Legal

Privacy Policy

This Privacy Policy explains how Northstar DeFi Consulting processes personal data in connection with this website and client communications, and informs you of your rights under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data is processed only where a legal basis under Article 6(1) GDPR exists.

1. Controller

The controller responsible for data processing on this website is:

Northstar DeFi Consulting – Philipp Bunke
Herteler Straße 25, 29643 Neuenkirchen, Germany
Email: inquiry@northstar-defi.com

2. Accessing the website and server log files

When you access this website, our hosting provider automatically collects and stores technical information that your browser transmits, in particular: IP address, date and time of the request, the page requested, referrer URL, and browser and operating-system information. This data is processed to enable the delivery of the website, to ensure stability and security, and to prevent misuse.

The legal basis is our legitimate interest in a secure and functional website (Article 6(1)(f) GDPR). Log data is deleted as soon as it is no longer required for these purposes, unless longer retention is necessary for security or as legal evidence.

3. Contact form and email

If you use the contact form or email us, we process the data you provide — such as your name, email address, Telegram handle, calendar link, project or protocol name and your message — in order to respond to your enquiry and to prepare or carry out a potential engagement.

The legal basis is the performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR) and, where your enquiry does not relate to a contract, our legitimate interest in responding to your request (Article 6(1)(f) GDPR). The form data is transmitted to us by email through our email service provider (see section 5); you also receive an automated acknowledgement email. We retain enquiry data for as long as needed to handle your request and thereafter in line with statutory retention obligations.

4. Cookies

This website uses only technically necessary cookies required to operate the site; these do not require consent (Article 6(1)(f) GDPR). We do not currently use analytics, tracking or marketing cookies. Should this change, non-essential cookies will be used only after your prior consent (Article 6(1)(a) GDPR), which you may withdraw at any time with future effect, and this policy will be updated accordingly.

5. Recipients, processors and international transfers

We use carefully selected service providers who process personal data on our behalf as processors under Article 28 GDPR:

• Hosting & delivery: Vercel Inc., USA — operates this website and processes server log data.
• Transactional email: Resend (Plus Five Five, Inc.), USA — delivers contact-form submissions and acknowledgement emails.

These providers may process data in the United States. Such transfers take place only on the basis of an EU adequacy decision where the provider is certified under the EU–US Data Privacy Framework, or otherwise on the basis of the EU Standard Contractual Clauses (Article 46(2)(c) GDPR) together with appropriate additional safeguards. Please note that, despite these safeguards, access by US authorities to the transferred data cannot be fully excluded. Beyond these processors, your data is not passed on to third parties unless we are legally obliged to do so.

6. Retention

We retain personal data only for as long as necessary for the purposes described above or as required by statutory retention obligations (for example under commercial and tax law). Once a purpose no longer applies and no retention obligation remains, the data is deleted.

7. Your rights

Under the GDPR you have the right to:

access your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time with future effect (Art. 7(3)).

To exercise these rights, please contact us using the details in section 1.

8. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for the controller is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
lfd.niedersachsen.de

You may also contact the supervisory authority of your habitual residence or place of work.

9. Obligation to provide data

Providing your data through the contact form or by email is voluntary; there is no statutory or contractual obligation to do so. However, without the information marked as required we may be unable to respond to your enquiry or enter into an engagement.

10. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Article 22 GDPR.

11. Changes to this policy

We may update this Privacy Policy to reflect changes to our processing or to legal requirements. The current version published on this page applies.

See also our Legal Notice. This is a draft prepared for a Germany-based sole proprietor. It should be reviewed by a qualified professional and confirmed against the site’s actual data processing before publication.