inverist

Privacy Policy

Version date: 2026-08-29

1. Controller

The service is offered under the name inverist. The controller for the processing of your personal data is:

Björn Frauen
4541 Apesia
Cyprus Email: info@inverist.com

No data protection officer has been appointed; none is required by law. Please address enquiries to the above.

2. Where your data is held

The service runs on a server administered by the provider itself, in a data centre in Germany (operator: netcup GmbH). The database is operated by the provider itself.

No managed database or backend service that could read your data in clear text is used — deliberately. The aim is to keep the number of parties able to read your data as small as possible.

Transmission between your device and the server is encrypted in transit (HTTPS) without exception. Credentials for bank and broker interfaces are additionally encrypted at rest (see section 4).

3. What data is processed

Account and sign-in data: email address, display name, first and last name, country, language, avatar selection, password only as a hash; where two-factor authentication is enabled, the encrypted shared secret and the hashes of the recovery codes; the times of creation and last sign-in.

Session and security data: session identifier (as a hash only), IP address and browser identification at the time of sign-in, timestamps, failed attempts for rate limiting, and acceptances of the legal texts with time, IP address, browser identification and a checksum of the wording displayed.

Content data: everything you record or import into the service — transactions, holdings, valuations, ideas, decisions, notes and comments, uploaded research documents and the analyses derived from them.

Bank and broker connection data: interface credentials you store yourself. PINs and TANs are not stored.

Problem and request reports: when you report a problem or a request through the Report button in the application, we process the text you write, the kind of report, and — for faults — your assessment of how badly it affects you.

We also attach technical context automatically, which you do not type: the address of the page and the area you were in, the active view, the running build, your language setting, the size of the browser window, the browser identification, and the last ten error messages the browser produced on that page. Without these a fault usually cannot be reproduced.

Files you attach to a report are stored with it. A screenshot can contain portfolio data — what you attach is your decision.

Server logs: technical logs of the web server and the application for troubleshooting and attack detection.

4. Purposes and legal bases

Processing for advertising purposes and any sale of data do not take place. Your content is not evaluated across mandates.

One exception, named: reports made through the Report button are read in a single list across mandates. That is running the platform, not evaluating your portfolio — a fault usually affects several mandates, and separate lists would mean hunting the same fault more than once. Only the platform operator has access, not your adviser and no other user. You see your own reports in the application; you do not see anyone else's.

5. Recipients

Hosting: netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany — operation of the servers. A data processing agreement pursuant to Art. 28 GDPR (version 2026/07) is in place with netcup. netcup in turn engages sub-processors within the Anexia group of companies: Anexia Holding GmbH and Anexia Cloud Solutions GmbH, Feldkirchner Straße 140, 9020 Klagenfurt, Austria, and Anexia Cloud Solutions GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The data centre locations are Nuremberg and Vienna.

Backups: Database backups are stored encrypted on a Storage Box operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Encryption takes place on our own server before transfer; the key remains exclusively with us, so the storage provider has no access to the plaintext data. In addition, a copy is retained for 14 days on the same server that runs the application.

Email delivery: System messages (invitation, password reset, confirmations) are sent by our own mail server, running on the same machine as the application. No external delivery service is used; your email address and the message content are not passed on to any further recipient. The only processor involved is netcup GmbH, named above, on whose infrastructure the mail server runs; the data processing agreement stated there also covers this processing. To deliver to your mailbox provider, our server connects directly to that provider's mail server; the transfer is encrypted where your provider's mail server offers transport encryption. The content of transactional messages is limited to a link, its expiry and one sentence of context — no portfolio data. Opens and link clicks are not tracked.

Answers to your reports go out the same way. They contain the answer we write and the number of your report — not the text you typed yourself, and no attached files. So the same holds here: no portfolio data in the mail. What you reported you read in the application.

Market data providers (including Yahoo Finance, Finnhub): to update prices and metrics the server retrieves data from these providers. This transmits security identifiers and the server's IP address — not your identity, not your holdings and not your quantities. Your own IP address is not transmitted, because the retrieval originates from the server, not from your device.

Your bank or broker where you set up a connection: transmitting your credentials to that institution is a necessary part of the retrieval you trigger. The institution is the controller for the processing that takes place there.

Public authorities, insofar as we are legally obliged.

As matters currently stand, no transfer to countries outside the EU and the EEA takes place.

6. Cookies and analytics

The service sets a single cookie: the session identifier after sign-in. It is technically necessary, becomes invalid on sign-out and serves no analytical purpose.

There is no tracking: no analytics services, no advertising networks, no embedded external fonts, maps or scripts. There is therefore also no cookie consent banner.

7. Retention

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Any consent given may be withdrawn at any time with effect for the future.

Please write to info@inverist.com. While the self-service functions for export and deletion are not yet available, we handle such requests manually within the statutory period of one month.

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: Office of the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), P.O. Box 23378, 1682 Nicosia, Cyprus, phone +357 22 818 456, commissioner@dataprotection.gov.cy, www.dataprotection.gov.cy.

9. Automated decisions

No automated decision-making producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR takes place. The scores, rankings and colour codes shown in the service are evaluations of your own inputs, not a decision about you; see no investment advice.

10. Obligation to provide data

Providing an email address and a password is necessary to create the account. All further details are voluntary; without them individual functions are unavailable.

11. Changes

This policy is adapted when the processing changes. An amended version is presented to you at your next sign-in.

Sign in Deutsch