Conditions of Use & Privacy Notice

Version 2026-08-21

1. Who operates this platform

This platform (tools.minussinus.de, "the Service") is operated by a private individual for personal investment analysis, and is made available to a limited number of invited/registered users on that basis. It is not a commercial product and is not offered by a registered company.

Data controller (GDPR Art. 4(7)):
[FILL IN: full legal name]
[FILL IN: postal address]
Contact: [FILL IN: contact email, e.g. an address at minussinus.de]

2. What data is collected and why
DataPurposeLegal basis (GDPR Art. 6)
Username, email address, password hash Account creation, authentication, email confirmation, password reset Consent (Art. 6(1)(a)) / performance of the account relationship (Art. 6(1)(b))
Login timestamp, IP-derived session identifiers, success/failure reason Fraud/abuse prevention, rate limiting, security incident investigation Legitimate interest (Art. 6(1)(f)) — securing the Service
Per-session activity logs (e.g. file uploads within tools) Debugging, support, abuse investigation Legitimate interest (Art. 6(1)(f))
Portfolio / financial data you enter into the tools Providing the analysis features you use Performance of the account relationship (Art. 6(1)(b))
Partial (5-character) SHA-1 hash of a chosen password, sent to a third-party breach-check API Rejecting passwords already known to be compromised elsewhere Legitimate interest (Art. 6(1)(f)) — protecting your account. Your actual password is never transmitted.
3. Where data is stored and who else sees it

No data is sold, and no data is shared with third parties beyond the processors listed above.

4. How long data is kept

Account data is kept for as long as the account is active. [FILL IN: define a concrete retention period for inactive/unconfirmed accounts and for login logs, e.g. "unconfirmed registrations are deleted after 30 days; login logs are retained for 12 months."]

5. Your rights

Under the GDPR, you have the right to:

To exercise any of these rights, contact [FILL IN: contact email].

6. Security measures

Passwords are hashed (never stored in plain text) before being saved. Password reset links are single-use and expire automatically. Login, registration, and password-reset attempts are rate-limited. New passwords are checked against a database of known-breached passwords before being accepted.

7. Account approval

Creating an account and confirming your email address does not by itself grant access to any analysis tool. An administrator must separately assign permissions to your account before you can use them.

8. Changes to this notice

This notice may be updated from time to time; the version at the top of this page changes when it does. [FILL IN: decide whether re-acceptance will be required from existing users on a material change, and how you'll notify them.]

Back to sign in