Effective: 8 August 2026Version: 1.1Applies to: onchainbridges.com
This Privacy Policy governs the processing of personal data carried out by Onchain Bridges in connection with the website identified above. It is issued having regard to Regulation (EU) 2016/679 (the “GDPR”) and to Directive 2002/58/EC as implemented in the applicable member state.
This Policy applies to personal data processed by the Controller by reason of a visit to, or use of, this website.
1.2
This Policy does not extend to (a) the Onchain Bridges testnet application, which is a separate interface having a different data profile; (b) any public blockchain, which is operated by no single party; or (c) any third-party website reached by means of a hyperlink from this website.
1.3
Onchain Bridges is a pre-mainnet project. This website is informational. It does not effect transactions, does not take custody of assets, and does not constitute an offer of, or an invitation to acquire, any security or other financial instrument.
Onchain Bridges, being the person which determines the purposes and means of the processing described in this Policy. See clause 3.
Personal data
Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
Processing
Any operation performed on personal data, as defined in Article 4(2) GDPR.
Processor
A person which processes personal data on behalf of the Controller, as defined in Article 4(8) GDPR.
Wallet address
A public identifier on a blockchain network which is capable of being linked to a natural person, and which is accordingly treated in this Policy as personal data where it is associated with other data held by the Controller.
The Controller is Onchain Bridges. Enquiries concerning this Policy may be addressed to the Controller by means of the contact form or to ilan@onchainbridges.com.
3.2
The Controller has not appointed a Data Protection Officer. The criteria in Article 37(1) GDPR are not met: the Controller is not a public authority, its core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, and it does not process special categories of data on a large scale.
Controller. The Controller is Onchain Bridges, a company registered in the State of Delaware, United States. Its registered office and registration number will be added on completion of legal review.
The Controller processes only the categories of personal data set out in the table below. No other category is collected by means of this website.
Category
Circumstances of collection
Purpose
Name, electronic mail address, stated role and message content
Upon submission of the contact form, and not otherwise
To consider and respond to the enquiry.
Message content submitted to the concierge, and wallet address where a wallet is connected
Upon use of the concierge, and not otherwise
To generate a response and to determine the on-chain compliance status of the address supplied.
Server log data, comprising IP address, time of request, resource requested and user-agent string
Upon each request to the server
Security, prevention of abuse and maintenance of the service.
First name, last name and email address
Upon submission of the document-download form, and not otherwise
To verify control of the address, deliver the requested document, and follow up about that document.
Analytics data, as described at clause 5
Only where consent has been given
Measurement of use of the website.
4.2
The Controller does not serve advertising, does not set advertising cookies, does not sell, rent or licence personal data, does not purchase contact lists, and does not enrich data supplied by a Visitor with data obtained from data brokers.
4.3
Visitors are requested not to submit special categories of personal data within the meaning of Article 9 GDPR by means of the contact form or the concierge.
This website uses Google Analytics 4, a service operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
5.2
Cookies are not set upon arrival. No analytics script is loaded, and no request is transmitted to any Google domain, unless and until the Visitor has given consent by means of the notice presented on first visit. Where consent is refused, no analytics cookie is set and no analytics data is transmitted.
5.3
The names, purposes and durations of the cookies concerned are set out in the Cookie Policy.
5.4
Consent may be withdrawn at any time, by the same means and with no greater effort than was required to give it, by means of the Cookie settings control appearing in the footer of every page. Withdrawal takes effect immediately, causes the cookies to be deleted and prevents further collection. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.5
The record of the Visitor’s consent decision is retained in the browser’s local storage under the keys ob_consent and ob_consent_at. That storage is strictly necessary in order to give effect to the decision recorded and is exempt from the consent requirement on that basis. It contains no identifier and is not transmitted.
5.6
The typefaces used on this website are served by the Controller and are not requested from any third-party font service. No IP address is disclosed to a font provider by reason only of a visit.
Contact form and concierge data: legitimate interests pursuant to Article 6(1)(f) GDPR, being the interest of the Controller in responding to a person who has deliberately initiated contact and in operating a demonstration which that person has elected to use.
6.2
Server log data: legitimate interests pursuant to Article 6(1)(f) GDPR, being the interest of the Controller in operating the service securely and in preventing abuse.
6.3
Analytics: consent pursuant to Article 6(1)(a) GDPR and to the national provisions implementing Article 5(3) of Directive 2002/58/EC. Consent is not a condition of access to this website or to any part of it.
6.4
Document-download requests: legitimate interests pursuant to Article 6(1)(f) GDPR, being the interest of the Controller in delivering a document the person has expressly requested, in verifying that the address supplied is controlled by that person, and in following up about the document requested. The person may object to further contact at any time, and every follow-up message identifies a means of doing so.
Subject to review. The balancing assessments underlying the legitimate interests asserted at clauses 6.1, 6.2 and 6.4 are to be confirmed on legal review.
Processor. Transmission occurs upon submission only.
Anthropic (United States)
Concierge message text
Processor. The concierge is built upon Anthropic’s Claude model.
Google Ireland Limited (Ireland, with onward transfer to the United States)
Analytics data, including IP address, pages viewed, approximate location derived from IP address, and device and browser characteristics
Subject to consent under clause 5.
Postmark (ActiveCampaign, United States)
Email address and the content of the verification and document emails
Processor. Transmission occurs upon submission of the download form and upon each email sent.
IONOS (Germany)
Server log data
Processor. Hosting of the website.
7.1
Personal data is not sold. No recipient is permitted to process the data for its own purposes save to the extent described in the published terms of the service concerned.
7.2
Personal data may be disclosed where disclosure is required by law or by order of a competent authority.
Formspree, Anthropic, Google and Postmark are established in, or transfer data to, the United States. Such transfers are made on the basis of the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
8.2
A copy of the safeguards relied upon may be requested from the Controller using the details at clause 16.
Contact form correspondence: retained for the period during which the enquiry is under consideration and for a period of 24 months thereafter, and erased earlier upon request.
9.2
Concierge message content: not retained by the Controller beyond the browser session, save in server logs.
9.3
Server log data: access logs are rotated daily and retained on the server operated by the Controller for a maximum of 15 days (the current day and 14 rotated generations). Error logs are retained for 14 rotated generations; because rotation is skipped on days without entries, those generations may span a longer calendar period. These periods apply to the logs held on the Controller’s server; any retention applied by the hosting provider at its own infrastructure level is governed by that provider’s practices.
9.4
Analytics data: event-level data is retained by Google Analytics for 2 months and user-level data for 14 months, in accordance with the data-retention settings configured in the Google Analytics property, after which it is deleted automatically by Google. These periods do not affect Google’s standard aggregated reports.
9.5
Document-download records: retained for 24 months from the Controller’s last interaction with the person, and erased earlier upon request. Verification codes are short-lived and are deleted once used or expired.
Subject to the conditions and exceptions in the GDPR, a data subject has the rights to: access (Article 15); rectification (Article 16); erasure (Article 17); restriction of processing (Article 18); data portability (Article 20); and to object to processing carried out on the basis of legitimate interests (Article 21).
10.2
Where processing is founded upon consent, that consent may be withdrawn at any time pursuant to Article 7(3) GDPR, without affecting the lawfulness of processing carried out before withdrawal.
10.3
A request may be made using the details at clause 16. The Controller shall respond within one month of receipt, which period may be extended by two further months where necessary, in accordance with Article 12(3) GDPR. No fee is charged save where a request is manifestly unfounded or excessive.
10.4
The rights set out at clause 10.1 are subject to the limitation described at clause 11 in respect of data recorded on a public blockchain.
A public blockchain is an append-only record replicated across independently operated nodes. The Controller does not control any such network and is not able to alter or delete data recorded upon it.
11.2
It follows that, in respect of data recorded on a public blockchain, the Controller cannot give effect to a request for erasure under Article 17 GDPR or for rectification under Article 16 GDPR. This limitation is inherent in the technology and is stated here expressly rather than omitted.
11.3
This limitation extends to any compliance credential associated with a wallet address which has been recorded on-chain. Such a record is public and permanent.
11.4
A wallet address is pseudonymous rather than anonymous. It does not of itself disclose identity, but it is capable of being linked to a natural person where it is associated with other information. The Controller does not attempt to effect such a linkage.
11.5
The Controller is able to erase data which it holds off-chain, and a request under clause 10 will be given effect to that extent.
For legal review, as a matter of substance. Clause 11 states a limitation upon a statutory right. Its formulation, and the question whether any further mitigation is required, are to be confirmed by counsel before this Policy is issued in final form.
The website is served exclusively over HTTPS. The Controller applies technical and organisational measures appropriate to the risk, having regard to Article 32 GDPR.
12.2
No system is capable of being rendered wholly secure. The Controller does not warrant absolute security.
12.3
The Onchain Bridges protocol is deployed on test networks, has not been the subject of a third-party security audit, and does not take custody of private keys or of assets. Nothing on this website should be relied upon as investment advice.
This website is not directed to persons under the age of 16 and the Controller does not knowingly process the personal data of such persons. Where the Controller becomes aware that it holds such data, it shall erase it.
The Controller does not carry out automated decision-making producing legal effects concerning a data subject, or similarly significantly affecting a data subject, within the meaning of Article 22 GDPR.
14.2
The concierge generates responses automatically. It does not determine any right or entitlement of the Visitor and produces no legal effect.
Enquiries and requests under clause 10 may be addressed to ilan@onchainbridges.com or submitted by means of the contact form.
16.2
A data subject has the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR, in the member state of his or her habitual residence, place of work or of the alleged infringement.
Status of this document. The factual statements in this Policy describe the behaviour of the website as implemented and as verified against its source code on 8 August 2026. This document has not been reviewed by external counsel. The matters marked above remain open, and the contracting entity and governing law have not been settled.