Privacy Policy
Last updated: 2 September 2026
This policy explains how [COMPANY LEGAL NAME], [COMPANY ADDRESS] (“we”) handles personal data in connection with IB Analytics. It is written for the GDPR and applies to everyone who uses the Service or whose data appears in it.
1. Two roles, two kinds of data
Account data — we are the controller. For the people who sign in (the client and teammates they invite) we process: name, e-mail address, hashed credentials, sign-in events and technical logs. Legal basis: performance of the service agreement (Art. 6(1)(b)) and our legitimate interest in securing the Service (Art. 6(1)(f)).
Network data — we are the processor.The business data shown in a client’s dashboard (their sub-IBs and those sub-IBs’ client accounts: names, account numbers, balances, deposit events, and, where the broker provides it, contact details) is retrieved from the client’s own broker account on the client’s documented instruction. For that data the client is the controller and we process it solely to provide their dashboard, under the data-processing terms of the service agreement. A signed DPA is available on request. Individuals whose data appears in a client’s dashboard should direct requests to that client; we will assist the client in answering them.
2. What we do not do
- No advertising, no sale or sharing of personal data for marketing.
- No profiling or automated decisions with legal effect.
- No tracking cookies — see the Cookie Policy.
3. Sub-processors
- Supabase — database and authentication (hosted in the EU).
- Vercel — application hosting and delivery.
- Anthropic — powers the optional in-app assistant. When you ask it a question, the question and the relevant slices of your own network data are processed to produce the answer; they are not used to train models.
- Resend — transactional e-mail (invites, service notices).
- Google — only if you choose “Continue with Google”, to authenticate you.
Where a sub-processor handles data outside the EU/EEA, transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
4. Retention
- Account data: for the life of the account, then deleted within 30 days.
- Network data: for the life of the client’s subscription; on termination the client’s deployment and its data are deleted within 30 days of written request.
- Technical logs: up to 12 months, for security.
5. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Write to [CONTACT EMAIL]. We answer within one month. You may also complain to your supervisory authority (in Spain, the AEPD; elsewhere, your local authority).
6. Security
Each client’s deployment is isolated; every read of network data is scoped server-side to the signed-in client’s own network; credentials for data retrieval are stored in a managed vault; access is provisioned individually and revocable per user.
7. Changes
We will post changes here and, for material changes, notify clients directly. Contact for anything in this policy: [CONTACT EMAIL].