Trusted by Swell Blockchain

DefiRilla Privacy Policy

Last Updated: August 24, 2026

1. Who We Are & Data Controller Identity

This Privacy Policy applies to the website, platform, and alerting services accessible via defirilla.com (collectively, the "Platform"), operated by Brightstart Nominees PTY LTD trading as DefiRilla (referred to as "DefiRilla," "we," "our," or "us"), registered in Australia at 102 Victoria Street, Carlton, Melbourne, Victoria 3053, Australia.

For the purposes of applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988 (Cth), Brightstart Nominees PTY LTD is responsible for the processing of personal information described in this Policy and acts as a data controller where applicable under relevant privacy laws. If you have questions regarding this Privacy Policy or our data practices, contact our Privacy Contact at .

The GDPR and UK GDPR apply to DefiRilla only to the extent required by their respective territorial scopes, including where DefiRilla offers goods or services to individuals in the European Economic Area or the United Kingdom, or monitors the behaviour of individuals located there. Where the GDPR or UK GDPR applies, DefiRilla will comply with the requirements applicable to the relevant processing. References to GDPR rights and obligations in this Policy apply only where and to the extent the GDPR or UK GDPR is legally applicable to the relevant processing.

2. Platform Overview & Read-Only Architecture

DefiRilla provides a passive, read-only monitoring and alerting tool for decentralized finance (DeFi) positions across EVM-compatible blockchain networks. DefiRilla enables users to receive automated risk notifications (including Health Factor changes, LP active range exits, and yield fluctuations) without requiring non-custodial wallet connections or transaction signatures.

Read-Only Security Commitment

  • No Wallet Connections: DefiRilla will never ask you to connect your Web3 wallet (e.g., MetaMask, Rabby, Coinbase Wallet).
  • No Signatures or Approvals: DefiRilla never requests transaction signatures, message signing, or smart contract token approvals.
  • Zero Access to Assets or Private Keys: DefiRilla cannot access, hold, transfer, trade, stake, or manage private keys, seed phrases, or user funds under any circumstances.

3. Information We Process

DefiRilla is engineered around the principle of data minimisation. Depending on how you interact with the Platform, we process the following categories of information:

A. Information Provided by You

  • Public Wallet Addresses: Public EVM wallet addresses that you submit for on-chain position monitoring.
  • Notification Destinations: Your Telegram Chat ID/username or email address to route alerts to your designated device.

B. Information Automatically Processed (Usage & Technical Data)

  • Technical & Server Logs: Standard server and application error logs, including IP addresses, access timestamps, user-agent details (browser type and OS), and request headers, processed on infrastructure managed by DefiRilla and provided by third-party cloud infrastructure providers for security, system stability, and abuse prevention.
  • Pseudonymous Analytics: Usage and traffic metrics collected via Google Analytics to evaluate traffic, usage patterns, and system performance.

C. Public Blockchain Information

Publicly available, on-chain data associated with submitted wallet addresses, including token balances, borrowing/lending Health Factors, liquidity pool positions, and smart contract interactions.

Public blockchain data is obtained from publicly accessible blockchain infrastructure services used by DefiRilla to query and monitor those networks.

D. Raw Blockchain Data vs. DefiRilla Derived Data

  • Raw On-Chain Data: Public ledger state that exists independently on decentralized networks.
  • DefiRilla Derived Data: Calculations, risk state evaluations, Health Factor alerts, LP active range statuses, and APR tracking generated by our internal monitoring engine.

E. Sources and Indirect Collection

We collect information directly from you when you submit a wallet address, configure alerts, provide a notification destination or contact us. We also collect information indirectly from public blockchain ledgers and from third-party blockchain infrastructure, RPC and indexing providers used to retrieve on-chain data. These providers may receive wallet addresses, network and query information necessary to return blockchain data. We may also receive information about blockchain addresses or transactions relating to individuals who have not directly interacted with DefiRilla.

4. Wallet Re-Identification & Public Blockchain Disclaimer

Pseudonymity Notice: Public wallet addresses are pseudonymous identifiers. While DefiRilla does not require your legal name or identity, wallet addresses may become re-identifiable when combined with third-party data sources, public social profiles, or notification endpoints.

Blockchain Immutability: Public blockchain networks are decentralized, transparent, and permanent public ledgers. DefiRilla does not control, alter, or erase public blockchain data.

5. Purposes & Legal Bases for Processing (GDPR Disclosure)

We assess the legal basis for each processing activity separately. Depending on the context, the same category of data may be processed under different legal bases:

Processing Activity Categories of Data GDPR Legal Basis
Delivering Alert Services Wallet addresses, Telegram ID, Email address Performance of Contract (GDPR Art. 6(1)(b)) – Necessary to deliver requested alerts.
System Security & Abuse Prevention Technical server logs, IP addresses, error logs Legitimate Interests (GDPR Art. 6(1)(f)) – Protecting internal infrastructure and preventing DDoS/abuse.
Product Analytics & Traffic Analysis Pseudonymous usage metrics (Google Analytics) Consent (GDPR Art. 6(1)(a)) – Where Google Analytics is non-essential, we only activate analytics after obtaining the user's affirmative consent.
Legal & Regulatory Compliance Technical records, correspondence Legal Obligation (GDPR Art. 6(1)(c)) – Complying with statutory requirements.
Blockchain Monitoring & Derived Risk Data Wallet addresses submitted by users, public on-chain data, Health Factor, LP and APR calculations Performance of Contract (GDPR Art. 6(1)(b)) where processing is objectively necessary to provide monitoring requested by the user. Legitimate Interests (GDPR Art. 6(1)(f)) may apply to blockchain data collection or processing that is not objectively necessary to perform the user’s contract, as well as security, service improvement and processing relating to individuals who are not DefiRilla users, subject to a documented balancing assessment.

6. Wallet-to-Notification Linkage & Commercialisation Guarantee

A. Association Disclosure

When you configure an alert, DefiRilla associates the public wallet address you provide with your selected notification destination (Telegram Chat ID or Email address) in our internal database. This association exists solely to route risk alerts regarding that wallet to your destination.

B. Commercialisation Guarantee

DefiRilla does not sell, rent, license, trade, or monetize your wallet addresses, wallet-to-notification associations, portfolio data, or alert configurations to third parties for advertising, cross-site profiling, or behavioral targeting.

7. Analytics, Cookies & Global Privacy Control (GPC)

A. Google Analytics Safeguards

We utilize Google Analytics to analyze platform traffic patterns and optimize system performance.

B. Cookie Preferences, Consent & GPC Signals

Cookie Consent & Withdrawal: Non-essential analytical cookies (such as Google Analytics) are blocked by default and are only deployed if you provide affirmative opt-in consent via our cookie banner. You may withdraw this consent at any time via our cookie preference center; withdrawal will not affect the lawfulness of processing that occurred before withdrawal.

Global Privacy Control: Where required by applicable law, the Platform also recognizes and processes Global Privacy Control (GPC) opt-out preference signals to automatically suppress non-essential tracking.

8. Infrastructure & Third-Party Service Providers

Cloud Infrastructure Providers: DefiRilla uses third-party cloud infrastructure providers, including Oracle, Heroku, and Google Cloud, as applicable, to host and operate components of the Platform. These providers may process technical information, application data, and other information necessary to provide the infrastructure services.

Telegram (Optional Destination): If you elect to receive alerts via Telegram, only your Telegram Chat ID and the alert message text are transmitted via the official Telegram Bot API; Telegram acts as an independent controller for that data and processes it subject to Telegram's own Privacy Policy.

Analytics Tooling: Google Analytics is used for website and product analytics and is configured to operate only after obtaining applicable user consent.

Depending on the network and technical configuration, RPC and indexing providers may process wallet addresses, network requests, query metadata and related on-chain data. Their processing is governed by their own privacy notices and, where applicable, contractual arrangements with DefiRilla. These providers may process information in Australia or overseas, including in the United States, depending on the service and configured processing location.

9. International Data Transfers

DefiRilla operates from Australia and uses third-party cloud infrastructure providers that may process personal information in Australia and overseas, including the United States. The specific location depends on the provider, service, and configured hosting location.

EEA & UK Users: For transfers originating from the European Economic Area or the United Kingdom we rely on legally recognized transfer mechanisms and appropriate safeguards including Standard Contractual Clauses (SCCs) where applicable.

Australian Users: We take reasonable steps in accordance with Australian Privacy Principle (APP) 8 to ensure that overseas infrastructure providers handle personal information consistently with the APPs.

10. Data Retention Policy

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected:

  • Wallet Addresses & Notification Destinations: Retained in our internal database while your alerting tripwire remains active. Following deletion or alert cancellation, we delete the relevant wallet address, notification destination and alert configuration from active production systems within a reasonable operational period. Copies may temporarily remain in encrypted backups, security logs, disaster-recovery systems or third-party systems where necessary for security, legal compliance or ordinary backup management. Such copies are protected from ordinary use and deleted in accordance with the applicable retention schedule. If an alerting tripwire remains inactive (i.e., undeliverable or unacknowledged) for 3 consecutive months, we may deactivate and delete the associated wallet address and notification mapping.
  • Blockchain Query Logs & Technical Server Logs: Processed on our managed infrastructure for system stability, security auditing and debugging. Ordinary logs are retained for a maximum of 90 days, after which they are automatically deleted. Records may be retained longer where reasonably necessary for an active security investigation, legal compliance or dispute resolution.
  • Analytics Data: Retained in accordance with Google Analytics retention settings under anonymized parameters.

11. Security Safeguards

DefiRilla maintains appropriate technical and organizational security measures designed to protect personal information stored and processed on infrastructure managed by DefiRilla and provided by third-party cloud infrastructure providers.

  • Enforced Encryption-in-Transit (TLS/HTTPS) across all web endpoints and API communications.
  • Encryption-at-Rest for internal databases and data stores.
  • Least-privilege administrative access controls and credential management.
  • Routine monitoring for system vulnerabilities and unauthorized access attempts.

12. Your Privacy Rights (GDPR & Australian Privacy Framework)

Depending on your geographic location, you may exercise specific rights regarding your personal information:

European Economic Area (EEA) & United Kingdom (GDPR / UK GDPR)

  • Right of Access & Rectification: Request confirmation, copies, or corrections of the personal data we hold about you.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your wallet address and notification mappings from our active databases.
  • Right to Restriction or Objection: Request restriction of processing or object to certain processing where the applicable data protection law provides that right.
  • Right to Data Portability: Request a structured machine-readable copy of your active configurations.
  • Right to Withdraw Consent: Where processing is based on consent (e.g., analytics), withdraw that consent at any time without affecting prior lawful processing.

Australia (Privacy Act 1988 / APPs)

  • Access & Correction: Request access to or correction of personal information held by DefiRilla.
  • Complaints Handling: Lodge an enquiry or complaint regarding privacy handling directly with us.

We respond to privacy requests within the timeframe required by applicable law. Under the GDPR and UK GDPR, we generally respond within one month and may extend that period by up to two further months where permitted for complex or numerous requests; we will notify you of any extension and the reason for it. For Australian requests, we will respond within a reasonable period in accordance with the Privacy Act 1988 (Cth) and applicable Australian Privacy Principles. We may need to verify your identity before processing a request. To exercise your rights, contact us at .

13. United States Privacy Rights (CCPA/CPRA and Other Applicable State Laws)

If you reside in California or another US state with applicable privacy legislation, you may have additional rights regarding your personal information, subject to statutory limitations:

  • Right to Know & Access: You have the right to request details regarding the categories and specific pieces of personal information we have collected, used, disclosed, or processed about you, as required by applicable law.
  • Right to Deletion & Correction: You have the right to request the deletion or correction of inaccurate personal information held by us, subject to legal exceptions.
  • No Sale or Sharing of Personal Information: DefiRilla does not sell your personal information or share it for cross-context behavioral advertising (as defined under applicable law).
  • Non-Discrimination: We will not discriminate against you (such as denying services or altering service quality) for exercising any privacy rights available to you.

To exercise applicable US privacy rights, contact us at with the subject line "US Privacy Request."

14. Data Deletion Limitations & Blockchain Immutability

When you delete an alert configuration, we delete the associated wallet address, alert settings and notification-destination linkage from our active application databases within a reasonable operational period. Deletion may not immediately remove copies held in backups, security logs, disaster-recovery systems or by third-party notification providers and does not remove public blockchain records.

Blockchain Disclaimer: Deletion from DefiRilla does not, and cannot, alter, delete, or remove public transaction records or state data from underlying, immutable blockchain networks.

15. Children's Privacy

DefiRilla is not directed toward or intended for use by individuals under the age of 18 ("Children"). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take prompt steps to delete such data from our servers.

16. Automated Decision-Making (ADM) Disclaimer

DefiRilla's automated alerts are technical, rule-based notifications generated from public blockchain data and user-configured monitoring parameters. They are strictly informational and are not intended to make automated legal, credit, financial, or eligibility decisions concerning users.

17. Data Breach Response

DefiRilla maintains an internal incident response procedure. Suspected personal data breaches are assessed promptly. Where required by applicable law (including under the Australian Notifiable Data Breaches scheme or GDPR Articles 33 and 34), we will notify relevant regulatory authorities and affected individuals within the applicable statutory timelines.

18. Complaints Handling Process

If you believe DefiRilla has processed your personal information in violation of applicable privacy laws or this Policy:

  • Internal Review: Contact our Privacy Contact directly at . We will acknowledge and investigate your complaint within a reasonable period.
  • Regulatory Escalation: If you are unsatisfied with our response, you retain the right to lodge a complaint with your local regulatory authority:
    • Australia: Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
    • EEA/UK: Your local EU Data Protection Authority or the UK Information Commissioner's Office (ICO).

19. Important Notice: Terms & Risk Disclaimer

This Privacy Policy addresses data collection and privacy practices only. DefiRilla provides informational monitoring and automated notifications only and does not provide financial, investment, legal, or tax advice. Alerts may experience delays or delivery failures due to network congestion or RPC node interruptions. For complete terms governing platform use, please consult our separate Terms of Service.

20. Contact Information

For all privacy-related questions, data requests, or complaints:

Support Email:
Registered Address: 102 Victoria Street, Carlton, Melbourne, Victoria 3053, Australia
Website: defirilla.com