← Back to home
REVELIQ RESEARCH
Improve your Judgement

Privacy Policy

This is a convenience translation. In case of discrepancies, the German version prevails.

§1 Controller and data protection contact

The controller for the processing of personal data within the meaning of Art. 4(7) GDPR (General Data Protection Regulation, Regulation (EU) 2016/679) is:

Reveliq Research
Axel Brosey
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Phone: +49 177 6512834
Email: hello@reveliqresearch.com

A data protection officer does not have to be appointed under Art. 37 GDPR and §38 BDSG (German Federal Data Protection Act). For questions regarding data protection, you can reach us at the email address given above.

§2 Scope, principles, intended audience

This privacy policy applies to the use of the website reveliq.io and the SaaS application Investment Cockpit accessible through it. It is not authoritative for external websites to which we link.

In the interest of data minimization, Reveliq Research deliberately collects no portfolio compositions, no client identities and no order data.

The platform is not directed at minors under the age of 16. Reveliq Research does not knowingly process personal data of persons under 16; if we become aware of such processing, the data concerned will be deleted without undue delay.

§3 Visiting the website, server logs, cookies

When the website is accessed, technically necessary data is processed: IP address, date and time of access, URL accessed, referrer URL and user agent. This data is stored by Cloudflare (CDN, DDoS protection, see §13) and Hetzner (hosting, see §13) in the form of server logs for a maximum of 14 days for the purposes of attack defense and error analysis. The legal basis is Art. 6(1)(f) GDPR (and, where applicable, the UK GDPR) — legitimate interest in secure, stable provision of the service.

Reveliq Research does not set cookies that are not technically necessary, in particular no advertising, marketing or tracking cookies. Reach measurement via Plausible is cookie-free (see §10). Following successful magic-link authentication, a technically necessary session cookie is set (see §5), which is necessary within the meaning of §25(2) no. 2 TDDDG (German Digital Services Data Protection Act) and does not require consent. A cookie banner pursuant to §25(1) TDDDG is therefore not required; should the configuration change in future, a consent-compliant banner will be introduced.

Language selection. If you change the language of the interface, we store your choice in a cookie (reveliq_locale) so that the site appears in the desired language on your next visit. The cookie contains only the language code (e.g. "de" or "en"), no personal data, and expires after twelve months. It is strictly necessary for the function you have requested (§25(2) no. 2 TDDDG); no consent is required for it.

§4 Wait list

If you sign up for the wait list, we process your email address and the time of registration in order to inform you about the launch of the Investment Cockpit and for onboarding emails. The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future, informally, by writing to our support address; the lawfulness of processing carried out up to that point remains unaffected. Storage takes place in Supabase, email delivery via Resend (see §13). The data is stored for a maximum of 12 months from registration or until withdrawal (see §16).

§5 Registration, sign-in, account

For use of the service we process: email address (for magic-link authentication), optionally a name, and the time of registration. During use, the following additionally arise: sign-in timestamps and sign-in IP (security audit), tier membership and credit balance, watchlist content created by you, and the analysis request history.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR for the security audit data (legitimate interest in account security).

Authentication runs via Supabase Auth using a magic-link procedure without passwords; the session cookie set after sign-in is technically necessary (§25(2) no. 2 TDDDG).

§6 Platform use — Module A (single-security analysis)

When you use Module A, we process the ticker symbols and analysis parameters you enter, the Module A outputs generated, and audit trail metadata (with a pseudonymized correlation ID, user ID reference, timestamp, classification, model version and data sources used). Source research is carried out via the Anthropic web search tool; AI inference runs via the Anthropic API, and processing currently takes place in the USA (inference_geo=us), as a European Anthropic endpoint is not currently available (see §12 and §14).

The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

§7 Platform use — further modules

Currently, only Module A is available. If further analysis modules are activated, the information in §6 applies accordingly; any differing processing will be added here before activation.

§8 Payment processing

Payment processing does not currently take place. No payment-related personal data is currently collected or transferred to third parties.

When payment processing commences, it will be carried out via a Merchant of Record, who is an independent controller in that respect; there is no joint controllership within the meaning of Art. 26 GDPR. We will name that provider here before the first processing takes place, link to its privacy policy and update the overview of processors. The data processed will then be: name and billing address, email address, country (for VAT calculation), means of payment, as well as transaction ID, amount and timestamp. Reveliq Research receives only subscription status and billing master data via a signature-secured webhook, not the complete payment data; webhook logs are retained for 30 days.

The legal basis is then Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (retention under tax law).

§9 Email communication

If you contact us by email, we process your email address and the content of your message in order to answer your enquiry; delivery takes place via Resend (see §13). The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries and Art. 6(1)(f) GDPR for general enquiries.

§10 Web analytics with Plausible

We use Plausible Analytics (Plausible Insights OÜ, Tallinn, Estonia) for cookie-free reach measurement. Plausible sets no cookies, stores no IP addresses in identifiable form and transfers no data to third countries. The data processed is anonymized usage data (page title, referrer, browser/OS type, country via aggregated geolocation without IP storage, time on page). The legal basis is Art. 6(1)(f) GDPR.

§11 Error tracking with Sentry

We use Sentry for error diagnosis; ingest runs via the EU region (ingest.de.sentry.io). When an error occurs, technical metadata (stack trace, browser information, timestamp) is transmitted. The transmission of personal data from the request context is switched off (sendDefaultPii is set to false); performance data is recorded on a sampled basis at a rate of 0.1 (tracesSampleRate). The legal basis is Art. 6(1)(f) GDPR.

§12 Use of generative AI

The Investment Cockpit uses generative AI (Anthropic Claude, via the Anthropic API) for Module A. AI processing currently takes place in the USA (inference_geo=us); a European Anthropic endpoint is not currently available.

What is transmitted to Anthropic is the Module A inputs together with intermediate results of the inference. Account identities (name, email address, payment data) are not transmitted; the correlation ID is a pseudonymized UUID. According to Anthropic publications, API inputs are not used for training by default; the contractual basis is the Anthropic Data Processing Addendum, the current version of which Reveliq Research will conclude before going live. The legal basis for the transfer to the USA is governed by §14.

§13 Sub-processors used

Reveliq Research uses processors (Art. 28 GDPR) in the following categories: server hosting and compute, database/storage/authentication, AI inference, CDN/DDoS protection/DNS, transactional email delivery, reach measurement and error tracking. Data processing agreements (or equivalent data processing addenda) pursuant to Art. 28 GDPR are in place with all processors, or will be concluded before going live.

A consistently up-to-date and complete overview — stating provider, registered office and data location, the categories of data processed and the third-country basis — as well as the delineation from independent controllers (in particular the Merchant of Record, see §8) and from self-operated software, is available from us on request (hello@reveliqresearch.com). We announce material changes to existing customers at least 30 days in advance by email, pursuant to §17 of the Terms.

§14 Third-country transfers

Insofar as sub-processors outside the EU/EEA are used, Reveliq Research bases the third-country transfer as follows: if the provider is certified under the EU-US Data Privacy Framework (DPF), the transfer takes place on the basis of the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR); Cloudflare is DPF-certified. Otherwise, we conclude the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR); this applies in particular to Anthropic. Technical measures apply in addition (TLS 1.3, AES-256, pseudonymization of correlation IDs, no account identities in the AI calls).

A transfer to the USA cannot completely rule out access by US authorities (in particular under the CLOUD Act). If you do not accept the third-country transfer, use of the functions concerned — in particular AI inference via Anthropic — is not possible; in that case you may terminate the contract at any time pursuant to §8 of the Terms.

§15 Controllership constellations and processing on behalf

Reveliq Research is the controller (Art. 4(7) GDPR) for the data of the platform usage relationship (account data, sign-in audit, tier/credits, watchlist, analysis history, billing data, support communication).

The service providers named in §13 are processors within the meaning of Art. 28 GDPR and process personal data exclusively on the instructions of Reveliq Research. The Merchant of Record referred to in §8, by contrast, is an independent controller; there is no joint controllership within the meaning of Art. 26 GDPR. Software operated on our own infrastructure is not an external processor.

§16 Retention periods and deletion concept

Reveliq Research deletes personal data as soon as the purpose of processing ceases to apply or a statutory retention obligation ends:

Wait list datauntil withdrawal, max. 12 months from registration
Delivery logs for transactional emails12 months
Account master datacontract term + 30-day export period
Watchlist and analysis request historycontract term + 30-day export period
Module A outputs and audit trailcontract term + 30-day export period
Sign-in audit data30 days, rolling
Server logs (Cloudflare/Hetzner)14 days
Payment webhook logs30 days
Billing data10 years (§147 AO, German Fiscal Code)
Sentry error reports30 days

The email address is both the account identifier and a billing data item: the account record is deleted at the end of the 30-day export period; insofar as the email address is contained in billing data, the tax-law period of 10 years applies to that data point (§147 AO). After the period expires, a physical hard-delete takes place. Within 30 days of the end of the contract, the customer may request an export of their analysis outputs (§14 of the Terms).

§17 Your rights as a data subject

You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21 GDPR), as well as the right to withdraw consent given at any time with effect for the future (Art. 7(3) GDPR). The right to object exists insofar as processing is based on Art. 6(1)(f) GDPR. Data portability covers the data you have provided, not the analysis outputs generated from it (the export of which is governed as a service in §16).

Please address requests informally to hello@reveliqresearch.com. We respond within the statutory period (Art. 12(3) GDPR), as a rule within one month.

§18 Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for Reveliq Research is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden (the Hesse Commissioner for Data Protection and Freedom of Information)

An overview of the German state data protection authorities is available at bfdi.bund.de.

§19 No automated individual decision-making

Reveliq Research does not take automated individual decisions within the meaning of Art. 22 GDPR which produce legal effects concerning you or similarly significantly affect you. The AI-assisted outputs are methodical tools for preparing your own decision (see §13 of the Terms).

§20 Changes to this privacy policy

Reveliq Research may adapt this privacy policy insofar as this is necessary to adjust to a changed legal situation, to new functions or for clarification. We announce material changes — in particular to the sub-processor list and to the third-country transfer constellation — to existing customers at least 30 days in advance by email. The current version is available at all times at reveliq.io/legal/datenschutz.

§21 Obligation to provide data

The provision of your data is neither required by law nor by contract. The only consequence of not providing it is that the functions concerned cannot be used — no registration without an email address, no paid tier without payment data.