Pursuant to GDPR (EU) 2016/679 — version: 17 September 2026. Convenience translation; the German version prevails.
Astrid Jaeger
Laubenweg 22, 9020 Klagenfurt am Wörthersee, Austria
E-mail: support@thedrawdowndiary.com
We collect the following personal data:
Registration: e-mail address, encrypted password
Usage data: trades entered, psychology logs, weekly reviews and optionally uploaded chart screenshots (entered or uploaded exclusively by the user; screenshots are stored in a private storage bucket and are accessible only to the respective user)
Payment data: the payment itself is handled by Stripe — we do not store credit-card data and never see the full card number
Place-of-supply indicators of a payment: For a paid purchase we process two pieces of information about where the service is received: the billing address you enter during checkout (a mandatory field since 1 August 2026 — § 11 of the Austrian VAT Act requires the recipient's address on the invoice), and the issuing country of your payment method, which we retrieve from Stripe: for cards the country of the issuing bank, for SEPA direct debit the country of the bank account derived from the IBAN. Some payment methods carry no such country; the item then remains empty. We do not retrieve the card number or the IBAN itself, only the two-letter country code. The two country items are stored only where a purchase has to be reviewed manually or reversed because of them — in that case in the corresponding internal processing note (table ops_tasks; for the retention period see "Retention Period")
Contract records: at purchase we document the time and wording of your express request for immediate provision of the service (plan, checkout reference, e-mail address)
Push reminders (only if you switch them on): the address at which the push service of your browser or operating system reaches your device, two encryption keys generated by your browser, the chosen time, your device’s time zone and language, the time you switched the reminder on and of any withdrawal, and the calendar day of the last reminder sent — per device on which you switched the reminder on. The content of the reminder is always the same note that no entry has been made that day; your trades or journal entries are never transmitted
Cancellation requests: details submitted via the public cancellation page (e-mail address, plan, type of cancellation, time)
Withdrawal declarations: details submitted via the public withdrawal page (name, e-mail address, order or invoice number, plan, an optional note, and the date and time of receipt). Name, contract identification and e-mail address are mandatory items of the withdrawal function prescribed by § 13a of the Austrian FAGG
Referral program: the record of which referral link an account was registered through
Commission records: where a referral leads to a paid purchase, a settlement record is created (table affiliate_commissions). We store the referral code of the referring person, the user identifier of the referred account, the plan purchased, the purchase amount, the commission calculated from it and its payout status — no name and no e-mail address
Lifetime reservations: when you purchase Lifetime access we reserve one of the ten Early Bird slots for you. We store your user identifier, the Stripe checkout reference, the status of the reservation and the associated timestamps — no name and no e-mail address
Market waiting list: In countries where we currently do not conclude paid contracts (§ 1 of our Terms — today only the United Kingdom) you can join a waiting list instead of buying. For this we store your e-mail address, the country code of the market concerned, the language in which the form was shown to you, the wording of the consent statement displayed to you together with its version identifier, the times of your entry, of your confirmation, of any notification, of any unsubscription and of any archiving — the latter records when an entry that has already been notified was taken out of the active list so that the same address can sign up again for the same market; the entry itself remains unchanged, it is neither deleted nor treated as a withdrawal — and, as evidence of consent under Art. 7(1) GDPR, your IP address at the time of entry and your IP address at the time of confirmation. In addition there are two randomly generated identifiers that address the confirmation link and the unsubscribe link and contain no information about you; the one for the confirmation link is deleted when you confirm. We do not collect a name; the waiting list is open without registration and is not linked to any user account
Technical data: IP address, browser type (via Vercel hosting)
Country detection: When you open the home page or the pricing page and when you make a purchase, our hosting provider Vercel tells us the two-letter code of your country, derived from your IP address. We use that code solely to determine whether a paid contract can be concluded in your country, and we do not store it — unless you join the waiting list, in which case it forms part of that record. The check carried out after a payment is not based on it but on the place-of-supply indicators stated above
Anonymous page views: we store only the visited path, any referrer and the time — without a user identifier, without a cookie and without your IP address. However, to prevent abuse, your IP address is transmitted to our rate-limiting provider Upstash (USA) when this endpoint is called and retained there for the duration of the time window; it is not linked to the stored page views (legal basis: Art. 6(1)(f) GDPR; transfer to the USA based on Standard Contractual Clauses)
— Providing the trading-journal functionality — legal basis: Art. 6(1)(b) GDPR (performance of contract)
— Processing payments and subscriptions — legal basis: Art. 6(1)(b) GDPR (performance of contract)
— Authentication and account security — legal basis: Art. 6(1)(b) GDPR (performance of contract)
— Documenting legally required confirmations (Austrian FAGG) and handling cancellations — legal basis: Art. 6(1)(c) GDPR (legal obligation) and (f) (interest in evidence)
— Technical operation of the platform (server logs) — legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)
— Bot and abuse protection (captcha, rate limiting) — legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)
— Affiliate/referral tracking (ddd_ref cookie) — legal basis: Art. 6(1)(a) GDPR (consent)
— Daily reminder of your journal entry by push notification — legal basis: Art. 6(1)(a) GDPR (consent, which you give in the settings per device and can withdraw there at any time by switching the reminder off; the reminder contains no advertising)
— Reserving and evidencing the ten Early Bird Lifetime slots — legal basis: Art. 6(1)(b) GDPR (performance of contract) and (f) (legitimate interest in a correct scarcity claim, Annex item 7 of the Austrian UWG)
— Settling and paying out commissions under the referral programme — legal basis: Art. 6(1)(b) GDPR (performance of the contract with the referring person) and (c) (accounting and retention obligation, § 132 of the Austrian Federal Fiscal Code)
— Determining whether a paid contract can be concluded in your country (country detection) — legal basis: Art. 6(1)(f) GDPR (legitimate interest in not concluding contracts in markets for which we lack the required tax registration)
— Determining the place of supply after a payment and reversing a purchase from a market in which we do not conclude paid contracts (place-of-supply indicators of a payment) — legal basis: Art. 6(1)(c) GDPR (tax obligations, in particular determining the place of supply and the invoice details required by § 11 of the Austrian VAT Act), and (b) (handling the payment including the refund) and (f) (legitimate interest in not supplying a service for consideration in markets without the required tax registration)
— Notifying you that the service has become available in a market where we do not yet sell (market waiting list) — legal basis: Art. 6(1)(a) GDPR (consent)
Purpose limitation of the waiting list: Your address is used for one single message only — the notification that DrawDownDiary is available in the market concerned. No newsletter, no product information, no disclosure to third parties for advertising purposes. Signing up alone is not enough: we first send you a confirmation e-mail. The link it contains leads to a page with a single button; only that click gives your consent (double opt-in, § 174 of the Austrian Telecommunications Act 2021). This intermediate step exists because spam filters, link-scanning services and mail previews open links in e-mails automatically in advance — if merely opening the link were enough, it would no longer be you who consented but your mail server. The confirmation link is valid for up to 72 hours, but never beyond the end of the retention period of your entry — a link outliving the entry would lead nowhere; the period that applies to you is stated in the confirmation e-mail. If you do not confirm, you will receive no further message from us and the entry is deleted (for the individual periods see the section "Retention Period"). You may withdraw your consent at any time with effect for the future — via the unsubscribe link contained in every e-mail sent to that address. For the same reason it, too, leads to a page with a single button that unsubscribes you. Withdrawal is therefore exactly as easy as giving consent — one click against one click (Art. 7(3) GDPR); no login is required, no reason need be given, and the unsubscribe link does not expire. The lawfulness of processing carried out before the withdrawal remains unaffected.
Obligation to provide data (Art. 13(2)(e) GDPR): your e-mail address and a password are required to conclude the contract — without them we cannot create an account or provide the service; all other details (trades, psychology logs, screenshots, name) are voluntary, and not providing them has no disadvantage other than the loss of the respective feature. Joining the market waiting list is likewise voluntary and is required neither for registration nor for use of the free plan; without your e-mail address we simply cannot notify you.
Automated decision-making (Art. 13(2)(f), Art. 22 GDPR): There is exactly one automated decision, and it concerns purchases that have already been paid for. The occasion: In some countries we do not conclude paid contracts (§ 1 of our Terms — today only the United Kingdom) because we lack the VAT registration required there. If, despite the upstream block, a payment from such a market comes through, we reverse it automatically. The logic: After the payment arrives we compare the two place-of-supply indicators stated above — the billing address from checkout and the issuing country of your payment method. A purchase is reversed only where both items are present, name the same country, and that country is a blocked market. If one of them is missing or the two differ, nothing happens automatically: the purchase continues unchanged and a human being looks at the case. Your behaviour, your use of the application and your IP address play no part in it; no profiling takes place. Significance and consequences: Where a purchase is reversed we refund the amount paid in full and without any deduction to the same payment method, cancel any subscription created in the process, and do not activate the paid plan — no paid contract therefore comes into existence and nothing further is debited. Your account continues to exist and runs on the free plan; what is blocked is the purchase alone, not your access, and your data is fully retained. You receive an e-mail about it stating the amount, the time, the reference and the market concerned. The decision is not reported to any third party, and no payment default and no misconduct is attributed to you as a result. Your safeguards (Art. 22(3) GDPR): You may contest this decision, express your own point of view and request that a human being review the case — informally by replying to that e-mail or by e-mail to support@thedrawdowndiary.com. We then look at the case by hand; no login, no form and no reason are required. Your statutory rights remain unaffected. No automated decision-making within the meaning of Art. 22 GDPR takes place beyond this.
We do not use advertising or analytics cookies. Specifically:
— Login/session cookies (Supabase Auth): technically necessary, no consent required
— ddd_consent: stores your decision on the referral cookie (12 months), technically necessary
— ddd_ref: referral tracking (30 days) — only set after your consent via the cookie banner
— ddd_lang: stores a language you switched to yourself (12 months), technically necessary — not set unless you use the language switcher
Consent: You decide on the referral cookie in the cookie banner; "Decline all" is just as easy to reach as "Accept all". A cookie named ddd_consent_tv, used until 30 August 2026 for your decision on the since-removed TradingView price ticker, is deleted on your next page load.
Reach measurement without storing anything on your device: To count anonymous page views we store nothing on your device — no cookie, no localStorage, no sessionStorage. Until 28 July 2026 a sessionStorage entry ("pv_tracked") was used for this; it has been removed without replacement. Counting now happens once per page load, and the lock required for it lives solely in the volatile memory of the loaded page. § 165(3) of the Austrian Telecommunications Act 2021 is therefore not engaged.
You can revoke your consent at any time with effect for the future — with a single click on "Cookie settings" in the footer of every page. This immediately deletes ddd_consent and ddd_ref and the cookie banner reappears. Withdrawal is thus as easy as giving consent (Art. 7(3) GDPR). The lawfulness of processing carried out before the revocation remains unaffected.
Supabase (Supabase Inc., Frankfurt/Germany data centre) — database hosting and authentication; data is stored within the EU (processing on our behalf pursuant to Art. 28 GDPR; where support access from the USA occurs, on the basis of Standard Contractual Clauses)
Vercel (Vercel Inc., USA) — web hosting; processing on our behalf pursuant to Art. 28 GDPR, transfer to the USA based on certification under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses
Stripe — payment processing. The contracting entity for customers in the EEA is Stripe Payments Europe Ltd., Ireland; any transfer to Stripe, Inc. (USA) is based on certification under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses. For payment processing itself Stripe acts as a processor on our behalf (Art. 28 GDPR), while for fraud prevention and anti-money-laundering and regulatory obligations it acts as an independent controller; in that respect Stripe's own privacy policy applies
Push services of the browser and device vendors — only if you switch the push reminder on. The message then goes to the push service dictated by your browser or operating system: Apple Push Notification service (Apple Inc., USA) for Safari and on iPhone/iPad, Firebase Cloud Messaging (Google LLC, USA) for Chrome and on Android, Mozilla Push Service (Mozilla Corporation, USA) for Firefox. Transmitted are your device’s address at that service and the encrypted message; the content is end-to-end encrypted (RFC 8291) and cannot be read by the service. These providers are recipients dictated by your browser, not our processors; Apple, Google and Mozilla are certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023, Art. 45 GDPR). The processing ends as soon as you switch the reminder off.
Resend (Resend, Inc., sending region eu-west-1/Ireland) — delivery of transactional e-mails (contract confirmation pursuant to § 7(3) Austrian FAGG, guarantee declaration pursuant to § 9b Austrian KSchG, confirmation of receipt of a cancellation). The same service is also used to send the confirmation e-mail and the later notification e-mail of the market waiting list; for those, only your e-mail address and the market concerned are processed. Processed are your e-mail address, name or form of address where available, and the contract details contained in the message (plan, price, purchase date, reference). Resend is also used to send the notice about the reversal of a purchase from a blocked market; it is your record of the refund and for that purpose contains your e-mail address, the amount refunded together with the currency and the time, the reference of the purchase, the plan purchased and the market concerned. After a purchase we use the same service to send a single onboarding e-mail explaining how to set up your journal; for that purpose only your e-mail address and the language shown during checkout are processed. It contains no payment or contract details and does not advertise any further services or plans. The same service is also used to forward feedback from the beta to our own support mailbox when you use the feedback window in the beta header; for that purpose we process the text you entered, the page you sent it from, the language selected and — if you provide one — your reply address. Providing a reply address is voluntary; without it we cannot reply to you. That message goes to us only and does not trigger any e-mail to you. Technical delivery takes place via Amazon SES in the eu-west-1 region (Ireland); the data remains within the EU (legal basis: Art. 6(1)(b) GDPR, performance of contract, and (c), legal obligation, as the confirmation is required by law; for the waiting-list e-mails Art. 6(1)(a) GDPR, consent; for the notice about a reversal Art. 6(1)(b) GDPR, handling of the payment, and (f), legitimate interest in providing a record in text form; for the onboarding e-mail Art. 6(1)(b) GDPR, performance of contract — it concerns the use of the service you paid for; for feedback from the beta Art. 6(1)(f) GDPR, legitimate interest in improving the service and in replying to your message; processing on our behalf pursuant to Art. 28 GDPR)
Zoho (Zoho Corporation B.V., EU data centre) — hosting of our mailboxes support@thedrawdowndiary.com and mikko@thedrawdowndiary.com, i.e. receipt and handling of customer enquiries, withdrawal and guarantee declarations, and of feedback from the beta. Processed are all contents you send us by e-mail as well as your sender address and the message metadata. Data is held within the EU (mx.zoho.eu) (legal basis: Art. 6(1)(b) GDPR, performance of contract, and (f), legitimate interest in handling enquiries; processing on our behalf pursuant to Art. 28 GDPR)
Cloudflare Turnstile (Cloudflare, Inc., USA) — captcha protecting registration, login, password reset and the sign-up form of the market waiting list against bots; your IP address is transmitted to Cloudflare. For the waiting-list form we additionally verify the result with Cloudflare ourselves and transmit your IP address a second time for that purpose (legal basis: Art. 6(1)(f) GDPR, legitimate interest in secure operation; data transfer based on the EU-US Data Privacy Framework or Standard Contractual Clauses)
Upstash (USA) — rate limiting to protect against abuse; your IP address is processed briefly for this purpose. For forms that trigger an e-mail to a freely entered address — cancellation, withdrawal and joining the market waiting list — that address is additionally transmitted as a counting key and held there for the duration of the time window (one hour at most); no content of the message is transmitted (legal basis: Art. 6(1)(f) GDPR, legitimate interest in secure operation and in protecting third-party mailboxes from misuse of our sending domain; data transfer based on Standard Contractual Clauses)
Data is stored for as long as an active account exists. Upon account deletion, your personal data is irrevocably deleted within 30 days — in backup copies (backups held by our database provider) until they are overwritten in the regular cycle, at the latest after 30 days. The only exceptions are those expressly listed below; the list is exhaustive.
Delivery records of our transactional e-mails (table mail_outbox: recipient address and the full message text, kept as evidence of the legally required notification) are deleted 90 days after successful dispatch. Where a message could not be delivered, the entry is kept beyond those 90 days until we have dealt with the failure: it documents that a legally required notification did not reach its recipient and is the only basis for sending it again (Art. 6(1)(c) GDPR, Art. 17(3)(b)). If you delete your account, all entries relating to your address are removed immediately — including undelivered ones.
Push reminders (table push_subscriptions) are stored for as long as the reminder is switched on on the device concerned. If you switch it off, the entry is marked as withdrawn and no longer used from that moment; it is retained until account deletion as evidence of the withdrawal. If the push service reports that your device can no longer be reached at the stored address (for example because you revoked the permission in your browser), we delete the entry immediately. On account deletion all entries are deleted along with the account.
Internal processing notes (table ops_tasks) arise whenever a case cannot be completed automatically and requires a decision by us. These are not only payment events: a referral that could not be attributed to any referrer, or the expiry of Pro credit from the referral programme, also creates such a note. We store only what is needed to handle the case — user identifier or e-mail address and, where applicable, amounts and a payment reference. Open items are retained until they are resolved (Art. 6(1)(c) GDPR in conjunction with § 14 Austrian FAGG, Art. 17(3)(e) GDPR); they are deleted 90 days after resolution. On account deletion we remove resolved notes relating to your account immediately; an item still open remains until it has been resolved.
Cancellation requests (table cancellation_requests) are retained as evidence of timely handling until the statutory limitation periods expire (Art. 17(3)(e) GDPR); they are deleted together with your account.
Withdrawal declarations (table withdrawal_declarations) are treated according to their outcome. Where we accepted the withdrawal and reversed the transaction in whole or in part, the declaration is the record of a payment flow and is kept for the duration of the statutory tax retention period (§ 132 of the Austrian Federal Fiscal Code, 7 years; Art. 17(3)(b) and (e) GDPR) — including beyond deletion of your account. A withdrawal not yet decided remains until it has been decided, because the repayment period under § 14 Austrian FAGG runs regardless of whether the account still exists. Where we rejected the withdrawal, we delete the declaration together with the related correspondence at the latest when your account is deleted.
Lifetime reservations (table lifetime_reservations) record which of the ten advertised Early Bird slots have been taken. A redeemed slot is stored permanently — including after account deletion and after a refund — because the publicly displayed counter "X of 10 left" would otherwise run backwards and become an incorrect scarcity claim (Art. 6(1)(f) GDPR, Annex item 7 of the Austrian UWG; Art. 17(3)(e) GDPR). The only data held is your user identifier, the Stripe checkout reference, the status and the timestamps — no name, no e-mail address. Reservations that were not redeemed, i.e. expired or released again, are removed immediately on account deletion.
Commission records (table affiliate_commissions) are accounting records of the operator and are subject to the statutory tax retention obligation (§ 132 of the Austrian Federal Fiscal Code, 7 years; Art. 6(1)(c), Art. 17(3)(b) GDPR). If you delete your account, we remove the link to your user identifier from the record; what remains is the plan, the amount, the commission and the status, and it can no longer be attributed to you.
Market waiting list (table market_waitlist) is deleted according to four separate periods, depending on what became of the entry. Not confirmed: deleted 7 days after sign-up, provided that no confirmation link is still outstanding at that point — a confirmation link is valid for 72 hours at most, and without confirmation there is no legal basis; the few days of grace serve only to let us match a later query ("I signed up and nothing arrived"). If you submitted the form again and the confirmation link issued at that point is still valid, deletion is postponed until that link expires — it would make no sense to send you a link and delete the entry before the link runs out. The period always runs from the first sign-up and it is capped: at the latest 10 days after the first sign-up (7 days plus the 72 hours of link validity) the entry is deleted, no matter how often the form was submitted. Confirmed and notified: deleted 3 years (1,095 days) after the notification was sent. Dispatch fulfils the purpose; from then on the entry serves solely as evidence that you had consented to precisely that one message and when it went out. The burden of proving that consent lies with us (Art. 7(1) GDPR), and an administrative penalty for unsolicited electronic mail (§ 174 of the Austrian Telecommunications Act 2021) may still be imposed up to three years after dispatch under the limitation rules of the Austrian Administrative Penal Act — keeping the record for a shorter time would mean destroying our own evidence while proceedings are still possible. Unsubscribed: deleted 90 days after the unsubscription, provided no notification had yet been sent to you and provided the entry was confirmed at that point — until then the entry serves solely as evidence that and when you withdrew your consent (§ 174 of the Austrian Telecommunications Act 2021, Art. 7(1) GDPR); where the period of 730 days from your confirmation stated below expires earlier, we delete at that earlier point. If the entry had not been confirmed when you unsubscribed, the period stated above for unconfirmed entries applies instead, i.e. deletion 7 days after the first sign-up: unsubscribing invalidates any confirmation link still outstanding, so deletion is no longer postponed and the cap of 10 days does not come into play in this case. If the notification had already been sent, the preceding period of 3 years from dispatch applies instead; your unsubscription is recorded in that same entry and is deleted together with it. Confirmed but never notified: deleted at the latest 730 days (2 years) after your confirmation, even if the market has not opened by then; we do not rely on older consent. The entry is not linked to any user account and is therefore not covered by an account deletion — you can end it yourself at any time via the unsubscribe link in every e-mail or informally by e-mail to support@thedrawdowndiary.com. The delivery record of the e-mails sent for it is governed not by these periods but by the period for delivery records stated above (90 days from successful dispatch).
Anonymous page views (table page_views: path, any referrer, time) contain no user identifier, no IP address and no cookie. They cannot be attributed to a person and are therefore not subject to a retention limit; we evaluate them on an ongoing basis for reach measurement.
Otherwise: invoice and payment data is subject to the statutory retention obligation (§ 132 of the Austrian Federal Fiscal Code, 7 years). Contract records (table withdrawal_waivers, e.g. the documented express request for immediate provision) are retained for the establishment or defence of legal claims until the statutory limitation periods expire (Art. 17(3)(e) GDPR); records of abandoned checkouts, which evidence no contract, are already deleted after 90 days.
Under the GDPR you have the right to:
— access to stored data (Art. 15)
— rectification of inaccurate data (Art. 16)
— erasure of your data (Art. 17) — directly via Settings → Delete account
— restriction of processing (Art. 18)
— data portability (Art. 20) — at any time yourself via Settings → Your data → "Export all my data", and in addition still free of charge on request by e-mail
— objection to processing (Art. 21)
— revocation of consent with effect for the future (Art. 7(3))
Data export (Art. 15 and 20 GDPR, § 5c(2) Austrian VGG): In your settings you can download a complete copy of your data as a JSON file yourself at any time and free of charge — on every plan, including the Free plan and including after a paid contract has ended. It contains: your account master data and preferences, all trades, tags, psychology logs, weekly reviews, journal entries, achievements, your push reminders per device (data.push_subscriptions, without your browser’s encryption keys), contract and subscription data, contract records, cancellation and withdrawal declarations, in-app notifications, your reservations of one of the ten Lifetime slots including abandoned purchase attempts (data.lifetime_reservations), commission records relating to your purchases, operational cases concerning your account that had to be reviewed manually (data.operations_backlog), the log of transactional e-mails sent to you, and time-limited download links to your screenshots (the image files themselves are not embedded, for size reasons). Not included are payment and credit-card data — held exclusively by Stripe — and identifiers of other people from the referral program, in particular the referral code of the referring person (Art. 15(4) GDPR); from the operational cases we additionally remove the internal instruction to the operator and the raw technical error text, since neither is information about you. Also not included is any entry in the market waiting list: it is stored without an account and without a user identifier and therefore cannot be matched to the file; you can obtain information about it and have it deleted at any time informally by e-mail to support@thedrawdowndiary.com. The unsubscribe link in every e-mail ends your consent, but it does not provide information and does not delete the entry straight away — the periods stated in the section "Retention Period" apply to that.
Self-check before delivery: Before the file is produced, the export reconciles itself against independent counters — among them the trade counter in your profile record. If it contradicts itself, or if a query reported an error, we deliberately deliver nothing: an access response that falsely presents itself as a complete copy would be worse than none at all, because you would consider the matter settled. You receive a notice instead, the case is reported automatically for us to handle, and your right of access is unaffected — the one-month period under Art. 12(3) GDPR continues to run from your request, not from the fix.
Requests to: support@thedrawdowndiary.com
You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien, Austria
www.dsb.gv.at