1. Data Controller
Kristian Kovac, Am Grimnitzsee 3, 16247 Althüttendorf, Germany
Email: info@ngutrading.com
2. What Data We Collect
We collect and process the following personal data:
- Account data: Email address, display name, password (hashed)
- Trading data: Journal entries, trade logs, P&L records, account information, screenshots
- Usage data: Interface preferences, navigation history, XP/level progression
- Authentication data: Session tokens, Google account ID (if linked)
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): Processing your trading data to provide the journaling service
- Consent (Art. 6(1)(a) GDPR): Optional features like weekly email digests, public profiles
- Legitimate interest (Art. 6(1)(f) GDPR): Security measures, fraud prevention, service improvement
4. Third-Party Services
- MongoDB Atlas: Database hosting — data may be stored on servers in the EU/US
- Resend: Transactional emails (password reset, verification) — processes email addresses
- Google OAuth: Optional authentication — only email and name are accessed if you choose Google login
- Google Analytics: Usage analytics (only with your consent) — collects anonymized page views, session data, and device type. Processed by Google LLC. See Google's Privacy Policy
We do not sell data to third parties. Analytics data is only collected when you accept analytics cookies via the cookie banner.
5. Cookies
We use only essential cookies required for authentication and storing your preferences (theme, interface mode). No tracking or advertising cookies are used. See our Cookie Policy for details.
6. Data Retention
- Account and trading data: retained as long as your account is active
- Authentication tokens: automatically deleted after 15 minutes (or upon use)
- Rate limiting logs: automatically deleted after 1 hour
- Upon account deletion: all personal data is permanently removed within 30 days
7. Your Rights (GDPR Articles 15–22)
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Delete your account and all data (Art. 17) — available in Settings
- Export your data in a machine-readable format (Art. 20) — available in Settings
- Restrict processing (Art. 18)
- Object to processing (Art. 21)
- Withdraw consent at any time (Art. 7(3))
To exercise any of these rights, contact us at info@ngutrading.com or use the self-service options in your Settings page.
8. Data Security
We implement appropriate technical and organizational measures to protect your data, including encrypted connections (HTTPS), hashed passwords (bcrypt), hashed authentication tokens (SHA-256), and rate-limited API endpoints.
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. The competent authority in Germany is the data protection authority of the state of Brandenburg (LDA Brandenburg).
10. No Financial Advice
NGU Edge is a journaling and performance tracking tool. Nothing on this platform constitutes financial, investment, or trading advice. All trading decisions are your sole responsibility. See our full disclaimer.