Investing Aura/Privacy Policy

Legal

Privacy Policy

Last updated: 1 July 2026  ·  Effective: 1 July 2026

1. Data Controller

The data controller for personal data processed through Investing Aura (the “Platform”) is the individual sole proprietor operating under the trading name Investing Aura, resident and established in Greece, European Union. For all privacy-related enquiries or to exercise your rights, please contact: privacy@investingaura.com.

This Privacy Policy governs the collection, use, storage, and transfer of personal data in connection with the Platform, in compliance with Regulation (EU) 2016/679 (GDPR) and the Hellenic Data Protection Authority (HDPA) guidance.

2. What Data We Collect

We collect and process the following categories of personal data:

  • Account data: Your email address and encrypted password hash (or OAuth identity provider token) provided when you register an account.
  • Profile data: Subscription status (free or Premium), stored as a boolean flag in your user profile.
  • User-generated content: Financial model inputs, scenario names, saved portfolios, life event configurations, and other data you voluntarily submit to the Platform. This data is inherently personal but is provided entirely at your own discretion.
  • Usage data: Server logs, page views, feature interactions, and error logs collected for operational stability and security. These may include IP addresses, browser type, device type, and timestamps.
  • Payment data: We do not directly collect or store payment card details or banking information. See Section 6 below.

3. Legal Basis for Processing (GDPR Article 6)

We process your personal data on the following legal bases:

  • Contract (Art. 6(1)(b)): Processing necessary to provide the Platform services you have requested, including account creation and feature access.
  • Legitimate Interests (Art. 6(1)(f)): Processing for operational security, fraud prevention, abuse detection, and platform improvement, where our interests are not overridden by your rights and interests.
  • Legal Obligation (Art. 6(1)(c)): Where we are required to process data to comply with applicable law.
  • Consent (Art. 6(1)(a)): Where we seek your consent for specific optional processing activities (e.g., marketing communications), which you may withdraw at any time.

4. How We Use Your Data

We use your personal data to:

  • Create and maintain your account and authenticate your identity;
  • Provide, operate, and improve the Platform features and services;
  • Manage your subscription and coordinate with our Merchant of Record;
  • Send transactional communications (account confirmations, subscription receipts, security alerts);
  • Detect and prevent fraud, abuse, and security incidents;
  • Comply with our legal obligations under EU and Greek law;
  • Respond to your enquiries and support requests.

We do not sell, rent, or trade your personal data to third parties for commercial purposes. We do not use your financial model inputs or scenario data for algorithmic profiling, credit scoring, or automated decision-making that produces legal or similarly significant effects.

5. Data Storage and Infrastructure

Your personal data and user-generated content are stored on infrastructure provided by Supabase, Inc. (a US entity with EU data processing capabilities). Supabase operates PostgreSQL databases and authentication services. We configure our Supabase project to use EU-based data centre regions where available. Supabase processes data on our behalf as a data processor under a Data Processing Agreement (DPA) that incorporates appropriate safeguards consistent with GDPR Chapter V (including Standard Contractual Clauses as applicable).

For further information on Supabase’s data handling practices, please refer to the Supabase Privacy Policy.

6. Payment Processing and Our Merchant of Record

We do not directly process, store, or have access to your payment card details, banking information, or full payment credentials. All payment transactions are handled exclusively by our authorised Merchant of Record (MoR) — which is either Paddle (Paddle.com Market Limited) or Lemon Squeezy (Lemon Squeezy LLC) — or such other MoR as we appoint.

The MoR acts as the merchant of record for your purchase and independently collects and processes your payment and billing information for purposes including payment processing, VAT/tax compliance, fraud detection, and their own legal obligations. The MoR’s privacy policy governs the processing of your payment data. We receive from the MoR only the minimum information necessary to confirm subscription status (e.g., a subscription active/inactive flag and your email address).

7. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide you with the Platform services. We may retain certain data for longer periods where required by law (e.g., tax and accounting records for a minimum of five years under Greek tax law) or for legitimate interests (e.g., fraud prevention logs).

Upon account deletion or a verified Right to Erasure request, we will delete or anonymise your personal data within 30 days, except to the extent that retention is required by law or for the establishment, exercise, or defence of legal claims.

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights with respect to your personal data. These rights may be subject to certain exceptions under applicable law.

  • Right of Access (Art. 15): You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data.
  • Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data we hold about you.
  • Right to Erasure / Right to be Forgotten (Art. 17): You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent (where consent is the basis of processing), among other grounds.
  • Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
  • Right to Data Portability (Art. 20): Where processing is based on contract or consent and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to Object (Art. 21): You have the right to object to processing based on legitimate interests, including for direct marketing purposes.
  • Rights Related to Automated Decision-Making (Art. 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. We do not engage in such processing.

To exercise any of these rights, please submit a verifiable request to privacy@investingaura.com. We will respond within 30 days. We may require identity verification before processing your request.

9. Cookies and Tracking Technologies

The Platform uses strictly necessary cookies and session tokens to maintain your authenticated session (provided by Supabase Auth). We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies that transmit personal data to external parties without your consent.

If we introduce optional analytics or functionality cookies in the future, we will seek your consent via a compliant cookie banner before setting any non-essential cookies.

10. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), in particular by Supabase (headquartered in the United States) and our Merchant of Record. Any such transfers are made subject to appropriate safeguards under GDPR Chapter V, such as Standard Contractual Clauses approved by the European Commission, or equivalent adequacy mechanisms. By using the Platform, you acknowledge such transfers.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include encrypted connections (TLS/HTTPS), row-level security on our database, and access controls limiting data access to the minimum necessary. However, no transmission over the internet or electronic storage system is 100% secure. You use the Platform at your own risk.

12. Children’s Privacy

The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a person under 18, we will take prompt steps to delete that data.

13. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time. If we make material changes, we will notify you via email or a prominent notice on the Platform at least 14 days before the changes become effective. Your continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

14. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA):

You also have the right to lodge a complaint with the supervisory authority of your country of habitual residence or place of work within the EU.

15. Contact

For all privacy and data protection enquiries: privacy@investingaura.com