Legal · Data Protection

Privacy Policy

How MAISNER collects, uses, stores, and shares personal data — and what you can do about it. This is the privacy notice required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Version
1.0
Effective
30 August 2026
Applies to
maisner.eu · /app
Hosting
Amsterdam, NL (EU)
Contents
  1. Who we are
  2. Scope of this notice
  3. What we collect, why, and for how long
  4. Where the data comes from
  5. Who we share it with
  6. International transfers
  7. Cookies and browser storage
  8. Analytics
  9. Automated decision-making
  10. Security
  11. Your rights
  12. Deletion and backups
  13. Your clients' data (processor role)
  14. Children
  15. Changes to this notice

1. Who we are

MAISNER is a quantitative portfolio-analytics platform operated from Estonia. For the personal data described in this notice, the operator of MAISNER is the data controller within the meaning of Art. 4(7) GDPR.

Service
MAISNER — maisner.eu
Operator
The MAISNER operator, an Estonian private limited company (osaühing) currently in formation. Company name, registry code, and registered address will be published here and in the Legal Notice as soon as registration is complete.
Contact
maisnerplatform@gmail.com — for all privacy questions and data subject requests
DPO
Not appointed. MAISNER does not carry out large-scale processing of special-category data and does not systematically monitor data subjects on a large scale, so none of the triggers in Art. 37(1) GDPR apply. Privacy requests go to the contact address above.
Lead authority
Estonian Data Protection Inspectorate — Andmekaitse Inspektsioon, aki.ee

2. Scope of this notice

This notice covers the public website (maisner.eu), the application at /app, the documentation pages (/methodology, /validation, /security), the analytics instance at analytics.maisner.eu, and email correspondence with the operator.

It does not cover third-party websites you reach from links on our pages, nor the internal data handling of your own firm.

3. What we collect, why, and for how long

Every category below is listed with its purpose, its legal basis under Art. 6(1) GDPR, and its retention period. We do not collect special-category data (Art. 9 GDPR) and we do not ask for it — do not upload it.

DataPurposeLegal basisRetention
Account credentialsusername, bcrypt password hash, role, creation date Authenticate you, apply your subscription tier, operate the account Art. 6(1)(b) — performance of contract For the life of the account, then deleted within 30 days of closure (see §12 on backups)
Profile datafirst name, last name, email, country, city, role, firm Address you correctly, service notices, support Art. 6(1)(b) — performance of contract Same as the account; optional fields can be cleared by you at any time in the app
Access-request dataname, email, company, country, city, professional role, AUM range, client count, phone, message, plan of interest Evaluate and respond to your request for platform access Art. 6(1)(b) — steps taken at your request before entering a contract 24 months from the request, or until the account is opened and the data moves into the account record; earlier on request
Portfolio and analysis datatickers, weights, quantities, purchase prices and dates, notes, alert rules, saved results and reports Run the analytics you asked for and store the outputs so you can return to them Art. 6(1)(b) — performance of contract Until you delete the item or close the account. Generated result files are pruned from backups after 30 days
Support messages Answer your support enquiries and keep a record of the thread Art. 6(1)(b) — performance of contract Until the account is closed, then deleted with it
Action logusername, action name, timestamp, action parameters Reconstruct what happened after a support or security incident, detect abuse, audit access to the platform Art. 6(1)(f) — legitimate interests: platform security, abuse prevention, service integrity 12 months
Login-security dataIP address, failed-attempt counter Enforce the brute-force lockout (5 failures → 15-minute block) and per-IP rate limits Art. 6(1)(f) — legitimate interests: securing accounts against credential attacks Held in server memory only, for the duration of the block; discarded on service restart
Web server logsIP address, timestamp, requested URL, status code, user agent, referrer Operate and secure the server, diagnose faults, investigate attacks Art. 6(1)(f) — legitimate interests: network and information security 14 days, then rotated out. Application service logs are held in the system journal and expire on size-based rotation, typically within a few weeks
Email correspondence Answer whatever you wrote to us about Art. 6(1)(b) or 6(1)(f), depending on the subject Deleted when the matter is closed and no longer needed for evidence; commercial correspondence may be kept where accounting law requires
Analytics eventspage path, referrer, screen size, country, browser — aggregated, no identifiers Understand which pages are used, in aggregate Art. 6(1)(f) — legitimate interests: improving the product (see §8) Aggregate counts only; no record is linkable to you

Where processing rests on legitimate interests (Art. 6(1)(f)), we have weighed those interests against your rights and concluded that keeping a secure, auditable platform does not override the reasonable expectations of a professional user of a financial analytics tool. You may object at any time — see §11.

4. Where the data comes from

5. Who we share it with

We do not sell personal data and we do not share it for advertising. The recipients below are the complete list of parties that can come into contact with personal data, and what each one gets.

RecipientRoleWhat it receivesLocation
DigitalOcean Infrastructure provider (processor) Everything stored by the platform, as the operator of the virtual server and its disks AMS3 data centre, Amsterdam, Netherlands (EU)
jsDelivr Content delivery network Your IP address and browser headers when the app loads its charting libraries (Chart.js, Plotly, globe.gl) and two globe textures. No cookies are set Global CDN edge nodes
unpkg / Cloudflare Content delivery network Your IP address and browser headers when the app loads the TradingView Lightweight Charts library. No cookies are set Global CDN edge nodes
Cloudflare (cdnjs) Content delivery network Your IP address and browser headers when the /methodology page loads MathJax to typeset formulas. No cookies are set Global CDN edge nodes
Google (Gmail) Email service for the operator's contact address The content and metadata of email you send to, or receive from, the operator Google Ireland Limited / Google LLC
Let's Encrypt (ISRG) TLS certificate authority Nothing about you — issues the certificate for the domain United States
Competent authorities Legal obligation Only what a valid, binding legal order requires, and only to the extent it requires Case by case

Deliberately not on this list: the analytics tool is self-hosted on our own server, so no analytics vendor receives anything (§8). Web fonts are served from our own domain, not from a font CDN. There is no payment processor in the loop today — subscriptions are invoiced manually; if that changes, this list and the notice will be updated before any processor goes live. Market data providers (Financial Modeling Prep, Polygon, Yahoo Finance) receive ticker symbols from our server and no personal data.

6. International transfers

Your account data, portfolios, results, and logs are stored on a server in Amsterdam, in the European Union, and are not routinely transferred out of it.

Two of the recipients in §5 can involve processing outside the EEA: content delivery networks answer your browser from whichever edge node is closest to you, which may be outside the EEA, and the operator's email is a Google service. Where a transfer to a third country occurs, it is covered either by an adequacy decision under Art. 45 GDPR (including the EU–US Data Privacy Framework, where the recipient is certified) or by the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR. The data involved is limited to what the table in §5 states — connection metadata for the CDNs, and the content of your own email for Gmail.

7. Cookies and browser storage

MAISNER sets no cookies. Not for sessions, not for analytics, not for anything else. There is no consent banner because there is nothing to consent to.

The application does keep a small amount of data in your browser's own localStorage, which never leaves your device except where the value is your session token being sent back to our own server:

KeyPurpose
maisner_tkYour JWT session token — this is what keeps you logged in
maisner_roleYour subscription tier, so the interface renders the right modules without a round trip
maisner_ob_doneA flag recording that you have completed onboarding, so it is not shown again
maisner_wlYour watchlist tickers
maisner-themeInterface preference
maisner_term_*Your terminal command history and variables, stored per user

All of these are strictly necessary to deliver the service you explicitly requested, and are therefore exempt from prior consent under Art. 5(3) of Directive 2002/58/EC (ePrivacy) as transposed nationally. Clearing your browser storage logs you out and resets these preferences; it does not delete anything on the server.

8. Analytics

We use Umami, a privacy-preserving analytics tool that we host ourselves on the same server as the platform. It sets no cookies, assigns no persistent visitor identifier, does not track you across sites, and does not build a profile. It records aggregate page views, referrers, approximate country, and browser type. No third party receives this data, because there is no third party involved. Blocking the analytics script has no effect on how the platform works.

9. Automated decision-making and profiling

MAISNER computes a great deal — optimal weights, risk metrics, stop levels, stress outcomes. None of it is a decision about you. There is no automated decision-making producing legal or similarly significant effects on a data subject within the meaning of Art. 22 GDPR, and no profiling of users. Every output is a computation on the portfolio data you supplied, presented for you to evaluate. The investment decision is always yours.

Reminder

MAISNER is analytics software, not investment advice and not a regulated financial service. The operator is not authorised or supervised by any financial supervisory authority. See the Terms & Disclaimer.

10. Security

No system is perfectly secure. If a personal data breach occurs and is likely to result in a risk to your rights, we will notify the Estonian Data Protection Inspectorate within 72 hours under Art. 33 GDPR, and notify you directly under Art. 34 where the risk is high.

11. Your rights

Under Arts. 15–22 GDPR you have the right to:

To exercise any of these, email maisnerplatform@gmail.com from the address on your account. We respond within 30 days (Art. 12(3)), extendable by two further months for complex requests, in which case we will tell you within the first month and explain why. There is no charge unless a request is manifestly unfounded or excessive. If we cannot identify you from the request, we may ask for information to confirm it is really your data you are asking about — we will not demand ID documents where a simpler check will do.

12. Deletion and backups

When you close your account, or when we act on an erasure request, the live records — account, profile, portfolios, monitors, results, notes, alerts, support threads — are deleted from the production system within 30 days.

Encrypted-at-rest server backups are taken daily and rotated on a 7 daily / 8 weekly / 12 monthly schedule, so a copy of deleted data can persist in a backup archive for up to 12 months. We do not restore deleted personal data from backups except to recover from an incident, and where a restore does bring it back, the deletion is re-applied. Backups are never used for analysis, profiling, or any other purpose.

Some records survive an erasure request where the law requires it — for example accounting documents subject to statutory retention, or a minimal record of a deletion request itself so we can demonstrate compliance.

13. Your clients' data — where we act as processor

If you are a wealth manager, RIA, or family office and you enter personal data about your own clients into the platform, the roles shift: you are the controller for that data and MAISNER is the processor (Arts. 4(8) and 28 GDPR). In that capacity the operator processes such data only on your documented instructions, keeps it confidential, applies the security measures in §10, assists you with data subject requests, engages no sub-processor beyond those listed in §5 without prior authorisation, and deletes or returns the data when the service ends.

A written Data Processing Agreement must be in place before you upload client personal data. The standard DPA is available on request at maisnerplatform@gmail.com. The list in §5 is the current sub-processor list; controllers will be notified of intended additions in advance, with the opportunity to object.

You do not need to upload client personal data to use MAISNER. Portfolios can be identified by label or reference alone, and we recommend that they are.

14. Children

MAISNER is a professional tool sold to businesses and experienced investors. It is not directed at children, and we do not knowingly process the personal data of anyone under 18. If you believe a minor's data has reached us, write to the contact address and it will be deleted.

15. Changes to this notice

We may update this notice as the platform changes — a new sub-processor, a new data category, a change of legal entity. The version number and effective date at the top of the page always reflect the current text. Material changes will be announced in the application or by email before they take effect. Superseded versions are available on request.

Related

Terms of Service & Disclaimer — contract, liability, GDPR summary, DPA clause · Security Architecture — the technical measures behind §10 · Methodology — what the platform actually computes.