Legal
Privacy policy
Last updated: 6 October 2026 · Translation for convenience; the German version prevails.
1. Controller
Sigma Maze GmbHc/o Mindspace, Rödingsmarkt 9
20459 Hamburg, Germany
Managing director: Omri Erez
Email: hello@sigmamaze.com
No data protection officer is appointed, as the legal requirements (§ 38 BDSG) are not met.
2. Principle
This site sets no cookies, uses no analytics or tracking, and loads no fonts, scripts or images from third-party servers. Your browser talks only to our server.
3. Hosting and server logs
The site is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers in Germany, under a data processing agreement (Art. 28 GDPR).
Our web server automatically records:
- a truncated IP address (IPv4 without the last octet, IPv6 truncated to /48),
- date and time of the request,
- the requested URL, HTTP status and bytes transferred,
- the referrer and your browser type and version (user agent).
Purpose: delivering the site and keeping it stable and secure. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in those purposes). Logs are deleted automatically after 7 days and are not combined with other data.
Your full IP address is processed only briefly in memory for rate limiting and is not stored.
4. Live figures
The product and blockchain figures on the home page are fetched by our server and delivered to your browser. No personal data of yours is passed to third parties in the process.
5. Theme preference
If you switch between light and dark mode, your browser stores this choice locally (localStorage, key smlabs.theme). It never leaves your device. Legal basis: § 25(2) No. 2 TDDDG (strictly necessary for a function you requested). You can delete it in your browser settings at any time.
6. Email contact
If you email us, we process your email address, your name (if given) and your message to handle your request. Legal basis: Art. 6(1)(b) GDPR where your request concerns a contract, otherwise Art. 6(1)(f) (interest in answering enquiries). We delete the data once the request is closed, unless statutory retention periods apply (e.g. § 257 HGB, § 147 AO: 6 or 10 years).
Email provider: TODO
7. External links
This site links to external services (e.g. our products or blockchain explorers). Data is passed to them only when you follow a link; their own privacy policies apply.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20).
Right to object: you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21).
Contact hello@sigmamaze.com.
9. Right to lodge a complaint
You may complain to a data protection supervisory authority. Ours is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.
10. No automated decision-making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place on this site.
11. Security
All traffic is encrypted (TLS/HTTPS).
12. Changes
We update this policy when the site or the law changes. The version published here applies.