Legal
Privacy Policy
Last updated: 19 September 2026
This policy explains what personal data we process in connection with the Dera Protocol website and interfaces, why, and what rights you have.
1.Who we are
Dera Labs Limited, a company registered in England and Wales under company number 16535617, is the controller for the processing described in this policy.
Contact: legal@dera.fi
2.Our starting point
The Protocol is non-custodial. We do not operate accounts, we do not ask you to register, and we do not collect names, email addresses, postal addresses or identity documents in order for you to use the Protocol.
We do not carry out identity verification (KYC) for access to the Protocol, and we do not sell personal data or use it for advertising.
3.What we process
3.1. Website analytics. We use Vercel Analytics, a privacy-focused analytics service, to understand aggregate site usage. It does not set cookies and does not track individuals across websites. It processes technical data such as the page visited, referrer, country, browser and device type. Vercel derives an anonymised visitor identifier from request data, which is not used to identify you and is not linked to your wallet.
3.2. Blockchain data. Transactions with the Protocol occur on the public Ethereum blockchain. Wallet addresses, transaction amounts, timestamps and transaction hashes are published on-chain by the network itself, permanently and publicly. We do not put this data on the blockchain and we cannot alter or erase it.
3.3. Indexed on-chain events. So that the interface can display transaction history and protocol statistics, we read mint and burn events from the blockchain and store a copy in our own database. Each record contains a wallet address, transaction hash, block number, timestamp, transaction type and DERA amount. This is a cache of already- public information; it contains no name, email address or other off-chain identifier.
3.4. Server logs. Our hosting provider (Vercel) processes standard request logs, including IP address, for security, abuse prevention and diagnostics. These are retained for a short period under Vercel's own retention policy.
3.5. Correspondence. If you email us, we process your email address and the content of your message in order to respond.
4.Is a wallet address personal data?
A wallet address is pseudonymous. On its own it does not identify a person, but it can become personal data where it is combined with other information that links it to an individual.
We treat wallet addresses as personal data where the UK GDPR and EU GDPR require it, and we apply this policy to them accordingly. We do not attempt to link wallet addresses to real-world identities, and we do not combine them with analytics data.
5.Legal bases
Legitimate interests (Article 6(1)(f)) for analytics, server logs, and indexing public on-chain events, being our interest in operating, securing and improving the Protocol and its interfaces. We have considered your rights and use the least intrusive means available.
Performance of a contract or steps prior to it (Article 6(1)(b)) where processing is necessary to provide the interface you have asked to use.
Legal obligation (Article 6(1)(c)) where we are required to retain or disclose information by law.
6.Sharing and international transfers
We share data with service providers acting on our behalf: Vercel Inc. (hosting and analytics) and our database and RPC infrastructure providers. We also read publicly available yield data from third-party sources such as DefiLlama; this involves no personal data.
Some providers are located outside the UK and EEA. Where personal data is transferred, we rely on appropriate safeguards such as the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
Public blockchain data is, by design, replicated globally by network participants outside our control.
7.Retention
Indexed on-chain event records are retained for as long as the interface needs to display protocol history. Server logs are retained for a short period per our hosting provider's policy. Correspondence is retained for as long as needed to handle your enquiry and to meet our legal obligations.
Data recorded on the Ethereum blockchain is permanent and cannot be deleted by us or by anyone else.
8.Your rights
Subject to conditions in applicable law, you have the right to access your personal data, to have inaccurate data corrected, to request erasure, to restrict or object to processing, and to data portability. Where we rely on legitimate interests, you may object at any time.
An important limitation. We cannot amend or delete data recorded on the public blockchain — no one can. Where you ask us to erase data, we can act only on the copies held in our own systems.
To exercise a right, contact legal@dera.fi. We may need information to verify that a request relates to you — for example, a signed message from the wallet address concerned.
You have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in your country of residence.
9.Cookies
This website does not set advertising or tracking cookies. Our analytics provider operates without cookies. Your browser or wallet extension may store data locally to function; that storage is controlled by you and by the software you have installed, not by us.
10.Children
The Protocol is not intended for anyone under 18, and we do not knowingly process the personal data of children.
11.Changes
We may update this policy. The "last updated" date above will change, and material changes will be notified on this website.
This document is provided for information. It is not legal advice, and it does not replace your own assessment of whether use of the Protocol is lawful and appropriate for you.