Privacy Policy
Last updated: August 2026This privacy policy explains how ProFuturesTrading("we", "us") processes personal data when you visit profuturestrading.de. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing on this website is:
ProFuturesTrading.de — Phil Wasmuth, c/o Online-Impressum #8862, Europaring 90, 53757 Sankt Augustin, Germany.
Email: insider@profuturestrading.de
2. Hosting & Content Delivery (Cloudflare)
This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. The provider processes server log files (including IP address, date and time of request, browser type) on our behalf for the purpose of delivering and securing the website. A data processing agreement (DPA) is in place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website).
In addition, we use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (content delivery network, DNS and security layer). When you access the website, your IP address is processed by Cloudflare to deliver content and to protect the site against attacks. Cloudflare may transfer data to the United States; such transfers are safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and Cloudflare's certification under the EU-U.S. Data Privacy Framework. A data processing agreement is in place. Legal basis: Art. 6(1)(f) GDPR. All fonts and animation assets are self-hosted — no requests are made to Google or other third-party font/asset servers.
3. Server Log Files
When you access the website, the following data is automatically collected and stored in server log files: browser type and version, operating system, referrer URL, host name, time of the server request, and IP address. This data is not merged with other data sources and is used solely for technical operation and security.
4. Cookies
This website uses only technically necessary cookies required for basic functionality. We do not use tracking or advertising cookies. Our website analytics (see section 12) works entirely without cookies and without storing or reading any information on your device. Should cookies requiring consent be introduced in the future, they will only be set after your explicit consent (Art. 6(1)(a) GDPR / § 25 TDDDG).
5. Checkout & Payment (CopeCart)
Purchases and subscriptions are processed by our reseller CopeCart GmbH, Augustinusstraße 9d, 50226 Frechen, Germany, acting as merchant of record. When you proceed to checkout, you are forwarded to CopeCart, and the data you enter there (name, email, payment and billing details) is processed by CopeCart under its own privacy policy. We receive only the information necessary to activate and manage your license (in particular your ATAS-linked email address). Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
6. License Activation (ATAS)
To activate your indicator license, your ATAS-account email address is transmitted to the ATAS marketplace operator so that the purchased tools can be unlocked for your account. Legal basis: Art. 6(1)(b) GDPR.
7. Contact
If you contact us by email, the data you provide will be processed to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR.
8. Your Rights
Under the GDPR you have the right to:
- access your personal data (Art. 15 GDPR);
- rectification (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- object to processing (Art. 21 GDPR);
- lodge a complaint with a supervisory authority (Art. 77 GDPR).
9. Data Retention
We store personal data only as long as necessary for the purposes described above. Where statutory retention periods apply, the following applies: business and commercial correspondence is retained for 6 years (§ 257 German Commercial Code, § 147 German Fiscal Code); accounting records, invoices and payment data are retained for 10 years (§ 257 HGB, § 147 AO). Server log files are deleted after 14 days at the latest unless a security incident requires longer storage. All other personal data is deleted once the purpose of processing ceases.
10. EdgeBook App, Cloud Sync & AI Connector (MCP)
EdgeBook is our desktop trading journal (part of the PFT Terminal). By default it stores your journal locally on your device. The cloud and AI features described below are strictly optional and only take effect after you enable them.
Data processed.If you enable cloud sync, we process the journal data you choose to sync: trades (instrument, entry/exit, size, P&L, timestamps), your written notes, reflections, tags, ratings and setups/playbook entries, chart screenshots attached to trades, voice-note recordings and their text transcripts, and broker / prop-firm account data. Broker account numbers are shown to any connected AI in masked form (e.g. ****1234). We do not use your journal to train any AI model, and we do not sell it or use it for third-party advertising.
Where it is stored. Cloud journal data is stored in the EU with Supabase (Frankfurt, Germany); attached images are stored in access-controlled EU object storage (Cloudflare R2). Data is encrypted in transit (TLS) and at rest. Data-processing agreements are in place with both providers. Legal basis: Art. 6(1)(a) GDPR (consent) for the cloud/AI features; Art. 6(1)(b) GDPR for operating your account.
AI Connector (MCP). The optional EdgeBook AI Connector lets an AI assistant of your choice (for example Claude or ChatGPT) read your own journal over the Model Context Protocol. The connector is read-only — it cannot create, change or delete any data. Access is authorised per user via OAuth 2.1, every request is strictly limited to the signed-in user through database Row-Level Security, and access tokens are never exposed to the AI model.
“Bring your own AI” — important. When you connect an AI client, the journal data you request flows to the AI provider you chose(e.g. Anthropic for Claude, OpenAI for ChatGPT) so that it can answer you. That provider processes the data under its own privacy terms and your own account with it. We never send your data to an AI provider on our own initiative — it happens only in response to a request you make in your AI client. If that provider is located outside the EU, the transfer is safeguarded by the mechanisms in that provider's own agreement with you (e.g. EU Standard Contractual Clauses).
Retention. Cloud journal data (trades, notes, transcripts, screenshots and prop-account data) is kept for as long as your account is active. When you delete your account or your cloud data, the corresponding records and stored images are removed from our systems without undue delay, and residual backups are overwritten on their normal rotation. Statutory billing records are kept only where the law requires (see section 9).
Export & withdrawal. You can obtain a copy of your data or withdraw consent to the cloud/AI features at any time — by disabling them in the app, deleting your cloud data, or emailing insider@profuturestrading.de. Your GDPR rights (access, portability, erasure) in section 8 apply.
11. AI Mentor (rAI)
The AI Mentor is optional and switched off by default. It only runs when you open it and send a message.
What is processed. Your messages, and the journal data the assistant needs to answer them: your trades, journal entries, statistics, strategies, prop-firm accounts and notes. The assistant can also store what it has learned about your trading, so that it does not have to ask you the same thing twice.
Where it runs. We use Scaleway (Scaleway SAS, France) as our model provider. Processing takes place within the European Union, currently in a data centre in Paris, France. Your data is not transferred outside the European Union for this purpose.
What does not happen. Your prompts, requests and the generated answers are not stored by the provider and are not used to train, retrain or improve any AI model. They are not accessible to third parties, to other customers of the provider, or to the creators of the underlying models. The provider records only aggregated, anonymised metadata such as token counts, status codes and timestamps in order to monitor performance; this is kept for up to six months. One exception: if a request causes a technical error or activity looks abusive, the provider may temporarily store and access the full content of that request in order to find and fix the cause, for no longer than two weeks.
How to remove it. You can delete individual conversations at any time. Deleting your account removes the entire history, including everything the assistant has learned about you.
Legal basis: Art. 6(1)(a) GDPR (your consent — the feature is off until you use it).
12. Web Analytics (Pirsch)
To understand how our website is used and which pages people actually reach, we use Pirsch Analytics, a service of Emvi Software GmbH, Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Germany. Processing takes place on servers in Germany (Nuremberg and Falkenstein). A data processing agreement under Art. 28 GDPR is in place.
Pirsch works without cookies and does not store or read any information on your device. It does not build profiles across websites and does not track you elsewhere. Recorded are aggregated statistics: page views, the referring website, any campaign parameters contained in the link you followed, the type of device and browser, and the country and city derived from your IP address.
Your IP address is not stored as such. It is combined with your browser's user agent and a random string that is unique to this website, in order to calculate a number that distinguishes visitors from one another. A visit is counted for at most 24 hours, after which a new number is assigned. Because the random string differs per website, that number cannot be matched across sites.
Legal basis is our legitimate interest in a statistical evaluation of website usage and in improving our offering (Art. 6(1)(f) GDPR). As no information is stored on or read from your device, consent under § 25 TDDDG is not required. Further information: pirsch.io/privacy.
13. Product Emails & Newsletter (Brevo)
We send emails through Brevo (Sendinblue GmbH, Berlin, Germany). Two kinds of email have to be told apart here, because they rest on different legal grounds.
Service emails are sent because you use the product — for example the setup instructions after you confirm your address, or a notice about your license. They are necessary to provide what you signed up for. Legal basis: Art. 6(1)(b) GDPR. They do not advertise anything and cannot be switched off separately, as long as you have an account.
Product updates and trading resources are only sent if you actively asked for them. The checkbox during registration is not pre-ticked, and ticking it is never a condition for creating an account. Legal basis: Art. 6(1)(a) GDPR.
Your consent only takes effect once you confirm your email address: the entry in our mailing list is created after that click, not when you submit the form. This double opt-in makes sure nobody can sign up an address that is not theirs. We record when you consented, through which channel, and which version of the consent text you were shown — that record is our proof under Art. 7(1) GDPR and is kept for as long as we rely on it.
You can withdraw your consent at any time, with effect for the future, using the unsubscribe link in every such email or by writing to insider@profuturestrading.de. Withdrawing is as easy as giving consent and has no effect on your account or on service emails. Data processed until the withdrawal remains lawful.
