Privacy Policy
Version 1.0 · Effective date: 20 July 2026
1. Purpose and scope
This Privacy Policy explains how the BFLabs project processes personal data in connection with the Farona website and web application at https://farona.io. It applies to visitors, registered users, support contacts, prospective customers, and customers.
Farona is currently a beta product operated as part of the early-stage, unincorporated BFLabs startup project in North Rhine-Westphalia, Germany.
2. Controller and privacy contact
The data controller for the current Farona beta operation is:
BFLabs — Farona project
Büchel 12–14
41460 Neuss
Germany
Email: info@farona.io
Phone: +49 155 67607085
Privacy requests should be sent to info@farona.io with the subject line “Privacy Request”. No data protection officer has currently been appointed.
3. Principles of processing
Personal data is processed only where there is a legal basis and only to the extent reasonably necessary for the relevant purpose. Depending on the processing activity, the legal basis is:
- Article 6(1)(b) GDPR, where processing is necessary to provide requested services, administer an account, prepare an offer, or perform a contract;
- Article 6(1)(c) GDPR, where processing is necessary to comply with a legal obligation;
- Article 6(1)(f) GDPR, where processing is necessary for legitimate interests such as service security, fraud prevention, product improvement, support, establishment or defence of legal claims, and the provision of blockchain risk information, provided those interests are not overridden by the rights and freedoms of affected individuals; or
- Article 6(1)(a) GDPR and Section 25(1) TDDDG, where consent is requested for non-essential cookies, analytics, or comparable device access.
4. Website access and server logs
When the website or application is accessed, technical data may be processed automatically, including:
- IP address;
- date and time of access;
- requested URL and referring URL;
- browser type, device type, operating system, and language;
- response status, transferred data volume, and technical error information; and
- security, rate-limit, and abuse-prevention events.
This data is processed to deliver the website, maintain technical stability, detect attacks and misuse, troubleshoot errors, and protect users and infrastructure. The legal basis is Article 6(1)(f) GDPR. Routine server and security logs are generally retained for no longer than 30 days, unless a longer period is required to investigate a security incident, prevent abuse, comply with law, or establish, exercise, or defend legal claims.
Farona uses infrastructure and hosting services provided by Vercel and Hetzner. These providers may process technical and hosting data on BFLabs' behalf under applicable data-processing terms.
5. Accounts and authentication
When a user creates or uses an account, Farona may process:
- email address;
- name or profile information voluntarily provided or received through the selected sign-in method;
- internal account identifier;
- authentication method and authentication events;
- account status, settings, language, and consent choices; and
- security and abuse-prevention information.
The legal basis is Article 6(1)(b) GDPR and, for security and misuse prevention, Article 6(1)(f) GDPR.
Users may sign in with Google. When Google Sign-In is selected, Google may provide Farona with the user's email address, name, profile image, and a Google account identifier, depending on the permissions displayed during sign-in. Google processes data under its own privacy terms. Farona does not receive the user's Google password.
6. Wallet addresses, transaction hashes, blockchain data, and reports
To generate a report, Farona processes information submitted by the user and related analytical data, which may include:
- wallet addresses and transaction hashes;
- selected blockchain network and asset;
- publicly accessible transactions, balances, timestamps, smart-contract interactions, and counterparty relationships;
- labels, indicators, and information obtained from selected external blockchain-data providers;
- internally generated risk levels, indicators, explanations, evidence references, and report identifiers; and
- report history, creation time, status, and usage information.
Blockchain addresses and transaction data are generally public and pseudonymous. They may nevertheless constitute personal data where they can reasonably be linked to an identifiable individual. For data submitted in order to provide a requested report, processing is based on Article 6(1)(b) GDPR. To the extent Farona analyses public blockchain information or information relating to third-party addresses for security, fraud-prevention, and risk-information purposes, processing is based on Article 6(1)(f) GDPR.
Users must not submit private keys, seed phrases, passwords, authentication codes, confidential personal documents, or information they are not legally permitted to use. Farona never needs a private key or seed phrase to generate a report.
7. Automated analysis and risk scoring
Farona reports are generated automatically. The system applies internally developed rules and analytical methods to public blockchain information and selected signals obtained from external data providers. Relevant factors may include transaction patterns, address relationships, exposure paths, known service categories, timing, frequency, direct or indirect proximity to risk indicators, and network-specific context.
The output shown to the user is Farona's own analytical result. External-provider data may contribute to the analysis but does not by itself determine the final presentation or risk level.
Automated blockchain analysis is inherently probabilistic and may produce false positives, false negatives, outdated associations, incomplete results, or incorrect attributions. Farona does not independently verify the identity of every person or entity associated with an address. A report is not an official legal, regulatory, sanctions, AML, KYC, KYB, criminal, or compliance determination.
Farona does not itself make a decision that produces legal or similarly significant effects concerning the person who may be associated with a wallet. Users decide independently how to use a report and are expressly instructed not to use Farona as the sole basis for a decision producing legal or similarly significant effects. Questions or objections concerning a report may be sent to info@farona.io, but the beta service does not currently include a guaranteed human review procedure.
8. Support, enquiries, and business communications
When a person contacts BFLabs or Farona, the submitted contact details, message content, attachments, and related correspondence are processed to respond, provide support, prepare or administer a contract, prevent abuse, and document the communication. The legal basis is Article 6(1)(b) GDPR where the communication concerns a contract or requested pre-contractual steps, and otherwise Article 6(1)(f) GDPR.
Farona does not currently send newsletters or general marketing emails. Necessary account, security, service, support, and contractual communications may still be sent without being treated as marketing.
9. Beta purchases, billing, and payment information
Farona offers in-app purchase of plans and prepaid reports. Users pay by depositing supported stablecoins (USDT or USDC) to their Farona deposit address, which credits a non-withdrawable USD wallet, then settle the pending order from that balance. Display or invoice amounts may also use EUR or USD where stated.
For purchases, billing, payment verification, credit allocation, accounting, and compliance with legal obligations, Farona may process contact and billing details, product or credit amount, invoice information, payment status, payment reference, USD wallet ledger entries, and, where a blockchain payment is used, the relevant public deposit address and transaction identifier.
The legal bases are Article 6(1)(b) GDPR and Article 6(1)(c) GDPR. Payment and accounting records are retained for the periods required by German commercial and tax law. Farona does not request or store wallet private keys or seed phrases in connection with payment.
10. Cookies, local storage, and consent management
Farona may use cookies, browser storage, or similar technologies that are strictly necessary to provide requested functionality, maintain sessions, remember security or language settings, and store consent choices. Necessary technologies are used under Section 25(2) TDDDG and, where personal data is processed, Article 6(1)(b) or Article 6(1)(f) GDPR.
Non-essential technologies, including analytics, are activated only after the user has provided consent through the cookie-consent interface. Consent can be refused without losing access to the basic website and can be withdrawn or changed at any time through the Cookie Settings link. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
11. Google Analytics and Google Tag Manager
With the user's consent, Farona uses Google Analytics 4 to understand aggregated website and application usage and to improve the beta product. Google Tag Manager is used to manage website tags; it does not determine the purposes for which the managed tags process data.
Depending on the user's interaction and device settings, analytics data may include page views, approximate location derived from technical signals, device and browser information, language, referral information, interaction events, pseudonymous identifiers, and consent status. Google may receive technical information, including the user's IP address, when analytics resources are requested.
The provider in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing occurs only on the basis of consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Analytics data is retained according to the configured Analytics retention settings and is subsequently deleted or aggregated. Users can prevent future analytics processing by withdrawing consent in Cookie Settings.
12. Recipients and service providers
Personal data may be disclosed only where necessary to:
- hosting, cloud, infrastructure, security, and technical-service providers, including Vercel and Hetzner;
- authentication and analytics providers, including Google where the relevant function is selected or consented to;
- selected blockchain-data and risk-signal providers that assist with requested reports;
- communications and email-infrastructure providers;
- professional advisers, such as legal, tax, or accounting advisers, where necessary and subject to confidentiality duties;
- authorities, courts, or other parties where disclosure is required by law or necessary to establish, exercise, or defend legal claims; or
- a successor or transaction adviser in connection with a genuine financing, restructuring, acquisition, or transfer of the project, subject to appropriate confidentiality and data-protection safeguards.
External blockchain-data providers receive only the information reasonably necessary to obtain the relevant signal, typically a public wallet address, transaction hash, network identifier, or comparable public blockchain reference. They do not receive private keys or seed phrases from Farona.
13. International data transfers
Some service providers may process data outside Germany or the European Economic Area. Where personal data is transferred to a country without an adequacy decision, Farona relies, as applicable, on approved safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures. Where a recipient validly participates in the EU–US Data Privacy Framework, transfers may also rely on the applicable adequacy decision.
14. Retention and deletion
Farona keeps personal data only for as long as necessary for the relevant purpose, including:
- account data for the duration of the account and until an account-deletion request has been completed, unless continued retention is legally required;
- reports and report inputs until the user deletes them, requests account deletion, or retention is no longer necessary for the service, security, legal claims, or legal compliance;
- routine server and security logs generally for no more than 30 days, subject to incident and legal exceptions described above;
- support correspondence for as long as necessary to resolve the matter and for the applicable limitation period where documentation is reasonably required;
- consent records for as long as reasonably necessary to demonstrate valid consent and compliance; and
- contractual, invoice, and payment records for the statutory retention periods under applicable commercial and tax law.
Deleted data may remain in access-restricted backups until the relevant backup cycle is overwritten. Data may also be retained where necessary to comply with law, enforce agreements, resolve disputes, prevent fraud, or protect legal rights.
Registered users can delete individual reports in the application. Account deletion is currently handled by request to info@farona.io. Identity verification may be required before an account or personal data is deleted.
15. User rights
Subject to the conditions and limitations of the GDPR, individuals may have the right to:
- obtain access to their personal data and a copy of it;
- correct inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- receive data they provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- object to processing based on Article 6(1)(f) GDPR on grounds relating to their particular situation;
- withdraw consent at any time for future processing; and
- lodge a complaint with a data-protection supervisory authority.
Requests may be sent to info@farona.io. Farona may request information reasonably necessary to verify the requester's identity and protect accounts and third parties.
The supervisory authority responsible for data-protection matters in North Rhine-Westphalia is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Website: https://www.ldi.nrw.de
16. Right to object
Where processing is based on legitimate interests under Article 6(1)(f) GDPR, the data subject has the right to object at any time, on grounds relating to their particular situation. Farona will stop the relevant processing unless compelling legitimate grounds override the person's interests, rights, and freedoms, or the processing is required for the establishment, exercise, or defence of legal claims.
17. Security
Farona uses reasonable technical and organisational measures intended to protect personal data against accidental or unlawful loss, alteration, disclosure, destruction, and unauthorised access. No internet service, blockchain-data source, authentication method, or storage system can be guaranteed to be completely secure. Users are responsible for protecting their account and authentication methods and for promptly reporting suspected unauthorised access.
18. Children and legal capacity
Public information on Farona is not subject to a general age restriction. A person who lacks legal capacity to create an account or conclude a contract must use the service only with the authorisation of a parent or legal guardian. Where consent is the legal basis for processing data of a child and parental authorisation is legally required, the service may request evidence of that authorisation.
Farona is not designed to collect private information from children and users must not submit private keys, identity documents, or unnecessary personal data about a child.
19. Public blockchains
Public blockchains are independent, decentralised systems. Information recorded on a public blockchain may be permanent and cannot generally be altered or erased by Farona. A GDPR deletion request can apply to personal data stored in Farona's own systems, but Farona cannot delete or modify data recorded on an independent public blockchain.
20. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect product development, new providers, legal changes, or changes in processing. The current version and effective date will be published on the website. Where required by law, users will receive additional notice or be asked for renewed consent.
---

