Privacy policy
Last updated: 5 August 2026 · Version 2.1
1. Controller
If you have any questions about data protection, you may contact us at any time at the email address given above.
1.1 Data protection officer
Investboard GmbH is currently under no statutory obligation to appoint a data protection officer under Art. 37 GDPR in conjunction with Section 38(1) of the German Federal Data Protection Act (§ 38 Abs. 1 BDSG): as a rule, fewer than 20 people at our company are constantly engaged in the automated processing of personal data. Nor do our core activities consist of large-scale, regular and systematic monitoring within the meaning of Art. 37(1)(b) GDPR, and no large-scale processing of special categories of data under Art. 37(1)(c) GDPR takes place.
The responsible point of contact for all data protection matters is the management of Investboard GmbH (see section 1 “Controller”). You can reach us on data protection matters at datenschutz@investboard.de. Enquiries are treated confidentially and answered within the statutory time limits under Art. 12(3) GDPR.
Investboard reviews the thresholds of Art. 37 GDPR and Section 38 BDSG on an ongoing basis and will appoint a data protection officer without undue delay as soon as one of the following triggers occurs: (a) at least 20 employees engaged in automated data processing, (b) the start of large-scale processing of special categories of data under Art. 9 GDPR, or (c) core activities consisting of large-scale, regular and systematic monitoring of data subjects within the meaning of Art. 37(1)(b) GDPR. The appointment will then be made by way of a qualified external data protection officer; the contact details will be published at this point and notified to the competent supervisory authority in accordance with Art. 37(7) GDPR.
2. Categories of data processed
When you use Investboard, we process the following categories of personal data:
Master data (account data)
- Email address
- Name
- Access credentials. Your password is stored exclusively with our authentication provider Clerk (as a cryptographic hash); we do not store a password ourselves.
- Subscription and billing information
Usage data
- IP address. It is processed in order to deliver the pages, to authenticate you and to prevent abuse, and it is not stored for analytics purposes; in records of evidence it is stored only in truncated or cryptographically hashed form.
- Browser type and version
- Operating system
- Date and time of access
- Pages and features accessed
Portfolio data
- Portfolio positions imported or entered by the user
- CSV import data
- Investment strategies and simulations
- Watchlists and custom analyses
Asset, property and liability data
- Assets held outside the securities account, such as bank balances, retirement provision, precious metals and other assets
- Property, including valuations and value histories
- Liabilities such as loans and credit, together with their terms
- Asset overviews and their development over time
Household and family data
- Details of your household and of persons with whom you view assets jointly, including their shares
- Details of children, in so far as you record them for goals, allowances or transfers
- Marital status and tax assessment type, in so far as required for calculations
- Planned or recorded gifts and transfers
Tax data
- Tax profile, church tax liability and solidarity surcharge
- Exemption orders and their allocation
- Loss pots, realised gains, advance lump sums and annual tax overviews
Goals, financial situation and investment strategy
- Details of income, expenditure, savings rate and financial situation
- Investment goals, time horizons and milestones
- Answers on your risk appetite and the classifications derived from them
- Your investment strategy (investment policy statement), including its change history and self-commitments
Linked bank and securities accounts
- Name and identifier of linked bank and securities accounts
- Holdings and transactions retrieved via the account information service (see section 10)
- Status and metadata of the link, as well as retrieval logs
AI dialogue data
- Your inputs and questions to the AI features, as well as the responses generated
- The extract of your portfolio and planning data used as the basis in each case (the context of the dialogue)
- Logs of model calls, costs and safety checks
Behavioural and decision data
- Deviations from your investment strategy and their documentation
- Analyses of trading activity and its costs, and of its consistency with your plan
- Interactions with notices and recommendations, such as dismissing them
- Search histories within the application
Communication, support and security data
- Notification settings, push identifiers of your devices and email consents
- Reports, briefings and analyses sent, as well as their delivery, open and click status
- Support enquiries and messages sent via the contact form
- Security logs on sign-ins, devices used and security-relevant account changes
- Records of consents granted and of contract versions accepted
- Learning progress in the knowledge content
Withdrawal declaration data
- Name, confirmation email address and voluntary postal address
- Contract reference and, where applicable, the date the contract was concluded
- Time of receipt, case number and version of the withdrawal notice
- Technical evidence data (truncated user agent and, where applicable, cryptographically hashed IP address)
3. Purposes and legal bases of processing
Performance of a contract (Art. 6(1)(b) GDPR)
- Provision and operation of the Investboard platform
- User administration and authentication
- Processing of portfolio data for analysis and for presenting strategies
- Billing and payment processing
- Receipt, allocation and handling of declarations of withdrawal
Legitimate interests (Art. 6(1)(f) GDPR)
- Improvement and further development of our services
- Detection and correction of technical faults
- Security and abuse prevention
- Anonymised, aggregated usage statistics
Consent (Art. 6(1)(a) GDPR)
- Setting of non-essential cookies (see our Cookie policy (German))
- Web analytics with PostHog in the browser (where you consent; the server-side measurement of completed registrations relies on legitimate interests, see section 8)
Legal obligation (Art. 6(1)(c) GDPR)
- Retention of billing data in accordance with tax and commercial law requirements
- Operation of the statutorily prescribed electronic withdrawal function and confirmation of its receipt
4. Recipients of the data
We disclose your personal data to third parties only in so far as this is necessary for the performance of the contract or we have a legal basis for doing so:
Supabase (database)
Supabase Inc.: storage of account and portfolio data. Data processing on EU servers.
Vercel (hosting)
Vercel Inc.: hosting and delivery of the web application. Edge network with data processing in the EU.
PostHog (web analytics)
PostHog Inc.: web analytics, EU-hosted. Analytics in the browser takes place only with your consent; the server-side measurement of completed registrations is carried out pseudonymously on the basis of legitimate interests (see section 8).
Sentry (error tracking)
Functional Software Inc.: technical error tracking to improve platform stability. Error data with a pseudonymous user identifier; session replay only with consent (see section 9).
Google Ads (conversion measurement)
Google Ireland Limited: measurement of which of our ads lead to a registration. The Google tag is embedded on every page and transmits your IP address in the process; storage on your device takes place only with your consent (see section 8).
5. Retention periods
We store personal data only for as long as is necessary for the respective processing purposes:
- Account data: for the duration of the contractual relationship and for up to 30 days after deletion of the account
- Portfolio data: for the duration of the contractual relationship; deletion on request or on deletion of the account
- Usage data: a maximum of 90 days, then anonymisation or deletion
- Billing data: 10 years in accordance with the commercial and tax law retention periods (Section 147 of the German Fiscal Code, § 147 AO, and Section 257 of the German Commercial Code, § 257 HGB)
- Declarations of withdrawal: as a rule for three years from the end of the calendar year in which the declaration was made, for processing and as evidence of statutory claims; longer only in so far as statutory retention obligations or pending proceedings require it
- Error logs (Sentry): a maximum of 90 days
- AI dialogues (history and content of your conversations): 7 years from creation, followed by automated deletion through a nightly deletion run. Irrespective of this, you may delete individual conversations yourself at any time; a deletion you initiate takes effect immediately and is not held up by this period.
- AI logs (records of model calls, costs and safety checks): 7 years
- Security logs (sign-ins, devices, security-relevant account changes): 10 years, to prevent and investigate abuse and as evidence towards supervisory authorities
- Records of consent and approval: 10 years, as evidence under Art. 7(1) GDPR and to document the contract version accepted in each case
These periods are maximum periods. Where a statutory retention obligation exists, the record is blocked from further use until that obligation expires and is deleted thereafter. A request for erasure under Art. 17 GDPR remains unaffected, in so far as no statutory retention obligation stands in its way.
6. Your rights
Under the GDPR you have the following rights:
- Right of access (Art. 15 GDPR): you have the right to request information about the personal data we process.
- Right to rectification (Art. 16 GDPR): you may request the rectification of inaccurate data.
- Right to erasure (Art. 17 GDPR): you may request the erasure of your data, provided that no statutory retention obligations stand in the way.
- Right to restriction (Art. 18 GDPR): you may request the restriction of the processing of your data.
- Right to data portability (Art. 20 GDPR): you have the right to receive your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): you may object to the processing of your data at any time.
- Right to withdraw consent (Art. 7(3) GDPR): consent that has been given may be withdrawn at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
7. Cookies
Investboard uses cookies and similar technologies. Detailed information on the nature, scope and purposes of the cookies we use can be found in our Cookie policy (German).
8. Web analytics and performance measurement
We use PostHog as our web analytics solution. PostHog is operated for us on EU servers (Frankfurt). The processing is pseudonymous, not anonymous: a user identifier is assigned to the events collected, by means of which events can be attributed to a person.
We distinguish between two processing operations with different legal bases:
- Analytics in the browser (consent-based): page views, click paths and feature usage. For this purpose, identifiers are stored on or read from your device. This processing takes place only if you have consented to analytics in the cookie banner (Section 25(1) of the German Telecommunications Digital Services Data Protection Act, § 25 Abs. 1 TDDDG, and Art. 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future via the cookie settings.
- Server-side registration measurement (legitimate interests): when a registration is completed, we transmit an event containing your pseudonymous user identifier, the registration method chosen and, where present, the origin marker of the visit (ref/utm parameters). No identifiers are stored on or read from your device in the process, which is why Section 25 TDDDG does not apply. The legal basis is our legitimate interest in measuring and improving the registration process (Art. 6(1)(f) GDPR). You may object to this processing under Art. 21 GDPR.
No contact data: neither your email address nor your name, your postal address or your telephone number is transmitted to PostHog. The IP address is not stored for analytics purposes.
In addition, we use Vercel Analytics and Vercel Speed Insights from our hosting provider Vercel (see section 9.2). These services work without cookies and do not place any identifiers on your device. They transmit aggregated page view, interaction and load time telemetry to Vercel (web vitals as well as counted events without any personal reference, such as clicks on key buttons and the visibility of page sections) in order to measure the stability, speed and comprehensibility of the platform. The legal basis is our legitimate interest in the secure and performant operation of the platform (Art. 6(1)(f) GDPR).
Google Ads conversion measurement
We place ads with Google and measure which of these ads lead to a registration. For this purpose, the Google tag (gtag.js) is embedded on every page of this website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose of the processing: exclusively the measurement of conversions, that is, attributing a completion on this website to a preceding ad click. We do not build remarketing audiences, do not run personalised advertising and do not transmit email addresses or other contact data to Google (no “enhanced conversions”).
Public pages only: a page view is reported to Google exclusively on the publicly accessible pages (home page, product and knowledge pages, legal texts as well as sign-in and registration). Within the signed-in area no page view is reported to Google; the addresses accessed there, for example those of individual portfolios or analyses, do not leave the platform. Even for the pages that are reported, we transmit the address without query parameters.
Consent and Google Consent Mode v2: the tag is loaded as soon as you call up the page, but by default operates in the “denied” state. In this state, Google does not store or read any identifier on your device, and click identifiers are additionally suppressed (ads_data_redaction). Storage on your device, in particular the _gcl_au cookie, takes place only once you have consented to marketing storage in the cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw this consent at any time with effect for the future via the cookie settings.
Processing even without consent: because the tag is loaded before you make your decision, your IP address is transmitted to Google for technical reasons, and Google receives the information that a page view has taken place, without any identifier being stored on or read from your device. The legal basis for this is our legitimate interest in measuring the success of our advertising (Art. 6(1)(f) GDPR). You may object to this processing under Art. 21 GDPR.
Transfer to the USA: our contractual partner is Google Ireland Limited, established in the EU. A transfer to Google LLC in the USA cannot be ruled out; it is based on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Google LLC is certified, supplemented by the EU standard contractual clauses. Details can be found in section 9.1.
9. Third-party services in detail
Supabase
We use Supabase for database storage. Authentication is handled via Clerk (see sections 9.1 and 9.2). Supabase processes data on EU servers. A data processing agreement (Auftragsverarbeitungsvertrag, AVV) under Art. 28 GDPR has been concluded.
Vercel
Our web application is hosted on Vercel. In doing so, Vercel processes access metadata (IP addresses, user agent). Vercel offers data processing within the EU. A data processing agreement under Art. 28 GDPR has been concluded.
Sentry
We use Sentry to detect and correct technical faults. Sentry records error data such as stack traces, browser information and operating system data. Automatic data scrubbing rules remove content that may contain personal data.
The processing is pseudonymous, not anonymous: if you are signed in, your pseudonymous user identifier is attached to the error report so that we can attribute a fault to the account affected and remedy it specifically. The legal basis is our legitimate interest in stable and secure operation (Art. 6(1)(f) GDPR).
Session replay: only if you have expressly consented in the cookie banner does Sentry additionally record a replay of your session so that errors can be reconstructed. All texts and input fields are masked in the process, so that content you have entered is not transmitted; areas marked as sensitive are hidden entirely. Without your consent, no session replay takes place. You may withdraw your consent at any time via the cookie settings.
9.1 Transfer of personal data to third countries
Within the processor and recipient relationships named in section 9, personal data is in part transferred to providers established in the United States of America (USA). Under data protection law, the USA is regarded as an unsafe third country within the meaning of Articles 44 et seq. GDPR. A transfer takes place exclusively on one of the following legal bases:
- EU-U.S. Data Privacy Framework (DPF): adequacy decision of the EU Commission of 10 July 2023 (C(2023) 4745). Providers holding a valid DPF certification are deemed to offer an adequate level of data protection under Art. 45 GDPR. You can view the certification status of each provider at dataprivacyframework.gov.
- EU standard contractual clauses (SCC): Module 2 or 3 in the version of 4 June 2021 (Implementing Decision (EU) 2021/914), concluded between Investboard and the respective provider, supplemented by additional safeguards in accordance with the Schrems II case law (CJEU, judgment of 16 July 2020 – C-311/18) and by a transfer impact assessment (TIA) in accordance with EDPB Recommendations 01/2020.
- Explicit consent under Art. 49(1)(a) GDPR, only in narrowly limited individual cases, which we make transparent to you in advance.
Specific third-country transfers by provider
- Clerk Inc.
- Registered office
- USA (San Francisco, CA)
- Data transferred
- Email address, password hash, IP address, session metadata
- Legal basis
- SCC Module 2 + TIA; DPF certification will be verified before market entry
- Stripe Payments Europe Ltd. (with US group affiliates)
- Registered office
- Ireland (with transfer to the USA)
- Data transferred
- Name, billing address, payment method metadata, transaction amount
- Legal basis
- EU contracting party; intra-group transfer on the basis of SCC Module 3
- Resend Inc.
- Registered office
- USA
- Data transferred
- Email address, the content of transactional and consented optional emails, as well as delivery, open and click events
- Legal basis
- SCC Module 2 + TIA
- Financial Modeling Prep (FMP)
- Registered office
- USA
- Data transferred
- no personal data, exclusively anonymised market data queries
- Legal basis
- no transfer of personal data
- Twelve Data Inc.
- Registered office
- USA
- Data transferred
- no personal data, exclusively anonymised market data queries
- Legal basis
- no transfer of personal data
- Upstash, Inc.
- Registered office
- USA
- Data transferred
- pseudonymous user and session identifiers (Clerk ids), cached derived metrics
- Legal basis
- SCC Module 2 + TIA
- Arcjet, Inc.
- Registered office
- USA
- Data transferred
- IP address, request metadata (security and abuse analysis)
- Legal basis
- SCC Module 2 + TIA
- Google Ireland Limited (Google Ads)
- Registered office
- Ireland (EU); onward transfer to Google LLC, USA
- Data transferred
- IP address, page-call metadata; after consent, additionally the conversion identifier from the _gcl_au cookie
- Legal basis
- DPF (Google LLC certified) + SCC Module 2
You may inspect the current version of the standard contractual clauses and of the transfer impact assessments on request at datenschutz@investboard.de.
Despite these safeguards, a residual risk remains that US security authorities (in particular under FISA 702 and EO 12333) could access transferred data. Investboard cannot give a full guarantee of a level of data protection comparable to that of the EU. If you do not want this transfer, you cannot use our services in full.
9.2 Data processing agreements (Art. 28 GDPR)
Where we have personal data processed by external service providers, we conclude a data processing agreement (DPA) with them in accordance with Art. 28(3) GDPR. The DPA obliges the processor to process data exclusively in accordance with our documented instructions, to implement appropriate technical and organisational measures (TOMs) in accordance with Art. 32 GDPR and to support us in meeting our obligations towards data subjects. The legal bases for the third-country transfers required alongside this are set out in section 9.1 of this Privacy policy (DPF, SCC and, where applicable, consent).
The following table names all processors with which Investboard currently works. Data processing agreements under Art. 28 GDPR are in place with all processors that process personal data on our behalf. We will provide you with a copy of the respective DPA on request. Please address your request to datenschutz@investboard.de.
- Supabase Inc.
- Purpose of processing
- Database storage (EU region eu-central-1)
- Category of data
- Master data, portfolio data, application data
- Vercel Inc.
- Purpose of processing
- Web hosting (EU region Frankfurt fra1)
- Category of data
- Access metadata, IP addresses, user agent
- Clerk Inc.
- Purpose of processing
- Authentication, session and user administration
- Category of data
- Email address, password hash, IP address, session metadata
- Stripe Payments Europe Ltd.
- Purpose of processing
- Payment processing, subscription administration
- Category of data
- Name, billing address, payment method metadata, transaction amount
- Resend Inc.
- Purpose of processing
- Dispatch of transactional and consented optional emails; processing of delivery, open and click events
- Category of data
- Email address, email content, delivery status, time of opening and of clicking
- Functional Software, Inc. (Sentry)
- Purpose of processing
- Recording and diagnosis of technical application errors
- Category of data
- Error data with pseudonymous user identifier, stack traces, browser metadata; with consent, additionally masked session replay
- Amazon Web Services EMEA SARL
- Purpose of processing
- Compute hosting (ECS Fargate, crons, mobile/REST API) and AI inference via Amazon Bedrock, EU region eu-central-1 (Frankfurt)
- Category of data
- Application data in processing and in transit, content of AI inputs (prompts); at the user’s request, possibly portfolio context
- Upstash, Inc.
- Purpose of processing
- High-availability cache and rate limiting (Redis)
- Category of data
- pseudonymous user and session identifiers (Clerk ids), cached derived metrics
- Arcjet, Inc.
- Purpose of processing
- Security and abuse protection (rate limiting)
- Category of data
- IP address, request metadata
- Financial Modeling Prep (FMP)
- Purpose of processing
- Market data queries (prices, fundamentals)
- Category of data
- no personal data, server-to-server anonymised symbol queries
- Twelve Data Inc.
- Purpose of processing
- Market data streaming (real-time prices via WebSocket)
- Category of data
- no personal data, server-to-server anonymised symbol queries from a central consumer service
- wealthAPI GmbH
- Purpose of processing
- Account information service (Kontoinformationsdienst, PSD2 / AIS), aggregation of brokerage and bank accounts
- Category of data
- pseudonymised user identifier, authentication metadata (see section 10)
- PostHog, Inc.
- Purpose of processing
- Product and usage analytics, measurement of the registration process (EU hosting Frankfurt, see section 8)
- Category of data
- pseudonymous user identifier, event and page view data, device and browser metadata; no contact data
- Usercentrics GmbH (Munich)
- Purpose of processing
- Consent management (consent management platform), documentation and withdrawal of your cookie consent
- Category of data
- Consent id, time and scope of the consent, IP address, device and browser metadata
An internal list of all processors, with their registered office, category of data, date of signature, DPF status and the date of the transfer impact assessment (TIA), is maintained in the record of processing activities in accordance with Art. 30 GDPR and submitted to the competent supervisory authority on request. The legal bases for the third-country transfers required alongside this (DPF, SCC, consent) are set out in section 9.1 of this Privacy policy.
10. Disclosure of data to wealthAPI GmbH (account aggregation)
If you link your brokerage or bank account to Investboard, we transmit the following data to wealthAPI GmbH (provider of the account information service, AIS, see Terms of use section 9):
- A pseudonymised user identifier (no plaintext email address, no plaintext name).
- The time and the result of the authentication request, for diagnostic purposes.
We do NOT transmit
- Your plaintext name, your email address or your postal address.
- Your Investboard access credentials (password, two-factor codes).
- Your tax identification number or other financial identifiers.
What wealthAPI provides for us
- A secure PSD2/AIS-compliant connection to your bank or your broker (supervised by BaFin).
- Anonymised brokerage data (positions, transactions) for transfer to Investboard.
Local storage at Investboard
- Refresh tokens used to establish the connection are stored by us in a table (
investboard_external_provider_user.refresh_token) that is accessible exclusively to our servers. Access is restricted to the service context by Row Level Security; access through our interfaces is possible neither for you nor for third parties. - We do not store a password for your wealthAPI account. Where required, it is derived from a secret that is held exclusively on the server side and is never transmitted to your device.
- If your Investboard account is deleted, the associated tokens are removed automatically through a CASCADE relationship; you may additionally request confirmation of the disconnection at wealthAPI.
11. Changes to this Privacy policy
We reserve the right to amend this Privacy policy in order to adapt it to changes in the law or to changes in our service. The version in force at any given time is always available on this page. Registered users are informed by email of material changes.
12. Contact for data protection enquiries
If you have questions about data protection or wish to exercise your data subject rights, please contact: