Privacy Policy

← Back to Home

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you use the TradingControl platform. Personal data is any data with which you can be personally identified. For detailed information on data protection, please refer to the full privacy policy below.

Data Collection on This Platform

Who is responsible for data collection?

Data processing on this platform is carried out by the platform operator. You can find their contact details in the "Data Controller" section of this privacy policy.

How do we collect your data?

Some of your data is collected when you provide it to us, e.g. by entering it in a registration form, recording trades, or uploading chart screenshots. Other data is collected automatically or with your consent when you visit the platform by our IT systems. This is primarily technical data (e.g. internet browser, operating system, or time of page access).

What do we use your data for?

Some of the data is collected to ensure error-free provision of the platform. Other data may be used to analyse your user behaviour — but only with your explicit consent (opt-in).

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

2. Data Controller

TradingControl UG (haftungsbeschränkt)

Fährstrasse 217

40221 Düsseldorf

Germany

Represented by the managing director: Thorsten Polte

Email: datenschutz@tradingcontrol.de

The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

3. Legal Bases for Processing (Art. 6 GDPR)

We process your personal data on the following legal bases:

  • Consent (Art. 6(1)(a) GDPR): For analytics tracking (Umami, self-hosted) and optional mentoring data sharing. You can revoke your consent at any time.
  • Performance of a Contract (Art. 6(1)(b) GDPR): For providing platform features (registration, login, trade recording, portfolio management, risk management, mentoring, reports, subscription management).
  • Legal Obligation (Art. 6(1)(c) GDPR): For tax-related retention obligations (German HGB § 257, AO § 147) and audit logging.
  • Legitimate Interest (Art. 6(1)(f) GDPR): For IT security measures (rate limiting, login logging, error resolution), provided your interests do not prevail.

4. Categories of Personal Data

We process the following categories of personal data:

CategoryDataLegal Basis
Master DataName, email address, password (bcrypt-hashed)Performance of contract
Profile DataAvatar, display name, language, timezonePerformance of contract
Financial DataTrade data, portfolio holdings, exchange API keys (AES-256-GCM encrypted), cold wallet addressesPerformance of contract
Usage DataLogin timestamps, audit logs, page views (pseudonymised)Legitimate interest / Consent
Technical DataIP address, browser type, operating system, referrer URLLegitimate interest
Payment DataInvoices, subscription status, payment history (payment processing by Stripe/BTCPay)Performance of contract
Communication DataMentoring chat messages, video call metadata (duration, status — no content)Performance of contract
Security Data2FA secret (encrypted), session tokens, password reset tokensPerformance of contract / Legitimate interest

5. Purposes of Processing

  • Provision and operation of the TradingControl platform
  • User registration, authentication, and account management
  • Recording, management, and analysis of trading data
  • Portfolio tracking and risk management calculations
  • Synchronisation of trades via exchange APIs (Phemex, BingX, Bitpanda)
  • Mentoring and coaching features (chat, video calls, data sharing)
  • Generation of performance reports (PDF)
  • Subscription and payment management
  • Ensuring IT security (abuse detection, rate limiting)
  • Platform improvement through pseudonymised usage analysis (only with consent)
  • Fulfilment of statutory retention obligations
  • Notification of relevant account activities (email, push, Telegram)

6. Retention Periods

We store your personal data only as long as necessary for the respective processing purposes or as required by statutory retention periods:

Data TypeRetentionBasis
Account dataUntil account deletionPerformance of contract
System logs90 daysLegitimate interest
Position change log180 daysLegitimate interest
Audit logs365 days (active), then archivedLegal obligation
Invoices / accounting records10 yearsGerman HGB § 257 / AO § 147
NotificationsUntil expiration datePerformance of contract
Redis tokens (JWT, 2FA, reset)Token lifetime (5 min – 24 hrs)Performance of contract

After the retention periods expire, data is automatically deleted or anonymised. Upon account deletion, all personal data is immediately deleted or anonymised (email → deleted_uuid@deleted.local, name → "Deleted User").

7. Recipients and Third-Country Transfers

7.1 Data Processors

We use the following service providers as data processors (Art. 28 GDPR):

ProviderPurposeLocationSafeguard
Stripe, Inc.Payment processing (credit card, SEPA)USAEU-US Data Privacy Framework
BTCPay ServerCryptocurrency paymentsSelf-hosted (EU)Own infrastructure
SMTP ProviderTransactional emails (verification, password reset, reports)EUDPA / GDPR-compliant
Telegram Bot APIOptional notificationsInternationalUser opt-in
Google STUN ServerNAT traversal for WebRTC video calls (no media data)USAConnection setup only, no content data

7.2 Third-Country Transfers

When using Stripe and Google STUN servers, data may be transferred to the USA. Stripe is certified under the EU-US Data Privacy Framework. Google STUN servers only transmit technical connection data (IP addresses) for connection establishment — no audio/video content or personal data.

Video calls use our own WebRTC implementation (peer-to-peer). Audio and video streams flow directly between the participants, without being routed through our servers.

8. Your Rights as a Data Subject

You have the following rights under the GDPR:

Right of Access (Art. 15 GDPR)

You can request a complete export of your personal data at any time. Use the export function in your account settings or send an email to the data controller. The export includes: profile data, trades, holdings, snapshots, notifications, API key metadata, and subscription data.

Right to Rectification (Art. 16 GDPR)

You can correct inaccurate personal data at any time through your profile settings or by contacting us via email.

Right to Erasure (Art. 17 GDPR)

You can delete your account completely at any time. The deletion covers all 17 related data tables. Email and name are anonymised, all sessions are immediately invalidated. Use the "Delete Account" function in your account settings.

Right to Restriction of Processing (Art. 18 GDPR)

Under certain conditions, you can request the restriction of the processing of your personal data. Please contact the data controller for this purpose.

Right to Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, commonly used, and machine-readable format. The export is available in JSON format.

Right to Object (Art. 21 GDPR)

You can object at any time to the processing of your personal data based on legitimate interest. For analytics tracking, you can revoke your consent at any time in your account settings.

Right to Withdraw Consent (Art. 7(3) GDPR)

You can withdraw any consent given at any time. This particularly applies to analytics consent (toggle in settings) and mentoring data sharing (individually revocable). The withdrawal applies for the future.

9. Competent Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority about our processing of personal data. The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen

Postfach 20 04 44

40102 Düsseldorf, Germany

Phone: +49 211 38424-0

Email: poststelle@ldi.nrw.de

Website: www.ldi.nrw.de

10. Automated Decision-Making

No automated decision-making including profiling pursuant to Art. 22 GDPR takes place. The platform's risk management system generates analyses and warnings based on your defined rules but does not make independent decisions. No automated trades are executed.

11. Cookies and Tracking Technologies

11.1 Technically Necessary Storage

We do not use cookies in the traditional sense. Instead, we use the following browser-side storage technologies (localStorage):

  • tc-auth — Authentication token (JWT) for your session
  • tc-analytics-optout — Your analytics preferences
  • i18nextLng — Language setting

These storage entries are technically necessary and fall under § 25(2)(2) TTDSG (German Telecommunications-Digital Services Data Protection Act — strictly necessary). No consent is required for these.

11.2 Analytics (Consent-Based Only)

We use Umami (self-hosted) for pseudonymised usage analysis. Umami sets no cookies and stores no personal data. User IDs are hashed with SHA-256 (with a project pepper). Tracking is performed only after your explicit consent (opt-in). You can revoke your consent at any time in your account settings. The Do-Not-Track setting is respected.

12. Technical and Organisational Measures (Art. 32 GDPR)

We implement comprehensive technical and organisational measures to protect your data:

  • Encryption: AES-256-GCM for sensitive data (API keys, screenshots), bcrypt (12 rounds) for passwords
  • Transport encryption: TLS/HTTPS with HSTS (1 year, including subdomains)
  • Two-factor authentication: TOTP-based (optional additional protection)
  • Rate limiting: Multi-layered protection against brute-force attacks (backend + NGINX)
  • Security headers: CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Input validation: XSS sanitisation, SQL injection protection through parameterised queries
  • Audit logging: Comprehensive logging of all security-relevant actions
  • High availability: PostgreSQL cluster (Patroni HA) with automatic failover
  • Peer-to-peer video calls: Audio/video streams are not routed through our servers

13. Changes to This Privacy Policy

We reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to reflect changes in our services. Any future visits will be subject to the updated privacy policy. We recommend that you read this privacy policy regularly to stay informed about the protection of the personal data we collect.

The German version of this privacy policy (Datenschutzerklärung) is the legally binding version. This English translation is provided for convenience only.

This privacy policy has been prepared with the utmost care. For a legally binding review, we recommend consulting a specialised data protection lawyer.

Last updated: 14 March 2026