1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR), other national data protection laws of the member states and other data protection provisions is:
Auras & Bielawski GbR
represented by the partners Wadim Auras and André Bielawski
Eduard-Bäumer-Str. 4
56288 Kastellaun
Germany
Email: hello@tmb-invest.de
Website: https://tmb-invest.de
Contact form
For enquiries about data protection, data subject rights or the processing of your data, you can also use our contact form.
A data protection officer is not required by law. If you have questions about the processing of your data, please use the contact details above.
2. Purpose and scope
This privacy policy informs you about the type, scope, and purpose of processing personal data within our online offerings tmb-invest.de as well as related features like the Library (software shop), index analyses, Noélee (AI agent for PineScript®), stelaraX (AI chart analysis), instaTrader, customer accounts, contact form, cancellation and termination functions, waiting lists, and newsletters.
3. Hosting and server logs
Our website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with ALL-INKL.COM.
Each time the site is accessed, technically necessary data is stored in so-called server log files:
- IP address (anonymised / truncated after 7 days at most)
- Date and time of access
- URL accessed and amount of data transferred
- Browser type, operating system and referrer URL
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, security and functionality of the website). Retention: 14 days at most, unless security incidents require longer retention.
Further information on data processing by ALL-INKL.COM: all-inkl.com/datenschutzinformationen.
3.1 Audience measurement (TMB Analytics, self-hosted)
If you have consented to the "Statistics" category in the cookie banner, we carry out our own self-hosted audience measurement under the name "TMB Analytics". Data is not transferred to external analytics providers (e.g. Google Analytics, Matomo Cloud); processing takes place exclusively on our own infrastructure at ALL-INKL.COM (see Section 3).
Data processed per page view:
- URL accessed and page title;
- Referrer (referring URL) and referrer domain;
- Device type (desktop/tablet/mobile), browser, operating system (derived from the user agent);
- Screen width;
- UTM parameters (utm_source, utm_medium, utm_campaign), if contained in the URL;
- Country – determined from the IP address using a local database on our server (see below);
- Timestamp;
- A pseudonymous visitor ID (
tmb_visitor_id, stored in the browser's localStorage, is recreated after 13 months) and a session identifier (tmb_session, sessionStorage, expires after 30 minutes of inactivity). Both identifiers are randomly generated; they are pseudonymous data;
- A SHA-256 hash of your IP address – salted with a secret known only to us. Your IP address itself is not stored in the analytics tables; the data is pseudonymized.
Geolocation without third-party providers: We determine the country from your IP address using the "IP to Country Lite" database from DB-IP (db-ip.com, license CC BY 4.0), which is hosted on our own server. Your IP address is not transmitted to third parties; region and city are not determined.
Legal basis: Art. 6(1)(a) GDPR (consent via our cookie banner) in conjunction with Section 25(1) TDDDG. Consent is voluntary; without consent no analysis takes place. You can withdraw your consent at any time — either via the cookie settings ("Settings" in the footer) or by deleting the local browser data. A withdrawal takes effect from the time of withdrawal.
Retention: Individual page view records are deleted automatically after 365 days (daily cron job). Aggregated evaluations are therefore never older than one year.
Exceptions: Users logged in as administrators (manage_optionspermission) are never recorded — so our own test visits do not distort the statistics.
4. Cookies and similar technologies
We use technically necessary cookies and storage techniques that are required for the operation of the site (login session, shopping cart, language selection, CSRF protection, saving your cookie choices). These are set based on § 25 para. 2 no. 2 TDDDG and Art. 6 para. 1 lit. f GDPR and do not require consent. Only with your consent do we set pseudonymous identifiers for self-hosted reach measurement (category "Statistics", see section 3.1) and the partner cookie. tmb_aff (category "Marketing", see section 17). We currently do not use marketing and tracking cookies from third parties. You can change your selection anytime via "Cookie Settings" in the footer.
5. Contact form and email
If you contact us via the contact form or by email, we process your details (first and last name, email, optionally phone, subject, message text) solely to handle your enquiry. If you address a team member directly, the message is forwarded to their assigned email address, with hello@tmb-invest.de in copy for internal follow-up.
Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual measures) or lit. f GDPR (legitimate interest in responding to your inquiry). Consent is not required for this. Storage duration: until the matter is resolved; statutory retention periods (e.g., § 257 HGB, § 147 AO) remain unaffected.
6. Customer account and order processing
To purchase products from our Library we create a customer account or use an existing one. The following data is processed:
- Name, email address, password (hashed)
- Billing address: first and last name, optionally company, street, postcode, city, country
- Order data: product(s), price, order number, timestamp, status
- Licence data: licence key, bound MetaTrader 5 account (if activated), activation and download times
- IP address at the time of the order (for fraud prevention)
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention in accordance with commercial and tax law obligations (usually 10 years).
7. Payment processing via Mollie
For payment processing, we use the service provider Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam, Netherlands). When placing an order, the data required for payment (name, email, order amount, order reference) is transmitted to Mollie. Mollie processes the actual payment data (e.g., credit card, SEPA, PayPal, Apple Pay, Google Pay) as an independent controller according to its own privacy policy: https://www.mollie.com/privacy.
Apple Pay and Google Pay: On iPhone and iPad, we offer Apple Pay at checkout, and on Android devices, Google Pay. Which option appears is determined by the device identifier of your browser (User-Agent); nothing is stored. With Apple Pay, your device retrieves a merchant session from Mollie via our server; the encrypted payment data from Apple Pay goes directly to Mollie, and we do not receive any card data. With Google Pay, we redirect you to Mollie's payment page. Apple or Google process payment data under their own responsibility according to their privacy policies.
Legal basis: Art. 6(1)(b) GDPR. A data processing agreement with Mollie is in place.
7.1 Subscriptions and recurring payments (instaTrader)
For subscriptions (e.g. the instaTrader monthly or yearly plan) we create a customer record at Mollie (name, e-mail address, our customer number). With the first payment you grant Mollie a mandate for recurring payments; the actual payment data (card or account details) remain with Mollie. We only store the Mollie identifiers of the customer record, the mandate and the subscription as well as the term, next due date, amount, payment status and the time of a cancellation in order to manage the charges, invoices and the validity of your licence.
The validity of the software license is linked to the paid subscription period: The software regularly checks via our servers whether the license is active and transmits the license key, a device identifier, and the device name (see section 8). If a charge fails, you will receive a payment reminder with a deadline of 14 days; if no payment is received by then or the subscription ends, the license will be marked as expired. We will inform you of this via email.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and, with regard to the retention of invoice data, Art. 6 (1) (c) GDPR in conjunction with the retention periods under commercial and tax law (up to ten years). The mandate at Mollie remains in place until you revoke it or the subscription ends; you can revoke it at any time through us or your payment provider.
7.2 Trading account credentials (instaTrader)
instaTrader is a local Windows application. The credentials of your trading account (login, password, server) that you enter in instaTrader are stored exclusively on your computer – encrypted via the Windows data protection interface (DPAPI) of your user account – and only passed to the MetaTrader terminal on the same computer. They are not transmitted to our servers or to third parties; the optional cloud sync of program settings technically excludes passwords, keys and credentials. We therefore do not process this data.
7.3 Measuring checkout abandonment
To understand at which step orders are abandoned, we store technical events during checkout (e.g. "cart", "checkout opened", "form error", "payment cancelled", last edited field, time spent, device type) together with a pseudonymous session value. IP address, name or email are not stored; no cookie is set (we use the checkout key that the ordering process needs anyway). The legal basis is our legitimate interest in a working ordering process (Art. 6(1)(f) GDPR). The events are deleted after 180 days.
7.4 instaTrader tester programme
If you apply as an instaTrader tester via our website, we process your name, your email address and your details on platform, account, experience, available time, broker and motivation in order to select testers and contact you. If you become a tester, we create a customer account if necessary, issue a time-limited licence and store your questionnaire answers in your customer account. We use the answers only to improve instaTrader. We publish your verdict only with your explicit consent and only with your first name. The legal basis is Art. 6(1)(b) GDPR (running the tester programme) and, for publishing the verdict, Art. 6(1)(a) GDPR; you can withdraw your consent at any time. Applications that are not selected are deleted no later than six months after the end of the tester programme. Questionnaire answers are deleted on request or together with your customer account.
8. Provision of digital products and licences
After successful payment a licence key is generated automatically and sent by email. Downloads are available after logging in to the customer account. For software that binds a MetaTrader 5 account, the MT5 account number is linked to the licence on first activation to prevent multiple use. This binding serves licence enforcement only; no further processing of the MT5 account data takes place.
9. Index analyses (market data and AI market summary)
Under /tools/dax-analyse/ as well as /tools/dow-jones-analyse/, /tools/nasdaq-analyse/ and /tools/sp500-analyse/, we provide analysis tools that evaluate price and fundamental data of companies in the DAX 40, Dow Jones 30, Nasdaq 100, and S&P 500, along with economic news, creating an AI-generated summary of the market situation ("TMB Market Summary"). We obtain market data server-side from Yahoo Finance (Yahoo EMEA Ltd., Ireland) and finanzen.net (finanzen.net GmbH, Karlsruhe); the composition of the US indices from Wikipedia (Wikimedia Foundation, USA) and nasdaq.com (Nasdaq, Inc., USA). The summary is generated via the API of OpenAI (OpenAI Ireland Ltd. or OpenAI, L.L.C., USA) or Anthropic PBC (USA).
No personal data: All queries are automated by our server and contain only market data and news – no data from our website visitors. When you access the page, only the server log data described in section 3 is processed by your browser. If you're logged in, we check your user account to see if extended areas (e.g., headlines) have been activated for you (Art. 6 para. 1 lit. b GDPR).
10. Noélee – AI agent for PineScript® / MQL (OpenAI)
At /noelee/ we offer the AI agent Noélee, which helps users program trading software (PineScript® v6 for TradingView and MQL5 for MetaTrader 5). The "PineScript® Indicators" area can be used free of charge within a one-off credit budget; further areas are unlocked via paid bundles.
Technically, Noélee runs on the OpenAI API. The responsible contracting party for users in the EEA is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; technical processing may be carried out by OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA). We use a current model of the GPT-4 class (currently GPT-4o) and update it to newer versions when needed.
10.1 Data processed
When you use the chat, the following data is processed:
- Chat content (your requests and the AI's answers), stored separately per area;
- Identifier: for logged-in users, the internal user ID of your TMB account; for non-logged-in users, a pseudonymized value (Hash from your IP address or a random browser identifier with a secret server salt);
- Timestamp of each message;
- Area assignment (e.g. "pine_indicators", "mt5_eas") per chat entry;
- Technical request data (IP address, user agent, timestamp) to enforce the credit budgets in the free tier (10 credits anonymous, 25 credits for logged-in users).
10.2 Transfer to OpenAI (Ireland and USA)
To generate the response, your chat content (request text and previous conversation history, max. the last 30 messages) is transmitted to the OpenAI API and processed there. This may involve a transfer to a third country (USA). The legal basis for processing is Art. 6 para. 1 lit. b GDPR (execution of the AI assistance you requested). The transfer to the USA is based on the adequacy decision of the EU Commission regarding the EU-US Data Privacy Framework (Art. 45 GDPR), under which OpenAI is certified; additionally, standard contractual clauses apply (Art. 46 para. 2 lit. c GDPR).
OpenAI has its own privacy policies; according to its own statements, inputs transmitted via the API are not used for training the models and are stored for up to 30 days to prevent misuse. Details: openai.com/policies/privacy-policy · API Data Usage Policies.
Please do not enter any sensitive or personal data (health data, financial account information, passwords, third-party data, etc.) in the Noélee chat.
10.3 Retention of the chat history
To allow you to continue using the service, we store your chat histories in our database:
- Logged-in users: Stored permanently until you delete the chat yourself via the "Clear chat" button or close your account.
- Non-logged-in users: Storage linked to a pseudonymized value (see section 10.1); access to the history is only possible as long as you use the same IP address or browser. The histories are automatically deleted 90 days after the last message; you can also delete them yourself at any time.
- Chat histories are stored separately per area (e.g. the PineScript® indicators history separately from the MQL5 EAs history).
Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment or pre-contractual measures for providing the requested service).
10.4 Trading Academy (lesson progress and PDF export)
The Noélee "Trading Academy" area provides structured learning modules on trading topics (basics, technical analysis, risk management, psychology, strategy). In addition to the chat content described in Section 10.3, we process the following data for this purpose:
- Lesson Progress: For each module, we store which lessons you've completed (list of lesson IDs), the currently processed lesson, the status ("in_progress"/"completed"), as well as the start and possibly end time. This data is linked to your user ID (logged in) or to a pseudonymized value (not logged in). They help you seamlessly continue your learning path.
- Thread assignment: Each module gets its own chat thread so that questions and answers about a lesson are kept separate from other conversations. Thread content is stored as described in Section 10.3 and transmitted to OpenAI (Section 10.2).
- Generated PDF summaries (premium feature): After completing a module you can have a personalised PDF summary of your learning path generated in exchange for credits (Academy PDF bundle). The PDF file is stored on our server (directory with a random path); in the database we store the file path, file size, title, module reference, user ID, timestamp and optionally the associated order ID. Once generated, the PDF contains content from the associated chat thread and the lessons you completed.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures to provide the learning service) and – for retaining the PDF transactions – Art. 6(1)(c) GDPR in conjunction with Section 147 AO, Section 257 HGB (tax retention for paid Academy PDFs).
Retention:
- Lesson progress: permanently, until you close your account or request deletion by email to hello@tmb-invest.de.
- Generated PDF files: remain available in your account as long as your account exists. You can delete individual PDFs yourself at any time. The transaction metadata for paid PDF generations is subject to the 10-year retention period for tax-relevant transactions.
- For non-logged-in users, we store the lesson progress linked to a pseudonymized value and delete it 90 days after the last activity; a PDF export is not possible without logging in.
10.5 Premium bundles, credit refills and area unlocks
For the use of paid areas ("premium bundles") and for pure credit top-ups ("credit refills") we additionally process the following data:
- Credit balance: current balance of purchased and used credits, linked to your user ID;
- Area unlocks: list of the premium areas unlocked for your account with the date of unlocking and a reference to the underlying order;
- Transaction log (ledger): chronological record of all credit movements (bundle purchases, refill purchases, usage, manual adjustments) with timestamp and reference to the area. Serves traceability and dispute resolution.
Legal basis: Art. 6(1)(b) GDPR (performance of the bundle/refill contract) and Art. 6(1)(c) GDPR (commercial and tax retention obligations, in particular Section 257 HGB, Section 147 AO).
Retention: This data is kept for the duration of your account use and, after it ends, for the statutory retention periods (usually 10 years for tax-relevant transactions).
10.6 Payment processing for bundle purchases
Bundle purchases are processed via the payment service provider Mollie B.V.. The provisions in Section 7 of this privacy policy apply accordingly. On purchase, the order number, buyer ID and bundle name are recorded for confirmation and linked to the unlocking of the area and the credit top-up.
10.7 Credit budget in the free tier
To enforce fair usage in the free tier, we manage a one-time granted credit budget (10 credits for anonymous users, 25 credits for registered users). Each request to Noélee uses one credit from this budget. The budget is persistent and regenerates not automatically; if it's used up, paid premium bundles or credit refills are available to top up (Sec. 10.5).
Technically, the remaining credit balance is stored server-side — for registered users as user meta on the TMB account, for non-registered users under a pseudonymized key (hash from IP address and a randomly generated UUID created in the browser). The storage contains no content data, only the numerical credit balance and a timestamp of the initial grant. Without registration, we delete this entry 12 months after the initial grant.
For non-registered users, the credit budget is additionally anchored to a device-specific, randomly generated identifier ("browser ID"). This ID is a random, pseudonymous UUID and is stored locally (localStorage) of your browser. It prevents the budget from being granted again by switching networks (e.g. from Wi-Fi to mobile data). You can delete this ID at any time via your browser settings; your current credit balance is then discarded and a new initial budget is granted on your next visit.
To ward off automated bot requests we use the service Cloudflare Turnstile from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for users who are not logged in. Turnstile checks in the background, using technical browser characteristics (user agent, header properties, mouse and keyboard behaviour, IP address), whether a real person is present — without a visible captcha task and without tracking. No cookies are set and no personal data is stored permanently. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protection against abuse). Cloudflare processes data in the USA on the basis of the EU-US Data Privacy Framework. More information: cloudflare.com/privacypolicy.
10.8 Withdrawal and deletion
You can:
- delete the chat history yourself at any time via the "Clear chat" button in Noélee (per area or globally);
- stop using Noélee at any time by no longer opening the page;
- as a logged-in user, request the complete deletion of all Noélee chat data via hello@tmb-invest.de;
- have the credit balance and area unlocks deleted on request — however, this amounts to waiving the purchased services and does not lead to a refund. The retention of the transaction logs for tax reasons (Section 10.5) remains unaffected.
11. stelaraX – AI chart analysis (OpenAI ChatGPT)
Under /stelarax/, we offer registered users the free service stelaraX. stelaraX generates an AI-supported setup suggestion based on user inputs (symbol, timeframe, strategy) with entry, take-profit, stop-loss, and risk-reward ratio. stelaraX does not recommend a position size; the position calculator only computes locally in your browser with values you enter yourself – these values are not transmitted to us.
Technical architecture: To provide the service we work with two specialised partners:
- Live market data is obtained server-side via the market data API of Twelve Data Pte. Ltd., 20A Tanjong Pagar Road, Singapore 088443. Only the instrument selected by the user (e.g. EURUSD) and the timeframe are transmitted — no personal user data. The request originates from our server, not from your browser; your IP address is not passed on to Twelve Data.
- Validation and analysis of the setup proposals then takes place via the OpenAI API. OpenAI receives the market data snapshot and your input parameters in order to validate and comment on the setup proposal.
OpenAI's responsible contracting party for users in the EEA is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI OpCo, LLC (3180 18th Street, San Francisco, CA 94110, USA) is responsible for US-side processing.
11.1 Data processed
When you use stelaraX, the following data is processed:
- Inputs to us: selected symbol (e.g., EURUSD, BTCUSD, XAUUSD), timeframe (M15, H1, H4, D1 etc.) and strategy selection (e.g., OTE, SMC, Donchian, Fibonacci);
- Technical metadata (only with us): IP address, user agent, timestamp of the request — for abuse protection and rate limiting. This metadata is not transmitted to Twelve Data or OpenAI.
- To Twelve Data: only symbol and timeframe to retrieve the corresponding price data (no personal details).
- To OpenAI: the chosen parameters (symbol, timeframe, strategy) as well as the market data snapshot obtained from Twelve Data, which OpenAI needs for validation and commentary – no personal information;
- AI result: the setup suggestion generated by the OpenAI API with entry/TP/SL/comment.
Using this requires a TMB user account; the request is assigned for abuse protection and storage function of your user ID.
11.2 Transfer to OpenAI (USA and Ireland)
To validate and comment on the setup, the user input mentioned above and the market data snapshot obtained from Twelve Data are transmitted to OpenAI. OpenAI uses them to generate the final analysis text. Depending on model availability, processing takes place in the EU (via OpenAI Ireland Ltd.) and/or in the USA (via OpenAI OpCo, LLC). This therefore constitutes a transfer to a third country (USA).
Legal basis: Art. 6 para. 1 lit. b GDPR (execution of the AI chart analysis you requested). The transfer to the USA is based on the adequacy decision of the EU Commission regarding the EU-US Data Privacy Framework (Art. 45 GDPR), under which OpenAI is certified; additionally, standard contractual clauses apply (Art. 46 para. 2 lit. c GDPR). More information on data processing by OpenAI: openai.com/policies/eu-privacy-policy.
Please do not enter any sensitive or personal data (health data, account information, passwords, third-party data, etc.) in stelaraX. The input fields are designed exclusively for market parameters anyway.
11.3 Storage of generated analyses (opt-in)
stelaraX analyses are not automatically saved with us. You will initially see a generated setup only in your browser session. Only when you actively choose to save it (button "Save analysis"), we will store a copy with the following details in your TMB user account:
- Symbol, timeframe, selected strategy;
- entry price, take-profit, stop-loss, R:R;
- Time of generation, optionally a comment/title you assigned.
Legal basis: Art. 6(1)(a) GDPR (consent by actively saving) or Art. 6(1)(b) GDPR (provision of the requested save function).
Storage Duration: Saved analyses remain permanently accessible, until you delete them yourself. Deletion is irreversible and happens directly in the stelaraX interface per analysis or globally via an "Delete All" action. When you close your TMB account, all saved stelaraX analyses will also be deleted.
11.4 Free service — no billing record
stelaraX is completely free. No payment data, billing or contract addresses, or credit balances are collected. Processing is limited to what is technically necessary for providing the analysis (§ 11.1) and – when using the storage function – to what the user has actively saved (Section 11.3).
11.5 Abuse protection and rate limiting
To ensure fair access we apply a request limit per IP and hour/day. The counters are kept in a server-side cache (WP transients) for at most 24 hours and contain no content, only timestamps and a hash of the request source. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse).
11.6 Objection and deletion
You can:
- stop using stelaraX at any time by no longer opening the page — transient analysis results that were not saved are discarded as soon as you leave the page;
- delete saved analyses individually or all at once in the stelaraX interface at any time;
- as a logged-in user, request the complete deletion of all stelaraX data via hello@tmb-invest.de.
Data that has already been transmitted to OpenAI is thereafter within OpenAI's area of responsibility; according to its own statements, API input is not used to train the models but may be cached briefly to prevent abuse.
12. Newsletter and marketing emails
If you sign up for our newsletter, we process your email address on the basis of your consent (Art. 6(1)(a) GDPR). We use the double opt-in procedure. You can unsubscribe at any time via the link in every newsletter email or by sending a message to hello@tmb-invest.de.
13. External services and links
stelaraX AI Analysis: For data processing including transmission to Twelve Data and OpenAI, see Section 11.
MetaTrader 5 / MQL5: Links to MetaTrader 5 downloads or MQL5 signals lead to offerings of MetaQuotes Software Corp.
Broker Links: We link to brokers as external providers. By clicking, you leave our offer; the privacy policies of the respective provider apply. If we receive a commission for a link, we label it as advertising.
14. Fonts
We use locally embedded fonts (web fonts) that are loaded directly from our server. No connection to Google Fonts or other external font CDNs is made.
15. Recipients and processors
Your data is only transferred to third parties in the following cases:
- To ALL-INKL.COM – Neue Medien Münnich as a hosting provider for operating the website and sending system emails.
- To Mollie B.V. for processing payments (with Apple Pay or Google Pay, additionally Apple or Google are responsible, see Section 7)
- To OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C. or OpenAI OpCo, LLC, USA) for processing AI chat requests (Noélee, see Section 10) and AI chart analyses (stelaraX, see Section 11)
- To Cloudflare, Inc. (USA) for bot defense Cloudflare Turnstile at Noélee without registration (see Section 10.7)
- To Twelve Data Pte. Ltd. (Singapore) and for index analyses to OpenAI or Anthropic PBC (USA) only market data is transmitted, no personal data
- To tax advisers and authorities, where legally required
We have concluded contracts pursuant to Art. 28 GDPR with processors where the respective arrangement requires it.
16. Transfers to third countries
Transmission of personal data to third countries outside the EU/EEA occurs in the following cases:
- OpenAI (USA): Noélee chat requests (Section 10) and stelaraX chart analyses (Section 11). The basis is the adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), under which OpenAI is certified; additionally, standard contractual clauses (Art. 46 para. 2 lit. c GDPR). The contracting partner for EEA users is OpenAI Ireland Ltd.
- Cloudflare, Inc. (USA): Bot defense Turnstile (Section 10.7). The basis is the EU-US Data Privacy Framework (Art. 45 GDPR).
- Mollie B.V.: primarily EU processing; for card payments, a transmission to card networks outside the EU may be necessary (Art. 49 para. 1 lit. b GDPR, contract fulfillment).
Anthropic PBC (USA) und Twelve Data Pte. Ltd. (Singapur) erhalten von uns ausschließlich Marktdaten und keine personenbezogenen Daten.
17. Partner program (affiliate)
We run a partner program through which registered affiliate partners can receive a commission for referring customers. Participation is voluntary and requires a TMB Invest user account. As part of the partner program we process the following data:
a) Attribution via cookie
If a person clicks on a partner link (URL parameter ?ref=CODE) und willigt sie in den Cookie-Einstellungen in die Kategorie „Marketing“ ein, setzen wir ein Cookie namens tmb_aff mit dem Referenz-Code des Partners. Laufzeit: 30 Tage. Bestehende Zuordnungen werden nicht überschrieben (First-Touch-Attribution). Das Cookie enthält keine Angaben über den Besucher, sondern nur den öffentlichen Partner-Code. Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO in Verbindung mit § 25 Abs. 1 TDDDG (Einwilligung) sowie bei späterem Abschluss einer Bestellung Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung gegenüber dem Partner). Ohne Einwilligung wird kein Cookie gesetzt.
b) Click log
When a partner link is opened we log: partner code, a SHA-256 hash of the IP address (no plain-text IP), the user agent, the target URL (landing page) and the referrer. The log serves fraud detection only (cookie stuffing, self-purchases, unusual click patterns). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). Retention: 12 months, then automatic deletion.
c) Commission and payout data
For our own partners (program participants) we additionally process: full name, email address, account holder, IBAN and BIC for paying out commissions, and the time of acceptance of the terms and conditions. For each referred order we store the order ID, gross/net amount, commission amount, status and timestamp. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR in conjunction with Section 147 AO (tax retention obligation, 10 years).
d) Recipients
Bank details are viewed exclusively by authorised staff of Auras & Bielawski GbR and – within the scope of statutory record-keeping and reporting obligations – by our tax adviser and, where applicable, the competent tax authorities.
e) Widerruf und Löschung
Du kannst deine Einwilligung in den Partner-Cookie jederzeit über die „Cookie-Einstellungen“ im Seitenfuß widerrufen; der Cookie wird dann gelöscht. Als registrierter Partner kannst du dein Partner-Konto mit einer E-Mail an hello@tmb-invest.de schließen lassen. Bereits ausgezahlte Provisionen sowie die zugehörigen Abrechnungsunterlagen unterliegen steuerlichen Aufbewahrungsfristen und können vor deren Ablauf nicht gelöscht werden.
17a. Bewerbungen
Einen Online-Bewerbungsbereich betreiben wir nicht mehr. Bewerbungen, die du uns per E-Mail schickst oder die über den früheren Karriere-Bereich eingegangen sind, verarbeiten wir ausschließlich zur Durchführung des Bewerbungsverfahrens (Kontaktdaten, Unterlagen, Angaben zu Verfügbarkeit und Konditionen). Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (vorvertragliche Maßnahmen auf deine Anfrage); freiwillig mitgeteilte besondere Kategorien personenbezogener Daten verarbeiten wir auf Grundlage von Art. 9 Abs. 2 lit. b DSGVO. Kommt kein Beschäftigungsverhältnis zustande, löschen wir die Unterlagen spätestens sechs Monate nach Abschluss des Verfahrens, sofern du nicht ausdrücklich in eine längere Speicherung eingewilligt hast (Art. 6 Abs. 1 lit. a DSGVO, jederzeit widerruflich). Die Unterlagen liegen ausschließlich bei unserem Hoster (Ziff. 3); eine Übermittlung an Dritte findet nicht statt. Eine automatisierte Entscheidungsfindung findet nicht statt.
17b. Widerrufsfunktion und Kündigungsseite
If you withdraw from a contract using the "Withdraw from contract" button (/vertrag-widerrufen/) or cancel using "Cancel contracts here" (/abo-kuendigen/), we process the details you enter (name, email address, order number or licence key, for a cancellation the type, date and, if applicable, reason for the cancellation, voluntary additional information) together with the date and time of receipt. The purpose is to handle your declaration and to send the legally required confirmation of receipt by email. The legal basis is Art. 6(1)(c) GDPR in conjunction with Section 356a or Section 312k BGB, and Art. 6(1)(b) GDPR. To prevent abuse we use an invisible check field and a shortened hash of your IP address for rate limiting (one hour at most). We store withdrawal declarations for three years from receipt as proof and then delete them automatically; cancellations become part of the contract records and are subject to their retention periods.
18. Your rights as a data subject
You have the following rights at any time:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR), unless statutory retention obligations prevent it
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
Please send requests to hello@tmb-invest.de.
19. TMB CopyFlow (Windows software)
TMB CopyFlow is a Windows application for copying trade orders between your own MetaTrader 5 accounts. When the software is used, data is processed as follows:
19.1 Processing on your device
The login details of your trading accounts (login number, password, server name), your copy settings, the mapping state of open positions and a log of the copied orders are stored exclusively locally on your computer in the folder %LOCALAPPDATA%TMBCopyFlow . Passwords are encrypted with the Windows Data Protection API (DPAPI) and are bound to your Windows user account. This data is not transmitted to us.
19.2 Licence check
On start-up and roughly every six hours thereafter, the software checks the validity of your licence via an encrypted connection (HTTPS) to tmb-invest.de. The following is transmitted: your licence key, a device identifier derived from hardware characteristics, the program version and, for technical reasons, your IP address. Purpose: binding the licence to one PC and protection against unauthorised use. Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The device identifier is stored assigned to the licence for as long as the licence exists; the binding can be reset on request when you change devices.
19.3 Optional remote view on a mobile device
If you enable the "Phone via tmb-invest.de" function in the software, your PC sends a status report to our server roughly every three seconds, which forwards it to your paired mobile device. The status report contains: names and login numbers of your accounts, server names, balance and equity, open positions, the latest log lines and the name of your PC. Broker passwords are not transmitted. Commands triggered from the mobile device (e.g. start copying, close position) are stored until collected by the PC, for a maximum of two minutes. The last status report is deleted automatically after 24 hours. When creating accounts via the mobile device, the account password is transmitted end-to-end encrypted; our server cannot read it.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract, additional function requested by you). The function is off by default and can be ended at any time in the software or in the customer account (unpair). Hosting: ALL-INKL.COM as processor (see Section 3).
19.4 Microsoft Store
When you purchase via the Microsoft Store, Microsoft Ireland Operations Ltd. or Microsoft Corporation processes your purchase and account data under its own responsibility. We receive no personal data of buyers from Microsoft, only anonymous sales statistics. Microsoft's privacy statement applies: privacy.microsoft.com.
19.5 No sharing, no analytics
The software contains no third-party advertising or analytics services and sends no usage statistics. Transmission to brokers takes place exclusively via the MetaTrader terminals running on your PC and is subject to the privacy policy of the respective broker.
19.6 Your rights
You have the rights to access, rectification, erasure and restriction described in the "Data subject rights" section. You delete local data yourself by removing the folder %LOCALAPPDATA%TMBCopyFlow; we delete the server data of the remote view and the device binding on request to hello@tmb-invest.de.
20. AI labelling and transparency (Art. 50 AI Act)
Since 2 August 2026, the transparency obligations of Art. 50 of the EU AI Act (Regulation (EU) 2024/1689) apply. We implement them as follows:
- AI interaction: Our AI services Noélee (AI chat and Trading Academy) and stelaraX (AI chart analysis) are clearly disclosed as AI systems from the very first interaction (Art. 50(1) AI Act).
- KI-generierte Ausgaben: Von Noélee und stelaraX erzeugte Inhalte (Chat-Antworten, Setup-Vorschläge, Lern-PDFs) sowie die TMB Marktzusammenfassung der Index-Analysen werden als KI-generiert ausgewiesen. Die von stelaraX ausgegebenen Setup-Vorschläge tragen einen sichtbaren KI-Hinweis; Academy-PDFs enthalten einen entsprechenden Hinweis im Dokument.
- Visible labelling of editorial content: Posts on this website that were created entirely or substantially by artificial intelligence are marked with a clearly perceptible notice directly on the content. AI-generated or AI-altered realistic image, audio or video representations ("deepfakes") are disclosed as such at the first perception (Art. 50(4) AI Act).
- Machine-readable marking: Labelled content additionally receives a machine-readable marking in the source code (meta data and structured data according to the IPTC standard "Digital Source Type"), so that the AI origin is also technically recognisable (Art. 50(2) AI Act).
- AI-assisted content: Content for which AI was used only in a supporting role and which is subject to human editorial review is voluntarily labelled as "AI-assisted".
We answer questions about AI labelling at hello@tmb-invest.de.
21. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Hintere Bleiche 34, 55116 Mainz, Germany
Web: www.datenschutz.rlp.de
22. Currency of this policy
As of: Oktober 2026. Wir behalten uns vor, diese Datenschutzerklärung anzupassen, wenn sich rechtliche oder technische Rahmenbedingungen ändern.