Privacy Policy
Compliant with the Swiss Federal Act on Data Protection (nDSG) and the EU General Data Protection Regulation (GDPR)
Last updated: August 21, 2026 — Version 1.2
1. Data Controller
The data controller responsible for data processing on this website and through the FinUties API is:
Sebastian Becker
Postfach 5411
78433 Konstanz, Germany
Email: [email protected]
If you have questions about how your personal data is processed, contact us at the address above.
A Data Protection Officer has not been appointed as the conditions under Art. 37 GDPR are not met.
2. Data We Collect
2.1 Account Data
When you register for a FinUties account, we collect:
- Username
- Email address (optional)
- Password (stored as an Argon2id hash — we never store plaintext passwords)
- Account creation date
2.2 API Usage Data
When you use the FinUties API, we record:
- Endpoint accessed (e.g.,
/api/v1/sec/filings) - HTTP method (GET, POST)
- Domain and resource queried
- Credits consumed
- Response size and duration
- HTTP status code
- Timestamp
This data is used for billing, usage analytics, and service improvement. It is linked to your account via a hashed token — not your IP address.
2.3 Technical Data
Our servers automatically collect:
- IP address (in server access logs)
- User agent string
- Request timestamps
Server logs are retained for 90 days for security and debugging purposes, then deleted.
2.4 Website Analytics
We use Metrility, a self-hosted analytics platform (metrility.techuties.com). The public site does not load either Metrility pixel until you make a choice (see our Cookie Policy).
- Necessary only: Lightweight pixel for basic first-party page-use statistics. Legal basis: your choice (Art. 6(1)(a) GDPR, Art. 5(3) ePrivacy Directive).
- Analytics: The same lightweight pixel. Same legal basis.
- Advanced analytics (extra consent): Additional richer pixel, only if you opt in separately. Same legal basis. Never loaded on necessary-only.
Global Privacy Control and Do Not Track are treated as an opt-out of both pixels. Analytics are self-hosted. We do not sell this data.
2.5 Data We Do Not Collect
- We do not collect financial data about you (FinUties provides public regulatory data, not personal finance information)
- We do not use third-party advertising trackers
- We do not sell or share personal data with data brokers
3. Purposes and Legal Basis
| Purpose | Legal Basis (GDPR) | Legal Basis (nDSG) |
|---|---|---|
| Account creation and management | Art. 6(1)(b) — Contract performance | Art. 31(1) nDSG — Information duty |
| API access and billing | Art. 6(1)(b) — Contract performance | Art. 31(1) nDSG |
| Usage tracking and credit management | Art. 6(1)(b) — Contract performance | Art. 31(1) nDSG |
| Remembering cookie/analytics choice | Art. 6(1)(f) — Necessary to honour your choice / ePrivacy strictly necessary storage | Art. 31(1) nDSG |
| Website analytics (lightweight or advanced Metrility pixels) | Art. 6(1)(a) — Consent | Art. 31(1) nDSG + consent |
| Security and abuse prevention | Art. 6(1)(f) — Legitimate interest | Art. 31(1) nDSG |
| Service improvement | Art. 6(1)(f) — Legitimate interest | Art. 31(1) nDSG |
4. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| API usage logs | 12 months |
| Server access logs (IP addresses) | 90 days |
Consent record (fin_cookie_consent) | 12 months from last save |
| Metrility analytics (only after consent) | As defined by Metrility cookie expiry (see Cookie Policy) |
| Referral records | Duration of referrer and referred accounts |
5. Data Sharing
We share personal data only with the following categories of recipients, and only to the extent necessary:
- Infrastructure providers: Our servers are hosted in Switzerland and Europe. Cloudflare, Inc. (USA) provides CDN, DDoS protection, and SSL termination. Cloudflare processes request metadata (IP addresses, headers) in accordance with their privacy policy and EU-US Data Privacy Framework.
- Payment processors: When payment integration is active, payment data is processed by Stripe, Inc. (USA) under their PCI-DSS certified infrastructure. We do not store credit card numbers.
We do not sell personal data. We do not share personal data with advertisers or data brokers.
6. International Data Transfers
Your data is processed and stored on servers in Switzerland and Europe. The operator is based in Germany. Switzerland is recognized by the European Commission as providing an adequate level of data protection.
Cloudflare may process request metadata at edge nodes globally. Cloudflare participates in the EU-US Data Privacy Framework and maintains Standard Contractual Clauses (SCCs) for international transfers.
Where data is transferred outside Switzerland or the EEA, we ensure adequate safeguards are in place as required by Art. 16 nDSG and Chapter V GDPR (adequacy decisions, SCCs, or binding corporate rules).
7. Your Rights
Under the Swiss nDSG (Art. 25-29)
- Right to information (Art. 25): You may request information about whether and what personal data we process about you.
- Right to data portability (Art. 28): You may request your personal data in a commonly used electronic format.
- Right to correction: You may request correction of inaccurate personal data.
- Right to deletion: You may request deletion of your personal data, subject to legal retention obligations.
Under the EU GDPR (Chapter III)
If you are located in the EU/EEA, you additionally have the right to:
- Access (Art. 15): Obtain confirmation and a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request deletion ("right to be forgotten").
- Restriction of processing (Art. 18): Limit how we use your data.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)): Change your choice via Cookie Settings, send GPC/DNT, or clear the
fin_cookie_consentcookie and localStorage key (banner returns; no pixel until a new choice). Switching away from Advanced stops the advanced pixel. We cannot reliably delete cookies already set bymetrility.techuties.com. - Lodge a complaint: You have the right to lodge a complaint with your national data protection authority.
Swiss supervisory authority
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, CH-3003 Bern
www.edoeb.admin.ch
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encrypted connections (TLS/SSL) for all data in transit
- Password hashing with Argon2id (OWASP recommended parameters)
- API key hashing with SHA-256 (plaintext keys are never stored)
- Database access restricted via VPN (Tailscale mesh network)
- Rate limiting and abuse protection
- Regular security updates and monitoring
9. Automated Decision-Making
We do not use automated decision-making or profiling as defined in Art. 22 GDPR. Rate limiting and credit balance enforcement are purely technical measures based on usage thresholds and do not constitute profiling of individuals.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR. We will also notify the competent supervisory authority within 72 hours as required by Art. 33 GDPR.
11. Children
FinUties is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page. We encourage you to review this page periodically.
If we make significant changes that affect your rights, we will make reasonable efforts to notify you (e.g., via email if you have an account, or via a notice on the website).
13. Contact
For data protection inquiries, requests to exercise your rights, or questions about this policy:
Email: [email protected]
Postal: Sebastian Becker, Postfach 5411, 78433 Konstanz, Germany
We aim to respond to all data protection requests within 30 days.