Legal

Privacy Policy

Last updated:

This Privacy Policy explains how Bitwater LLC (“we”, “us”) processes personal data when you visit bitwaterlabs.com or contact us through it. Bitwater Labs is a brand operated by Bitwater LLC. This policy is written to meet the requirements of the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

1. At a glance

  • This website sets no cookies and uses no analytics, tracking or advertising technologies.
  • Fonts and all other files come from our own domain. Apart from the content delivery network that delivers this website (section 5), your browser connects to no third-party servers.
  • To deliver the website securely, our hosting provider and our content delivery network process technical connection data, including your IP address.
  • If you use the contact form, we receive your details by email and use them only to handle your inquiry.
  • Your light or dark display preference is stored only in your browser and is never sent to us.

2. Controller and contact

The controller responsible for processing personal data on this website is:

Bitwater LLC
5830 E 2nd St, Ste 7000
Casper, WY 82609
United States of America

Email: [email protected]
Contact form: bitwaterlabs.com/contact

For questions about data protection, and to exercise your rights (section 10), you can use either channel.

3. Scope and applicable law

This policy applies to the website bitwaterlabs.com. Bitwater LLC is established in the United States.

The FADP applies to our processing insofar as it has effects in Switzerland. The GDPR applies insofar as we process personal data of people in the European Union or the European Economic Area (EU/EEA) in connection with offering our services to them. References in this policy to legal bases under Art. 6 GDPR apply only to the extent that the GDPR applies.

Under the FADP, not every processing activity requires a legal basis. We comply with the processing principles of the FADP. Where a justification is required, we rely on the overriding interests described for each processing activity below, in particular processing in direct connection with the conclusion or performance of a contract (Art. 31 FADP).

4. Hosting and server log files

This website, including its contact form, runs on a server operated by an external hosting provider. The server is located in the European Union.

Each time you access this website, the web server automatically records the following information in server log files:

  • the IP address of the requesting device
  • the date and time of the request
  • the requested page or file (URL) and the HTTP method used
  • the HTTP status code and the amount of data transferred
  • the referrer URL (the page you came from), if your browser sends it
  • the user agent, meaning the browser type and version and the operating system, as reported by your browser

Purpose. We use these records to deliver the website, keep it stable and secure, and detect and investigate misuse and attacks. We do not use the log files to identify visitors, we do not create profiles from them, and we do not combine them with other data.

Legal basis. Our legitimate interest in the secure and reliable operation of this website (Art. 6(1)(f) GDPR).

Retention. We keep log data only as long as it is needed for these purposes. It is then deleted automatically. Log entries needed to investigate a specific security incident are kept until the incident has been resolved.

Processing on our behalf. Our hosting provider processes, on our behalf, all data that arises when you use this website. This includes the server log files, contact form submissions (section 6) and our mailbox (section 7). The processing is governed by a data processing agreement. The hosting provider is based in the United States, so access from the United States, for example for support or maintenance, cannot be ruled out. The safeguards for such transfers are described in section 9.

5. Content delivery and security

This website is delivered through a content delivery network (CDN) and security service operated by an external provider. The provider is based in the United States. It provides the domain name system (DNS), a reverse proxy and content delivery network, TLS encryption, and protection of this website against attacks and abuse.

What the CDN processes. Every request to this website passes through the CDN before it reaches our server, including contact form submissions. The CDN decrypts the connection and forwards the request to our server over a separate encrypted connection. In doing so, it processes the data this requires. That includes your IP address, the requested URL, request headers such as the user agent and referrer, the time of the request and the content of the request. The CDN operates a global network, and requests are usually handled at the location closest to you.

The CDN may also ask your browser to send it reports about failed connections to this website (Network Error Logging). These reports contain technical information such as the URL, the type of error and timing data. The provider uses them to detect network problems.

Cookies. The CDN does not set cookies on this website during normal use. If its security systems classify a request as potentially automated or malicious, it may show a short check in your browser. Once you pass it, it may set a technically necessary cookie that records the result, so that you are not checked again.

Purpose and legal basis. Secure, fast and reliable delivery of this website and protection against attacks. This is our legitimate interest (Art. 6(1)(f) GDPR).

Processing on our behalf. The provider processes this data on our behalf under a data processing agreement. It may use the data only to provide its services to us, and keeps it only as long as this is necessary, at the latest until our contract ends. The safeguards for transfers to the United States and other countries are described in section 9.

6. Contact form

Data we process. When you send us a message through the contact form, we process:

  • your name
  • your business email address
  • your company
  • the project type you select
  • your message

The form shows which fields are required.

How it works. The form sends your entries over an encrypted connection to a script on our own web server (section 4). The script checks the entries and forwards them by email to our own mailbox, which is hosted by the same hosting provider. We do not use a separate email service provider or a third-party form service. Once the email has been sent, the web server keeps no copy of your message. The email contains your entries and the time of submission. It does not contain your IP address. We reply to the email address you provide.

Protection against spam and abuse. To protect the form against automated submissions, we use the following measures:

  • A hidden field that people do not see and leave empty. Submissions that fill it in are discarded.
  • A check of the time between loading the form and sending it.
  • A check that the submission was sent from this website.
  • A limit on the number of submissions per sender within a set period. For this limit, the script computes a keyed cryptographic hash (HMAC-SHA-256) of your IP address and stores it with the time of submission. The script does not store the IP address itself. The hash is kept separately from your message, is not included in the email, and is deleted automatically after at most 24 hours.

Independently of these measures, each request is recorded in the server log files described in section 4.

Purposes and legal bases.

  • Handling and answering your inquiry. If your inquiry relates to a possible contract with us, such as a project, product or partnership inquiry, the legal basis is steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). Otherwise, it is our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR).
  • Spam and abuse protection. The legal basis is our legitimate interest in protecting our contact channel and our systems (Art. 6(1)(f) GDPR).

Voluntary provision. Providing your data is voluntary. Without the required fields, we cannot process your inquiry.

Retention. We keep your inquiry and our correspondence for as long as we need them to deal with it. If no business relationship results, we delete them once the matter is closed and no follow-up questions are expected. If your inquiry leads to a contract, we keep the correspondence for as long as the business relationship requires and for as long as statutory retention obligations apply, for example under commercial or tax law. The hashes used for rate limiting are deleted after at most 24 hours.

7. Contact by email

If you email us, we process your email address, the content of your message, any attachments, and the technical metadata of the email, such as the time it was sent. Our mailbox is hosted by our hosting provider (section 4). The purposes, legal bases and retention periods described in section 6 apply accordingly. Email between mail servers is usually, but not always, encrypted in transit. Please keep this in mind before you send confidential information by email.

8. No cookies, no tracking, local storage

Cookies. This website does not set cookies. The only exception is the security check of the content delivery network described in section 5.

No analytics and no third-party content. We use no analytics or tracking tools, no advertising technology, no social media plugins and no embedded third-party content such as maps or videos. The fonts (Geist) and all other files come from our own domain. Apart from the content delivery network (section 5), your browser does not connect to third-party servers when you use this website. Links to other websites are ordinary links. The linked website receives data from your browser only if you follow the link.

Display preference. If you switch between light and dark mode, the website stores your choice in your browser’s local storage (localStorage), so that further pages and later visits use the same mode. The stored value only records the selected mode. It stays on your device and is never sent to us or to anyone else. It is not a cookie and is not used for tracking. You can avoid this storage by not using the switch. You can delete the value at any time by clearing this website’s stored data in your browser settings.

9. Recipients and processing outside Switzerland and the EU/EEA

Recipients. We disclose personal data only to the following categories of recipients:

  • our hosting provider, which hosts this website, its contact form and our mailbox (section 4)
  • the provider of our content delivery network (section 5)
  • authorities or courts, where we are legally required to do so

Our service providers process personal data only on our behalf, under data processing agreements. We do not sell personal data and do not use it for advertising.

Countries.

  • European Union: location of the server that hosts this website and our mailbox (section 4).
  • United States: Bitwater LLC is established in the United States, so your inquiry is processed by a US company. Some of our service providers are also based in the United States.
  • Other countries: the content delivery network operates worldwide and may handle your requests at a location near you (section 5).

Safeguards. The United States is not generally recognized by Switzerland or the European Union as providing an adequate level of data protection. That recognition extends only to companies certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. Where a service provider is certified, transfers to it are covered by two decisions. For the EU, this is the European Commission’s adequacy decision of 10 July 2023. For Switzerland, it is the Federal Council’s recognition of certified US companies as providing adequate protection, in force since 15 September 2024. In all other cases, and if a certification lapses, transfers to countries without an adequate level of data protection are based on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with the adaptations required for transfers from Switzerland. The FDPIC recognizes these clauses as a safeguard.

Information on request. On request, we will tell you which service providers we use and send you a copy of the safeguards that apply. Write to us at [email protected].

10. Your rights

Depending on the applicable law, you have the following rights regarding your personal data:

  • Access: to learn whether we process personal data about you, and to receive information about it (Art. 25 FADP; Art. 15 GDPR).
  • Rectification: to have inaccurate data corrected (Art. 32 FADP; Art. 16 GDPR).
  • Erasure: to have your data deleted (Art. 32 FADP; Art. 17 GDPR).
  • Restriction and prohibition: to have processing restricted (Art. 18 GDPR), or to prohibit specific processing or disclosure to third parties (Art. 32 FADP).
  • Data portability: to receive the data you provided to us in a common electronic format, or to have it transferred to another controller (Art. 28 FADP; Art. 20 GDPR).
  • Objection: to object to processing, as described below.

Right to object. Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defense of legal claims. Under the FADP, you can likewise object to the processing of your personal data.

How to exercise your rights. Email us at [email protected], or use the contact form (section 2). We may ask you to verify your identity. We respond within the statutory time limits and free of charge, except where the law permits otherwise.

No automated decisions. We do not make decisions based solely on automated processing that have legal effects on you or similarly significantly affect you. The automatic spam checks described in section 6 only decide whether a form submission is delivered. If a submission is rejected by mistake, you can reach us at [email protected].

11. Supervisory authorities

Switzerland. You can report a concern to the Swiss supervisory authority:

Office of the Federal Data Protection and Information Commissioner FDPIC
Feldeggweg 1
CH-3003 Berne
www.edoeb.admin.ch

EU/EEA. Where the GDPR applies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). You can do this in particular in the member state of your habitual residence, of your place of work, or of the place of the alleged infringement. The European Data Protection Board lists the national authorities: edpb.europa.eu.

We would appreciate the chance to address your concern first, so please feel free to contact us directly at [email protected].

12. Data security

We protect personal data with technical and organizational measures appropriate to the risk. These include:

  • encrypted connections (TLS) for all access to this website
  • no storage of contact form messages on the web server
  • storage of IP addresses for spam protection only as keyed hashes, deleted after at most 24 hours
  • hosting of the website on a server in the European Union

No method of transmission or storage is completely secure. We review our measures when this website or the services we use change.

13. Changes to this policy

We update this policy when we change this website, the services we use or how we process personal data, or when the law requires it. The version published on this page is the current one.

Last updated:

Imprint