Controller
The controller responsible for processing personal data through this website is:
Danny SchwenkeOperator of offbnk
Wattstr. 9
12459 Berlin
Germany
d.schwenke@offbnk.com
Website delivery and access logs
When the website is requested, the hosting infrastructure necessarily processes technical connection data. This may include the IP address, date and time, requested address, response status, transferred data volume, referrer, browser, operating system, and user agent.
This processing is necessary to deliver the website, maintain availability, diagnose faults, and protect the service against misuse and attacks. The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure, reliable, and technically correct operation of offbnk.
Technical logs are deleted or anonymised when they are no longer required for operation or security. They may be retained longer where a specific security incident must be investigated or legal claims preserved. Hosting and infrastructure providers process this data as technical service providers subject to applicable data-protection requirements.
Bank Check
Bank Check asks only which documented institutional characteristics should be used to filter the bank directory, such as audited directory criteria, bank domicile, published account-opening acceptance by residence region, client and offering type, recorded currencies, services, published entry-amount range, and pricing availability. It does not ask you to state your identity, contact details, finances, actual residence, citizenship, PEP status, or document readiness.
The browser applies your selections to a public bank-data snapshot delivered as part of the website. Selections remain in temporary page memory: they are not placed in the address, written to cookies or browser storage, sent to an offbnk backend or database, or shared with a bank. Reloading or leaving Bank Check clears them.
Because the selections are not transmitted to offbnk, they do not create a separate server-side personal-data record. The ordinary technical connection data needed to deliver the Bank Check page is processed as described in section 02.
The filtered list is not profiling, an automated eligibility decision, or a decision with legal or similarly significant effect under Article 22 GDPR. It is a neutral view of documented bank facts.
Vault Check works the same way for the vault directory. It asks only which documented characteristics of precious-metal storage should be used as filters, such as storage type, metals, storage country, customs status, ownership safeguards, access and delivery, onboarding, published acceptance by residence region and the provider’s headquarters, and applies them in your browser to a public vault-data snapshot. Its selections are handled exactly as described above for Bank Check.
Email contact and contact form
If you contact us by email, we process your email address, message, attachments, and related communication data to respond. Depending on the request, the legal basis is Article 6(1)(b) GDPR for steps connected with a requested service or Article 6(1)(f) GDPR for general communication and organisation.
The contact form on the homepage asks for your name, email address, and message. The website sends these to the offbnk backend on Render, which forwards them as an email to the operator’s mailbox through Resend, Inc. The message is not stored by the backend beyond that delivery; the resulting email is handled like any other correspondence under this section. The same legal bases apply. The backend applies a per-address submission limit to prevent abuse and records only the technical connection data described in section 02.
Correspondence is deleted when the request is resolved and no further retention is necessary. Statutory retention duties and the establishment, exercise, or defence of legal claims may require longer storage.
Newsletter
You can subscribe to the offbnk newsletter with your email address. Subscription is voluntary and is never a condition for using this website. The legal basis is your consent under Article 6(1)(a) GDPR, given by ticking the consent box in the signup form.
The newsletter uses a double opt-in procedure. After you submit the form, you receive an email asking you to confirm the subscription, and no newsletter is sent until you do. If the confirmation is not completed, the pending entry is discarded by the provider. Alongside your address, the language of the page you subscribed from is stored so the newsletter can be sent in English or German.
The newsletter is sent by beehiiv, Inc., 228 Park Ave S, New York, NY 10003, United States, acting as a processor on our behalf under a data processing agreement. Your address is stored on beehiiv’s infrastructure, which involves a transfer to the United States as described in section 08. offbnk does not store newsletter addresses in its own database.
You can withdraw your consent at any time with effect for the future, using the unsubscribe link in every newsletter or by writing to d.schwenke@offbnk.com. Withdrawal does not affect the lawfulness of processing carried out before it. After you unsubscribe, your address is deleted, unless a record must be retained as evidence of the consent previously given.
Cookies, storage, and analytics
offbnk measures how the website is used with Cloudflare Web Analytics, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, which also delivers the website. A small script reports, for each page view, the page address, the referring address, the browser and device type, page-loading timings, and the country derived at Cloudflare’s edge from the IP address. It sets no cookies, stores or reads no identifier in your browser, does not fingerprint your device, and does not follow you to other websites; the IP address is not part of the analytics data offbnk can see. offbnk receives aggregated figures only — page views, visits, popular pages, referrers, countries, and devices — never an individual visitor’s history.
The legal basis is Article 6(1)(f) GDPR; the legitimate interest is knowing which content is read and keeping the website fast and reliable. Because the script neither stores information on your device nor reads information from it beyond what any page request already carries, the website still displays no consent banner. You can prevent the measurement with a content blocker or by disabling JavaScript; the website works without it. offbnk uses no advertising pixels, profiling tools, or non-essential cookies. If that changes, this policy and any required consent controls will be updated before such technologies are activated.
One entry is written to your browser’s local storage: whether the newsletter dialogue has been subscribed to or closed, so that it is not shown to you again. It contains no identifier, is never transmitted to offbnk or a third party, and is removed when you clear site data for this domain. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is not repeating a dialogue you have already answered.
When you open an English page of offbnk from another website, a bookmark, or a typed address, offbnk chooses the language version. If the country derived by Cloudflare from your IP address is Germany, Austria, Switzerland, or Liechtenstein and your browser names German as its preferred language, you are forwarded to the German version of that page. Only these signals, which every page request already carries, are evaluated, together with whether the request comes from a page of offbnk itself; they are not stored, and no profile is created. Pages opened from within offbnk are never forwarded, so a switch to English in the language menu is respected. Search-engine crawlers are never forwarded. Nothing is written to your device for this. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is showing the website in the language its visitors read.
Only if you pick a language in the language menu is that choice saved in a cookie named offbnk-lang, so that the website opens in your chosen language on later visits. It contains only “en” or “de”, no identifier, is read only by offbnk, and expires after twelve months or when you delete it. Because you request it by choosing a language, it is strictly necessary for providing that service (Section 25(2) no. 2 TDDDG); the legal basis is Article 6(1)(f) GDPR, the legitimate interest being to respect the language you chose.
External links
Articles may link to regulators, banks, storage providers, public authorities, or other third-party websites. No connection to those third parties is initiated merely by displaying an offbnk page. When you choose an external link, the destination provider independently processes connection data under its own privacy information.
Recipients and international transfers
Personal data is disclosed only where necessary to technical providers, professional advisers, public authorities under a legal obligation, or other recipients you have authorised. Cloudflare delivers and protects the website, processes technical connection data for that purpose, and provides the cookie-free reach measurement described in section 06. Supabase hosts the editorial bank and vault database used to prepare the published website snapshots, but neither Bank Check nor Vault Check contacts Supabase or Render when you choose filters. beehiiv, Inc. processes newsletter subscriptions as described in section 05. Resend, Inc. delivers contact form messages to the operator’s mailbox as described in section 04. offbnk does not sell personal data or share Bank Check selections with banks.
If a service provider processes data outside the European Economic Area, offbnk will use an applicable legal transfer mechanism, such as an adequacy decision or appropriate safeguards under Articles 44–49 GDPR. beehiiv, Inc. is based in the United States; that transfer is covered by standard contractual clauses under Article 46 GDPR together with the provider’s data processing terms. Resend, Inc. is also based in the United States; contact form messages are covered by its data processing agreement, which incorporates the standard contractual clauses. Cloudflare, Inc. is also based in the United States; the delivery and reach-measurement data described in sections 02 and 06 are covered by Cloudflare’s data processing addendum, which incorporates the standard contractual clauses.
Your rights
Subject to the applicable conditions, you may request access, rectification, erasure, restriction, and data portability. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for the future at any time.
Send requests to d.schwenke@offbnk.com. You also have the right to lodge a complaint with a supervisory authority. The locally competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, datenschutz-berlin.de.
Security and policy updates
Appropriate technical and organisational measures are used to protect personal data against loss, alteration, and unauthorised access. No internet transmission can be guaranteed to be completely secure.
This policy will be updated when the service, its providers, or applicable requirements change. The date above identifies the current version.
