If you have any questions about data protection, you may contact us at any time at the email address given above.
1.1 Data protection officer
Investboard GmbH is currently under no statutory obligation to appoint a data protection officer under Art. 37 GDPR in conjunction with Section 38(1) of the German Federal Data Protection Act (§ 38 Abs. 1 BDSG): as a rule, fewer than 20 people at our company are constantly engaged in the automated processing of personal data. Nor do our core activities consist of large-scale, regular and systematic monitoring within the meaning of Art. 37(1)(b) GDPR, and no large-scale processing of special categories of data under Art. 37(1)(c) GDPR takes place.
The responsible point of contact for all data protection matters is the management of Investboard GmbH (see section 1 “Controller”). You can reach us on data protection matters at . Enquiries are treated confidentially and answered within the statutory time limits under Art. 12(3) GDPR.
Investboard reviews the thresholds of Art. 37 GDPR and Section 38 BDSG on an ongoing basis and will appoint a data protection officer without undue delay as soon as one of the following triggers occurs: (a) at least 20 employees engaged in automated data processing, (b) the start of large-scale processing of special categories of data under Art. 9 GDPR, or (c) core activities consisting of large-scale, regular and systematic monitoring of data subjects within the meaning of Art. 37(1)(b) GDPR. The appointment will then be made by way of a qualified external data protection officer; the contact details will be published at this point and notified to the competent supervisory authority in accordance with Art. 37(7) GDPR.
2. Categories of data processed
When you use Investboard, we process the following categories of personal data:
Master data (account data)
Email address
Name
Access credentials. Your password is stored exclusively with our authentication provider Clerk (as a cryptographic hash); we do not store a password ourselves.
Subscription and billing information
Usage data
IP address. It is processed in order to deliver the pages, to authenticate you and to prevent abuse, and it is not stored for analytics purposes; in records of evidence it is stored only in truncated or cryptographically hashed form.
Browser type and version
Operating system
Date and time of access
Pages and features accessed
Portfolio data
Portfolio positions imported or entered by the user
CSV import data
Investment strategies and simulations
Watchlists and custom analyses
Asset, property and liability data
Assets held outside the securities account, such as bank balances, retirement provision, precious metals and other assets
Property, including valuations and value histories
Liabilities such as loans and credit, together with their terms
Asset overviews and their development over time
Household and family data
Details of your household and of persons with whom you view assets jointly, including their shares
Details of children, in so far as you record them for goals, allowances or transfers
Marital status and tax assessment type, in so far as required for calculations
Planned or recorded gifts and transfers
Tax data
Tax profile, church tax liability and solidarity surcharge
Exemption orders and their allocation
Loss pots, realised gains, advance lump sums and annual tax overviews
3. Purposes and legal bases of processing
Performance of a contract (Art. 6(1)(b) GDPR)
Provision and operation of the Investboard platform
User administration and authentication
Processing of portfolio data for analysis and for presenting strategies
Billing and payment processing
Receipt, allocation and handling of declarations of withdrawal
Legitimate interests (Art. 6(1)(f) GDPR)
Improvement and further development of our services
Detection and correction of technical faults
Security and abuse prevention
Anonymised, aggregated usage statistics
Consent (Art. 6(1)(a) GDPR)
Setting of non-essential cookies (see our Cookie policy (German))
Web analytics with PostHog in the browser (where you consent; the server-side measurement of completed registrations relies on legitimate interests, see section 8)
Legal obligation (Art. 6(1)(c) GDPR)
Retention of billing data in accordance with tax and commercial law requirements
Operation of the statutorily prescribed electronic withdrawal function and confirmation of its receipt
4. Recipients of the data
We disclose your personal data to third parties only in so far as this is necessary for the performance of the contract or we have a legal basis for doing so:
Supabase (database)
Supabase Inc.: storage of account and portfolio data. Data processing on EU servers.
Vercel (hosting)
Vercel Inc.: hosting and delivery of the web application. Edge network with data processing in the EU.
5. Retention periods
We store personal data only for as long as is necessary for the respective processing purposes:
Account data: for the duration of the contractual relationship and for up to 30 days after deletion of the account
Portfolio data: for the duration of the contractual relationship; deletion on request or on deletion of the account
Usage data: a maximum of 90 days, then anonymisation or deletion
Billing data: 10 years in accordance with the commercial and tax law retention periods (Section 147 of the German Fiscal Code, § 147 AO, and Section 257 of the German Commercial Code, § 257 HGB)
Declarations of withdrawal: as a rule for three years from the end of the calendar year in which the declaration was made, for processing and as evidence of statutory claims; longer only in so far as statutory retention obligations or pending proceedings require it
Error logs (Sentry): a maximum of 90 days
AI dialogues (history and content of your conversations): 7 years from creation, followed by automated deletion through a nightly deletion run. Irrespective of this, you may delete individual conversations yourself at any time; a deletion you initiate takes effect immediately and is not held up by this period.
AI logs (records of model calls, costs and safety checks): 7 years
Security logs (sign-ins, devices, security-relevant account changes): 10 years, to prevent and investigate abuse and as evidence towards supervisory authorities
Records of consent and approval: 10 years, as evidence under Art. 7(1) GDPR and to document the contract version accepted in each case
These periods are maximum periods. Where a statutory retention obligation exists, the record is blocked from further use until that obligation expires and is deleted thereafter. A request for erasure under Art. 17 GDPR remains unaffected, in so far as no statutory retention obligation stands in its way.
6. Your rights
Under the GDPR you have the following rights:
Right of access (Art. 15 GDPR): you have the right to request information about the personal data we process.
Right to rectification (Art. 16 GDPR): you may request the rectification of inaccurate data.
Right to erasure (Art. 17 GDPR): you may request the erasure of your data, provided that no statutory retention obligations stand in the way.
Right to restriction (Art. 18 GDPR): you may request the restriction of the processing of your data.
Right to data portability (Art. 20 GDPR): you have the right to receive your data in a structured, machine-readable format.
Right to object (Art. 21 GDPR): you may object to the processing of your data at any time.
Right to withdraw consent (Art. 7(3) GDPR): consent that has been given may be withdrawn at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
7. Cookies
Investboard uses cookies and similar technologies. Detailed information on the nature, scope and purposes of the cookies we use can be found in our Cookie policy (German).
8. Web analytics and performance measurement
We use PostHog as our web analytics solution. PostHog is operated for us on EU servers (Frankfurt). The processing is pseudonymous, not anonymous: a user identifier is assigned to the events collected, by means of which events can be attributed to a person.
We distinguish between two processing operations with different legal bases:
Analytics in the browser (consent-based): page views, click paths and feature usage. For this purpose, identifiers are stored on or read from your device. This processing takes place only if you have consented to analytics in the cookie banner (Section 25(1) of the German Telecommunications Digital Services Data Protection Act, § 25 Abs. 1 TDDDG, and Art. 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future via the cookie settings.
9. Third-party services in detail
Supabase
We use Supabase for database storage. Authentication is handled via Clerk (see sections 9.1 and 9.2). Supabase processes data on EU servers. A data processing agreement (Auftragsverarbeitungsvertrag, AVV) under Art. 28 GDPR has been concluded.
Vercel
Our web application is hosted on Vercel. In doing so, Vercel processes access metadata (IP addresses, user agent). Vercel offers data processing within the EU. A data processing agreement under Art. 28 GDPR has been concluded.
Sentry
We use Sentry to detect and correct technical faults. Sentry records error data such as stack traces, browser information and operating system data. Automatic data scrubbing rules remove content that may contain personal data.
The processing is pseudonymous, not anonymous: if you are signed in, your pseudonymous user identifier is attached to the error report so that we can attribute a fault to the account affected and remedy it specifically. The legal basis is our legitimate interest in stable and secure operation (Art. 6(1)(f) GDPR).
Session replay: only if you have expressly consented in the cookie banner does Sentry additionally record a replay of your session so that errors can be reconstructed. All texts and input fields are masked in the process, so that content you have entered is not transmitted; areas marked as sensitive are hidden entirely. Without your consent, no session replay takes place. You may withdraw your consent at any time via the cookie settings.
9.1 Transfer of personal data to third countries
Within the processor and recipient relationships named in section 9, personal data is in part transferred to providers established in the United States of America (USA). Under data protection law, the USA is regarded as an unsafe third country within the meaning of Articles 44 et seq. GDPR. A transfer takes place exclusively on one of the following legal bases:
EU-U.S. Data Privacy Framework (DPF): adequacy decision of the EU Commission of 10 July 2023 (C(2023) 4745). Providers holding a valid DPF certification are deemed to offer an adequate level of data protection under Art. 45 GDPR. You can view the certification status of each provider at .
9.2 Data processing agreements (Art. 28 GDPR)
Where we have personal data processed by external service providers, we conclude a data processing agreement (DPA) with them in accordance with Art. 28(3) GDPR. The DPA obliges the processor to process data exclusively in accordance with our documented instructions, to implement appropriate technical and organisational measures (TOMs) in accordance with Art. 32 GDPR and to support us in meeting our obligations towards data subjects. The legal bases for the third-country transfers required alongside this are set out in section 9.1 of this Privacy policy (DPF, SCC and, where applicable, consent).
The following table names all processors with which Investboard currently works. Data processing agreements under Art. 28 GDPR are in place with all processors that process personal data on our behalf. We will provide you with a copy of the respective DPA on request. Please address your request to datenschutz@investboard.de.
Supabase Inc.
Purpose of processing
Database storage (EU region eu-central-1)
Category of data
Master data, portfolio data, application data
Vercel Inc.
Purpose of processing
Web hosting (EU region Frankfurt fra1)
Category of data
Access metadata, IP addresses, user agent
Clerk Inc.
10. Disclosure of data to wealthAPI GmbH (account aggregation)
If you link your brokerage or bank account to Investboard, we transmit the following data to wealthAPI GmbH (provider of the account information service, AIS, see Terms of use section 9):
A pseudonymised user identifier (no plaintext email address, no plaintext name).
The time and the result of the authentication request, for diagnostic purposes.
We do NOT transmit
Your plaintext name, your email address or your postal address.
Your Investboard access credentials (password, two-factor codes).
Your tax identification number or other financial identifiers.
What wealthAPI provides for us
A secure PSD2/AIS-compliant connection to your bank or your broker (supervised by BaFin).
Anonymised brokerage data (positions, transactions) for transfer to Investboard.
Local storage at Investboard
Refresh tokens used to establish the connection are stored by us in a table (investboard_external_provider_user.refresh_token) that is accessible exclusively to our servers. Access is restricted to the service context by Row Level Security; access through our interfaces is possible neither for you nor for third parties.
We do not store a password for your wealthAPI account. Where required, it is derived from a secret that is held exclusively on the server side and is never transmitted to your device.
If your Investboard account is deleted, the associated tokens are removed automatically through a CASCADE relationship; you may additionally request confirmation of the disconnection at wealthAPI.
11. Changes to this Privacy policy
We reserve the right to amend this Privacy policy in order to adapt it to changes in the law or to changes in our service. The version in force at any given time is always available on this page. Registered users are informed by email of material changes.
12. Contact for data protection enquiries
If you have questions about data protection or wish to exercise your data subject rights, please contact:
Goals, financial situation and investment strategy
Details of income, expenditure, savings rate and financial situation
Investment goals, time horizons and milestones
Answers on your risk appetite and the classifications derived from them
Your investment strategy (investment policy statement), including its change history and self-commitments
Linked bank and securities accounts
Name and identifier of linked bank and securities accounts
Holdings and transactions retrieved via the account information service (see section 10)
Status and metadata of the link, as well as retrieval logs
AI dialogue data
Your inputs and questions to the AI features, as well as the responses generated
The extract of your portfolio and planning data used as the basis in each case (the context of the dialogue)
Logs of model calls, costs and safety checks
Behavioural and decision data
Deviations from your investment strategy and their documentation
Analyses of trading activity and its costs, and of its consistency with your plan
Interactions with notices and recommendations, such as dismissing them
Search histories within the application
Communication, support and security data
Notification settings, push identifiers of your devices and email consents
Reports, briefings and analyses sent, as well as their delivery, open and click status
Support enquiries and messages sent via the contact form
Security logs on sign-ins, devices used and security-relevant account changes
Records of consents granted and of contract versions accepted
Learning progress in the knowledge content
Withdrawal declaration data
Name, confirmation email address and voluntary postal address
Contract reference and, where applicable, the date the contract was concluded
Time of receipt, case number and version of the withdrawal notice
Technical evidence data (truncated user agent and, where applicable, cryptographically hashed IP address)
PostHog (web analytics)
PostHog Inc.: web analytics, EU-hosted. Analytics in the browser takes place only with your consent; the server-side measurement of completed registrations is carried out pseudonymously on the basis of legitimate interests (see section 8).
Sentry (error tracking)
Functional Software Inc.: technical error tracking to improve platform stability. Error data with a pseudonymous user identifier; session replay only with consent (see section 9).
Google Ads (conversion measurement)
Google Ireland Limited: measurement of which of our ads lead to a registration. The Google tag is embedded on every page and transmits your IP address in the process; storage on your device takes place only with your consent (see section 8).
Server-side registration measurement (legitimate interests): when a registration is completed, we transmit an event containing your pseudonymous user identifier, the registration method chosen and, where present, the origin marker of the visit (ref/utm parameters). No identifiers are stored on or read from your device in the process, which is why Section 25 TDDDG does not apply. The legal basis is our legitimate interest in measuring and improving the registration process (Art. 6(1)(f) GDPR). You may object to this processing under Art. 21 GDPR.
No contact data: neither your email address nor your name, your postal address or your telephone number is transmitted to PostHog. The IP address is not stored for analytics purposes.
In addition, we use Vercel Analytics and Vercel Speed Insights from our hosting provider Vercel (see section 9.2). These services work without cookies and do not place any identifiers on your device. They transmit aggregated page view, interaction and load time telemetry to Vercel (web vitals as well as counted events without any personal reference, such as clicks on key buttons and the visibility of page sections) in order to measure the stability, speed and comprehensibility of the platform. The legal basis is our legitimate interest in the secure and performant operation of the platform (Art. 6(1)(f) GDPR).
Google Ads conversion measurement
We place ads with Google and measure which of these ads lead to a registration. For this purpose, the Google tag (gtag.js) is embedded on every page of this website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose of the processing: exclusively the measurement of conversions, that is, attributing a completion on this website to a preceding ad click. We do not build remarketing audiences, do not run personalised advertising and do not transmit email addresses or other contact data to Google (no “enhanced conversions”).
Public pages only: a page view is reported to Google exclusively on the publicly accessible pages (home page, product and knowledge pages, legal texts as well as sign-in and registration). Within the signed-in area no page view is reported to Google; the addresses accessed there, for example those of individual portfolios or analyses, do not leave the platform. Even for the pages that are reported, we transmit the address without query parameters.
Consent and Google Consent Mode v2: the tag is loaded as soon as you call up the page, but by default operates in the “denied” state. In this state, Google does not store or read any identifier on your device, and click identifiers are additionally suppressed (ads_data_redaction). Storage on your device, in particular the _gcl_au cookie, takes place only once you have consented to marketing storage in the cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw this consent at any time with effect for the future via the cookie settings.
Processing even without consent: because the tag is loaded before you make your decision, your IP address is transmitted to Google for technical reasons, and Google receives the information that a page view has taken place, without any identifier being stored on or read from your device. The legal basis for this is our legitimate interest in measuring the success of our advertising (Art. 6(1)(f) GDPR). You may object to this processing under Art. 21 GDPR.
Transfer to the USA: our contractual partner is Google Ireland Limited, established in the EU. A transfer to Google LLC in the USA cannot be ruled out; it is based on the adequacy decision on the EU-U.S. Data Privacy Framework, under which Google LLC is certified, supplemented by the EU standard contractual clauses. Details can be found in section 9.1.
EU standard contractual clauses (SCC): Module 2 or 3 in the version of 4 June 2021 (Implementing Decision (EU) 2021/914), concluded between Investboard and the respective provider, supplemented by additional safeguards in accordance with the Schrems II case law (CJEU, judgment of 16 July 2020 – C-311/18) and by a transfer impact assessment (TIA) in accordance with EDPB Recommendations 01/2020.
Explicit consent under Art. 49(1)(a) GDPR, only in narrowly limited individual cases, which we make transparent to you in advance.
Specific third-country transfers by provider
Clerk Inc.
Registered office
USA (San Francisco, CA)
Data transferred
Email address, password hash, IP address, session metadata
Legal basis
SCC Module 2 + TIA; DPF certification will be verified before market entry
Stripe Payments Europe Ltd. (with US group affiliates)
EU contracting party; intra-group transfer on the basis of SCC Module 3
Resend Inc.
Registered office
USA
Data transferred
Email address, the content of transactional and consented optional emails, as well as delivery, open and click events
Legal basis
SCC Module 2 + TIA
You may inspect the current version of the standard contractual clauses and of the transfer impact assessments on request at datenschutz@investboard.de.
Despite these safeguards, a residual risk remains that US security authorities (in particular under FISA 702 and EO 12333) could access transferred data. Investboard cannot give a full guarantee of a level of data protection comparable to that of the EU. If you do not want this transfer, you cannot use our services in full.
Purpose of processing
Authentication, session and user administration
Category of data
Email address, password hash, IP address, session metadata
Dispatch of transactional and consented optional emails; processing of delivery, open and click events
Email address, email content, delivery status, time of opening and of clicking
Functional Software, Inc. (Sentry)
Recording and diagnosis of technical application errors
Error data with pseudonymous user identifier, stack traces, browser metadata; with consent, additionally masked session replay
An internal list of all processors, with their registered office, category of data, date of signature, DPF status and the date of the transfer impact assessment (TIA), is maintained in the record of processing activities in accordance with Art. 30 GDPR and submitted to the competent supervisory authority on request. The legal bases for the third-country transfers required alongside this (DPF, SCC, consent) are set out in section 9.1 of this Privacy policy.
Financial Modeling Prep (FMP)
Registered office
USA
Data transferred
no personal data, exclusively anonymised market data queries
Legal basis
no transfer of personal data
Twelve Data Inc.
Registered office
USA
Data transferred
no personal data, exclusively anonymised market data queries
Legal basis
no transfer of personal data
Upstash, Inc.
Registered office
USA
Data transferred
pseudonymous user and session identifiers (Clerk ids), cached derived metrics
Legal basis
SCC Module 2 + TIA
Arcjet, Inc.
Registered office
USA
Data transferred
IP address, request metadata (security and abuse analysis)
Legal basis
SCC Module 2 + TIA
Google Ireland Limited (Google Ads)
Registered office
Ireland (EU); onward transfer to Google LLC, USA
Data transferred
IP address, page-call metadata; after consent, additionally the conversion identifier from the _gcl_au cookie
Legal basis
DPF (Google LLC certified) + SCC Module 2
Provider
Registered office
Data transferred
Legal basis
Clerk Inc.
USA (San Francisco, CA)
Email address, password hash, IP address, session metadata
SCC Module 2 + TIA; DPF certification will be verified before market entry
Stripe Payments Europe Ltd. (with US group affiliates)