
Privacy Policy
This Privacy Policy explains which personal data is processed when you visit this website or use our services. Personal data means any information relating to an identified or identifiable natural person
1. Data controller
The controller responsible for processing personal data on this website is:
DeVcore Technology
Owner: Barbara Kamila Swierczynska
Wurmberger Str. 51
75175 Pforzheim
Germany
Email: contact@devcoredienstleistungen.com
2. Data Protection Officer
A data protection officer has not been appointed because there is currently no legal obligation to appoint one
3. General information about data processing
We process personal data only where necessary to provide this website, handle enquiries, communicate with prospective and existing customers, take steps before entering into a contract, perform contractual obligations, maintain website security, analyse website usage and optimise our marketing activities
Depending on the purpose, processing is based on Article 6(1)(a), (b), (c) or (f) GDPR. Where consent is required, processing begins only after consent has been given. You may withdraw consent at any time with effect for the future
4. Website hosting and delivery
This website is hosted by Netlify. The provider is Netlify Inc., 101 2nd Street, San Francisco, CA 94105, USA
When you access the website, the hosting provider automatically processes technical data required to deliver the website and ensure its security and stability
• IP address
• Date and time of access
• page or file accessed
• Referrer URL
• Browser type and browser version
• operating system used
• Host name of the accessing computer
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is providing this website securely, reliably and efficiently. Where required, we have a data processing agreement with Netlify under Article 28 GDPR
5. Domain and DNS management through Cloudflare
The domain of this website is managed via Cloudflare. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
Cloudflare is used for domain and DNS management and for TradingOS Turnstile security checks. A Cloudflare proxy or content delivery network is not enabled. The website is served through Netlify
When DNS enquiries are resolved, technical connection data such as requested domain names and the IP addresses of requesting systems may be processed. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is ensuring that the website remains reliably and securely accessible through its domain
6. Contact form and contact by Email
When you contact us through the contact form or by Email, we process the information you provide to handle your enquiry and answer any further questions
• Name, if provided
• Email address
• Telephone number, if provided
• Content of the message
• Time of the request
• technical transmission metadata
Where your enquiry relates to a contract or steps taken before entering into a contract, the legal basis is Article 6(1)(b) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is handling incoming enquiries appropriately and efficiently
Data submitted when you contact us is deleted once the enquiry has been fully handled, unless statutory retention obligations require otherwise
7. Netlify Forms
The contact form may be processed using Netlify Forms. When you submit the form the information you enter is sent to Netlify and processed there to provide the form technically and forward your enquiry
Where the enquiry relates to a contract or steps taken before entering into a contract, the legal basis is Article 6(1)(b) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the reliable provision of a contact form
8. Email communication through Google
We use Google services for business Email communication. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Communication by Email may involve processing sender and recipient details, message content, attachments and technical communication data in particular
Where the communication relates to a contract or steps taken before entering into a contract, the legal basis is Article 6(1)(b) GDPR. In all other cases, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is reliable business communication
9. Cookies and similar technologies
This website uses cookies and similar technologies. Some technologies are strictly necessary to provide the website securely and reliably. Others are used to analyse website usage, measure advertising performance and optimise marketing activities
Technically necessary technologies are used on the basis of Section 25(2) TDDDG and Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional provision of this website
Technologies that are not strictly necessary are used only after you give consent. The legal basis is Section 25(1) TDDDG and Article 6(1)(a) GDPR. You may withdraw or change your consent at any time with effect for the future through the cookie settings
10. Cookiebot Consent Management
We use Cookiebot CMP to manage consent. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark
Cookiebot records and documents which consents have been granted or refused. In particular, this may involve processing a shortened IP address, the date and time of consent, browser data, the user's selection and an anonymous identifier
Where processing is required to meet statutory record keeping obligations, the legal basis is Article 6(1)(c) GDPR. Processing is also based on Article 6(1)(f) GDPR. Our legitimate interest is managing and documenting consent in a legally compliant manner
11. Google Tag Manager
This website uses Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Google Tag Manager is used to manage website tags. It can integrate and control other services. According to Google, Tag Manager itself does not create user profiles or store analytics cookies. It may, however, be technically necessary to run other services in accordance with your consent
Google Tag Manager and services that are not essential and are integrated through it are activated only after you select statistics or marketing. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG
12. Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Google Analytics is used to analyse how this website is used. In particular, this may involve processing pages viewed, visit duration, interactions, approximate location data, device information, browser information and shortened IP addresses. It is integrated through Google Tag Manager
Google Analytics is activated only after you give consent through the cookie banner. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future
13. Meta Pixel
This website uses Meta Pixel and Meta Business Tools. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Meta Pixel is used to measure visits and actions on this website, evaluate advertising activities on Facebook and Instagram, create audiences and optimise advertisements. It is integrated through Google Tag Manager
Meta Pixel is activated only after you give consent through the cookie banner. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future
14. TikTok Pixel
This website uses the TikTok Pixel. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland
The TikTok Pixel is used to measure visits and actions on this website, evaluate advertising activities on TikTok, create audiences and optimise advertisements. It is integrated through Google Tag Manager
The TikTok Pixel is activated only after you give consent through the cookie banner. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future
15. LinkedIn Insight Tag
This website uses the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, 70 Sir John Rogersons Quay, Dublin 2, D02 R296, Ireland
The LinkedIn Insight Tag is used to measure visits and actions on this website, evaluate the effectiveness of LinkedIn advertising, create audiences and optimise advertising activities. It is integrated through Google Tag Manager
The LinkedIn Insight Tag is activated only after you give consent through the cookie banner. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future
16. Web fonts
This website uses the Poppins font. The font is hosted locally and delivered directly by our hosting provider
Loading the fonts does not establish a connection to servers operated by Google or any other external provider. No personal data such as your IP address is transferred to external parties for this purpose. The fonts ensure a consistent and visually appealing presentation of our website
17. Social media profiles
We maintain publicly accessible profiles on Google Business Profile, Instagram, Facebook, TikTok and LinkedIn. If you visit or interact with these profiles, the relevant platform operator may process personal data
The data processed may include profile information, interactions, comments, messages, IP addresses, device information and usage data. We use these profiles to present our business, communicate with prospective and existing customers, and publish information about our services
The legal basis for our processing is Article 6(1)(f) GDPR. Our legitimate interest is presenting our business publicly and communicating with prospective and existing customers
18. International data transfers
The use of Netlify, Google, Meta, TikTok, LinkedIn and other technical service providers may involve transfers of personal data to countries outside the European Union and the European Economic Area, including the United States
Where data is transferred to a third country, the transfer is based on an adequacy decision, the EU US Data Privacy Framework, standard contractual clauses or another safeguard permitted under the GDPR, provided that the applicable requirements are met
19. Storage period
We retain personal data only for as long as required for the relevant purpose or by statutory retention obligations. Once the purpose ceases to apply or the statutory period expires, the data is deleted unless another legal basis permits continued storage
20. Your data protection rights
Within the limits of applicable law you have the following rights
• Right of access under Article 15 GDPR
• Right to rectification under Article 16 GDPR
• Right to erasure under Article 17 GDPR
• Right to restriction of processing under Article 18 GDPR
• Right to data portability under Article 20 GDPR
• Right to object under Article 21 GDPR
• Right to withdraw consent under Article 7(3) GDPR
You may contact us at any time to exercise your rights. Email: contact@devcoredienstleistungen.com
21. Objection to processing based on legitimate interests
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Where personal data is processed for direct marketing, you have the right to object to that processing at any time
22. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR
In particular the competent authority is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
www.baden-wuerttemberg.datenschutz.de
23. Data security
This website uses an encrypted connection for security. You can identify an encrypted connection because the browser address begins with HTTPS. Encryption prevents external parties from readily reading data that you send to us
24. Automated processing and human review
Solely automated decisions producing legal or similarly significant effects within Article 22 GDPR are not intended. TradingOS uses automated access and security checks and scores and ranks for access planning. Details and the option of human review appear in the TradingOS sections of this policy
26. TradingOS accounts and Early Access
For TradingOS we process your Email, verification state, language, technical account and session identifiers, and optional profile information. This may include role, country, markets, platforms and the workflow you are interested in. Required information supports authentication, account management and the Early Access service you request
Processing to provide the requested account and prepare or perform a reservation is based on Article 6(1)(b) GDPR. Security measures and prevention of abusive duplicate registrations are based on Article 6(1)(f) GDPR. A free account does not subscribe you to unrelated advertising
27. Supabase database, authentication and file storage
TradingOS uses Supabase for its PostgreSQL application database, Email authentication, session management, administrator multi factor authentication and protected files. The database processes account, organisation, referral, score, content and payment reference data. It does not store full payment card details
Application data is stored in an EU project region. Regional database hosting does not mean that all administration, support or subprocessor processing takes place exclusively in Germany or the EU. Supabase and its subprocessors may process data outside the EEA as part of their services. The applicable contractual basis and transfer safeguards depend on the processing involved
The purposes and legal bases follow the account, contract or security function being supported. Supabase acts as a technical service provider. Provider information: https://supabase.com/privacy
28. Founding reservations and Stripe
For a Founding reservation we process the plan, reservation amount, currency, contract version, acceptance time, payment and refund status, and Stripe customer, checkout and payment references. Name, billing address and business billing information are processed where required for billing. Full card details are entered with Stripe and are not stored by DeVcore
Stripe processes payment data for payment handling and fraud prevention. Depending on the activity, Stripe acts as a processor or an independent controller, including for regulatory obligations. Information about the relevant Stripe entities, uses of data and international transfers is available at https://stripe.com/privacy
The legal bases are Article 6(1)(b) GDPR for the contract, Article 6(1)(c) GDPR for statutory billing and retention obligations, and Article 6(1)(f) GDPR for preventing and investigating payment fraud. The reservation does not start a subscription or by itself create recurring charges
29. Referrals and historical attribution
Referral links contain a randomly generated code rather than your Email. A new signup may be linked to its direct source. Records include the referral identifier, direct referring account, the member and organisation involved at that time where applicable, and visit, signup and verification times
Historical attribution remains traceable after later changes of role or organisation. This prevents reassignment of referrals and supports review of scores, refunds and abuse. There are no multi level commissions. Regular members see only information available to their role; contact details of referred people are masked in referral views
A persistent referral cookie is set only with the relevant consent and currently lasts at most 30 days. Without that consent, a code passed within the signup flow may be used, without setting a persistent referral cookie. Consent can be withdrawn through cookie settings. Cookie storage relies on Article 6(1)(a) GDPR and section 25(1) TDDDG; requested attribution and abuse prevention rely on Article 6(1)(b) or (f) GDPR respectively
30. Access Score, rankings and access waves
Access Score reflects verified direct referrals, confirmed Founding purchases and, where enabled, expressly accepted contributions. Refunds, payment disputes or reviewed abuse may correct scores. The underlying events remain traceable. Individuals, Teams and Companies are ranked separately; ties use the earlier verification time, then the account ID
Rankings support planning of limited access waves and do not guarantee a date. They are updated periodically and may briefly lag behind a score event. Solely automated decisions producing legal or similarly significant effects within Article 22 GDPR are not intended. You may request human review of scores, eligibility or an abuse classification at contact@devcoredienstleistungen.com
Requested access planning relies on Article 6(1)(b) GDPR; traceable, fair allocation and abuse prevention rely on Article 6(1)(f) GDPR. Display names are public only with a separate opt in, which can be withdrawn in the account
31. Teams, companies and the Founding Hub
Organization owners and authorized administrators manage invitations, memberships, roles and available seats. This involves member Email addresses and related administrative events. Removed members lose organisation access. Shared scores and historical attribution remain with the organisation
The Founding Hub processes access entitlements, published development information, voluntary feedback and responses to enabled research questions. Feedback is not automatically public. Private files are provided through short lived links after authorization. Article 6(1)(b) GDPR applies to the requested service; voluntary product feedback is processed to improve the service under Article 6(1)(f) GDPR
32. Cloudflare Turnstile and abuse prevention
In addition to DNS management, protected TradingOS forms use Cloudflare Turnstile to distinguish legitimate requests from automated abuse. Cloudflare processes IP addresses, browser and device information, and technical interaction and challenge data. The server validates the result, expected hostname, challenge purpose, validity and single use
The legal basis is Article 6(1)(f) GDPR. Our interest is protecting registration, reservations and the platform against spam, account attacks and capacity abuse. Any strictly necessary access to the terminal device is assessed under section 25(2) TDDDG. Turnstile does not activate a Cloudflare proxy or CDN for this website. Provider information: https://www.cloudflare.com/privacypolicy/
33. Security logs and account messages
Rate limits use time limited identifiers hashed with a secret key, for example from an IP or Email address. Security events record the event type, time, acting account where applicable and a correlation identifier. Administrator changes record the actor, target and state change. Secrets, complete authentication tokens and full payment details are excluded from these logs
Verification, login, invitation, payment and important account messages support the requested service and account security. They do not constitute newsletter consent. Account Emails, company names, Stripe references and comparable sensitive account data are not sent to Google Analytics, Meta, TikTok or LinkedIn
We use Brevo, a service of Sendinblue SAS in France, to deliver these transactional messages. Sender and recipient details including Email address, the content required for the relevant message, delivery metadata and technical sending information are processed. Full card details are not sent to Brevo. Supabase sends native authentication messages through Brevo; application invitation and service messages use the separate TradingOS Email outbox when triggered. Brevo is not used as a marketing list for these messages
Brevo states that its databases are stored on servers in the European Union and provides a data processing agreement. This does not mean that every activity by every subprocessor takes place exclusively in Germany. Where an international transfer occurs, the applicable basis and appropriate safeguards depend on the specific processing and Brevo's current contractual documents. Provider information: https://www.brevo.com/legal/privacypolicy/ and https://www.brevo.com/legal/termsofuse/
34. TradingOS data retention
Sign in links can be used for at most 15 minutes; expired authentication flow records are cleared after the following day. Invitation tokens are valid for seven days. Expired rate limit counters are cleared after at most one further day. Turnstile replay protection lasts only for the short validity window. Security events and optional usage events are routinely deleted after 90 days; sent technical Email jobs after 30 days. Brevo delivery logs are limited to one month in the active account; message content previews are not stored there for new messages
Account and profile information is retained while the account exists and reviewed for deletion or anonymization upon a valid erasure request, unless another obligation prevents this. Contract, payment, refund and tax relevant records may be subject to statutory retention. Section 147 AO distinguishes, by record category, particularly ten, eight or six years; audits and other statutory reasons may require longer retention
Historical referrals, score events, Founding identifiers and administrative records are not overwritten solely because of an organisation change or refund. On account closure we assess which personal links are still needed for evidence and abuse prevention. Personal links that are no longer required are removed or anonymized, subject to statutory obligations
35. International processing for TradingOS
Netlify, Supabase, Stripe, Cloudflare and their subprocessors may process data outside the EEA. Where required, appropriate safeguards such as EU Standard Contractual Clauses apply; an adequacy decision may apply where its conditions are met for the specific recipient. An EU database does not replace that assessment. You can request information about the applicable safeguards at contact@devcoredienstleistungen.com
36. Updates to this Privacy Policy
This Privacy Policy is dated 1 September 2026. Technical changes, new services or changes in legal requirements may require updates