Privacy Policy

Information pursuant to Art. 13, 14 GDPR

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Marcus Aurum
c/o IP-Management #11307
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
E-Mail: admin@plutos.cloud

2. General Information on Data Processing

The protection of your personal data is important to me. Personal data is collected and processed exclusively on the basis of statutory provisions (GDPR, German Federal Data Protection Act BDSG, German Digital Services Act DDG) and only to the extent technically and organizationally necessary. This policy informs you about the nature, scope, and purpose of processing as well as about your rights.

3. Website Access (Server Log)

When you access the platform, technically necessary data is automatically processed:

  • IP address (truncated where possible)
  • Date and time of access
  • Page / URL accessed
  • Referrer URL (if transmitted)
  • Browser type and version
  • Operating system

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical provision and security). Retention period: max. 14 days, then automatic deletion.

4. Registration and User Account

A user account is required to use the platform. The following data is processed at registration:

  • E-Mail address (mandatory)
  • Password (stored as cryptographic hash, never in plain text)
  • Display name / username (mandatory)
  • First and last name (optional)
  • Profile picture, description (optional)

Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement). Data is retained until the user account is deleted.

5. User-Generated Content

Content you create (posts, comments, ratings, messages, investment theses, notes) is stored and displayed to other users according to your visibility settings. Legal basis: Art. 6(1)(b) GDPR. Such content generally remains available in anonymized form after account deletion, unless full deletion is expressly requested.

6. File Uploads (Profile Picture, Attachments)

You may upload files, in particular:

  • Profile picture (avatar)
  • Documents and file attachments (e.g. PDFs, reports) as part of company notes and analyses

Files are stored on my own infrastructure (Supabase Storage, Germany) and made accessible to other users or circle members depending on the visibility you set. Legal basis: Art. 6(1)(b) GDPR. You are responsible for the content of uploaded files; do not upload personal data of third parties without an appropriate legal basis.

7. Team Circles and Shared Content

The platform enables collaboration in so-called Circles (private or shared workspaces). Within a Circle, the following data is visible to other members: display name, profile picture, role, and all content created within the Circle (posts, notes, comments, uploaded files). Visibility and roles can be reviewed in the settings of the respective Circle. Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement).

8. E-Mail Delivery (Transactional Messages)

For registration confirmations, password resets, and comparable system-related notifications, a self-hosted e-mail server (Stalwart) is operated on my own infrastructure within the EU. Your e-mail address is not passed to any external e-mail service provider. Legal basis: Art. 6(1)(b) GDPR.

9. Reporting and Complaints Function

Users may report allegedly unlawful content or content violating the terms of use by other users via a reporting function. The following is processed: user ID of the reporter, user ID of the reported party, reported content, timestamp, and reason. This data is processed for the purpose of investigating the report, for the fulfilment of legal obligations (in particular DDG and the EU Digital Services Act DSA), and for legal defence. Legal basis: Art. 6(1)(c) and (f) GDPR. Reports are retained until the matter is resolved and, beyond that, within the scope of statutory retention obligations.

10. Data Processors and Services Used

The following technical services are used to operate the platform. Data processing agreements pursuant to Art. 28 GDPR exist with all providers where required.

  • Supabase (self-hosted): authentication, database, and file storage. Data is processed on my own infrastructure in Germany. No transfer to third countries.
  • Stalwart (self-hosted): e-mail server for transactional messages. Operated on my own infrastructure within the EU.
  • Hosting provider: operation of the server infrastructure within the EU.

No transfer of personal data to third countries outside the EU/EEA takes place.

11. Cookies and Local Storage

The platform uses strictly necessary cookies and local storage entries to maintain your session (e.g. session tokens after login). These are essential for the functioning of the platform and are set without consent on the basis of § 25(2) no. 2 TDDDG (German Telecommunications and Digital Services Data Protection Act). No tracking or analytics cookies are used. No external resources (e.g. Google Fonts) are embedded; all fonts are served from my own server.

12. Disclosure to Third Parties

Your personal data is generally not disclosed to third parties, except:

  • to data processors within the framework described above
  • where required by law (e.g. requests for information from law enforcement authorities)
  • for the establishment, exercise, or defence of legal claims

13. Your Rights

Under the GDPR you have the following rights:

  • Right of access to processed data (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure of your data (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw a given consent with effect for the future

To exercise these rights, an informal message to the e-mail address stated above is sufficient.

14. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. Pursuant to Art. 77 GDPR you may in particular contact the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement. An overview of the German state data protection commissioners as well as the Federal Commissioner for Data Protection is available at https://www.bfdi.bund.de.

15. Retention Period and Erasure

Personal data is deleted as soon as the purpose of processing ceases to apply and no statutory retention obligations conflict with deletion. You may delete your user account and the associated data at any time via the account settings or by request via e-mail.

16. Technical and Organizational Measures (Art. 32 GDPR)

State-of-the-art security measures are in place to protect your data, in particular:

  • Transport encryption (HTTPS/TLS) for all connections
  • Storage of passwords exclusively as cryptographic hashes (never in plain text)
  • Access restrictions and a role/permission model at the database level
  • Regular backups and updates of deployed software
  • Operation of the entire infrastructure in data centres within the EU

17. Minimum Age

The platform is intended exclusively for adults. Users under 16 years of age are not permitted to use the platform. By registering, you confirm that you are at least 16 years old (Art. 8 GDPR). If registrations by minors come to my attention, the affected accounts and associated data will be deleted without delay.

18. Processing of Publicly Available Third-Party Data (AI-Assisted Research)

To enrich platform content with contextual information about publicly listed companies, an automated, AI-assisted research process is operated. It collects exclusively publicly available, profession-related information about persons in their role as officers or executives of the companies concerned and transfers this into an internal knowledge graph. User data is not processed as part of this activity.

Categories of processed data:

  • Name, position/role (e.g. CEO, CFO, board member, supervisory board member)
  • Associated company and period of activity
  • Professional history, previous positions
  • Board and supervisory board mandates
  • Reportable transactions (e.g. directors' dealings, notifications under the German Securities Trading Act WpHG)
  • Public statements and decisions made in a professional context

Private data (home address, family status, health, private contacts, private opinions, etc.) is not collected. Special categories of personal data (Art. 9 GDPR) are not processed.

Data sources:

Exclusively publicly available registers and publications, in particular the German commercial register, EDGAR (SEC), BaFin and comparable supervisory registers, investor-relations pages of the companies, ad-hoc disclosures, and business and financial press.

Purpose:

Building a structured knowledge graph of companies in the energy and natural-resources sector as a research and analysis basis for platform users.

Legal basis:

Art. 6(1)(f) GDPR (legitimate interests). The legitimate interest is the provision of well-founded, context-rich information for investors and the interested public. Processing is restricted exclusively to the professional sphere of the persons concerned, in which — according to the settled case-law of the CJEU and the German Federal Court of Justice — there is a significantly reduced expectation of protection. A written balancing test has been conducted and documented.

Retention period:

For the duration of the person's active role at the respective company plus a reasonable historical period to enable longitudinal analyses. Thereafter it is reviewed regularly whether further storage is still necessary.

Recipients:

Registered platform users in the context of research and analysis results. No disclosure to third parties outside the platform. No transfer to third countries outside the EU/EEA.

Right to object (Art. 21 GDPR):

Data subjects may object to the processing of their data at any time. An informal objection by e-mail to the address stated above is sufficient. Following review, processing will either be discontinued and the affected data removed from the knowledge graph, or — where compelling protective grounds for further processing override — processing will be continued and this will be explained to the data subject.

19. Changes to this Privacy Policy

This privacy policy may be adjusted in response to changes to the platform or the legal framework. The current version is always available at this URL.

This English version is provided for convenience. In case of discrepancies between the German and English versions, the German version shall prevail.