Legal
Privacy policy
We collect as little data as possible. This page explains exactly what happens when you visit our website – and what does not.
This translation is provided for convenience. Only the German version is legally binding.
- 01Controller
- 02All processing at a glance
- 03Hosting on our own server
- 04Server log files
- 05Audience measurement without cookies
- 06Partner links (redirect via /go/)
- 07Newsletter
- 08Optional reader account (knowledge dashboard)
- 09Storage in your browser
- 10Team area, administration and sign-in cookie
- 11Email to us and our mail server
- 12No third parties, no embeds
- 13Recipients, third countries, automated decisions
- 14Data security
- 15Your rights
- 16Right to lodge a complaint
- 17Do you have to give us data?
- 18Changes to this privacy policy
In short~65 sec
- 01No cookies for visitors – only people who voluntarily sign in (reader account) or belong to the team get a strictly necessary sign-in cookie.
- 02No third parties: fonts, icons and scripts are served from our own server. No Google, no CDN, no social media plug-ins. Live prices are fetched by our server – without any data about you.
- 03Audience measurement and counting of opened provider cards without cookies and without storing your IP address. We respect “Do Not Track” and “Global Privacy Control”.
- 04Partner links are counted without IP addresses. What happens on the provider’s site is governed by their privacy policy.
- 05Learning progress, stage checks, goal, checklists, tool inputs, colour scheme and motion setting stay in your browser – with an optional reader account we sync your saved items and progress between your devices.
- 06Reader account without password and without ads: sign-in via a link sent to your email address, no link to click or partner data, delete it yourself at any time.
- 07Emails to us are handled by our own mail server. By law we must keep business emails for 6 or 8 years.
Controller
- Controller
- Konrad Klar
- Address
- Stiftsweg 18
13187 Berlin
Deutschland - support@blockchain21.net
You can reach our data protection officer at: [Name und Kontakt der datenschutzbeauftragten Person]. If you have questions about data protection, you can also write to us directly: support@blockchain21.net.
All processing at a glance
The table summarises what we process. Details follow in the sections below.
| Processing · Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Server log filesDelivery, security | IP address, time, page, browser | Art. 6(1)(f) GDPR | 14 days |
| Audience measurementStatistics to improve content | page, referring domain, device class, daily ID (hash) | Art. 6(1)(f) GDPR | 400 days; ID can no longer be linked after the day ends |
| Card opensStatistics on which cards are read | provider card, page; briefly in memory: daily ID against double counting | Art. 6(1)(f) GDPR | daily totals only, no personal reference; ID can no longer be linked after the day ends |
| Partner linksCommission accounting, fraud prevention | click number, partner, page, daily ID | Art. 6(1)(f) (accounting: (c)) GDPR | 400 days; clicks with a sale per statutory retention periods |
| NewsletterSending, proof of consent | email address, language, timestamps, consent text | Art. 6(1)(a); proof (c) GDPR | until you unsubscribe, then deletion within 30 days |
| Reader account (knowledge dashboard)optional account, sync between your devices | email address, display name (optional), language, saved items, learning progress, certificates, timestamps, session cookie | Art. 6(1)(b) GDPR; cookie: § 25(2) no. 2 TDDDG | until you delete it; after 24 months without sign-in a notice, deletion 30 days later |
| Sign-in link by emailSign-in without password | email address, time, hashed IP against abuse | Art. 6(1)(b); abuse protection (f) GDPR | link valid 15 min, deleted after 1 day; hash 24 h |
| Publicly verifiable certificateProof towards third parties | verification code, type, date; your name only with consent | Art. 6(1)(b); name: (a) GDPR | until withdrawal or deletion of the account |
| Email to us (own mail server)Replying, cooperation, protection against spam and fraud | sender, recipients, content, attachments, headers, address of the delivering server | Art. 6(1)(f) (or (b)) GDPR | mail server logs 30 days; mailbox: until the matter is resolved |
| Archive of business emailsStatutory retention | incoming and outgoing emails (except spam) | Art. 6(1)(c) GDPR with § 147 AO, § 257 HGB | from year end: business letters 6 years, accounting records 8 years, other 1 year |
| Access to team mailboxesCover, clarifying transactions, compliance, technical issues | mailbox contents; log: who, when, occasion, reason | Art. 6(1)(f), (c) GDPR | log 3 years from year end |
| Browser storageFeatures you use | colour scheme, motion, learning progress, stage checks, goal, kit, checklists, tool inputs | § 25(2) no. 2 TDDDG | only on your device, until you delete it |
| Team and admin sign-inProtecting the team and admin area | username, password hash, two-factor key (encrypted), session cookie, hashed IP on login attempts | § 25(2) no. 2 TDDDG; Art. 6(1)(b), (f) GDPR | cookie 12 h (60 min without activity); login attempts 24 h; log 730 days |
| BackupsRecovery after failures | server data as above, encrypted | Art. 6(1)(f), (c) GDPR | at most 12 months |
Hosting on our own server
Blockchain21 does not run on a big cloud platform but on our own server, which we operate ourselves (location: [Standort des Servers, z. B. Deutschland]). All pages, fonts, images and scripts are served from there.
DetailsRead all details
For the internet connection we use [Anbieter der Internetanbindung]. In addition, traffic is routed through a rented virtual server at [Anbieter und Sitz des vorgeschalteten virtuellen Servers] so that the website is reachable at a fixed address. The connection to it is encrypted, and HTTPS encryption only ends on our own server. These service providers therefore only see technically necessary connection data such as IP addresses and timestamps, but no content. [We have concluded a data processing agreement pursuant to Art. 28 GDPR with the provider of the virtual server.]
Our mail server also runs on this server of our own. The virtual server forwards emails addressed to us to it, and emails from us leave via its fixed address. Whether emails are encrypted on this route also depends on the other side’s mail server – today almost all use transport encryption (STARTTLS).
Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in providing the website securely and reliably.
Server log files
When you open a page, your browser automatically sends information to our server. Our web server (Caddy) logs:
- your IP address
- date and time of the request
- the requested address and the type of request
- the status code and the amount of data transferred
- the previously visited page (referrer), if your browser sends it
- browser and operating system (user agent)
DetailsRead all details
Purpose: delivering the website, finding errors, and detecting and preventing attacks. Legal basis: Art. 6(1)(f) GDPR. Log files are deleted automatically after 14 days. We do not combine them with other data and do not create profiles from them. Only if a specific security incident has to be investigated do we keep the affected entries for as long as necessary.
Audience measurement without cookies
We want to know which pages are read so that we can improve our content. For this we use our own privacy-friendly counter – without cookies and without third parties.
DetailsRead all details
- When a page loads, a small script sends a message to our own server: the path of the page, the address of the previous page (we only store its domain name), the width of the browser window (from this and the browser identifier we only derive a rough device class such as “phone” or “desktop”) and, if present, campaign parameters from the address (
utm_source,utm_medium,utm_campaign). - Our server derives a daily ID from this: it combines your IP address and browser identifier (user agent) with a random value that is valid for one day only, and calculates a shortened one-way hash. The IP address itself is not stored.
- The random value is replaced every day and the old one is deleted. After that nobody – including us – can link the ID to an IP address or recognise you on another day.
- We store nothing on your device (no cookies, no local storage) and do not use fingerprinting.
- If you have enabled “Do Not Track” or “Global Privacy Control” in your browser, the script sends nothing at all. Without JavaScript there is no counting either.
We filter out obvious bots and unusually frequent requests. Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in improving our service based on aggregated usage figures. We delete the individual records automatically after 400 days.
Card opens: if you open a provider card in the text, we count this as a daily total per card and page – without cookies, without an identifier in the database and not at all with “Do Not Track” or “Global Privacy Control”. To avoid double counting, our server briefly checks the daily ID described above, in memory only. Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in knowing which cards are helpful.
Partner links (redirect via /go/)
We mark links to partners with an asterisk * or “Ad*”. They first lead to an address on our server (/go/…) and from there on to the provider.
DetailsRead all details
What we store when you click
- a random click number
- the partner, date and time
- the page and the position of the link, and the language
- the device class and the domain name of the previous page
- the daily ID as used for audience measurement – without the IP address
- whether the click is valid: bots, duplicate clicks and altered links are not counted as valid
We do not set a cookie.
What is passed to the provider
We redirect you to the provider’s address. If the provider runs a partner programme, this address contains our partner ID and the random click number. Your browser also tells the provider that you are coming from blockchain21.net – but not from which page. We do not pass on your name, email address or other personal details; we do not even know them.
What the provider reports back to us
If the click leads to a sign-up or purchase, the provider or its affiliate network reports the click number, the type of transaction, the amount of our commission and its status. We do not receive names, contact details or details of your purchases.
What happens at the provider
As soon as you are on the provider’s website, its privacy policy applies. Providers and affiliate networks (currently, for example, FirstPromoter, Impact, Oshi) usually use their own cookies or similar technologies there to recognise that you came via us, and may ask for your consent. They are responsible for this themselves. Our partners are listed on How we are funded.
Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in settling commissions correctly and in a tamper-proof way, and thereby funding our free service. We delete click data after 400 days. Clicks for which a sale was reported are kept together with the accounting records for as long as tax and commercial law require (Art. 6(1)(c) GDPR).
Newsletter
When you subscribe to our newsletter, we store:
- your email address and chosen language
- the time of sign-up, confirmation and, if applicable, unsubscription
- the version of the consent text you agreed to
- on confirmation, a hash of your IP address formed with a secret key, as proof – not the IP address itself
- random tokens for the confirmation and unsubscribe links
DetailsRead all details
Double opt-in: after signing up you receive an email with a confirmation link that is valid for 7 days. You are only subscribed once you confirm with it. This way nobody can sign up other people’s addresses. We delete unconfirmed sign-ups after 30 days.
Abuse protection: the form contains an invisible field and a timing check. We also limit the number of sign-up attempts; for this we store a hash of your IP address formed with a secret key – not the IP address itself – and delete it after 24 hours at the latest.
No tracking: our emails contain no tracking pixels. We do not measure whether or when you open an email or which links you click. Links to partners go through our redirect just like on the website – without any connection to your email address.
Content: new articles and tools, important changes such as regulation and tax, security tips and occasionally offers from our partners – always labelled as advertising.
Sending: we send the emails via our own mail server, which runs on our server alongside the website.
Legal basis: your consent (Art. 6(1)(a) GDPR). Logging the sign-up serves as proof of your consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).
You can unsubscribe at any time via the link in every email or by sending a short message to support@blockchain21.net. You will then receive no further newsletters, and we delete your address completely within 30 days. Withdrawal does not affect the lawfulness of processing before the withdrawal.
Optional reader account (knowledge dashboard)
You do not need an account – all content and tools work without one. If you like, you can create a free reader account: your knowledge dashboard with saved items, learning progress and certificates on all your devices.
DetailsRead all details
Sign-in link instead of a password
You enter your email address and we send you a sign-in link. It is valid for 15 minutes and works only once; the account is created when you first use it. The email only contains the link – no ads, no partner links. If you did not request the link, simply ignore the email: without using it, no account is created. We delete requested links after one day.
To prevent abuse, we limit the number of sign-in links per address, per connection and in total per day. For this we store a hash of your IP address formed with a secret key – not the IP address itself – and delete it after 24 hours at the latest. Under the GDPR, such a hash is still personal data.
What we store
- your email address, a display name if you want one, your language
- the time of registration, address confirmation and last sign-in
- the version of this privacy information shown to you when you registered
- your saved items and learning progress (stages, checks, goal, kit, checklists), as far as you sync them
- registered certificates with a verification code – your name on them only if you explicitly want this
- a session cookie (
__Host-b21_konto) that keeps you signed in for 30 days
No link to advertising: we do not connect your account with audience measurement, clicks on partner links or commission data. We do not build profiles and do not send you advertising through the account.
Sync between your devices
Your browser remains the main source. When you are signed in, the site syncs your saved items and progress with our server. If a browser already holds progress, we ask on the first sync whether it should be added to your account.
Publicly verifiable certificate
The learning-path certificate is created only in your browser. If you voluntarily register it, anyone with the verification code can see which type of certificate was issued when and whether it is still valid. We only show your name there if you explicitly consent. You can withdraw your consent at any time; we then remove the name.
Deletion
You can delete your account yourself at any time. We then delete it immediately together with saved items, progress and sessions; registered certificates are revoked and the name removed. Beforehand you can download all your data as a file. If you have not signed in for 24 months, we send you a notice and delete the account 30 days later. In our encrypted backups the data remains for at most 12 months; if we ever had to restore a backup, we would delete accounts deleted in the meantime again.
Legal basis: Art. 6(1)(b) GDPR – the terms of use for the optional account. The session cookie is strictly necessary for the sign-in you use (§ 25(2) no. 2 TDDDG). Abuse protection: Art. 6(1)(f) GDPR. Name on the certificate: your consent (Art. 6(1)(a) GDPR).
Storage in your browser
Some features remember settings directly in your browser (local storage):
- your colour scheme (light or dark), if you switch it yourself –
b21-theme - your “Reduce motion” setting from the footer –
b21-motion - articles or learning-path steps you have read and your learning progress –
b21-read - results of the stage checks on the learning path (best score per stage) –
b21-checks - your goal from the goal compass or “Save as my goal” –
b21-goal - items ticked in “Your kit” on the learning-path page –
b21-kit - your personal knowledge blockchain (article keys, timestamps and SHA-256 hashes of completed articles) –
b21-chain; delete it via the learning path (“Reset”) or your browser data - your optional country choice for matching partner offers –
b21-country - that you already closed the “Pre-launch” notice during this visit (version and time), so it doesn’t reappear on every page –
b21-aufbau; only for the duration of the visit (sessionStorage), deleted when you close the tab - ticked items in checklists –
b21-check-… - inputs or results of individual tools, if the tool offers this (e.g. holding period calculator, goal compass, best score in the quiz) – keys start with
b21-
DetailsRead all details
This data never leaves your device. It is not transmitted to us or to third parties, and we cannot see it – unless you have a reader account and are signed in: then we sync your saved items and learning progress with our server. You can delete the data in your browser at any time using the reset buttons or by clearing the site data for blockchain21.net in your browser.
Legal basis: § 25(2) no. 2 TDDDG – storage is strictly necessary for the feature you explicitly use, for example a checklist you tick off.
Team area, administration and sign-in cookie
The protected team and admin area (/team/, /admin/) is only accessible to our team. Signing in requires a username and a password; team accounts always confirm it with a two-factor code as well. After that we set a session cookie (__Host-b21_staff) that expires after at most 12 hours and after 60 minutes without activity. Website visitors never receive this cookie. To protect against password attacks, we store login attempts with a hash of the IP address formed with a secret key for at most 24 hours. Sign-ins and important administrative steps are recorded in an admin log for accountability – also only with this hash, never with the IP address itself – and deleted after 730 days.
How we process our team members’ data (sign-in, mailboxes, access logs) is described in an internal policy that every team member receives and confirms before first accessing a mailbox.
Legal basis: § 25(2) no. 2 TDDDG for the cookie; Art. 6(1)(b) and (f) GDPR for sign-in, protection and logs.
Email to us and our mail server
If you email us, we process your email address, your name (if provided), the content and any attachments in order to reply. The same applies to emails from partners, service providers and authorities. We deliberately do not use a contact form. Please do not send us sensitive data – and never your seed phrase, passwords or 2FA codes.
DetailsRead all details
Our own mail server
Emails to addresses at blockchain21.net are received and sent by our own mail server, which runs on our server alongside the website – we do not use an external email provider. Besides the content, the mail server processes sender and recipient addresses, timestamps, technical headers and the IP address and name of the delivering mail server. We delete its logs (connections, deliveries, access by the application) after 30 days. The mail server notifies our website of new emails using technical identifiers only, so that the team can see them.
Protection against spam and fraud
The mail server automatically checks every incoming email: whether it really comes from the stated domain (SPF, DKIM, DMARC – for this it queries the sender domain’s DNS), whether the delivering server is on public blocklists ([abgefragte Sperrlisten und Sitz ihrer Betreiber]; only the address or domain of the delivering server is transmitted) and whether content and structure suggest spam. Emails recognised as spam go to a spam folder and are deleted automatically after [Anzahl] days. For our domain the mail server also creates and receives technical delivery reports (DMARC and TLS reports) with IP addresses of mail servers and message counts, but no content. We do not automatically load images from the internet in emails we receive.
Who reads your email
Your email is read by the team members responsible for the mailbox concerned. They sign in only via our website, with a password and – always for team accounts – a second factor. Our mailboxes may only be used for business purposes. If a team member is absent or a matter needs to be clarified, the administration can view a mailbox – only for defined occasions (cover, a specific business matter, compliance, technical issues, legal obligations), with a written reason, for a limited time and fully logged. We keep these logs for 3 years after the end of the calendar year.
Retention
Business emails are commercial and business letters that tax and commercial law require us to keep. We therefore archive incoming and outgoing emails – except spam – in a tamper-proof way: business letters for 6 years, accounting records such as invoices and commission statements for 8 years, automatic reports and notifications for 1 year, each from the end of the calendar year. If you want us to delete your email earlier, we restrict its processing: it is then blocked from search and display and only retrievable for a tax audit or legal dispute; we delete it when the period ends (Art. 17(3)(b), Art. 18 GDPR). Emails that do not have to be kept are deleted once your matter has been dealt with.
Our replies
When we reply, the email goes from our mail server to the mail server of your email provider, which is responsible for it. Our emails contain no tracking pixels and no read receipts. Our signature links to this privacy information.
Legal bases: Art. 6(1)(f) GDPR – our legitimate interest in answering requests, working with partners, ensuring cover and continuity of business and protecting ourselves against spam, fraud and attacks; where a contract is concerned, Art. 6(1)(b) GDPR; for retention, Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB.
No third parties, no embeds
We do not embed any third-party content: no external fonts (no Google Fonts either), no content delivery networks, no social media plug-ins, no embedded videos, maps or charts, no ad networks and no external analytics tool. When you open our pages, your browser only connects to our own server.
Live prices and network data
Values such as the bitcoin price, the block height or current fees are fetched by our server from public interfaces: from mempool.space and, if that fails, from Bitstamp, Kraken, Coinbase, Blockstream or blockchain.info. Your browser only gets these values from our own server. We do not transmit any data about you or your visit to these data sources – neither your IP address nor your browser identifier. The request to our server appears in the server log files like any other page request.
Links to live charts and other websites
For price charts we link to live charts on TradingView, CoinGecko and mempool.space. These are plain links: nothing is transmitted to these services when our page loads. The same applies to links to sources, authorities or providers. Only when you click a link does your browser connect to the other website. Its operator then sees your IP address, among other things, and usually learns that you came from blockchain21.net – for the chart links we suppress this referrer information. The respective operator is responsible for processing there.
Recipients, third countries, automated decisions
We do not sell data or pass it on for advertising purposes. Personal data is only received by the technical service providers named above (internet connection, upstream server), to the extent that they technically come into contact with it, the recipients’ mail servers when we send emails, operators of blocklists during spam checks (only the address or domain of the delivering mail server) and authorities where we are legally obliged.
We do not transfer data to countries outside the European Union or the European Economic Area – except for blocklist queries where their operators are based there [operators and basis of transfer]. There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
Data security
The entire website is only available encrypted via HTTPS. We keep server and software up to date, restrict access to what is necessary and protect the team and admin area with a password, login rate limiting and a second factor that is mandatory for team accounts. We store two-factor keys encrypted. From outside, the mail server can only be reached to accept emails; its administration is not publicly accessible. The team area only shows HTML emails in an isolated view.
We back up the server data daily. The backups are encrypted, and the key to decrypt them is not stored on the server. We keep them for at most 12 months and regularly check that they can be restored.
Above all, we collect as little data as possible: data that does not exist cannot be lost.
Your rights
You have the following rights regarding your personal data:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR), for example for the newsletter
Simply write to support@blockchain21.net. If you have a reader account, you can also download your data and delete the account yourself.
Much of our data is designed so that we cannot attribute it to a person – for example the daily ID after the day has ended. In such cases we can only fulfil requests for access or erasure if you provide additional information that allows identification (Art. 11 GDPR).
Where we must keep data for legal reasons – such as business emails – we restrict its processing at your request instead of deleting it, and delete it when the retention period ends.
Right to object (Art. 21 GDPR)
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
You may object to the use of your data for direct marketing – i.e. the newsletter – at any time without giving reasons. An informal message to support@blockchain21.net is sufficient. For audience measurement you can also enable “Do Not Track” or “Global Privacy Control” in your browser.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de.
Do you have to give us data?
You are not obliged to provide us with personal data. A reader account is optional; all content and tools work without one. Without an email address, however, we cannot send you a newsletter or a sign-in link or reply to you. Server log files arise for technical reasons – the website cannot be delivered without them.
Changes to this privacy policy
We update this privacy policy when our website or the legal situation changes. The version published here applies. You can see the date of the current version at the top of this page.