find further information about the processing of your personal data in the chapter “Processing operations according to Article 13 GDPR”.

3. Recipients and cross-border data transfer

Visiting and using our demonstrator
When visiting and using our demonstrator, your IP address is processed by Netlify, Inc (located at 44 Montgomery Street, Suite 300, San Francisco, California 94104, USA), a service provider that hosts our demonstrator. Our demonstrator is served by Netlify using a Content Delivery Network, a geographically distributed network, with servers within and outside of the European Economic Area (EEA). This means, if you are located within the EEA, your IP address will most likely (but not guaranteed) be processed on a Netlify server within the EEA.

There is no adequacy decision for the USA from the European Commission. However, Netlify is EU-US DPF (EU‐US Data Privacy Framework) certified. The EU‐US DPF is an adequacy decision of the European Commission, limited to certified entities. Moreover, we signed SCC with our provider. You have the right to receive a copy of these SCC. To exercise your right, please contact us at privacy@delta-dao.com.

Contact via e-mail
When you contact us via e-mail, our (mail) service provider Microsoft Corporation (located at 1 Microsoft Way, Redmond, Washington 98052-8300, USA) supports us in processing your personal data so we can communicate with you.

There is no adequacy decision for the USA from the European Commission. However, Microsoft is EU-US DPF (EU‐US Data Privacy Framework) certified. The EU‐US DPF is an adequacy decision of the European Commission, limited to certified entities. Moreover, we have restricted storage on the EEA and signed SCC with our provider. You have the right to receive a copy of these SCC. To exercise your right, please contact us at privacy@delta-dao.com.

4. Processing operations according to Article 13 GDPR

4.1 Providing our demonstrator and its functionalities and creating logfiles
We collect and use your IP address for providing our demonstrator and its functionalities. Our demonstrator is hosted externally by our service provider Netlify (see also chapter 3), which stores your IP address in a server logfile. deltaDAO does not store your data and will not receive your personal data from Netlify.

Purpose:
Collecting and using your IP address is necessary for providing our demonstrator and its functionalities because it is a technical requirement for ensuring communication between your device and our demonstrator.
Logfiles are created to troubleshoot connectivity issues, maintain security, and to ensure an error free usage of the demonstrator.

Legal basis:
The legal basis for this processing is our legitimate interest, pursuant to Art. 6(1)(f) GDPR.

Legitimate interest:
Our legitimate interest is to provide our demonstrator and its functionalities to you.
Your IP address is stored by Netlify in a logfile because of the legitimate interest in the technically error-free presentation, security, and optimization of the website.

Retention period:
Netlify stores your IP address for 30 days.

4.2 Contact via e-mail
We collect, use, and store your e-mail address and the personal data that you voluntarily provide in your e-mail (e.g., your name) when you reach out to us via e-mail. Microsoft supports us technically in providing our mail service to you (see also chapter 3).

Purpose:
Your personal data is collected, used, and stored by us to respond to your inquiries.

Legal basis:
The legal basis for this processing is our legitimate interest, according to Art. 6(1)(f) GDPR.

Legitimate interests:
Our legitimate interest is to answer your inquiries.

Retention period:
We store your personal data as long as we need it to process your inquires. We store your personal data beyond this period if we are obliged to do so due to retention obligations under tax and commercial law or in the event of legal disputes. If the latter is the case, your personal data will be erased after the retention period has expired.

5. Automated decision making including profiling according to Article 13(2)(f) GDPR

Automated decision making including profiling does not take place.

6. Cookies and web storage

A cookie is a small file that stores information in your browser. Your web browser downloads it on the first visit to a website. The next time you open this website with the same device, the cookie and the information stored in it are either sent back to the website that created it (first-party cookie) or sent to another website it belongs to (third-party cookie). This enables the website to detect that you have opened it previously with this browser and, in some cases, to vary the displayed content. Some cookies are necessary for making websites work, and others are used for enhancing your experience on the visited website. Cookies can also be used for marketing, tracking, and analytics purposes. Web storage (local storage and session storage) has similar functionality to cookies.

Our demonstrator does not use cookies or web storage for marketing, tracking, or analytics purposes. We use your web storage to remember your page preferences, enable functionalities and to enhance your user experience. Your browser will remove the session storage once you close your browser. You have the option of disabling cookies and deleting cookies and web storage from your computer's hard disk at any time in your browser settings.

7. External links

Our demonstrator contains links to external websites that are beyond the control and responsibility of deltaDAO.

8. Your rights

Pursuant to the GDPR, you have the following rights. If you wish to exercise your rights or have any questions, do not hesitate to contact us.

8.1 Right of access (Art. 15 GDPR)
You have the right to obtain confirmation about whether deltaDAO processes personal data about you. If we do so, you have the right to access these personal data along with the information defined in Art. 15 GDPR.

8.2 Right to rectification (Art. 16 GDPR)
You have the right to obtain from us the rectification of inaccurate personal data about you without undue delay. Also, you have the right to obtain from us the completion of incomplete personal data about you.

8.3 Right to erasure (Art. 17 GDPR)
You have the right to obtain the erasure of your personal data without undue delay, where the legal grounds defined in Art. 17 GDPR apply.

8.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to obtain the restriction of processing personal data about you where the legal grounds defined in Art. 18 GDPR apply.

8.5 Right to data portability (Art. 20 GDPR)
You have the right to receive from us your personal data in a structured, commonly used, and machine-readable format and the right to transmit the received data to another controller without hindrance from us, where the legal grounds defined in Art. 20 GDPR apply.

8.6 Right to object (Art. 21 GDPR)
You have the right to object to the processing of your personal data, where we base the processing on legitimate interests (Art. 6(1)(f) GDPR). We will no longer process your personal data except we can demonstrate compelling legitimate grounds, which override your freedoms, rights, and interests, or if we have to establish, exercise, or defend legal claims.

8.7 Right to lodge a complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority, especially in the Member State of your habitual residence, your place of work, or the place of the alleged infringement if you think that deltaDAO processes your personal data in a way that infringes the GDPR.

9. Questions

If you have any questions about our privacy policy, please send us an e-mail at privacy@delta-dao.com.

10. Changes to the Privacy Policy

This privacy policy will be amended from time to time. You can see the date of the last alteration at the top of the privacy policy. The latest version of this policy applies to the processing of your personal data.