Privacy Policy
Last updated: 26 July 2026
Manage your privacy choice
Optional functional storage can be enabled or withdrawn at any time.
1. Controller
Varga-Tech – Attila Varga
Leipziger Str. 3
37085 Göttingen
Deutschland
Email: vargatech@attila-varga.eu
Phone: 0172 8400 913
2. Hosting, website access and server logs
When the website is accessed, the web server processes technically necessary connection data. This may include IP address, date and time, requested URL, referrer URL, HTTP status, transferred data volume, browser type, operating system and user agent. Processing is used for secure delivery, stability, error analysis and abuse prevention. The legal basis is Article 6(1)(f) GDPR and, where access relates to entering into or performing a user relationship, Article 6(1)(b) GDPR.
3. Stratum connections and mining data
When establishing and operating a Stratum connection, data processed includes IP address, timestamp, connection status, submitted Bitcoin Stratum username, worker name, share difficulty, share results, estimated hashrate and technical error messages. This is required to provide the solo-mining service, identify a successful miner, perform security checks, analyze errors and document proper pool operation. The legal bases are Article 6(1)(b) and (f) GDPR.
4. Public pool and worker statistics
Bitcoin addresses and worker names may be personal data or linkable to an individual. Public views are intended to shorten addresses and display only performance data required for pool operation. Users must not use real names, email addresses, telephone numbers or other personal information as worker names. The personal miner dashboard retrieves existing pool data using the Bitcoin address entered by the user; no user account is created.
5. Cookies, local storage, service worker and Cache Storage
The website uses a strictly necessary consent cookie to remember your privacy choice. A technical session cookie is created only for protected push requests. Optional local-storage values, the service worker and PWA caches are activated only after consent to the “Functionality & PWA” category. Analytics, advertising and profiling cookies are not used. Names, purposes and retention periods are listed in the cookie and storage information.
6. Legal bases for device storage
Strictly necessary device storage is used under Section 25(2)(2) TDDDG. Optional functional storage is used only with consent under Section 25(1) TDDDG. Where personal data is processed, optional processing is based on Article 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time for the future through the “Privacy settings” link.
7. PWA and offline functionality
After consent to the functional category, a service worker may be registered. It stores static resources such as stylesheets, scripts, icons and an offline information page in Cache Storage. Dynamic pool, miner, admin and push API data is not stored as offline content. On withdrawal, the website attempts to delete known VargaTech PWA caches and unregister the service worker.
8. Push notifications
Web push is activated only when the user first allows the functional category, then actively selects “Enable block alert” and confirms the separate browser prompt. The push endpoint, cryptographic keys, device label, user agent and technical timestamps are stored. The data is used only to deliver block-found notifications. Consent may be withdrawn in the privacy settings, through the disable function, or in browser and operating-system settings.
9. External resources and recipients
Data may be processed by the hosting provider as a processor. The open-source Chart.js library is currently delivered through jsDelivr for chart rendering. The CDN operator may receive the IP address and technical request data when the resource is fetched. The purpose is fast and reliable display of pool charts; the legal basis is Article 6(1)(f) GDPR. No analytics or advertising services are integrated and VargaTech does not create visitor profiles. Other disclosure occurs only where legally required, necessary for legal defense, or technically required to provide an expressly requested function.
10. Retention periods
Personal data is retained only for as long as necessary for its purpose or statutory retention obligations. Web-server and security logs should be regularly deleted or anonymized unless needed for a specific security incident. Worker-history data is reduced after the configured technical retention period. Push data is deleted following unsubscription or technical invalidity of the endpoint once detected during the regular cleanup process.
11. Data subject rights
Where statutory requirements are met, data subjects have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Data subjects also have the right to lodge a complaint with a data-protection supervisory authority, including the authority for their residence, workplace or the place of the alleged infringement.
12. Objection under Article 21 GDPR
Where processing is based on Article 6(1)(f) GDPR, the data subject may object at any time on grounds relating to their particular situation. Processing will then cease unless compelling legitimate grounds or grounds for establishing, exercising or defending legal claims apply.
13. Data security
The website is provided over HTTPS. Access is protected by technical and organizational measures including restrictive security headers, access restrictions for configuration files, CSRF protection for write-based push requests and separate admin authentication. Measures are developed on a risk-based basis; absolute security cannot be guaranteed.
14. Changes to this privacy policy
This privacy policy will be updated when features, legal requirements or service providers change. The version published on this page is authoritative.
Note: Provider information, hosting agreements, specific log-retention periods and the actual server configuration must be regularly checked against this policy.
This English translation is provided for convenience. The German privacy policy remains authoritative.