← Back to app

Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Jonas Rösch, Hauptstraße 154, 77876 Kappelrodeck, Germany
Email: support@wavg.de

2. General Information on Data Processing

We process personal data only insofar as this is necessary to provide a functional website as well as our content and services, or where you have given your consent. Legal bases are in particular Art. 6 (1) (a) (consent), (b) (contract / pre-contractual measures) and (f) (legitimate interest) GDPR.

Whether provision is required. Providing your email address is necessary in order to create an account; without it no contract can be concluded. Name, country and phone number are optional.

Automated decision-making. Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

3. Hosting

Our website is hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The server location is Germany. A data processing agreement (Art. 28 GDPR) is in place with the provider. Legal basis: Art. 6 (1) (f) GDPR (secure, efficient provision of the service).

4. Server Log Files

When you access the website, information transmitted by your browser is automatically collected (e.g. IP address, date/time, requested resource, referrer, browser type). This data serves the technical provision, security and stability of the service. Legal basis: Art. 6 (1) (f) GDPR. These web server log files are deleted automatically no later than 15 days after they are written.

Separately from these, our application writes a technical log of its own (start-up, errors, and security-relevant events such as failed logins or requests that exceeded a rate limit). Entries of the latter kind contain the IP address concerned. We need this log to find faults and to detect misuse; it is the only record from which we can reconstruct what happened days later. Legal basis: Art. 6 (1) (f) GDPR. It is deleted automatically no later than 90 days after it is written, and earlier if the journal reaches its size limit.

5. Registration & User Account

For a user account we process your email address and a securely stored (hashed) password. Optionally, you may provide a name, country and phone number. This data is used for login, authentication and providing the personalized features. Legal basis: Art. 6 (1) (b) GDPR. You can delete your account at any time in your profile settings.

If you change your account email address, we additionally store your previous address for 72 hours, together with a one-time token and an expiry time, and send a message to that previous address containing a link. The link lets you reverse the change from your old mailbox if it was not you who requested it. After 72 hours the link stops working and the previous address, the token and the expiry time are deleted. Legal basis: Art. 6 (1) (f) GDPR (protecting accounts against takeover).

5a. Security Log

Separately from the logs described in section 4, we keep a security log of events affecting the security of your account. These are, in particular: sign-in, failed sign-in, password change, sign-out from all devices, change of email address (including a cancelled or reversed change), and deletion of the account. Where we change something on your account ourselves — your subscription plan or access rights, an immediate cancellation of a running subscription, or a sign-out from all devices triggered on your behalf — that is recorded in the same way. We also record requests that were rejected for security reasons — for example a session that had expired or was not valid, a missing or invalid security token, a request that exceeded a rate limit, or a password-reset link that was no longer valid.

Every entry contains the time, the type of event and the IP address the request came from. Where the account is known, the entry also contains its internal identifier. Depending on the type of event, an entry may additionally contain the address of the interface the request was sent to (for example „/api/auth/logout“), a short reason for the rejection, or — where someone tried to sign in with an address we have no account for — a short value calculated from that address. That value is not the address itself and we do not store the address; it lets us tell repeated attempts on one address apart from attempts on many different ones. It is not, however, a secret: anyone who already suspects a particular address can calculate the same value and compare it.

We need this record to detect and investigate unauthorised access to accounts and, in the case of deletion, to be able to demonstrate that the deletion was carried out. Legal basis: Art. 6 (1) (f) GDPR (security of our service) and, for the record of deletion, Art. 6 (1) (c) GDPR in conjunction with our accountability obligation under Art. 5 (2) GDPR. Entries are deleted no later than 90 days after they are written. Entries relating to a deleted account remain until then — they contain the internal identifier and the IP address only, no email address and no name.

Deletion register. When an account is deleted, we additionally write one line to a separate register: the internal identifier, the date and time, and who triggered the deletion. This line contains no IP address, no email address and no name. It exists so that we can still demonstrate months later that a deletion was in fact carried out — a complaint under Art. 77 GDPR is not bound to a deadline, and the security log above is long gone by then. Legal basis: Art. 6 (1) (c) GDPR in conjunction with Art. 5 (2) and Art. 24 GDPR. We keep it for three years, counted from the end of the year of the deletion (§§ 195, 199 BGB).

6. Support Requests

If you contact us (e.g. via our support function or by email), we process the content of your message together with your email address and account data in order to handle and respond to your request. Legal basis: Art. 6 (1) (b) and (f) GDPR.

Contact form. You can also reach us without an account via our contact form. We process the email address you enter, your message, and optionally your name and a subject line, in order to reply. In addition we store the time of receipt and the IP address the message was sent from — solely to limit abuse of the form (spam, mass submissions). Legal basis: Art. 6 (1) (b) GDPR where the request concerns a contract, otherwise Art. 6 (1) (f) GDPR (answering enquiries, protecting the form against misuse). We do not send you a copy of your message.

Your message is stored on our own server in Germany and deleted automatically 90 days after it was received. It is not forwarded to our support mailbox: that mailbox only receives a notification containing a reference number and the subject line you entered, so that we know a message is waiting. We read the message itself in our own administration area.

The address support@wavg.de is hosted by Hetzner Online GmbH (Gunzenhausen, Germany) — the same provider that hosts this website (see section 3). Messages sent to that address are stored on servers in Germany; a data processing agreement under Art. 28 GDPR is in place and no transfer to a third country takes place. Replies we write from that mailbox are sent through the same provider. Messages sent through the contact form do not reach that mailbox at all: they stay on our own server, and only a notification with a reference number and your subject line is sent there.

7. Email Delivery

For transactional emails (e.g. password reset, email confirmation, support transcript) we use the service Resend (Resend, Inc., USA). Your email address is transmitted to the provider. A data processing agreement is in place; transfer to the USA takes place on the basis of the EU Standard Contractual Clauses. Legal basis: Art. 6 (1) (b) and (f) GDPR.

COT report notifications. If — and only if — you switch this on yourself in your profile, we send you one email per week when the CFTC publishes a new Commitments of Traders report. This setting is off by default. Legal basis: Art. 6 (1) (a) GDPR (your consent). You can withdraw your consent at any time with future effect, either via the unsubscribe link in every one of these emails (no login required) or by unticking the box in your profile. Withdrawing does not affect the lawfulness of processing carried out beforehand. These emails are also delivered via Resend.

Congressional trading alerts. If — and only if — you switch this on yourself and select the members of Congress you wish to follow, we send you an email when a newly published disclosure shows a purchase by one of them. This setting is off by default and is part of a paid plan. We record the time at which you gave this consent in order to document it. Legal basis: Art. 6 (1) (a) GDPR (your consent). You can withdraw your consent at any time with future effect, either via the unsubscribe link in every one of these emails (no login required) or by switching the alerts off in your profile. Withdrawing does not affect the lawfulness of processing carried out beforehand. These emails are also delivered via Resend.

8. Payment Processing

For paid subscriptions, payment processing is carried out via Stripe (Stripe Payments Europe, Ltd., Ireland). The data required for payment is processed directly by Stripe; we do not store complete payment data (e.g. card numbers) ourselves. Stripe's privacy notices apply. Legal basis: Art. 6 (1) (b) GDPR.

Stripe processes the payment data as an independent controller under its own privacy notices. A transfer to Stripe, LLC (USA) takes place. Stripe is certified under the EU-US Data Privacy Framework. Under Stripe's Data Transfers Addendum exactly one mechanism governs the transfer, in this order: first the Data Privacy Framework, and — if it does not apply — the EU Standard Contractual Clauses, which are contractually incorporated as a fallback. We additionally use Stripe Tax to calculate value-added tax. Invoice and payment data is retained in accordance with § 14b UStG and § 147 AO for the periods prescribed there; the legal basis for this is Art. 6 (1) (c) GDPR.

8a. Data from Public Disclosure Registers

We evaluate publicly accessible mandatory disclosures (including disclosures by members of the US Congress under the STOCK Act, filings by corporate officers and major shareholders to the US Securities and Exchange Commission, and lobbying registers). We process name, function, the reported transaction, the amount range and the filing and publication dates. The purpose is to prepare and present publicly known market information. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in informing about publicly disclosed market events. The sources are exclusively the public registers named above. Individual notification of the data subjects does not take place pursuant to Art. 14 (5) (b) GDPR, as it would involve disproportionate effort; this information takes its place. Data subjects may object to the processing under Art. 21 GDPR at support@wavg.de.

8b. Record of Your Order

When you place an order we record your email address, the plan chosen, the date and time, the IP address the order was sent from, the language your browser requested, and a fingerprint of the versions of the Terms and the withdrawal instructions that were displayed to you. We do this to be able to prove what was agreed and what you declared (Art. 7 (1) GDPR and our legitimate interest in securing evidence, Art. 6 (1) (f) GDPR), and to document the place of supply for VAT purposes, for which we also record the country of your billing address and the country in which your card was issued (Art. 6 (1) (c) GDPR). This record is not deleted when you delete your account, because it is subject to statutory retention periods — see section 13.

9. Error Monitoring & Web Analytics

To detect, diagnose and fix technical faults we use the error-monitoring service Sentry (Functional Software, Inc., USA). We use Sentry's EU data region, so error data is stored on servers within the European Union. When an error occurs (on the server or in your browser), technical data such as your IP address, browser/device information and the technical error context is processed. This is not used for tracking. A data processing agreement is in place. Should data nevertheless be transferred to the USA, exactly one mechanism governs that transfer, in this order: first the EU-US Data Privacy Framework, under which Sentry is certified, and — if it does not apply — the EU Standard Contractual Clauses agreed with Sentry as a fallback. Legal basis: Art. 6 (1) (f) GDPR (secure and stable provision of the service).

To understand how our service is used and to improve it, we use the web-analytics tool Umami. Umami runs self-hosted on our own server (no data is shared with third parties), sets no cookies and does not create cross-site or cross-device profiles. It processes aggregate usage data such as page views, referring source, approximate region, browser and device type, the section of the app being used and whether a paywall was shown. For logged-in users, the subscription plan in use (free, Pro or Elite) is additionally recorded as a group label. It is not linked to your name, e-mail address or account ID; attribution to an individual person is not intended, but with very small groups it cannot be ruled out in every case. Legal basis: Art. 6 (1) (f) GDPR (analysis and improvement of our service). You may object to this analysis at any time under Art. 21 GDPR. Usage data collected by Umami is retained for twelve months and is then deleted automatically; the deletion job runs once a week.

10. Cookies & Local Storage

We use the following cookies:

NamePurposeRetention
__Host-wavg_sesskeeps you logged in, and determines whether the landing page or the application is shown at wavg.de (readable by the server only)7 days
__Host-wavg_csrfprotection against cross-site request forgery (security)7 days

Both cookies are strictly necessary for the operation of the service within the meaning of § 25 (2) no. 2 TDDDG: without them you could not stay logged in, and requests could not be protected against cross-site request forgery. We therefore do not ask for consent for them, and we set no cookies that would require it. We do not use advertising, tracking or profiling cookies.

In addition, we store the following entries in your browser’s local storage. They remain on your device and are not transmitted to us automatically:

NamePurposeRetention
wavg_usera copy of your account details from your last sign-in — including your name and email address — so that the interface can show you as signed in immediately, before the server repliesuntil logout
wavg_tokena marker that a session exists, so that signing in or out in one browser tab also takes effect in the others; it contains no access credentials — the session itself is held exclusively in the cookie listed aboveuntil logout
wavg_cal_alerts, wavg_news_alertswhether you have switched calendar and news alerts on (a local copy of the setting in your account)until logout
wavg_themeyour choice of light or dark displayuntil you delete it
wavg_cal_fired, wavg_cot_last_seen,
wavg_news_last_seen, wavg_cot_banner_ack
which alerts and reports you have already been shown, so that the same notice does not appear twiceuntil you delete it
umami.disabledset only for our own administrative and support accounts, in order to exclude internal use from the usage statistics described in section 9until you delete it

These technologies serve the operation of the service, remain associated with your device or session and are not used for analysis, tracking or advertising. The legal basis for the associated data processing is Art. 6 (1) (b) and (f) GDPR. Logging out removes the entries marked “until logout”; you can delete all of them at any time through your browser settings.

11. Browser Notifications

If you allow notifications for this website, we show alerts — for example on a new COT report or an upcoming calendar event — through your browser’s own notification function, using data the page has already retrieved. This happens only while a WAVG tab is open. We do not store a push address (endpoint), we do not use the push service of your browser vendor, and no data is transferred to third parties for this purpose. The permission is managed by your browser and can be withdrawn there at any time. Which alert types you have switched on is stored in your user account and mirrored locally in your browser (see section 10). The legal basis is your consent, Art. 6 (1) (a) GDPR.

12. External Content (CDN, Fonts)

All fonts and program libraries used to render this site are hosted on our own servers. No resources are loaded from third-party CDNs or font services, and no IP address is transmitted to such providers when you visit this site.

13. Retention Periods

Otherwise, personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations conflict with deletion.

14. Your Rights

Under the GDPR you have, in particular, the following rights:

To exercise these rights, an email to support@wavg.de is sufficient.

Right to object. You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data which is based on Art. 6 (1) (f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing.

15. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

16. Changes

We will adapt this privacy policy if the legal situation or our processing changes. The version published on this page at any given time applies.